Your 2026 guide to complying with the Baseline Information Security for Government 2 (BIO2)

The Baseline Informatiebeveiliging Overheid 2 (BIO2) sets one mandatory information security framework across Dutch central government, municipalities, provinces, and water authorities with version 1.3, published on 9 January 2026, being the current binding edition.

Built on ISO/IEC 27001 and 27002, BIO2 combines a management system with mandatory measures no risk assessment can waive, and places personal, non-delegable accountability on board members. This guide breaks BIO2 down domain by domain, outlines what your organization must implement, and shows how ManageEngine AD360 and Log360 help you operationalize and strengthen compliance.

What you’ll learn

eBook
  • Understand who BIO2 binds — central government, municipalities, provinces, water authorities, and every other Dutch public body — and whether the obligation arrives via the Cbw or OBDO self-regulation.
  • Follow the five-step risk cycle from context assessment through to treatment and the Statement of Applicability, and see why BIO2's ISMS is a governance system rather than a piece of software.
  • Identify where accountability actually sits: board members carrying personal, non-delegable responsibility, line management owning the ISMS in its area, and a CISO empowered to advise unsolicited.
  • Work through the four control domains — organizational, people, physical, technological — and the measures with clocks attached: quarterly privileged reviews, annual recertification, one-week vulnerability mitigation, three-year incident retention.
  • Map identity governance and security monitoring requirements onto more than 25 groups of BIO2 clauses, from MFA (5.17.01) to SIEM detection and response (8.16.03).

Fill out the form

below to grab your free copy of our e-book

  •  
  •  
  •  
  • By clicking 'Download Now' you agree to processing of personal data according to the Privacy Policy.

Zoho Corporation Pvt. Ltd. All rights reserved.