NIS2 in Belgium: What Compliance Is Doing to Cybersecurity Hiring

The 18 April 2026 deadline has passed. Belgian essential entities now have to evidence compliance, and the security talent pool has not grown.

September 22, 2026
Purple Elipse - Sparagus
8 minutes read

30-second post summary

Belgium transposed NIS2 with the Act of 26 April 2024, in force since 18 October 2024, and was the first member state to fully implement the directive. Essential entities had until 18 April 2026 to be verified under CyberFundamentals or engaged in an ISO 27001 certification path; important entities face no equivalent formality on that date. The constraint is no longer regulatory, it is people: Agoria counts around 4,000 unfilled cybersecurity vacancies with a vacancy rate of 12.4 percent, against 5.3 percent in IT overall.

Belgian companies spent two years treating NIS2 as a documentation problem. It has turned into a hiring problem.

The Act of 26 April 2024 and the Royal Decree of 9 June 2024 entered into force on 18 October 2024, making Belgium the first member state to fully implement the NIS2 directive. The first hard verification deadline for essential entities fell on 18 April 2026, and it has now passed.

What comes next is not more policy writing. It is finding the people who implement and maintain the measures.

What the 18 April 2026 deadline actually required

It required evidence of a chosen compliance path, not finished perfection.

Essential entities had to have obtained, or be actively in the process of obtaining, at least a CyberFundamentals Basic or Important verification, or hold a signed agreement with an accredited conformity assessment body. Entities choosing the ISO/IEC 27001 route had to send the Centre for Cybersecurity Belgium the intended certification scope covering all their networks and information systems, the Statement of Applicability, and the most recent internal audit, by that same date.

The reward for completing a conformity assessment is a presumption of conformity, which is what makes the exercise worth doing rather than merely surviving.

Essential and important entities are not in the same position

This is where a lot of Belgian companies over-invested or under-invested.

By the 18 April 2026 deadline, an important entity was not required to complete any specific administrative formality with the CCB. The security risk-management obligations still apply to important entities, but the verification and the paperwork trail sit differently, and supervision of important entities is reactive rather than proactive.

If you are unsure which category you are in, that is the first thing to settle, because it changes the size of the programme by an order of magnitude.

Why a compliance deadline turns into headcount

Because the measures are operational, not declarative.

Risk management, incident detection and reporting, supply chain security, business continuity and access control are all things somebody has to run every day. A consultant can build the framework. Somebody has to operate it afterwards, and CyberFundamentals at Important level runs to 133 controls.

The pattern we see is consistent: a project phase staffed by consultants, followed six to nine months later by a permanent recruitment need that nobody budgeted for at the start.

The numbers behind the shortage

The Belgian cybersecurity sector is small, growing fast, and cannot hire.

According to Agoria's February 2025 analysis, the sector counted 732 organisations, 9,750 full-time jobs and 2.61 billion euros of turnover in 2024, with turnover expected to grow 15.9 percent a year through 2030. Against that, around 4,000 cybersecurity vacancies cannot be filled.

The figure that should worry a hiring manager is the vacancy rate: 12.4 percent in cybersecurity, against 5.3 percent across IT and 3.9 percent economy-wide (source: Agoria). Security is more than twice as hard to staff as the rest of IT, which is itself already a shortage market.

Which profiles Belgian companies are actually looking for

Not, mostly, the ones the job titles suggest.

The demand generated by NIS2 concentrates on a narrow band: GRC analysts who can translate the law into controls, security architects who can design what the controls require, SOC and incident response engineers who run detection and meet the reporting deadlines, and increasingly a CISO or a fractional equivalent for organisations that never had one.

Note what is missing from that list: penetration testers. The regulatory driver creates far more governance and operations demand than offensive security demand, which is the opposite of how most people picture the field.

If you are a candidate reading this, that gap is the opportunity. See our overview of cybersecurity engineer jobs in Belgium.

Buy, build or borrow

With a 12.4 percent vacancy rate, hiring your way out on a normal timeline is not realistic for most organisations.

Three routes work, and most companies end up combining them. Borrowing, through consultants or an interim security lead, covers the assessment phase and buys time. Building, by moving an infrastructure or network engineer into security with a certification path, is slower but it is the only route that scales, and internal candidates already understand your estate. Buying on the open market works, but budget realistically and expect the search to take longer than an equivalent IT role.

What does not work is treating the permanent hire as something to start after the audit. By then the queue is longer.

In short

Belgium implemented NIS2 first and moved fastest, which means Belgian companies hit the operational phase before most of their European peers.

The 18 April 2026 deadline required essential entities to be on a verified compliance path. Important entities had no equivalent formality, and confusing the two is expensive in both directions.

The binding constraint now is people, in a sub-market with a 12.4 percent vacancy rate. If you are staffing a security function against a regulatory clock, our consulting and search and selection teams cover the borrow and the buy side of that equation.

FREQUENTLY
ASKED QUESTIONS

Purple Elipse - Sparagus
FAQ
Purple Elipse - Sparagus
NEWSLETTER

Stay up-to-date

By subscribing to our newsletter, you agree to receive communications in accordance with our privacy policy.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.