Chargement...
Chargement...
Three questions, a verdict in 30 seconds.
Question 1 of 3
The European NIS2 directive imposes cyber risk management measures and incident reporting obligations on many organisations, public and private. Whether it applies depends first on two criteria: the sector of activity and the size of the organisation.
The test combines these two criteria to indicate whether your organisation would be an essential entity, an important entity, or outside the direct scope of the directive. It remains indicative: size is also measured by turnover and balance sheet total, and some organisations are covered regardless of their size.
In Belgium, the directive is transposed by the law of 26 April 2024, in force since 18 October 2024. The Centre for Cybersecurity Belgium (CCB) supervises its application.
If your organisation is in scope, the next step is to measure the gap between your current practices and the requirements of the directive.
Understand NIS2 and its obligations→