NEN 7510 certification for healthcare information security

NEN 7510 certification for healthcare information security

A practical guide to NEN 7510 certification for Dutch healthcare providers and their suppliers.

Last updated: 7 September 2026 | 12 min. read

NEN 7510 is the Dutch standard for information security in healthcare. The standard helps you to systematically protect patient data and healthcare information. From data leaks to unauthorized access, from ransomware to human errors.

In this guide you can read everything you need to know: from the legal obligation to the costs, from preparation to choosing a certifier. Practical information for healthcare providers who want to get their information security in order.


1. What is NEN 7510?

NEN 7510 is the Dutch standard for information security specifically for the healthcare sector. The standard describes requirements for an Information Security Management System (ISMS) with additional measures relevant to the processing of health information.

In short: NEN 7510 helps you to systematically protect patient data and healthcare information against loss, theft and unauthorized access.

1.1 The standard in two parts

NEN 7510 consists of two parts:

PartContentsType
NEN 7510-1Requirements for the ISMSNormative (this is being audited)
NEN 7510-2Practice guidelines and explanationInformative (resource)

1.2 Current version: NEN 7510:2024

info

The current version is NEN 7510:2024, published in December 2024. This replaces the 2017 version. Main changes: better alignment with ISO 27001:2022, new controls for cloud computing and cyber threats, and alignment with NIS2 requirements.

Transition deadline: February 20, 2027. Existing certificate holders must be certified against the new version before that date.

1.3 Relationship with ISO 27001

NEN 7510 is based on ISO 27001, the international standard for information security. Both standards share the same structure and PDCA cycle (Plan-Do-Check-Act). The difference is in the scope and additional requirements.

AspectISO 27001NEN 7510
ScopeAll sectors worldwideDutch healthcare sector
Controls93 controls93 + healthcare-specific additions
FocusGeneral information securityPatient data, medical equipment
RecognitionInternationalNetherlands

Practical: Do you already have ISO 27001? Then you can add NEN 7510 relatively easily. The certification audit can be combined.

1.4 NEN 7512 and NEN 7513

In addition to NEN 7510, there are two additional standards:

StandardSubjectCertifiable
NEN 7512Secure data exchange between healthcare providersNo
NEN 7513Logging of access to patient filesNo

NEN 7512 and NEN 7513 expand on NEN 7510. They are not separately certifiable, but are tested as part of the NEN 7510 audit. Both standards are available free of charge (purchased by VWS).


2. Why NEN 7510 certification?

Working in accordance with NEN 7510 is legally required. Certification is not. Yet more and more healthcare organisations are opting for a certificate. The question is: does it help your organisation?

warning
Important: The Electronic Data Processing by Healthcare Providers Decree (effective since December 15, 2018) obliges all healthcare providers to demonstrably work in accordance with NEN 7510. This applies to any organisation that provides care and processes patient data electronically.

The law requires that you work according to the standard. The law does not require you to be certified. But how else do you demonstrate that you comply?

2.2 Four reasons to certify

1. Demonstrable compliance

A certificate is the most concrete way to show the IGJ, health insurers and chain partners that your information security is in order. No discussion, no interpretation.

2. Requirement from chain partners

Health insurers are increasingly asking for NEN 7510 certification when contracting. Partnerships and referrers can also demand it.

3. Structure and improvement

The certification process forces you to take a structural approach to information security. Not a one-time action, but a continuous cycle of improvement.

4. Trust

Patients and partners trust that their data is safe. A certificate supports that trust.

2.3 For whom is NEN 7510 relevant?

note
Primary target group: all healthcare providers that process patient data electronically.

This includes:

  • Hospitals and clinics
  • General practices
  • Mental health institutions
  • Nursing and care homes
  • Home care organisations
  • Physiotherapists and paramedics
  • Dental practices
  • Pharmacies
  • Laboratories

Secondary target group: suppliers to healthcare

  • ICT service providers to healthcare institutions
  • Software suppliers for healthcare (EPD, HIS)
  • Hosting providers for healthcare data
  • Suppliers of medical equipment

2.4 When certification may not be necessary

Honest advice: Certification is not the best first step for everyone.

Small practices (sole proprietorships, duo practices) can start with a self-assessment and internal audits. The standard requires working in accordance with NEN 7510, not certification. You can demonstrate compliance through documented internal controls.

Organisations without external pressure that do not require a certificate for contracts or tenders can consider first getting things in order internally and certifying later.


3. The NEN 7510 certification process

You go through six steps from decision to certificate. Count on two to eighteen months, depending on your organisation size and starting position.

3.1 The six steps to certification

  1. Determine scope - Which locations, systems and processes are covered by the ISMS? In most healthcare organisations this is the entire organisation.

  2. Perform Risk Assessment - Identify risks to patient data and healthcare information. What threats are there? What are the consequences? This is the heart of NEN 7510.

  3. Set up ISMS - Implement controls, establish policies, train employees, document processes.

  4. Complete proof period - Work under your ISMS for a minimum of three months. Auditors want proof that the system works in practice.

  5. Internal audit and management review - Check yourself whether everything is working and have management formally assess the ISMS.

  6. External audit - The certifier carries out the audit in two phases. If successful you will receive the certificate.

3.2 Timeline per organisation type

Organisation typeLead timeAudit duration
Small practice (well prepared)2-4 months1-2 days
Small practice (from scratch)4-6 months1-2 days
Medium-sized healthcare institution6-12 months2-3 days
Large hospital12-18 months4-5 days

3.3 Who does what?

PartyRole
You / information securityRisk analysis, setting up ISMS, internal audits
IT departmentTechnical measures, logging, monitoring
Data Protection OfficerGDPR alignment, privacy aspects
Consultant (optional)Guidance, gap analysis, templates
CertifierPerform audit, issue certificate

Good to know: A consultant is not mandatory. Organisations with experienced IT and compliance people regularly do it themselves.


4. What does NEN 7510 cost?

Costs vary widely by organisation size. A small general practice pays much less than a large hospital.

Rule of thumb: Small practice €5,000-€8,000 first year, medium-sized institution €8,000-€15,000 first year.

4.1 Cost items overview

Cost itemIndication
Preparation and gap analysis€1,000 - €3,000
Certification audit (year 1)€3,000 - €10,000
Surveillance audit (per year)€2,000 - €4,000
Recertification (every three years)€3,000 - €8,000
Consultant (optional)€5,000 - €20,000

4.2 Price indication per organisation size

Organisation typeFirst yearAnnually thereafter
Small practice (GP, physiotherapist)€5,000 - €8,000€2,000 - €3,000
Medium-sized healthcare institution€8,000 - €15,000€3,000 - €5,000
Large hospital/GGZ€15,000 - €35,000+€5,000 - €10,000+

Prices indicative, excl. VAT, excl. consultant and internal hours.

4.3 What influences the price?

Five factors determine your costs:

  1. Number of employees (more = more audit time)
  2. Number of locations (each location is assessed)
  3. Complexity of IT environment (EPD, connections, medical equipment)
  4. Current Maturity (from scratch is more expensive)
  5. Certifier’s choice (prices vary 20-40%)
tip
Save by comparing. Always request quotes from at least three certifiers. All accredited certifiers provide a valid certificate. In addition to price, also pay attention to healthcare experience.

5. Preparation for NEN 7510

Good preparation is half the battle. Most of the time is spent on the risk analysis and setting up your ISMS, not on the audit itself.

5.1 What do you need to arrange internally?

note
First step: Ensure commitment from management or practice owner. Information security is a management responsibility. Without support from above, certification becomes difficult.

Then follow these steps:

  • Appoint project leader - Someone with a mandate who takes the lead
  • Determine scope - Which systems, locations, processes?
  • Perform risk analysis - Focus on patient data and healthcare systems
  • Implement measures - Technically and organizationally
  • Employee training - Awareness about information security
  • Start proof period - Work for at least three months according to ISMS
  • Perform internal audit - Test whether everything works

5.2 What documentation is needed?

DocumentWhat it is
Information Security PolicyYour vision and objectives
Scope of the ISMSWhich parts of your organisation
Risk analysis and treatment planIdentified risks and chosen measures
Statement of ApplicabilityWhich controls you apply and which you do not
Process descriptionsIncident management, access management, etc.
RegistrationsEvidence of compliance (audits, incidents, training)

Care-specific documentation:

  • Policy for access to patient records
  • Logging policy (in accordance with NEN 7513)
  • Data exchange policy (in accordance with NEN 7512)
  • Agreements with processors and subcontractors

5.3 Three common mistakes

warning
Mistake 1: Focusing only on IT. NEN 7510 is also about organizational and human measures. Consider policy, awareness, physical access and supplier management.

Mistake 2: Paper tiger

Your documents must correspond with the practice. If you write down that you will check access logs weekly, you should do so. Auditors ask for evidence.

Mistake 3: Starting the proof period too late

You must have worked under your ISMS for at least three months before the external audit. Plan this.

Read also: How do you prepare for a certification audit? - Practical tips that also apply to NEN 7510.


6. The NEN 7510 audit

The external audit is the moment of truth. If you are well prepared, there is little to worry about.

6.1 Phases one and two

The audit consists of two parts:

Phase 1: Documentation and readiness check (often partly remote)

The auditor assesses your ISMS documentation: policy, risk analysis, Statement of Applicability. Is everything there? Are you ready for the on-site audit?

Phase 2: On-site audit (on location)

The auditor visits, speaks to employees, examines systems and processes, checks logging and registrations. It revolves around the question: does paper correspond to practice?

The gist: The auditor is looking for evidence that your ISMS is effective. Not just that procedures exist, but that they work.

6.2 Possible outcomes

OutcomeWhat’s happening?
CertificateYou meet the requirements
Minor deviationsCertificate, but resolve points for next audit
Major deviationsFix first, then reaudit within 90 days
Requirements not metRestart the process
info
Most well-prepared organisations obtain the certificate in one go. Small deviations are common and indicate areas for improvement.

6.3 Tips for a smooth audit

  1. Know your own system - Know where documents are located and how processes work
  2. Prepare employees - They do not need to know the standard, but they do need to know their own tasks
  3. Be Honest - Auditors value openness more than perfection
  4. Have proof ready - Logs, registrations, training records
  5. Focus on patient data - That is the emphasis in the healthcare industry

7. Choosing a NEN 7510 certifier

Not every certifier is allowed to certify NEN 7510. You must choose from accredited parties with specific recognition for this standard.

7.1 Accredited certifiers for NEN 7510

The following certification bodies are accredited for NEN 7510 in the Netherlands:

  • Brand Compliance B.V.
  • BSI Group Nederland B.V.
  • DEKRA Certification B.V.
  • DNV Business Assurance B.V.
  • Kiwa Nederland B.V.
  • LRQA Nederland B.V.
  • Noordbeek Certification B.V.
  • TÜV NORD
warning
Note accreditation. Always choose a certifier that is accredited for NEN 7510. Non-accredited certificates are not recognised by regulators and health insurers.

7.2 Five criteria to pay attention to

CriterionWhy important
Accreditation for NEN 7510Otherwise the certificate is not valid
Experience in healthcareAn auditor who knows the healthcare sector adds more value
PriceDifferences of 20-40% are normal
ServicePermanent contact person? Quick responses?
Working relationship with the auditorYou will work together for at least three years

7.3 Questions to ask

Before you choose, ask these questions:

  • Are you accredited for NEN 7510? (check with the RvA)
  • What is your experience with my type of healthcare organisation?
  • Does the auditor have experience with our systems (EPD, HIS)?
  • What are the total costs for three years?
  • How do you deal with the transition to NEN 7510:2024?

The right choice is not necessarily the cheapest. An auditor who understands the healthcare sector and provides constructive feedback is worth more than a few hundred euros in savings.

Read also: How do you choose the right certifier? 5 practical tips - General criteria that also apply to NEN 7510.

note

Ready to compare? View our overview of certification bodies and find one that fits your healthcare organisation.

Compare certification bodies →


8. Frequently asked questions about NEN 7510

Is NEN 7510 mandatory?

Working in accordance with NEN 7510 is legally required for all healthcare providers (Electronic Data Processing Decree). Certification itself is not mandatory, but it is the most common way to demonstrate compliance.

What does NEN 7510 certification cost?

Small practice (GP, physiotherapist): €5,000-€8,000 first year, then €2,000-€3,000 per year. Medium-sized healthcare institution: €8,000-€15,000 first year. The exact price depends on organisation size and complexity.

How long does certification take?

Small practice: two to six months. Medium institution: six to twelve months. Large hospital: twelve to eighteen months. The audit itself takes one to five days.

What is the difference with ISO 27001?

NEN 7510 is based on ISO 27001 but contains healthcare-specific additions: protection of patient data, medical equipment, and references to NEN 7512 (data exchange) and NEN 7513 (logging). ISO 27001 is international, NEN 7510 is Dutch and healthcare-specific.

Can I combine both standards?

Yes. ISO 27001 and NEN 7510 share the same structure. The audit can be combined. This is efficient for organisations that want both international recognition and healthcare-specific compliance, such as IT suppliers to healthcare.

What are NEN 7512 and NEN 7513?

NEN 7512 describes requirements for secure data exchange between healthcare providers. NEN 7513 concerns logging of access to patient files. Both expand on NEN 7510 and are tested as part of the NEN 7510 audit.

What changes in NEN 7510:2024?

The new version is better aligned with ISO 27001:2022 and NIS2. There are new controls for cloud computing and cyber threats. Existing certificate holders must switch before February 20, 2027.

How often is an audit after certification?

A surveillance audit every year. Full recertification every three years. Your certificate is valid for three years, provided you successfully complete the annual audits.

Can I switch certifiers?

Yes, anytime. Your new certifier will take over your file and plan a transfer audit. Your certificate remains valid during the transfer.

Does NEN 7510 help with the GDPR?

Yes. NEN 7510 demonstrably helps to meet the GDPR requirement of “appropriate technical and organizational measures”. It does not guarantee full GDPR compliance, but covers a large part of the security requirements for patient data.


This guide is updated regularly. Last checked: December 2025.

Compare NEN 7510 certification bodies

Find a certification body with healthcare experience.

Request free quotations