Law / Belgium

Loi du 26 avril 2024, Significant-Incident Notification Obligations

Loi du 26 avril 2024 établissant un cadre pour la cybersécurité des réseaux et des systèmes d'information d'intérêt général pour la… sécurité publique, Artt. 34-37

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 18 October 2024.

A vulnerability and incident reporting rule binding public and private bodies.

As of 14 September 2026.

What it requires

  • This binds the same essential and important entities as this jurisdiction's companion risk-management row, on the same Annex I and Annex II scope.
  • Notify the national CSIRT of any significant incident without undue delay, following the arrangements set out in the protocol between the CSIRT and the National Crisis Centre.
  • Submit an early warning within 24 hours of becoming aware of the significant incident, stating whether it is suspected to result from unlawful or malicious action and whether it may have a cross-border impact.
  • Follow with an incident notification within 72 hours, updating the early warning with an initial assessment of the incident's severity and impact and any available indicators of compromise.
  • Submit an interim report if the national CSIRT or the competent sectoral authority asks for one, and a final report no later than one month after the incident notification, describing the incident in detail, its severity and impact, the likely threat or root cause, the mitigation measures applied and in progress, and any cross-border impact.
  • Where public awareness is necessary to prevent or manage the significant incident, or where disclosure is otherwise in the public interest, the national CSIRT may itself inform the public of the incident or require you to do so.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Title 4, Chapter 2 of the NIS2 law is the Act's own sanction for an Article 34-38 violation: an administrative fine under Article 59, doubled on recidivism for the same facts within three years. No provision reviewed here makes a reporting failure itself a criminal offence.

Penalty structure

Article 59, 5 sets the ceiling for an essential entity that does not comply with the Article 30 risk-management or Article 34-38 notification obligations at EUR 10,000,000 or 2 percent of the undertaking's total worldwide annual turnover for the preceding financial year, whichever is higher; Article 59, 4 sets the ceiling for an important entity at EUR 7,000,000 or 1.4 percent of that turnover, whichever is higher; both fines start at a floor of EUR 500 and are doubled on recidivism for the same facts within three years (Article 59, final paragraph).

Rule
Higher of
As of
14 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

The national cybersecurity authority, the Centre for Cybersecurity Belgium (CCB), which also serves as the national CSIRT receiving the notifications, or the competent sectoral authority for the entity's sector.

Settledness

As of
14 September 2026
Guidance link
https://atwork.safeonweb.be/nis2
Guidance body
Centre for Cybersecurity Belgium (CCB), Safeonweb at Work

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 34 requires an essential entity or an important entity to notify any significant incident to the national CSIRT without undue delay, following the arrangements set out in a protocol between the CSIRT and the National Crisis Centre (NCCN).

Article 35 sets the clock: an early warning within 24 hours of becoming aware of the significant incident, stating whether it is suspected to result from unlawful or malicious action and whether it may have a cross-border impact; an incident notification within 72 hours, updating the early warning with an initial assessment of the incident's severity and impact and any available indicators of compromise; an interim report if the national CSIRT or the competent sectoral authority asks for one; and a final report no later than one month after the incident notification, describing the incident, its severity and impact, the likely threat or root cause, the mitigation measures applied, and any cross-border impact.

A qualified trust service provider instead reports any significant incident affecting its trust services within 24 hours in a single stage. Article 36 requires the national CSIRT to respond to an early warning within 24 hours where possible, with initial feedback and, on request, operational guidance.

Article 37 lets the national CSIRT, after consulting the entity, the NCCN, any sectoral authority concerned and the responsible minister, inform the public of a significant incident or require the entity to do so, where public awareness is necessary to prevent or manage the incident or where disclosure is otherwise in the public interest. Article 54, paragraph 2 bars a further administrative fine for conduct already fined by the data protection authorities under General Data Protection Regulation (GDPR) Article 58(2)(i).

When LexLint raises it

  • operates_social_platform

Read the law

Consolidated text, ejustice.just.fgov.be Justel database (mirrored via Internet Archive), Loi du 26 avril 2024, updated to 19 January 2026

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://www.ejustice.just.fgov.be/eli/loi/2024/04/26/2024202344/justel

Back to the example  ·  Lint your app