Belgium’s Centre for Cybersecurity Belgium (CCB) issued a communication clarifying how NIS2 essential entities must demonstrate required cybersecurity measures under the national framework tied to the CyberFundamentals Framework (CyFun). The notice says that by 18 April 2027, organizations that cannot show implementation of controls equivalent to the CyFun assurance level Essential must submit a remediation plan, while entities already able to demonstrate that level—or able to justify a lower level through risk analysis—will not need to do so.
The remediation plan must show compliance equivalent to CyFun assurance level Important and explain how the organization will reach the Essential level by 18 April 2028. The CCB said the communication applies across all three conformity-assessment routes: CyFun certification by an authorized conformity assessment body, ISO/IEC 27001 certification by an authorized body, and conformity assessment by the CCB inspection service. Officials also stressed that the notice does not alter the legal obligations or deadlines established by Belgium’s NIS2 law and its Royal Decree.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
Belgium's Centre for Cybersecurity issued a communication explaining that NIS2 essential entities unable to demonstrate cybersecurity measures equivalent to CyberFundamentals assurance level "Essential" by 18 April 2027 will be required to submit a remediation plan. The notice says this approach applies across CyFun certification, ISO/IEC 27001 certification, and CCB inspection-service conformity assessments, and does not change existing legal obligations or deadlines under the Belgian NIS2 Law and Royal Decree.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.