AsteronAsteron

    NEN 7510 certification for Dutch healthtech

    Asteron builds the information security management system required to protect personal health information within the Dutch healthcare ecosystem. We combine ISO 27001-aligned governance with the healthcare-specific controls and evidence required by NEN 7510:2024. The service is designed for healthcare providers, software suppliers and European healthtech companies entering or expanding in the Netherlands.

    View NEN 7510 pricing
    • Current NEN 7510:2024 scope implemented
    • ISO 27001-aligned ISMS reused
    • Dutch healthcare requirements mapped
    • Independent certification readiness prepared

    €9,900 with an existing Compliance Core

    What is NEN 7510?

    NEN 7510 is the Dutch information-security standard for organisations that provide healthcare or process personal health information within the healthcare chain. It establishes a controlled management system for protecting the confidentiality, integrity and availability of health information.

    The standard is relevant not only to hospitals and clinical practices. It also applies to laboratories, mental-health providers, municipalities, insurers, ICT suppliers and other organisations whose products or services process or exchange personal health information.

    NEN 7510 is aligned with ISO/IEC 27001 and ISO/IEC 27002 and adds healthcare-specific controls based on ISO 27799 and the Dutch legal and operational context.

    NEN 7510 applies to the organisation and its defined information-security scope. A software product, application or cloud platform cannot be “NEN 7510 compliant” in isolation from the organisation operating and governing it.

    Is NEN 7510 mandatory?

    Dutch healthcare organisations and other managers of personal health information must be able to demonstrate appropriate information security. The Wabvpz and the related Dutch rules on electronic processing by healthcare providers refer to NEN 7510 as the recognised standard for securing healthcare information systems.

    This does not mean that every organisation is legally required to hold a certificate. The obligation is to demonstrate that information security is organised and operated according to the applicable standard.

    Independent certification is nevertheless a strong and widely recognised form of assurance. Hospitals, healthcare customers, procurement teams and supervisory bodies may use certification as evidence that the organisation’s management system is periodically assessed.

    Demonstrable compliance may be required even where certification is not. Certification provides independent evidence, but it does not replace the organisation’s responsibility to operate the system every day.

    The current NEN 7510 standard

    NEN 7510-1:2024
    Defines the requirements for the healthcare information security management system. Certification is assessed against the applicable management-system requirements and controls.
    NEN 7510-2:2024
    Provides healthcare-specific controls and implementation guidance aligned with ISO 27002 and ISO 27799.
    2026 amendment to NEN 7510-2
    Updates healthcare controls and annexes to align with the final ISO 27799 and adds mapping to the Dutch Cyberbeveiligingswet.
    NCS 7510:2025
    Defines requirements for certification bodies performing NEN 7510 audits.

    NEN 7510:2024 replaced the previous edition in December 2024. Organisations with existing certificates must transition to the current version by 20 February 2027.

    Already certified? View the NEN 7510:2024 Transition service.

    Who should implement NEN 7510?

    NEN 7510 is commonly relevant to:

    • hospitals, clinics and independent treatment centres
    • primary-care and mental-health organisations
    • laboratories and diagnostic providers
    • digital-health and telemedicine platforms
    • SaaS providers processing health information
    • EHR, patient-portal and integration vendors
    • medical-device and IVD software companies
    • municipalities involved in youth or social care
    • healthcare insurers and administrative service providers
    • suppliers connecting to Dutch healthcare information systems

    For suppliers, applicability depends on the services, data flows and responsibilities involved. Even where formal certification is not contractually required, Dutch healthcare customers frequently expect clear evidence that NEN 7510 requirements are addressed.

    NEN 7510 and ISO 27001

    NEN 7510 and ISO 27001 use a closely aligned management-system structure. Both require defined scope, leadership, risk management, objectives, competence, documented information, operational control, internal audit, management review and continual improvement.

    The difference is context. NEN 7510 applies these principles to personal health information and adds controls reflecting healthcare availability, patient safety, professional access, information exchange and sector-specific threats.

    Existing Asteron Compliance Core or ISO 27001-aligned ISMS
    Reuse governance, risk, audit, supplier, incident and evidence processes; add the Dutch healthcare scope and NEN-specific controls.
    No mature ISMS
    Build the management-system foundation and NEN 7510 requirements as one first project.
    Existing NEN 7510:2017 certificate
    Use the separate transition service to update the system and evidence before the February 2027 deadline.

    What NEN 7510 addresses in healthcare

    Management and operational governance

    • Healthcare information-security scope
    • Risk ownership and acceptance
    • Management responsibilities and objectives
    • Supplier and processor governance
    • Workforce competence and confidentiality
    • Incident response and external reporting
    • Business continuity and healthcare availability
    • Internal audit and management review

    Healthcare-specific controls

    • Access to personal health information
    • Identity and authentication
    • Logging and monitoring
    • Secure exchange of health information
    • Medical-device and connected-system interfaces
    • Patient and healthcare-professional access
    • Data integrity and availability
    • Secure lifecycle and change management

    Controls must be selected and justified according to risk. Where the organisation deviates from healthcare-specific implementation guidance, the alternative approach and its ability to meet the control objective should be documented through the standard’s comply-or-explain model.

    How NEN 7510 connects to Dutch and European requirements

    Wabvpz
    Refers to recognised information-security requirements for electronic processing of healthcare information.
    Wegiz
    Supports secure and standardised electronic exchange of healthcare data.
    Cyberbeveiligingswet
    Implements NIS2 in the Netherlands. NEN 7510:2024 provides substantial overlap and includes mapping, but does not automatically prove full legal compliance.
    GDPR / AVG
    Requires appropriate protection and accountability for personal data. NEN 7510 supports security but does not cover every GDPR obligation.
    NEN 7512
    Adds requirements concerning the trusted basis for electronic healthcare information exchange.
    NEN 7513
    Addresses logging of actions involving electronic patient records.
    NTA 7516
    Addresses secure ad hoc communication of personal health information.
    ISO 27001
    Provides the international ISMS foundation on which much of NEN 7510 is built.
    Cyberbeveiligingswet update: The Dutch Cyberbeveiligingswet was approved in July 2026 and enters into force on 15 August 2026. Applicability, registration, duty-of-care and incident-reporting obligations must still be assessed separately for each organisation.

    From scope to certification readiness

    1. Scope and healthcare context

      Define legal entities, services, locations, systems, suppliers and health-information flows covered by the ISMS.

    2. Baseline and applicability

      Assess existing ISO 27001 or NEN processes, Dutch legal dependencies, customer requirements and Cyberbeveiligingswet exposure.

    3. Risk and control design

      Update the risk assessment, select applicable controls and document healthcare-specific implementation or justified alternatives.

    4. Management-system implementation

      Build or update policies, responsibilities, registers, supplier controls, incident processes, continuity arrangements and performance measures.

    5. Operation and evidence

      Run the key workflows, complete reviews, test representative controls and resolve priority gaps. Evidence must show that the system operates beyond its written documentation.

    6. Internal audit and certification

      Complete internal audit, management review and corrective actions. Coordinate the independent certification body and prepare process owners for the external audit.

    What Asteron delivers

    The final deliverables depend on the agreed scope and existing maturity. Production infrastructure changes, penetration testing, specialist legal opinions and other technical implementation work are included only when expressly stated in the proposal.

    Management-system foundation

    • NEN 7510 scope and implementation plan
    • Organisational and healthcare-context assessment
    • Risk methodology and updated risk register
    • Statement of Applicability
    • Policy and procedure set
    • Objectives and reporting cadence
    • Internal-audit programme
    • Management-review preparation

    Healthcare evidence and controls

    • Personal health-information flow mapping
    • Healthcare-specific control assessment
    • Access and logging governance
    • Supplier and processor review process
    • Incident and reporting workflow
    • Business-continuity evidence
    • NIS2 and Cyberbeveiligingswet mapping
    • Certification evidence and audit preparation

    Pricing

    From an existing Compliance Core
    €9,900

    This route reuses the existing security management system, evidence and operating processes. The project focuses on the Dutch healthcare context, NEN-specific controls, legal mapping and certification evidence.

    As the first Asteron framework project
    €19,900

    This route establishes the required management-system foundation together with the NEN 7510 healthcare requirements.

    These published starting prices apply to the initial 10–50 employee band shown on the Pricing page. Larger organisations, several legal entities or complex healthcare environments are priced using the applicable company-size and complexity band.

    The existing-Core route saves €10,000 because most of the information-security operating model can be reused.

    Payment terms (fixed-scope)
    • 40% at signing
    • 40% when the agreed audit-ready milestone is reached
    • 20% after certification

    Prices exclude VAT where applicable.

    View full pricing

    Independent certification audit

    Asteron builds the management system, prepares evidence, coordinates the audit and supports corrective actions. Asteron cannot issue the certificate or independently audit its own implementation because that would create a conflict of interest.

    The client selects and contracts an appropriately recognised NEN 7510 certification body. The certification body performs its own document review, interviews, site assessment and certification decision. Its fees are paid directly by the client and never pass through Asteron.

    Indicative external certification fees
    • €4,500–€6,000 for organisations with 10–50 employees
    • €6,000–€9,000 for organisations with 51–150 employees

    The certification body confirms the actual quotation based on scope, locations, headcount, audit duration and the NCS 7510 scheme. NEN registration or administration charges may also appear in the certification body’s quotation.

    If certification is not achieved because an Asteron deliverable is incomplete or deficient, Asteron corrects that work at no additional professional fee within the contracted scope. This does not override the certification body’s independent judgement and does not cover new scope, missing client actions or technical changes outside the proposal.

    Responsibilities

    Asteron

    • Builds or updates the NEN 7510 management system
    • Maps Dutch healthcare and cybersecurity requirements
    • Structures risk, controls and operating evidence
    • Prepares process owners for assessment
    • Performs internal readiness activities
    • Coordinates the independent certification audit

    Your organisation

    • Provides accurate information about services, systems and data
    • Assigns management, risk and process owners
    • Approves scope and risk-acceptance decisions
    • Implements required technical changes
    • Operates the ISMS and retains evidence
    • Contracts and pays the certification body
    • Maintains compliance after certification

    Frequently asked questions

    What is NEN 7510?

    NEN 7510 is the Dutch standard for information security in healthcare and for organisations managing personal health information.

    Who needs NEN 7510?

    It is relevant to healthcare providers and other organisations processing personal health information, including healthtech and healthcare ICT suppliers.

    Is NEN 7510 certification legally mandatory?

    Certification is not universally mandatory. Organisations may nevertheless be required to demonstrate that they work according to NEN 7510, and customers may contractually require certification.

    What is the difference between NEN 7510 and ISO 27001?

    ISO 27001 is an international information-security management standard. NEN 7510 applies a closely aligned structure to the Dutch healthcare sector and adds healthcare-specific controls.

    What are NEN 7510-1 and NEN 7510-2?

    Part 1 contains management-system requirements. Part 2 provides healthcare-specific controls and implementation guidance.

    What changed in NEN 7510:2024?

    The standard was aligned with current ISO 27001, ISO 27002 and ISO 27799 structures, updated healthcare controls and added stronger links to NIS2 and the Cyberbeveiligingswet.

    When must existing certificates transition?

    Existing certificates must be converted to NEN 7510:2024 by 20 February 2027.

    Does NEN 7510 prove GDPR compliance?

    No. It supports information-security requirements but does not cover every GDPR obligation, including legal bases, transparency and individual rights.

    Does NEN 7510 satisfy the Cyberbeveiligingswet?

    It provides substantial overlap and useful mapping, but organisations must separately assess Cyberbeveiligingswet applicability and legal obligations.

    Can a software product be NEN 7510 certified?

    NEN 7510 certification applies to an organisation and its defined management-system scope, not to a standalone application in isolation.

    How much does NEN 7510 implementation cost?

    For the initial published company-size band, implementation costs €9,900 from an existing Compliance Core or €19,900 as the first framework project. External certification fees are separate.

    Official references

    • – NEN 7510 information-security-in-healthcare portal
    • – NEN 7510-1:2024
    • – NEN 7510-2:2024 and the March 2026 amendment
    • – NCS 7510:2025 certification scheme
    • – NEN 7510 certification register and transition guidance
    • – Dutch Wabvpz and related electronic-health-data rules
    • – Dutch Cyberbeveiligingswet information from NCTV
    • – IGJ information-security expectations

    Last reviewed: July 2026

    Asteron is not endorsed by or partnered with NEN, ISO, IEC, the European Commission, any supervisory authority or certification body.

    Build the security system Dutch healthcare customers expect to see

    We will assess your existing ISMS, healthcare data flows, Dutch market requirements and certification objective, then define the practical route to NEN 7510 readiness.

    View NEN 7510 pricing