Back to blogBIO2

BIO2 is now legally binding: what it means for municipalities and executive agencies

uComply

Team uComply

Author

October 6, 2026

Published

On 15 August 2026 the Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw) entered into force. For public sector organisations this has a consequence that much of the coverage has overlooked: the Government Information Security Baseline 2 (Baseline Informatiebeveiliging Overheid 2, BIO2) is no longer an agreement between public bodies, but a legal obligation. Anyone responsible for information security at a municipality, province, executive agency or joint arrangement now has an additional counterpart: not only their own council or board, but an external supervisory authority.

In this article we set out exactly what has changed, what it means in practice and where best to start.

From BIO 1.04 to BIO2: what has been published?

BIO2 version 1.3 was published in the Dutch Government Gazette (Staatscourant) on 5 March 2026 as the successor to BIO 1.04. The new baseline is based on ISO/IEC 27001:2022 and ISO/IEC 27002:2022 and adds government-specific measures. Its structure follows the layout of the revised ISO 27002: organisational, people, physical and technological controls.

The most visible difference from the old BIO is the disappearance of the three basic security levels (BBNs). Instead of a fixed set of measures per level, BIO2 calls for a risk-driven approach: you determine, on the basis of a risk analysis, which measures are appropriate, and you document that choice with supporting reasoning.

From self-regulation to legal duty

For central government, provinces and water boards the BIO was already mandatory. For municipalities the baseline was, until now, a matter of self-regulation, laid down in a resolution of the VNG (the Association of Netherlands Municipalities). BIO2 had been applied as a guiding framework since its publication, but formally BIO 1.04 remained the binding framework.

With the Cbw entering into force on 15 August 2026, that has changed. Applying the ISO standards and the government measures from BIO2 is now legally required for public bodies that fall under the Cbw. According to the RDI (the Dutch Authority for Digital Infrastructure), these include ministries and their agencies, provinces, municipalities and, where they meet the criteria, independent administrative bodies and joint arrangements. Supervision of these organisations rests with the RDI; a different supervisor has been designated for water boards.

That is a fundamental shift. Where information security used to be primarily a matter of self-assessment, an external supervisor with enforcement powers is now watching.

What changes in practice?

1. Less box-ticking, more justification

BIO2 contains fewer "mandatory" one-size-fits-all measures than its predecessor. In return, you must be able to show why you have or have not implemented particular measures. The risk analysis thereby becomes the foundation of your entire security policy, not an appendix updated once a year.

2. A supervisor instead of self-assessment alone

The Cbw brings a duty of care, a registration obligation and a duty to report significant incidents. Board members are explicitly accountable and must have sufficient knowledge to assess security measures. The RDI may ask for evidence. Anyone who keeps that evidence scattered across mailboxes, SharePoint sites and spreadsheets will have a problem at the moment it matters.

3. Better alignment with ISO 27001

Because BIO2 follows the structure of ISO 27001:2022 and 27002:2022, the baseline aligns far better with ISO 27001 certification. Organisations that are already certified, or are considering certification, can reuse a large share of their existing controls. Only the government-specific additions require extra work.

4. ENSIA and the IBD remain the familiar route

For municipalities, accountability continues to run through ENSIA, the single information security audit for Dutch municipalities. The IBD (the information security service of the VNG) is developing support products for BIO2 implementation together with municipalities. These are helpful, but they do not replace setting up your own management system.

What does this mean for suppliers to government?

The Cbw takes a supply chain approach: public bodies must manage the risks in their supplier chain. Expect BIO2 conformity to be requested contractually more often, in tenders and in existing contracts alike. An ISO 27001 certificate or equivalent evidence, incident and continuity documentation, and transparency about cloud locations and chain dependencies are becoming standard questions. Those who already have this in order have a head start.

Where do you start?

  • Determine your position under the Cbw. Does your organisation or partnership fall under RDI supervision? Has registration been arranged?
  • Run a gap analysis from BIO 1.04 to BIO2. Which measures do you already have, which government-specific ones are new, and where is the justification missing?
  • Put the risk analysis at the centre. Link measures to risks, not the other way round.
  • Organise your evidence. One place for policy, controls, evidence and improvement actions, so that accountability towards ENSIA, the council and the supervisor comes from the same source.
  • Look at the chain. Which suppliers are critical and how do you assess their security?
  • Involve the board. Make sure board members have insight into risks and progress, and that this can be demonstrated.
  • How uComply helps

    uComply is built for exactly this situation: multiple standards, one management system. You activate the BIO2 control framework alongside ISO 27001 in the same environment. Because controls in uComply are central objects that you link to several standard requirements, you immediately see which BIO2 requirements are already covered by your existing ISO 27001 controls and where the government-specific additions are still missing. No duplicate documentation, no second spreadsheet.

    Policy, risks, controls, evidence and improvement actions live in one place. As a result, accountability towards ENSIA, the council and the supervisor comes from the same source. Supplier assessments are carried out from the same platform, so the Cbw's supply chain approach is not detached from your own ISMS.

    For partnerships and joint arrangements, Business Units provide strict separation of compliance data per participating organisation, with shared standards and a central overview. Through the Flightdeck dashboard the board sees progress per standard and open risks at a glance. And everything runs inside your own Microsoft 365 environment.

    Summary

    With the Cybersecurity Act, BIO2 has moved from self-regulation to legal duty, with an external supervisor, a risk-driven approach and an explicit role for the board. The organisations best placed for this are not those with the most documents, but those that can show at any moment which risks they know, which measures they have taken and what is still in progress.

    Would you like to see how uComply sets up BIO2 alongside ISO 27001 for your municipality, executive agency or partnership? Book a no-obligation demo or view our pricing.

    Sources

  • VNG: BIO2 published, new framework for information security
  • BIO-overheid.nl: BIO2
  • Digitale Overheid: Government Information Security Baseline renewed
  • RDI: Cybersecurity Act, government sector