AsteronAsteron

    Compliance Operations for European healthtech

    Asteron runs the evidence, reviews, security questionnaires, surveillance preparation and regulatory-change work required to keep your compliance system current. A named senior specialist owns the annual calendar and coordinates your team, so you do not need to build a separate compliance operations function.

    See Compliance Operations pricing
    • Named senior compliance specialist
    • One annual operating calendar
    • Core onboarding included for a usable existing system
    • 12-month managed service

    Compliance does not stay current by itself

    After implementation, evidence expires, owners change, new systems and suppliers enter scope, and customer or audit requests return. Without an operating owner, the documented system gradually stops matching how the company works.

    People and ownership
    Control responsibilities, approvals and recurring reviews lose their owners.
    Products, systems and suppliers
    Scope, inventories, risks and retained evidence no longer match the operating environment.
    Customers and auditors
    Questionnaires, evidence packs and audit preparation are repeatedly rebuilt under deadline pressure.
    Frameworks and regulations
    New obligations are identified but not converted into owned and tracked actions.

    Compliance Operations provides one named operating owner for the agreed compliance scope: maintaining the calendar, coordinating evidence and decisions, preparing external reviews and tracking applicable change.

    Start from the system you have today

    Compliance Operations can begin after an Asteron implementation or take over an existing management system built internally or by another provider.

    READY TO OPERATE

    After an Asteron implementation

    The agreed scope, owners, evidence model and operating calendar transfer directly into Compliance Operations.

    No separate onboarding or recovery project.
    CORE ONBOARDING INCLUDED

    Existing and usable system

    We map the current scope, owners, evidence sources, review cycles and tools into the Asteron Compliance Core.

    Core onboarding is included with annual Compliance Operations or an eligible framework extension.
    Explore Core onboarding
    RE-BASELINE FIRST

    Outdated or abandoned system

    If scope, risks, evidence or ownership no longer reflect the company, Re-baseline restores the system before ongoing operations begin.

    Assessed and priced separately.
    Explore Re-baseline

    No usable management system yet? Start with the relevant framework implementation.

    How Compliance Operations runs through the year

    Asteron turns the agreed scope and framework requirements into an annual calendar of evidence, reviews, decisions and external deadlines. Every activity has an owner, due date and retained record.

    1

    Collect and maintain

    • Recurring control evidence
    • Asset and supplier records
    • Access-review records
    • Policy and training evidence
    • Risk and action updates
    2

    Review and decide

    • Control-owner reviews
    • Risk decisions
    • Supplier and access reviews
    • Scope-change assessment
    • Management reporting
    3

    Prepare and respond

    • Security questionnaires
    • Customer evidence requests
    • Internal audit
    • Management review
    • Surveillance and recertification preparation
    4

    Adapt and improve

    • Corrective actions
    • Regulatory-change actions
    • New systems and suppliers
    • Product and market changes
    • Framework extensions

    Review frequencies are agreed during onboarding based on framework requirements, risk and operating context. The calendar is updated when the scope changes.

    Asteron runs the system. Your team owns the business decisions.

    Your team provides context and approves material decisions. Asteron owns recurring coordination, preparation and follow-up.

    Asteron

    • Assigns a named senior compliance specialist
    • Owns the annual operating calendar
    • Coordinates evidence and recurring reviews
    • Follows up with control owners
    • Prepares governance, questionnaire and audit materials
    • Tracks regulatory-change actions
    • Maintains the action trail and escalates unresolved issues

    Your team

    • Reports material business, product and system changes
    • Maintains accountable internal owners
    • Provides access to relevant records and systems
    • Approves scope, policy and risk decisions
    • Implements changes requiring internal access
    • Attends focused management and audit discussions
    • Resolves escalated decisions and overdue actions

    Human ownership, supported workflows

    A named senior specialist owns the operating calendar, coordination and escalations. Supported workflows handle reminders, evidence reuse, recurring reviews and questionnaire preparation. Scope decisions, risk acceptance and audit judgement remain with accountable people.

    Compliance Operations pricing

    All bands include the same essential managed service. Price varies with company size, supported frameworks, workload and operating complexity.

    UP TO 50 EMPLOYEES
    €2,400/month

    For a focused healthtech operating environment with a typical number of systems, suppliers, control owners and recurring reviews.

    51-150 EMPLOYEES
    €3,900/month

    For broader teams with more owners, products, systems, suppliers and evidence activity.

    COMPLEX ENVIRONMENT
    from €6,500/month

    For larger or unusually complex environments, including multiple entities, products, markets or supported frameworks.

    Prices exclude VAT where applicable. Minimum term: 12 months. Core onboarding is included for a usable existing system; re-baseline work is scoped separately when needed.

    What Compliance Operations includes

    The agreed monthly scope covers ongoing ownership, recurring compliance work, external-review preparation, automation and regulatory-change tracking.

    All three pricing bands include the same essential service. Price changes with workload and complexity, not by removing core operations from lower bands.

    Ongoing ownership

    • Named senior compliance specialist
    • Annual operating calendar
    • Control-owner coordination
    • Management-review preparation

    Recurring compliance work

    • Evidence collection and review
    • Access reviews
    • Supplier reviews
    • Asset and risk updates
    • Policy review and training cycle

    Audits and external requests

    • Surveillance and recertification preparation
    • Security questionnaire support
    • Audit evidence pack
    • Auditor questions and agreed remediation
    • Certificate and scope-change coordination where applicable

    Automation and regulatory change

    • Recurring evidence workflows
    • Review and approval reminders
    • Regulatory-change tracking
    • Applicability decisions
    • Tracked implementation actions
    View all pricing

    What remains separate

    The monthly service covers the agreed compliance-operations scope. New implementations, recovery work, specialist security services and external certification fees are scoped separately.

    Separate Asteron projects

    • New framework implementation
    • Framework extensions not included in the annual scope
    • Re-baseline of an outdated or abandoned system
    • Penetration testing
    • vCISO
    • Vulnerability Management
    • Incident Response
    • Major technical remediation projects

    External or client-controlled costs

    • Certification-body audit fees, where applicable
    • Legal advice or formal data-protection opinions
    • Specialist product or clinical assessments
    • Technical changes requiring internal system access
    • Third-party tools or licences not included in the agreed scope

    Independent certification remains separate

    Where an agreed framework uses accredited certification, surveillance and recertification audits are conducted by an independent accredited certification body selected and contracted directly by the client. Asteron prepares the evidence, coordinates the audit process and supports questions and agreed remediation, but does not act as the certification body or make the certification decision.

    Keeping implementation and certification roles separate protects impartiality and avoids a conflict of interest. Certification-body fees are paid directly to the selected body and are not included in the Compliance Operations monthly fee.

    External fees depend on the framework, certification scope, company size, locations, required audit time and selected certification body.

    Run overlapping frameworks through one Core

    Compliance Operations can support multiple agreed frameworks through the same operating model. Shared risks, controls, suppliers, evidence and review processes are maintained once and reused where the requirements overlap.

    The supported framework scope is agreed before the service begins. Some frameworks use accredited certification; others are regulatory-readiness or governance scopes without a certificate. New frameworks may require an implementation or extension project before they enter ongoing operations.

    Questions about Compliance Operations

    Compliance Operations is Asteron's managed service for keeping an existing compliance system current. A named senior specialist owns the annual operating calendar and coordinates evidence, recurring reviews, security questionnaires, surveillance preparation where applicable and regulatory-change actions.
    European healthtech companies that already have a compliance implementation or regulatory-readiness scope and need the resulting management system to remain current across customer reviews, surveillance audits where applicable and regulatory change.
    Yes. If the existing system is representative and usable, Core onboarding maps scope, owners, evidence and reviews into the Asteron Compliance Core and is included with annual Compliance Operations. If the system no longer reflects the company, Re-baseline is scoped separately before ongoing operations begin.
    Core onboarding is the included mapping of an existing, usable management system into the Compliance Core. Re-baseline is a separately scoped recovery project used when scope, risks, evidence or ownership no longer represent the operating reality and the system must be restored before ongoing operations start.
    Multiple agreed frameworks can share one Compliance Core, including ISO 27001, IEC 81001-5-1, ISO 27701, ISO 42001, NEN 7510 and NIS2 readiness. Some frameworks use accredited certification; others are regulatory-readiness or governance scopes without a certificate. The supported scope is agreed before the service begins.
    Your team reports material changes, keeps accountable internal owners, provides access to relevant records, approves scope and risk decisions, implements internal technical changes and attends focused management and audit discussions. Asteron owns the recurring coordination, preparation and follow-up.
    Asteron's surveillance and recertification preparation, coordination and audit-day support are included where accredited certification applies. The independent audit itself and certification-body fees are separate and paid directly to the selected accredited body.
    Yes. Asteron coordinates responses, reuses approved answers and supporting evidence, and identifies requests that require a new internal decision from your team.
    No. Penetration testing, vCISO, vulnerability management, incident response and major technical remediation are separate Asteron Security Operations services or client-controlled work. Compliance Operations coordinates related actions but does not deliver technical security work itself.
    Additional frameworks can change scope, evidence volume and audit activity, so they can affect the monthly price. New frameworks may also require an implementation or extension project before they enter ongoing operations. The impact is confirmed as part of the scoping proposal.
    The minimum term is 12 months. This reflects the annual operating calendar that underpins the service, including surveillance-audit preparation where applicable and full-year evidence, review and questionnaire cycles.
    Routine scope adjustments and applicable regulatory changes are converted into tracked actions inside the operating calendar with documented applicability decisions. Material new products, entities, locations or frameworks that expand the agreed scope may require a separately scoped extension project before entering ongoing operations.

    See what Compliance Operations would cover for your team

    Tell us which frameworks you already have, how they are maintained and which customer or audit deadlines are ahead. We will confirm the right starting point, operating scope and monthly price.

    See all pricing