www.belgium.be Logo of the federal government
eu be flags

Is my organisation in scope of the NIS2 Law ?

News

On April 2024, the federal Parliament adopted the law establishing a framework for the cybersecurity of networks and information systems of general interest for public security (the "NIS2 law"). It transposes EU directive 2022/2555of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union(the "NIS2 directive") into Belgian law and shall enter into force on October 18th this year.

The visual accompanying this news article is a simplified version of the two criteria that shall in principle be applied to understand if an organisation falls into the scope of the NIS2 law (there are some exceptions, more information about the exceptions).

To be covered by the NIS2 law, an organisation shall, in principle:

  1. Provide in the European Union a service listed in Annexes I and II to the NIS2 Act; and
  2. exceed the size thresholds set out in European Commission Recommendation 2003/361/EC, i.e. have at least 50 full-time employees (FTEs) or an annual turnover and/or annual balance sheet total exceeding €10 million (see European Commission guide).
For more info on what exactly NIS2 entails, whether it applies to your company/organisation and what your obligations are under this new legal framework, please visit the following link.
 
 
This article is part of a series on the transposition of the NIS2 directive in Belgium. See also the other articles.
in scope