Belgium completed its NIS2 transposition on time to take effect.
The Loi du 26 avril 2024 établissant un cadre pour la cybersécurité des réseaux et des systèmes d'information d'intérêt général pour la sécurité publique (the NIS2 law), published in the Moniteur belge on 17 May 2024 (Numéro 2024202344), entered into force on 18 October 2024 under its own Article 98, and its own Article 97 repeals the predecessor Loi du 7 avril 2019, the original NIS Directive transposition, so no earlier Belgian cybersecurity-framework act remains in force alongside it.
A Royal Decree of 9 June 2024 designates the Centre for Cybersecurity Belgium (CCB), created by the Royal Decree of 10 October 2014, as the national cybersecurity authority under Article 15 of the NIS2 law, and Article 16 gives it the combined roles of competent authority, national CSIRT and single point of contact.
The NIS2 law binds an essential entity and an important entity drawn from its Annex I and Annex II sector lists, which restate the NIS2 Annex I and Annex II sectors, to appropriate and proportionate risk-management measures over their network and information systems (Article 30, an eleven-point list covering risk analysis policy, incident handling, business continuity, supply-chain security, secure acquisition and development including vulnerability handling and disclosure, effectiveness-assessment policy, cyber hygiene and training, cryptography policy, personnel and access-management security, multi-factor or continuous authentication, and its own separate coordinated vulnerability-disclosure policy point, with the management body responsible for approving the measures and answering for a violation under Article 31) and to a graduated significant-incident notification clock to the national CSIRT: a 24-hour early warning, a 72-hour notification, an interim report on request, and a final report within one month (Articles 34 and 35).
Annex II's digital-provider entry names an online marketplace, an online search engine and a social-networking-services platform, and Annex I's digital-infrastructure entry separately names a DNS service provider, a top-level-domain name registry, a cloud-computing-service provider, a data-centre-service provider, a content-delivery-network provider, a managed service provider and a managed security service provider; the Belgian Institute for Postal Services and Telecommunications (BIPT, called "l'Institut" in the text) holds a parallel supervisory and instruction power over a digital-infrastructure provider specifically, inserted into the Loi du 13 juin 2005 relative aux communications électroniques by the NIS2 law's own Articles 84 to 94, while CCB remains the general competent authority for the rest.
No instrument reviewed here imposes a product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here.
Belgium has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation and the Loi du 30 juillet 2018's implementation of GDPR Articles 33 and 34's breach-notification duties to the Autorité de protection des données, both of which sit in the privacy topic rather than here.
Separately, the NIS2 law also inserted a conditional safe harbour into the Code penal's unauthorised-access offences (articles 550bis and 550ter) and into article 145 of the 2005 electronic-communications law, for a good-faith vulnerability finder who notifies the system's operator and the national CSIRT within 24 hours and follows with a complete notification within 72 hours; because that duty runs to the person who discovered the vulnerability by accessing another's system rather than to the entity operating it, it reads as a defence to an unauthorised-access offence, whose home is the scraping topic's computer-misuse family, so it is not filed as an instrument here.
The NIS2 law's own penalty provision is administrative rather than criminal: Title 4, Chapter 2 empowers the national cybersecurity authority or the competent sectoral authority to impose an administrative fine, doubled on recidivism within three years, and Article 54, paragraph 2 bars a further administrative fine for conduct already fined by the data protection authorities under GDPR Article 58(2)(i).