Today is the deadline for EU Member States to transpose the NIS2 Directive into national law, with national measures applying from tomorrow.
Progress is uneven: a number of Member States have not yet completed transposition. Belgium is among the early adopters, with its NIS2 law applying from 18 October 2024. Belgian essential and important entities can use the CCB’s CyberFundamentals (CyFun) framework or ISO/IEC 27001 certification to demonstrate compliance.
Key NIS2 obligations
- Article 21 risk-management measures: risk analysis, incident handling, business continuity, supply chain security, secure development, vulnerability handling, cryptography, MFA and training.
- Incident reporting: early warning within 24 hours, notification within 72 hours and a final report within one month.
- Management bodies are accountable and must undertake training.
- Registration with national authorities.
Organisations with EU operations or EU-regulated clients should check registration requirements in each relevant Member State.
Source: Directive (EU) 2022/2555, NIS2 (EUR-Lex)
This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.