+31 (0)73 220 2000 | info@brandcompliance.com
English EN
  • Dutch NL
  • English EN
  • French FR
  • Dutch NL
  • English EN
  • French FR
Brand Compliance
  • Certify
    • ISO 9001
    • ISO 22301 (BCM)
    • ISO 19770-1 (IT-assets)
    • ISO 27001
    • ISO 27017 and ISO 27018
    • BIO
    • ISO 27701 (Privacy)
    • NEN 7510
  • IT Assurance
    • SOC 2
  • Vacancies
  • Knowledge base
  • BC Academy
Discuss your situation
  • Information security
    • ISO 27001
    • NEN 7510
    • CyFun
      • CyFun verification
      • Request CyFun verification
    • ISO 27799
    • ISO 27017 and ISO 27018
    • BIO2
    • ISO 19770-1
  • Privacy
    • BC 5701
    • ISO 27701
    • GDPR standard BC 5701:2024 EN
  • IT assurance
    • SOC 2
    • ISAE 3402
    • ISAE 3000
  • Quality & continuity
    • ISO 9001
    • ISO 14001
    • ISO 22301
    • Gap analysis
  • Knowledge & news
    • Knowledge articles
    • News
  • Academy
    • All training courses
    • NIS2 & CyFun
    • ISO 27001
  • About us
    • Accreditations
    • Careers
    • Compliment, complaint or tip
    • Locations
    • Privacy Statement
    • Contact

Preparing for certification

6
  • Certification checklist: how to prepare for certification
  • Do you have your first certification audit soon?
  • The certification process step by step
  • How long does ISO certification take?
  • How to conduct an internal audit
  • Describing the scope of certification: tips and examples

Audit process & certification cycle

7
  • Initial audit Stage 1
  • Initial audit Stage 2
  • What is a certification cycle?
  • Nonconformities within the management system
  • What should you know about certificate suspension or revocation?
  • Transfer of certification
  • The use of certification logos

Management systems & key concepts

6
  • Whitepaper management system audits
  • Quality Management: best practices for success
  • Certification glossary
  • What is a management system?
  • Internal or external audit?
  • Accreditation versus certification

Information security

3
  • Excelling in information security: best practices
  • Operational Capabilities: The Backbone of Information Security
  • The Traffic Light Protocol (TLP): what does it mean for you?

NEN 7510 & healthcare

4
  • Transition to NEN 7510-1:2024
  • NEN 7510 without healthcare institution?
  • How to expand with NEN 7510
  • The differences between ISO 27001 and NEN 7510

NIS2 & CyberFundamentals

5
  • ISO 27001 in a NIS2 context in Belgium
  • CyberFundamentals 2025: transition from CyFun 2023 to 2025
  • Self-assessment & CyFun verification: best chance of success
  • NIS2 liability for board members
  • CyberFundamentals Framework in Belgium: what is the relationship with NIS2?

Privacy & data protection

8
  • ISO 27701:2025 transition
  • GDPR compliance best practices
  • Data breach: What is it and how do you prevent it?
  • Your Data Protection Officer and the GDPR
  • Your record of processing activities and the GDPR
  • Checklist for your BC 5701 certification
  • BC 5701 certification: where do you start?

Assurance audits

1
  • ISAE 3402 vs SOC 2: what is the difference?
View Categories

ISO 27001 in a NIS2 context in Belgium

ISO 27001 in a NIS2 context in BelgiumAre you familiar with the possibility of certification for ISO 27001 in a NIS2 context in Belgium?

This article consists of the latest information from the Centre for Cybersecurity Belgium, regarding the applicable conditions that ISO 27001 certification must meet in this context.

Scope #

The scope of the Information Security Management System should cover the entire organization. Limitation of the scope is only possible if IT and OT environments are demonstrably physically or technically separated and any exclusions:

  • are clearly documented;
  • do not affect the risks of the environment that falls within scope;
  • are explicitly defined.

Statement of Applicability (SoA) #

The Statement of Applicability must demonstrate that your organization implements cybersecurity measures that are demonstrably equivalent to the measures from the CyFun® assurance levels Basic, Important or Essential.

The applicable assurance level is determined on the basis of your organization’s risk analysis. The CyFun® Selection Tool is used for this purpose. The established level is leading for the assessment within the ISO 27001 certification process.

Next steps #

If you are interested, please take the steps below.

  1. Confirmation of scope
    Determine whether the scope of the certification meets the conditions, including the justification of any exclusions.
  2. Statement of Applicability (SoA)
    Assess the SoA against the applicable CyFun® measures and evaluate which CyFun® assurance level has been determined by the risk analysis, and whether the Statement of Applicability demonstrates that the measures implemented by your organization are demonstrably equivalent to the requirements of this level.
  3. Audit and assessment
    To confirm that your ISO 27001 certification aligns with the Belgian NIS2 context, we perform a special audit. During this audit, we verify that the necessary adjustments have been effectively implemented within your Information Security Management System. If not all employees, activities and locations fall within the current scope yet, this special audit can be directly combined with an extension of the scope of your certification.
  4. Outcome and confirmation
    After successful completion of the process, your ISO 27001 certification will be updated and demonstrably usable within the Belgian NIS2 context.

What does this mean for your organization? #

Would you like to know what this means in practice for your organization and how your ISO 27001 certification can be used within the Belgian NIS2 context? Plan an introductory meeting!

Share This Article :

  • Facebook
  • X
  • LinkedIn
Updated on 2 April 2026
CyberFundamentals Framework in Belgium: what is the relationship with NIS2?CyberFundamentals 2025: transition from CyFun 2023 to 2025
Contents
  • Scope
  • Statement of Applicability (SoA)
  • Next steps
  • What does this mean for your organization?

Accreditation

RvA C548Brand Compliance B.V. has accreditation (C548) to certify ISO 27001, ISO 27701 NEN 7510 and ISO 9001 technical area 33 information technology and 35 other services.

View our accreditations

Contact

Have a question about certification, verification or assurance?

info@brandcompliance.com
+31 (0)73 220 2000

Prefer local contact details?
View our locations

Our locations

‘s-Hertogenbosch, The Netherlands

Antwerp, Belgium

Ottignies-Louvain-la-Neuve, Belgium

Stockholm, Sweden

Dublin, Ireland

Luxembourg, coming soon

Practical information

Privacy statement

Terms and conditions

Company details

Feedback and complaints

 

© Copyright 2026 Brand Compliance