The NIS2 directive, transposed into Belgian law by the law of April 26, 2024, considerably broadens the scope of entities subject to cybersecurity obligations. Many SMEs are now concerned without knowing it. Three questions to position yourself.
Question 1: is your sector in the annexes?
NIS2 targets two categories: highly critical sectors (energy, transport, banking, health, water, digital infrastructures, public administration, aerospace) and critical sectors (postal services, waste management, chemicals, food, manufacturing, digital providers, research).
"Digital providers" include online marketplaces, search engines, social networking platforms, cloud computing services, data centers, CDNs — and above all managed service providers and managed security service providers. Many IT SMEs fall into this category.
Question 2: do you meet the size thresholds?
Except for sectoral exceptions, only medium-sized entities (50-249 employees and > €10M turnover or > €43M balance sheet) and large entities are concerned.
But beware: managed service providers and certain critical infrastructures (DNS providers, domain name registries) are subject regardless of their size. A 12-person IT SME offering MSP (Managed Service Provider) services is concerned.
Question 3: are you a supplier to a concerned entity?
This is the most misunderstood point: NIS2 requires concerned entities to master their supply chain. In practice, this means they will require their suppliers to have new contractual clauses, certifications, sometimes audits.
In other words, you may not be directly subject to NIS2 while being contractually obliged to comply because your client is. We've been seeing this cascade effect deploy since late 2024, particularly in the IT, transport, and energy sectors.
The main obligations
For directly concerned entities:
Registration with the CCB (Centre for Cybersecurity Belgium) within legal deadlines — this obligation is being rolled out, with sectoral registration waves.
Cyber risk management measures: security policy, incident management, business continuity, supply chain security, training. The framework is largely based on ISO 27001 and ANSSI principles.
Notification of significant incidents to the CCB within 24 hours for early warning, then complete report within 72 hours.
Management body responsibility: directors are personally responsible for implementing measures. They must also undergo regular training.
Penalties
Administrative fines up to €10M or 2% of worldwide turnover (whichever is higher) for essential entities, up to €7M or 1.4% for important entities. In case of serious and persistent breach, possible suspension of the director from their duties.
What to do, in what order
First: qualification. Are you directly concerned, indirectly, or not at all? This step generally takes a 45-minute interview with sector analysis. We carry it out as part of the entry audit.
Then, if concerned: a pragmatic compliance plan, prioritised on high-impact, controlled-cost measures (security policy, incident management, director training). A realistic plan spans 6 to 12 months — NIS2 compliance is not a flash project.
If not directly concerned but in the supply chain: anticipate upcoming contractual requirements, ahead of their imposition. It's as much a commercial argument as a constraint.