🚨  NIS2 is now in effect. Security awareness is now legally required in the EU.

Check compliance
Log in
Back to Resource Center

The IBP normenkader: what school boards must arrange before 2027 and 2030

IBP normenkader

The IBP normenkader (in full: Normenkader Informatiebeveiliging en Privacy) is the Dutch national framework for information security and privacy in primary and secondary education, written for school boards in the Netherlands. It describes in 94 concrete norms, 69 for information security and 25 for privacy, what a school organization must have in place. Two dates anchor it: by 2027 every school board must know where it stands and have a plan, and by January 1, 2030 every board must operate at maturity level 3 on all norms.

In this article we explain what the framework contains and who is behind it, how the growth path toward 2030 works, and how to run a baseline measurement so your plan rests on facts instead of assumptions.

In short

  • What: the IBP normenkader is the Dutch standard for information security and privacy in primary and secondary education, with 69 security norms and 25 privacy norms.
  • Who: school boards carry final responsibility, for all their schools.
  • 2027: self-evaluation done and a plan in place.
  • 2030: maturity level 3 on all norms from January 1, 2030.
  • Start: a baseline measurement of paper and behavior, plus an awareness habit that builds evidence over the school years.

What is the normenkader IBP?

The normenkader IBP was developed by the Digitaal Veilig Onderwijs program, a partnership of the Ministry of Education (OCW), Kennisnet, SIVON, the PO-Raad and the VO-Raad. It translates generic security standards into the language and situations of a school: pupil data in the student information system, accounts of teachers who also work on personal devices, suppliers that process data on the school’s behalf.

The framework is the sector’s answer to a practical problem: standards such as ISO 27001 were written for companies, not for a board with twenty locations and one IT coordinator. Every norm in the framework comes with a maturity level, so a board can score itself and see exactly where the gaps are. The official norms, the supporting documents and the self-evaluation instrument are published by Kennisnet on normenkaderibp.kennisnet.nl.

ICT in education: why digital safety became urgent

ICT in education has grown faster than the safeguards around it. Digital learning environments, student tracking systems, online testing and hundreds of apps process sensitive data about minors every single day. At the same time, schools have become an attractive target: ransomware incidents at school organizations have shown how one compromised account can disrupt education for weeks and expose the data of thousands of pupils.

That is why the sector chose one shared framework instead of every board writing its own policy. The framework also settles a governance question: digital safety is explicitly a board-level responsibility. The board carries final responsibility for information security and privacy across all its schools, not the individual IT coordinator who happens to care about it.

Normenkader IBP 2030: the growth path to maturity level 3

The framework comes with a growth path, the Groeipad, that spells out when which norms must be met, so boards can work toward the goal at a realistic pace. Two milestones matter most. By 2027, every school board must have completed a self-evaluation, so it knows where it stands, and must have a plan to meet all norms. By January 1, 2030, every board must reach maturity level 3 on all norms.

Maturity level 3 means that measures are documented and consistently applied: not a binder that exists somewhere, but daily practice that holds up when someone checks. For most boards the distance to level 3 is larger on the organizational and human norms than on the technical ones, and those are exactly the norms that take the longest to change.

Note that the normenkader stands on its own: it is not NIS2. Under the Dutch Cyberbeveiligingswet, only publicly funded higher education is being designated; primary and secondary schools follow the normenkader instead. More on that in the FAQ below.

Want the human norms covered while you build your plan?

Guardey trains your staff with short weekly challenges of about three minutes. Roll it out in minutes and start building evidence today.

Try Guardey free for 14 days

Baseline measurement: know where you stand with the IBP normenkader

The 2027 milestone is essentially a baseline measurement: know where you stand and put a plan under it. A good baseline combines the paper reality with the actual behavior in your schools, because those two rarely match.

  1. Run the self-evaluation. Score your organization against the norms with the official instrument and the Groeipad on the Kennisnet site. Involve the IT coordinator and the privacy officer together: information security and privacy overlap, but they are scored separately.
  2. Measure actual behavior. Policy on paper says little about what people do on a Tuesday morning. A phishing simulation shows how staff respond to a realistic attack, and a short knowledge assessment shows what they know. How to set this up, we describe in our guide to the security awareness baseline measurement.
  3. Compare and prioritize. The gap between paper and practice tells you where the real risk sits. Prioritize the norms the Groeipad puts first and the gaps that touch pupil data directly.
  4. Put it in a plan with owners and dates. The board carries final responsibility, so the plan belongs on the board’s agenda. Assign every norm an owner, repeat the measurement yearly and you have the progress file that 2027 asks for.

Security awareness in education: from paper to behavior

A significant share of the norms is not about firewalls but about people: recognizing phishing, handling pupil data with care, reporting incidents instead of hiding them. Level 3 requires that this happens consistently, which rules out the one-off study day. A workshop in September is forgotten by November, and the new colleague who starts in January never saw it at all.

Schools have a specific challenge here: teachers’ time is scarce, schedules are full and the group includes supporting staff and volunteers who rarely sit behind a desk. What fits is a short, recurring format: a few minutes of training per week, on the phone or in the browser, between two lessons. The habit itself becomes your evidence. Participation and scores per team show that awareness is trained and applied continuously, which is precisely what level 3 asks you to demonstrate.

Guardey: from IBP normenkader to a weekly habit

Guardey built its security awareness training around short weekly challenges of about three minutes, with gamification, leaderboards and streaks that keep teams engaged through the school year. Integrated phishing simulations cover the behavioral side of your baseline and show progress after it. Everything runs in the browser or in the mobile app for iOS and Android, so a teacher without a fixed workplace trains just as easily as the staff office.

The reporting is audit-ready: participation, scores and progress per team, exportable as evidence for frameworks such as NIS2 and ISO 27001, and equally usable as your file for the awareness norms in the IBP normenkader. More than 500 organizations work with Guardey, including the European Parliament. Rollout takes minutes, and on our education page you can read how schools use Guardey in practice.

Frequently asked questions about the IBP normenkader

Is the IBP normenkader mandatory?

The normenkader is the standard the education sector itself has committed to, with fixed milestones: a self-evaluation and plan by 2027, maturity level 3 by January 1, 2030. It is not a law in the way the AVG is, but boards are expected to demonstrate progress along the Groeipad, and the milestones are treated as binding within the sector.

IBP normenkader in education: does it also apply to mbo, hbo and wo?

No. The normenkader IBP is written for primary and secondary education. Vocational and higher education work with the SURF frameworks, and publicly funded higher education is being designated under the Cyberbeveiligingswet, the Dutch implementation of NIS2. How NIS2 treats education, including thresholds and obligations, we explain in our article on NIS2 requirements for education.

What is maturity level 3?

The framework scores every norm on a maturity scale. Level 3 means measures are documented and consistently applied: the same secure behavior in every school, every week, with evidence to show for it. That combination of documentation plus consistent practice is what boards must reach on all norms by January 1, 2030.

Where do you start if you have done nothing yet?

Start with the two measurements this school year: the self-evaluation for the paper side and a phishing simulation plus knowledge assessment for the behavioral side. Together they produce the plan that 2027 asks for. Start the awareness program right away as well, because habits are the slowest thing to build and the evidence has to grow over multiple school years.

The IBP normenkader looks like a compliance exercise, but underneath it is a simple promise to pupils and parents: their data is safe at school. Boards that start now can spread the work over three school years and let the human norms, the slowest ones, mature in time. Boards that wait until 2029 will find that behavior does not change in a semester.

See how Guardey helps schools meet the awareness norms?

In a 45-minute demo we show the weekly challenges, the phishing simulations and the reports you can use as evidence toward level 3.

Request a demo
Dinela Lokvancic
Dinela Lokvancic Marketing Specialist Dinela keeps Guardey's online presence up to date. She creates content that makes complex cyber security topics accessible, and helps organizations understand why security awareness training matters for their teams.
READY TO GET STARTED?

Join 500+ businesses already protecting their teams with Guardey

Start your free 14-day trial
14 days free · No credit card · Full access · Setup in 5 minutes
Or schedule a personalised demo