Cyberattacks rarely stay confined to a single target. In many cases, the same ransomware campaign, phishing infrastructure, or malicious indicators can affect multiple organizations at once. To reduce the chance that one party’s discovery becomes everyone else’s delayed lesson, organizations need a fast, standardized way to exchange threat information.
That is where STIX/TAXII 2.1 comes in. The NCSC has submitted STIX/TAXII version 2.1 for inclusion on the Dutch “comply or explain” list of Forum Standaardisatie. Since 1 July 2026, STIX and TAXII 2.1 have been added to that list—replacing the older version already listed. For Dutch municipalities, provinces, the central government, water authorities, and all their implementing organizations, this means the standard must be requested when buying or developing security solutions, unless there is a well-founded reason not to.
Below, we explain what STIX/TAXII 2.1 enables, why it is technically different from earlier versions, and how you can adopt it step by step in your own environment.
Why threat intelligence sharing needs to be fast
Consider a scenario in which an organization—or a key supplier—becomes the target of a ransomware campaign that is still not fully understood. Analysts may identify indicators of compromise, such as IP addresses or domains associated with the attack.
With STIX, these indicators can be captured in a structured, machine-readable format. Through the TAXII protocol, the same information can then be shared in an automated way—encrypted and ready for consumption by partner organizations, other suppliers, or sector-based collaboration groups such as an ISAC.
The benefit is operational speed. Security tools in connected organizations—think SIEM or XDR systems—can ingest the indicators directly and detect comparable malicious activity without waiting for manual interpretation. If desired, they can also take protective actions such as blocking.
In practice, this turns local observation into collective action, so other parties do not spend time re-creating or re-identifying indicators. The entire ecosystem gains time, which is often the difference between containment and escalation.
What “real-time” sharing looks like in a SOC
One reason STIX/TAXII 2.1 matters is that it supports more consistent end-to-end workflows inside security operations centers (SOCs). Imagine two organizations exchanging threat intelligence: indicators flow from one to the other, and observations can be fed back again.
In a SOC setup with SIEM and SOAR components, automation can connect the dots: detections and sightings can be processed as structured data, then distributed to partners according to the agreed technical standard. The goal is not just to send information outward, but to create a feedback loop so what one organization learns becomes useful to others quickly.
What improves with STIX/TAXII 2.1
STIX/TAXII 2.1 brings practical improvements that make automation and scale easier compared to older STIX/TAXII 1.x implementations.
From complex one-way exchange to bidirectional workflows
In earlier STIX/TAXII 1.x versions, the return of threat information and sightings was theoretically possible. However, real-world implementations often ended up as one-directional sharing due to complexity.
STIX/TAXII 2.1 improves this substantially by using a modern JSON-based data model and a REST architecture, rather than relying on older XML and SOAP structures. The result is that implementing automated, bidirectional exchange—including the direct sharing of sightings—becomes much simpler. That makes it feasible to use at larger scale.
More clarity in how threat knowledge is modeled
STIX 2.1 also offers better structure for modeling threat intelligence. Where STIX 1.x objects could be reused for multiple purposes, STIX 2.x splits practical concepts into clearer entities such as Attack Pattern, Malware, Tool, and Vulnerability.
This helps teams and partners communicate threat information in a consistent way, reducing ambiguity about how the intelligence should be interpreted.
Better scalability for larger datasets
Another improvement is scalability. TAXII 2.1 includes features such as pagination, batch processing, and improved filtering. These capabilities allow organizations to process larger datasets more efficiently than in TAXII 1.x.
For teams that receive frequent updates from multiple sources, this can be a key difference between a workflow that works in testing and one that holds up during high-volume incidents.
Integration via RESTful APIs over HTTPS
STIX/TAXII is built on RESTful APIs over HTTPS. That simplifies integration between systems used by different organizations—because they can connect through common web standards rather than being tied to bespoke mechanisms.
Additionally, because STIX/TAXII is an open standard, dependency on a single vendor’s proprietary approach is reduced. The underlying technology provides a solid foundation for threat information exchange.
Who needs to use STIX/TAXII 2.1 in the Netherlands
Since 1 July 2026, STIX and TAXII 2.1 have been added to the Dutch “comply or explain” list. For Dutch municipalities, provinces, the central government, water authorities, and all implementing organizations, the implication is clear:
- When buying or developing security solutions, they must request this open standard.
- They may only deviate with a well-justified reason.
- Other organizations are encouraged to adopt STIX/TAXII 2.1 for exchanging threat intelligence as well.
If you operate as a supplier to public bodies—or you deliver security platforms used by public-sector partners—this change will likely influence procurement requirements and project specifications.
A practical 4-step path to adopt STIX/TAXII 2.1
Adoption works best when you treat STIX/TAXII 2.1 as an enablement project for your threat intelligence workflow, not just as a technology switch. Here is a four-step approach derived from the NCSC guidance.
1) Inventory your current CTI capabilities
Start by mapping what threat information you already receive. For example, do you get intelligence from the NCSC, commercial feeds, or sector partners? Then look at how you process it today.
Pay attention to how much of the workflow is manual or dependent on scripts. This baseline helps you estimate the effort needed to move to structured, standardized exchange.
2) Check whether your systems support STIX/TAXII 2.1
Many security solutions may already support STIX/TAXII 2.1, but you should verify rather than assume. Ask your vendor whether your Threat Intelligence Platform, SIEM, or other components support STIX/TAXII 2.1 specifically.
If support is unclear, include STIX/TAXII 2.1 as a hard requirement in procurement for new solutions—or require it as part of an upgrade path.
3) Start simple with one reliable source
Begin with a low-risk setup. For instance, start by automating ingestion of data from a trusted source such as a sector ISAC using a TAXII 2.1 client.
Then test whether your systems translate STIX objects into usable alerts in your dashboards, and whether the flow of new data can be handled without creating an overload of false positives. Once that works reliably, expand slowly to additional sources.
4) Move toward actively producing and sharing intelligence
After consumption becomes stable, shift from “only receiving” to “also contributing.” Set up internal processes to share your own findings and threat intelligence back to the ecosystem.
Decide which types of information are appropriate to share—such as specific IP addresses or malware hashes—so you can complete the bidirectional loop. This step is what transforms shared threat intelligence from a one-way feed into a continuous, collaborative capability.
The bigger picture: building a trusted intelligence chain
When multiple parties share threat intelligence continuously, defenders can react earlier and with more confidence. A chain model illustrates this well: organizations such as suppliers, manufacturers, logistics partners, IT service providers, cloud providers, security organizations, and government entities can exchange intelligence through a central STIX/TAXII platform.
The practical outcome is simple: threats can spread through the ecosystem faster, but so can countermeasures—because indicators and observations move in a consistent format that downstream tools can interpret automatically.
Conclusion
STIX/TAXII 2.1 is designed to make threat intelligence exchange more practical: structured and machine-readable, scalable for larger datasets, and easier to integrate through modern RESTful APIs. With the standard now included on the Dutch “comply or explain” list from 1 July 2026, many public-sector organizations will need to request it when procuring or building security solutions.
By inventorying current CTI workflows, verifying system support, starting with a single reliable source, and gradually adding bidirectional sharing, you can adopt STIX/TAXII 2.1 in a controlled way—and help protect not just your own organization, but the broader security ecosystem.
Source: https://www.ncsc.nl/expertblogs/wissel-effectiever-dreigingsinformatie-uit-met-stixtaxi-21
