Market perspective

ISO/IEC 42001, SOC 2 and CyberFundamentals in Belgium

Belgian organizations can face customer requests for SOC 2, AI governance questions suited to ISO/IEC 42001, and national cyber requirements for certain entities. The CyberFundamentals framework from the Centre for Cybersecurity Belgium gives the country page a concrete local implementation context.

Put AI ownership and impacts in one operating system

ISO/IEC 42001 requires a management approach to AI, from context and policy through risk, impact, lifecycle, evaluation, and improvement. Build an inventory of AI systems used or supplied, and give each material use case an owner. Capture supplier dependencies, intended use, affected parties, testing, and monitoring.

Belgian and wider EU legal questions should be evaluated separately for each system and organizational role. The AIMS can provide traceable records for that analysis, but an ISO certificate does not automatically establish EU AI Act conformity.

Use CCB CyberFundamentals where the local context calls for it

The Centre for Cybersecurity Belgium describes CyberFundamentals, CyFun, as a tiered framework with Basic, Important, and Essential assurance levels. Its official materials connect to NIST CSF, ISO/IEC 27001/27002, IEC 62443, and CIS controls. A Belgian organization should determine whether CyFun is a customer request, a chosen framework, or part of an in-scope NIS2 response.

Use the CCB selection and self-assessment tools to identify a level and evidence gaps. Do not present an unverified internal mapping as a CCB label or independent assessment result.

Keep the NIS2 applicability decision explicit

The CCB publishes Belgian NIS2 guidance and a quickstart. Start by determining whether the organization is an essential or important entity under the national framework and which services are covered. Then connect governance, incident, supplier, continuity, and security measures to named owners.

ISO/IEC 27001 can provide an ISMS base, and CyFun can offer a local assurance route, but legal duties and the evidence path need validation in the applicable scope. Avoid treating a generic control library as a complete national compliance opinion.

Use SOC 2 only for the service assurance question

A Belgian service provider may prepare for SOC 2 when customers want a report on controls in a defined service organization system. Specify the service, Trust Services Criteria, reporting period, significant suppliers, and customer responsibilities. Evidence should be produced by the operational teams that run the controls.

A SOC 2 report is distinct from a CyFun label, ISO/IEC 42001 certification, and obligations under Belgian NIS2 law. Buyer-facing material should describe exactly what each artifact covers and avoid claiming that one proves all of them.

Common questions

Clarify the outcome before the work.

Is a CyFun self-assessment the same as a CyFun label?

No. CCB describes a conformity assessment process and a separate label request after assessment.

Does ISO/IEC 42001 certification establish EU AI Act compliance?

No. It concerns the AI management system. AI Act duties require system- and role-specific analysis.

Can a SOC 2 report replace Belgian NIS2 work?

No. SOC 2 examines a defined service under AICPA criteria; national legal duties have their own scope.

Work with Normstone

Make the next assurance decision clear.

Tell us your service, AI use, and customer requirements. We’ll help shape the scope.

Start a conversation