Country guide

Rail cyber security regulations in Belgium

Belgium's NIS2 law has applied since 18 October 2024. For rail organisations, preparation means more than documenting security controls: entity classification, registration, incident reporting and evidence for supervision need clear owners. CyberFundamentals provides an assurance route, while the separate CER framework addresses broader resilience.

Official sources checked

Who needs to consider these requirements?

Rail is a transport subsector under NIS2. Infrastructure managers and railway undertakings should assess the Belgian law's activity, size and special-case provisions to establish whether they are essential or important entities. A supplier's contractual obligations may support its customer's compliance without making that supplier a regulated rail entity. Keep operating-company scope distinct from the wider group's IT certification boundary.

Key regulations and frameworks

Belgian NIS2 law of 26 April 2024

Law — in force from 18 October 2024

The Belgian regime combines registration, cyber-risk management and supervision for covered entities. The CCB explains that outsourcing IT does not transfer an organisation's legal responsibility. Rail teams should therefore document the services and dependencies included in their security programme, including third-party maintenance and operational technology that supports essential transport services.

Official source: Belgian NIS2 law of 26 April 2024

CCB significant-incident notification

Reporting duty — early warning, notification and follow-up

Report without undue delay: the maximum times are 24 hours for an early warning and 72 hours for the incident notification, measured from awareness of a significant incident. A final report is normally due within one month of the incident notification. For an ongoing incident, the CCB provides for a progress report followed by a final report after handling. Build escalation around significance and service impact, not just individual device alerts.

Official source: CCB significant-incident notification

CyberFundamentals and conformity assessment

CCB assurance guidance — route and scope matter

The CCB's April 2026 guidance required essential entities to demonstrate implementation and progress through a recognised assessment route. It distinguishes CyberFundamentals, ISO/IEC 27001 and direct inspection, with different supporting evidence. Confirm the current timetable and any entity-specific supervisory instructions with the CCB. An existing office-IT certificate should not be assumed to cover operational rail systems or every NIS2 obligation.

Official source: CyberFundamentals and conformity assessment

Law of 19 December 2025 on critical-entity resilience

CER transposition — distinct from NIS2

Belgium's National Crisis Centre identifies the law of 19 December 2025 as the national transposition of CER. Assess critical-entity designation and the resulting resilience duties separately from the NIS2 classification. For rail planning, coordinate physical and cyber disruption scenarios without assuming that the two frameworks have identical scope, notification triggers or reporting authorities.

Official source: Law of 19 December 2025 on critical-entity resilience

Practical steps for rail teams

Use these engineering and project-planning actions to prepare evidence for the requirements that apply to your organisation.

  1. Document essential or important entity classification and confirm registration details, reporting access and responsible deputies. Keep a separate record of any critical-entity designation.
  2. Define the assurance boundary around the rail service. Include relevant train-to-ground communications, depot networks, remote maintenance and outsourced services in the risk assessment.
  3. Exercise the 24-hour and 72-hour reporting stages with engineering, operations, security and suppliers. Collect timestamps, affected services and recovery actions without waiting for a complete root-cause analysis.
  4. Map evidence to the chosen assessment route. Record exceptions for legacy rail equipment, the compensating controls used and who will review them as fleets and support contracts change.

Using this guide

This is an introduction to selected frameworks, not a complete legal assessment. Applicability depends on your organisation, systems and contracts. Check the linked official texts and obtain advice for your project before relying on a requirement or deadline.