Command of the Belgian regulatory framework — Centre for Cyber Security Belgium, Data Protection Authority, NIS2 — for public and private organizations.
Last updated — August 22, 2026
Belgium's cybersecurity framework is carried by the Centre for Cyber Security Belgium (CCB), the national cybersecurity authority, and by the Data Protection Authority (APD/GBA) for personal data protection. The NIS2 transposition law, adopted in 2024, broadens the scope of essential and important entities subject to risk management and incident notification obligations. The CCB also promotes the CyberFundamentals Framework, a set of security controls graded by an organization's maturity and criticality level, widely used as an operational compliance tool.
Engagement model
Direct engagement
Operational framework
CCB CyberFundamentals Framework
Languages
French, Dutch, English
The Centre for Cyber Security Belgium (CCB), which drives the national strategy and the NIS2 transposition.
A set of graded security controls developed by the CCB, allowing organizations to structure their compliance according to their maturity and criticality level.
Entities identified as essential or important based on the sector and size criteria set by the national transposition. This topic has its own dedicated page on this site.
The Data Protection Authority (APD/GBA), which enforces GDPR.
It serves as an operational tool for entities subject to NIS2 to demonstrate and structure compliance with risk management requirements.
Security audits, GRC compliance aligned with the CyberFundamentals Framework, and penetration testing for essential and important entities.
With an initial scoping phase to determine the entity's status under NIS2 and the targeted CyberFundamentals control level.