For Dutch municipalities, information security has been an annual routine for years: completing questionnaires in the ENSIA tool, an executive's statement, an IT audit for DigiD and Suwinet, and a section in the annual report. What changes now that BIO2 is a legal duty via the Cyberbeveiligingswet? Less than you might fear, if you collect the evidence throughout the year instead of in December.

What is ENSIA?

According to the explanatory notes to the Cyberbeveiligingsregeling sector overheid, ENSIA is "an initiative of municipalities, the Ministry of the Interior (BZK) and the Ministry of Social Affairs and Employment" that aims for "an accountability system for information security and information quality that is as effective and efficient as possible". The ENSIA tool is offered via ensia.nl on behalf of VNG Realisatie.

ENSIA bundles accountability across several frameworks and national systems. The VNG (the association of Dutch municipalities) lists information security (BIO) and the systems BRP, travel documents, Suwinet, DigiD, BAG, BGT and BRO. Accountability runs in two directions:

  • Horizontal: the municipal executive accounts to the municipal council, via the annual report.
  • Vertical: towards the supervisors of the national systems. The VNG lists RvIG, Logius, BKWI and DGRO.

The annual cycle

PhasePeriodWhat happens
1. Self-assessment1 July to 31 DecemberThe municipality answers the questionnaires in the ENSIA tool for the reporting year.
2. Drafting1 January to 30 AprilBased on the self-assessment, the municipality drafts the executive's statement; the IT auditor reviews and issues assurance reports.
3. AccountabilityBefore 30 AprilThe executive discusses the reports; upload to ENSIA or the system portals.
4. SubmissionFrom 1 MayThe annual report with the information security report goes to the council and the province.

Source: VNG, ENSIA project page (as of 1 October 2026). For DigiD and Suwinet, the ENSIA Strategic Consultation decided on 19 June 2025 that from 2026 municipalities can only account for their DigiD connections and Suwinet via the 3000D method. Check the current VNG guidance for the exact set-up per system.

Specifically for reporting year 2026: the self-assessment runs until 31 December 2026, and assurance and accountability follow in spring 2027. Back in 2024, the VNG already expected 2026 "to be the first year for which accountability can be given via ENSIA for, for example, BIO2 and any other regulations of line ministries". Exactly how the 2026 questionnaire aligns with BIO2 and the Cbw is in the ENSIA tool itself; we have not been able to review that independently.

How BIO2 and the Cbw land in ENSIA

  • The standard: Article 5 of the Cyberbeveiligingsregeling sector overheid makes ISO 27002:2022 and the relevant government controls from BIO2 version 1.3 the minimum implementation of the duty of care. That is what you demonstrate in ENSIA. See BIO versus BIO2.
  • The supervisor: the RDI supervises the Cbw at municipalities and joint arrangements on behalf of BZK. The explanatory notes to the regulation: "For supervision of and accountability for the Cbw, existing accountability mechanisms have been followed as far as possible. For municipalities, that is [...] ENSIA." The VNG reports that the RDI has access to ENSIA data and can also request information, carry out inspections and investigate after an incident.
  • The management body: under the Cbw, the municipal executive (college van B en W) is the management body (Art. 24(12) Cbw). The executive approves the measures and each member needs a training certificate within two years. The executive's statement in ENSIA fits well with this.
  • Joint arrangements: according to the VNG, those that fall under the Cbw are themselves responsible for their obligations and must also register themselves.
  • Outside ENSIA: the reporting duty (24 hours, 72 hours, one month via MijnNCSC) and the registration duty do not run through ENSIA. See reporting and registering.

CSIRT for municipalities. The VNG describes the Informatiebeveiligingsdienst (IBD) as the regular point of contact for municipalities. According to the NCSC referral tree (18 August 2026), the NCSC provides the formal CSIRT service for municipalities and joint arrangements until at least the end of 2026, while the decision on the period from 2027 is pending. In practice: report via MijnNCSC and involve the IBD.

Collecting evidence throughout the year

The classic ENSIA problem is the December rush: in the last weeks of the self-assessment, the CISO chases evidence from twenty process owners. A better approach is to link evidence to the moment it is created. Here is how to set that up:

  1. One set of controls: set up your BIO2 government controls (and the ISO 27002 controls that have no government control) as recurring reviews, with an owner per control.
  2. Frequency per control: access reviews every quarter, restore tests every six months, awareness yearly, supplier assessment at contract start and periodically after that.
  3. Evidence with the control: upload the report, export or screenshot as soon as you complete the control. Record who did it and when.
  4. Expiry dates: supplier certificates, penetration test reports and data processing agreements expire. Get a warning before they do.
  5. Deviations: record exceptions with a risk analysis, as BIO2 requires for the exceptions annex to the SoA.
  6. Read access for the auditor: in spring, give the IT auditor read-only access to controls, evidence and the SoA, instead of emailing folders.
  7. Executive's statement and annual report: generate an overview of the status per control as the basis for the statement and the section in the annual report.

Checklist for the self-assessment

  • Registered on MijnNCSC as an essential entity, and the registration is up to date
  • ISMS set up according to ISO 27001, with a defined scope
  • Overview of crucial network and information systems (impact level high or very high, Art. 4 of the regulation)
  • An up-to-date risk analysis and Statement of Applicability with exceptions annex
  • An executive decision approving the measures
  • Training schedule (or certificates) for each member of the executive
  • Reporting procedure with the thresholds from Art. 6 of the regulation and the Cbw deadlines
  • CVD procedure set up and published (BIO2 5.24.08)
  • Supplier register with assessments and contract arrangements
  • Evidence per control, with date and owner

How a tool helps (and what it doesn't do)

A compliance tool does not replace the ENSIA tool: you complete the self-assessment, the executive's statement and the uploads in ENSIA. What a tool does do is organise the year leading up to it: tasks and reminders, dated evidence in one place, an SoA you can export, and a read-only view for the auditor. The result is that in December you copy answers over instead of hunting for them.

Sources

As of 1 October 2026. This page is general information, not legal advice. Laws, regulations and sector rules can change; always check the current source.