AsteronAsteron
    NEN 7510 & Dutch Healthcare

    NEN 7510:2024 transition guide: what healthtech organisations must finish before 20 February 2027

    How to transition from NEN 7510:2017+A1:2020 to NEN 7510-1:2024 before 20 February 2027, including A1:2026, audit readiness and supplier scope.

    By Asteron Compliance Team17 min read

    Every certificate against NEN 7510-1:2017+A1:2020 must be converted to the 2024 edition before 20 February 2027. The transition is not complete when the policies have been rewritten; the organisation must complete the certification process against the new edition before the deadline.

    Transition status as of 6 July 2026. NEN 7510-1:2024 is the current management-system standard. The current controls publication is NEN 7510-2:2024+A1:2026, which replaced the unamended 2024 Part 2. Certification bodies work under NCS 7510:2025 and must be accredited for the new edition before issuing an accredited certificate. Existing certificates must be converted within the formal transition window.

    That leaves just over seven months from this article's review date. For a small healthtech company with an established ISMS, that can be enough time. It is not enough time to postpone the gap analysis until the next annual audit and assume the certification body will turn it into a transition audit automatically.

    The practical job is to establish the correct baseline, confirm that the certification scope still makes sense, rebuild the statement of applicability, implement the changed controls, collect operating evidence, complete the internal assurance cycle and leave time to close any audit findings before the deadline.

    This deadline sits alongside the Cyberbeveiligingswet, CRA, EU AI Act and other European healthtech milestones. Asteron's EU Healthtech Compliance Calendar can be used to view those dates on one planning timeline.

    The short answer

    • Certificates against NEN 7510-1:2017+A1:2020 must be converted within the formal transition window; a later nominal expiry date does not override the transition rules.
    • The certification target is NEN 7510-1:2024. Control selection and healthcare-specific implementation should use the current NEN 7510-2:2024+A1:2026 publication.
    • The 2026 amendment did not change Part 1, but it did update healthcare-specific guidance, terminology and annexes, including the mapping to the Cyberbeveiligingswet.
    • A transition normally requires a documented gap analysis, updated risk assessment and statement of applicability, implementation evidence, internal audit, management review and corrective-action closure.
    • The certification body must be accredited for the new edition before it can issue an accredited NEN 7510-1:2024 certificate. Verify its status and transition plan rather than relying on a generic booking confirmation.
    • Not every company selling to healthcare should hold NEN 7510. Certification eligibility turns on healthcare activity or demonstrable, structural processing of personal health information; ISO 27001 may be the correct alternative for other suppliers.

    Which documents form the current NEN 7510 baseline?

    The phrase NEN 7510:2024 is convenient but incomplete. A transition team should distinguish the requirements applied to the organisation from the rules applied to the certification body.

    DocumentCurrent roleWhat it means for the transition
    NEN 7510-1:2024Management-system requirements; the certification target.Replaces NEN 7510-1:2017+A1:2020. Requirements in clauses 4-10 cannot be excluded when conformity is claimed.
    NEN 7510-2:2024+A1:2026Current healthcare information-security controls and guidance.Use the amended publication when updating the risk treatment and statement of applicability. The unamended 2024 Part 2 is withdrawn.
    NCS 7510:2025Certification scheme for bodies auditing healthcare information-security management systems.Replaced NCS 7510:2018 and started the two-year certification transition window on 20 February 2025.
    RvA SAP-C025Specific accreditation protocol used by the Dutch Accreditation Council.Defines accreditation and scope expectations and confirms the end of old-edition accreditation on 20 February 2027.

    Certification is against Part 1. NEN 7510-1 contains the management-system requirements and its Annex A reference controls. NEN 7510-2 provides healthcare-specific implementation guidance; it is not a separate product certificate. The certificate concerns the organisation's information-security management system and its stated scope, not a software product in isolation.

    A practical note for international teams

    NEN 7510 is a Dutch standard and NEN states that no English edition is available. Under an agreement between the Dutch Ministry of Health, Welfare and Sport and NEN, the current NEN 7510-1 and NEN 7510-2 texts can be consulted without charge through NEN Connect. International teams should work from the official Dutch text and use ISO/IEC 27001, ISO/IEC 27002 and ISO 27799 as cross-references, not as substitutes for the Dutch healthcare requirements.

    The transition timeline

    DateWhat happenedPractical significance
    16 December 2024NEN 7510-1:2024 and the original NEN 7510-2:2024 became current.Existing users could begin implementation and gap analysis.
    20 February 2025NCS 7510:2025 became effective.Certification bodies could seek accreditation for the new scheme; the certificate transition period runs for two years.
    March 2026NEN 7510-2:2024+A1:2026 replaced the unamended Part 2.Transition work should use the amended controls publication and updated annexes.
    6 July 2026Review date of this guide.Just over seven months remain, including audit scheduling and corrective-action time.
    Before 20 February 2027Certification against NEN 7510-1:2024 must be completed.An internal project or audit alone may not complete the transition under the certification body's process.

    NEN also communicated an initial one-year implementation period after publication of the 2024 standard. That internal implementation milestone ended in December 2025. It should not be read as a second deadline or as permission to wait until February 2027 before operating the updated controls.

    If an old-edition certificate displays a later nominal expiry date, do not assume that printed date overrides the transition rules. Obtain written confirmation from the certification body showing when the transition audit will occur, when findings must be closed, when the certification decision will be completed and when the updated certificate will be available.

    Who should transition — and who should not pursue the certificate?

    Existing certificate holders

    Every organisation that wants to maintain accredited NEN 7510 certification beyond the deadline must transition. The work applies whether the current certificate belongs to a hospital, clinic, laboratory, healthcare service provider, hosting provider or healthtech supplier.

    New applicants

    A new applicant should implement and seek certification against NEN 7510-1:2024, using the current Part 2. Starting a fresh programme against the 2017 edition would create immediate rework and would not provide a viable certification route beyond the deadline.

    Healthcare providers and organisations managing personal health information

    NEN describes two principal certification populations: healthcare providers and other organisations that manage personal health information. A healthcare provider's certification scope must include at least one primary care process; a scope restricted to back-office functions that avoids the primary healthcare activity is not acceptable under the accreditation protocol.

    For suppliers and other processors, eligibility is more specific. NEN's 2025 target-group clarification links certification to demonstrable, lawful and structural processing of personal health information for Dutch healthcare customers, together with relevant healthcare-specific controls in the statement of applicability. Storage, backup and other processing can qualify even where staff do not routinely read the records.

    Suppliers without structural processing

    A software vendor does not become an appropriate NEN 7510 certification candidate merely because hospitals buy its product. NEN's clarification says that where a supplier has no lawful basis or responsibility for structural processing of personal health information, NEN 7510-1 certification should not be required; ISO 27001 should be treated as the applicable alternative for that supplier.

    This distinction matters commercially. Pursuing the wrong certificate can create a misleading scope, force artificial healthcare controls into the statement of applicability and still fail to answer the customer's real question. The correct first step is a short eligibility and scope decision, not a certificate purchase.

    What changed from the 2017 edition?

    The new edition aligns the NEN framework with ISO/IEC 27001:2022, ISO/IEC 27002:2022 and the healthcare guidance in ISO 27799. That changes the structure, language and control catalogue, but the transition is more than a cross-reference exercise.

    1. A modernised control structure

    NEN 7510-2 now follows the four-theme structure used by ISO/IEC 27002:2022: organisational, people, physical and technological controls. Controls from the previous edition have been merged, reorganised or rewritten. Each control is supported by a clearer purpose and attributes that make it easier to group controls by cybersecurity concept, operational capability and security property.

    Teams should pay particular attention to topics introduced or made more explicit through the 2022 ISO baseline, including threat intelligence, cloud-service security, ICT readiness for business continuity, physical-security monitoring, configuration management, information deletion, data masking, data-leakage prevention, security monitoring, web filtering and secure coding. Existing tools may already perform some of this work; the transition task is to make the ownership, risk rationale and operating evidence explicit.

    2. Updated healthcare-specific guidance

    The 2026 amendment brought Part 2 into line with the final ISO 27799 publication and refined healthcare-specific controls. NEN's April 2026 explanation highlights, among other changes:

    • special attention for genetic and biometric information;
    • more room for proportionate organisation-specific policy while preserving the control objective;
    • clearer expectations for professional competence;
    • a stronger link between emergency procedures and continuity planning;
    • sharper monitoring and response around access to personal health information;
    • explicit inclusion of social engineering in awareness, education and training;
    • attention to a culture that encourages incident reporting;
    • simulation of crisis management as part of management training.

    3. Comply or explain is operational, not cosmetic

    NEN explains that an organisation selects controls through its information-security risk assessment and records them in the statement of applicability. Where a selected control departs from the healthcare-specific implementation guidance, the organisation should document how the control objective is still achieved. Auditors can ask for that reasoning.

    This makes a copied statement of applicability especially weak. A transition should connect each included control to a risk, an accountable owner, an implemented process and evidence. Exclusions and deviations need a defensible explanation based on the real scope, not a generic sentence inherited from the previous template.

    4. A more explicit connection to Dutch NIS2 implementation

    Annex E of Part 2 maps the NEN framework to the Cyberbeveiligingswet and Cyberbeveiligingsbesluit. This can support a control crosswalk and reduce duplicated work, but it does not turn an NEN certificate into proof of every legal duty. Registration, statutory incident reporting, legal scope, management obligations and systems outside the certificate scope still require separate treatment.

    5. The 2026 amendment must be included

    The amendment did not change NEN 7510-1. It updated terminology and Annexes C, D and E in Part 2 and refined several healthcare controls. A transition project that froze its baseline in early 2025 should therefore refresh the gap analysis against NEN 7510-2:2024+A1:2026 before the internal audit.

    Do not count controls and stop. A transition cannot be validated by showing that an old control list was renumbered. The test is whether the updated risks, responsibilities, controls and evidence operate within the certified scope.

    A practical eight-step transition plan

    1. Lock the baseline and certification route

    Obtain the current Part 1, the consolidated Part 2 amendment and the applicable certification information from NEN. Ask the current certification body to confirm in writing that it is accredited — or will be accredited in time — for NEN 7510-1:2024, and how it plans to combine the transition with surveillance or recertification.

    Agree the planned audit date, expected certification-decision date, certificate availability, treatment of open nonconformities and the last realistic date for submitting corrective-action evidence. An audit booked for February may already be too late to complete the certification process before the deadline.

    2. Reconfirm eligibility and scope

    Document which legal entity is certified, which locations and services are included, which personal health information is processed and which healthcare customers or primary care processes support the certification scope. Review acquisitions, new hosting arrangements, international operations and services added since the previous certification.

    For a supplier, retain evidence of structural processing arrangements, such as processor agreements that describe duration, nature, purpose, data categories and responsibilities. For a healthcare provider, ensure the scope includes the relevant primary care process rather than only central IT.

    3. Build a clause-and-control gap analysis

    Separate management-system gaps from control gaps. For clauses 4-10, review context, interested parties, scope, leadership, risk planning, objectives, resources, operational control, performance evaluation and improvement. For the controls, map the previous statement of applicability to the current catalogue and identify new, merged, renamed or materially revised topics.

    Record each gap with an owner, required evidence, target date and validation method. A spreadsheet can track the programme, but it should not become the only proof that the ISMS changed.

    4. Refresh the risk assessment and dependencies

    Update the risk model before finalising the control set. Include cloud concentration, critical subprocessors, identity providers, remote support, software dependencies, medical-device interfaces, data exchange, ransomware scenarios, loss of clinical availability and unauthorised access to personal health information.

    Supplier security should be linked to service criticality. Define which suppliers require due diligence, contractual controls, security evidence, incident escalation and periodic reassessment. A list of vendors without a risk method or follow-up process will not demonstrate an operating supply-chain programme.

    5. Rebuild the statement of applicability

    The statement of applicability should identify the controls selected, their implementation status and the justification for inclusion, exclusion or deviation. It should align with the current numbering and with the risks and healthcare-specific objectives in the amended Part 2.

    Where one control is delivered through several systems or teams, name the accountable process rather than pasting tool names. Where a control is not applicable, document the factual reason and check that another part of the scope does not reintroduce the risk.

    6. Implement the change and collect operating evidence

    Policies are necessary, but transition evidence should show the system running. Useful evidence includes completed access reviews, vulnerability remediation records, secure-development checks, supplier assessments, backup and recovery tests, incident exercises, monitoring outputs, awareness completion, management training and decisions taken after control reviews.

    For healthtech teams, product and corporate security evidence should connect where the risks connect. A vulnerability in a clinical application may affect the ISMS, MDR or IVDR product processes, privacy obligations and customer commitments at the same time. Separate repositories are acceptable; contradictory ownership and escalation rules are not.

    7. Complete internal assurance

    Run an internal audit against the 2024 management-system requirements and the updated statement of applicability. The audit should test implementation, not only document presence, and it should cover the transition changes explicitly. Resolve findings or place them in a controlled corrective-action process with evidence and dates.

    Management review should then consider the updated scope, risk profile, performance data, incidents, supplier issues, audit results, resource needs and transition readiness. The minutes should record decisions and actions rather than simply stating that the ISMS was reviewed.

    8. Complete the transition audit and close findings

    Provide the certification body with the requested transition material before the audit. After the audit, respond to nonconformities with cause analysis, correction, corrective action and evidence. Leave enough calendar time for review by the auditor and the certification decision; the audit meeting itself does not necessarily complete the certification process.

    Evidence to have ready

    The certification body determines its audit plan, so no generic list can guarantee certification. A well-prepared transition file will normally make the following evidence easy to trace:

    • approved transition plan and completed gap analysis;
    • current certification scope, process map and personal health information flows;
    • updated context, interested parties and legal or contractual requirements;
    • current risk assessment, risk-treatment plan and statement of applicability;
    • control ownership and implementation evidence for new or changed topics;
    • supplier inventory, criticality method, assessments and contractual follow-up;
    • access reviews, logging and monitoring evidence relevant to health information;
    • continuity, recovery and crisis-exercise results;
    • training and competence evidence, including management participation;
    • internal audit report, management-review records and closed corrective actions.

    How to plan the audit without losing the certification cycle

    A transition audit may be coordinated with a surveillance or recertification audit, but the route is determined by the certification body and the organisation's existing cycle. Do not assume that combining activities is automatic or that a normal surveillance booking contains enough time to assess the transition.

    Ask four direct questions:

    • Is the certification body already accredited for NEN 7510-1:2024, and is that status visible through the official NEN or RvA information?
    • Will the transition be assessed during surveillance, recertification or a separate audit, and what additional audit time or evidence is required?
    • What is the planned date for the certification decision and certificate issuance, not merely the audit date?
    • What correction window is available if the audit identifies a nonconformity close to the deadline?

    There is a common deadline for every old-version certificate. That creates a rational scheduling risk even without making claims about market-wide capacity. Contact the certification body early, but choose dates based on internal evidence readiness rather than booking the earliest slot and hoping the system catches up.

    Common transition mistakes

    Using the withdrawn Part 2

    The original NEN 7510-2:2024 was replaced in 2026. A gap analysis that still cites only that withdrawn publication should be refreshed against NEN 7510-2:2024+A1:2026.

    Treating the statement of applicability as a numbering exercise

    Control identifiers changed, but so did the structure, guidance and risk emphasis. A cross-reference is the beginning of the analysis, not the completed analysis.

    Keeping an outdated scope

    A certificate can look reassuring while omitting the service, location, platform or processing activity that customers actually depend on. Reconfirm scope before investing in control remediation.

    Writing policies without evidence

    A new cloud policy does not prove that cloud services are approved, configured, monitored and periodically reviewed. Every material policy change needs an operating process and evidence owner.

    Assuming ISO 27001 automatically becomes NEN 7510

    The standards share an ISMS foundation, but the certification populations, healthcare scope and care-specific controls matter. An ISO 27001 certificate is not automatically a NEN 7510 certificate.

    Starting the audit too close to the deadline

    Nonconformities require correction and certification decisions take time. A February audit date can create a break in certification even when the remediation work is technically manageable.

    Confusing certification with legal compliance

    NEN states that certification is not itself mandatory for the Cyberbeveiligingswet. It can be strong evidence for risk-management controls, but it does not replace legal scope assessment, NCSC registration, statutory incident reporting or obligations outside the certified ISMS scope.

    NEN 7510, ISO 27001 and the Cyberbeveiligingswet

    FrameworkPrimary questionWhat it does not prove by itself
    NEN 7510-1:2024Does the scoped healthcare information-security management system meet the Dutch healthcare ISMS requirements?That every product is secure, every customer service is in scope, or every legal reporting duty is fulfilled.
    ISO/IEC 27001:2022Does the scoped ISMS meet the international information-security management-system requirements?That the healthcare-specific NEN certification conditions and controls are satisfied.
    CyberbeveiligingswetDoes an in-scope entity meet Dutch NIS2 duties for risk management, governance, registration and incident reporting?A certificate does not replace the entity's statutory decisions and notifications.

    A combined ISO 27001 and NEN 7510 certification route can reduce duplicated audit work because the standards share an ISMS foundation. The certification body must still assess the distinct scopes and NEN-specific requirements. A combined programme should maintain one coherent ISMS while keeping the certificate scopes and healthcare-specific evidence clear.

    A realistic transition schedule from July 2026

    The following sequence is not an official timetable and does not guarantee certification. It illustrates how to preserve time for operating evidence and corrective actions.

    PeriodPriority workExit condition
    July-August 2026Confirm baseline, scope, eligibility and certification route; complete the gap analysis and transition plan.Approved plan, booked audit route, named owners and current standards.
    September-October 2026Implement control and process changes; update risk, suppliers, cloud, continuity, access and secure-development evidence.Controls operate and evidence is accumulating.
    November 2026Run the transition-focused internal audit and management review.Findings are understood, owned and being corrected.
    December 2026-January 2027Complete the external transition audit and submit corrective-action evidence.Certification decision can be completed before the deadline.
    Before 20 February 2027Confirm completion of certification against NEN 7510-1:2024 and update customer evidence packs.No break in certified status.

    An organisation starting later should reduce scope ambiguity and decision latency, not skip the internal audit or manufacture retrospective evidence. If uninterrupted certification is no longer realistic, discuss the consequences transparently with the certification body and affected customers.

    Three healthtech examples

    A Dutch hospital SaaS supplier with an old NEN certificate

    The supplier hosts and backs up patient communication data for several Dutch hospitals under processor agreements. Its current certificate references NEN 7510-1:2017+A1:2020. It is a credible supplier-certification candidate because it structurally processes personal health information. It should transition the certificate, refresh its cloud, supplier, access and continuity evidence, and make sure the scope names the services customers actually use.

    A German medical-software vendor with ISO 27001

    The vendor licenses software to Dutch clinics but never receives, hosts or supports access to patient data. Selling into Dutch healthcare does not by itself make NEN 7510 certification appropriate. ISO 27001 may be the more accurate assurance route unless the operating model changes or another qualifying basis is established. Dutch customers can still specify product-security and incident-cooperation requirements.

    A Dutch healthcare provider

    The provider's old certificate covers central IT and one clinical service. During transition it must ensure that the certification scope includes the relevant primary care process, update the control framework and demonstrate that continuity, access monitoring, supplier risk and crisis governance work in the care environment. A back-office-only scope would not meet the accreditation expectation for a healthcare institution.

    Conclusion

    For an existing certificate holder, this is a fixed-deadline transition, not a document-renaming exercise. The purpose is to bring the healthcare information-security management system onto the current ISO-aligned structure, apply the amended healthcare guidance and show that the controls operate within an accurate scope.

    Before planning remediation, answer three questions: Is NEN 7510 the right certificate for this organisation? Does the scope cover the healthcare services and information that matter? Is there enough time not only to audit the new system, but also to close findings and complete the certification process before the deadline?

    For teams that answer those questions now, the remaining work can be organised. For teams that postpone them, the deadline risk is not only an audit delay; it is a period in which customers can no longer rely on an uninterrupted accredited certificate against the current standard.

    Information only. This article provides general information and is not legal, certification or audit advice. Confirm the current standard editions, accreditation status, certificate scope and transition route with NEN and the selected certification body.

    Frequently asked questions

    What is the NEN 7510:2024 transition deadline?
    All existing certificates must be converted before 20 February 2027. To avoid a gap, certification against the new edition must be completed before that date. Confirm with the certification body when the transition is considered complete under its process; finishing only the internal project or audit may not be enough.
    Which editions should we use now?
    Use NEN 7510-1:2024 for the management-system requirements and the current NEN 7510-2:2024+A1:2026 for controls and healthcare-specific implementation guidance. NCS 7510:2025 governs certification bodies.
    Did the 2026 amendment change NEN 7510-1?
    No. NEN states that Part 1 did not change. The amendment updated Part 2, including healthcare-specific guidance, terminology and Annexes C, D and E.
    Can our old certificate remain valid after 20 February 2027 if it shows a later expiry date?
    Do not rely on that assumption. NEN says existing certificates must be converted before 20 February 2027, and the RvA protocol ends old-edition accreditation on that date. Ask the certification body for written confirmation of the transition and issue dates.
    Is NEN 7510 certification legally mandatory?
    Certification is one way to demonstrate conformity, but it is not universally mandatory and NEN states it is not itself required by the Cyberbeveiligingswet. Applicable healthcare rules, supervisory expectations and contracts may still require demonstrable NEN 7510 conformity.
    Does every healthtech software supplier need NEN 7510?
    No. Certification is appropriate for healthcare providers and organisations that lawfully and structurally process or manage personal health information. A supplier without such processing may be better served by ISO 27001, even if hospitals are customers.
    Is NEN 7510 a product certification?
    No. It certifies the organisation’s scoped information-security management system. Software and services are relevant because they sit within or support that scope, but the certificate is not a product-security approval.
    Can ISO 27001 and NEN 7510 be audited together?
    Yes, a combined certification route can reduce duplicated audit effort because the standards share an ISMS foundation. The certification body must still assess the distinct scopes and healthcare-specific NEN requirements.
    Can the transition audit be combined with surveillance or recertification?
    Often it can be coordinated, but this is not automatic. The certification body must confirm the audit route, additional time, evidence requirements and certificate-issue schedule.
    What should be done first?
    Confirm the current standards, certificate scope, eligibility and certification-body route. Then complete a structured gap analysis before rewriting policies or rebuilding the statement of applicability.

    Primary sources

    Change log

    • 6 July 2026 — First publication. Reflects NEN 7510-1:2024, NEN 7510-2:2024+A1:2026, NCS 7510:2025 and RvA SAP-C025.