Cyberattacks dominating the headlines, businesses locked down, and critical infrastructure under constant threat—it’s the reality of the digital world we live in today. Europe’s massive shield against these threats is the NIS2 Directive. But where exactly does Belgium stand today? Is the legislation just a checklist of paperwork, or is it driving a true cybersecurity revolution?
To go beyond the classroom theory, I recently sat down for a brand-new episode of the Howest IT Student Podcast.
I had the absolute honor of hosting a familiar face from my recent internship at the Centre for Cybersecurity Belgium (CCB): Johan Klykens, Director of the National Cybersecurity Certification Authority (NCCA) at the CCB. If you want to know how Belgium is executing NIS2, there is quite literally no better person to ask.

Diving Into the Post-April 2026 Reality
What makes this episode incredibly timely is that we have officially passed the crucial deadline of April 18th, 2026. Johan and I pulled no punches and dove straight into the hard questions that Belgian organizations are facing right now. We covered ground that every IT professional, business leader, and compliance officer needs to hear:
- The Reality of the Deadline: Did Belgian companies actually get their acts together by April 18th? Johan shared his first-hand observations on compliance rates and what has surprised him the most so far.
- Essential vs. Important Entities: We broke down the numbers of how many organizations in Belgium actually fall under these strict regulatory umbrellas.
- Supply Chain Risks & CyFun 2025: Having worked on the CyFun 2025 policy templates during my CCB internship, it was great to discuss with Johan why the latest framework places such a massive, deliberate focus on securing the supply chain.
- The “Iron Glove” Question: The CCB’s mantra has long been “We are here to help, not to punish.” But with massive regulatory fines on the table and board members now facing personal liability, I asked Johan point-blank: When do the velvet gloves come off, and when do the iron gloves come on?
Real Impact: Is NIS2 Actually Working?
One of the most fascinating parts of our conversation was looking at the data. Is all this regulatory enforcement actually translating to fewer successful breaches? We also looked ahead to the next major milestone coming up on April 18th, 2027, outlining exactly what companies need to prepare for over the next 12 months.
Johan wrapped up the episode with one crucial, invaluable piece of advice for organizations trying to navigate the complex waters of compliance without losing their minds.
Tune In to the Episode Now
Whether you are a cybersecurity student, a business owner trying to secure your supply chain, or an IT professional tasked with implementing these frameworks, this episode is packed with direct, authoritative insights.
A massive thank you to Johan Klykens for his time, his leadership, and his valuable insights!
🎧 Listen to the Episode Here:
For more official resources and practical documentation on compliance, make sure to visit Safeonweb@work or the official Centre for Cybersecurity Belgium (CCB) website.
What are your thoughts? Is your organization feeling the impact of the post-April 2026 NIS2 enforcement? Let’s get a discussion going in the comments below!