Why Belgian SMEs Are Failing NIS2 Audits (And What to Fix)
NIS2 became enforceable in Belgium in October 2024. Several months on, the Centre for Cybersecurity Belgium (CCB) is already seeing a familiar pattern: organisations that assumed they were compliant are discovering they are not. Belgian SMEs in particular are struggling — not because they lack intention, but because they are tripping over the same three gaps, again and again.
Here is what those gaps look like in practice — and what you can do about each one.
Gap 1: No Asset Inventory
NIS2 requires organisations to know what they are protecting. Article 21 mandates risk management measures, which begin with knowing your attack surface. Yet most SMEs we speak to cannot answer a simple question: what systems are directly exposed to the internet?
Shadow IT makes this worse. A cloud SaaS subscription taken out by the marketing team, a forgotten VPN appliance on a legacy subnet, a development server that was "temporary" three years ago — these are exactly the entry points attackers exploit. Auditors flag missing or outdated asset inventories in the majority of NIS2 assessments.
What to fix: Build a living CMDB (configuration management database). It does not need to be expensive — a structured spreadsheet or a lightweight CMDB tool is enough to start. Include all hardware, software, cloud services, and third-party connections. Review it quarterly.
Gap 2: No Incident Response Plan
NIS2 requires organisations to report significant incidents to the CCB within 24 hours (initial notification) and 72 hours (detailed report). This is impossible if your first response to a breach is to call an IT contractor and ask what to do.
An incident response plan does not need to be a 50-page document. It needs to answer four questions clearly: Who do we call first? Who has authority to take systems offline? Who notifies the CCB and customers? What is our communication script for the press and partners?
The absence of a tested IRP is one of the most common NIS2 findings in Belgian audits. "We handle incidents as they come" is not a plan — it is a liability.
What to fix: Draft a one-page IRP covering roles, escalation paths, CCB notification contacts, and a basic communication template. Then tabletop-test it once with your leadership team. Update it annually or after any significant IT change.
Gap 3: No Supplier Risk Management
NIS2 explicitly extends cybersecurity obligations into your supply chain. If a managed service provider, cloud vendor, or software supplier has access to your systems and suffers a breach, you share the liability — and the reputational damage.
Most Belgian SMEs have no formal process for assessing supplier security posture. Contracts signed years ago contain no security clauses. There is no list of which suppliers have access to which systems, let alone any assessment of whether those suppliers meet minimum security standards.
The CCB has been explicit: supply chain risk management is a core NIS2 requirement, not an optional extra. Auditors are asking for evidence of supplier assessments.
What to fix: Map your critical suppliers. For each one, document what access they have and what security standards they claim to meet. Add a basic security annex to new contracts requiring incident notification within 24 hours. For existing contracts, request security attestations from your top 10 suppliers by access level.
The Common Thread
These three gaps share a root cause: NIS2 compliance is treated as a one-time project rather than an ongoing discipline. Organisations complete a gap assessment, close the most visible findings, and move on. Twelve months later, the asset inventory is out of date, the IRP has not been tested, and two new suppliers have been onboarded without security review.
Compliance is not a destination. It is a process.
Where to Start
If you are an IT manager or business owner at a Belgian SME and you are not sure where you stand, the answer is not to guess. A structured NIS2 gap assessment takes three to five days and gives you a clear, prioritised remediation roadmap — before an auditor, regulator, or incident does it for you.
Gforce Networks offers a free initial NIS2 readiness consultation. We work with Belgian SMEs of 10 to 250 employees across manufacturing, professional services, logistics, and healthcare. We will tell you exactly where your gaps are and what fixing them realistically costs — no obligation, no sales pressure.
Contact Gforce Networks to book your free NIS2 readiness consultation →