Law / Belgium

Loi du 26 avril 2024, Cybersecurity Risk-Management Measures and Governance

Loi du 26 avril 2024 établissant un cadre pour la cybersécurité des réseaux et des systèmes d'information d'intérêt général pour la… sécurité publique, Artt. 30-33

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 18 October 2024.

A sector security regimes rule binding public and private bodies.

As of 14 September 2026.

What it requires

  • This binds an essential entity or an important entity drawn from Annex I or Annex II; Annex II's digital-provider entry names an online marketplace, an online search engine and a social-networking-services platform, and Annex I's digital-infrastructure entry separately names a DNS service provider, a top-level-domain name registry, a cloud-computing-service provider, a data-centre-service provider, a content-delivery-network provider, a managed service provider and a managed security service provider, so a service in any of those lines is reached at the medium-enterprise size threshold or above; the wider sector classes (energy, transport, banking, health, drinking water, public administration and the rest of the Annexes) are a designation and sector class no activity in this vocabulary expresses, and are not raised here on that account.
  • Take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems you use in the course of your activities or to provide your services.
  • Cover at minimum: policies on risk analysis and information-system security; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including the direct suppliers and service providers you rely on; security in the acquisition, development and maintenance of your network and information systems, including vulnerability handling and disclosure; policies to assess the effectiveness of your risk-management measures; basic cyber-hygiene practices and cybersecurity training; policies on the use of cryptography and, where applicable, encryption; personnel security, access-control policies and asset management; multi-factor or continuous authentication and secure voice, video, text and emergency communications where needed; and your own coordinated vulnerability-disclosure policy.
  • Have your management body approve these risk-management measures, supervise their implementation, and answer for a violation of this duty; you remain responsible for your own risk analysis and for the choice and implementation of the measures.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Title 4, Chapter 2 of the NIS2 law ("Les mesures et amendes administratives") is the Act's own sanction for a violation of Article 30: an administrative fine under Article 59, doubled on recidivism for the same facts within three years. No provision reviewed here makes an Article 30 violation itself a criminal offence.

Penalty structure

Article 59, 5 sets the ceiling for an essential entity that does not comply with the Article 30 risk-management or Article 34-38 notification obligations at EUR 10,000,000 or 2 percent of the undertaking's total worldwide annual turnover for the preceding financial year, whichever is higher; Article 59, 4 sets the ceiling for an important entity at EUR 7,000,000 or 1.4 percent of that turnover, whichever is higher; both fines start at a floor of EUR 500 and are doubled on recidivism for the same facts within three years (Article 59, final paragraph).

Rule
Higher of
As of
14 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

The national cybersecurity authority, the Centre for Cybersecurity Belgium (CCB), or the competent sectoral authority for the entity's sector; the Belgian Institute for Postal Services and Telecommunications (BIPT) holds a parallel instruction and supervisory power specifically over a digital-infrastructure provider.

Settledness

As of
14 September 2026
Guidance link
https://atwork.safeonweb.be/nis2
Guidance body
Centre for Cybersecurity Belgium (CCB), Safeonweb at Work
Open questions
Does the reference-framework Royal Decree of 9 June 2024 (conformity-evaluation frameworks such as CyberFundamentals) or a sector-specific Royal Decree under Article 33 create a duty going beyond what Article 30 itself already states for a given sector or subsector?

What it reaches

Obligation class

Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 30 requires an essential entity or an important entity to take appropriate and proportionate technical, operational and organisational measures to manage the risks threatening the security of the network and information systems it uses for its activities or to provide its services, on an all-hazards approach covering at minimum eleven points: risk-analysis and information-system-security policy, incident handling, business continuity (backup management, disaster recovery and crisis management), supply-chain security, security in the acquisition, development and maintenance of network and information systems including vulnerability handling and disclosure, policies to assess the effectiveness of the risk-management measures, basic cyber-hygiene practices and training, cryptography and encryption policy, human-resources security and access-control and asset management, multi-factor or continuous authentication and secure voice, video, text and emergency communications, and the entity's own coordinated vulnerability-disclosure policy.

Article 31 requires the management body of an essential or important entity to approve the cybersecurity risk-management measures it takes to comply with Article 30, supervise their implementation, and answer for that entity's violation of Article 30, without prejudice to the liability rules that otherwise apply to a public institution. Article 32 makes the entity itself responsible for the risk analysis it performs and for the choice and implementation of the Article 30 measures.

Article 33 lets the King, after consulting the national cybersecurity authority, any sectoral authority concerned and the federated entities concerned, impose additional appropriate and proportionate sector- or subsector-specific risk-management measures by decree deliberated in the Council of Ministers. This Act's own Article 97 repeals the predecessor Loi du 7 avril 2019, the original NIS Directive transposition, effective the same date.

When LexLint raises it

  • operates_social_platform

Read the law

Consolidated text, ejustice.just.fgov.be Justel database (mirrored via Internet Archive), Loi du 26 avril 2024, updated to 19 January 2026

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://www.ejustice.just.fgov.be/eli/loi/2024/04/26/2024202344/justel

Back to the example  ·  Lint your app