In brief
- The real shift is not in the technology but in the liability: after a serious incident, the law looks to management, personally.
- Start with two questions, not with tools: do you fall under NIS2 (from 50 employees or 10 million euro in turnover), and are you registered with the CCB?
- MFA is named in Article 21 and is the fastest win; the 24-hour reporting duty is mainly an organisational question that you write out in advance.
- Standard technology does the heavy lifting: EU cloud, SSO with MFA, a WAF, a full audit trail and tested back-ups together cover the largest part of the requirements.
NIS2 mainly shifts the question of who answers for an incident. The directive has been in force since 18 October 2024, and after a serious disruption the law no longer looks only to the IT team. It looks to management, personally. That is the reason to put this on this month's agenda, not next quarter's.
In Belgium the directive has been transposed in the act of 26 April 2024, which entered into force on 18 October 2024. Across Europe the text affects roughly 160,000 entities in eighteen sectors. What follows is not legal advice. It is a practical map of what you need to work out yourself, plus the decisions you are better off making together with the CCB.
Do you fall under it?
The lower bound is that of the medium-sized enterprise: from 50 employees or more than 10 million euro in turnover. If you are above that and active in a designated sector, assume the obligations apply. The act also splits those entities into essential and important, with heavier supervision of the first group. If you are in doubt about which one you belong to, settle that with the CCB and your legal counsel. A blog post does not decide that for you.
- Your size: do you reach the threshold of 50 employees or 10 million euro in turnover?
- Your sector: does your activity fall under one of the eighteen sectors the directive designates?
- Your category: essential or important, because that determines how heavily supervision and sanctions weigh.
What Article 21 asks of you
Article 21 imposes risk-management measures. Multi-factor authentication is named in it, and it is also the measure with the best ratio between effort and effect. If you still work with standalone passwords today, that is where you start. The rest of the article covers risks systematically, from access management to recovery after an incident. Objectives, then, not prescribed products.
24 hours, not a week
You report a significant incident within 24 hours. That is tight, and it is an organisational requirement rather than a technical one. You know in advance who decides that something is reportable, who submits the report, and which data has to be ready at that moment.
You only meet those 24 hours if the file is already prepared. An audit trail that records every action, logging you can search quickly, a fixed escalation path: that is the difference between a report on time and a reconstruction after the fact. Put the playbook on paper before you need it at three in the morning. At that moment you do not want any more discussion about who does what.
Management is liable
Under NIS2, management is personally liable for overseeing these measures. That is not an item on the IT budget, it is a boardroom question. For essential entities the fines run up to 10 million euro or 2% of worldwide annual turnover, whichever of the two amounts is higher. That shifts the incentive from reputation and downtime to something that sits at the top and cannot be delegated.
From requirement to working technology
You make the translation from objective to concrete control yourself, and it need not be exotic. The building blocks below are standard and together cover the largest part of what Article 21 asks.
- SSO with MFA: one identity, strong authentication, exactly what Article 21 asks for by name.
- EU cloud: your data stays within the European Union, which keeps the question of data residency simple.
- A WAF plus a full audit trail: known attacks are blocked and every action remains traceable afterwards, exactly what you need for a report within 24 hours.
- Daily back-ups with a yearly DR test: a back-up you never restore is an assumption, not a recovery plan.
- Offline mode for counter and POS: if the connection drops, the desk keeps working.
Data residency deserves its own consideration. NIS2 does not require storage in the EU in so many words, but your position becomes stronger as soon as you can show where the data sits and who can access it. An EU cloud with a clear processing register removes a discussion you would otherwise have again at every audit.
So do not start with the technology but with two questions: do you fall under it, and are you registered? Once that is settled, the rest becomes a matter of switching on measures you probably needed anyway. The CCB publishes the official frameworks and reporting channels, use those as your source of truth. Let this piece open the conversation internally, this week.
Sources
Want to apply this to your own situation?
Belgian, founder-led and built to hand over. One email is enough.
More reading
