Home › Frameworks › BIO

BIO software for gemeenten and the Dutch overheid.

The government-specific BIO controls (BBN classification, ENSIA or In-Control Verklaring, BSN handling, NCSC reporting, screening), recurring and with evidence, run alongside ISO 27001. For gemeenten, provincies, waterschappen, the Rijk and their suppliers. Included in Enterprise, €499 a month.

At a glance

  • BBN1: Basis baseline: minimum-required controls for any government information system.
  • BBN2: Verhoogde baseline: applies to systems with higher confidentiality, integrity or availability needs.
  • BBN3: Hoge baseline: applies to systems with critical confidentiality, integrity or availability needs.
  • ISO 27002 mapping: The full BIO is mapped to ISO 27002 controls; reuse the same evidence if you also run ISO 27001.

On this page

  1. What is BIO?
  2. Who needs to comply
  3. Key BIO controls covered by Dazr
  4. What auditors look for
  5. How Dazr helps with BIO

What is BIO?

BIO (Baseline Informatiebeveiliging Overheid). Dutch ministries, municipalities (gemeenten), water boards (waterschappen), provinces, executive agencies (uitvoeringsorganisaties) and the suppliers serving them.

As of 1 October 2026. BIO2 was adopted on 23 September 2025 and links to the Cyberbeveiligingswet, in force since 15 August 2026 (Kiwa, VNG). Read the differences between BIO and BIO2 and BIO2 and ENSIA for gemeenten (in Dutch).

Who needs to comply

  • Dutch ministries and central-government departments
  • Municipalities (gemeenten) of all sizes
  • Provinces and water boards (waterschappen)
  • Executive agencies (UWV, RDW, Belastingdienst-adjacent organisations)
  • Private suppliers running BIO-classified systems for public-sector customers

Key BIO controls covered by Dazr

BBN1Basis baseline: minimum-required controls for any government information system.
BBN2Verhoogde baseline: applies to systems with higher confidentiality, integrity or availability needs.
BBN3Hoge baseline: applies to systems with critical confidentiality, integrity or availability needs.
ISO 27002 mappingThe full BIO is mapped to ISO 27002 controls; reuse the same evidence if you also run ISO 27001.
ENSIAEenduidige Normatiek Single Information Audit: how gemeenten account once a year for the BIO and for DigiD, Suwinet, BRP and other registrations, to the gemeenteraad and to national supervisors.

What auditors look for

BIO audits sample the same evidence as ISO 27001 (the baseline is mapped to ISO 27002), plus public-sector specifics: BBN classification per system, the ENSIA self-evaluation or In-Control Verklaring, and security requirements passed on to suppliers. Dazr holds the controls and the evidence for each.

How Dazr helps with BIO

Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. BIO is one of its eleven frameworks, included in Enterprise, €499 a month. In practice that means:

  • Run the BIO-specific controls, including the BBN classification per system, on a recurring schedule
  • Run BIO controls alongside ISO 27001 Annex A in one workspace
  • Run the annual ENSIA or In-Control Verklaring cycle as a control, and record the submission date in Prepare for Audit
  • Keep suppliers in the vendor register with DPA links, review dates and contract expiry
  • Hand the auditor or the supervisor a read-only view or a single-PDF audit trail

Back to the full Dazr Compliance overview › | Sign up free ›

BIO questions, answered.

What is the difference between BIO 1.04 and BIO2?

BIO2 was adopted on 23 September 2025 and published on bio-overheid.nl. It is based on ISO 27001:2022 and ISO 27002:2022, replaces the three BBN levels with a risk-based approach plus mandatory basic-hygiene measures, and gets a legal basis through the Cyberbeveiligingswet, which has applied since 15 August 2026. Provinces, water boards and the Rijk apply it as mandatory self-regulation; gemeenten should follow VNG and IBD guidance for their timeline. Dazr's BIO set follows BIO 1.04; enable ISO 27001:2022 alongside to cover the control structure BIO2 builds on. As of 1 October 2026.

Can we run BIO alongside ISO 27001?

Yes; in fact most public-sector organisations should. The BIO is mapped to ISO 27002, so the same evidence often serves both. Enable both frameworks in the same workspace.

Does Dazr file the ENSIA self-assessment for us?

No. The ENSIA self-evaluation is completed in the ENSIA environment for gemeenten. Dazr holds the evidence behind your answers, runs the annual cycle as a control and records the submission date in Prepare for Audit.

Where is data hosted?

European Union only. Workspace records are encrypted at rest with AES-256-GCM at the application layer; uploaded evidence files rely on the storage provider's at-rest encryption.

Which compliance software helps Dutch municipalities with BIO and ENSIA?

Dazr runs the BIO controls, the BBN classification per system and the yearly ENSIA cycle as recurring controls with evidence, included in Enterprise. Its BIO set follows BIO 1.04; run ISO 27001:2022 alongside it for the control structure BIO2 builds on. The ENSIA self-evaluation itself is still completed in the ENSIA environment.

Ready to start your BIO program?

BIO is included in Enterprise (€499/mo, self-serve via Mollie, excl. VAT, cancel any time). Free and Basic cover ISO 27001, GDPR and NIS2; Pro adds NEN 7510, ISO 27701, ISO 22301 and SOC 2. Custom is the only tier on a contract, priced on request.