The Baseline Information Security for Government (Baseline informatiebeveiliging Overheid, or BIO in Dutch) is the fundamental standards framework for information security across all levels of government (central government, municipalities, provinces, and water authorities).
Benefits of 1 baseline framework
A single baseline framework for information security across government offers important benefits:
-
A clear foundation for effective information security management
The BIO provides government organisations with a common framework for establishing, managing and continuously improving information security in a mature manner. It supports risk-based working, clear responsibilities and demonstrable internal controls.
-
A reliable and appropriate baseline level of security
Citizens, businesses, and supply chain partners need to trust government organisations to handle information carefully and ensure digital resilience. By setting a minimum level of security, the BIO helps protect information, systems and services.
-
Secure digital collaboration across supply chains
A shared baseline framework makes collaboration between different levels of government, implementing organisations and suppliers easier. It provides a common language, predictable security requirements and greater mutual trust across supply chains.
-
Greater consistency and less duplication
Harmonisation helps organisations avoid developing or maintaining separate requirements, assessment frameworks, and accountability processes for similar issues. This reduces the administrative burden and helps organisations remain compliant with laws and regulations.
The latest English-language version of the BIO is available at bio-overheid.nl.
Key changes in BIO2
BIO2 aligns with international security standards (NEN-EN-ISO/IEC 27001:2023 (nl) and NEN-EN-ISO/IEC 27002:2022 (nl)). It replaces the previous classification into 3 basic security levels (BBNs) with a more transparent, risk-based approach. This enables government agencies to customise measures to specific risks without being limited to the 3 security levels.
The government has also revised its measures, easing some where possible. However, the mandatory adoption of the NIS2 Directive, implemented in the Netherlands through the Cyberbeveiligingswet (Cbw), has strengthened certain government measures.
BIO2 and ISO standards
The BIO2 is based on NEN-EN-ISO/IEC 27001:2023 (nl) and NEN-EN-ISO/IEC 27002:2022 (nl).
- NEN-EN-ISO/IEC 27001:2023 (nl) sets out the requirements for establishing, implementing, maintaining and continuously improving an information security management system, and for defining the scope of that management system.
- NEN-EN-ISO/IEC 27002:2022 (nl) must be applied on a risk-driven basis when defining appropriate controls.
When control measures from the ISO standard are required based on the identified risk, government organisations must, at a minimum, apply the government-specific measures in BIO2. This approach guarantees a baseline of information security and promotes cooperation.
Considering the risks, organisations should implement additional security measures beyond the ISO standard controls and government measures outlined in the BIO. They can choose standards that suit their needs. Examples include the Cybersecurity Implementation Guideline (CSIR) (Dutch) for Operational Technology (OT) security or NEN7510 for healthcare information.
BIO2 as a statutory duty of care
In line with the National Cybersecurity Strategy, the BIO2 will be included as a duty of care in the ministerial regulation for the government sector under the Cyberbeveiligingswet (Cbw), as part of the Dutch implementation of the NIS2 Directive. With the Cbw having entered into force on 15 August 2026, the government measures outlined in the BIO2 for securing network and information systems have become mandatory.
The ministerial regulation under the Cbw refers to the publication of BIO2 version 1.3 in the Government Gazette (Staatscourant).
Statutory self-regulation following the introduction of the Cbw
Even with the Cbw in force, the BIO2 continues to serve as statutory self-regulation for organisations not covered by the Cbw. This includes the High Councils of State, the Ministry of Defence, the General Intelligence and Security Service (AIVD), and the police. These organisations will remain bound by the BIO2 by decision of the Council of Ministers, as announced in the Government Gazette.
The same applies to independent administrative bodies (ZBOs) that are exempt from the Cbw requirements. Intergovernmental arrangements beyond the scope of the Cbw will also remain subject to the BIO2 through their contracting authority. As a result, the BIO2 effectively applies to all government organisations.
Statutory self-regulation remains in force for applying the BIO2 to aspects of information security not covered by the Cbw, such as the security of information on paper. This also applies to 3 government measures that fall outside the scope of the Cbw; BIO2 marks these as such.
Ministerial regulation takes precedence
Differences between the BIO2 PDF version, the BIO2 version published in the Government Gazette and the ministerial regulation may cause uncertainty about which measures are exempt. The ministerial regulation takes precedence. Controls 5.32 and 5.34, and government-specific measures 5.32.01, 5.33.01 and 5.34.01, are exempt. Control 5.33 is legally mandatory. This ambiguity will be corrected in the next version.
Maintenance and governance of BIO2
The intergovernmental BIO working group maintains the BIO. Chaired by the Ministry of the Interior and Kingdom Relations (BZK), it includes representatives from the different levels of government:
- CIO of the Central Government
- Association of Netherlands Municipalities (VNG)
- Interprovincial Consultation (IPO)
- Dutch Water Authorities (UvW)
The working group also includes:
- Several large executive agencies
- Standardisation Forum (Forum Standaardisatie)
- National Cyber Security Centre (NCSC)
- Centre for Information Security and Privacy Protection (CIP)
The Core Intergovernmental Consultation Body (IBO) makes decisions on the BIO. The IBO comprises representatives from the 4 government tiers and meets under the chairmanship of the Ministry of BZK.
As the BIO is a government-wide product, the aim is to gather feedback from all user groups. BIO users can provide feedback on an ongoing basis via GitHub (Dutch). The BIO working group reviews this feedback as part of developing the next version.
The aim is to publish the next version of BIO2 by the end of 2027. To prepare for this version, CIP started an evaluation involving all levels of government (Dutch) in 2026.
Getting started with BIO2
To help organisations implement BIO2, CIP has developed various supporting documents, including the BIO Self-Assessment, frequently asked questions and a ‘before and after’ list showing the differences between BIO2 and previous versions.
In addition, at the request of the Ministry of BZK, the CIP is running an implementation support campaign that features events and practical guidance. This helps organisations strengthen their information security.
Various tools are available, including those on the Tools and resources for the Cyberbeveiligingswet page and the CISO toolbox (Dutch) provided by CIP.
For more information on BIO2 in English, visit bio-overheid.nl.




