Skip to main content

BIO and ABDO for public sector organisations

One platform for the BIO, your ENSIA accountability and ABDO. Ready-made control frameworks, evidence that collects itself, and one dossier your IT auditor and the executive board can both look into.

  • BIO, ENSIA and ABDO on one set of controls
  • Evidence that collects itself through integrations
  • Built and hosted in the EU
The Tidal Control dashboard showing progress on ABRO

What public sector organisations achieve with Tidal

35+
Frameworks on one set of controls, including BIO, ABDO and ISO 27001
300+
Automated tests on your cloud and tooling
1 dossier
For your IT auditor and the executive board, instead of separate folders

Why the BIO is a sprint every year

The work runs all year, the accountability comes once a year.

  • Searching again every year

    For the ENSIA cycle, evidence is gathered from scratch each time, out of folders and mailboxes.

  • Outsourcing without oversight

    Hosting, case management and archiving sit outside the organisation, but the responsibility does not.

  • Controls without an owner

    When nobody owns a control, it waits until just before the accountability round.

  • Frameworks side by side

    BIO, ENSIA and sometimes ABDO are kept separately, while the controls largely overlap.

How public sector organisations use Tidal

From the BIO controls to the executive statement, always from the same source.

The BIO controls, set up and ready

The BIO is the mandatory baseline for central government, municipalities, provinces and water authorities, and follows the structure of ISO 27002. In Tidal those controls are mapped and waiting, each with an owner and a status, so you never start from a blank page.

More on the BIO
The controls overview in Tidal Control, with status, progress and framework per control

Evidence for your controls collects itself

Connect Azure and Entra ID and the rest of your tooling. Tidal pulls the evidence in automatically and attaches it to the right control, so you stop chasing screenshots when the ENSIA cycle comes round again.

See all integrations
Connected integrations in Tidal Control, including Azure, Google Workspace and Google Cloud

Outsourcing in view, including the risk

You may outsource the work, not the responsibility. From hosting provider to case management system: Tidal tracks the risk per supplier and whether the security annex to the contract actually exists.

More on vendor management
Vendors in Tidal Control with risk rating and assessment status

One dossier for ENSIA and your IT auditor

DigiD, Suwinet, BAG, BGT, BRO, BRP and PNIK all run through the same annual cycle. In Tidal those accountability reports build themselves from your live data, so the executive statement and the assurance report are one export.

More on controls and reporting

ENSIA accountability

PDF

  • DigiDCurrent
  • SuwinetCurrent
  • BAG, BGT and BROCurrent
  • BRP and PNIKCurrent

Manual or with Tidal

  • ENSIA accountability

    Manual

    A sprint every year

    With Tidal

    From the same evidence as the BIO

  • BIO controls

    Manual

    A spreadsheet

    With Tidal

    Pre-mapped with owner and status

  • Suppliers and outsourcing

    Manual

    Spread across contracts

    With Tidal

    Risk and agreements per supplier

  • Evidence current between rounds

    Manual

    Not included

    With Tidal

    Continuous tests through your integrations

  • BIO and ABDO together

    Manual

    Two sets of records

    With Tidal

    One set of controls

From baseline assessment to accountability, with government as the starting point

No certificate, but accountability: you set it up once and then follow the annual cycle.

  1. Stage 1

    Baseline assessment

    We map your processes, systems and base registries and test them against the BIO. You see immediately where you stand and what the next accountability cycle requires.

  2. Stage 2

    Setup

    Policy, risk analysis and controls go into Tidal, with templates written for public sector organisations.

  3. Stage 3

    Accountability

    Your evidence is ready and keeps collecting itself through your integrations. The IT auditor and the executive board get one dossier instead of separate folders per base registry.

  4. After that

    Keeping it current

    It does not stop at the report. The annual ENSIA cycle, new suppliers and changes to the standard are handled in the same system.

Connect the systems you already use

  • Azure
  • Entra ID
  • Google Workspace
  • TOPdesk
  • Microsoft Sentinel
  • Jira
  • OVHcloud
  • Scaleway
  • STACKIT
  • Hetzner
  • AWS
  • All integrations

In the public sector this is not the organisation's choice

Four frameworks that are already fixed for public sector organisations.

BIO
The mandatory baseline for central government, municipalities, provinces and water authorities
ENSIA
Annual accountability for DigiD, Suwinet and the base registries
ABDO
Security requirements for organisations carrying out work for the Ministry of Defence
NIS2
The Dutch Cybersecurity Act brings a duty of care and a reporting duty for public sector organisations

Frequently asked questions

Yes. The BIO is the established baseline for central government, municipalities, provinces and water authorities. Unlike ISO 27001 it is not about a certificate, but about demonstrably complying and accounting for it.

The BIO follows the structure of ISO 27002 and is the public sector reading of it. If you have already implemented ISO 27001 you will recognise most of the controls; on top of that, the BIO fixes the minimum level you have to reach.

The BIO says what you have to arrange, ENSIA is the annual accountability for it, with its own control frameworks for DigiD, Suwinet and the base registries. In Tidal you set up the BIO once and use the same evidence for the ENSIA cycle.

When you carry out work for the Ministry of Defence involving classified information. ABDO then adds requirements for personnel, physical security and information security, on top of what you already do for the BIO or ISO 27001.

That depends on your size and what is already in place. After the baseline assessment you see per control what is left to do, so you know what the next accountability round needs. After that you follow the annual cycle in the same system.