NIS2
NIS2 in Belgium: who does it apply to, and what does ‘demonstrable’ really mean?
NIS2 doesn't just ask you to take measures. It asks you to prove they work. That distinction changes what a GAP analysis actually delivers.
Robin Millecam · 13 September 2026 · 6 min read
NIS2 is often described as “the new cybersecurity directive”, as if it were just one more checklist alongside what an organisation already does. That undersells it. NIS2 shifts the question from “do we have measures in place?” to “can we prove they work?” And for most SMEs, that second question is the real challenge.
Who does it apply to?
NIS2 becomes relevant from a certain size or sector onward: essential and important entities in, among others, energy, transport, digital infrastructure, healthcare, and government. But demonstrability reaches further than that direct scope. Anyone who supplies an entity that does fall under NIS2 often gets the same question passed down through the contract, without being formally subject to NIS2 themselves.
What “demonstrable” actually means
NIS2 requires risk management measures under Article 21: access management, supplier management, business continuity, incident response, and more. It isn't enough for those measures to exist somewhere on paper. An auditor or supervisory authority wants to see two things: documentation (policy, procedures) and evidence of effective implementation (logs, training records, test results, incident logs). That's why a GAP analysis always scores both dimensions separately: an organisation can have perfectly documented policy and still score low on demonstrability, simply because no one can prove the policy is actually being followed.
Why this shapes the approach
That distinction is why a NIS2 track doesn't stop at a policy document. Findings from the GAP analysis are translated into a concrete action plan with ownership and a realistic timeline, followed by an incident notification procedure aligned with the NIS2 reporting deadlines, and preparation of the management body for its own responsibility. Demonstrability isn't an endpoint. It's something that keeps running after the project is done.
Not sure whether this applies to you?
Sector and size together determine whether NIS2 applies directly, and indirect contractual pressure (via a client or principal) is at least as often the actual reason organisations start working on it. A short scoping analysis quickly clarifies where you stand.
Wondering how this applies to your organisation? More about NIS2 at Millecam, or schedule a conversation right away.