FactBox.

Moniteur Belge · 21 Sep 2026 · 6 vistas

The CCB becomes a national cyber-hub and comes under the supervision of the Ministry of the Interior

Por FactBox Admin

Le CCB devient cyberpôle national et passe sous tutelle de l'Intérieur

The Centre for Cybersecurity Belgium (CCB) is now placed under the authority of the Minister of Security and the Interior and designated as the national cyber hub within the meaning of European Regulation (EU) 2025/38. The Royal Decree of September 15, 2026, published in the Belgian Official Gazette (Moniteur belge) No. 212 of September 21, 2026, under reference [2026/202297] (p. 50894), amends the Royal Decree of October 10, 2014, establishing the CCB. The text is signed by King Philippe and countersigned by Prime Minister B. De Wever and the Minister of Security and the Interior B. Quintin.

A transfer of oversight from the Prime Minister to the Interior

The report to the King annexed to the decree recalls that the CCB is currently placed under the authority of the Prime Minister and benefits from the administrative and logistical support of the FPS Prime Minister’s Chancellery. Within the framework of its 2025-2029 coalition agreement, the federal government intends to logically group all security-related competencies under the Minister of Security and the Interior.

The amendments made to the Royal Decree of October 10, 2014 — already amended by the Royal Decrees of September 8, 2015, February 16, 2022, and October 16, 2022 — are as follows:

  • Article 1: the CCB is established within the Federal Public Service Interior and placed under the authority of the Minister of Security and the Interior.
  • Article 2: the mention of the FPS Prime Minister’s Chancellery is replaced by that of the FPS Interior; paragraph 2, which considered the CCB as an operational service of the Chancellery, is repealed.
  • Article 4: the words “Prime Minister” are replaced by “Minister of Security and the Interior” in Articles 5, 6, § 5, 12, §§ 2 and 3, 13, 14, paragraph 1, 16, and 19 of the same decree.

The CCB designated as the national cyber hub within the meaning of Regulation (EU) 2025/38

Article 3 inserts an Article 3quater which designates the CCB as the national cyber hub referred to in Article 4 of Regulation (EU) 2025/38 of the European Parliament and of the Council of December 19, 2024, establishing measures to strengthen solidarity and capabilities in the Union to detect, prepare for, and respond to cyber threats and incidents, and amending Regulation (EU) 2021/694.

The report to the King specifies that this regulation on cyber-solidarity entered into force in January 2025 and that Article 4, paragraph 1, requires each Member State that decides to participate in the European cybersecurity alert system — established in Article 3 of the same regulation — to designate a national cyber hub. This system is a pan-European network of infrastructures composed of national and cross-border cyber hubs that join voluntarily. The cyber hub must be a single entity acting under the authority of a Member State; it may be a CSIRT, a national cyber crisis management authority, or another competent authority designated or established under Article 8, paragraph 1, of Directive (EU) 2022/2555 (NIS2 Directive). Recital 25 of the regulation specifies that this is a civilian project, which may also benefit the cyber-defense community.

The CCB had already been designated, under the NIS2 law and the Royal Decree of June 9, 2024, implementing the law of April 26, 2024, establishing a framework for the cybersecurity of networks and information systems of general interest for public security, as the national cybersecurity authority, national CSIRT, national cyber crisis authority, and competent authority within the meaning of Article 8, paragraph 1, of the NIS2 Directive. The new Article 3quater further provides that, when tasks arising from the regulation affect the competencies of other federal or federated entities, the CCB supports and cooperates closely with the competent administrations, in compliance with the applicable cooperation agreements pursuant to Article 92bis of the Special Law of August 8, 1980, on institutional reforms, and exchanges all relevant information with them.

Independence of the NIS2 inspection service

The repeal of paragraph 2 of Article 2 of the 2014 Royal Decree responds to a requirement for independence. The report to the King indicates that the CCB has established an inspection service responsible for the supervision missions provided for by the NIS2 law and that, in accordance with Articles 44 and 64 of this law, this service must perform its tasks independently of the entities it supervises, including public administration authorities falling within the scope of the NIS2 law — including the FPS Chancellery of the Prime Minister and the FPS Interior. Maintaining the CCB as an operational service of another public authority would have created a risk of conflict of interest between its inspection missions and the decisions of those authorities.

Entry into force and prior opinions

Article 5 sets the entry into force for January 1, 2027, with the exception of Article 3:

  • The entire decree enters into force on January 1, 2027, so that the administration has the necessary time to prepare the transfer and so that the change coincides with the start of a new budget year.
  • Article 3, regarding the designation as the national cyber hub, enters into force ten days after the publication of the decree, as this designation should not wait until January 1, 2027.

The file received the opinion of the Finance Inspector accredited to the FPS Chancellery of the Prime Minister (December 9, 2025) and the Finance Inspector accredited to the FPS Home Affairs (May 13, 2026), as well as the agreement of the Minister of Budget (June 25, 2026). The decree is issued on the proposal of the Prime Minister and the Minister of Security and Home Affairs, who are each responsible, as far as they are concerned, for its execution.

For readers, the text formalizes a double shift: the immediate designation of the CCB as the Belgian contact point for the future European cybersecurity alert system, and the administrative attachment of the center to the FPS Home Affairs on January 1, 2027, with the removal of the link that threatened the independence of its NIS2 inspection service.

Source: Belgian Official Gazette (Moniteur belge) No. 212 of September 21, 2026, royal decree of September 15, 2026, [2026/202297], p. 50894.