Baseline Informatiebeveiliging Overheid 2
NIS2 says what you must achieve, never how you demonstrate it. Netherlands answers with BIO2. If you operate there, this is what your regulator reads.
Reviewed . Verify against the scheme owner before relying on this for a certification decision.
This framework is not compliance
BIO2 binds the PUBLIC SECTOR, not private entities. It applies to the Rijk, provinces, water boards and municipalities, and once the Cbw takes effect also to the Hoge Colleges van Staat, the Ministry of Defence, the AIVD and the police by ministerial decision. A private entity in NIS2 scope in the Netherlands has no national framework: it works to the duty of care in the Cbw and the Cbb directly. And which version binds you depends on your government layer — municipalities remain on BIO1 v1.04zv as binding self-regulation and use BIO2 as guidance.
We put that first because it is the most expensive misunderstanding about any national framework. None is needed: BIO2 IS the ISO/IEC 27002:2022 control set with government additions. An organisation certified to ISO/IEC 27001 recognises the whole structure, and only the overheidsmaatregelen are new work.
What it is built on
BIO2 does not invent its own taxonomy. It sits on NEN-EN-ISO/IEC 27001:2023 (nl) and NEN-EN-ISO/IEC 27002:2022 (nl).
The controls are those of ISO/IEC 27002:2022, plus a set of overheidsmaatregelen — government-specific measures that apply where applicable regardless of the risk assessment. Several were tightened for NIS2; three are expressly excluded from the Cyberbeveiligingswet obligation, because the act reaches only the protection of network and information systems.
Where it is heading
How it covers article 21(2)
Resolved by reference to ISO/IEC 27001:2022 Annex A, because BIO2 adopts the ISO/IEC 27002:2022 control set and its numbering. Holding one mapping for both is the only way they cannot drift apart.
The ISO controls map; the overheidsmaatregelen do not, because their identifiers and their number are not transcribed here yet. That gap matters: they are exactly the part specific to the Dutch government, and the part the Cbw makes legally binding.
| Art. 21(2) | Measure | BIO2 — ISO/IEC 27002:2022 control |
|---|---|---|
| (a) | Risk analysis and security policies | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 |
| (b) | Incident handling | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 |
| (c) | Business continuity | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 |
| (d) | Supply chain security | 5.19 5.20 5.21 5.22 5.23 |
| (e) | Security in acquisition, development and maintenance | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 |
| (f) | Assessing the effectiveness of the measures | 5.33 5.35 5.36 8.16 |
| (g) | Basic cyber hygiene and cybersecurity training | 5.37 6.3 8.7 |
| (h) | Cryptography and encryption | 8.24 |
| (i) | Human resources security, access control and asset management | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 |
| (j) | Multi-factor authentication and secured communications | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 |
What you already have, for the same measure
Nobody in scope starts from nothing. BIO2 is what your supervisor reads; NIST 800-53 is what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.
ISO 27001 is not repeated here: BIO2 publishes no identifiers of its own and its mapping above is the ISO 27001 one. Showing it twice would make a duplication look like independent confirmation.
| Art. 21(2) | BIO2 | NIST 800-53 NIST SP 800-53 Rev. 5 control family |
|---|---|---|
| (a) Risk analysis | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 | RA PL PM |
| (b) Incident handling | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 | IR AU SI |
| (c) Continuity | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 | CP PE |
| (d) Supply chain | 5.19 5.20 5.21 5.22 5.23 | SR SA |
| (e) Secure development | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 | SA CM MA RA SI |
| (f) Effectiveness | 5.33 5.35 5.36 8.16 | CA PM |
| (g) Hygiene and training | 5.37 6.3 8.7 | AT SI CM |
| (h) Cryptography | 8.24 | SC |
| (i) HR, access, assets | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 | PS AC IA CM MP PE |
| (j) MFA and comms | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 | IA AC SC |
A crosswalk is not an equivalence
Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:
- NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.
Use a row to find the evidence you already hold, then read the requirement itself.
- https://www.bio-overheid.nl/bio2/
- https://www.digitaleoverheid.nl/overzicht-van-alle-onderwerpen/cybersecurity/bio-en-ensia/baseline-informatiebeveiliging-overheid/
- https://www.bio-overheid.nl/bio2/veelgestelde-vragen-over-de-bio2/
We are not affiliated with Interbestuurlijke werkgroep-BIO, chaired by the Ministry of the Interior (BZK). BIO2 and related marks belong to their owners.