ECP vs BIO2 (Baseline Informatiebeveiliging Overheid): For Public Sector Or Private MSPs?
BIO2 is the Dutch national information-security baseline for government. It is mandatory self-regulation for the State, provinces and water authorities (guiding for municipalities via ENSIA), aligned to NEN-EN-ISO/IEC 27002:2022, and anchored in the Cyberbeveiligingswet, the Dutch NIS2 transposition, in force since 15 August 2026. Easy Cyber Protection is a Belgian MSP platform: a compliance engine for private-sector SMEs, CyFun-native today, multi-framework by design. These are not head-to-head products for the same buyer. This page names where they overlap, where they do not, and how a cross-border MSP should think about both.
At a glance
| BIO2 | Easy Cyber Protection | |
|---|---|---|
| What it is | National information-security baseline for Dutch government | MSP compliance platform (SaaS) for private-sector SMEs |
| Who it is for | Central government, provinces, water authorities, municipalities (ENSIA) | MSPs serving Belgian and pan-EU private-sector SMEs |
| Legal status | Mandatory self-regulation; anchored in Cyberbeveiligingswet (Cbw), in force since 15 Aug 2026 | Commercial SaaS; supports Belgian CyFun (CCB's NIS2 path) |
| Framework basis | NEN-EN-ISO/IEC 27001:2023 + 27002:2022 + Dutch government-specific measures | CyFun 2025 (NIST CSF 2.0-aligned); framework engine hosts more |
| Approach | Risk-based (BBN 1/2/3 levels abolished in BIO2) | Risk-based via CyFun tiering (Small / Basic / Important / Essential) |
| Assessment / audit | ENSIA (municipalities); BIO2 certification via accredited CBs | Audit-readiness engine + signed .ecpbundle.zip hand-off to any auditor |
| Assessment cost | ≈ €15,000–€25,000 per ENSIA cycle (municipalities) | One fee per client per month, by client size; no monthly base |
| Private-sector fit | Not designed for private SMEs (they use ISO 27001 or fall under Cbw directly) | Built for private-sector MSP delivery from day one |
| MSP / multi-tenancy | No product: BIO2 is a specification, not a platform | Partner dashboard, white-label, per-client branding |
Sources: bio-overheid.nl/bio2 (BIO2 v1.3 factsheet, 09-01-2026), digitaleoverheid.nl/nieuws (24-09-2025 vernieuwing announcement), ncsc.nl/onderwerpen/cyberbeveiligingswet (Cbw in force 15-08-2026). Last verified 2026-08-24.
What the Cyberbeveiligingswet changed on 15 August 2026
The Netherlands transposed NIS2 on 15 August 2026, nearly 22 months after the EU deadline of 17 October 2024. Only four member states had fully transposed by that deadline; the Commission opened infringement procedures against the other 23, the Netherlands among them. The Cbw covers more than 8,000 Dutch organisations across the eighteen NIS2 sectors and, unlike BIO2, it binds the private sector directly. Every article number below is read from the consolidated statute, not from press coverage.
| Duty | What the statute says | Article |
|---|---|---|
| Register | Entities in scope supply their details to the Minister for the national register of entities; in practice registration runs through the MijnNCSC portal. Sector, size and criticality decide scope. Not registering is itself a breach. | art. 43 to 46 |
| Secure | Analyse the risks, then take technical, operational and organisational measures. The duty runs through to purchased products, systems and services, and to physical security. | art. 21 |
| Report | Early warning without delay or within 24 hours, full notification within 72 hours (24 hours for trust services), interim report on request, final report within one month of the notification. | art. 25 to 29 |
| Be supervised | Supervisors can order a security scan (art. 71) or an audit (art. 72) and can publish the breach (art. 73). An important entity faces that toolkit only once there is evidence or an indication of a possible breach (art. 81); no such trigger limits supervision of an essential entity. Where an essential entity misses a compliance deadline, the supervisor can ask the civil court to suspend board members (art. 78). That suspension route is the part that does not apply to government bodies (art. 79); scans, audits and publication still do. | art. 71 to 81 |
The large fines land on the entity, not the person: up to EUR 10,000,000 or 2% of worldwide annual turnover for an essential entity (art. 80), up to EUR 7,000,000 or 1.4% for an important entity (art. 87), the higher of the two in both cases. Any other breach caps at EUR 1,000,000. Where the Dutch DPA has already fined the same conduct under art. 58(2)(i) GDPR, no art. 80 or 87 fine follows for the personal-data breach arising from it (art. 58). That bar is narrow: it does not touch the personal fine under art. 93.
The board duty, stated precisely
Coverage of the Cbw has compressed to "directors are now personally liable". The statute is narrower than that, and more useful to sell against. The word "aansprakelijk" does not appear anywhere in it. What article 24 does is impose two named duties: the risk measures require the approval of the board (lid 1), and every board member must personally hold the knowledge and skills to identify cyber risks, judge the measures, and judge what both mean for the services the entity delivers (lid 2). In a one-tier board the duty binds the executive directors only (lid 8). Lid 5 turns that into something a supervisor can check, because each board member has to hold a certificate showing they attended a training covering those topics, kept demonstrably current under lid 4. Lid 3 gives sitting members two years, so 15 August 2028, and new appointees two years from appointment.
The enforcement against an individual sits in article 93: a supervisor can fine a board member personally up to EUR 25,000 for failing the article 24 competence duty, backed by an order subject to a penalty payment under article 92. So the multi-million figures hit the company, and the personal exposure under the Cbw is EUR 25,000 plus, for essential entities only, suspension through the civil court. Anyone quoting EUR 10 million as a director's personal risk has merged two different articles.
Sources: Cyberbeveiligingswet, BWBR0052872, consolidated text as at 15-08-2026, wetten.overheid.nl (art. 21, 24, 25 to 29, 43 to 46, 58, 71 to 81, 87, 92, 93); ncsc.nl/onderwerpen/cyberbeveiligingswet and rijksoverheid.nl (in force 15-08-2026, scope of more than 8,000 organisations). Read 2026-08-24.
Where BIO2 is the right target
- You are (or you serve) a Dutch government body: the State, a province, a water board, or a municipality accountable through ENSIA
- You are a supplier to Dutch government and your customer requires BIO2 evidence in your ISMS or in the tender response
- Your engagement is anchored in the Cyberbeveiligingswet (Cbw): BIO2 is the Dutch government's statutory route to NIS2 obligations
- You need to align with ISO/IEC 27002:2022 controls plus Dutch government-specific measures (overheidsmaatregelen) rather than a broader multi-framework library
- ENSIA accountability, VNG/IBD tooling and Dutch-language audit reporting are hard requirements for you
Where Easy Cyber Protection fits better
- You are an MSP and your clients are private-sector SMEs (Belgian NIS2 essential/important, or non-NIS2 clients wanting audit-readiness)
- You want one fee per client by client size, no monthly base, so cost tracks the work rather than headcount tiers
- You need white-label deliverables (branded reports, policies, training) in your own brand, with NL / FR / EN materials
- You want a compliance engine that already adapts to multiple national frameworks (CyFun today; the ADR-0039 activation model is the mechanism for more)
- Your fastest path to NIS2 evidence is CyFun, the CCB's recognised route in Belgium, aligned with NIST CSF 2.0
The pricing math
These pricing models sit in different worlds. BIO2 is a specification, not a product. The direct cost is the assessment (ENSIA or BIO2 certification), plus whatever consultancy and tooling you buy around it. ECP is a per-client SaaS sold to the MSP. The numbers below give an honest side-by-side for a 50-client MSP book, but the comparison is illustrative: a Belgian MSP would not "buy BIO2" the way they buy ECP.
BIO2: 50 Dutch public-sector engagements
- • ENSIA-style assessment cycle per municipality: ≈ €15,000–€25,000, 4–6 weeks (Secura, Bureau Veritas, RSM public rate cards)
- • BIO2 certification via accredited CB (e.g., Brand Compliance): quoted per-scope, no standard public rate
- • On top: IBD membership / VNG tooling, internal ISMS effort, evidence collection (unpriced, but non-trivial)
- • Cost per engagement dominated by third-party audit + internal effort, not a subscription
- • Not applicable to private-sector SME clients: they fall under ISO 27001 or Cbw directly, not BIO2
ENSIA cost range from public assessor rate cards (Secura, Bureau Veritas, RSM Netherlands); BIO2 certification pricing not published, quoted per engagement. BIO2 is not a SaaS; there is no per-client platform fee.
ECP: 50 private-sector SME clients on the MSP's book
- • Direct end-client price by employee count: Micro (1–9) €95, Small (10–49) €195, Medium (50–249) €395, Large (250–999) €750, 1,000+ on request
- • A Small client (10–49 employees) costs €195 / month, €2,340 / year, no monthly base (at the monthly rate; longer terms are discounted)
- • Partners buy below the published rate; the partner rate card is on request
- • Every client gets the full feature set: AI assistance and integrations included
ECP charges one fee per client per month, by the client's size in employees: Micro (1–9) €95, Small (10–49) €195, Medium (50–249) €395, Large (250–999) €750, 1,000+ on request. Partners buy below the published rate; the partner rate card is on request. No monthly base. One-time €400 MSP onboarding per partner. Evaluate via the live demo (no signup). All clients get the full feature set from day one.
Framework coverage
BIO2 is depth on one thing: Dutch government information security, aligned to ISO 27002:2022 with government-specific measures on top. ECP is CyFun-native today, with the framework engine (ADR-0039) as the mechanism for hosting additional national frameworks side by side. BIO2 is not on our shipped list. This row-by-row is honest about that.
| Framework | BIO2 | ECP |
|---|---|---|
| BIO2 (Dutch government) | Native (this IS BIO2) | Not shipped; engine could host it, not on committed roadmap |
| CyFun (CCB): Small / Basic | Not applicable (different country, different scope) | Native, YAML-implemented |
| CyFun (CCB): Important / Essential | Not applicable | YAML implemented, CCB verification pending |
| ISO/IEC 27001:2022 / 27002:2022 | Aligned by construction (BIO2 = 27002 + overheidsmaatregelen) | Planned, not yet shipped |
| NIS2 (in the Netherlands) | Cbw route: BIO2 is the government sector's statutory implementation | Not the primary NIS2 path in NL; supports CyFun (Belgian NIS2 path) |
| NIS2 (in Belgium) | Not applicable | Via CyFun (CCB's official NIS2 route in Belgium) |
| ENSIA (municipal accountability) | Primary tool for Dutch municipalities | Not supported: out of scope for Belgian MSP delivery |
| NIST CSF 2.0 | Not a direct mapping (27002-anchored) | CyFun 2025 is aligned with NIST CSF 2.0 |
Sources: bio-overheid.nl (BIO2 v1.3 factsheet), nldigitalgovernment.nl (BIO overview), ECP roadmap.md + ADR-0039. If your audit is against a framework not listed above, verify directly with the certifying body.
Common questions
Is BIO2 an alternative to CyFun for a Belgian SME?
No. BIO2 is the Dutch government's information-security baseline. A Belgian SME would not implement BIO2. The Belgian NIS2 path is CyFun (via the CCB), and a Belgian MSP delivering audit-readiness to Belgian SMEs is squarely in ECP territory. BIO2 becomes relevant only if you have a Dutch government client, or you are a supplier to Dutch government and your tender demands BIO2 evidence.
Can ECP be used to prepare for a BIO2 audit?
Not today, honestly. BIO2 is not on our shipped framework list: CyFun is native, ISO 27001 is planned, and ADR-0039 sets up multi-framework activation (GDPR and EU AI Act already sit next to CyFun). BIO2 would be an engineering addition (YAML controls, government-specific measures, ENSIA output), plausible on the framework engine but not committed on the roadmap. If BIO2 is your target today, use a Dutch-focused ISMS tool or partner with a Dutch CB.
My client is a Dutch private-sector SME. Should I use BIO2 or ECP?
Neither, cleanly. BIO2 is written for public administration. It is not designed for private SMEs and Dutch commercial buyers typically go the ISO 27001 route or fall directly under the Cyberbeveiligingswet (Cbw) as NIS2 essential/important entities. ECP today is CyFun-native and speaks Belgian NIS2; for a Dutch private SME we would honestly point you at ISO 27001 tooling until we ship a Dutch NIS2 path. Watch ADR-0039 activation: if we bring a Dutch NIS2 or ISO 27001 module online, that is where it will show up.
BIO2 is aligned to ISO 27002:2022. Does CyFun overlap?
Yes, meaningfully. CyFun 2025 is aligned with NIST CSF 2.0, and NIST CSF 2.0 has documented crosswalks with ISO 27001/27002. So a control in CyFun typically maps to a control in ISO 27002 and, by transitivity, to a BIO2 control. But an ISO 27001 or BIO2 auditor will not accept CyFun evidence without an explicit mapping. Controls overlap, evidence formats and auditor expectations do not. If a client needs both, you carry both.
Does the Cbw make Dutch directors personally liable, and is that an opening for us?
Not in the way the headlines describe, and the real version is the more useful one. The Cbw never uses the word "aansprakelijk". Article 24 requires the board to approve the risk measures, and requires every board member to hold the knowledge and skills to judge them, evidenced by a training certificate (lid 5) and kept demonstrably current (lid 4), with two years to get there: 15 August 2028 for sitting members, two years from appointment for new ones. Article 93 lets a supervisor fine a board member personally up to EUR 25,000 for failing that duty. The EUR 10 million and 2% figures are article 80 and land on the entity, not the person. So sell the article 24 evidence problem, which is real, dated and unsolved at most Dutch boards. A personal-liability number that does not survive a lawyer reading the statute will cost you the room.
Package CyFun audit-readiness for your clients
If you are an MSP serving private-sector SMEs and our per-client pricing (one fee by client size, no monthly base, full features for every client) fits your book better than a per-engagement audit cycle, let us talk.
Related
Fact check: sources for every claim
Every numeric and factual claim in this page maps to a public source. Access date shown. If any source has updated since, please flag it.
| Claim | Source | Access date |
|---|---|---|
| BIO2 v1.3 published 5 March 2026 in the Staatscourant, replacing v1.2 | bio-overheid.nl/media/dr4inbhc/20260109-baseline-informatiebeveiliging-overheid-2-bio2-v13-def.pdf | 2026-08-24 |
| BIO2 is aligned to NEN-EN-ISO/IEC 27001:2023 + 27002:2022; four themes: organizational, people, physical, technological | bio-overheid.nl/bio2/ + nldigitalgovernment.nl/overview/cybersecurity/baseline-information-security-for-government/ | 2026-08-24 |
| Three Basic Security Levels (BBN1/2/3) abolished in BIO2; replaced by a risk-based approach | digitaleoverheid.nl/nieuws/baseline-informatiebeveiliging-overheid-vernieuwd/ | 2026-08-24 |
| BIO2 is mandatory self-regulation for provinces, water authorities and central government from OBDO decision 23 September 2025 | digitaleoverheid.nl/overzicht-van-alle-onderwerpen/cybersecurity/bio-en-ensia/baseline-informatiebeveiliging-overheid/ | 2026-08-24 |
| For municipalities, BIO2 is guiding; ENSIA remains the primary accountability tool, updated in 2026 to reflect BIO2 | nldigitalgovernment.nl/overview/cybersecurity/bio-and-ensia/ | 2026-08-24 |
| The Cyberbeveiligingswet (Cbw), the Dutch NIS2 transposition, is in force since 15 August 2026 and covers more than 8,000 Dutch organisations providing essential or important services (secondary: the count is published by the NCSC, not stated in the statute) | ncsc.nl/onderwerpen/cyberbeveiligingswet + rijksoverheid.nl/actueel/nieuws/2026/08/15/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-vandaag-van-kracht | 2026-08-24 |
| BIO2 is incorporated as the zorgplicht in the ministerial regulation for the Overheid sector under the Cbw; from 15 August 2026 applying the ISO standards and the BIO2 overheidsmaatregelen is a legal obligation for government bodies in scope of the Cbw. Bodies outside its scope stay bound via a ministerial council decision published in the Staatscourant | digitaleoverheid.nl/overzicht-van-alle-onderwerpen/cybersecurity/bio-en-ensia/baseline-informatiebeveiliging-overheid/, verbatim: "is de BIO2 als zorgplicht opgenomen in de ministeriele regeling voor de sector Overheid onder de Cyberbeveiligingswet (Cbw)" | 2026-08-24 |
| Four member states had fully transposed NIS2 by the 17 October 2024 deadline; the European Commission sent letters of formal notice to the other 23, the Netherlands included | digital-strategy.ec.europa.eu/en/news/commission-calls-23-member-states-fully-transpose-nis2-directive (28-11-2024) | 2026-08-24 |
| Cbw art. 24: the risk measures need the approval of the board (lid 1); every board member must hold the knowledge and skills to identify cyber risks and assess the measures and their consequences (lid 2), within two years of entry into force or of appointment (lid 3), kept demonstrably current (lid 4), evidenced by a certificate of participation in a training (lid 5) | wetten.overheid.nl/BWBR0052872, consolidated text as at 2026-08-15, art. 24 | 2026-08-24 |
| Cbw fines on the entity: essential up to EUR 10,000,000 or 2% of total worldwide annual turnover, whichever is higher (art. 80 lid 3); important up to EUR 7,000,000 or 1.4%, whichever is higher (art. 87 lid 3); any other breach up to EUR 1,000,000 | wetten.overheid.nl/BWBR0052872, consolidated text as at 2026-08-15, art. 80 and art. 87 | 2026-08-24 |
| Cbw exposure of an individual board member: administrative fine up to EUR 25,000 for breaching art. 24 lid 2 to 6 (art. 93 lid 2), plus an order subject to a penalty payment (art. 92); suspension of board members is limited to essential entities, requested from the civil court after a missed compliance deadline (art. 78), and arts. 76 to 78 do not apply to government bodies (art. 79) | wetten.overheid.nl/BWBR0052872, consolidated text as at 2026-08-15, art. 78, 79, 92, 93 | 2026-08-24 |
| Cbw incident reporting: early warning without delay or within 24 hours (art. 26), notification within 72 hours and within 24 hours for trust services (art. 27), interim report on request (art. 28), final report within one month of the notification (art. 29) | wetten.overheid.nl/BWBR0052872, consolidated text as at 2026-08-15, art. 25 to 29 | 2026-08-24 |
| The word "aansprakelijk" does not occur anywhere in the consolidated Cbw text | wetten.overheid.nl/BWBR0052872, consolidated text as at 2026-08-15, full-text search of the consolidated regulation (0 occurrences), corroborated against the original act as published in Stb. 2026, 187 | 2026-08-24 |
| ENSIA assessment cost range ≈ €15,000–€25,000, 4–6 weeks | secura.com/services/process/audit-and-assurance/ensia-suwinet-audits + bkbo.nl/hoe-werkt-het-ensia-assessment-voor-gemeenten/ | 2026-08-24 |
| BIO2 does not apply to Dutch private-sector organisations; they typically use ISO/IEC 27001 or fall under the Cbw directly | digitrust.nl/en/sectors/government/ + linkedin.com/pulse/bio-iso27001-compare-learn-igor-van-gemert (industry commentary) | 2026-08-24 |
| ECP MSP pricing: one fee per client per month by the client's size in employees (Micro (1–9) €95, Small (10–49) €195, Medium (50–249) €395, Large (250–999) €750, 1,000+ on request); no monthly base; €400 one-time MSP onboarding; partner rates on request | docs/adr/0050-two-lane-pricing-sized-by-employees.md + docs/adr/0036-msp-onboarding-fee-and-demo-only-evaluation.md | 2026-08-24 |
| ECP multi-framework activation (GDPR + EU AI Act next to CyFun) shipped under ADR-0039 | docs/adr/0039-multi-framework-activation.md | 2026-08-24 |