AsteronAsteron

    Core onboarding for European healthtech compliance

    Asteron brings an existing compliance system into a clear, manageable operating model. We review the current scope, evidence, responsibilities, audit commitments and open actions, then establish the baseline and annual calendar needed for ongoing Compliance Operations. Core onboarding is designed for healthtech companies that already have an ISO 27001, NEN 7510 or related management system and need a reliable handover — not another implementation project from the beginning.

    View Compliance Operations pricing
    • Existing system taken over
    • Evidence and ownership mapped
    • Annual compliance calendar established
    • Included with 12-month Compliance Operations or an eligible framework extension

    Core onboarding is included with annual Compliance Operations or an eligible framework extension.

    What Core Onboarding means

    Core onboarding is the controlled transfer of an existing compliance system into Asteron’s operating model. It gives both teams a shared view of what already exists, what remains current, what needs attention and who owns each recurring activity.

    The purpose is not to rewrite every policy or repeat work that has already been completed. The purpose is to verify the baseline, organise the available evidence and create a practical cadence for reviews, audits, questionnaires and regulatory-change actions.

    At the end of onboarding, the system should be understandable and operable: scope is confirmed, evidence has an owner, recurring activities have dates, and material gaps are visible rather than buried in documents or spreadsheets.

    Core onboarding transfers a usable existing system into ongoing operations. If the baseline is materially outdated, incomplete or no longer reflects the business, a separate re-baseline may be required.

    When Core Onboarding is the right starting point

    After certification or initial implementation

    The company has completed ISO 27001, NEN 7510 or another framework project but does not want the system to become a once-a-year audit exercise. Onboarding turns project outputs into a recurring operating calendar.

    When changing compliance providers

    Policies and evidence exist, but ownership, tooling and working methods need to be transferred without losing audit history or interrupting recurring obligations.

    When internal ownership has changed

    A compliance lead, security manager or consultant has left, and the remaining team needs a named specialist to reconstruct responsibilities and keep the system moving.

    When evidence has become fragmented

    The formal management system still exists, but evidence, reviews, customer questionnaires and action tracking are spread across people, folders and tools. Onboarding creates one controlled baseline before managed operations begin.

    Core onboarding is not intended for a company starting its first management system from zero. New framework implementation follows the relevant ISO 27001, NEN 7510 or other framework service.

    What happens during onboarding

    1. Understand the current system

      Asteron reviews the applicable frameworks, certified or intended scope, company structure, products, markets, audit history and current compliance responsibilities.

      We identify which documents, registers, tools and evidence sources are considered authoritative and where knowledge currently sits inside the organisation.

    2. Review the operational baseline

      We examine the current policy set, risk and control records, evidence status, previous audit findings, management reviews, internal audits, supplier activities and material open actions.

      This is an operational review rather than a new certification audit. Its purpose is to determine whether the existing system can move directly into Compliance Operations or requires targeted recovery work.

    3. Establish ownership and cadence

      Recurring activities are mapped to named Asteron and client owners. We establish the annual calendar for reviews, evidence refreshes, internal audits, management reporting, surveillance preparation and other agreed obligations.

      Communication routes, escalation points and working tools are also confirmed.

    4. Handover into ongoing operations

      Asteron documents the accepted baseline, prioritised actions, agreed responsibilities and first operating period. Open issues are carried into Compliance Operations with clear owners and dates instead of being left as an informal onboarding backlog.

    What Core Onboarding delivers

    The output is a working compliance baseline, not a generic onboarding presentation. The exact records depend on the frameworks and operating scope, but a standard onboarding normally establishes the following:

    • Confirmed organisational, product and certification scope
    • Inventory of policies, registers and evidence sources
    • Status of previous audit findings and open actions
    • Named internal and Asteron responsibilities
    • Annual compliance and audit calendar
    • Evidence-refresh and recurring-review schedule
    • Agreed communication and escalation routes
    • Prioritised onboarding action list
    • Handover record for Compliance Operations
    • Clear identification of work that remains outside the managed service

    The result gives management a clear view of the current position and gives the operating team enough structure to maintain the system throughout the year.

    One core system across European healthtech markets

    Netherlands

    For companies working with Dutch healthcare providers, onboarding can incorporate an existing NEN 7510:2024 or ISO 27001 baseline, surveillance commitments, healthcare-customer evidence and relevant actions connected to the Dutch market.

    NEN 7510 is specifically designed for organisations handling personal health information in the Netherlands. Core onboarding does not replace NEN 7510 implementation or certification; it makes the existing system and recurring obligations operational.

    Germany and wider Europe

    For German and wider European healthtech companies, onboarding can organise the existing ISO 27001, GDPR, medical-software, DiGA-related or customer-assurance evidence that falls within the agreed system.

    Country-specific requirements remain explicit extensions to the core. Do not assume that one generic compliance system automatically satisfies every Dutch, German or EU regulatory requirement.

    Asteron’s focus is European healthtech. The operating model is therefore built around sensitive health data, regulated products, hospital customers and the need to maintain evidence across multiple European markets.

    Core onboarding is included with Compliance Operations

    Core onboarding is included when a company enters an annual Compliance Operations engagement or purchases an eligible framework extension. It is not charged as an additional standard setup package when the existing system is suitable for direct onboarding.

    If Core Onboarding is requested without a 12-month Compliance Operations engagement or an eligible framework extension, the standalone engagement is scoped individually.

    Up to 50 employees
    €2,400/month
    51–150 employees
    €3,900/month
    Complex environments
    From €6,500/month

    All Compliance Operations tiers provide the same essential managed service. The fee changes with organisational complexity, framework coverage, evidence volume, customer-assurance workload and the required operating cadence.

    Minimum term: 12 months. Prices exclude VAT where applicable.

    When re-baselining is needed

    If the scope, risk assessment, control set, ownership or evidence no longer reflects the current organisation, Asteron may recommend a separate Re-baseline from €3,900 before or alongside onboarding.

    A re-baseline is agreed explicitly. It is not presented as automatically included or added without prior scoping.

    What remains separate

    Core onboarding establishes the operational baseline but does not silently expand into a new certification, full framework implementation or technical-security project.

    Unless explicitly included in the proposal, the following remain separate:

    • New ISO 27001, NEN 7510 or other framework implementation
    • Material re-baselining or reconstruction of an outdated system
    • Penetration testing and vulnerability management
    • vCISO leadership and executive security ownership
    • Legal advice or formal regulatory interpretation
    • Remediation implementation by the client’s engineering or operational teams
    • External certification and surveillance audits

    Certification and surveillance audits are performed by an independent accredited certification body. Asteron can prepare the system, evidence and team and coordinate the audit process, but cannot issue the certificate or act as both implementer and certifier because those roles must remain independent. External auditor fees are contracted and paid directly to the certification body.

    Shared responsibilities

    Asteron

    Asteron reviews the available system, identifies the operational baseline, defines the recurring calendar, documents responsibilities and carries agreed open actions into Compliance Operations.

    Your team

    The client provides access to existing policies, registers, evidence, audit reports, relevant tools and responsible stakeholders. Management remains accountable for organisational decisions, risk acceptance, resources and implementation of actions assigned to the company.

    Frequently asked questions

    What is Core Onboarding?

    Core onboarding is the structured transfer of an existing compliance management system into Asteron’s managed operating model. It confirms scope, evidence, responsibilities, open actions and the annual compliance calendar.

    Is Core Onboarding a new ISO 27001 or NEN 7510 implementation?

    No. It is intended for an existing system. A company starting from zero should use the appropriate framework implementation service.

    Is Core Onboarding included in the price?

    It is included with annual Compliance Operations or an eligible framework extension when the existing system is suitable for onboarding.

    What if our compliance system is outdated?

    Asteron will identify whether targeted corrections are sufficient or whether a separate re-baseline is required. Re-baseline work starts from €3,900 and is agreed explicitly.

    Can you take over from another consultant or provider?

    Yes. The onboarding process is designed to transfer the current scope, records, evidence, audit history and responsibilities into a controlled operating model.

    Can Core Onboarding cover both ISO 27001 and NEN 7510?

    Yes, when both frameworks are already within the agreed system and engagement scope. The onboarding must preserve the framework-specific obligations rather than treating them as interchangeable.

    Is Core Onboarding suitable for Dutch and German healthtech companies?

    Yes. Asteron focuses on European healthtech and can organise an existing core system together with the Dutch, German and EU requirements included in the agreed scope.

    Does Asteron perform the external certification audit?

    No. Certification and surveillance audits must be performed independently by an accredited certification body. External audit fees are paid directly to that body.

    How long does onboarding take?

    Timing depends on the condition of the existing system, number of frameworks, evidence volume and stakeholder availability. The schedule is confirmed after the initial review rather than promised as a generic duration.

    What happens after onboarding?

    The accepted baseline, recurring calendar and open actions move into Compliance Operations. A named specialist then coordinates the agreed evidence, reviews, audit preparation and regulatory-change activities throughout the engagement.

    Bring the existing system into a reliable operating rhythm

    Share the frameworks, audit position and records already in place. Asteron will determine whether the system is ready for Core Onboarding or needs targeted re-baselining first.

    View Compliance Operations pricing