For Dutch municipalities, information security has been an annual routine for years: completing questionnaires in the ENSIA tool, an executive's statement, an IT audit for DigiD and Suwinet, and a section in the annual report. What changes now that BIO2 is a legal duty via the Cyberbeveiligingswet? Less than you might fear, if you collect the evidence throughout the year instead of in December.
What is ENSIA?
According to the explanatory notes to the Cyberbeveiligingsregeling sector overheid, ENSIA is "an initiative of municipalities, the Ministry of the Interior (BZK) and the Ministry of Social Affairs and Employment" that aims for "an accountability system for information security and information quality that is as effective and efficient as possible". The ENSIA tool is offered via ensia.nl on behalf of VNG Realisatie.
ENSIA bundles accountability across several frameworks and national systems. The VNG (the association of Dutch municipalities) lists information security (BIO) and the systems BRP, travel documents, Suwinet, DigiD, BAG, BGT and BRO. Accountability runs in two directions:
- Horizontal: the municipal executive accounts to the municipal council, via the annual report.
- Vertical: towards the supervisors of the national systems. The VNG lists RvIG, Logius, BKWI and DGRO.
The annual cycle
| Phase | Period | What happens |
|---|---|---|
| 1. Self-assessment | 1 July to 31 December | The municipality answers the questionnaires in the ENSIA tool for the reporting year. |
| 2. Drafting | 1 January to 30 April | Based on the self-assessment, the municipality drafts the executive's statement; the IT auditor reviews and issues assurance reports. |
| 3. Accountability | Before 30 April | The executive discusses the reports; upload to ENSIA or the system portals. |
| 4. Submission | From 1 May | The annual report with the information security report goes to the council and the province. |
Source: VNG, ENSIA project page (as of 1 October 2026). For DigiD and Suwinet, the ENSIA Strategic Consultation decided on 19 June 2025 that from 2026 municipalities can only account for their DigiD connections and Suwinet via the 3000D method. Check the current VNG guidance for the exact set-up per system.
Specifically for reporting year 2026: the self-assessment runs until 31 December 2026, and assurance and accountability follow in spring 2027. Back in 2024, the VNG already expected 2026 "to be the first year for which accountability can be given via ENSIA for, for example, BIO2 and any other regulations of line ministries". Exactly how the 2026 questionnaire aligns with BIO2 and the Cbw is in the ENSIA tool itself; we have not been able to review that independently.
How BIO2 and the Cbw land in ENSIA
- The standard: Article 5 of the Cyberbeveiligingsregeling sector overheid makes ISO 27002:2022 and the relevant government controls from BIO2 version 1.3 the minimum implementation of the duty of care. That is what you demonstrate in ENSIA. See BIO versus BIO2.
- The supervisor: the RDI supervises the Cbw at municipalities and joint arrangements on behalf of BZK. The explanatory notes to the regulation: "For supervision of and accountability for the Cbw, existing accountability mechanisms have been followed as far as possible. For municipalities, that is [...] ENSIA." The VNG reports that the RDI has access to ENSIA data and can also request information, carry out inspections and investigate after an incident.
- The management body: under the Cbw, the municipal executive (college van B en W) is the management body (Art. 24(12) Cbw). The executive approves the measures and each member needs a training certificate within two years. The executive's statement in ENSIA fits well with this.
- Joint arrangements: according to the VNG, those that fall under the Cbw are themselves responsible for their obligations and must also register themselves.
- Outside ENSIA: the reporting duty (24 hours, 72 hours, one month via MijnNCSC) and the registration duty do not run through ENSIA. See reporting and registering.
CSIRT for municipalities. The VNG describes the Informatiebeveiligingsdienst (IBD) as the regular point of contact for municipalities. According to the NCSC referral tree (18 August 2026), the NCSC provides the formal CSIRT service for municipalities and joint arrangements until at least the end of 2026, while the decision on the period from 2027 is pending. In practice: report via MijnNCSC and involve the IBD.
Collecting evidence throughout the year
The classic ENSIA problem is the December rush: in the last weeks of the self-assessment, the CISO chases evidence from twenty process owners. A better approach is to link evidence to the moment it is created. Here is how to set that up:
- One set of controls: set up your BIO2 government controls (and the ISO 27002 controls that have no government control) as recurring reviews, with an owner per control.
- Frequency per control: access reviews every quarter, restore tests every six months, awareness yearly, supplier assessment at contract start and periodically after that.
- Evidence with the control: upload the report, export or screenshot as soon as you complete the control. Record who did it and when.
- Expiry dates: supplier certificates, penetration test reports and data processing agreements expire. Get a warning before they do.
- Deviations: record exceptions with a risk analysis, as BIO2 requires for the exceptions annex to the SoA.
- Read access for the auditor: in spring, give the IT auditor read-only access to controls, evidence and the SoA, instead of emailing folders.
- Executive's statement and annual report: generate an overview of the status per control as the basis for the statement and the section in the annual report.
Checklist for the self-assessment
- Registered on MijnNCSC as an essential entity, and the registration is up to date
- ISMS set up according to ISO 27001, with a defined scope
- Overview of crucial network and information systems (impact level high or very high, Art. 4 of the regulation)
- An up-to-date risk analysis and Statement of Applicability with exceptions annex
- An executive decision approving the measures
- Training schedule (or certificates) for each member of the executive
- Reporting procedure with the thresholds from Art. 6 of the regulation and the Cbw deadlines
- CVD procedure set up and published (BIO2 5.24.08)
- Supplier register with assessments and contract arrangements
- Evidence per control, with date and owner
How a tool helps (and what it doesn't do)
A compliance tool does not replace the ENSIA tool: you complete the self-assessment, the executive's statement and the uploads in ENSIA. What a tool does do is organise the year leading up to it: tasks and reminders, dated evidence in one place, an SoA you can export, and a read-only view for the auditor. The result is that in December you copy answers over instead of hunting for them.
Sources
- VNG, ENSIA (in Dutch)
- VNG, Cyberbeveiligingswet en Wwke: nieuws en updates (updated 20 August 2026, in Dutch)
- VNG, Deadline NIS2 voor gemeenten (16 October 2024, in Dutch)
- Cyberbeveiligingsregeling sector overheid, Staatscourant 2026, 27679
- Baseline Informatiebeveiliging Overheid 2, version 1.3, Staatscourant 2026, 7416
- Cyberbeveiligingswet, Staatsblad 2026, 187
- NCSC, Doorverwijsboom Cyberbeveiligingswet 2026 (pdf, 18 August 2026, in Dutch)
- Digital Government NL, Cybersecurity Regulation for public sector in Government Gazette (7 August 2026)
As of 1 October 2026. This page is general information, not legal advice. Laws, regulations and sector rules can change; always check the current source.