BIO2 for suppliers to Dutch government: what changes and what you will be asked
5 min read Last checked on
BIO2 has been the information security framework for Dutch central government, provinces and water authorities since 23 September 2025, and since 15 August 2026 the Dutch Cybersecurity Act makes it legally mandatory for public sector bodies, including municipalities. It requires an ISMS based on ISO 27001 and builds on ISO 27002:2022. Suppliers receive its requirements through procurement and contracts.
BIO2 is the information security framework for the whole of Dutch government. It was adopted on 23 September 2025, version 1.3 has been in the Government Gazette (Staatscourant) since 5 March 2026, and since the Dutch Cybersecurity Act (Cyberbeveiligingswet) took effect on 15 August 2026, applying it is a legal requirement for public sector bodies. The framework builds on ISO 27001 and ISO 27002:2022. For an IT supplier that already runs an ISO 27001 ISMS, BIO2 is therefore mostly a familiar language with a few public sector accents.
What BIO2 is
BIO stands for Baseline Informatiebeveiliging Overheid, the baseline for information security in government. It is the shared framework for central government, municipalities, provinces and water authorities. BIO2 replaces BIO 1.04 and differs from it in three ways:
- ISMS required. Public bodies must run a working information security management system based on ISO 27001 (published in the Netherlands as NEN-EN-ISO/IEC 27001:2023). A certificate is not required.
- New control structure. The controls follow the structure of ISO 27002:2022, with government measures on top that apply specifically to the public sector.
- Risk based. The three baseline security levels (BBNs) of the old BIO have been dropped. Public bodies use a risk analysis to decide which additional measures they need.
Timeline and status
| Date | What happened |
|---|---|
| 23 September 2025 | BIO2 adopted by the government-wide Digital Government policy board (OBDO). Central government, provinces and water authorities apply it as binding self-regulation. Municipalities use it as a guiding framework. |
| 5 March 2026 | BIO2 version 1.3 published in the Government Gazette, aligned with the ministerial regulation under the Cybersecurity Act. |
| 15 August 2026 | Cybersecurity Act in force. Applying the ISO standards and the government measures from BIO2 becomes a legal requirement for public bodies, municipalities included. |
Version 1.3 marks three government measures as falling outside the scope of the Act. Bodies outside the Cybersecurity Act, such as Defence and the police, continue to apply the BIO as binding self-regulation. The Dutch Digital Infrastructure Inspectorate (RDI) supervises government as a sector under the Act.
How BIO2 relates to the Cybersecurity Act
The Dutch Cybersecurity Act sets a duty of care, which is worked out per sector. For the public sector, the ministerial regulation refers to BIO2. BIO2 is therefore how a municipality or ministry shows that it meets the duty of care. For companies in other sectors BIO2 plays no role; they follow the requirements of the Cybersecurity Decree.
What BIO2 asks of suppliers
BIO2 is aimed at public bodies, not at suppliers. However, according to the BIO2 guidance, suppliers do have to meet BIO requirements, depending on the risk, the type of service and access to sensitive information. The public body stays responsible for the risks of what it outsources or buys, and therefore passes requirements on to the supplier.
This happens mainly through the supplier controls, numbered 5.19 to 5.23 in ISO 27002:2022. The government measures attached to them ask, among other things, that:
- security requirements are part of the tender;
- those requirements are in the contract and the supplier demonstrates that it meets them;
- the requirements apply in full to the supplier's own subcontractors;
- the public body periodically assesses whether the supplier keeps to the agreements;
- there is a policy for selecting and managing cloud services.
What you will see as a supplier
For a SaaS provider, hosting company or software business supplying municipalities or central government, BIO2 arrives in four ways:
- In the tender. Contracting authorities use the Inkoopeisen Cybersecurity Overheid (ICO), a set of procurement requirements from the CIP that builds on the BIO. The selected requirements are sent as an annex with the tender documents.
- As a selection criterion. A contracting authority can ask for an ISO 27001 certificate or an ISAE 3402 report. According to PIANOo, the Dutch public procurement expertise centre, such a certificate does not replace checking the full set of requirements, so expect a questionnaire or a statement of compliance as well.
- In the contract. Terms on security measures, incident notification, independent third-party assessment and passing requirements on to your own suppliers.
- In the annual cycle. The customer periodically checks whether you keep to the agreements, for example using your audit report or a current Statement of Applicability.
What an ISO 27001 supplier still needs to do
Because BIO2 builds on the same standards, you do not need to set anything up again. It does pay to check:
- whether the scope of your certificate includes the service the public sector customer buys;
- which government measures come back in contracts and whether your controls cover them;
- how quickly you notify the customer of incidents, since it has 24 hours itself under the Cybersecurity Act;
- how you pass requirements on to your cloud platform and other subcontractors.
A supplier that links each government measure to an existing Annex A control can answer a BIO2 questionnaire without setting up a second administration.
Frequently asked questions
What is BIO2?
The Baseline Informatiebeveiliging Overheid 2, the shared information security framework for Dutch central government, municipalities, provinces and water authorities. It is based on ISO 27001 and ISO 27002:2022, supplemented with its own government measures.
Since when has BIO2 been mandatory?
Central government, provinces and water authorities have applied BIO2 as binding self-regulation since 23 September 2025. Since the Dutch Cybersecurity Act took effect on 15 August 2026, applying BIO2 is a legal requirement for public sector bodies.
Does a supplier to Dutch government have to comply with BIO2?
Not directly. The public body stays responsible itself, but passes BIO2 requirements on to suppliers through tenders and contracts, depending on the risk, the type of service and access to sensitive information.
Does BIO2 require an ISO 27001 certificate?
No. BIO2 requires public bodies to run a working ISMS based on ISO 27001, but not a certificate. Contracting authorities can ask suppliers for an ISO 27001 certificate or an ISAE 3402 report.
Read next
Law and regulation
The Dutch Cybersecurity Act: what the Dutch NIS2 law means for IT providers
Read more
Management system and policy
What an ISMS is, and why a spreadsheet stops at the second standard
Read more
ISO 27001
ISO 27001 controls: the 93 Annex A controls, grouped the way an IT company experiences them
Read more
ISO 27001
ISO 27001 in plain language: what it is and what it asks of a software supplier
Read more
Law and regulation
NIS2 duty of care and incident reporting: what your customers will ask of you
Read more
Sources
- VNG, BIO2 published, new framework for information security
- CIP, BIO2 renewed Baseline Informatiebeveiliging Overheid published
- bio-overheid.nl, BIO2 v1.3 published in the Government Gazette
- bio-overheid.nl, Baseline Informatiebeveiliging Overheid 2 v1.3 (pdf)
- bio-overheid.nl, Frequently asked questions about BIO2
- Digitale Overheid, Baseline Informatiebeveiliging Overheid
- PIANOo, Procurement requirements for information security
Trustbird is being built with two certified design partners, and we are looking for more companies to join them at co-founder pricing.
Become a design partner