The government has a significant responsibility to secure the data of citizens and businesses, as well as ICT systems. Legislation and regulation play a crucial role.
- The NIS2 Directive is the successor to the NIS Directive. Established by the European Union, it aims to enhance the cybersecurity and resilience of essential services across EU member states. The NIS2 expands the scope of the original directive by covering more sectors. The Netherlands transposed it into Dutch legislation as the Cyberbeveiligingswet (Cbw).
- The Baseline Information Security Government (BIO) is the foundational framework for information security across all levels of government. Under the Cyberbeveiligingswet (Cbw), compliance with BIO2 is legally mandatory for securing network and information systems. Beyond this scope, BIO2 applies as binding self-regulation.
- The Administrative Covenant on Digital Security for Municipalities (in Dutch) was signed in December 2022 by the State Secretary for the Interior and Kingdom Relations, the Minister of Justice and Security, and the Mayor of The Hague, who is also the chair of the Association of Dutch Municipalities (VNG). This covenant is an action item from the Dutch Cybersecurity Strategy Action Plan 2022-2028. An official core group comprising representatives from the Ministries of the Interior, Justice, and Security, the VNG, and the G4 cities is now addressing 3 systemic challenges identified in the covenant. They are focusing on translating:
-
- The physical safety system in the digital era
- Comparing the alignment of authorities in both domains
- The information position concerning digital security within each municipality
- Structural funding to improve the digital security of municipalities.
-
Efforts focus on addressing the digital security challenges municipalities face. It does so in connection with the ongoing activities aimed at achieving the goals outlined in the covenant.




