# BIO2 awareness training: demonstrable training in Dutch government (2026)

> BIO2 requires demonstrable information security awareness training within three months of joining (6.03.02) and regular refreshers (5.04.01). How Dutch public bodies and their suppliers comply.

- Canonical: https://cyberpulse.it/en/bio2-awareness-training
- Dutch version: https://cyberpulse.it/bio2-awareness-training
- Published: 2026-08-09
- Updated: 2026-08-25
- Publisher: CyberPulse (https://cyberpulse.it)

BIO2: the Baseline Informatiebeveiliging Overheid 2, the Dutch government's baseline information security standard: requires that all employees and contractors demonstrably and successfully complete information security awareness training within three months of starting (measure 6.03.02). The baseline has applied since 2 March 2026 to the whole of Dutch government, and it works its way through to suppliers via contracts. This page sets out the two training measures and shows how to make them auditable.

If you supply a Dutch government body from abroad, this reaches you too, not through Dutch law directly, but through the contract your client puts in front of you.

## What is BIO2, and who does it apply to?

The Baseline Informatiebeveiliging Overheid 2 (version 1.3) has applied since 2 March 2026, laid down in a circular (BWBR0052376). It replaces the old BIO 1.04 and applies across the whole of Dutch government: central government, municipalities, provinces and water authorities. Just as important: the baseline works its way through to those bodies' suppliers via contractual arrangements: more on that below.

From 15 August 2026, BIO2 also acquires a statutory anchor. The Cyberbeveiligingsregeling overheid, the Dutch cybersecurity regulation for public bodies, then points to BIO2 as the way to fulfil the duty of care under the Dutch Cybersecurity Act (Cbw), the Dutch implementation of NIS2. Every EU member state has its own implementing law. That shifts BIO2 from an agreement inside government to the concrete substance of a legal obligation. For how the Cbw duty of care fits together, including the reporting obligation and management responsibility, read [the Dutch Cybersecurity Act: the training requirements](/en/dutch-cybersecurity-act-training-requirements).

Two measures are directly relevant to awareness training: 6.03.02 (demonstrable training on joining) and 5.04.01 (regular training for the management body and employees). We will take both in turn, because each asks something different of your organisation.

## Measure 6.03.02: demonstrably trained within 3 months of joining

The heart of the training requirement sits in measure 6.03.02:

> "All employees and contractors … have demonstrably and successfully completed information security awareness training within three months of starting employment"
> – BIO2, measure 6.03.02 (translated from Dutch)

Four parts of that sentence do the work:

- **"All employees and contractors"**: the requirement is not limited to civil servants on permanent contracts; contractors and external staff working for your organisation fall under it too. So you need visibility of intake through procurement, not only of your own HR process.
- **"Within three months of starting employment"**: a concrete deadline per person. Tie the training to onboarding rather than to an annual campaign that happens to land somewhere in the year: someone who starts in April cannot wait for the November session.
- **"Demonstrably"**: you must be able to show, per person, that the training was taken. That calls for registration: who, when, with what result. A general statement that everyone "received the e-learning" is not evidence.
- **"Successfully completed"**: inviting people is not enough, and neither is attendance. You record that the training was actually finished, and passed.

In practice: make information security awareness training a fixed part of onboarding, with automatic registration of completion and monitoring of the three-month deadline per person. The measure then stops being an annual exercise and becomes a process that proves itself.

### What "demonstrable within three months" looks like in practice

You will only hit the deadline consistently if the training sits inside onboarding, not in a standalone campaign. A workable set-up:

1. **Day 1: account on, training on.** Link the training invitation to account creation. No separate list to maintain: whoever gets access is automatically in the programme.
2. **Week 1: start, don't just invite.** Put the first module in the induction schedule, alongside the laptop handover and the tour. It then belongs here from the outset, instead of being an email that sinks down the inbox.
3. **Month 2: check progress.** One fixed checkpoint: who has started but is off track? A reminder in month 2 costs nothing; discovering in month 4 that someone never started means the deadline has already passed.
4. **Month 3: completed and recorded.** Monitor completion and the record: date, result and person. That is the "demonstrably" from the measure.
5. **Leavers and role changes: keep the administration current.** Otherwise your reporting silts up and gaps appear where nobody works any more.

Don't forget the intake that bypasses HR: contractors and agency staff often arrive through procurement or a staffing firm, and miss HR onboarding entirely. Agree that their access, too, only follows once they are in the programme.

For a municipality or SME supplier with dozens of joiners a year, doing this by hand is just about manageable: which means it will go wrong eventually. Automation is the difference between "we do our best" and "here is the completion date per person".

## Measure 5.04.01: regular training for the management body and employees

Alongside the onboarding requirement, BIO2 has measure 5.04.01: the management body and employees follow training regularly. Two things stand out.

First, the management body is named explicitly. Awareness is not something you roll out to the shop floor while the top watches on: members of the management body take part themselves, and you want to be able to show their participation too.

Second, the measure names no frequency. "Regularly" is yours to fill in, but you have to be able to defend how you fill it in. A continuous programme of short, recurring learning moments makes that straightforward: you never have to explain why nothing happened for eleven months, and you cover 6.03.02 and 5.04.01 in one movement: new people start on joining, existing staff and management stay in the rhythm.

## What does this mean for suppliers to Dutch government bodies?

BIO2 applies not only to public bodies themselves but, through contractual pass-through, to their suppliers as well. And measure 6.03.02 names contractors explicitly.

Do you deliver services to Dutch central government, a municipality, a province or a water authority? Then you can expect contracts and tender documents to require demonstrable working in line with BIO2, including training for the people who will work on that public sector account. That holds whether you are established in the Netherlands or elsewhere: the requirement reaches you through the contract, not through Dutch law. A supplier with per-employee training evidence ready answers with a single report instead of a scramble under time pressure.

For the public body, the mirror image applies: arrange the pass-through in your supplier contracts and actively ask for the training evidence. You can only deliver on the requirement that contractors are demonstrably trained within three months if your suppliers move with you.

### How to arrange it in procurement and contracts

Pass-through to the supply chain does not organise itself; it stands or falls with what your contracts and tenders say. Practical footholds for the purchasing public body:

- **Put the training requirement in explicitly**: in the contract or the processing arrangements: the supplier's staff who work for you are demonstrably trained in line with the requirements you set on the basis of BIO2.
- **Ask for evidence at fixed moments**, for instance at the start of the assignment and periodically thereafter, not only when an incident or an audit comes along.
- **Be specific about the form**: an overview per employee with date and result, not a general statement on letterhead.
- **Cover staff changes**: if the supplier replaces someone on the assignment, the same requirement applies to the replacement.

As a supplier, turn this around: don't wait for the request, make sure you can produce the overview today. In a tender, "we'll look into it" is a worse answer than a report already sitting there, and the same records serve you with every subsequent public sector client.

Working towards ISO 27001 certification as well? The requirements for demonstrable training look much alike: a training record you keep for BIO2 is usable evidence for your ISO auditor too. Read [ISO 27001 awareness training](/en/iso-27001-awareness-training) for exactly what is asked there.

## How to make it auditable

The common thread in both measures is evidence: not "we have a training course", but being able to show per person that it was successfully completed within the deadline and repeated afterwards.

CyberPulse records training participation, quiz results, certificates and phishing simulation outcomes per employee. New joiners work through the programme from day one, and the reporting shows per person whether the training was completed within the deadline: precisely the evidence 6.03.02 asks for. [Start a free trial](/trial).

### Checklist

- Map who falls under the requirement: your own employees as well as contractors and external staff.
- Make information security awareness training a fixed part of onboarding, with monitoring of the three-month deadline (6.03.02).
- Record per person: participation, successful completion and result.
- Plan regular refresher training for employees and the management body (5.04.01), and register that participation too.
- If you are a public body: put the BIO2 pass-through in your supplier contracts and ask for training evidence.
- If you are a supplier: keep your per-employee training records ready for public sector clients.
- Keep the evidence central and immediately retrievable, so that an audit or a contract question does not turn into a search.

Want the wider picture: which other laws and standards require training alongside BIO2, from NIS2 to ISO 27001? Read [is security awareness training mandatory?](/en/security-awareness-training-mandatory)

## Frequently asked questions

### Who does BIO2 apply to?

BIO2 applies to the whole of Dutch government: central government, municipalities, provinces and water authorities. Through contractual pass-through it also reaches those bodies' suppliers, wherever they are established. BIO2 (version 1.3) has applied since 2 March 2026 via a circular and replaces the old BIO 1.04. From 15 August 2026 the Cyberbeveiligingsregeling overheid also points to BIO2 as the way to fulfil the duty of care under the Dutch Cybersecurity Act.
### What exactly does BIO2 require in terms of awareness training?

Two measures. Measure 6.03.02: all employees and contractors have demonstrably and successfully completed information security awareness training within three months of starting employment. Measure 5.04.01: the management body and employees follow training regularly. Together they call for a training process that starts at onboarding, keeps running afterwards and is registered per person.
### Does the training requirement also apply to contractors and suppliers?

Yes. Measure 6.03.02 names contractors explicitly alongside employees, so external and agency staff must also be demonstrably trained within three months. On top of that, BIO2 works its way through to the suppliers of public bodies via contracts: they can encounter the requirement to work demonstrably in line with BIO2 in contracts and tenders, including training evidence for their people.
### What does 'demonstrably' mean in measure 6.03.02?

That you can show, per person, that the awareness training was actually and successfully completed within three months of starting employment. In practice: a record or certificate per employee with date and result. A general statement that everyone was invited to an e-learning does not suffice: the measure says successfully completed, so you must be able to prove completion.
### Is BIO2 legally mandatory?

BIO2 has applied since 2 March 2026 via a circular (BWBR0052376). From 15 August 2026 a statutory anchor is added: the Cyberbeveiligingsregeling overheid points to BIO2 as the way to fulfil the duty of care under the Dutch Cybersecurity Act. For public bodies BIO2 is therefore not optional; for suppliers the baseline works through via contractual arrangements with their public sector clients.
### How often must existing employees train under BIO2?

Measure 5.04.01 says the management body and employees follow training regularly, but names no frequency. That is yours to decide: as long as you can defend it. A continuous programme of short, recurring learning moments is the simplest route: it makes 'regularly' self-evident, covers the onboarding requirement of 6.03.02 at the same time, and produces a continuous stream of records with which you can demonstrate compliance.

## Sources

- [Wetten.overheid.nl, BIO2 circular (BWBR0052376)](https://wetten.overheid.nl/BWBR0052376/)
- [BIO-overheid.nl, Baseline Informatiebeveiliging Overheid](https://www.bio-overheid.nl/)
- [Dutch government, Cybersecurity Act in force from 15 August 2026](https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht)
