Market perspective

ISO/IEC 42001, SOC 2 and ISO/IEC 27001 in the Netherlands

Dutch organizations may have private customer assurance questions and public-sector or NIS2-related security questions at the same time. ISO/IEC 42001 governs AI use; SOC 2 examines a service; ISO/IEC 27001 can anchor security management. Dutch BIO2 and Cyberbeveiligingswet guidance matter only where the relevant scope applies.

Define AI use before selecting controls

Begin an ISO/IEC 42001 project with the AI systems the organization develops, supplies, or uses. Record internal tools as well as customer-facing features. Separate the legal entity and process boundary of the AI management system from a customer's service and from any public-sector contract.

For each significant system, capture intended use, data and supplier dependencies, risks, impacts, performance measures, and the owner who can accept or reject a change. This becomes the evidence base for repeatable review rather than a catalogue of policy intentions.

Use BIO2 context precisely

The Dutch government's Baseline Informatiebeveiliging Overheid, BIO2, is a baseline for public authorities. Official guidance says it reflects ISO/IEC 27001 and ISO/IEC 27002. A supplier serving a public authority should ask what its contract actually requires and which part of the service or supply chain must support that authority's controls.

Do not label a private SaaS provider BIO2-compliant solely because it has ISO/IEC 27001 certification. Map the specific customer controls, shared responsibilities, evidence, and contractual commitments. Keep a written record of differences.

Assess NIS2 coverage under Dutch guidance

The Netherlands implements NIS2 through the Cyberbeveiligingswet, and the Dutch NCSC publishes guidance on scope, registration, and reporting. The first implementation step is to determine whether the organization and service are in scope; do not apply a generic NIS2 checklist to every customer.

Where the law applies, assign accountable owners for risk management, incidents, continuity, and supplier security. ISO/IEC 27001 processes can support those activities, but legal duties and reporting routes need separate validation. An ISO certificate alone is not a legal conclusion.

Make SOC 2 relevant to buyer due diligence

A Dutch technology provider may use SOC 2 when customers, including international buyers, require an independent report on a defined service. Set the reporting boundary and Trust Services Criteria with the actual buyer question in mind. Build an evidence calendar and record subservice dependencies before the examination period.

ISO/IEC 42001, ISO/IEC 27001, and SOC 2 can share access, change, vendor, and incident processes. Each claim still requires its own scope and outcome. A customer-facing trust pack should state these differences plainly.

Common questions

Clarify the outcome before the work.

Does BIO2 apply to every Dutch private company?

No. BIO2 is the Dutch public-sector information security baseline. A private supplier should assess any customer or contractual expectations separately.

Is ISO/IEC 27001 certification enough for the Cyberbeveiligingswet?

No automatic legal conclusion follows. Applicability and obligations must be assessed against the Dutch law and official guidance.

Is SOC 2 a Dutch legal requirement?

No. It is an AICPA service assurance examination generally considered when customers ask for that report.

Work with Normstone

Make the next assurance decision clear.

Tell us your service, AI use, and customer requirements. We’ll help shape the scope.

Start a conversation