ISO 27001 certification for European healthtech
Asteron builds your ISO/IEC 27001 management system, prepares the evidence and coordinates the independent certification audit. Certification is issued independently by an accredited certification body.
- Audit-ready in 12 weeks
- Fixed scope and price
- Typically 25-40 hours of client time
- Contracted outcome guarantee
What is ISO 27001?
ISO/IEC 27001:2022 is the international standard for an information security management system, or ISMS. It requires a company to define its security scope, identify information risks, choose and operate appropriate controls, retain evidence and improve the system over time.
For a healthtech company, the practical value is not another folder of policies. It is a repeatable way to show hospitals, enterprise buyers, partners and auditors how sensitive information, software, suppliers and incidents are managed.
ISO/IEC 27001 is not generally a legal requirement. In healthtech, it often becomes a procurement, contractual or partner requirement when a company handles sensitive information or sells to hospitals and enterprise customers.
Certification is issued by an independent accredited certification body, not by Asteron.
When ISO 27001 becomes a real business requirement
Most healthtech teams do not begin with a desire to collect certificates. They begin when security evidence becomes necessary to move the business forward.
A hospital or enterprise deal is blocked
The buyer expects ISO 27001, structured controls and independent assurance before procurement can move forward.
Security questionnaires keep repeating
Your team is rebuilding the same answers about access, suppliers, incidents and data handling for every customer.
Security work has no clear owner
Controls exist across product, engineering and operations, but nobody maintains one coherent system or evidence cycle.
The next framework is already visible
You expect NEN 7510, IEC 81001-5-1, ISO 27701, ISO 42001 or another overlapping requirement after the first certification.
What ISO 27001 usually needs to cover in healthtech
The scope follows the systems, people and third parties that can affect sensitive information or the reliability of the service.
Product and platform
Production environments, application services, administration tools and the systems used to deliver the healthtech product.
Health and customer data
Personal data, health-related information, research data, customer records and the rules governing how each category is handled.
Cloud, code and deployment
Cloud accounts, source repositories, deployment pipelines, secrets, logging, backups and technical change.
People and access
Employee and contractor access, onboarding, offboarding, privileged accounts, devices, training and policy acceptance.
Suppliers and external services
Hosting, development partners, support tools, AI APIs, subprocessors and other providers that can affect security or availability.
Incidents and continuity
Detection, escalation, customer communication, recovery, lessons learned and evidence that the process operates.
Governance and evidence
Security ownership, risks, objectives, recurring reviews, internal audit, management review and the records an auditor will inspect.
The exact certification scope is agreed before delivery begins. Hospital systems or partner infrastructure that Asteron does not control are not automatically included.
What ISO 27001 does not replace
- A penetration test or technical security assessment
- GDPR legal analysis or a formal data-protection opinion
- ISO 13485, MDR or medical-device regulatory approval
- Clinical validation or proof that a product can never suffer an incident
It creates the management system around information security. Separate technical, privacy or medical-device work remains separate where the scope requires it.
What Asteron builds for you
Asteron prepares the management system, drives the work and stays with the project through the independent certification audit.
| Deliverable | What it gives the company |
|---|---|
| ISMS scope and context | Defines the products, systems, locations, people and third parties covered by certification. |
| Asset and supplier inventories | Creates a maintained view of the systems, information and providers that the security model depends on. |
| Risk assessment and treatment plan | Links real business and technical risks to owners, decisions and controls. |
| Statement of Applicability | Records which Annex A controls apply, how they are implemented and why any exclusions are justified. |
| Policies and operating procedures | Documents how access, suppliers, incidents, development, continuity and other security processes actually operate. |
| Evidence map and recurring calendar | Defines what evidence is retained, who owns it and when each review must happen. |
| Staff preparation and policy acceptance | Introduces the new processes and creates records that the organisation has adopted them. |
| Internal audit | Tests the management system before the independent certification audit. |
| Management review | Gives leadership a structured decision point on risks, performance, priorities and readiness. |
| Certification preparation and support | Coordinates the audit process, prepares the team and supports Stage 1, Stage 2 and agreed remediation. |
We do the compliance work. Your team provides the company knowledge.
Asteron
- Defines the project plan and drives delivery
- Drafts the management system and operating documents
- Maps risks, controls, evidence and responsibilities
- Configures recurring evidence workflows
- Runs the internal audit
- Prepares management review
- Coordinates the certification-body process
- Supports agreed remediation
Your team
- Explains how the company and product operate
- Makes scope and risk decisions
- Provides access to relevant records and systems
- Assigns accountable owners
- Approves policies and risk acceptance
- Implements technical changes that require internal access
- Attends focused working sessions and audit interviews
Typical client involvement: 25-40 hours across the full project.
From scope to audit-ready in 12 weeks
Structured delivery, automated where it helps and led by a named senior expert.
- 1WEEKS 1-2
Scope and operating model
Review the product, markets, customers, systems, data flows, suppliers and current controls. Agree the scope and delivery plan.
- 2WEEKS 2-5
Management system build
Create the risk model, control structure, policies, ownership model, supplier register and evidence requirements.
- 3WEEKS 4-8
Evidence and automation
Configure recurring evidence workflows and connect supported systems where the client environment allows.
- 4WEEKS 8-10
Test and correct
Complete the internal audit, review gaps, implement corrective actions and verify that required evidence is available.
- 5WEEKS 10-12
Management review and audit preparation
Complete management review, finalise the audit pack and prepare the team for the independent certification audit.
Audit-ready in 12 weeks is the Asteron delivery milestone. The certificate usually arrives 4-6 months from kickoff because Stage 1 and Stage 2 follow the certification body's independent schedule.
Expert-led delivery, with automation under the hood
One accountable person leads the work
A named senior compliance expert leads scoping, documentation, internal-audit coordination, certification preparation and audit support. You know who owns the work and who to contact from day one.
- 1:1 communication in Slack or Teams
- Project ownership and follow-ups
- Backed by engagement and engineering support
- No anonymous ticket queue
Repetitive work is handled systematically
Automation is used for recurring evidence, approvals, reminders, registers and review tasks where the client environment supports it. Scope decisions, risk acceptance and audit judgement remain with accountable people.
- Evidence workflows
- Policy acceptance and approvals
- Access and supplier review cycles
- Risk-review triggers
- Questionnaire reuse
ISO 27001 pricing
Fixed scope and transparent pricing for healthtech teams with up to 150 employees.
For one primary company scope and a typical early-stage or growth healthtech operating model.
For a broader team, more control owners, systems, suppliers or organisational complexity.
151+ employees, multiple entities or unusually complex scope - priced individually.
- Fixed scope and price
- Audit-ready in 12 weeks
- Typically 25-40 hours of client time
- Contracted outcome guarantee
Independent certification and external audit fees
ISO/IEC 27001 certification must be performed by an independent accredited certification body. Asteron builds the management system, prepares the evidence and supports the audit, but cannot act as the certification body or issue a certificate for its own implementation work. Keeping these roles separate protects impartiality and avoids a conflict of interest.
Your organisation selects and contracts with the certification body directly. Its fees are paid directly to that body and are not included in Asteron's implementation price.
- Up to 50 employees:typically €4,500-6,000
- 51-150 employees:typically €6,000-9,000
The final certification-body quote depends on the agreed scope, employee count, locations, required audit time, travel and the selected certification body.
Asteron can help compare suitable accredited certification bodies, align the proposed certification scope, coordinate the audit window, prepare the team and evidence, support Stage 1 and Stage 2 questions and coordinate agreed remediation. The audit findings and certification decision remain independent.
Payment terms: 40% at signing, 40% at audit-ready, 20% after certification.
Contracted outcome guarantee
If a non-conformity results from our deliverables, we correct it at our cost within the contracted scope.
The guarantee does not cover missing client actions, external delays, certification-body decisions unrelated to our work or changes introduced outside the agreed scope.
Certification runs on a three-year cycle. The work behind it does not stop.
The certificate remains valid while the management system is maintained and the required surveillance audits are completed. Recertification takes place at the end of the three-year cycle.
Evidence, access reviews, supplier reviews, risk updates, management review and surveillance preparation continue after certification. Compliance Operations keeps the system current without requiring the company to build a separate internal compliance function.
- Evidence and recurring controls maintained
- Surveillance and questionnaires supported
- Regulatory changes mapped to the company
ISO 27001 questions
Official reference
ISO/IEC 27001:2022, including Amendment 1:2024
Find out whether ISO 27001 is the right starting point
Tell us what you build, which customers you sell to, what security evidence they expect and whether you already have any controls or documentation. We will confirm the practical scope, price and route to audit.
