Municipalities are required to report annually on information security. An ENSIA audit helps demonstrate how your organisation meets the applicable requirements and provides insight into the effectiveness of your information security controls.

RSM IT Audit supports municipalities with the annual ENSIA audit. We combine knowledge of the public sector with experience in information security and IT audit engagements.

What is an ENSIA audit?

ENSIA stands for Eenduidige Normatiek Single Information Audit. Through ENSIA, municipalities report in a uniform way on information security, based among other things on the Baseline Informatiebeveiliging Overheid (BIO2), the Dutch Government Information Security Baseline.

By integrating ENSIA into the Planning & Control cycle, your municipality gains:

  • better insight into information security risks
  • clear responsibilities within the organisation
  • useful management information for the municpal board and management

Through ENSIA, municipalities report to parties including the municipal council, central government and supervisory authorities.

ENSIA and the Dutch Cybersecurity Act

Since 15 August 2026, the Dutch Cybersecurity Act has been in force. The Act implements the European NIS2 Directive and introduces additional requirements for the digital resilience of municipalities.

Municipalities must comply with requirements relating to areas such as risk management, incident reporting and management responsibility for information security.

Annual ENSIA reporting helps provide insight into how information security is managed within the municipality and supports accountability for the measures taken. The Cybersecurity Act also contains its own statutory obligations. An ENSIA audit therefore does not constitute a full assessment of compliance with the Cybersecurity Act.

How does an ENSIA audit work?

Each year, your municipality carries out a self assessment as part of ENSIA. Based on this assessment, the areas that fall within the scope of the audit are determined. The relevant reporting documentation must be submitted no later than 30 April of the following year.

RSM IT Audit supports you with:

  • preparing an efficient audit plan
  • assessing policies, processes and controls
  • performing the audit in accordance with ENSIA guidelines
  • preparing the audit report

Our auditors have experience with ENSIA audits, DigiD audits, WPG audits and other IT audits within the public sector. This helps ensure that the audit is carried out carefully, efficiently and within the required timeframe.

What can you expect from RSM IT Audit?

Ervaring met audits bij Experience with audits for municipalities and public sector organisations en overheidsorganisaties

Our auditors have extensive experience with audits for municipalities and other organisations within the public sector.

Knowledge of ENSIA, DigiD, WPG and IT Audit

You are supported by auditors with knowledge of ENSIA, DigiD, WPG, IT Audit and relevant laws and regulations.

Focus on quality and deadlines

A structured approach helps your municipality complete the audit process efficiently and submit the required reporting on time.

Need an ENSIA audit for your municipality?

Would you like to know more about carrying out an ENSIA audit or discuss what is required for your municipality? Contact the RSM IT Audit specialists.

Do you have a question? We will get back to you as soon as possible.

Frequently asked questions about ENSIA audits

An ENSIA audit, Eenduidige Normatiek Single Information Audit, forms part of the annual reporting process for municipalities on information security. This includes requirements based on the Baseline Informatiebeveiliging Overheid (BIO2).

Municipalities are required to report annually on information security to parties including the municipal council, central government and supervisory authorities. ENSIA provides a uniform and structured framework for this reporting.

An ENSIA audit assesses areas including:

  • the design and operation of security controls
  • compliance with selected BIO2 standards
  • information security processes
    specific areas such as DigiD and Suwinet

Municipalities carry out an ENSIA self assessment every year. The relevant reporting documentation must be submitted no later than 30 April of the following year.

The Dutch Cybersecurity Act sets requirements for the digital resilience of municipalities. ENSIA supports annual reporting on information security and provides insight into the controls that have been implemented. The Cybersecurity Act also contains separate obligations, including requirements relating to risk management and incident reporting.

Through ENSIA, municipalities report on information security based in part on the Baseline Informatiebeveiliging Overheid (BIO2). BIO2 is an important framework for information security within Dutch government organisations.

ENSIA covers several areas of municipal information security reporting. DigiD is one of the specific areas for which security requirements apply and on which municipalities report through ENSIA.

Good preparation includes:

  • ensuring policies and documentation are up to date
  • carrying out internal controls
  • identifying information security risks
  • carrying out a pre audit or baseline assessment where appropriate

Yes. RSM supports municipalities both in preparing for the ENSIA audit, for example through a baseline assessment, and in carrying out the audit itself.