NEN 7510:2024 transition for Dutch healthtech
Asteron helps organisations move an existing NEN 7510 management system to the 2024 edition without rebuilding everything from the beginning. We map the current system to the revised requirements, update the affected risks, controls and evidence, and prepare the organisation for its independent transition assessment. The service is designed for healthcare organisations and technology suppliers that already work with NEN 7510 and need a controlled route to the current version.
- Current system mapped to NEN 7510:2024
- Existing ISO 27001 controls reused where valid
- Evidence and healthcare-specific gaps updated
- Independent transition audit prepared
Transition deadline for existing NEN 7510 certificates: 20 February 2027
NEN 7510:2024 Transition from €6,900
What is the NEN 7510:2024 transition?
NEN 7510 is the Dutch information-security standard for healthcare organisations and other organisations that process personal health information. It applies the principles of information-security management to the specific risks, availability needs and data-sharing relationships found in healthcare.
NEN 7510:2024 is the current edition. It was published on 16 December 2024 and is aligned with the current versions of ISO/IEC 27001 and ISO/IEC 27002, together with healthcare-specific guidance derived from ISO 27799.
Organisations already certified against the previous NEN 7510 edition must transition their certificates by 20 February 2027. The transition is not simply a document-renaming exercise: the organisation must determine what changed, update the affected parts of its management system and demonstrate that the revised requirements operate in practice.
A transition preserves valid parts of the existing system while updating the scope, controls, evidence and operating practices affected by NEN 7510:2024.
Who needs to transition?
The transition service is intended for organisations that already have a functioning NEN 7510 management system or an existing NEN 7510 certificate.
Dutch healthcare providers
Hospitals, clinics, care providers and other healthcare organisations that maintain an existing NEN 7510 system must assess how the 2024 edition affects their management system and certification position.
Healthtech and software suppliers
Software companies, integration providers and other suppliers may need NEN 7510 because they process personal health information, connect to Dutch healthcare systems or face NEN 7510 requirements in tenders and customer contracts.
European companies entering the Netherlands
A German or other European healthtech company may already operate an ISO 27001-based core but still need a Dutch NEN 7510 extension when entering the Netherlands. The transition service is relevant only where an existing NEN 7510 system already exists.
Organisations with combined ISO 27001 and NEN 7510 systems
Where both frameworks share one management system, the transition should preserve the reusable ISO/IEC 27001 foundation while identifying the healthcare-specific NEN 7510 changes.
A company implementing NEN 7510 for the first time needs a new NEN 7510 implementation project, not the €6,900 transition service.
What changed in NEN 7510:2024
The revised standard reflects changes to the international information-security standards on which NEN 7510 is built. Existing policies and controls cannot simply be assumed to remain sufficient because their titles look similar.
The transition must consider whether the company’s scope, risks, control applicability, evidence and healthcare-specific practices still meet the current requirements.
Alignment with current international standards
NEN 7510:2024 is aligned with the current editions of ISO/IEC 27001 and ISO/IEC 27002 and incorporates the healthcare context associated with ISO 27799.
Updated healthcare-security context
The revised edition addresses information-security management in healthcare environments where personal health information is created, exchanged and relied upon by multiple organisations.
NIS2 relationship
NEN 7510:2024 includes a mapping to NIS2 requirements. This can help organisations understand overlap, but NEN 7510 certification must not be presented as automatic or complete compliance with every NIS2 or Cyberbeveiligingswet obligation.
Updated certification scheme
The NCS 7510:2025 conformity-assessment scheme supports certification against the 2024 edition and establishes the formal transition period for existing certificates.
The exact impact depends on the organisation’s previous NEN 7510 baseline, ISO 27001 version, products, data flows and operating maturity. Asteron determines the applicable transition scope before updating the system.
What the transition covers and delivers
Asteron reviews the parts of the existing management system affected by the new edition, retains material that remains current and updates the records and evidence required for transition readiness.
System and mapping
- – Confirmed organisational and certification scope
- – Mapping from the existing system to NEN 7510:2024
- – Updated risk and control baseline
- – Revised Statement of Applicability where required
- – Updated healthcare-specific policies and registers
- – Named internal and Asteron responsibilities
Evidence and assessment readiness
- – Evidence requirements and evidence-status review
- – Personal health-information and supplier dependencies
- – Continuity, incident and availability records
- – Prioritised transition action plan
- – Internal audit and management-review preparation
- – Certification-body coordination and agreed remediation support
The final readiness position distinguishes completed transition work, remaining client actions and issues that require separate remediation or re-baselining. The review prepares the organisation for assessment but is not the independent certification audit itself.
How the transition works
Confirm the current certification position
Asteron reviews the existing NEN 7510 scope, certificate, audit history, ISO 27001 relationship and planned transition date.
We also determine whether the current system is stable enough for direct transition or requires recovery through a separate re-baseline.
Map the existing system to NEN 7510:2024
Current requirements, controls and evidence are mapped to the revised edition. Valid ISO 27001 and NEN 7510 materials are reused, while changed or missing areas are identified explicitly.
The result is a transition plan based on the real system rather than a generic checklist.
Update the affected baseline and evidence
Asteron updates the included scope, risk and control records, policies, responsibilities and evidence requirements. Workshops are used where management or control owners need to make decisions.
Implementation activities assigned to the client are tracked with owners and deadlines.
Prepare for independent assessment
Asteron prepares the internal audit, management review, evidence set and team for the transition assessment. We can help select and coordinate the certification body, manage the audit schedule and support agreed remediation.
The certification decision remains entirely with the independent certification body.
Asteron maps the existing system, updates the agreed transition materials, coordinates evidence and prepares the organisation for assessment.
Your team provides current records, audit history and stakeholder access, approves scope and risk decisions, assigns internal owners and implements actions allocated to the organisation.
Choose the correct route and price
The price depends on the current certification scope, condition of the existing management system, relationship with ISO 27001, number of products and entities, evidence volume and amount of change required.
Prices exclude VAT where applicable. Framework-extension and first-project prices follow the applicable company-size assumptions used on the Pricing page.
External certification audit
Asteron prepares the management system, evidence and team and can coordinate the audit process. The transition assessment and certificate must be handled by an independent accredited certification body.
Asteron cannot act as both implementer and certifier because the certification decision must remain independent. The client contracts and pays the certification body directly; the audit payment never passes through Asteron.
Indicative external certification-audit ranges
- – €4,500–6,000 for organisations with 10–50 employees
- – €6,000–9,000 for organisations with 51–150 employees
These are indicative external costs from the Pricing page. The certification body confirms its own final transition-audit scope, duration and fee.
Frequently asked questions
What is NEN 7510:2024?
NEN 7510:2024 is the current edition of the Dutch information-security standard for healthcare organisations and other organisations processing personal health information.
What is the transition deadline?
Existing NEN 7510 certificates must be transitioned to NEN 7510:2024 by 20 February 2027, according to the official NEN transition information.
Who needs the transition service?
It is intended for organisations with an existing NEN 7510 management system or certificate. New adopters need a first implementation rather than a transition.
Does NEN 7510 apply to software suppliers?
It can apply to suppliers that process personal health information or connect to healthcare systems. NEN 7510 requirements also commonly appear in Dutch healthcare tenders and customer agreements.
Is NEN 7510 relevant outside the Netherlands?
NEN 7510 is a Dutch standard. Companies based elsewhere may need it when processing Dutch health information or selling products and services into the Dutch healthcare market.
Can our existing ISO 27001 system be reused?
Often, yes. NEN 7510 shares an international information-security foundation with ISO/IEC 27001 and ISO/IEC 27002, but healthcare-specific NEN requirements and evidence must still be addressed.
Does NEN 7510 certification automatically prove NIS2 compliance?
No. NEN 7510:2024 includes useful mapping to NIS2, but applicability and compliance with NIS2 and its Dutch implementation must be assessed separately.
What if our current NEN 7510 system is outdated?
A separate re-baseline may be required before or alongside the transition. Re-baseline starts from €3,900 and is agreed explicitly.
Who performs and pays for the transition audit?
Asteron prepares the system and coordinates the process, but the assessment and certification decision belong to an independent accredited certification body. The client contracts and pays that body directly; its fees are not included in Asteron’s project price.
What happens after the transition?
The updated system can move into Core Onboarding and Compliance Operations so that evidence, reviews, surveillance preparation and regulatory-change actions remain current.
Official references
- – NEN — NEN 7510 information security in healthcare
- – NEN — NEN 7510:2024 and NCS 7510:2025 transition information
- – ISO — ISO/IEC 27001 information security management systems
- – Dutch government — NIS2 and Cyberbeveiligingswet
Last reviewed: July 2026
Asteron is not endorsed by or partnered with NEN, ISO, the Dutch government or any certification body.
Related services and frameworks
Complete the transition before the certification deadline
Share the current certificate, audit history and management-system scope. Asteron will determine whether the organisation is ready for direct transition or needs targeted re-baselining first.
