Compliance re-baseline for European healthtech
Asteron restores an outdated or unreliable compliance system to a current, defensible baseline. We reassess the scope, risks, controls, evidence and ownership against the company that exists today - not the organisation described in last year's documents. The service is designed for European healthtech companies whose ISO 27001, NEN 7510 or related management system has fallen behind product, organisational or market change.
- Current scope and obligations confirmed
- Risks and controls brought up to date
- Evidence gaps prioritised
- Clear route back to managed operations
Re-baseline from €3,900
What a compliance re-baseline means
A management system can remain formally documented while becoming operationally unreliable. The company may have launched new products, entered new markets, changed infrastructure, added suppliers or reassigned responsibilities without updating the compliance baseline.
A re-baseline reconnects the management system to the current organisation. It confirms what is in scope, which risks and obligations matter, which controls are actually operating and what evidence is available to support them.
This is more than a list of missing documents. The work determines which existing materials remain valid, what needs targeted correction and which parts of the system must be rebuilt before ongoing compliance work can be trusted.
The objective is not to make the documentation look newer. It is to make the compliance system accurately reflect the current business, products, risks and responsibilities.
When re-baselining is the right step
The company has changed materially
New products, cloud services, locations, legal entities, acquisitions or changes in data processing may have made the existing scope and risk assessment inaccurate.
The system has not been maintained
Recurring reviews, evidence updates, internal audits or management activities have been missed, leaving the organisation unsure which controls are still operating effectively.
Ownership or providers have changed
A compliance lead or external provider has left, and important decisions, evidence locations or responsibilities were not transferred clearly.
An audit or customer review exposed deeper problems
Open findings may point to a wider issue with scope, risk ownership, evidence or governance rather than a single missing document. Re-baselining addresses the system behind the finding.
A re-baseline may also be appropriate before expanding from a core ISO 27001 system into NEN 7510, IEC 81001-5-1, ISO 27701, ISO 42001 or another market-specific requirement. The extension itself remains a separate project.
What Asteron reviews
The review follows the actual organisation and the frameworks within the agreed scope. Asteron examines how the business has changed since the previous baseline and whether the management system still addresses its products, health-data flows, customers, suppliers and target markets.
Existing work is retained where it remains accurate and useful. Re-baselining should correct the system selectively rather than recreate every document by default.
The exact review depth depends on the condition of the existing system. The agreed proposal defines which frameworks, entities, products and records are included.
Scope and obligations
- – Legal entities, teams, products and locations
- – Health-data processing and important data flows
- – Customer, contractual and market requirements
- – Applicable frameworks and certification boundaries
Risk and controls
- – Risk methodology and current risk register
- – Control selection and applicability
- – Product, supplier and cloud dependencies
- – Ownership, acceptance and treatment decisions
Operation and evidence
- – Policies, procedures and registers
- – Evidence status and recurring review records
- – Previous audit findings and open actions
- – Internal audit and management-review position
- – Compliance calendar and reporting cadence
How the re-baseline works
Establish what changed
Asteron reviews the previous scope and baseline together with material changes to the company, products, technology, suppliers, data processing and target markets.
The first objective is to understand why the existing system no longer provides a reliable operational picture.
Test the current baseline
We review the risk and control records, policies, ownership, evidence, audit history and recurring activities included in scope. Existing materials are classified as current, requiring correction or no longer applicable.
This is not an external certification audit. It is a practical review intended to restore the system before ongoing operations or independent assessment.
Correct the material foundations
Asteron updates the agreed foundational elements, such as scope, risk records, control applicability, responsibilities and the compliance calendar. Material evidence gaps and overdue actions are documented and prioritised.
The client remains responsible for business decisions, risk acceptance and implementation assigned to its internal teams.
Return the system to operation
The accepted baseline, remaining actions and recurring activities are prepared for Core Onboarding or direct continuation into Compliance Operations.
The handover distinguishes completed re-baseline work from actions that require further implementation, technical remediation or an external audit.
What the service delivers
A re-baseline should leave management with a defensible current position and the operating team with clear next actions. Standard outputs may include:
- – Confirmed organisational and product scope
- – Updated compliance and certification boundaries
- – Current obligations and framework coverage
- – Updated risk and control baseline
- – Validated or revised ownership
- – Evidence status by material control area
- – Review of previous findings and open actions
- – Prioritised remediation and implementation plan
- – Updated annual compliance calendar
- – Clear readiness decision for ongoing operations or audit preparation
The final output records what has been corrected, what remains open, who owns each material action and whether the system is ready to move into routine operation.
Re-baseline, Core Onboarding or new implementation?
Core Onboarding is included with annual Compliance Operations or an eligible framework extension. Re-baselining is separate because its scope depends on how far the existing system has drifted from the organisation.
Re-baselining for European healthtech markets
Netherlands
For companies operating in the Dutch healthcare market, the re-baseline can account for an existing NEN 7510:2024 or ISO 27001 system, personal health-information processing, Dutch healthcare customers and the organisation's relevant Cyberbeveiligingswet or NIS2-related work.
A general re-baseline does not automatically include the full NEN 7510:2024 Transition service. Where a formal version transition is required, scope it separately from €6,900.
Germany and wider Europe
For German and wider European healthtech companies, the baseline may need to reflect ISO 27001, GDPR, medical-software security, hospital customer requirements, DiGA-related activities or other obligations included in the agreed scope.
Re-baselining organises these obligations within one current management system. It does not imply that a generic ISO 27001 baseline automatically satisfies every German, Dutch or EU market requirement.
Asteron's focus on European healthtech keeps the review grounded in health data, regulated software, hospital procurement and cross-border market expansion rather than generic corporate compliance.
Re-baseline from €3,900
The price depends on the number of frameworks, legal entities and products in scope, the condition of the existing records, evidence volume, audit history and the extent of organisational or technical change.
The proposal defines which foundational records Asteron will update and which implementation or remediation activities remain separate.
Compliance Operations has a 12-month minimum term. Prices exclude VAT where applicable.
What remains separate
Re-baselining corrects the management-system foundation. It does not automatically include every project revealed by the review.
Unless explicitly included, the following remain separate:
- – New framework implementation or certification project
- – NEN 7510:2024 Transition
- – Technical remediation by engineering or infrastructure teams
- – Penetration testing or vulnerability management
- – Legal advice and formal regulatory interpretation
- – vCISO leadership and executive decision ownership
- – External certification or surveillance audits
Certification and surveillance audits are performed by an independent accredited certification body. Asteron can prepare the system and coordinate the audit process but cannot issue the certificate or act as both implementer and certifier. External audit fees are contracted and paid directly to the certification body.
Shared responsibilities
Asteron
Asteron reviews the agreed baseline, identifies material drift, updates the included foundational records and documents remaining actions, ownership and readiness.
Your team
The client provides existing records, audit reports, evidence access and relevant stakeholders. Management confirms scope, approves risk decisions, assigns internal owners and remains responsible for implementation performed by the company.
Frequently asked questions
What is a compliance re-baseline?
It is a structured review and correction of an existing management system whose scope, risks, controls, evidence or responsibilities no longer reflect the current organisation.
Is re-baselining the same as a gap assessment?
No. A gap assessment primarily identifies differences. Re-baselining also updates the agreed foundational elements and prepares the system to return to ongoing operation.
How do we know whether we need Core Onboarding or a re-baseline?
Core Onboarding is suitable when the existing system is substantially current and transferable. Re-baselining is needed when material parts of the baseline are outdated, incomplete or unreliable.
Can you re-baseline an ISO 27001 system?
Yes. The review can cover an existing ISO/IEC 27001 management system, including its scope, risk treatment, control applicability, evidence and operating activities.
Can the service cover NEN 7510?
Yes, when NEN 7510 is included in the agreed scope. A formal NEN 7510:2024 version transition may require the separate transition service.
Is re-baselining relevant after major product or architecture changes?
Yes. New products, cloud services, integrations, data flows and market expansion can change the scope and risk profile even when the original documents remain unchanged.
Will Asteron rewrite every policy?
Not automatically. Existing material is retained where it remains accurate. The service focuses on material corrections rather than unnecessary document replacement.
Does the price include remediation?
Only the re-baseline activities stated in the proposal are included. Technical, legal and broader framework implementation work remains separate unless explicitly scoped.
Does Asteron perform the certification audit?
No. Certification must be performed independently by an accredited certification body, which is contracted and paid directly by the client.
What happens after the re-baseline?
The restored baseline can move into Core Onboarding and Compliance Operations, audit preparation or a separately scoped framework extension, depending on the remaining actions.
Official references
- - ISO — ISO/IEC 27001 information security management systems
- - NEN — NEN 7510 information security in healthcare
Last reviewed: July 2026
Related services and frameworks
Restore the system before the next audit or customer review
Share the existing framework scope, audit history and major business changes. Asteron will determine whether the system needs Core Onboarding, a targeted re-baseline or a broader implementation project.
