NEN 7510 is the Dutch standard for information security in healthcare. The standard helps you to systematically protect patient data and healthcare information. From data leaks to unauthorized access, from ransomware to human errors.
In this guide you can read everything you need to know: from the legal obligation to the costs, from preparation to choosing a certifier. Practical information for healthcare providers who want to get their information security in order.
1. What is NEN 7510?
NEN 7510 is the Dutch standard for information security specifically for the healthcare sector. The standard describes requirements for an Information Security Management System (ISMS) with additional measures relevant to the processing of health information.
In short: NEN 7510 helps you to systematically protect patient data and healthcare information against loss, theft and unauthorized access.
1.1 The standard in two parts
NEN 7510 consists of two parts:
| Part | Contents | Type |
|---|---|---|
| NEN 7510-1 | Requirements for the ISMS | Normative (this is being audited) |
| NEN 7510-2 | Practice guidelines and explanation | Informative (resource) |
1.2 Current version: NEN 7510:2024
The current version is NEN 7510:2024, published in December 2024. This replaces the 2017 version. Main changes: better alignment with ISO 27001:2022, new controls for cloud computing and cyber threats, and alignment with NIS2 requirements.
Transition deadline: February 20, 2027. Existing certificate holders must be certified against the new version before that date.
1.3 Relationship with ISO 27001
NEN 7510 is based on ISO 27001, the international standard for information security. Both standards share the same structure and PDCA cycle (Plan-Do-Check-Act). The difference is in the scope and additional requirements.
| Aspect | ISO 27001 | NEN 7510 |
|---|---|---|
| Scope | All sectors worldwide | Dutch healthcare sector |
| Controls | 93 controls | 93 + healthcare-specific additions |
| Focus | General information security | Patient data, medical equipment |
| Recognition | International | Netherlands |
Practical: Do you already have ISO 27001? Then you can add NEN 7510 relatively easily. The certification audit can be combined.
1.4 NEN 7512 and NEN 7513
In addition to NEN 7510, there are two additional standards:
| Standard | Subject | Certifiable |
|---|---|---|
| NEN 7512 | Secure data exchange between healthcare providers | No |
| NEN 7513 | Logging of access to patient files | No |
NEN 7512 and NEN 7513 expand on NEN 7510. They are not separately certifiable, but are tested as part of the NEN 7510 audit. Both standards are available free of charge (purchased by VWS).
2. Why NEN 7510 certification?
Working in accordance with NEN 7510 is legally required. Certification is not. Yet more and more healthcare organisations are opting for a certificate. The question is: does it help your organisation?
2.1 The legal obligation
The law requires that you work according to the standard. The law does not require you to be certified. But how else do you demonstrate that you comply?
2.2 Four reasons to certify
1. Demonstrable compliance
A certificate is the most concrete way to show the IGJ, health insurers and chain partners that your information security is in order. No discussion, no interpretation.
2. Requirement from chain partners
Health insurers are increasingly asking for NEN 7510 certification when contracting. Partnerships and referrers can also demand it.
3. Structure and improvement
The certification process forces you to take a structural approach to information security. Not a one-time action, but a continuous cycle of improvement.
4. Trust
Patients and partners trust that their data is safe. A certificate supports that trust.
2.3 For whom is NEN 7510 relevant?
This includes:
- Hospitals and clinics
- General practices
- Mental health institutions
- Nursing and care homes
- Home care organisations
- Physiotherapists and paramedics
- Dental practices
- Pharmacies
- Laboratories
Secondary target group: suppliers to healthcare
- ICT service providers to healthcare institutions
- Software suppliers for healthcare (EPD, HIS)
- Hosting providers for healthcare data
- Suppliers of medical equipment
2.4 When certification may not be necessary
Honest advice: Certification is not the best first step for everyone.
Small practices (sole proprietorships, duo practices) can start with a self-assessment and internal audits. The standard requires working in accordance with NEN 7510, not certification. You can demonstrate compliance through documented internal controls.
Organisations without external pressure that do not require a certificate for contracts or tenders can consider first getting things in order internally and certifying later.
3. The NEN 7510 certification process
You go through six steps from decision to certificate. Count on two to eighteen months, depending on your organisation size and starting position.
3.1 The six steps to certification
Determine scope - Which locations, systems and processes are covered by the ISMS? In most healthcare organisations this is the entire organisation.
Perform Risk Assessment - Identify risks to patient data and healthcare information. What threats are there? What are the consequences? This is the heart of NEN 7510.
Set up ISMS - Implement controls, establish policies, train employees, document processes.
Complete proof period - Work under your ISMS for a minimum of three months. Auditors want proof that the system works in practice.
Internal audit and management review - Check yourself whether everything is working and have management formally assess the ISMS.
External audit - The certifier carries out the audit in two phases. If successful you will receive the certificate.
3.2 Timeline per organisation type
| Organisation type | Lead time | Audit duration |
|---|---|---|
| Small practice (well prepared) | 2-4 months | 1-2 days |
| Small practice (from scratch) | 4-6 months | 1-2 days |
| Medium-sized healthcare institution | 6-12 months | 2-3 days |
| Large hospital | 12-18 months | 4-5 days |
3.3 Who does what?
| Party | Role |
|---|---|
| You / information security | Risk analysis, setting up ISMS, internal audits |
| IT department | Technical measures, logging, monitoring |
| Data Protection Officer | GDPR alignment, privacy aspects |
| Consultant (optional) | Guidance, gap analysis, templates |
| Certifier | Perform audit, issue certificate |
Good to know: A consultant is not mandatory. Organisations with experienced IT and compliance people regularly do it themselves.
4. What does NEN 7510 cost?
Costs vary widely by organisation size. A small general practice pays much less than a large hospital.
Rule of thumb: Small practice €5,000-€8,000 first year, medium-sized institution €8,000-€15,000 first year.
4.1 Cost items overview
| Cost item | Indication |
|---|---|
| Preparation and gap analysis | €1,000 - €3,000 |
| Certification audit (year 1) | €3,000 - €10,000 |
| Surveillance audit (per year) | €2,000 - €4,000 |
| Recertification (every three years) | €3,000 - €8,000 |
| Consultant (optional) | €5,000 - €20,000 |
4.2 Price indication per organisation size
| Organisation type | First year | Annually thereafter |
|---|---|---|
| Small practice (GP, physiotherapist) | €5,000 - €8,000 | €2,000 - €3,000 |
| Medium-sized healthcare institution | €8,000 - €15,000 | €3,000 - €5,000 |
| Large hospital/GGZ | €15,000 - €35,000+ | €5,000 - €10,000+ |
Prices indicative, excl. VAT, excl. consultant and internal hours.
4.3 What influences the price?
Five factors determine your costs:
- Number of employees (more = more audit time)
- Number of locations (each location is assessed)
- Complexity of IT environment (EPD, connections, medical equipment)
- Current Maturity (from scratch is more expensive)
- Certifier’s choice (prices vary 20-40%)
5. Preparation for NEN 7510
Good preparation is half the battle. Most of the time is spent on the risk analysis and setting up your ISMS, not on the audit itself.
5.1 What do you need to arrange internally?
Then follow these steps:
- Appoint project leader - Someone with a mandate who takes the lead
- Determine scope - Which systems, locations, processes?
- Perform risk analysis - Focus on patient data and healthcare systems
- Implement measures - Technically and organizationally
- Employee training - Awareness about information security
- Start proof period - Work for at least three months according to ISMS
- Perform internal audit - Test whether everything works
5.2 What documentation is needed?
| Document | What it is |
|---|---|
| Information Security Policy | Your vision and objectives |
| Scope of the ISMS | Which parts of your organisation |
| Risk analysis and treatment plan | Identified risks and chosen measures |
| Statement of Applicability | Which controls you apply and which you do not |
| Process descriptions | Incident management, access management, etc. |
| Registrations | Evidence of compliance (audits, incidents, training) |
Care-specific documentation:
- Policy for access to patient records
- Logging policy (in accordance with NEN 7513)
- Data exchange policy (in accordance with NEN 7512)
- Agreements with processors and subcontractors
5.3 Three common mistakes
Mistake 2: Paper tiger
Your documents must correspond with the practice. If you write down that you will check access logs weekly, you should do so. Auditors ask for evidence.
Mistake 3: Starting the proof period too late
You must have worked under your ISMS for at least three months before the external audit. Plan this.
Read also: How do you prepare for a certification audit? - Practical tips that also apply to NEN 7510.
6. The NEN 7510 audit
The external audit is the moment of truth. If you are well prepared, there is little to worry about.
6.1 Phases one and two
The audit consists of two parts:
Phase 1: Documentation and readiness check (often partly remote)
The auditor assesses your ISMS documentation: policy, risk analysis, Statement of Applicability. Is everything there? Are you ready for the on-site audit?
Phase 2: On-site audit (on location)
The auditor visits, speaks to employees, examines systems and processes, checks logging and registrations. It revolves around the question: does paper correspond to practice?
The gist: The auditor is looking for evidence that your ISMS is effective. Not just that procedures exist, but that they work.
6.2 Possible outcomes
| Outcome | What’s happening? |
|---|---|
| Certificate | You meet the requirements |
| Minor deviations | Certificate, but resolve points for next audit |
| Major deviations | Fix first, then reaudit within 90 days |
| Requirements not met | Restart the process |
6.3 Tips for a smooth audit
- Know your own system - Know where documents are located and how processes work
- Prepare employees - They do not need to know the standard, but they do need to know their own tasks
- Be Honest - Auditors value openness more than perfection
- Have proof ready - Logs, registrations, training records
- Focus on patient data - That is the emphasis in the healthcare industry
7. Choosing a NEN 7510 certifier
Not every certifier is allowed to certify NEN 7510. You must choose from accredited parties with specific recognition for this standard.
7.1 Accredited certifiers for NEN 7510
The following certification bodies are accredited for NEN 7510 in the Netherlands:
- Brand Compliance B.V.
- BSI Group Nederland B.V.
- DEKRA Certification B.V.
- DNV Business Assurance B.V.
- Kiwa Nederland B.V.
- LRQA Nederland B.V.
- Noordbeek Certification B.V.
- TÜV NORD
7.2 Five criteria to pay attention to
| Criterion | Why important |
|---|---|
| Accreditation for NEN 7510 | Otherwise the certificate is not valid |
| Experience in healthcare | An auditor who knows the healthcare sector adds more value |
| Price | Differences of 20-40% are normal |
| Service | Permanent contact person? Quick responses? |
| Working relationship with the auditor | You will work together for at least three years |
7.3 Questions to ask
Before you choose, ask these questions:
- Are you accredited for NEN 7510? (check with the RvA)
- What is your experience with my type of healthcare organisation?
- Does the auditor have experience with our systems (EPD, HIS)?
- What are the total costs for three years?
- How do you deal with the transition to NEN 7510:2024?
The right choice is not necessarily the cheapest. An auditor who understands the healthcare sector and provides constructive feedback is worth more than a few hundred euros in savings.
Read also: How do you choose the right certifier? 5 practical tips - General criteria that also apply to NEN 7510.
Ready to compare? View our overview of certification bodies and find one that fits your healthcare organisation.
8. Frequently asked questions about NEN 7510
Is NEN 7510 mandatory?
Working in accordance with NEN 7510 is legally required for all healthcare providers (Electronic Data Processing Decree). Certification itself is not mandatory, but it is the most common way to demonstrate compliance.
What does NEN 7510 certification cost?
Small practice (GP, physiotherapist): €5,000-€8,000 first year, then €2,000-€3,000 per year. Medium-sized healthcare institution: €8,000-€15,000 first year. The exact price depends on organisation size and complexity.
How long does certification take?
Small practice: two to six months. Medium institution: six to twelve months. Large hospital: twelve to eighteen months. The audit itself takes one to five days.
What is the difference with ISO 27001?
NEN 7510 is based on ISO 27001 but contains healthcare-specific additions: protection of patient data, medical equipment, and references to NEN 7512 (data exchange) and NEN 7513 (logging). ISO 27001 is international, NEN 7510 is Dutch and healthcare-specific.
Can I combine both standards?
Yes. ISO 27001 and NEN 7510 share the same structure. The audit can be combined. This is efficient for organisations that want both international recognition and healthcare-specific compliance, such as IT suppliers to healthcare.
What are NEN 7512 and NEN 7513?
NEN 7512 describes requirements for secure data exchange between healthcare providers. NEN 7513 concerns logging of access to patient files. Both expand on NEN 7510 and are tested as part of the NEN 7510 audit.
What changes in NEN 7510:2024?
The new version is better aligned with ISO 27001:2022 and NIS2. There are new controls for cloud computing and cyber threats. Existing certificate holders must switch before February 20, 2027.
How often is an audit after certification?
A surveillance audit every year. Full recertification every three years. Your certificate is valid for three years, provided you successfully complete the annual audits.
Can I switch certifiers?
Yes, anytime. Your new certifier will take over your file and plan a transfer audit. Your certificate remains valid during the transfer.
Does NEN 7510 help with the GDPR?
Yes. NEN 7510 demonstrably helps to meet the GDPR requirement of “appropriate technical and organizational measures”. It does not guarantee full GDPR compliance, but covers a large part of the security requirements for patient data.
This guide is updated regularly. Last checked: December 2025.
