Loi du 26 avril 2024, Significant-Incident Notification Obligations
Loi du 26 avril 2024 établissant un cadre pour la cybersécurité des réseaux et des systèmes d'information d'intérêt général pour la… sécurité publique, Artt. 34-37
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 18 October 2024.
A vulnerability and incident reporting rule binding public and private bodies.
As of 14 September 2026.
What it requires
- This binds the same essential and important entities as this jurisdiction's companion risk-management row, on the same Annex I and Annex II scope.
- Notify the national CSIRT of any significant incident without undue delay, following the arrangements set out in the protocol between the CSIRT and the National Crisis Centre.
- Submit an early warning within 24 hours of becoming aware of the significant incident, stating whether it is suspected to result from unlawful or malicious action and whether it may have a cross-border impact.
- Follow with an incident notification within 72 hours, updating the early warning with an initial assessment of the incident's severity and impact and any available indicators of compromise.
- Submit an interim report if the national CSIRT or the competent sectoral authority asks for one, and a final report no later than one month after the incident notification, describing the incident in detail, its severity and impact, the likely threat or root cause, the mitigation measures applied and in progress, and any cross-border impact.
- Where public awareness is necessary to prevent or manage the significant incident, or where disclosure is otherwise in the public interest, the national CSIRT may itself inform the public of the incident or require you to do so.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Title 4, Chapter 2 of the NIS2 law is the Act's own sanction for an Article 34-38 violation: an administrative fine under Article 59, doubled on recidivism for the same facts within three years. No provision reviewed here makes a reporting failure itself a criminal offence.
Penalty structure
Article 59, 5 sets the ceiling for an essential entity that does not comply with the Article 30 risk-management or Article 34-38 notification obligations at EUR 10,000,000 or 2 percent of the undertaking's total worldwide annual turnover for the preceding financial year, whichever is higher; Article 59, 4 sets the ceiling for an important entity at EUR 7,000,000 or 1.4 percent of that turnover, whichever is higher; both fines start at a floor of EUR 500 and are doubled on recidivism for the same facts within three years (Article 59, final paragraph).
- Rule
- Higher of
- As of
- 14 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
The national cybersecurity authority, the Centre for Cybersecurity Belgium (CCB), which also serves as the national CSIRT receiving the notifications, or the competent sectoral authority for the entity's sector.
Settledness
- As of
- 14 September 2026
- Guidance link
- https://atwork.safeonweb.be/nis2
- Guidance body
- Centre for Cybersecurity Belgium (CCB), Safeonweb at Work
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 34 requires an essential entity or an important entity to notify any significant incident to the national CSIRT without undue delay, following the arrangements set out in a protocol between the CSIRT and the National Crisis Centre (NCCN).
Article 35 sets the clock: an early warning within 24 hours of becoming aware of the significant incident, stating whether it is suspected to result from unlawful or malicious action and whether it may have a cross-border impact; an incident notification within 72 hours, updating the early warning with an initial assessment of the incident's severity and impact and any available indicators of compromise; an interim report if the national CSIRT or the competent sectoral authority asks for one; and a final report no later than one month after the incident notification, describing the incident, its severity and impact, the likely threat or root cause, the mitigation measures applied, and any cross-border impact.
A qualified trust service provider instead reports any significant incident affecting its trust services within 24 hours in a single stage. Article 36 requires the national CSIRT to respond to an early warning within 24 hours where possible, with initial feedback and, on request, operational guidance.
Article 37 lets the national CSIRT, after consulting the entity, the NCCN, any sectoral authority concerned and the responsible minister, inform the public of a significant incident or require the entity to do so, where public awareness is necessary to prevent or manage the incident or where disclosure is otherwise in the public interest. Article 54, paragraph 2 bars a further administrative fine for conduct already fined by the data protection authorities under General Data Protection Regulation (GDPR) Article 58(2)(i).
When LexLint raises it
operates_social_platform