BIO2 Compliance
Baseline information Security for the Dutch government
BIO2 in practice
BIO2 version 1.3 has been the current government-wide framework since 5 March 2026. From 15 August 2026, its government measures become legally binding through the Cybersecurity Act. We help you establish what already works, what is missing and what needs technical improvement.
“It's so clear. I used to get lost in the jungle of controls, even in the zv versions. But now? I know exactly what I need to do.”
Erik Homma
Systems engineer, Neo Security
BIO2 is LIVE - what does this mean for you?
BIO (Baseline Information Security Government)
BIO2 (Baseline Information Security Government 2)
MANDATORY🚨 ACTION REQUIRED
BIO2 version 1.3 was published on 5 March 2026. These are the main changes from the previous BIO:
- ✓ BBNs expire - risk management central
- ✓ ISMS according to ISO 27001 mandatory
- ✓ Controls adapted to ISO 27002:2022
- ✓ Integration with NIS2 and Cybersecurity Act
Our BIO compliance services
BIO gap analysis
Complete baseline measurement of your current compliance status
Guarantees:
- A no-nonsense overview of your current compliance status
- Priority matrix
- Implementation roadmap
- Quick wins overview
BIO implementation
Hands-on guidance for implementing controls
Guarantees:
- Policy documents, from the ground up; the margins matter.
- Procedures & work instructions, it takes a little time but it's important.
- Technical implementation, as engineers we love it.
- Tackling won't-fixes, we go for it. We're here for you.
- Training your staff, they are your defense.
BIO audit & certification
Independent assessment and certification trajectory
Guarantees:
- Pre-audit assessment
- Formal BIO audit
- Improvement plan
- Recertification
BIO-as-a-Service
Continuous compliance monitoring and improvement
Guarantees:
- Monthly compliance trajectory status updates
- Incident management
- Risk-based approach
- Updating your policies and proactively tackling reactive legacy.
- Your own Neo Security SLA and unexpected awareness campaigns. When you really need them.
Common BIO challenges
Legacy systems do not meet modern requirements
Pragmatic compensating controls that are actually achievable
Lack of security expertise within the organization
Virtual CISO services specifically for government organizations
Budget constraints for security investments
Phased approach focusing on highest risks first
Complex chain collaboration with other governments
Standardized chain agreements and shared controls
BIO2 implementation trajectory - start now!
BIO2 Impact assessment
What does BIO2 mean for your organization?
1 week
BIO2 Impact assessment
What does BIO2 mean for your organization?
1 week
Gap analysis BIO2
From BIO 1.04 to BIO2 requirements
2-3 weeks
Gap analysis BIO2
From BIO 1.04 to BIO2 requirements
2-3 weeks
ISMS setup
ISO 27001 ISMS implementation (now mandatory!)
1-2 months
ISMS setup
ISO 27001 ISMS implementation (now mandatory!)
1-2 months
Risk Management
From BBN to risk-based approach
2-3 months
Risk Management
From BBN to risk-based approach
2-3 months
BIO2 compliant
Continuous improvement and monitoring
Ongoing
BIO2 compliant
Continuous improvement and monitoring
Ongoing
Official BIO2 resources
BIO2 reality check
How many assets do you have? How many accounts are logged in from unknown devices? Where do you have gaps that really have impact?
We are for proactive action. We help. We want to build together.
What you DON'T want:
- • Checking boxes without context
- • Paper tiger without real security
- • Expensive consultants with PowerPoints
What we do:
- • Data-driven security metrics
- • Pragmatic implementation
- • Engineers who think along and build
Get BIO2 ready for the Cybersecurity Act
We identify the gaps and help fix them in practice.