Directive NIS2 European Union
BIO2 v1.3, published in the Staatscourant · v1.3, 5 March 2026 (BIO2 first published 24 September 2025)

Baseline Informatiebeveiliging Overheid 2

NIS2 says what you must achieve, never how you demonstrate it. Netherlands answers with BIO2. If you operate there, this is what your regulator reads.

Published
Member states using it
1

Reviewed . Verify against the scheme owner before relying on this for a certification decision.

This framework is not compliance

BIO2 binds the PUBLIC SECTOR, not private entities. It applies to the Rijk, provinces, water boards and municipalities, and once the Cbw takes effect also to the Hoge Colleges van Staat, the Ministry of Defence, the AIVD and the police by ministerial decision. A private entity in NIS2 scope in the Netherlands has no national framework: it works to the duty of care in the Cbw and the Cbb directly. And which version binds you depends on your government layer — municipalities remain on BIO1 v1.04zv as binding self-regulation and use BIO2 as guidance.

We put that first because it is the most expensive misunderstanding about any national framework. None is needed: BIO2 IS the ISO/IEC 27002:2022 control set with government additions. An organisation certified to ISO/IEC 27001 recognises the whole structure, and only the overheidsmaatregelen are new work.

What it is built on

BIO2 does not invent its own taxonomy. It sits on NEN-EN-ISO/IEC 27001:2023 (nl) and NEN-EN-ISO/IEC 27002:2022 (nl).

The controls are those of ISO/IEC 27002:2022, plus a set of overheidsmaatregelen — government-specific measures that apply where applicable regardless of the risk assessment. Several were tightened for NIS2; three are expressly excluded from the Cyberbeveiligingswet obligation, because the act reaches only the protection of network and information systems.

Where it is heading

Mapping

How it covers article 21(2)


Basis

Resolved by reference to ISO/IEC 27001:2022 Annex A, because BIO2 adopts the ISO/IEC 27002:2022 control set and its numbering. Holding one mapping for both is the only way they cannot drift apart.

Limit of this mapping

The ISO controls map; the overheidsmaatregelen do not, because their identifiers and their number are not transcribed here yet. That gap matters: they are exactly the part specific to the Dutch government, and the part the Cbw makes legally binding.

Mapped at the level of
ISO/IEC 27002:2022 control
Units in the framework
93
Units carrying article 21(2)
91
Each of the ten risk-management measures of article 21(2), mapped to the ISO/IEC 27002:2022 control units of BIO2
Art. 21(2) Measure BIO2 — ISO/IEC 27002:2022 control
(a) Risk analysis and security policies 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36
(b) Incident handling 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16
(c) Business continuity 5.29 5.30 7.5 7.11 7.12 8.13 8.14
(d) Supply chain security 5.19 5.20 5.21 5.22 5.23
(e) Security in acquisition, development and maintenance 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34
(f) Assessing the effectiveness of the measures 5.33 5.35 5.36 8.16
(g) Basic cyber hygiene and cybersecurity training 5.37 6.3 8.7
(h) Cryptography and encryption 8.24
(i) Human resources security, access control and asset management 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19
(j) Multi-factor authentication and secured communications 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23
The chain continues

What you already have, for the same measure


Nobody in scope starts from nothing. BIO2 is what your supervisor reads; NIST 800-53 is what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.

ISO 27001 is not repeated here: BIO2 publishes no identifiers of its own and its mapping above is the ISO 27001 one. Showing it twice would make a duplication look like independent confirmation.

The ten measures of article 21(2), each mapped to BIO2 and to the enterprise frameworks an organisation is likely to already operate
Art. 21(2) BIO2 NIST 800-53 NIST SP 800-53 Rev. 5 control family
(a) Risk analysis 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 RA PL PM
(b) Incident handling 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 IR AU SI
(c) Continuity 5.29 5.30 7.5 7.11 7.12 8.13 8.14 CP PE
(d) Supply chain 5.19 5.20 5.21 5.22 5.23 SR SA
(e) Secure development 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 SA CM MA RA SI
(f) Effectiveness 5.33 5.35 5.36 8.16 CA PM
(g) Hygiene and training 5.37 6.3 8.7 AT SI CM
(h) Cryptography 8.24 SC
(i) HR, access, assets 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 PS AC IA CM MP PE
(j) MFA and comms 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 IA AC SC

A crosswalk is not an equivalence

Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:

  • NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.

Use a row to find the evidence you already hold, then read the requirement itself.

Sources

We are not affiliated with Interbestuurlijke werkgroep-BIO, chaired by the Ministry of the Interior (BZK). BIO2 and related marks belong to their owners.

Cart 0