Home / Knowledge center / Does your organisation fall under the NIS2 legislation?
19 August 2026
5 min read
Certification

Does your organisation fall under the NIS2 legislation

The Belgian NIS2 law has been in force since October 2024. The first deadline for essential entities has already passed, but many organisations still don't know for certain whether it applies to them, or what that means for their suppliers.

In short

  • The Belgian NIS2 law has been in force since 18 October 2024, supervised by the Centre for Cybersecurity Belgium (CCB).
  • The law distinguishes between essential entities (proactive supervision) and important entities (reactive supervision).
  • Waste management, including the processing of waste electrical and electronic equipment, is one of the sectors explicitly named in the directive, typically as an important entity.
  • The CCB offers a free tool to check yourself whether your organisation falls within scope.
  • Even organisations that are not directly in scope can be required by in-scope clients to meet additional security requirements.

What is the NIS2 legislation

NIS2 is the European cybersecurity directive that was transposed into Belgian law on 18 October 2024, supervised by the Centre for Cybersecurity Belgium. Organisations in scope had to register by 18 March 2025. Essential entities had to submit their first conformity assessment by 18 April 2026, a deadline that has now passed. By April 2027, they must reach the full mandatory security level.

 

Essential versus important entities

The law distinguishes between essential and important entities.

  • Essential entities are subject to proactive supervision, with mandatory checks in advance.
  • Important entities are subject to reactive supervision: no mandatory prior audit, but the obligation to demonstrate conformity whenever the CCB asks for it.

Which of the two applies depends on both the sector and the size of the organisation.

Does waste management fall under NIS2

What is often not known: waste management is one of the sectors explicitly named in the directive. This means that processors of waste electrical and electronic equipment can fall within scope, depending on their size, typically as an important entity.

At Brainscape, this touches directly on our own activity. Our certifications are exactly the kind of proof an organisation needs to demonstrate that its chain is under control, in terms of quality and environment as well as data.

How to check this yourself

To determine whether your organisation falls under the NIS2 legislation, the CCB has developed an extensive tool. In short, it looks at four elements:

  • Size of the organisation: number of FTEs, annual turnover and balance sheet total.
  • Sector and service: a list of all sectors covered by the law, including waste management.
  • Connection to Belgium: where the organisation is established.
  • Member states where the service is provided.

Based on this, one of three outcomes follows, determined by the size of the organisation:

  1. Out of scope — under 50 FTE, and under €10 million turnover, and under €10 million balance sheet total.
  2. Important entity — from 50 FTE, or from €10 million turnover, or from €10 million balance sheet total.
  3. Essential entity — from 250 FTE, or from €50 million turnover, or from €43 million balance sheet total.

For some sectors, such as domain name registration providers or public administrations, this threshold does not apply: they are always essential or important, regardless of their size.

Want to download the full NIS2 Scope Assessment tool? You can do so via this link, directly as an Excel file, without any form or registration.

The supply chain matters too, even outside scope

NIS2 requires in-scope organisations to also manage and demonstrate the security of their supply chain. That obligation extends to suppliers that are not themselves directly subject to the law: whoever supplies an essential or important entity is often passed the same requirements through the contract. How a supplier handles data and the disposal of IT equipment is part of that.

 

What does this mean for IT managers?

Whoever decides on the disposal of company hardware is also deciding on a part of that supply chain. A certified and traceable process for data erasure and equipment disposal provides exactly the proof needed for a supplier audit or a client request under NIS2.

At Brainscape, every device that comes in is linked to a verifiable process: from data erasure reporting to certification under ISO 9001, ISO 14001 and WEEELabex. You can read more about how these certifications come about and what they mean for your organisation in our article on ISO 9001 and ISO 14001 for your ITAD partner.

Questions about your own situation

Feel free to contact us. We're happy to look together at whether your organisation falls under this legislation, and how our certifications and processes can contribute to your own NIS2 file.

Frequently asked questions

Do you have questions about the current NIS2 legislation? We're happy to answer them.

What is the difference between an essential and an important entity under NIS2?

Essential entities are subject to proactive supervision by the CCB, with mandatory checks in advance. Important entities are subject to reactive supervision: they only need to demonstrate conformity when the CCB asks for it. Which status applies depends on the sector and the size of the organisation.

Does waste management fall under the NIS2 legislation?

Yes. Waste management is explicitly named as a sector in the directive. Processors of waste electrical and electronic equipment can, depending on their size, fall within scope, typically as an important entity.

How do I know if my organisation falls under NIS2?

The CCB offers a free Excel tool, the NIS2 Scope Assessment, which indicates — based on your sector, company size and connection to Belgium — whether you are out of scope, or considered an important or essential entity.

What if my organisation doesn't fall directly under NIS2?

Even then, you're not automatically off the hook. NIS2 requires in-scope organisations to manage the security of their supply chain. If you supply an organisation that does fall under NIS2, it can still impose additional security requirements on you through the contract.

What does data erasure have to do with NIS2?

How a supplier handles data on decommissioned IT equipment is part of the supply chain that NIS2 organisations must manage. A certified and traceable data erasure process, such as Brainscape's, provides the proof needed for that.

How does Brainscape help organisations with their NIS2 file?

Brainscape processes IT equipment through a certified process (ISO 9001, ISO 14001, WEEELabex), with traceable reporting on data erasure per device. Organisations that need to demonstrate how their supply chain is secured use that documentation as proof in their NIS2 file.

Back to blog overview