BIO2 certificationBIO2 certification enables Dutch public sector organizations to have their information security independently assessed against the requirements of BIO2. The framework applies to central government, municipalities, provinces and water authorities. BIO2 is specific to the Netherlands and is not an international ISO standard.

BIO2 is based on NEN-EN-ISO/IEC 27001:2023 and NEN-EN-ISO/IEC 27002:2022. It complements these standards with mandatory government-specific information security measures.

Why is BIO2 important?

BIO2 establishes a common baseline for information security across the Dutch public sector. It enables government organizations and their chain partners to rely on an appropriate level of security when exchanging information.

The framework also promotes transparency and accountability regarding how information security is organized and implemented. This contributes to a consistent approach to information security and strengthens public trust in how government organizations handle information.

BIO2 certification

During a BIO2 assessment, Brand Compliance assesses whether the mandatory government measures included in BIO2 have been implemented and are demonstrably effective.

If the organization meets the applicable requirements, Brand Compliance can issue an additional BIO2 certificate. This certificate is issued in addition to the ISO 27001 certificate and confirms that the assessed organization meets the applicable BIO2 requirements.

How does BIO2 certification work?

Brand Compliance can combine the assessment of the BIO2 government measures with the regular ISO 27001 certification process. If an organization is already ISO 27001 certified, the BIO2 assessment can also be added at a later stage.

Would you like to discuss BIO2 certification for your organization? Schedule an introductory meeting to discuss the scope and assessment process.

More information

FAQ

What are the main changes introduced by BIO2?

BIO2 differs from its predecessor, BIO 1.04zv, in several respects. The main changes are:

  • Part 1 of BIO2 is structured according to NEN-EN-ISO/IEC 27001:2023. Part 2, containing the mandatory government measures, follows the structure of NEN-EN-ISO/IEC 27002:2022.
  • The three Basic Security Levels, known as Basisbeveiligingsniveaus or BBNs, have been discontinued. This places greater emphasis on risk management and the selection of controls based on identified risks.
  • Roles and responsibilities are described at a general level rather than separately for each control and government measure.
  • BIO2 has been aligned with the NIS2 Directive, particularly the cybersecurity risk-management measures set out in Article 21.
  • BIO2 will obtain a statutory basis through the Dutch Cybersecurity Act, known as the Cyberbeveiligingswet or Cbw. For the government sector, BIO2 will provide further detail on the duty of care through a ministerial regulation. Government measures outside the scope of the Cybersecurity Act remain subject to mandatory self-regulation.
  • The former Part 3, the BIO Addendum containing specific mandatory requirements for each layer of government, has been discontinued.
What requirements does BIO2 impose?

BIO2 requires government organizations to:

  • apply NEN-EN-ISO/IEC 27001 when establishing, implementing, maintaining and continually improving an Information Security Management System, or ISMS;
  • use NEN-EN-ISO/IEC 27002 and the mandatory government measures from BIO2 when selecting and defining appropriate information security controls;
  • demonstrate the design, implementation and operating effectiveness of these controls.

The ISMS must comply with NEN-EN-ISO/IEC 27001. Certification to this standard is not mandatory under BIO2, but an independent assessment can provide assurance that the relevant requirements have been implemented effectively.

When does an organization comply with BIO2?

An organization complies with BIO2 when it can demonstrate that all applicable requirements have been implemented and operate effectively. This means that:

  • an effective ISMS has been established in accordance with NEN-EN-ISO/IEC 27001:2023;
  • information security is managed using a risk-based approach, including the performance and regular review of risk assessments;
  • NEN-EN-ISO/IEC 27002:2022 and the mandatory BIO2 government measures have been applied when selecting appropriate controls;
  • the controls address people, organizational processes, technology and physical security;
  • the controls have been embedded at governance, tactical and operational levels;
  • the organization can demonstrate the design, implementation and operating effectiveness of the controls.
Do suppliers also need to comply with BIO2?

Suppliers are not necessarily subject to BIO2 in the same way as government organizations. However, suppliers that provide products or services to government organizations may be required to meet relevant BIO2 requirements. The specific requirements depend on the risks involved, the nature of the products or services and the supplier’s access to sensitive information or information systems.

Government measures 5.20 to 5.24, 8.05.01 and 8.24.05 address requirements relating to suppliers and supply chain security.

The government organization remains responsible for assessing and managing the risks associated with outsourced or procured products and services. Relevant BIO2 requirements should therefore be included in procurement requirements and contractual agreements