- Applicability and scope
- Compliance levels and requirements
- Part 1: BIO2 framework
- Part 2: BIO2 government measures
- Challenges of implementing BIO2
- Benefits of implementing BIO2
- Best practices
- BIO2: What is the future?
The original BIO was created to fix a fragmented situation where each layer of government ran its own approach to information security. BIO2 updates that foundation, aligning with the 2022 and 2023 editions of ISO/IEC 27001 and ISO/IEC 27002, adding obligations from the Dutch Cybersecurity Act (Cyberbeveiligingswet, [Cbw]), and adding government-specific measures that go further than the international standards alone. Every public entity must apply it; and prove that they have.
Applicability and scope
BIO2 covers the information security of all Dutch government entities and every type of environment within those entities, including operational technology (OT) and healthcare information systems. The Netherlands Standardisation Forum has put the ISO standards that underpin BIO2 on its mandatory 'apply or explain' list for the public sector. Entities comply or formally justify any departure.
The regulation covers a wide range of organisations, including:
- Ministries and central government departments.
- Municipalities, provinces, and water authorities.
- Other public bodies in the Government sector under the Cybersecurity Act (Cbw).
- Government entities outside the Cbw's direct scope, for whom BIO2 applies as obligatory self-regulation by decision of the Government-wide Digital Policy Board (OBDO).
BIO2 does not replace sector-specific standards. Healthcare data processors still apply NEN 7510; organisations with operational technology still apply the Cybersecurity Implementation Guideline (CSIR) and IEC 62443. These standards are built to integrate with the BIO2's ISO-based management system, not to run separately from it.
Compliance levels and requirements
BIO2 comes in two parts. Part 1 sets out the governance framework: the management system, risk management approach, governance roles, accountability mechanisms, and the relationship to the Cbw. Part 2 contains the mandatory government measures, mapped to the 93 control themes in NEN-EN-ISO/IEC 27002:2022 and grouped across four control domains: organisational, people, physical, and technological. Part 1 gets the management system in place; Part 2 specifies and proves the controls.
Part 1: BIO2 framework
Part 1 is where an entity builds the governance foundations for BIO2 compliance. It defines what an information security management system (ISMS) must look like under BIO 2, how risk management must work, and what accountability, supervision, and governance roles are required. The board bears ultimate responsibility and cannot pass that off.
The risk management process that Part 1 requires is systematic and runs in a cycle. Every entity must work through the following steps, in order:
- Context assessment: Identify internal and external factors, including Cbw obligations, that affect information security risks.
- Methodology selection: Choose and apply a risk management methodology that includes a quick scan, a full risk assessment process, a risk register, and a risk monitoring process.
- Risk identification: Determine which information and assets are present, identify relevant threats and vulnerabilities, and assess potential consequences.
- Risk analysis: Classify risks by likelihood and impact to get a consistent, governance-ready view of risk priorities.
- Risk treatment: Select controls from ISO/IEC 27001 Annex A and the BIO2 government measures to address identified risks.
Entities must produce a statement of applicability (SoA) listing which controls have been implemented and which mandatory BIO2 measures apply. Any deviations or inapplicable controls go into a dedicated SoA Exceptions annex.
Part 2: BIO2 government measures
Part 2 contains the mandatory measures that put BIO2 compliance into practice at the control level. Each government measure is numbered to match the ISO/IEC 27002:2022 control it supplements; measure 5.17.01, for instance, corresponds to ISO control 5.17 on authentication. These measures are the minimum required implementation of each control. A risk assessment can determine that more is needed, but it cannot remove the mandatory baseline.
The government measures run across four control domains in the ISO 27002 structure:
- Organisational controls (5.xx): Information security policy, roles and responsibilities, supply chain security, incident management, continuity, and compliance. Key obligations include mandatory multi-factor authentication (5.17.01), annual access rights reviews (5.18.02), mandatory Coordinated Vulnerability Disclosure (CVD) procedures (5.24.08), and an annual In Control Statement (5.36.01).
- People controls (6.xx): Screening, onboarding awareness, ongoing training, and incident notification. All employees must complete awareness training within three months of appointment (6.03.02) and must demonstrably acknowledge the incident notification procedure (6.08.01).
- Physical controls (7.xx): Physical access, environmental security, and removable media. Critical information systems must never be accessible via a single secure zone (7.01.02), and removable media leaving the entity must be verified as irretrievably wiped (7.10.01).
- Technological controls (8.xx): Endpoint security, patch management, logging, SIEM/SOC monitoring, cryptography, network segmentation, and secure development. Internet-facing systems must be tested continuously for weaknesses (8.08.04) and must go through automated penetration testing at every major release (8.08.05).
Challenges of implementing BIO2
BIO2 compliance takes real work, especially for entities updating legacy security programmes or integrating multiple ISO management systems.
Proving setup, existence, and operation
BIO2 does not run on self-attestation. Entities must show government-approved auditors that each measure is set up correctly, exists in practice, and operates effectively if they want to get BIO2 compliant. That typically means internal audits, management reviews, independent assessments, and penetration tests. For organisations without mature audit infrastructure, building that evidence base from scratch takes time and money.
Mandatory measures that cannot be waived
Many compliance frameworks let risk acceptance stand in for implementation. BIO2 does not. Even when a risk assessment suggests a control is not strictly necessary, the mandatory government measures still apply—unless they genuinely do not fit. Organisations used to risk-based exemptions will need to rethink how they approach compliance logic.
Supply chain and subcontractor oversight
The BIO2 supply chain requirements go deep. Entities must confirm that security requirements imposed on direct suppliers flow fully to all subcontractors (5.21.03), assess supply chain risks on an ongoing basis (5.21.05), and ensure suppliers provide annual independent third-party evidence of compliance (5.20.03). For entities with large or complex supplier portfolios, maintaining that visibility is a real operational burden.
Keeping the ISMS current under legislative change
The Cbw introduced new obligations woven throughout BIO2 v1.3. As that legislation develops—and as the Dutch Authority for Digital Infrastructure (RDI) builds out its supervisory approach—entities will need to revisit risk assessments, controls, and accountability frameworks. Organisations that treat compliance as a project with an end date tend to find the same gaps every audit cycle.
Coordinating across governance roles
BIO2 requires documented roles for board members, CISOs, line managers, and internal supervisors, and those roles carry legal weight under the Cbw. Board members must train on cybersecurity risk (5.04.01), line managers own the risks on their information systems, and the CISO must be empowered to give unsolicited advice to the board. In organisations with historically informal security governance, getting these boundaries in place requires both procedural and cultural change.
Incident notification under tight statutory deadlines
BIO2 measure 5.24.07 requires reporting significant information security incidents to the relevant computer security incident response team (CSIRT) within statutory time limits. Detection, triage, and reporting processes must be mature enough to hit those deadlines consistently, including for incidents involving personal data, where data protection timelines run in parallel.
Benefits of implementing BIO2
Done properly, BIO2 compliance pays off in ways that go beyond just satisfying a legal requirement.
A shared language across government
BIO was built to give every government entity, large ministry or small municipality, the same security vocabulary and the same baseline expectations. That makes inter-governmental cooperation genuinely easier. When sharing data or connecting systems, organisations can point to a shared SoA rather than negotiate bespoke bilateral assessments each time.
Stronger public trust
Citizens and businesses are often required, not just invited, to share sensitive information with the government. BIO2 compliance gives entities a structural basis for showing that data is handled responsibly. Clear accountability statements and transparent SoA documents tell the public that the security posture is managed, tested, and improving—not assumed.
Cbw alignment from the outset
For entities in scope under the Cbw, BIO2 compliance and Cbw compliance cover much of the same ground. Getting a BIO2-compliant ISMS in place now means not having to rebuild governance arrangements every time new regulatory requirements emerge. The RDI will use BIO2 as its supervisory baseline, so entities with the framework already embedded face less remediation risk during inspections.
A real security posture improvement
The BIO2 government measures around multi-factor authentication (5.17.01), continuous vulnerability scanning (8.08.04), SIEM monitoring (8.16.03), and secure mobile working (8.01.01) target real attack vectors, not just boxes to tick. Entities that apply them properly end up with controls that would have made a material difference in many of the incidents Dutch public institutions have experienced.
Less duplicated effort across management systems
BIO2 follows the Harmonized Structure used across ISO management standards. Organisations already running ISO 9001, ISO 22301, or NEN 7510 management systems can integrate them with the BIO2 ISMS rather than maintain separate processes. For larger entities in particular, the reduction in overlapping documentation and parallel audit work is substantial.
Best practices
Meeting the minimum requirements is one thing. Building a programme that actually holds up over time takes a few extra habits.
Governance and accountability
- Give the CISO a formal mandate that includes the right to provide unsolicited board advice, and document that in the governance framework, not just the job description.
- Connect information security reporting to the Planning and Control (P&C) cycle from day one, so the annual In Control Statement emerges naturally from ongoing management rather than being assembled at the last minute.
- Keep the SoA current. Assign a named owner and set a trigger for review whenever the information systems landscape changes significantly.
- Run quarterly access rights reviews for privileged accounts and annual reviews for all accounts. Log the evidence—auditors and the RDI will ask for it.
Supplier management and supply chain security
- Build supply chain risk assessment into procurement before contracts are signed, not after a supplier is already onboarded.
- Put the right to independent external audits into all contracts involving information processing, as BIO2 measure 5.20.04 requires, and use that right on a risk-based schedule.
- Require suppliers to provide annual third-party evidence of compliance, not self-assessments, covering the full scope of services, including their own subcontractors
Technical controls, monitoring, and incident readiness
- Run continuous automated vulnerability scans on all internet-facing systems. Schedule penetration tests at every major release, not just once a year. Under BIO2 measure 8.08.05, high-risk findings must block deployment.
- Set SIEM logging retention periods using a documented risk assessment that accounts for long-dwell-time attack scenarios. Defaulting to the shortest permissible period is a common mistake.
- Tabletop the incident notification process at least annually with scenarios realistic enough to stress-test CSIRT reporting timelines. Statutory deadlines under the Cbw leave little room for confusion when an actual incident arrives.
BIO2: What is the future?
The BIO2 is the most comprehensive government-wide information security standard the Netherlands has put in place. It anchors compliance in ISO/IEC 27001 and 27002, then adds government-specific measures that cannot be negotiated away, creating a security baseline that runs across every layer of the Dutch public sector. Organisations that approach it as a management capability rather than a documentation project build postures that hold up under both regulatory scrutiny and real incidents.
BIO2 compliance does not have a finish line. The Cbw keeps developing, the RDI is building out its supervisory approach, and the threats facing Dutch government entities are not standing still either. The organisations that do well here are the ones that invest in the governance infrastructure, the continuous risk management cycle, and the evidence practices the framework requires—and that revisit all of it at the pace of change, not the pace of the audit calendar.

