Market perspective
ISO/IEC 42001, SOC 2 and CyberFundamentals in Belgium
Belgian organizations can face customer requests for SOC 2, AI governance questions suited to ISO/IEC 42001, and national cyber requirements for certain entities. The CyberFundamentals framework from the Centre for Cybersecurity Belgium gives the country page a concrete local implementation context.
Put AI ownership and impacts in one operating system
ISO/IEC 42001 requires a management approach to AI, from context and policy through risk, impact, lifecycle, evaluation, and improvement. Build an inventory of AI systems used or supplied, and give each material use case an owner. Capture supplier dependencies, intended use, affected parties, testing, and monitoring.
Belgian and wider EU legal questions should be evaluated separately for each system and organizational role. The AIMS can provide traceable records for that analysis, but an ISO certificate does not automatically establish EU AI Act conformity.
Use CCB CyberFundamentals where the local context calls for it
The Centre for Cybersecurity Belgium describes CyberFundamentals, CyFun, as a tiered framework with Basic, Important, and Essential assurance levels. Its official materials connect to NIST CSF, ISO/IEC 27001/27002, IEC 62443, and CIS controls. A Belgian organization should determine whether CyFun is a customer request, a chosen framework, or part of an in-scope NIS2 response.
Use the CCB selection and self-assessment tools to identify a level and evidence gaps. Do not present an unverified internal mapping as a CCB label or independent assessment result.
Keep the NIS2 applicability decision explicit
The CCB publishes Belgian NIS2 guidance and a quickstart. Start by determining whether the organization is an essential or important entity under the national framework and which services are covered. Then connect governance, incident, supplier, continuity, and security measures to named owners.
ISO/IEC 27001 can provide an ISMS base, and CyFun can offer a local assurance route, but legal duties and the evidence path need validation in the applicable scope. Avoid treating a generic control library as a complete national compliance opinion.
Use SOC 2 only for the service assurance question
A Belgian service provider may prepare for SOC 2 when customers want a report on controls in a defined service organization system. Specify the service, Trust Services Criteria, reporting period, significant suppliers, and customer responsibilities. Evidence should be produced by the operational teams that run the controls.
A SOC 2 report is distinct from a CyFun label, ISO/IEC 42001 certification, and obligations under Belgian NIS2 law. Buyer-facing material should describe exactly what each artifact covers and avoid claiming that one proves all of them.
Common questions
Clarify the outcome before the work.
Is a CyFun self-assessment the same as a CyFun label?
No. CCB describes a conformity assessment process and a separate label request after assessment.
Does ISO/IEC 42001 certification establish EU AI Act compliance?
No. It concerns the AI management system. AI Act duties require system- and role-specific analysis.
Can a SOC 2 report replace Belgian NIS2 work?
No. SOC 2 examines a defined service under AICPA criteria; national legal duties have their own scope.
Read next
A practical path from here.
ISO/IEC 42001
ISO/IEC 42001 in Europe: AI governance alongside the EU AI Act
Where an AI management system can support European governance work, and where AI Act analysis must remain separate.
NIS2
NIS2: the first decisions that matter
A clear starting point for applicability, governance, incident processes, and supplier security.
SOC 2
SOC 2 for European SaaS companies: when it helps and how to prepare
A buyer-led guide to SOC 2 in Europe: the right trigger, a defensible scope, and how it sits beside ISO 27001 and GDPR.
Work with Normstone
Make the next assurance decision clear.
Tell us your service, AI use, and customer requirements. We’ll help shape the scope.