Market perspective
ISO/IEC 42001, SOC 2 and ISO/IEC 27001 in the Netherlands
Dutch organizations may have private customer assurance questions and public-sector or NIS2-related security questions at the same time. ISO/IEC 42001 governs AI use; SOC 2 examines a service; ISO/IEC 27001 can anchor security management. Dutch BIO2 and Cyberbeveiligingswet guidance matter only where the relevant scope applies.
Define AI use before selecting controls
Begin an ISO/IEC 42001 project with the AI systems the organization develops, supplies, or uses. Record internal tools as well as customer-facing features. Separate the legal entity and process boundary of the AI management system from a customer's service and from any public-sector contract.
For each significant system, capture intended use, data and supplier dependencies, risks, impacts, performance measures, and the owner who can accept or reject a change. This becomes the evidence base for repeatable review rather than a catalogue of policy intentions.
Use BIO2 context precisely
The Dutch government's Baseline Informatiebeveiliging Overheid, BIO2, is a baseline for public authorities. Official guidance says it reflects ISO/IEC 27001 and ISO/IEC 27002. A supplier serving a public authority should ask what its contract actually requires and which part of the service or supply chain must support that authority's controls.
Do not label a private SaaS provider BIO2-compliant solely because it has ISO/IEC 27001 certification. Map the specific customer controls, shared responsibilities, evidence, and contractual commitments. Keep a written record of differences.
Assess NIS2 coverage under Dutch guidance
The Netherlands implements NIS2 through the Cyberbeveiligingswet, and the Dutch NCSC publishes guidance on scope, registration, and reporting. The first implementation step is to determine whether the organization and service are in scope; do not apply a generic NIS2 checklist to every customer.
Where the law applies, assign accountable owners for risk management, incidents, continuity, and supplier security. ISO/IEC 27001 processes can support those activities, but legal duties and reporting routes need separate validation. An ISO certificate alone is not a legal conclusion.
Make SOC 2 relevant to buyer due diligence
A Dutch technology provider may use SOC 2 when customers, including international buyers, require an independent report on a defined service. Set the reporting boundary and Trust Services Criteria with the actual buyer question in mind. Build an evidence calendar and record subservice dependencies before the examination period.
ISO/IEC 42001, ISO/IEC 27001, and SOC 2 can share access, change, vendor, and incident processes. Each claim still requires its own scope and outcome. A customer-facing trust pack should state these differences plainly.
Common questions
Clarify the outcome before the work.
Does BIO2 apply to every Dutch private company?
No. BIO2 is the Dutch public-sector information security baseline. A private supplier should assess any customer or contractual expectations separately.
Is ISO/IEC 27001 certification enough for the Cyberbeveiligingswet?
No automatic legal conclusion follows. Applicability and obligations must be assessed against the Dutch law and official guidance.
Is SOC 2 a Dutch legal requirement?
No. It is an AICPA service assurance examination generally considered when customers ask for that report.
Read next
A practical path from here.
ISO/IEC 42001
How to build an AI inventory for ISO/IEC 42001
The fields, ownership decisions, and review triggers that make an AI inventory useful beyond an initial assessment.
Cross-framework
ISO 27001, SOC 2, and ISO 42001: what to share and what to keep distinct
Three different assurance questions, one disciplined control operation. A guide to sequencing and reusing evidence responsibly.
SOC 2
SOC 2 for European SaaS companies: when it helps and how to prepare
A buyer-led guide to SOC 2 in Europe: the right trigger, a defensible scope, and how it sits beside ISO 27001 and GDPR.
Work with Normstone
Make the next assurance decision clear.
Tell us your service, AI use, and customer requirements. We’ll help shape the scope.