Since 2018, the Baseline Informatiebeveiliging Overheid has been the joint framework of central government, provinces, municipalities and water authorities, as an inter-governmental agreement: "binding self-regulation". With BIO2, less changes in substance than you might think, but all the more in legal terms. This page lists the differences and translates them into what local and regional government needs to do now.

Timeline

DateEvent
2018All tiers of government commit to the BIO (explanatory notes to the government regulation)
5 March 2025BIO2 1.0 draft published online
14 April 2025BIO2 1.1 draft
24 September 2025BIO2 1.2 adopted by the government-wide Digital Government policy council (OBDO)
9 January 2026BIO2 1.3 final: changes for BIO2 as legislation, marking of controls outside the Cbw, new control 5.24.08 (CVD)
2 March 2026BIO2 1.3 published in the Staatscourant (Stcrt. 2026, 7416)
3 July 2026Cyberbeveiligingsregeling sector overheid adopted (Stcrt. 2026, 27679)
15 August 2026Cbw, Cbb and the government regulation in force; BIO2 anchored in law for essential government entities

Dates from the change history in BIO2 1.3 itself and from the Staatscourant. Note: 5 March is the date of the first draft (2025), not of the publication of version 1.3 in the Staatscourant.

What changed

TopicBIO (1.04)BIO2 (1.3)
StatusInter-governmental agreement, binding self-regulationLegally mandatory for essential government entities via the Cyberbeveiligingsregeling sector overheid; binding self-regulation outside that group
Base standardsISO 27001 and ISO 27002 (2017 versions)NEN-EN-ISO/IEC 27001:2023 (part 1) and 27002:2022 (part 2)
StructureFramework and controls per BBN levelPart 1 BIO2 framework (ISMS, risk management, SoA, governance, suppliers); part 2 government controls, numbered after ISO 27002:2022 (for example 5.24.07)
LevelsThree baseline security levels (BBN1 to BBN3)No BBN; government controls are the mandatory minimum, supplemented on the basis of risk. The government regulation uses "interests to be protected" (central government) and impact levels (local and regional government) to identify crucial systems.

New or stricter in BIO2

TopicBIO2 (1.3)
ISMSISO 27001 is mandatory for setting up the management system
DeviationsDeviating from or not applying a control is justified with a risk analysis, referenced in an annex of exceptions to the Statement of Applicability
Other standardsControls may be replaced by equivalents or combined, for example NEN 7510 for healthcare information and CSIR or IEC 62443 for OT
Cbw scopeControls outside the Cbw are marked; for those only binding self-regulation applies. The government regulation excludes 5.32 to 5.34 (including intellectual property and privacy)
Vulnerabilities5.24.08: a Coordinated Vulnerability Disclosure procedure is set up and published (NCSC guideline or ISO/IEC 29147)
Reporting5.24.07: the incident procedure covers reporting to the CSIRT within the statutory deadline, processing CSIRT notifications and informing those affected

The BIO (1.04) column is a high-level summary; the BBN classification is confirmed by the government regulation itself, which sets the old BBN2 and BBN3 from BIO 1.04 next to the new levels.

Governance and accountability

BIO2 describes roles for the executive, line management, the CISO and the internal supervisor. The CISO coordinates, but is "expressly not responsible for information security by line management". On transparency, BIO2 says: "Information security is a standard part of the organisation's annual report", and government bodies give each other insight via the Statement of Applicability. On certification: "The BIO does not require NEN-EN-ISO/IEC 27001 certification."

BIO2 as law: the Cyberbeveiligingsregeling sector overheid

The regulation of the State Secretary for the Interior (BZK) applies to essential entities in the government sector, except water authorities. Under the Cbw, ministries, independent administrative bodies (zbo's, insofar as they are public administration entities), provinces, municipalities and joint arrangements are always essential, regardless of their size. The essentials:

  • Art. 3: apply NEN-EN-ISO/IEC 27001:2023 to your management system and its scope.
  • Art. 4: keep an overview of your crucial network and information systems. For local and regional government, these are systems with impact level "high" or "very high" according to Annex 2 (with dimensions including political damage, financial impact, reputational damage and personal data).
  • Art. 5: use at least the controls of ISO 27002:2022 (except 5.32 and 5.34) and the relevant government controls from BIO2 1.3 (except 5.32.01 to 5.34.01). Replacing them with an equivalent framework is allowed if you demonstrate the necessity and equivalence. Design, existence and operating effectiveness must be demonstrable.
  • Art. 6: thresholds for the reporting duty. For local and regional government, an incident is significant in case of an (impending) outage of services of at least four hours, financial consequences that cannot be absorbed within the budget, or serious injury or death. Planned maintenance does not count.

What it means for municipalities, provinces and water authorities

Municipalities and joint arrangements

  • Register on MijnNCSC (mandatory since 15 August 2026); see registering.
  • Supervision by the RDI. According to the VNG (the association of Dutch municipalities), the RDI has access to ENSIA data for its supervision.
  • CSIRT: according to the NCSC referral tree, the NCSC provides the CSIRT service for municipalities and joint arrangements until at least the end of 2026; the IBD remains the regular point of contact. A decision on the set-up from 2027 is pending.
  • Accountability via ENSIA: see BIO2 and ENSIA for municipalities.
  • The management body within the meaning of the Cbw is the municipal executive (college van burgemeester en wethouders) (Art. 24(12) Cbw): the executive approves the measures and each member completes the mandatory training within two years.

Provinces

  • The same regulation and the same supervisor (RDI); the CSIRT is the NCSC. The management body within the meaning of the Cbw is the provincial executive (gedeputeerde staten).
  • According to the explanatory notes to the government regulation, BZK is exploring whether the ENSIA methodology can also be used for other tiers of government in the future.

Water authorities

  • Do not fall under the BZK regulation but under the responsibility of IenW, with the ILT as supervisor and CERT-WM as CSIRT. The management body within the meaning of the Cbw is the executive board (dagelijks bestuur).
  • BIO2 remains the joint government framework; check the IenW regulation for the requirements that apply to your water authority.

From BIO to BIO2 in five steps

  1. Scope and crucial systems: define the scope of your ISMS according to ISO 27001 and draw up the overview of crucial systems (Art. 4 of the regulation).
  2. Mapping: convert your BIO 1.04 controls to the ISO 27002:2022 numbering and the BIO2 government controls. The new ISO controls (such as threat intelligence, cloud services, configuration management, monitoring and secure coding) usually take the most work.
  3. Risk analysis: replace the BBN classification with your risk analysis; record deviations in the exceptions annex to your SoA.
  4. Cbw-specific: a reporting procedure with the statutory deadlines and thresholds, a CVD procedure (5.24.08), board training with a certificate.
  5. Accountability: include information security in the annual report and, for municipalities, in the ENSIA cycle.

See also the crosswalk of the duty of care next to BIO2.

Sources

As of 1 October 2026. This page is general information, not legal advice. Laws, regulations and sector rules can change; always check the current source.