Security scan
The security scan is a structured assessment of an organisation's information security against the requirements of the Baseline Informatiebeveiliging Overheid (BIO, the Dutch government's information security baseline) and, where relevant, the NIS2 directive.

Why the security scan?
The security scan is a structured assessment of an organisation's information security against the requirements of the Baseline Informatiebeveiliging Overheid (BIO) and, where relevant, the NIS2 directive. BIO applies to municipalities, provinces, water authorities and other government organisations. NIS2 places comparable requirements on organisations in vital and important sectors, with stricter requirements for risk management, incident response and board-level accountability.
The scan assesses both technical measures, such as access security and logging, and organisational aspects, such as policy, responsibilities and incident response procedures.
Our approach
- 1
Determine scope and framework
We determine together which framework applies, BIO, NIS2 or a combination, and align the scope of the scan with the relevant systems and processes.
- 2
Assessment against the framework
We systematically assess technical and organisational measures against the requirements of the framework, based on documentation, interviews and, where relevant, technical verification.
- 3
Determine maturity per domain
We map out the maturity per domain, such as access security, logging, incident response and risk management, so it's clear where the biggest gaps are.
- 4
Set priorities and an improvement plan
We translate the findings into a concrete, prioritised improvement plan, distinguishing between quick wins and structural improvements that require more time and investment.
- 5
Reporting for the board and regulators
The scan results in a report suitable for sharing with the board, regulators or auditors, with a clear management summary alongside the detailed findings.
What does the compliancy scan deliver?
Maturity picture
A substantiated picture of the maturity of your information security per domain, assessed against BIO and/or NIS2.
Improvement plan
A prioritised improvement plan with a clear distinction between quick wins and structural improvements.
Usable reporting
A report that's immediately usable for the board, regulators and auditors.
Substantiated next steps
Insight into the risks of any gaps and a realistic starting point for next steps, without unnecessarily heavy measures.
Challenges within government organisations
Curious how we handle the challenges around guidelines and legislation within government organisations?

Ready to find out where you stand against BIO and NIS2?
Digital Survival Company carries out BIO/NIS2 compliancy scans for government organisations and organisations in vital and important sectors, with consultants experienced in the BIO, NIS2 and NEN7510 frameworks. Get in touch and let's discuss what the security scan delivers for your organisation.
FAQ
Does BIO apply to our organisation, or is that only for municipalities?
BIO applies to municipalities, provinces, water authorities and central government. Other organisations, such as housing corporations or healthcare institutions, don't formally fall under BIO but sometimes use the framework as a reference. We determine together in advance which framework, BIO, NIS2 or another framework such as NEN7510, best fits your situation.
What's the difference between BIO and NIS2?
BIO is specifically aimed at Dutch government organisations. NIS2 is a European directive that applies to organisations in vital and important sectors, with stricter requirements for risk management, incident response and board-level liability. Some organisations, such as certain government agencies, have to deal with both frameworks.
Is the scan enough to be demonstrably compliant?
The scan gives a substantiated picture of your maturity and a concrete improvement plan, but formal compliance certification is usually a separate process, often with an external auditor. The scan is, however, a strong foundation to prepare for that and to demonstrate that you're structurally working on improvement.



