WIRE 07.10.2026Belgium's NIS2 conformity assessment for essential entities falls due 18 April 2027
All wire
Hosaka Seven

Tech, policy and power. For the people who have to sign off on it.

Policy

Belgium's April 2027 deadline did not move.

The remediation plan it introduces runs to April 2028, and that is the part being read as an extension. The sentence that could actually move an entity's obligation is a different one, and it is about their own risk analysis.

A thick bound law on a dark desk, with 18 APR 2027 printed down its spine. A single letter rests on top of it, stamped in red across its lower margin: PLAN TO APR 2028. The stamp touches only the letter.

Belgium's NIS2 law has been in force since 18 October 2024. Nothing about what it obliges an essential entity to do changed this summer. What changed is what the inspectorate has said it will do about entities that cannot show they have done it, and the distinction is doing more work than most of the reading of it allows.

On 18 August the CCB's Inspection Service issued a general communication to Belgian NIS2 essential entities about their mandatory conformity assessment for 18 April 2027. Entities that cannot demonstrate by that date that they have implemented measures equivalent to the CyberFundamentals assurance level "Essential" will be asked to submit a remediation plan. The plan has two required parts: evidence of compliance equivalent to the lower level, "Important", and a description of the measures planned to reach "Essential" by 18 April 2028.

A year, in other words, for entities that arrive at 2027 short. That is how it is being read.

The checkpoint that already happened

It is worth being clear about where in the sequence this lands, because the first deadline went past six months ago and attracted almost no attention.

On 18 April 2026 essential entities had to be in a position to demonstrate that they were following a recognised compliance pathway, and to submit evidence to the inspection service. What that meant depended on the route. Entities on CyberFundamentals had to have obtained, or be actively in the process of obtaining, at least a Basic or Important verification — or hold a signed agreement with an accredited assessment body. Entities on ISO/IEC 27001 had to submit their certification scope, their Statement of Applicability and their most recent internal audit report. Entities choosing direct inspection had to provide a self-assessment and formally request one, which the CCB noted "may lead directly to supervisory measures".

The CCB's own description of that date is worth quoting, because it is not the language of a milestone:

The 18 April 2026 deadline constitutes a binding regulatory obligation, not a procedural formality.

An entity that did nothing in April did not buy itself time until 2027. It missed something.

The lawIn force, unchanged throughout

In force from 18 October 2024

Ex-ante supervisionWhat the inspectorate asked for

Pathway evidence due 18 Apr 2026

Conformity assessmentCyFun, ISO 27001 or CCB inspection

Due 18 April 2027

Remediation planOnly for entities short at 2027

"Important" now, "Essential" by Apr 2028

18 April 2027

Oct 2024Apr 2026Apr 2027Apr 2028
Four dates. The first is the law; the rest are the inspectorate describing how it will supervise. At the April 2026 checkpoint an entity had to hold a verification, have one under way, or have signed with an accredited body.Centre for Cybersecurity Belgium, news pages of 16 April 2026 and 18 August 2026, both read in full. The positions are drawn to the sequence, not to scale.

What the communication says about itself

One sentence in the August page is doing more than the rest of it together:

The communication does not alter the legal obligations or deadlines established by the Belgian NIS2 Law and its Royal Decree.

This is not boilerplate, and it is not a lawyer's reflex. It is the supervisor stating that what it has issued is a description of how it intends to supervise, not an amendment to anything. The obligation on 18 April 2027 is whatever the law and the Royal Decree make it. What the letter adds is the inspectorate's account of what it will ask for from an entity that falls short — and an account of supervisory intention is not a deadline, cannot be relied on as one, and binds a successor at the CCB no more than any other published practice.

An entity treating April 2028 as its date is relying on a document that says it has not moved the date.

The sentence that would actually move something

The last paragraph of the communication contains the exemption, and it has two limbs. No remediation plan is required from entities that can demonstrate compliance equivalent to "Essential" by 18 April 2027 — which is the obvious limb, and the one everybody will read.

The other limb is this: nor is one required from entities that can justify, on the basis of their risk analysis, cybersecurity measures equivalent to a lower CyFun assurance level.

That is not an extension. It is the supervisor saying that "Essential" is not automatically the right level for every essential entity, and that an entity whose own risk analysis supports a lower one may stay there and owe no plan at all. Which level a given entity owes is a question about its risk analysis, and the first place to look is therefore not the 2027 calendar but the document the entity already wrote.

I have not seen the letter itself. Both CCB pages link a PDF and both say it went directly to essential entities; the link refused this desk, so everything above is attributed to the CCB's public summary of its own communication rather than to the communication. An entity that received it is holding a longer document, and the conditions attached to that final paragraph are the part most likely to be longer in it.

What has not been established

How far apart "Important" and "Essential" sit in practice. The communication points entities at a named column in the CyberFundamentals correspondence table, published as a spreadsheet, and the honest position is that this desk has not opened it. Everything about whether a remediation plan is a year of real work or a year of paperwork turns on that mapping, and nothing here should be read as an answer to it.

The next date is 18 April 2027, and it has not moved. What the August letter tells an entity arriving short is what the inspection service will ask for. What it tells an entity that has not reread its own risk analysis is that it may be preparing for the wrong level.

Primary The document itself. Claims in this piece rest only on these.

  1. New communication for NIS2 essential entities, published 18 August 2026, updated 20 August 2026Centre for Cybersecurity Belgium, newsRead in full for this piece, in English, on the CCB's own site. Source for: the conformity assessment date of 18 April 2027; the remediation plan and its two required contents, quoted here as the page words them; the date of 18 April 2028 for reaching measures equivalent to CyFun assurance level 'Essential'; the statement that the approach applies across all three conformity-assessment routes, and the naming of those routes; the sentence that the communication 'does not alter the legal obligations or deadlines established by the Belgian NIS2 Law and its Royal Decree'; and the final paragraph exempting entities that can demonstrate equivalence to 'Essential' by 18 April 2027 or 'can justify, on the basis of their risk analysis, cybersecurity measures equivalent to a lower CyFun assurance level'.
  2. NIS2: 18 April 2026 deadline — What essential entities must have in place, published 16 April 2026Centre for Cybersecurity Belgium, newsRead in full for this piece. Source for the three compliance pathways as they stood at the April 2026 checkpoint and what each required by that date; for the statement that the deadline 'constitutes a binding regulatory obligation, not a procedural formality' and that failure may result in administrative measures or financial penalties; and for the page's own statement that the requirements derive from the Belgian NIS2 law, which it dates to entry into force on 18 October 2024.
  3. Official communication of the CCB Inspection Service to NIS2 essential entities, referenced from both pages aboveCentre for Cybersecurity BelgiumNot read. Both news pages link a PDF of the letter and both say it was sent directly to essential entities; the link refused every attempt from this desk. Everything attributed here to the communication is attributed to the CCB's own public summary of it, not to the letter, and the letter may well set out conditions the summary does not. An entity that received it is reading a document this piece has not seen, which is the right way round and worth saying plainly.
  4. Law of 26 April 2024 establishing a framework for the cybersecurity of networks and information systems of general interest for public security, and the Royal Decree of 9 June 2024Moniteur belge / Belgisch StaatsbladNot opened for this piece. The date of entry into force, 18 October 2024, is the CCB's own statement on its own pages and not a reading of the law. No article of the Belgian law or the Royal Decree is cited anywhere in this piece, deliberately: the argument is about what the supervisor has said it will do, which is a different question from what the statute requires, and conflating the two is the error the piece is about.
  5. CyberFundamentals correspondence table mapping assurance levels to the Belgian NIS2 lawCentre for Cybersecurity Belgium, cyfun.euNot opened. The August communication points entities at the column 'Relation to BE NIS2 law IMPORTANT' in this table, which is published as a spreadsheet. What the mapping actually says — and therefore how much work sits between 'Important' and 'Essential' — is the practical question behind every date in this piece, and this desk has not answered it. An editor should treat any impression the body gives about that distance as unsupported, which is why the body does not give one.

Marine Lefebvre

Policy correspondent

I cover EU tech regulation and the people who write it, from the AI Act to the next fight over data sovereignty. I have a soft spot for any Brussels leak that lands before the official press release.