AsteronAsteron

    ISO 27001 certification for European healthtech

    Asteron builds your ISO/IEC 27001 management system, prepares the evidence and coordinates the independent certification audit. Certification is issued independently by an accredited certification body.

    See ISO 27001 pricing
    • Audit-ready in 12 weeks
    • Fixed scope and price
    • Typically 25-40 hours of client time
    • Contracted outcome guarantee

    What is ISO 27001?

    ISO/IEC 27001:2022 is the international standard for an information security management system, or ISMS. It requires a company to define its security scope, identify information risks, choose and operate appropriate controls, retain evidence and improve the system over time.

    For a healthtech company, the practical value is not another folder of policies. It is a repeatable way to show hospitals, enterprise buyers, partners and auditors how sensitive information, software, suppliers and incidents are managed.

    ISO/IEC 27001 is not generally a legal requirement. In healthtech, it often becomes a procurement, contractual or partner requirement when a company handles sensitive information or sells to hospitals and enterprise customers.

    Certification is issued by an independent accredited certification body, not by Asteron.

    When ISO 27001 becomes a real business requirement

    Most healthtech teams do not begin with a desire to collect certificates. They begin when security evidence becomes necessary to move the business forward.

    A hospital or enterprise deal is blocked

    The buyer expects ISO 27001, structured controls and independent assurance before procurement can move forward.

    Security questionnaires keep repeating

    Your team is rebuilding the same answers about access, suppliers, incidents and data handling for every customer.

    Security work has no clear owner

    Controls exist across product, engineering and operations, but nobody maintains one coherent system or evidence cycle.

    The next framework is already visible

    You expect NEN 7510, IEC 81001-5-1, ISO 27701, ISO 42001 or another overlapping requirement after the first certification.

    What ISO 27001 usually needs to cover in healthtech

    The scope follows the systems, people and third parties that can affect sensitive information or the reliability of the service.

    Product and platform

    Production environments, application services, administration tools and the systems used to deliver the healthtech product.

    Health and customer data

    Personal data, health-related information, research data, customer records and the rules governing how each category is handled.

    Cloud, code and deployment

    Cloud accounts, source repositories, deployment pipelines, secrets, logging, backups and technical change.

    People and access

    Employee and contractor access, onboarding, offboarding, privileged accounts, devices, training and policy acceptance.

    Suppliers and external services

    Hosting, development partners, support tools, AI APIs, subprocessors and other providers that can affect security or availability.

    Incidents and continuity

    Detection, escalation, customer communication, recovery, lessons learned and evidence that the process operates.

    Governance and evidence

    Security ownership, risks, objectives, recurring reviews, internal audit, management review and the records an auditor will inspect.

    The exact certification scope is agreed before delivery begins. Hospital systems or partner infrastructure that Asteron does not control are not automatically included.

    What ISO 27001 does not replace

    • A penetration test or technical security assessment
    • GDPR legal analysis or a formal data-protection opinion
    • ISO 13485, MDR or medical-device regulatory approval
    • Clinical validation or proof that a product can never suffer an incident

    It creates the management system around information security. Separate technical, privacy or medical-device work remains separate where the scope requires it.

    What Asteron builds for you

    Asteron prepares the management system, drives the work and stays with the project through the independent certification audit.

    DeliverableWhat it gives the company
    ISMS scope and contextDefines the products, systems, locations, people and third parties covered by certification.
    Asset and supplier inventoriesCreates a maintained view of the systems, information and providers that the security model depends on.
    Risk assessment and treatment planLinks real business and technical risks to owners, decisions and controls.
    Statement of ApplicabilityRecords which Annex A controls apply, how they are implemented and why any exclusions are justified.
    Policies and operating proceduresDocuments how access, suppliers, incidents, development, continuity and other security processes actually operate.
    Evidence map and recurring calendarDefines what evidence is retained, who owns it and when each review must happen.
    Staff preparation and policy acceptanceIntroduces the new processes and creates records that the organisation has adopted them.
    Internal auditTests the management system before the independent certification audit.
    Management reviewGives leadership a structured decision point on risks, performance, priorities and readiness.
    Certification preparation and supportCoordinates the audit process, prepares the team and supports Stage 1, Stage 2 and agreed remediation.

    We do the compliance work. Your team provides the company knowledge.

    Asteron

    • Defines the project plan and drives delivery
    • Drafts the management system and operating documents
    • Maps risks, controls, evidence and responsibilities
    • Configures recurring evidence workflows
    • Runs the internal audit
    • Prepares management review
    • Coordinates the certification-body process
    • Supports agreed remediation

    Your team

    • Explains how the company and product operate
    • Makes scope and risk decisions
    • Provides access to relevant records and systems
    • Assigns accountable owners
    • Approves policies and risk acceptance
    • Implements technical changes that require internal access
    • Attends focused working sessions and audit interviews

    Typical client involvement: 25-40 hours across the full project.

    From scope to audit-ready in 12 weeks

    Structured delivery, automated where it helps and led by a named senior expert.

    1. 1WEEKS 1-2

      Scope and operating model

      Review the product, markets, customers, systems, data flows, suppliers and current controls. Agree the scope and delivery plan.

    2. 2WEEKS 2-5

      Management system build

      Create the risk model, control structure, policies, ownership model, supplier register and evidence requirements.

    3. 3WEEKS 4-8

      Evidence and automation

      Configure recurring evidence workflows and connect supported systems where the client environment allows.

    4. 4WEEKS 8-10

      Test and correct

      Complete the internal audit, review gaps, implement corrective actions and verify that required evidence is available.

    5. 5WEEKS 10-12

      Management review and audit preparation

      Complete management review, finalise the audit pack and prepare the team for the independent certification audit.

    Audit-ready in 12 weeks is the Asteron delivery milestone. The certificate usually arrives 4-6 months from kickoff because Stage 1 and Stage 2 follow the certification body's independent schedule.

    Expert-led delivery, with automation under the hood

    A NAMED SENIOR EXPERT

    One accountable person leads the work

    A named senior compliance expert leads scoping, documentation, internal-audit coordination, certification preparation and audit support. You know who owns the work and who to contact from day one.

    • 1:1 communication in Slack or Teams
    • Project ownership and follow-ups
    • Backed by engagement and engineering support
    • No anonymous ticket queue
    AUTOMATION UNDER THE HOOD

    Repetitive work is handled systematically

    Automation is used for recurring evidence, approvals, reminders, registers and review tasks where the client environment supports it. Scope decisions, risk acceptance and audit judgement remain with accountable people.

    • Evidence workflows
    • Policy acceptance and approvals
    • Access and supplier review cycles
    • Risk-review triggers
    • Questionnaire reuse

    ISO 27001 pricing

    Fixed scope and transparent pricing for healthtech teams with up to 150 employees.

    UP TO 50 EMPLOYEES
    €16,900

    For one primary company scope and a typical early-stage or growth healthtech operating model.

    51-150 EMPLOYEES
    €26,900

    For a broader team, more control owners, systems, suppliers or organisational complexity.

    151+ employees, multiple entities or unusually complex scope - priced individually.

    • Fixed scope and price
    • Audit-ready in 12 weeks
    • Typically 25-40 hours of client time
    • Contracted outcome guarantee

    Independent certification and external audit fees

    ISO/IEC 27001 certification must be performed by an independent accredited certification body. Asteron builds the management system, prepares the evidence and supports the audit, but cannot act as the certification body or issue a certificate for its own implementation work. Keeping these roles separate protects impartiality and avoids a conflict of interest.

    Your organisation selects and contracts with the certification body directly. Its fees are paid directly to that body and are not included in Asteron's implementation price.

    Indicative certification-body fees
    • Up to 50 employees:typically €4,500-6,000
    • 51-150 employees:typically €6,000-9,000

    The final certification-body quote depends on the agreed scope, employee count, locations, required audit time, travel and the selected certification body.

    Asteron can help compare suitable accredited certification bodies, align the proposed certification scope, coordinate the audit window, prepare the team and evidence, support Stage 1 and Stage 2 questions and coordinate agreed remediation. The audit findings and certification decision remain independent.

    Payment terms: 40% at signing, 40% at audit-ready, 20% after certification.

    View all pricing

    Contracted outcome guarantee

    If a non-conformity results from our deliverables, we correct it at our cost within the contracted scope.

    The guarantee does not cover missing client actions, external delays, certification-body decisions unrelated to our work or changes introduced outside the agreed scope.

    Certification runs on a three-year cycle. The work behind it does not stop.

    The certificate remains valid while the management system is maintained and the required surveillance audits are completed. Recertification takes place at the end of the three-year cycle.

    Evidence, access reviews, supplier reviews, risk updates, management review and surveillance preparation continue after certification. Compliance Operations keeps the system current without requiring the company to build a separate internal compliance function.

    • Evidence and recurring controls maintained
    • Surveillance and questionnaires supported
    • Regulatory changes mapped to the company

    ISO 27001 questions

    ISO 27001 is not a universal legal requirement for every healthtech company. It is often required commercially by hospitals, enterprise customers, partners or procurement processes, and it can support readiness for overlapping regulatory and market requirements.
    ISO 27001 is the international information-security management standard. NEN 7510 applies additional Dutch healthcare requirements. A company operating in the Dutch health sector may need NEN 7510 even when it already has ISO 27001.
    ISO 27001 governs information security across the organisation. IEC 81001-5-1 focuses on cybersecurity activities across the lifecycle of health software. The two overlap, but they do not replace one another.
    No. ISO 27001 is a certifiable management-system standard. SOC 2 is an independent attestation against Trust Services Criteria, with a separate CPA assessment process and, for Type II, an observation period.
    Asteron prepares the company to be audit-ready in 12 weeks. Stage 1, Stage 2 and the certification decision follow the independent certification body's schedule, so the certificate usually arrives 4-6 months from kickoff.
    A typical Asteron project requires approximately 25-40 hours of client time. Your team provides operational knowledge, decisions, approvals and technical changes that require internal access. Asteron handles the management-system build and project coordination.
    No. Certification-body fees are separate from Asteron's implementation price. Your organisation selects, contracts with and pays an independent accredited certification body directly. Typical fees are €4,500-6,000 for organisations with up to 50 employees and €6,000-9,000 for organisations with 51-150 employees, although the final quote depends on scope, locations, audit time and the selected body. Asteron coordinates preparation and audit support, but the certification decision remains independent.
    Because the organisation that implements or advises on the management system should not also make the independent certification decision. A separate accredited certification body protects impartiality and avoids a conflict of interest. Asteron prepares the system and supports the process; the certification body conducts the audit and decides whether to issue the certificate.
    Yes, where they accurately reflect current operations and can produce evidence. Existing material is reviewed and reused rather than rewritten automatically.
    Not every ISO 27001 project requires the same technical test, but vulnerability management and technical assurance must be appropriate to the company's risks. Penetration testing can be scoped separately where needed.
    A finding is assessed against its cause. If it results from Asteron deliverables, Asteron corrects the work at its cost within the contracted scope. Client actions and external decisions remain the client's responsibility.
    Yes. ISO 27001 creates reusable assets, risks, controls, supplier governance and evidence. Overlapping extensions such as IEC 81001-5-1, ISO 27701 and NEN 7510 can therefore be delivered with less duplicate work.
    The management system must continue operating through recurring reviews, evidence collection, management review and surveillance audits. Asteron can run these activities through Compliance Operations.

    Official reference

    ISO/IEC 27001:2022, including Amendment 1:2024

    Find out whether ISO 27001 is the right starting point

    Tell us what you build, which customers you sell to, what security evidence they expect and whether you already have any controls or documentation. We will confirm the practical scope, price and route to audit.

    See all framework pricing