| Abbreviation |
Name of the Norm |
| 33 CFR Part 101 |
Department of Homeland Security USA Coast Guard 33 CFR Parts 101 |
| BIC |
Baseline Informatiebeveiliging Corporaties |
| BIO 1 |
Baseline Information Security for the Dutch Government version 1.04 |
| BIO 2 |
Baseline Information Security for the Dutch Government version 2.0 |
| BSI IT-Grundschutz |
BSI IT-Grundschutz Standard 200-3 |
| CBW |
CBW – Cbw (NIS2) Control Framework |
| CIS v8 |
CIS Critical Security Controls Version 8 |
| CyFun |
CyberFundamentals Framework |
| CyRa |
Cyber Rating |
| Cyber Resilience Act (CRA) |
Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) |
| DigiD 1.0 |
DigiD norm v1.0 |
| DigiD 2.0 |
DigiD norm v2.0 |
| DigiD 3.0 |
DigiD norm v3.0 |
| DigiD 4.0 |
DigiD norm v4.0 |
| DORA |
The Digital Operational Resilience Act |
| Digital Services Act (DSA) |
Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act) (Text with EEA relevance) |
| GDPR/AVG |
General Data Protection Regulation |
| HIPAA |
Health Insurance Portability and Accountability Act |
| IBP FO |
IBP – Normenkader Digitaal Veilig Funderend Onderwijs |
| ISAE 3402 |
Assurance Reports on Controls at a Service Organization |
| ISO 27001:2013 |
Code for Practice for Information Security Controls |
| ISO 27001:2017 |
Code for Practice for Information Security Controls |
| ISO 27001:2022 |
Code for Practice for Information Security Controls |
| ISO 27017:2015 |
Code for Practice for Information Security Controls based on ISO/IEC 27002 for Cloud Services |
| ISO:80001-1:2021 |
Application of risk management for IT-networks incorporating medical devices |
| NBA:2019 |
Volwassenheidsmodel Informatiebeveiliging v2.0 van de NBA |
| NCSC |
ICT-beveiligingsrichtlijnen voor webapplicaties |
| NEN 7510:2017 |
Information Security Management in Healthcare |
| NEN 7510:2024 |
Information security management in healthcare |
| NIS2 |
NIS2 Directive |
| NIS2 Quality Mark |
NIS2 Quality Mark |
| NIS2UmsuCG |
Law “on the implementation of the NIS 2 Directive and on the regulation of essential principles of information security management in the federal administration.” |
| NIST 1.1 |
NIST Cybersecurity Framework v1.1 |
| NIST 2.0 |
NIST Cybersecurity Framework v2.0 |
| NOREA |
Logius / NOREA Norm ICT-beveiliginsassessments |
| OWASP 2017 |
Open Web Application Security Project 2017 edition |
| OWASP 2021 |
Open Web Application Security Project 2021 edition |
| OWASP 2025 |
Open Web Application Security Project 2025 edition |
| PCI DSS |
Payment Card Industry Data Security Standard |
| saMBO ICT |
Normenkader Informatiebeveiliging MBO |
| SOC |
System and Organization Controls: SOC Suite of Services |
| SURFaudit |
SURFaudit Assessment Framework for Information Security v2.3d |
| TISAX |
TISAX |