Skip to main content
BIO

BIO / BIO2 Compliance
Made Simple

Automate the Dutch government's mandatory information-security baseline. Map all BIO controls, collect evidence automatically, and stay continuously audit-ready across every process, supplier and system.

The Dutch Public Sector Security Standard

The Baseline Informatiebeveiliging Overheid (BIO) is the mandatory information-security standard for all Dutch public-sector organisations, including municipalities, ministries, provinces, agencies and water authorities. BIO2 is the modernised version aligned with ISO 27001:2022, updated control families and stronger requirements for chain responsibility, cloud environments and continuous risk management. Basenorm automates the full lifecycle of BIO compliance — from control mapping to evidence collection, policy generation and audit preparation.

  • Mandatory for all Dutch public-sector organisations
  • BIO2 aligned with ISO 27001:2022
  • Chain responsibility requirements
  • Cloud environment compliance
  • Continuous risk management
  • Full lifecycle automation

BIO2 Control Domains

ISO 27001:2022

Organisational

ISO 5.x

37

People

ISO 6.x

8

Physical

ISO 7.x

14

Technological

ISO 8.x

34
Total BIO2 Controls93

Dutch public sector baseline aligned with ISO

Chain Responsibility

Ministry

Rijksoverheid

Accountable

Agency

Uitvoeringsorganisatie

Responsible

Supplier

Leverancier

Contracted

Chain Requirements

  • Contractual security obligations
  • Supplier risk assessments
  • Continuous monitoring

Ketenverantwoordelijkheid under BIO2

Built for Public-Sector Compliance

Basenorm provides comprehensive automation for BIO compliance, designed specifically for Dutch public sector organisations.

  • Full BIO2 control library with automatic mappings to ISO 27001, GDPR and NIS2
  • Automated evidence collection across SaaS, cloud and IT infrastructure
  • Governance Graph for all BIO domains: risks, controls, assets, suppliers
  • AI-generated BIO policies, procedures, overviews and audit material
  • Auditor-ready workspace with real-time readiness scoring
  • Vendor and chain-risk management aligned with BIO2 requirements

One Unified Control Library for BIO and Beyond

Basenorm provides a complete BIO/BIO2 control library with real-time cross-mapping to ISO 27001 and NIS2. Every control, asset and process is linked to evidence, risks and responsibilities. This eliminates duplication, misalignment and administrative overhead.

  • Real-time cross-framework mapping
  • Every control linked to evidence, risks, responsibilities
  • Eliminates duplication and misalignment
  • Reduces administrative overhead
  • Continuous monitoring and updates
  • Full control lifecycle management

Cloud Compliance

Microsoft Azure
ISO 27001SOC 2BIO2 Verified
Amazon Web Services
ISO 27001C5BIO2 Verified
Google Cloud
ISO 27001
Cloud BIO2 Coverage67%

Cloud provider assessment for Dutch public sector

Start Automating BIO Compliance Today

Join leading Dutch public sector organisations using Basenorm to streamline BIO compliance.

Frequently Asked Questions

Explore frequently asked questions about BIO and related compliance topics.