Custom BIO-compliant software development
Appfront builds custom software for government organisations in line with the Baseline Information Security Government (BIO). Designed on a risk-based basis, with logging and monitoring, least-privilege access control, encryption and patchability, and with the technical justification your CISO, auditors and procurement teams need. The BIO is a standards framework, not a certification; we demonstrate that the software fits within your information security framework, while your organisation remains ultimately accountable.
What is BIO-compliant software?
The Baseline Information Security Government (BIO) is the information security standards framework for the Dutch government, based on the international standards NEN-EN-ISO/IEC 27001 and 27002. The current version, BIO2, replaces the earlier division into baseline security levels (BBNs) with a more explicit risk-based approach. BIO-compliant software is custom software that supports the control measures a government organisation needs in order to meet the BIO.
In practice, that means: a risk-based design, access control with least privilege, encryption of data in transit and at rest, comprehensive and searchable logging and monitoring, a working patch and vulnerability process, and data minimisation. Equally important is what it isn't: the BIO is not a certificate. There is no BIO quality mark that a supplier can obtain; we demonstrate conformity with the BIO through technical documentation and justification for each measure.
For many government processes, custom software is a better fit than a standard package: you decide which data is processed, how authorisation is set up and how far logging goes, without being tied to a supplier's choices. Appfront builds on a risk basis, in line with the BIO, and provides the supporting documentation that fits your information security policy and your accountability. You can find the official explanation of the BIO at digitaleoverheid.nl.
Designed on a risk-based basis
The strictness of security measures follows from the sensitivity of the data and the risk profile of the application — not a fixed checklist, but measures aligned with your risk assessment under BIO2.
Demonstrable and traceable
Comprehensive logging, clearly documented access models and justification for each measure. Your CISO and auditor get the information needed for accountability, and you can support RFI and tender questions with facts.
You remain ultimately accountable
The BIO leaves ultimate responsibility with your organisation. As a supplier in the chain, we build software so that you can take and demonstrate the necessary measures, and we record the division of responsibilities transparently.
How Appfront builds BIO-compliant software
We work on a risk-based basis, with information security from the very first step. From a risk assessment together with your information security officer through to go-live and ongoing management, every step provides the justification needed to fit within your BIO accountability. This keeps your team in control and the software demonstrably secure.
Together with your CISO or information security officer, we map out which data is processed, what the risk profile is and which BIO measures apply. This gives a clear scope and division of responsibilities.
We design the architecture with access control, encryption, logging and authorisation built in from the start, not added as an afterthought. Decisions are justified and documented for each relevant BIO measure.
Implementation using secure development practices, automated tests, structured logging and monitoring. You see working versions along the way, and penetration tests form part of the handover.
Controlled go-live, followed by ongoing management with a working patch and vulnerability process, monitoring and agreed incident response, so that the software remains BIO-compliant.
Control measures we build in as standard
Exactly which measures are required follows from your risk assessment, as the BIO is risk-based. Below are the control measures we most often build into government software, each justified and documented so that they contribute to your accountability.
Access control & least privilege
Role-based authorisation so that every user and every system has access only to what is strictly necessary. Strong authentication, segregated rights and periodic access reviews, so that misuse and errors are limited and traceable.
Logging & monitoring
Comprehensive, searchable and exportable logging of who did what and when, with monitoring and alerting for anomalies. The foundation for incident detection, forensic investigation and annual accountability, for example to ENSIA for municipalities.
Data encryption
Encryption of data in transit (TLS) and at rest, with careful secrets management. Keys and certificates are managed securely and rotated, so that sensitive government data stays protected, including in the event of a data breach at infrastructure level.
Patchability & vulnerability management
Software that is maintainable and quick to patch, with a working process for following up vulnerabilities in dependencies. Updates can be rolled out safely and in a controlled manner without compromising how the process operates.
Data minimisation
We process only the personal data necessary for the process and document the data flows for your processing register. This way the software supports both the relevant BIO measures and the GDPR, without duplicated effort.
Justification per measure
Technical documentation showing, for each relevant BIO measure, how it has been implemented, with penetration test reports and a clear division of responsibilities. Precisely the justification that buyers ask for in an RFI or tender.
For which government organisations
Building BIO-compliant software matters wherever government data is processed. The organisations below almost always ask for it in an RFI or tender, and for each of them we tailor the measures to the risk profile and the applicable chain frameworks.
Municipalities
Municipalities process large volumes of personal data and report annually via ENSIA on, among other things, the BIO (Dutch Baseline Information Security Standard). Our software supports this with full logging and clear access models. Also read about software for municipalities and AI for municipalities and government.
Provinces & water boards
For provinces and water boards, the BIO2 is mandatory self-regulation. Custom software often fits better here than an off-the-shelf package, as processes and risk profiles differ considerably. We build on a risk-based basis and provide the supporting justification for each measure for your Information Security Officer.
Implementing bodies & ZBOs
Implementing bodies and independent administrative authorities that work with chain systems, such as Suwinet with its own compliance framework, need strict access control and logging. We build integrations that fit within your BIO approach; see our example of a Suwinet integration.
Processes involving sensitive data
Social domain, enforcement, healthcare and safety: processes where the impact of a data breach is significant. Here, the risk assessment carries substantial weight, and encryption, least privilege and demonstrable logging are essential. We tailor the measures to the sensitivity of the data.
Test your idea first: a working prototype in 1 day
With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.
Explore OneDayBuild →Technology and government integrations
We build on a modern, maintainable web stack that can be patched quickly, a prerequisite for BIO compliance. Where the government process requires it, we integrate with national services. These integrations have their own connection requirements and frameworks that apply alongside the BIO; we build them with appropriate encryption, authorisation and logging. See, for example, our pages on DigiD integration, Digikoppeling, ZGW API integration and the Suwinet integration as an example of a dedicated framework.
Why choose Appfront for BIO-compliant software?
Appfront builds custom software for organisations in the Netherlands and always begins with a thorough analysis of processes, data and risks. Information security is not an afterthought but a starting point: we design on a risk-based basis, in line with the BIO, and provide the justification that supports your accountability.
On every project we write clear documentation, so that your own team, or any future supplier, can understand, manage and patch the software. No black box, but transparent code and clear agreements on monitoring, alerting, patching and incident handling.
We are honest about the chain: your organisation remains ultimately responsible for complying with the BIO, and we set out in advance which responsibilities lie with you and which with us. No empty claims such as "BIO-certified" (which does not exist), but demonstrable work that fits within your framework.
See also our software for municipalities and AI for municipalities and government, or get in touch directly for an advisory conversation.
- Risk-based design in line with the BIO2 (ISO 27001/27002)
- Access management with least privilege and role-based authorisation
- Encryption in transit and at rest, with careful secrets management
- Comprehensive, exportable logging and monitoring from day one
- A working patch and vulnerability process; regular penetration testing
- Justification per measure for CISOs, auditors and RFIs
- A transparent division of responsibilities across the chain
- Experience with government integrations (DigiD, Digikoppeling, ZGW, Suwinet)
- Clear documentation your team can read and manage
- No misleading claims: the BIO is a standards framework, not a certificate
BIO, GDPR and your accountability
The Dutch Baseline Information Security for Government (BIO) focuses on information security; the GDPR focuses on protecting personal data. In government software these almost always go hand in hand. Appfront builds on a risk-based basis, in line with BIO2, and follows secure development practices such as the OWASP ASVS: least-privilege access control, encryption, logging and monitoring, and a working patch process.
We work with data minimisation as a starting point and document the data flows, so your record of processing activities is complete and you can demonstrably comply with the GDPR. Importantly, and honestly: your organisation remains ultimately responsible for complying with the BIO, and that responsibility cannot be outsourced. We fulfil the supplier role in the chain and provide the justification per measure that supports your accountability and, for municipalities, the annual ENSIA reporting.
More about our approach to security: information security policy and CVD policy (coordinated vulnerability disclosure). The official explanation of the BIO is available at digitaleoverheid.nl.
- Risk-based in line with BIO2 (ISO 27001/27002)
- GDPR-compliant data processing and data minimisation
- Encryption in transit (TLS 1.2+) and at rest
- Role-based access and least-privilege principles
- Comprehensive, exportable audit logging
- Monitoring and alerting for anomalies
- Patch and vulnerability process; regular penetration tests
- Evidence per control for CISO, auditor and ENSIA
See also our other procurement pages: accessible software (WCAG), procuring custom software and Appfront as a software supplier to government.
Frequently asked questions about BIO-compliant software
Answers to the questions procurement officers and information security officers ask us most often about building in line with the BIO.
The Dutch Baseline Information Security for Government (BIO) is the framework of standards for information security within the Dutch government. It is based on the international standards NEN-EN-ISO/IEC 27001 and 27002. The current version is BIO2, which replaces the earlier division into baseline security levels (BBNs) with a more explicit risk-based approach. BIO-compliant software means software that supports the security measures a government organisation needs to meet the BIO: risk-based design, logging and monitoring, least-privilege access control, data encryption and patchability. Important to note: the BIO is a framework of standards, not a certificate, and there is no BIO certification mark a supplier can obtain.
No, and this question rests on a misunderstanding we are keen to correct: the BIO is a framework of standards, not a certification scheme. There is no official BIO certificate a software supplier can obtain. What a supplier can do is build software in line with the requirements the BIO sets and demonstrate this: with technical documentation, an overview of implemented security measures, logging and access models, and penetration test reports. This is how Appfront works, and we provide the evidence your information security officer (CISO) and auditor need. Anyone who claims to be 'BIO-certified' is describing something that formally does not exist.
The government organisation always remains ultimately responsible for complying with the BIO; that responsibility cannot be outsourced. A municipality, province or water board makes risk assessments, adopts its information security policy and is accountable for it. A software supplier such as Appfront plays a role in the chain: we build the software so the organisation can take and demonstrate the necessary control measures. We record agreements on patching, monitoring, incident handling and the division of responsibilities in clear documentation and, where relevant, a data processing agreement. This way our work aligns with your accountability, without us taking it over.
Government organisations are required to comply with the BIO and must be able to demonstrate that the software they procure fits within their information security framework. For this reason, buyers ask questions in a Request for Information (RFI) or tender about how a supplier handles logging, access management, encryption, patch management and incident response. They often ask for substantiation per BIO measure, for penetration testing policy, and for the division of responsibilities across the supply chain. A supplier that can answer these questions concretely and honestly, including what is and is not their responsibility, makes the buyer's assessment demonstrably easier.
Building BIO-compliant software is risk-based: the scope of the measures follows from the sensitivity of the data and the risk profile of the application. In practice, this means access management based on least privilege and role-based authorisation, strong authentication, encryption of data in transit and at rest, comprehensive and searchable logging and monitoring, a working patch and vulnerability management process, data minimisation, and secrets management. A process should accompany these: regular penetration tests, secure development practices and agreed incident response. We tailor the set of measures to your risk assessment rather than ticking off a fixed checklist.
ENSIA (Eenduidige Normatiek Single Information Audit, the standardised single information audit) is how municipalities account each year for information security, including for the BIO and for specific chains such as Suwinet and the BAG. Our software contributes indirectly: complete, exportable logging, clearly documented access models and demonstrable control measures make the annual ENSIA accountability easier to substantiate. We do not make the software 'ENSIA-proof' on your behalf, as the accountability stays with the municipality, but we make sure the information you need is available and traceable.
The BIO focuses on information security, the GDPR on the protection of personal data; they overlap but are not the same. In government software they almost always apply together. Appfront builds with data minimisation as a starting point, documents the data flows for your record of processing activities, and configures security measures so that they support both the GDPR and the relevant BIO measures. Where personal data is processed, we record agreements in a data processing agreement. This allows you to demonstrably comply with both frameworks without duplicated effort.
Yes. Integrations with national services such as DigiD, Digikoppeling and the case-oriented working APIs (ZGW) come with their own frameworks and connection requirements that apply alongside the BIO. Suwinet is a telling example: the connection has its own framework and strict requirements for logging and authorisation. Appfront builds these integrations so that they fit within your broader BIO approach: with appropriate encryption, authorisation and logging, and with documentation showing how the integration meets the applicable requirements. We state upfront, and honestly, which connection requirements and responsibilities lie with you and which with us.
Ready to build BIO-compliant software?
Tell us which government process you want to support, what data is processed in it, and which requirements your procurement team or CISO sets. We are happy to think along about the risk assessment, the appropriate control measures and the substantiation you need. A no-obligation first conversation will quickly give you a clear picture of an approach that fits your BIO accountability.