Security standard

BIO2

BIO2 (Baseline Informatiebeveiliging Overheid 2.0) is the Dutch government-wide information security baseline covering the entire public sector — central government, municipalities, provinces and water authorities. It is built on ISO/IEC 27001:2022 and 27002:2022 and sets a common minimum level of safeguards for every layer of Dutch government.

Start assessmentRead about the standard
93
controls in Guardiso
27
free-test questions
PL · EN
two languages

What is BIO2?

BIO (Baseline Informatiebeveiliging Overheid) is a single set of information security requirements for Dutch public administration. The first version has applied since 1 January 2020 and replaced four earlier, separate baselines for the different layers of government: BIR (central government), BIG (municipalities), IBI (provinces) and BIWA (water authorities). As a result, public bodies at every level speak the same security language — which matters enormously for inter-institutional data exchange and shared digital services.

BIO2 is the updated version of the baseline, aligned with the new editions of ISO/IEC 27001:2022 and ISO/IEC 27002:2022. It adopts their control structure (organisational, people, physical and technological themes) and supplements it with government-specific measures (overheidsmaatregelen). Compared with the first version, BIO2 puts a stronger emphasis on organisational risk management instead of rigid, pre-assigned protection levels — the organisation itself, based on risk analysis, decides on measures beyond the common baseline.

Who must comply?

BIO is binding for the entire Dutch public sector through inter-governmental agreements and cabinet decisions. The standard also reaches IT suppliers working for government — BIO requirements flow into public tenders and contracts, so companies serving the Dutch public sector must be able to demonstrate compliance.

  • Central government (Rijksoverheid) — ministries and their agencies and services.
  • Municipalities (gemeenten) — all 342 Dutch municipalities, supported by the sector CERT IBD (Informatiebeveiligingsdienst) at the VNG association.
  • Provinces (provincies) and water authorities (waterschappen).
  • Organisations performing public tasks and suppliers on whom government imposes BIO requirements in contracts and tenders.

Structure: ISO 27001/27002 plus government measures

BIO2 does not reinvent security — its foundation is an information security management system aligned with ISO/IEC 27001 and the ISO/IEC 27002:2022 control catalogue. Controls are grouped into four themes: organisational (chapter 5, 37 controls — policies, roles, risk, suppliers, incidents, continuity, legal compliance), people (chapter 6, 8 controls — screening, awareness, remote work), physical (chapter 7, 14 controls — zones, equipment, media) and technological (chapter 8, 34 controls — privileged access, cryptography, backups, logging, vulnerabilities, software development).

On top of this come government-specific measures that spell out how a control is to be implemented in public sector reality — for example employee screening requirements (VOG), the use of mandatory open standards from the Forum Standaardisatie list (such as HTTPS with HSTS, DNSSEC or secure email standards), and accountability rules towards representative bodies. An organisation that has implemented ISO 27001 has therefore already covered most of the road to BIO2 compliance.

Accountability: ENSIA and the planning cycle

BIO has no certification scheme — compliance is verified through the accountability mechanisms of each government layer. Municipalities account annually via ENSIA (Eenduidige Normatiek Single Information Audit): one unified self-assessment covering BIO and key national systems (for example DigiD and Suwinet), on the basis of which the municipal executive (college) issues a statement to the municipal council, with selected areas examined by an independent IT auditor.

In central government, the state of information security is reported within the annual departmental planning and accountability cycle, overseen among others by the central government audit service (Auditdienst Rijk) and the Netherlands Court of Audit (Algemene Rekenkamer), whose reports regularly flag information security shortcomings as one of the most frequent management problems. Provinces and water authorities have analogous horizontal accountability mechanisms.

BIO2 vs NIS2 (Cyberbeveiligingswet) and the AVG

The NIS2 directive is implemented in the Netherlands by the Cyberbeveiligingswet, which also covers a large part of public administration and introduces cybersecurity risk management duties, incident reporting (a 24-hour early warning and a 72-hour notification) and board-level accountability. BIO2 is intended as the practical way to fulfil the duty of care: an organisation that has genuinely implemented the baseline covers the substantial part of the act’s requirements.

In parallel, every public body processes personal data and is subject to the AVG (GDPR), supervised by the Autoriteit Persoonsgegevens — with 72-hour breach notification and records of processing. These requirements overlap heavily with BIO2 controls on classification, access, encryption and incidents, so one well-run management system serves all three regimes.

How does Guardiso help?

Guardiso guides a public organisation through implementing and maintaining BIO2 — from self-assessment, through registers and policies, to evidence for the annual accountability cycle.

  • All BIO2 controls (93 controls across the four ISO 27002:2022 themes) seeded automatically when you enable the standard — with statuses and owners.
  • Policies generated from public sector templates, with versioning and board approval.
  • A risk register supporting BIO2’s risk-based approach — risk analyses, treatment plans and board acceptance of residual risks.
  • Recurring tasks: access reviews, backup tests, awareness training, supplier reviews — with reminders.
  • An incident register with external reporting paths (Autoriteit Persoonsgegevens, NCSC/IBD) and deadline tracking.
  • An evidence repository ready for the self-assessment and IT audit — one source of truth instead of scattered spreadsheets.
  • Cross-mapping to ISO 27001, NIS 2 and GDPR/AVG — work done for BIO2 satisfies the overlapping requirements of the other frameworks.
Official sources
01Select standard›02Complete the self assessment›03Close gaps in Guardiso
—
BIO2 readiness score
0/27 answered
The score updates live as you answer.

Other standards to assess

ISO 27001GlobalGDPREUNIS 2 (Polish KSC act)EU · PLSOC 2GlobalDORAEUTISAXAutomotiveISO 9001GlobalISO 42001 (AI)GlobalKRIPLPCI DSSGlobalNIST CSFUSANIST 800-53USAHIPAAUSACMMC 2.0USACyber EssentialsUKSOX ITGCUSAEU AI ActEUISO 27701GlobalISO 22301GlobalISO 14001GlobalISO 45001GlobalISO 13485MedicalIEC 62304MedicalMDREU · MedicalISO 14971MedicalDCB0129UKMiCAEUIEC 62443GlobalISO 21434Automotive
Browse all 30 standards