Who needs to consider these requirements?
Rail is a transport subsector under NIS2. Infrastructure managers and railway undertakings should assess the Belgian law's activity, size and special-case provisions to establish whether they are essential or important entities. A supplier's contractual obligations may support its customer's compliance without making that supplier a regulated rail entity. Keep operating-company scope distinct from the wider group's IT certification boundary.
Key regulations and frameworks
Belgian NIS2 law of 26 April 2024
Law — in force from 18 October 2024
The Belgian regime combines registration, cyber-risk management and supervision for covered entities. The CCB explains that outsourcing IT does not transfer an organisation's legal responsibility. Rail teams should therefore document the services and dependencies included in their security programme, including third-party maintenance and operational technology that supports essential transport services.
CCB significant-incident notification
Reporting duty — early warning, notification and follow-up
Report without undue delay: the maximum times are 24 hours for an early warning and 72 hours for the incident notification, measured from awareness of a significant incident. A final report is normally due within one month of the incident notification. For an ongoing incident, the CCB provides for a progress report followed by a final report after handling. Build escalation around significance and service impact, not just individual device alerts.
CyberFundamentals and conformity assessment
CCB assurance guidance — route and scope matter
The CCB's April 2026 guidance required essential entities to demonstrate implementation and progress through a recognised assessment route. It distinguishes CyberFundamentals, ISO/IEC 27001 and direct inspection, with different supporting evidence. Confirm the current timetable and any entity-specific supervisory instructions with the CCB. An existing office-IT certificate should not be assumed to cover operational rail systems or every NIS2 obligation.
Official source: CyberFundamentals and conformity assessment
Law of 19 December 2025 on critical-entity resilience
CER transposition — distinct from NIS2
Belgium's National Crisis Centre identifies the law of 19 December 2025 as the national transposition of CER. Assess critical-entity designation and the resulting resilience duties separately from the NIS2 classification. For rail planning, coordinate physical and cyber disruption scenarios without assuming that the two frameworks have identical scope, notification triggers or reporting authorities.
Official source: Law of 19 December 2025 on critical-entity resilience
Practical steps for rail teams
Use these engineering and project-planning actions to prepare evidence for the requirements that apply to your organisation.
- Document essential or important entity classification and confirm registration details, reporting access and responsible deputies. Keep a separate record of any critical-entity designation.
- Define the assurance boundary around the rail service. Include relevant train-to-ground communications, depot networks, remote maintenance and outsourced services in the risk assessment.
- Exercise the 24-hour and 72-hour reporting stages with engineering, operations, security and suppliers. Collect timestamps, affected services and recovery actions without waiting for a complete root-cause analysis.
- Map evidence to the chosen assessment route. Record exceptions for legacy rail equipment, the compensating controls used and who will review them as fleets and support contracts change.
Using this guide
This is an introduction to selected frameworks, not a complete legal assessment. Applicability depends on your organisation, systems and contracts. Check the linked official texts and obtain advice for your project before relying on a requirement or deadline.
