NEN 7510 certification and the transition to the 2024 edition before 20 February 2027
5 min read Last checked on
Organisations holding a NEN 7510:2017 certificate must be certified against NEN 7510:2024 before 20 February 2027. Certification runs through a certification body accredited by the Dutch Accreditation Council, under the NCS 7510:2025 scheme that NEN published in February 2025. A supplier that also runs ISO 27001 can usually have both standards assessed in one combined audit.
Organisations holding a certificate against NEN 7510:2017 must be certified against NEN 7510:2024 before 20 February 2027. That date is set out by NEN, the Dutch standardisation body, which published the new edition on 16 December 2024. Certification itself runs through an accredited certification body under the NCS 7510:2025 scheme. For a supplier that also runs ISO 27001, the transition is mostly an addition to what is already in place.
How NEN 7510 certification works
A NEN 7510 certificate is issued by a certification body, not by NEN. NEN maintains the standard and the certification scheme, and the Dutch Accreditation Council (Raad voor Accreditatie, RvA) supervises the certification bodies. NEN keeps a public register of certified organisations.
The scheme is called NCS 7510:2025 and was published in February 2025. It replaces NCS 7510:2018 and sets out the requirements a certification body must meet when it assesses against NEN 7510. In doing so it supplements ISO/IEC 27006-1, the general standard for bodies that audit information security management systems. The RvA has accepted the scheme.
The process is the same as for ISO 27001, because both rest on ISO/IEC 17021-1:
| Step | What happens |
|---|---|
| Stage 1 | The auditor reviews whether the management system is complete on paper and whether the organisation is ready for the next stage. |
| Stage 2 | The auditor tests whether the system works: interviews, samples of evidence, visits to processes. |
| Certificate | Once any nonconformities are resolved, a certificate is issued for a three-year cycle. |
| Surveillance audits | In between, usually annually, the body assesses part of the system. |
| Recertification | At the end of the cycle a full audit leads to a new certificate. |
Who can be certified
Not every supplier can obtain a NEN 7510 certificate. In an explanatory note from October 2025, NEN distinguishes two groups: healthcare organisations, whose scope must include at least one primary care process, and organisations that structurally manage personal health information for healthcare customers. The second group includes hosting providers, backup services and other processors.
For that second group the processing must be lawful, which in practice means a data processing agreement under Article 28 of the GDPR. NEN expects that lawfulness to be demonstrable at every audit, or within the six months before it. A SaaS provider hosting records for a mental health organisation will usually meet that. A supplier of software that runs at the customer and never sees health data will not. For the latter, NEN states that a NEN 7510 certificate may not be required and that ISO 27001 should be treated as equivalent.
The transition from 2017 to 2024
After publication, NEN gave certificate holders a year, up to and including December 2025, to implement the new edition, and set 20 February 2027 as the final date for a certificate against it. The transition audit has to be completed before that date, including the handling of any nonconformities.
What changes in substance largely follows the move from ISO 27001:2013 to 2022. Anyone who has been through that will recognise most of it:
- A new structure of controls. NEN 7510-2:2024 follows the 93 controls of ISO 27002:2022 in four themes: organisational, people, physical and technological. According to NOREA, the Dutch association of IT auditors, the 2017 edition still worked with 114 general controls.
- Eight healthcare-specific HLT controls. According to NOREA, that brings the total to 101. Each of the eight needs a decision on applicability.
- Healthcare guidance on a comply-or-explain basis. Departures from the 66 healthcare-specific implementation guidelines are recorded and justified, usually in the Statement of Applicability.
- An updated Statement of Applicability and risk assessment. The old mapping to 2017 controls has to move to the new numbering, and risk treatment has to refer to the new controls.
A practical order for a supplier: convert the Statement of Applicability first, then decide on each HLT control and each healthcare guideline, then gather the missing evidence and run an internal audit on the new parts. Talk to your certification body early about which audit will cover the transition and how much extra time it needs. How long the work takes depends on where you start, not on the standard.
The combined audit with ISO 27001
Because NEN 7510-1 is the equivalent of ISO 27001, many suppliers have both standards assessed in one process. Certification bodies offer combined audits for this: the management system is assessed once, the healthcare-specific controls and guidance are added as an extra part, and the organisation receives two certificates.
That only works if the organisation itself also runs one system. An auditor who finds two risk registers or two statements that contradict each other during a combined audit sees a nonconformity in the system, not an administrative detail. One Statement of Applicability with a column per standard, one risk assessment and evidence supplied once make the combined audit simpler for the organisation as well. The background is covered in NEN 7510 for software suppliers.
Trustbird keeps ISO 27001 and NEN 7510 as two standards on one set of controls, with an audit trail the auditor can read directly. Whether you do that in a tool or in your own overview, the transition date is the same for everyone.
Frequently asked questions
When do I need to move to NEN 7510:2024?
Holders of a NEN 7510:2017 certificate must be certified against NEN 7510:2024 before 20 February 2027. After that date, a certificate against the old edition no longer counts as proof.
What is NCS 7510?
NCS 7510:2025 is NEN's certification scheme setting out requirements for certification bodies that carry out NEN 7510 audits. It supplements ISO/IEC 27006-1, replaces NCS 7510:2018 and has been accepted by the Dutch Accreditation Council.
Can any software supplier obtain NEN 7510 certification?
No. Certification is open to healthcare organisations and to organisations that structurally process health data on behalf of healthcare customers under a data processing agreement. For suppliers without such processing, NEN treats ISO 27001 as equivalent.
Can ISO 27001 and NEN 7510 be assessed in one audit?
Yes, certification bodies offer combined audits. The management system is assessed once, and the healthcare-specific controls and guidance are added as an extra part.
How long is a NEN 7510 certificate valid?
As with other management system certificates, it runs on a three-year cycle with surveillance audits in between, followed by recertification.
Read next
Management system and policy
What an ISMS is, and why a spreadsheet stops at the second standard
Read more
ISO 27001
ISO 27001 certification: steps, timeline and who does what
Read more
ISO 27001
ISO 27001 in plain language: what it is and what it asks of a software supplier
Read more
NEN 7510
NEN 7510 for software suppliers in healthcare: what it adds to ISO 27001
Read more
ISO 27001
Statement of Applicability: what goes in it and how to keep it current
Read more
Sources
- NEN, NEN 7510 certification and register (Dutch)
- NEN, NEN 7510 information security in healthcare (Dutch)
- NEN, NCS 7510:2025 (Dutch)
- NEN, NEN 7510 explanation of target groups for certification, October 2025 (Dutch)
- NOREA, De nieuwe NEN 7510:2024 en de waarde voor NIS2, 21 February 2025 (Dutch)
- ISO, ISO/IEC 17021-1 Requirements for bodies providing audit and certification of management systems
- Kiwa, combined ISO 27001 and NEN 7510 audit (Dutch)
Trustbird is being built with two certified design partners, and we are looking for more companies to join them at co-founder pricing.
Become a design partner