NEN 7510 certification for Dutch healthtech
Asteron builds the information security management system required to protect personal health information within the Dutch healthcare ecosystem. We combine ISO 27001-aligned governance with the healthcare-specific controls and evidence required by NEN 7510:2024. The service is designed for healthcare providers, software suppliers and European healthtech companies entering or expanding in the Netherlands.
- Current NEN 7510:2024 scope implemented
- ISO 27001-aligned ISMS reused
- Dutch healthcare requirements mapped
- Independent certification readiness prepared
€9,900 with an existing Compliance Core
What is NEN 7510?
NEN 7510 is the Dutch information-security standard for organisations that provide healthcare or process personal health information within the healthcare chain. It establishes a controlled management system for protecting the confidentiality, integrity and availability of health information.
The standard is relevant not only to hospitals and clinical practices. It also applies to laboratories, mental-health providers, municipalities, insurers, ICT suppliers and other organisations whose products or services process or exchange personal health information.
NEN 7510 is aligned with ISO/IEC 27001 and ISO/IEC 27002 and adds healthcare-specific controls based on ISO 27799 and the Dutch legal and operational context.
NEN 7510 applies to the organisation and its defined information-security scope. A software product, application or cloud platform cannot be “NEN 7510 compliant” in isolation from the organisation operating and governing it.
Is NEN 7510 mandatory?
Dutch healthcare organisations and other managers of personal health information must be able to demonstrate appropriate information security. The Wabvpz and the related Dutch rules on electronic processing by healthcare providers refer to NEN 7510 as the recognised standard for securing healthcare information systems.
This does not mean that every organisation is legally required to hold a certificate. The obligation is to demonstrate that information security is organised and operated according to the applicable standard.
Independent certification is nevertheless a strong and widely recognised form of assurance. Hospitals, healthcare customers, procurement teams and supervisory bodies may use certification as evidence that the organisation’s management system is periodically assessed.
The current NEN 7510 standard
NEN 7510:2024 replaced the previous edition in December 2024. Organisations with existing certificates must transition to the current version by 20 February 2027.
Already certified? View the NEN 7510:2024 Transition service.
Who should implement NEN 7510?
NEN 7510 is commonly relevant to:
- – hospitals, clinics and independent treatment centres
- – primary-care and mental-health organisations
- – laboratories and diagnostic providers
- – digital-health and telemedicine platforms
- – SaaS providers processing health information
- – EHR, patient-portal and integration vendors
- – medical-device and IVD software companies
- – municipalities involved in youth or social care
- – healthcare insurers and administrative service providers
- – suppliers connecting to Dutch healthcare information systems
For suppliers, applicability depends on the services, data flows and responsibilities involved. Even where formal certification is not contractually required, Dutch healthcare customers frequently expect clear evidence that NEN 7510 requirements are addressed.
NEN 7510 and ISO 27001
NEN 7510 and ISO 27001 use a closely aligned management-system structure. Both require defined scope, leadership, risk management, objectives, competence, documented information, operational control, internal audit, management review and continual improvement.
The difference is context. NEN 7510 applies these principles to personal health information and adds controls reflecting healthcare availability, patient safety, professional access, information exchange and sector-specific threats.
What NEN 7510 addresses in healthcare
Management and operational governance
- – Healthcare information-security scope
- – Risk ownership and acceptance
- – Management responsibilities and objectives
- – Supplier and processor governance
- – Workforce competence and confidentiality
- – Incident response and external reporting
- – Business continuity and healthcare availability
- – Internal audit and management review
Healthcare-specific controls
- – Access to personal health information
- – Identity and authentication
- – Logging and monitoring
- – Secure exchange of health information
- – Medical-device and connected-system interfaces
- – Patient and healthcare-professional access
- – Data integrity and availability
- – Secure lifecycle and change management
Controls must be selected and justified according to risk. Where the organisation deviates from healthcare-specific implementation guidance, the alternative approach and its ability to meet the control objective should be documented through the standard’s comply-or-explain model.
How NEN 7510 connects to Dutch and European requirements
From scope to certification readiness
Scope and healthcare context
Define legal entities, services, locations, systems, suppliers and health-information flows covered by the ISMS.
Baseline and applicability
Assess existing ISO 27001 or NEN processes, Dutch legal dependencies, customer requirements and Cyberbeveiligingswet exposure.
Risk and control design
Update the risk assessment, select applicable controls and document healthcare-specific implementation or justified alternatives.
Management-system implementation
Build or update policies, responsibilities, registers, supplier controls, incident processes, continuity arrangements and performance measures.
Operation and evidence
Run the key workflows, complete reviews, test representative controls and resolve priority gaps. Evidence must show that the system operates beyond its written documentation.
Internal audit and certification
Complete internal audit, management review and corrective actions. Coordinate the independent certification body and prepare process owners for the external audit.
What Asteron delivers
The final deliverables depend on the agreed scope and existing maturity. Production infrastructure changes, penetration testing, specialist legal opinions and other technical implementation work are included only when expressly stated in the proposal.
Management-system foundation
- – NEN 7510 scope and implementation plan
- – Organisational and healthcare-context assessment
- – Risk methodology and updated risk register
- – Statement of Applicability
- – Policy and procedure set
- – Objectives and reporting cadence
- – Internal-audit programme
- – Management-review preparation
Healthcare evidence and controls
- – Personal health-information flow mapping
- – Healthcare-specific control assessment
- – Access and logging governance
- – Supplier and processor review process
- – Incident and reporting workflow
- – Business-continuity evidence
- – NIS2 and Cyberbeveiligingswet mapping
- – Certification evidence and audit preparation
Pricing
This route reuses the existing security management system, evidence and operating processes. The project focuses on the Dutch healthcare context, NEN-specific controls, legal mapping and certification evidence.
This route establishes the required management-system foundation together with the NEN 7510 healthcare requirements.
These published starting prices apply to the initial 10–50 employee band shown on the Pricing page. Larger organisations, several legal entities or complex healthcare environments are priced using the applicable company-size and complexity band.
The existing-Core route saves €10,000 because most of the information-security operating model can be reused.
- – 40% at signing
- – 40% when the agreed audit-ready milestone is reached
- – 20% after certification
Prices exclude VAT where applicable.
Independent certification audit
Asteron builds the management system, prepares evidence, coordinates the audit and supports corrective actions. Asteron cannot issue the certificate or independently audit its own implementation because that would create a conflict of interest.
The client selects and contracts an appropriately recognised NEN 7510 certification body. The certification body performs its own document review, interviews, site assessment and certification decision. Its fees are paid directly by the client and never pass through Asteron.
- – €4,500–€6,000 for organisations with 10–50 employees
- – €6,000–€9,000 for organisations with 51–150 employees
The certification body confirms the actual quotation based on scope, locations, headcount, audit duration and the NCS 7510 scheme. NEN registration or administration charges may also appear in the certification body’s quotation.
Responsibilities
Asteron
- – Builds or updates the NEN 7510 management system
- – Maps Dutch healthcare and cybersecurity requirements
- – Structures risk, controls and operating evidence
- – Prepares process owners for assessment
- – Performs internal readiness activities
- – Coordinates the independent certification audit
Your organisation
- – Provides accurate information about services, systems and data
- – Assigns management, risk and process owners
- – Approves scope and risk-acceptance decisions
- – Implements required technical changes
- – Operates the ISMS and retains evidence
- – Contracts and pays the certification body
- – Maintains compliance after certification
Frequently asked questions
What is NEN 7510?
NEN 7510 is the Dutch standard for information security in healthcare and for organisations managing personal health information.
Who needs NEN 7510?
It is relevant to healthcare providers and other organisations processing personal health information, including healthtech and healthcare ICT suppliers.
Is NEN 7510 certification legally mandatory?
Certification is not universally mandatory. Organisations may nevertheless be required to demonstrate that they work according to NEN 7510, and customers may contractually require certification.
What is the difference between NEN 7510 and ISO 27001?
ISO 27001 is an international information-security management standard. NEN 7510 applies a closely aligned structure to the Dutch healthcare sector and adds healthcare-specific controls.
What are NEN 7510-1 and NEN 7510-2?
Part 1 contains management-system requirements. Part 2 provides healthcare-specific controls and implementation guidance.
What changed in NEN 7510:2024?
The standard was aligned with current ISO 27001, ISO 27002 and ISO 27799 structures, updated healthcare controls and added stronger links to NIS2 and the Cyberbeveiligingswet.
When must existing certificates transition?
Existing certificates must be converted to NEN 7510:2024 by 20 February 2027.
Does NEN 7510 prove GDPR compliance?
No. It supports information-security requirements but does not cover every GDPR obligation, including legal bases, transparency and individual rights.
Does NEN 7510 satisfy the Cyberbeveiligingswet?
It provides substantial overlap and useful mapping, but organisations must separately assess Cyberbeveiligingswet applicability and legal obligations.
Can a software product be NEN 7510 certified?
NEN 7510 certification applies to an organisation and its defined management-system scope, not to a standalone application in isolation.
How much does NEN 7510 implementation cost?
For the initial published company-size band, implementation costs €9,900 from an existing Compliance Core or €19,900 as the first framework project. External certification fees are separate.
Official references
- – NEN 7510 information-security-in-healthcare portal
- – NEN 7510-1:2024
- – NEN 7510-2:2024 and the March 2026 amendment
- – NCS 7510:2025 certification scheme
- – NEN 7510 certification register and transition guidance
- – Dutch Wabvpz and related electronic-health-data rules
- – Dutch Cyberbeveiligingswet information from NCTV
- – IGJ information-security expectations
Last reviewed: July 2026
Asteron is not endorsed by or partnered with NEN, ISO, IEC, the European Commission, any supervisory authority or certification body.
Related services and frameworks
Build the security system Dutch healthcare customers expect to see
We will assess your existing ISMS, healthcare data flows, Dutch market requirements and certification objective, then define the practical route to NEN 7510 readiness.
