What is BIO2?
BIO (Baseline Informatiebeveiliging Overheid) is a single set of information security requirements for Dutch public administration. The first version has applied since 1 January 2020 and replaced four earlier, separate baselines for the different layers of government: BIR (central government), BIG (municipalities), IBI (provinces) and BIWA (water authorities). As a result, public bodies at every level speak the same security language — which matters enormously for inter-institutional data exchange and shared digital services.
BIO2 is the updated version of the baseline, aligned with the new editions of ISO/IEC 27001:2022 and ISO/IEC 27002:2022. It adopts their control structure (organisational, people, physical and technological themes) and supplements it with government-specific measures (overheidsmaatregelen). Compared with the first version, BIO2 puts a stronger emphasis on organisational risk management instead of rigid, pre-assigned protection levels — the organisation itself, based on risk analysis, decides on measures beyond the common baseline.
Who must comply?
BIO is binding for the entire Dutch public sector through inter-governmental agreements and cabinet decisions. The standard also reaches IT suppliers working for government — BIO requirements flow into public tenders and contracts, so companies serving the Dutch public sector must be able to demonstrate compliance.
- Central government (Rijksoverheid) — ministries and their agencies and services.
- Municipalities (gemeenten) — all 342 Dutch municipalities, supported by the sector CERT IBD (Informatiebeveiligingsdienst) at the VNG association.
- Provinces (provincies) and water authorities (waterschappen).
- Organisations performing public tasks and suppliers on whom government imposes BIO requirements in contracts and tenders.
Structure: ISO 27001/27002 plus government measures
BIO2 does not reinvent security — its foundation is an information security management system aligned with ISO/IEC 27001 and the ISO/IEC 27002:2022 control catalogue. Controls are grouped into four themes: organisational (chapter 5, 37 controls — policies, roles, risk, suppliers, incidents, continuity, legal compliance), people (chapter 6, 8 controls — screening, awareness, remote work), physical (chapter 7, 14 controls — zones, equipment, media) and technological (chapter 8, 34 controls — privileged access, cryptography, backups, logging, vulnerabilities, software development).
On top of this come government-specific measures that spell out how a control is to be implemented in public sector reality — for example employee screening requirements (VOG), the use of mandatory open standards from the Forum Standaardisatie list (such as HTTPS with HSTS, DNSSEC or secure email standards), and accountability rules towards representative bodies. An organisation that has implemented ISO 27001 has therefore already covered most of the road to BIO2 compliance.
Accountability: ENSIA and the planning cycle
BIO has no certification scheme — compliance is verified through the accountability mechanisms of each government layer. Municipalities account annually via ENSIA (Eenduidige Normatiek Single Information Audit): one unified self-assessment covering BIO and key national systems (for example DigiD and Suwinet), on the basis of which the municipal executive (college) issues a statement to the municipal council, with selected areas examined by an independent IT auditor.
In central government, the state of information security is reported within the annual departmental planning and accountability cycle, overseen among others by the central government audit service (Auditdienst Rijk) and the Netherlands Court of Audit (Algemene Rekenkamer), whose reports regularly flag information security shortcomings as one of the most frequent management problems. Provinces and water authorities have analogous horizontal accountability mechanisms.
BIO2 vs NIS2 (Cyberbeveiligingswet) and the AVG
The NIS2 directive is implemented in the Netherlands by the Cyberbeveiligingswet, which also covers a large part of public administration and introduces cybersecurity risk management duties, incident reporting (a 24-hour early warning and a 72-hour notification) and board-level accountability. BIO2 is intended as the practical way to fulfil the duty of care: an organisation that has genuinely implemented the baseline covers the substantial part of the act’s requirements.
In parallel, every public body processes personal data and is subject to the AVG (GDPR), supervised by the Autoriteit Persoonsgegevens — with 72-hour breach notification and records of processing. These requirements overlap heavily with BIO2 controls on classification, access, encryption and incidents, so one well-run management system serves all three regimes.
How does Guardiso help?
Guardiso guides a public organisation through implementing and maintaining BIO2 — from self-assessment, through registers and policies, to evidence for the annual accountability cycle.
- All BIO2 controls (93 controls across the four ISO 27002:2022 themes) seeded automatically when you enable the standard — with statuses and owners.
- Policies generated from public sector templates, with versioning and board approval.
- A risk register supporting BIO2’s risk-based approach — risk analyses, treatment plans and board acceptance of residual risks.
- Recurring tasks: access reviews, backup tests, awareness training, supplier reviews — with reminders.
- An incident register with external reporting paths (Autoriteit Persoonsgegevens, NCSC/IBD) and deadline tracking.
- An evidence repository ready for the self-assessment and IT audit — one source of truth instead of scattered spreadsheets.
- Cross-mapping to ISO 27001, NIS 2 and GDPR/AVG — work done for BIO2 satisfies the overlapping requirements of the other frameworks.
