Skip to content
Beveiligingsnieuws

STIX and TAXII 2.1 required from July 1, 2026

STIX en TAXII 2.1

From 1 July 2026, STIX and TAXII 2.1 are added to the Dutch “comply or explain” list. That step brings an important change for public organizations that handle cyber threat information: the updated standards must be applied by government bodies, while other public-sector entities are strongly encouraged to follow the same approach.

Below, you’ll find what this means in practice, why STIX and TAXII matter, and which parts of the scope have been updated alongside the new version.

Who must apply STIX and TAXII 2.1

The update applies directly to Dutch public organizations including municipalities, provinces, central government bodies, water boards, and all implementing organizations that carry out government tasks. For these groups, applying STIX and TAXII 2.1 becomes a requirement as of the start of July 2026.

For other organizations in the public sector, the guidance is different: adoption is presented as a strong recommendation, not a strict obligation.

In other words, if your organization is part of the government landscape or supports governmental processes, you should plan for version alignment well ahead of the deadline.

Why STIX and TAXII are central to threat sharing

STIX and TAXII are widely used as a foundation for sharing threat intelligence. They make it possible to describe cyber threats and attacks in a structured and machine-readable way.

That structured format matters because it supports real-time and automated exchange. When threat information is expressed consistently, receiving parties can more quickly translate it into defensive actions, such as adjusting detection rules, updating monitoring, or improving incident response workflows.

The NCSC, the Dutch National Cyber Security Centre, previously requested the inclusion of STIX and TAXII 2.1 in the “comply or explain” list via the Forum Standaardisatie. That move reflects the role these standards play as an interoperable bridge between parties that need to exchange cyber threat data.

Version 2.1 replaces earlier STIX and TAXII releases

A key point in the update is that STIX and TAXII 2.1 are not merely an additional option. The inclusion replaces the earlier STIX and TAXII version that was already listed.

The earlier 1.* versions are now considered outdated. According to the announcement, they are only limited in use and are less supported by vendors. Many organizations—including the NCSC—already use version 2.1, which signals both practical readiness and a move toward broader standard alignment.

What improved in version 2.1

Compared with prior versions, STIX and TAXII were improved in several areas. The announcement highlights one especially relevant enhancement: the way technical facilitation of threat information sharing works.

In practical terms, these improvements aim to make information sharing more robust and better suited to operational needs, including the realities of how organizations integrate threat intelligence into their tooling and processes.

Functional scope updated: “exchange” becomes “provide and/or receive”

Alongside the version update, the functional application scope was revised. While the original scope provided a solid base, it required clarification and modernization.

One notable adjustment is the change in wording from “exchange” to “provide and/or receive.” The rationale is straightforward: “exchange” can be interpreted as mutual communication, which is not strictly required in every scenario—especially when an organization only consumes threat intelligence coming from a supplier.

By switching to “provide and/or receive,” the scope better reflects different operational models, such as:

  • Organizations that mainly receive intelligence without sending the same data back.
  • Organizations that both provide and receive depending on agreements and operational needs.

Additional changes were made to ensure the functional scope aligns with current legislation and current language use.

What organizations should do now

If your organization is required—or even strongly advised—to adopt STIX and TAXII 2.1, the most practical next step is to assess where your current threat intelligence workflows rely on older versions.

Consider the following action points:

  • Inventory your threat intelligence pipeline: Identify where STIX and TAXII formats are produced, transformed, or consumed.
  • Check vendor and integration support: Determine whether your threat feeds, platforms, and middleware support version 2.1.
  • Align operational expectations: Confirm whether your organization is primarily receiving data, providing data, or doing both.
  • Plan for testing: Validate that your detectors, enrichment steps, and reporting components can process the updated structure.

Because the requirement date is fixed at 1 July 2026, starting early reduces the risk of last-minute upgrades or integration delays.

Conclusion

Starting 1 July 2026, STIX and TAXII 2.1 become mandatory for Dutch municipalities, provinces, central government, water boards, and implementing organizations under the “comply or explain” framework. Other public-sector organizations receive a strong recommendation to adopt the updated versions.

The change replaces older 1.* releases that are now less supported, while also updating the functional scope so it more accurately covers both providing and/or receiving threat intelligence. If you operate in this environment, now is the right time to review your integrations and plan for a smooth transition.

Source: https://www.ncsc.nl/nieuws/versie-21-van-stix-en-taxii-per-1-juli-2026-verplicht-voor-de-overheid