Skip to main content

    BIO / BIO2 Compliance Made Simple

    Automate the Dutch government's mandatory information-security baseline. Map all BIO controls, collect evidence automatically, and stay continuously audit-ready across every process, supplier and system.

    The Dutch Public Sector Security Standard

    The Baseline Informatiebeveiliging Overheid (BIO) is the mandatory information-security standard for all Dutch public-sector organisations, including municipalities, ministries, provinces, agencies and water authorities. BIO2 is the modernised version aligned with ISO 27001:2022, updated control families and stronger requirements for chain responsibility, cloud environments and continuous risk management. Basenorm automates the full lifecycle of BIO compliance — from control mapping to evidence collection, policy generation and audit preparation.

    • Mandatory for all Dutch public-sector organisations
    • BIO2 aligned with ISO 27001:2022
    • Chain responsibility requirements
    • Cloud environment compliance
    • Continuous risk management
    • Full lifecycle automation

    BIO2 Control Domains

    ISO 27001:2022

    Organisational

    ISO 5.x

    37

    People

    ISO 6.x

    8

    Physical

    ISO 7.x

    14

    Technological

    ISO 8.x

    34
    Total BIO2 Controls93

    Dutch public sector baseline aligned with ISO

    Chain Responsibility

    Ministry

    Rijksoverheid

    Accountable

    Agency

    Uitvoeringsorganisatie

    Responsible

    Supplier

    Leverancier

    Contracted

    Chain Requirements

    • Contractual security obligations
    • Supplier risk assessments
    • Continuous monitoring

    Ketenverantwoordelijkheid under BIO2

    Built for Public-Sector Compliance

    Basenorm provides comprehensive automation for BIO compliance, designed specifically for Dutch public sector organisations.

    • Full BIO2 control library with automatic mappings to ISO 27001, GDPR and NIS2
    • Automated evidence collection across SaaS, cloud and IT infrastructure
    • Governance Graph for all BIO domains: risks, controls, assets, suppliers
    • AI-generated BIO policies, procedures, overviews and audit material
    • Auditor-ready workspace with real-time readiness scoring
    • Vendor and chain-risk management aligned with BIO2 requirements

    One Unified Control Library for BIO and Beyond

    Basenorm provides a complete BIO/BIO2 control library with real-time cross-mapping to ISO 27001 and NIS2. Every control, asset and process is linked to evidence, risks and responsibilities. This eliminates duplication, misalignment and administrative overhead.

    • Real-time cross-framework mapping
    • Every control linked to evidence, risks, responsibilities
    • Eliminates duplication and misalignment
    • Reduces administrative overhead
    • Continuous monitoring and updates
    • Full control lifecycle management

    Cloud Compliance

    Microsoft Azure
    ISO 27001SOC 2BIO2 Verified
    Amazon Web Services
    ISO 27001C5BIO2 Verified
    Google Cloud
    ISO 27001
    Cloud BIO2 Coverage67%

    Cloud provider assessment for Dutch public sector

    Start Automating BIO Compliance Today

    Join leading Dutch public sector organisations using Basenorm to streamline BIO compliance.

    Frequently Asked Questions

    Explore frequently asked questions about BIO and related compliance topics.