What is BIO?
BIO (Baseline Informatiebeveiliging Overheid). Dutch ministries, municipalities (gemeenten), water boards (waterschappen), provinces, executive agencies (uitvoeringsorganisaties) and the suppliers serving them.
As of 1 October 2026. BIO2 was adopted on 23 September 2025 and links to the Cyberbeveiligingswet, in force since 15 August 2026 (Kiwa, VNG). Read the differences between BIO and BIO2 and BIO2 and ENSIA for gemeenten (in Dutch).
Who needs to comply
- Dutch ministries and central-government departments
- Municipalities (gemeenten) of all sizes
- Provinces and water boards (waterschappen)
- Executive agencies (UWV, RDW, Belastingdienst-adjacent organisations)
- Private suppliers running BIO-classified systems for public-sector customers
Key BIO controls covered by Dazr
What auditors look for
BIO audits sample the same evidence as ISO 27001 (the baseline is mapped to ISO 27002), plus public-sector specifics: BBN classification per system, the ENSIA self-evaluation or In-Control Verklaring, and security requirements passed on to suppliers. Dazr holds the controls and the evidence for each.
How Dazr helps with BIO
Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. BIO is one of its eleven frameworks, included in Enterprise, €499 a month. In practice that means:
- Run the BIO-specific controls, including the BBN classification per system, on a recurring schedule
- Run BIO controls alongside ISO 27001 Annex A in one workspace
- Run the annual ENSIA or In-Control Verklaring cycle as a control, and record the submission date in Prepare for Audit
- Keep suppliers in the vendor register with DPA links, review dates and contract expiry
- Hand the auditor or the supervisor a read-only view or a single-PDF audit trail
Back to the full Dazr Compliance overview › | Sign up free ›