What is the NIS2 directive?
NIS2 stands for Network and Information Security Directive 2 — the successor to the original NIS directive from 2016. The European Union issued this directive to strengthen the cyber security of organisations in critical and important sectors.
In Belgium, NIS2 has been transposed into national law through the act of 26 April 2024. This means Belgian organisations falling within its scope have concrete obligations around risk management, incident reporting and the security of their systems.
Who falls under NIS2?
NIS2 expands the scope considerably compared with NIS1. The directive distinguishes two categories:
- Essential entities: energy, transport, water, finance, healthcare, digital infrastructure
- Important entities: postal services, waste management, chemicals, food, manufacturing, digital providers
For SMEs the threshold is this: organisations with more than 50 employees or an annual turnover above €10 million in the sectors concerned may fall under NIS2. But smaller organisations in the supply chain of affected companies can pick up obligations indirectly as well.
"NIS2 is no longer somebody else's problem. Many Belgian SMEs are affected — even if they don't know it yet."
Which obligations follow from NIS2?
Affected organisations must, among other things:
- Carry out and document a risk analysis
- Take appropriate technical and organisational security measures
- Have an Incident Response Plan in place
- Report incidents with significant impact within 24 hours (initial notification) and 72 hours (detailed notification)
- Manage supply chain security
- Safeguard personnel security and access management
What are the penalties?
NIS2 provides for substantial fines. Essential entities risk up to €10 million or 2% of global annual turnover. Important entities risk up to €7 million or 1.4% of turnover.
But beyond the financial penalties, the reputational damage from an incident — and from being unable to demonstrate compliance — can be enormous.
Which first steps to take today?
Not sure whether your organisation falls under NIS2? Start with these steps:
1. Check whether your sector and size place you within NIS2
2. Run a baseline assessment: where does the organisation stand today?
3. Draw up a priority list of measures
4. Develop a basic information security policy
5. Consider external support through a CISO as a Service
NetGuard guides SMEs from baseline assessment to compliance. Get in touch for a no-obligation conversation.
Related articles
Why your biggest client is suddenly asking how secure you are
Since 18 April 2026, large Belgian companies must prove their cybersecurity is in order — and they are now passing that requirement down to their suppliers. Why SMEs not covered by NIS2 themselves are feeling it too, and what to do about it today.
The password on thousands of firewalls was simply “admin”
A flaw at firewall maker Fortinet gave hackers access to more than 270 Belgian businesses — often through a firewall whose default password was never changed. What happened, why SMEs are vulnerable, and which steps help starting today.
That voice on the phone might not be human
Scammers now use AI to mimic the voice of a business owner to push through an urgent payment. Here's how this new form of CEO fraud works, and five concrete steps to reduce the risk.