Compliance & Security for European Healthtech
We build, run and extend your compliance system - combining automation with hands-on expert delivery.
Certification through independent accredited bodies














Sound familiar?
A hospital or enterprise deal is waiting on security evidence
The buyer expects ISO 27001, structured controls and independent assurance before procurement can move forward - not another round of improvised questionnaire answers.
Compliance keeps landing on people who already have a full-time job
It moves between product, engineering and operations with no clear owner or timeline - until a deal, hospital questionnaire or auditor forces the issue.
You are certified, but the system behind the badge has gone stale
The original consultant is gone, evidence has not been maintained and the next questionnaire, customer review or surveillance audit will surface the gaps.
New healthtech requirements keep becoming separate projects
NIS2, NEN 7510, AI governance, product cybersecurity and medical-device requirements are creating repeated work for the same small team.
Why companies choose Asteron
Our specialists work across digital health, SaMD, clinical AI and hospital-facing software. We understand how security, privacy, medical-device regulation and buyer requirements overlap, so the work is scoped around your actual product and market.
Assets, suppliers, risks, controls and evidence are structured into one operating foundation. Later frameworks reuse what already exists, reducing duplicate work and making extensions 40-60% less expensive than starting again.
A named senior compliance expert leads the project end to end - scoping, policies, internal-audit coordination, auditor preparation and audit-day support. You work with a real person in Slack or Teams, backed by engineering and delivery support, with no junior handoff or anonymous ticket queue.
We automate evidence workflows, approvals, reminders, registers, recurring reviews and questionnaire reuse wherever the client environment allows it. Senior specialists remain responsible for control design, regulatory interpretation and audit preparation.
Asteron handles documentation, control mapping, evidence structure, coordination and audit preparation. Your specialists provide operational knowledge, approve key decisions and implement the limited technical or organisational changes that require internal access.
The guarantee applies to the outcome and scope defined in the agreement. It does not cover missing client actions, external delays, certification-body decisions unrelated to our work or changes introduced outside the agreed scope.
One core, built once and kept alive all year
One core, three stages. Created once, kept alive, then reused for every next framework.
Build the first framework on a solid core
We map your product, data flows, suppliers and buyer requirements, then prepare the controls, documentation and evidence with healthtech specialists.
- Scope based on product and market
- Documentation and evidence prepared for you
- Audit-ready in 12 weeks
Keep the system current all year
Recurring evidence, reviews, questionnaires and regulatory changes are managed through automated workflows and expert oversight.
- Evidence and control reviews kept current
- Surveillance and questionnaires supported
- Regulatory changes mapped to your company
Add the next framework faster
We reuse the existing company model, controls and evidence, then complete only the gaps specific to the new requirement.
- Existing controls and evidence reused
- New requirements mapped by specialists
- Extensions cost 40-60% less
Build the first framework on a solid core
We map your product, data flows, suppliers and buyer requirements, then prepare the controls, documentation and evidence with healthtech specialists.
- Scope based on product and market
- Documentation and evidence prepared for you
- Audit-ready in 12 weeks
Keep the system current all year
Recurring evidence, reviews, questionnaires and regulatory changes are managed through automated workflows and expert oversight.
- Evidence and control reviews kept current
- Surveillance and questionnaires supported
- Regulatory changes mapped to your company
Add the next framework faster
We reuse the existing company model, controls and evidence, then complete only the gaps specific to the new requirement.
- Existing controls and evidence reused
- New requirements mapped by specialists
- Extensions cost 40-60% less
How it works
Automated where it helps, expert-led where it matters
We combine automated compliance technology with a dedicated security expert who drives the project, keeps stakeholders aligned, and defends you at the audit. Along the way we build your compliance core - the living model of your company that every next framework is produced from.
Free assessment(before you commit)
Free assessment(before you commit)
We map your situation in 25-30 minutes: product, data flows, customers, deadlines. You get our read on scope, the frameworks that actually apply to you, what's genuinely urgent versus what can wait - and a realistic timeline against your deadline. Yours to keep, whether or not you work with us.
Scoping memo
Scoping memo
We review your product, markets, customer requirements, current certifications and regulatory deadlines before defining the scope and delivery plan. You receive a focused scoping memo within five business days: exact scope and its reasoning, week-by-week timeline, an itemized list of your team's hours, and a fixed price. Valid for 21 days.
Kickoff & connect
Kickoff & connect
Week 0: read-only connectors to your cloud, workspace and HR stack - no agents installed, nothing changes in your systems. We begin certification-body coordination immediately and plan delivery around the available audit window. You appoint one internal owner; we take everything else.
Build compliance core
Build compliance core
Weeks 1-6: the connectors help populate and maintain your asset and supplier inventories; one structured interview completes the picture. Risk assessment drafted by day ten. Policies and controls are generated for your actual setup, validated by a senior expert, and approved by you in 30-60 minute batches - decisions, not paperwork. Production implementation remains with your team unless separately scoped; we support planning, evidence and review.
Where the client environment allows it, we connect the systems that already hold compliance evidence - including identity, cloud, code, ticketing, HR, device-management and security-testing tools.
- Microsoft 365 or Google Workspace
- AWS, Azure or Google Cloud
- GitHub or GitLab
- Jira or Linear
- HR and device-management systems
- Vulnerability and security-testing tools
These connections support evidence collection, access and supplier reviews, policy acceptance, control-owner reminders, recurring tasks, vulnerability records and questionnaire reuse.
Evidence is refreshed automatically where integrations support it. Other controls follow a scheduled monthly, quarterly or annual review cycle based on the control and risk.
Changes in assets, suppliers, incidents and vulnerabilities can trigger risk-review tasks. Risk decisions and acceptance remain with accountable people.
Evidence & training
Evidence & training
Weeks 6-10: evidence collection runs automatically against your core. Your team gets security awareness training that auditors accept and engineers don't hate. Management review is held and properly minuted - a core audit record that is often missing in first-time projects.
Internal audit & readiness
Internal audit & readiness
Weeks 10-12: a certified lead auditor who did not build your ISMS performs the internal audit - real independence, not a formality. Findings get fixed. You are audit-ready: a defined, contractual milestone, and the point where most clients realize the hard part is behind them.
Certification & ongoing
Certification & ongoing
Stage 1 and Stage 2 with our expert in the room - not to answer for you, but because knowing how auditors think is a craft. If a non-conformity results from our deliverables, we correct it at our cost within the contracted scope. After the audit, the Compliance Core moves into ongoing operation - evidence maintenance, surveillance preparation, buyer questionnaires and future framework extensions.
Regulatory timeline
More compliance lands on European healthtech in the next 30 months than in the past decade.
- Cyberbeveiligingswet 🇳🇱15 August 2026
- NEN 7510:2024Feb 2027
- Cyber Resilience ActDec 2027
- EU AI Act2027-2028
- EHDS2029
Not every deadline applies to every healthtech company. We identify which requirements affect your product, markets and current certifications - and when preparation should start.
What the market looks like today
Three ways to run compliance. Different ownership, effort and accountability.
DIY - even with AI
Low external cost, high internal workload
Templates and AI can speed up drafting, but your team still has to define the scope, make control decisions, collect evidence, coordinate the audit and maintain the system afterward.
Compliance platforms
Strong automation, but delivery still sits with the customer
Platforms simplify evidence collection and monitoring, while the company usually remains responsible for implementation, documentation, remediation and auditor coordination.
Asteron
Automation and expert delivery in one operating model
We automate repetitive work and use healthtech specialists for the decisions, documentation and audit preparation that require experience and accountability.
Different tools solve parts of the problem. Asteron takes responsibility for the full operating system.
Think you can do it cheaper in-house? See the real numbers →
Frequently asked questions
We are a done-for-you compliance and security partner for European healthtech. We build your ISMS, write the policies, run the internal audit, coordinate the accredited certification body, and sit next to you on audit day - then keep the certificate alive year-round.
No. Independent certification under ISO/IEC 17021-1 requires the certification body to be independent from the party that built the system. Asteron builds and operates the management system; an accredited certification body issues the certificate. Accreditation bodies (for example RvA in the Netherlands, DAkkS in Germany, SWEDAC in Sweden and UKAS in the United Kingdom) do not certify companies themselves - they accredit the certification bodies. Certification bodies such as BSI, DNV, Bureau Veritas and TÜV are the organisations that perform Stage 1 and Stage 2 audits and issue certificates.
Yes if you're European healthtech, roughly 10-200 people, with a real requirement - a tender, a notified body, a DiGA submission, an enterprise deal. No if you need a certificate in four weeks or the cheapest software-only route: those aren't us.
A single compliance core - one risk model, one control set, one evidence system - built once and projected into whichever frameworks you actually need: ISO 27001, ISO 27701, ISO 42001, IEC 81001-5-1, NEN 7510, NIS2, HIPAA. so every next certificate costs 40-60% less and takes weeks, not quarters.
It depends on what your product is and which buyers or regulators are blocking you: an MDR medical device follows one path, health software outside MDR another, clinical AI a third. That classification is exactly what the free assessment gives you - a map of which deadlines apply to your product, which don't, and what can safely wait - in writing, whether or not you work with us.
Audit-ready in 12 weeks is a defined, contractual milestone - internal audit passed, evidence in place, team trained. The certificate itself typically lands 4-6 months from kickoff, driven by the certification body's own scheduling of Stage 1 and Stage 2.
25-40 hours across the project. We do the work; you make the decisions. Your team's role is limited to what only they can do: approving documents, applying technical changes to their own systems from our step-by-step instructions, and attending short training we run. In-house, the same project consumes 200-400 hours.
Scoping, policies, risk assessment, control implementation guidance, evidence collection, internal audit, auditor coordination and audit-day advocacy - all delivered by a named senior expert. One contract, one accountable team, one price agreed up front.
No - independent certification under ISO/IEC 17021-1 requires the certification body to be independent from the party that built your system. You contract and pay the certification body directly - typically €4,500-6,000 for 10-50 people, €6,000-9,000 for 51-150. We negotiate partner rates, book the slot and prepare every session.
The guarantee covers the specific outcome defined in your signed scope - for example, ISO 27001 certification against a defined scope statement. If non-conformities arise from our deliverables, we remediate them at zero additional cost and support you through re-assessment until that contracted outcome is achieved. It is not an unlimited guarantee: it applies to the outcome named in the contract, not to work outside that scope.
A certificate needs feeding - surveillance every year, recertification every three. Our ongoing plans (Compliance Operations) keep evidence current, handle surveillance audits, and handle customer security questionnaires with a defined turnaround. Or take it fully in-house with a structured handover - no lock-in.
Yes - it's a distinct service we call Core onboarding. We inherit your existing policies, controls and evidence, map them into the Asteron Compliance Core, close gaps, and take over year-round operation: surveillance audits, questionnaires, evidence collection. Especially useful when the consultant has left or the ISMS owner has changed jobs.
Regulatory Radar is our ongoing tracking of European healthtech regulation - AI Act, CRA, EHDS, NIS2, NEN 7510:2024, MDR updates. When something changes that affects your product, you get a written note explaining what it means for your certificates and what, if anything, needs to change. Included in ongoing plans.
Yes - that's the point of the Compliance Core. Because adding the next certificate is weeks, not quarters, at 40-60% less than the standalone price. Common next steps: ISO 27701 for privacy, ISO 42001 for AI, IEC 81001-5-1 for medical device software.
Yes - it's core to our Dutch practice. Every NEN 7510 certificate issued against the 2017+A1 version expires on 20 February 2027. The transition to NEN 7510:2024 is a real project - a new control structure aligned with ISO 27001:2022, new requirements on cloud and supply-chain security - and certification bodies' transition slots are finite. We run the transition at a fixed price from your existing ISMS.
Yes. IEC 81001-5-1 is now the expected state of the art for medical device software security - files that passed review two years ago are coming back with cybersecurity findings. We build the security file end-to-end, integrated with your ISO 13485 QMS and aligned with your notified body's expectations.
We run a dedicated medical device track covering IEC 81001-5-1 security files, MDR/IVDR security expectations, and integration with your ISO 13485 QMS. One contract, one accountable team - designed to align with your notified body, not fight it.
Our practice is European healthtech - Warsaw and Amsterdam offices, remote work with companies across the EU and UK. Certification audits are performed by accredited certification bodies with local auditors; we coordinate the process regardless of where you're incorporated. For US frameworks we support SOC 2 and HIPAA on the same core.
Know what your company needs before the next requirement becomes urgent
Tell us what you build, where you operate and which customers you sell to. We will identify the relevant frameworks, deadlines and most practical starting point.
