HomeFrameworksNational Cyber & Cloud SchemesBIO

Framework  National Cyber & Cloud Schemes

BIO

The Baseline Informatiebeveiliging Overheid (BIO, Government Information Security Baseline) is the mandatory information security standard for all layers of Dutch government: central government, provinces, municipalities, and water boards.

It is built on ISO/IEC 27001 and 27002 and adds government-specific mandatory controls and three basic protection levels (BBN 1, 2, and 3) that an organization assigns to each information system based on a risk assessment.

BIO2, the second generation, was published in the Staatscourant on March 5, 2026 (version 1.3), aligned to the 2022 editions of ISO/IEC 27001 and 27002 and to the NIS2 duty of care as implemented by the Dutch Cyberbeveiligingswet. It was developed under the Ministry of the Interior (BZK) with the municipal, provincial, and water board associations.

BIO does not come with a certificate. Government bodies account for compliance through their own governance line: an annual in-control statement by the board, internal audits, and for municipalities the ENSIA (Eenduidige Normatiek Single Information Audit) process, in which an IT auditor examines a defined set of BIO controls.

In writing, a BIO organization needs an information security policy adopted by the board, a risk assessment per system with the assigned BBN, a statement of applicability or control matrix, procedures for the mandatory controls (access, logging, change, supplier management, incident handling), supplier agreements that pass BIO obligations to vendors, and the annual accountability report.

Suppliers to Dutch government are increasingly asked to demonstrate BIO compliance contractually, usually by mapping an ISO/IEC 27001 certificate to the BIO controls.

AI-compiled
Share
Sponsored
BIO
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with BIO
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

All Dutch public bodies (central government, provinces, municipalities, water boards) as a matter of government policy; suppliers and processors of government data are bound through contracts and procurement conditions, not directly by the standard.

What the assessor asks to see

Information security policy and board approval; risk assessments and BBN assignments per system; control matrix or statement of applicability; procedures and evidence for mandatory controls (access management, logging, change management, cryptography, supplier management, incident response, business continuity); supplier contracts with BIO clauses and supplier assurance reports; awareness training records; internal audit reports; ENSIA self-assessment and IT auditor's report; the annual accountability statement.

BIO2

BIO2 version 1.3 was published in the Staatscourant on March 5, 2026. It aligns with ISO/IEC 27001:2022 and 27002:2022 and with the NIS2 duty-of-care requirements under the Dutch Cyberbeveiligingswet, and it gives public bodies a single instrument for accounting to chain partners, supervisors, and citizens. Check the IBD and BZK pages for the transition timetable from BIO 1.04.

Assessors

Who assesses BIO

Internal audit and the organization's own accountability line; registered IT auditors (RE, under NOREA) for the ENSIA audits at municipalities and for assurance reports requested by supervisory bodies. No certification body issues a BIO certificate. scheme-specific; IT auditors are regulated by NOREA (Dutch association of registered IT auditors).

No firm has claimed a BIO assessor listing yet. Claim yours →

Consultants

Who helps with BIO

Dutch information security consultancies and IT audit firms specialize in BIO implementation, ENSIA preparation, and supplier mapping. Engagements typically run three to twelve months for a first implementation.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a BIO consultant listing yet. Claim yours →

Software

Tools for BIO

Tools that name this framework in their own material.

No firm has claimed a BIO tool listing yet. Claim yours →

Related reading

  1. BIO2 gepubliceerd: nieuw kader voor informatiebeveiligingThe Dutch municipalities association on what BIO2 replaces and the timetable local authorities are actually working to.VNG
  2. De BIO en wat er met BIO2 verandertExplains the shift away from the fixed BBN protection levels toward a risk-based approach, and what that changes in practice.2-Control

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for BIO

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with BIO

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.