NEN 7510 for software suppliers in healthcare: what it adds to ISO 27001
6 min read Last checked on
NEN 7510 is the Dutch standard for information security in healthcare, current since 16 December 2024 as NEN 7510-1:2024 and NEN 7510-2:2024. Part 1 is the equivalent of ISO 27001; part 2 adds eight healthcare-specific controls and healthcare guidance to ISO 27002. An organisation that already runs ISO 27001 therefore has largely the same controls under two standards.
Since 16 December 2024, NEN 7510 has been published in two parts, NEN 7510-1:2024 and NEN 7510-2:2024, and it builds directly on ISO 27001 and ISO 27002. For a software supplier that already runs ISO 27001, NEN 7510 is therefore not a second security programme. It is largely the same set of controls, with a healthcare layer on top and a different group of customers asking for it.
What NEN 7510 is
NEN 7510 is the Dutch standard for information security in healthcare. It is maintained by NEN, the Dutch standardisation body, which published the current edition on 16 December 2024. The standard has two parts:
| Part | What it is | International basis |
|---|---|---|
| NEN 7510-1:2024 | Requirements for the information security management system: context, leadership, risk, operation, evaluation and improvement. | Equivalent of ISO 27001 |
| NEN 7510-2:2024 | The controls with implementation guidance, extended for healthcare. | ISO 27002, combined with ISO 27799 |
Part 1 therefore follows the same clause structure as ISO 27001, the shared structure of management system standards also covered in the ISMS article. Part 2 is where healthcare becomes visible.
What NEN 7510 adds to ISO 27001
Put the 2024 edition next to ISO 27001:2022 and four differences stand out. In our own words, without reproducing the standard:
- Eight healthcare-specific controls. NEN 7510-2:2024 takes over the 93 controls from ISO 27002:2022 and adds eight healthcare-specific ones, marked HLT. According to an analysis by NOREA, the Dutch association of IT auditors, that brings the total to 101. Examples include zero trust principles (8.35), communication in emergencies (5.42), training for management (6.9) and reporting incidents to external parties (5.43).
- Healthcare guidance that is less optional. According to NOREA, part 2 contains 66 healthcare-specific implementation guidelines. Where an organisation departs from one, it explains why, usually in its Statement of Applicability. The principle is comply or explain.
- A healthcare context for risk. The controls drawn from ISO 27799 bring patient data and care processes into the risk assessment. For a supplier this mainly means that availability and integrity are judged not only by the impact on your own service, but by what an outage means for care at the customer.
- A link to NIS2. Annex E of NEN 7510-2 shows, for each part of NIS2, how the standard relates to it. For healthcare organisations that fall under the Dutch Cybersecurity Act (Cyberbeveiligingswet), that helps show how their NEN 7510 controls support their duty of care.
What NEN 7510 does not add is a different management system. Scope, risk assessment, internal audit and management review work the same way as under ISO 27001.
Where Dutch law refers to NEN 7510
NEN 7510 is a voluntary standard, but Dutch law points to it. Article 15j of the Act on additional provisions for processing personal data in healthcare (Wet aanvullende bepalingen verwerking persoonsgegevens in de zorg, Wabvpz) provides the basis for further rules on securing healthcare information systems. Those rules are set out in the Decree on electronic data processing by care providers (Besluit elektronische gegevensverwerking door zorgaanbieders):
- Article 3 requires care providers to use their healthcare information systems, and those responsible for exchange systems to use theirs, safely and carefully in line with NEN 7510 and NEN 7512.
- Article 4 requires them to use the terms from those standards in their policies and procedures.
- Article 5 requires the logging of those systems to meet NEN 7513.
That brings two companion standards into view. NEN 7512 covers trusted data exchange between parties in healthcare; NEN 7513 covers recording who does what in an electronic patient record. For a supplier of healthcare software, NEN 7513 is often the most tangible: the logging sits in the product, and the customer relies on it to meet the law.
The obligation rests with the care provider, not the supplier, and the decree does not require a certificate. Under an agreement between the Ministry of Health, Welfare and Sport and NEN, NEN 7510, NEN 7512 and NEN 7513 can be viewed free of charge through NEN Connect.
Why suppliers are asked for it
Because the care provider remains responsible for systems it neither builds nor hosts, it passes the question on to its suppliers. A hospital that buys a SaaS scheduling application, or places its records with a hosting provider, wants to show that the supplier works at the level the law expects of the hospital. A NEN 7510 certificate is the simplest proof of that in a procurement process.
NEN draws a distinction here that matters to suppliers. Certification against NEN 7510 is open to healthcare organisations and to organisations that structurally manage personal health information on behalf of healthcare customers, such as hosting providers, backup services and other processors. That processing has to be lawful, which in practice means a data processing agreement under Article 28 of the GDPR.
For suppliers that do not process health data, NEN states that a NEN 7510 certificate cannot and may not be required, and that ISO 27001 should then be treated as equivalent. A developer of rostering software that never touches patient data can rely on ISO 27001. A SaaS provider hosting client records will almost certainly be asked for NEN 7510.
One set of controls, two standards
This is the heart of it for a supplier that already runs ISO 27001. The management system is the same, and 93 of the 101 controls in NEN 7510-2 are the controls already listed in the ISO 27001 Statement of Applicability. What is genuinely new is manageable:
- eight HLT controls, each needing a decision on applicability and, where relevant, implementation;
- the healthcare guidance attached to existing controls, with a choice per guideline: apply it or explain why not;
- a scope and risk assessment that explicitly include healthcare customers and their data;
- where the product touches logging or data exchange, attention to NEN 7513 and NEN 7512.
The trap is to treat NEN 7510 as a second project next to ISO 27001, with its own risk register, its own statement and its own evidence. The organisation then describes the same access control twice, supplies the same backup log twice, and makes a change in one place but not the other.
A more workable approach is one Statement of Applicability with the controls as rows and a column per standard, extended with the eight HLT controls and the choices on the healthcare guidance. One risk assessment, one set of controls, evidence supplied once that counts for both standards. Certification bodies also offer combined audits, as described in NEN 7510 certification.
How you maintain that single core is a choice: a well-kept spreadsheet, an ISMS tool, or a management system that treats standards as projections of one set of controls. Trustbird is built around that last idea, with ISO 27001 and NEN 7510 as its first two standards. Whatever form you choose, the decisions on applicability and risk remain with the organisation itself.
Frequently asked questions
What is the difference between NEN 7510 and ISO 27001?
NEN 7510-1 sets the same management system requirements as ISO 27001. The difference lies mainly in NEN 7510-2, which adds healthcare-specific controls and implementation guidance to the controls from ISO 27002.
Is NEN 7510 a legal requirement?
For Dutch healthcare providers, yes. A Dutch decree on electronic data processing by care providers requires them to secure their healthcare information systems in line with NEN 7510 and NEN 7512, and to log access in line with NEN 7513. It does not require a certificate.
Does a software supplier need NEN 7510 certification?
Not by law. Healthcare organisations do ask for it, particularly from suppliers that process health data on their behalf. For suppliers without such processing, NEN states that ISO 27001 certification should be treated as equivalent.
What are NEN 7512 and NEN 7513?
NEN 7512 covers trusted data exchange between parties in healthcare. NEN 7513 covers logging of actions on electronic patient records. Both build on NEN 7510.
Where can I read NEN 7510?
Under an agreement between the Dutch Ministry of Health, Welfare and Sport and NEN, NEN 7510, NEN 7512 and NEN 7513 can be viewed free of charge through NEN Connect.
Read next
Management system and policy
What an ISMS is, and why a spreadsheet stops at the second standard
Read more
ISO 27001
ISO 27001 certification: steps, timeline and who does what
Read more
ISO 27001
ISO 27001 in plain language: what it is and what it asks of a software supplier
Read more
NEN 7510
NEN 7510 certification and the transition to the 2024 edition before 20 February 2027
Read more
ISO 27001
Statement of Applicability: what goes in it and how to keep it current
Read more
Sources
- NEN, NEN 7510 information security in healthcare (Dutch)
- NEN, NEN 7510 certification and register (Dutch)
- NEN, NEN 7510 explanation of target groups for certification, October 2025 (Dutch)
- Wetten.nl, Besluit elektronische gegevensverwerking door zorgaanbieders (Dutch)
- Wetten.nl, Wet aanvullende bepalingen verwerking persoonsgegevens in de zorg (Dutch)
- NOREA, De nieuwe NEN 7510:2024 en de waarde voor NIS2, 21 February 2025 (Dutch)
- ISO, ISO/IEC 27001 Information security management systems
Trustbird is being built with two certified design partners, and we are looking for more companies to join them at co-founder pricing.
Become a design partner