The 18 April 2026 deadline has passed. Belgian essential entities now have to evidence compliance, and the security talent pool has not grown.

Belgium transposed NIS2 with the Act of 26 April 2024, in force since 18 October 2024, and was the first member state to fully implement the directive. Essential entities had until 18 April 2026 to be verified under CyberFundamentals or engaged in an ISO 27001 certification path; important entities face no equivalent formality on that date. The constraint is no longer regulatory, it is people: Agoria counts around 4,000 unfilled cybersecurity vacancies with a vacancy rate of 12.4 percent, against 5.3 percent in IT overall.
Be on a verified compliance path. That meant having obtained, or being actively in the process of obtaining, at least a CyberFundamentals Basic or Important verification, or holding a signed agreement with an accredited conformity assessment body. Entities going the ISO/IEC 27001 route had to send the CCB the intended certification scope, the Statement of Applicability and the most recent internal audit by that date.
No. The security risk-management obligations apply to both, but by the 18 April 2026 deadline an important entity was not required to complete any specific administrative formality with the CCB. Supervision of important entities is also reactive rather than proactive.
18 October 2024. The framework comes from the Act of 26 April 2024 and the Royal Decree of 9 June 2024, and Belgium was the first EU member state to fully implement the NIS2 directive.
Agoria's February 2025 analysis counted around 4,000 unfillable cybersecurity vacancies, with a vacancy rate of 12.4 percent against 5.3 percent across IT and 3.9 percent economy-wide. The sector employed 9,750 full-time staff across 732 organisations in 2024.
Mostly governance and operations rather than offensive security: GRC analysts who translate the law into controls, security architects, SOC and incident response engineers who handle detection and the reporting deadlines, and a CISO or fractional equivalent for organisations that never had one. Penetration testing demand is comparatively unaffected.
Retraining is slower to start and faster to finish. An infrastructure or network engineer moved into security with a certification path already understands your estate, whereas an external hire in a market with a 12.4 percent vacancy rate takes longer to find than an equivalent IT role. Most organisations combine both, using consultants or an interim security lead to cover the assessment phase.
By subscribing to our newsletter, you agree to receive communications in accordance with our privacy policy.