NEN 7510 and healthcare

NEN 7510:2024: applicability, checklist and audit preparation

From a healthcare-specific scope to an effective management system and verifiable evidence.

The move to NEN 7510:2024 is an opportunity to assess processes, responsibilities and evidence too. This practical checklist helps with preparation; the NEN 7510 standard page provides an overview of the standard and our support.

Who does NEN 7510 apply to?

According to the Dutch Health and Youth Care Inspectorate (IGJ), healthcare providers processing personal data in a healthcare information system must demonstrably work to NEN 7510. Youth care has a different reference: the IGJ refers to ISO 27001 there. Check which role and regulations apply to your organisation. Read the IGJ guidance.

NEN also identifies managers of personal health information, including suppliers processing such information, as a target group for certification. Examine which information you actually manage and which contractual requirements customers impose; supplying the healthcare sector alone does not settle the scope question. NEN explains the target group and relationship with ISO 27001.

For a healthcare provider, an ICT supplier's certificate does not replace its own responsibility. Record which tasks belong to the supplier and which care processes you must manage yourselves.

Which edition should you use for implementation?

NEN published the revision on 16 December 2024. The standard aligns with the updated ISO/IEC 27001 and 27002 and includes healthcare-specific additions. View NEN's information on the revision.

For part 2, the consolidated edition NEN 7510-2:2024+A1:2026 is now available, published in March 2026. It replaces NEN 7510-2:2024. Include this amendment when comparing requirements and controls. View NEN's current publication.

Keep a record of which edition of the standard you use and which changes have been assessed. Update an existing ISMS selectively: retain useful policies and evidence, and record where substantive changes are needed. A change in numbering alone does not mean a control has been implemented.

NEN 7510 checklist: what should you prepare?

Use these working questions in an initial assessment. For each answer, record the owner, evidence location and any follow-up action. This is a practical starting list, not a full assessment against the standard.

  • Scope: which care processes, locations, systems, data exchanges and suppliers are included?
  • Risks: where could the confidentiality, accuracy or availability of information be affected?
  • Choices: which controls address those risks, who implements them and who accepts residual risks?
  • Access: how are access rights requested, changed, reviewed and withdrawn?
  • Continuity: how can care processes continue during an outage, and where has recovery been tested?
  • Suppliers: which agreements, dependencies and checks are supported by documented evidence?
  • Assessment: when are operation, findings and improvements assessed independently?

Bring together the scope, risk assessment, treatment decisions, Statement of Applicability, working arrangements, records and audit results. Ensure the evidence file reflects actual operations. Give auditors appropriate access and share no more patient information than necessary.

How do you allocate implementation work and internal time?

Start with an initial assessment, set priorities and assign an owner to each work package. Involve the board, clinical process owners, IT, privacy, HR and procurement where their work is affected. Allocate their time for discussions, decisions, implementation and checks; software or support does not replace that contribution.

DCA can help with analysis, planning, tailoring documents and audit preparation. You provide context, validate arrangements and make decisions. Record this allocation as part of implementation support. The prices and calculator separate software from support hours; external certification and internal hours are separate budget items.

What do you demonstrate during the audit?

Ensure an assessor can trace arrangements through to implementation: from risk and control to the responsible person, record and any improvement. Prepare interviewees to discuss their own process and make recent records easy to find.

The IGJ expects an independent assessment to cover both the ISMS and applicable controls, with evidence of operation and justification of the assessor's expertise and independence. View the IGJ criteria for an independent assessment.

An internal audit, independent assessment and certification audit may serve different purposes. Agree the purpose, criteria and required report in advance. See our audits and assessments. An independent certification body decides whether to issue a certificate.

Is certification mandatory, and what transition applies?

The IGJ states that a NEN 7510 certificate is not a statutory requirement. Demonstrably working to the standard and obtaining an independent assessment are still necessary. A customer or contract may additionally require a certificate. Read the IGJ's explanation of the distinction.

For existing certificate holders, NEN states that the new standard had to be implemented by December 2025 and that certification against it before 20 February 2027 is required. The first date has already passed. Agree the audit schedule and applicable edition with your certification body. Check NEN's current certification guidance.

Frequently asked questions

Does every healthcare supplier need a NEN 7510 certificate?+

Not simply because it supplies the healthcare sector. Examine your role, the personal health information you manage and the statutory and contractual requirements that apply. Holding a certificate and demonstrably working to the standard are different things.

Does an established organisation have to start again?+

No. Compare the existing ISMS with the current editions of the standard. Reuse what demonstrably works and plan changes, assessment and decisions to address the differences found.

Which edition of part 2 is current?+

In March 2026, NEN published the consolidated NEN 7510-2:2024+A1:2026. It replaces NEN 7510-2:2024. Check with NEN and your certification body which publications are needed for the assessment.

Sources for this article

Explore this topic further

Further readingNEN 7510: the standard and our supportRead the guide →Further readingPreparing for an internal auditRead the guide →Further readingISO 27001 certification: roadmapRead the guide →

This is general guidance and does not replace an assessment of your situation or the official standard.