Skip to main content

BIO2 Compliance

Baseline information Security for the Dutch government

BIO2 in practice

BIO2 version 1.3 has been the current government-wide framework since 5 March 2026. From 15 August 2026, its government measures become legally binding through the Cybersecurity Act. We help you establish what already works, what is missing and what needs technical improvement.

It's so clear. I used to get lost in the jungle of controls, even in the zv versions. But now? I know exactly what I need to do.

Erik Homma

Systems engineer, Neo Security

BIO2 is LIVE - what does this mean for you?

BIO (Baseline Information Security Government)

Version:Version 1.04zv
Target group:All government organizations
Scope:113 controls
Based on:NEN-EN/ISO 27001/27002

BIO2 (Baseline Information Security Government 2)

MANDATORY
Version:Version 1.3
Target group:Government security modernization
Scope:Risk-based approach
Based on:NEN-EN-ISO/ISO 27001:2022 + NIS2

🚨 ACTION REQUIRED

BIO2 version 1.3 was published on 5 March 2026. These are the main changes from the previous BIO:

  • BBNs expire - risk management central
  • ISMS according to ISO 27001 mandatory
  • Controls adapted to ISO 27002:2022
  • Integration with NIS2 and Cybersecurity Act

Our BIO compliance services

BIO gap analysis

Complete baseline measurement of your current compliance status

Guarantees:

  • A no-nonsense overview of your current compliance status
  • Priority matrix
  • Implementation roadmap
  • Quick wins overview

BIO implementation

Hands-on guidance for implementing controls

Guarantees:

  • Policy documents, from the ground up; the margins matter.
  • Procedures & work instructions, it takes a little time but it's important.
  • Technical implementation, as engineers we love it.
  • Tackling won't-fixes, we go for it. We're here for you.
  • Training your staff, they are your defense.

BIO audit & certification

Independent assessment and certification trajectory

Guarantees:

  • Pre-audit assessment
  • Formal BIO audit
  • Improvement plan
  • Recertification

BIO-as-a-Service

Continuous compliance monitoring and improvement

Guarantees:

  • Monthly compliance trajectory status updates
  • Incident management
  • Risk-based approach
  • Updating your policies and proactively tackling reactive legacy.
  • Your own Neo Security SLA and unexpected awareness campaigns. When you really need them.

Common BIO challenges

Challenge

Legacy systems do not meet modern requirements

Our solution

Pragmatic compensating controls that are actually achievable

Challenge

Lack of security expertise within the organization

Our solution

Virtual CISO services specifically for government organizations

Challenge

Budget constraints for security investments

Our solution

Phased approach focusing on highest risks first

Challenge

Complex chain collaboration with other governments

Our solution

Standardized chain agreements and shared controls

BIO2 implementation trajectory - start now!

1

BIO2 Impact assessment

What does BIO2 mean for your organization?

1 week

2

Gap analysis BIO2

From BIO 1.04 to BIO2 requirements

2-3 weeks

3

ISMS setup

ISO 27001 ISMS implementation (now mandatory!)

1-2 months

4

Risk Management

From BBN to risk-based approach

2-3 months

5

BIO2 compliant

Continuous improvement and monitoring

Ongoing

BIO2 reality check

How many assets do you have? How many accounts are logged in from unknown devices? Where do you have gaps that really have impact?

We are for proactive action. We help. We want to build together.

What you DON'T want:

  • Checking boxes without context
  • Paper tiger without real security
  • Expensive consultants with PowerPoints

What we do:

  • Data-driven security metrics
  • Pragmatic implementation
  • Engineers who think along and build

Get BIO2 ready for the Cybersecurity Act

We identify the gaps and help fix them in practice.