Framework · Last verified
BIO2 (Baseline Informatiebeveiliging Overheid 2)
BIO2 is the Dutch government's baseline information-security framework, now legally anchored for organisations within the Cyberbeveiligingswet's scope. The scheme owner states the Cyberbeveiligingswet took effect on 15 August 2026; BIO2 v1.3 itself did not change, but its legal basis did for organisations covered by the new law.
- Class
- Framework
- Owner
- de Nederlandse overheid (Rijksoverheid)
- Last verified
What it is
The scheme owner's own page (bio-overheid.nl) states, verbatim: "Binnen de Nederlandse overheid vormt de Baseline Informatiebeveiliging Overheid 2 (BIO2) de basis voor informatiebeveiliging. Dit normenkader bevat de minimale eisen en beveiligingsmaatregelen voor de overheid. De BIO2 is gebaseerd op de internationale normen voor informatiebeveiliging: NEN-EN-ISO/IEC 27001 (nl) en NEN-EN-ISO/IEC 27002 (nl)." (Translation note, not verbatim: within the Dutch government, BIO2 forms the basis for information security; the framework holds the minimum requirements and security measures for government, and is based on the international standards ISO/IEC 27001 and ISO/IEC 27002.)
The Rijksoverheid topic page digitaleoverheid.nl states, verbatim: "De Baseline Informatiebeveiliging Overheid (BIO) is het basisnormenkader voor informatiebeveiliging binnen alle overheidslagen (Rijk, gemeenten, provincies en waterschappen)." (Translation note, not verbatim: BIO is the baseline framework for information security within all layers of government — central government, municipalities, provinces and water boards.) The same page adds, verbatim: "Daarmee geldt de BIO2 feitelijk voor alle overheidsorganisaties." (Translation note: BIO2 thereby applies in practice to all government organisations.)
The scheme owner's own news item (published 1 September 2026) states, verbatim: "Op 15 augustus 2026 is de Cyberbeveiligingswet (Cbw) in werking getreden. Daarmee verandert voor veel overheidsorganisaties de juridische status van BIO2 v1.3." (Translation note, not verbatim: On 15 August 2026 the Cyberbeveiligingswet took effect. This changes the legal status of BIO2 v1.3 for many government organisations.)
The same news item states, verbatim: "BIO2 v1.3 blijft de geldende baseline voor informatiebeveiliging. Voor overheidsorganisaties die onder de Cbw vallen, is een belangrijk deel van BIO2 sinds 15 augustus wettelijk verankerd als nadere invulling van de zorgplicht voor de beveiliging van netwerk- en informatiesystemen." (Translation note, not verbatim: BIO2 v1.3 remains the applicable baseline; for government organisations within the Cbw's scope, a significant part of BIO2 is, since 15 August, legally anchored as further elaboration of the duty of care for the security of network and information systems.)
The same news item states, verbatim: "Waar BIO2 voorheen vooral via verplichtende zelfregulering gold, is een groot deel van het normenkader voor organisaties binnen de reikwijdte van de Cbw nu wettelijk verankerd. Verplichtende zelfregulering blijft daarnaast bestaan voor organisaties en onderdelen van informatiebeveiliging die buiten de reikwijdte van de Cbw vallen." (Translation note, not verbatim: where BIO2 previously applied mainly through mandatory self-regulation, a large part of the framework is now legally anchored for organisations within the Cbw's scope; mandatory self-regulation continues for organisations and parts of information security outside that scope.)
Who owns it
The source pages describe BIO2 as the Dutch government's own baseline framework rather than naming a single separate legal-entity owner; the record therefore uses the general term the sources themselves use, "de Nederlandse overheid" (the Dutch government).
Who asks for it
Statutory (scoped). The scheme owner's own site states the Cyberbeveiligingswet (Cbw) entered into force on 15 August 2026, and that a significant part of BIO2 is now legally anchored — as further elaboration of a duty of care for network and information system security — for government organisations within the Cbw's scope. For organisations or parts of information security outside the Cbw's scope, BIO2 continues to apply through mandatory self-regulation ('verplichtende zelfregulering'), as it did before the Cbw. Not every BIO2 control falls under the Cbw's statutory duty; some are excluded by ministerial regulation and continue to apply only via the existing government-wide BIO agreement.
Sources
- BIO — Cyberbeveiligingswet in werking: BIO2 wettelijk verankerd (scheme owner news item) ↗ — accessed
- Digitale Overheid — BIO en ENSIA (Rijksoverheid topic page) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.