When does NEN 7510 apply to your organisation?
The IGJ explains the obligation for healthcare providers, including small providers. For youth care, the inspectorate refers to ISO 27001. First assess the nature of your services and the information systems used.
An IT supplier in healthcare may also face contractual requirements. Record which health information you manage, which responsibilities apply and exactly what the customer expects. A NEN 7510 certificate does not replace a separate assessment of GDPR obligations.
Which version of the standard should you use?
Use NEN 7510-1:2024 for the management system and the current publication for controls. NEN now publishes part 2 as NEN 7510-2:2024+A1:2026. If you already hold a certificate, also check the certification body’s transition arrangements and the NEN certification scheme.
Read the explanation of NEN 7510:2024, implementation and the current amendment to include the transition in your work plan.
NEN 7510 implementation checklist
- Define the scope: describe healthcare processes, electronic patient/client records (EPD/ECD), locations, data exchange and suppliers.
- Discuss risks: examine the availability, integrity and confidentiality of information; involve frontline care staff and management.
- Record decisions: appoint owners, create a treatment plan and justify which controls apply.
- Put arrangements into practice: establish appropriate access controls, supplier arrangements, incident handling and continuity measures.
- Check effectiveness: gather evidence from practice, carry out internal audits and have management decide on improvements.
- Arrange independent assessment: agree expertise, independence, scope and follow-up. Choose certification if it fits your objective.
Documents and audit preparation
Create a coherent evidence file covering scope, policy, risk analysis, treatment plan, applicable controls, responsibilities, supplier arrangements and improvement actions. Also prepare the internal audit and management review.
Use actual operational records: an access rights review, a recovery test, incident follow-up or a supplier check. Have employees explain how they put arrangements into practice. Audit preparation should therefore go beyond completing templates.
Agree with the assessor which processes, employees and evidence need to be available. An internal audit or readiness assessment can reveal missing evidence. Your organisation remains responsible, even when suppliers are certified.
What does DCA do and what does your team do?
With the Compliance Tool you bring requirements, risks, tasks, documents and evidence together. Through implementation support DCA helps with the gap analysis, plan, adaptation of documents and preparation for assessment. The agreed division of responsibilities determines how much implementation we take on.
- Your management: defines the scope, allocates time and decides on risks and priorities.
- Your team: provides process knowledge, implements agreed controls and gathers evidence from day-to-day practice.
- DCA: helps structure, develop and follow up the work. An internal audit is assigned an independent assessor who does not approve their own work.
- Certification body: conducts the external assessment independently as part of a certification process and makes the certification decision.
The support results in an established management system with owners, decisions and evidence. Certification depends on independent assessment; software or support alone is not a certificate.
Costs, internal time and planning
Distinguish between software, support, internal time, any technical measures and the independent external audit. Implementation support starts at 4 hours per week at €120 per hour: an average of €2,080 per month, excluding VAT. The software licence and external certification costs are separate. View current prices and calculate the division of work.
There is no fixed number of internal hours or guaranteed lead time. Allocate time for the project owner, management, IT, HR and relevant process owners. Scope, existing controls, missing evidence and auditor availability determine the schedule. Turn the initial discussion into a work plan with tasks, owners and review points.
Frequently asked questions about NEN 7510
Does every healthcare provider need a NEN 7510 certificate?+
No. The Dutch Health and Youth Care Inspectorate (IGJ) distinguishes between demonstrably working to the standard and certification. Have contractual requirements assessed separately too.
Is ISO 27001 sufficient for healthcare?+
ISO 27001 and NEN 7510 overlap, but an ISO 27001 certificate does not automatically demonstrate compliance with all healthcare-specific requirements. Assess the differences in scope, controls and evidence.
Can a small healthcare organisation start without doing everything at once?+
Start with the scope and the main information security risks. Record priorities, owners and next steps, then develop the management cycle further. Size alone does not remove the obligation.
Official sources
Sources consulted on 19 September 2026. Use the current standard or scheme requirements for implementation.
