What NEN 7510 certification actually requires for a digital health platform entering the Dutch market, why most of the work is already done if you hold ISO 27001, and how the right auditor relationship in the Netherlands keeps the whole thing on schedule.
If NEN 7510 has landed on your desk as a Dutch procurement requirement, the good news is you’re probably not starting from zero. Here’s how a digital health platform extended its existing ISO 27001 ISMS to meet the Netherlands’ healthcare security standard, without building a second management system from scratch.
Ask most people outside the Netherlands what NEN 7510 is and you’ll get a shrug. Ask a Dutch hospital procurement team, and it’s non-negotiable. If you’re selling digital health technology into the Netherlands, NEN 7510 tends to arrive as a hard requirement in the contract before anyone explains what it actually involves, which is usually where the anxiety starts.
The most common misconception is that NEN 7510 means building a second, parallel management system alongside whatever you already have. It doesn’t. NEN 7510 is the Dutch national standard for information security in healthcare, and it’s structured directly on ISO 27001 and ISO 27002, with a set of healthcare-specific controls layered on top. If your ISMS is already ISO 27001 certified, you are not starting a new project, you’re extending one.
NEN 7510 doesn’t replace your ISMS. It adds a healthcare-specific layer on top of the ISO 27001 structure you likely already have.
For the client, that meant the starting point wasn’t a blank page. It was the existing ISO 27001 certified ISMS, with a gap analysis against the additional Dutch healthcare requirements to work out exactly what needed adding, rather than what needed building.
The extra layer NEN 7510 adds on top of ISO 27001 comes in two forms: healthcare-specific controls, and what the standard calls High Level Theme (HLT) measures, additional requirements aimed squarely at organisations processing personal health data on behalf of Dutch healthcare providers. This is where the genuine, new work sits, not in rebuilding the management system itself.
Healthcare-specific controls: requirements that go beyond generic ISO 27001 Annex A because the data in question is patient health information, not just “personal data” in the abstract.
HLT measures: the additional sector-level themes NEN 7510 layers on top, which needed mapping against what the client’s ISMS already covered, so we could see precisely what was already met and what genuinely needed building.
Scope discipline: NEN 7510 only needed to cover the systems and services actually processing Dutch patient data. The client’s other country deployments had no reason to be pulled into a Netherlands-specific audit, so they weren’t.
Instead of treating NEN 7510 as a separate project, we mapped the existing ISO 27001 Annex A controls straight across, then ran a gap analysis against the healthcare-specific controls and HLT measures to identify exactly what was missing. Internal audits and management reviews, run through the same ISMS cadence the client already had in place, were then used to evidence that the additional requirements were operating, not just documented.
This is the same principle we apply across every regional certification we run for this client: reuse the evidence that already exists in the ISMS, and only build new controls for the genuinely new requirement. It’s what keeps five certifications achievable without five separate management systems running in parallel.
NEN 7510 certification has to be issued by a certification body accredited by the Dutch Accreditation Council (RvA), and not every auditor who knows ISO 27001 well also knows the Dutch healthcare context well. This is a market where Periculo’s existing relationships with regional auditors did real, practical work.
Because we already work regularly with accredited certification bodies operating in the Netherlands, the audit itself moved faster: a shared understanding of what the healthcare-specific controls and HLT measures actually need to look like in evidence, and no time lost explaining Dutch healthcare context from scratch. That familiarity, built over previous engagements, is often worth more than any amount of internal preparation, because it removes the guessing on both sides of the audit table.
Certification was achieved by extending the client’s existing ISMS rather than standing up a second one, scoped specifically to the systems handling Dutch patient data. The additional healthcare-specific controls and HLT measures were identified early through the gap analysis and built deliberately rather than discovered under audit pressure. And because the audit itself ran with a certification body we already had a working relationship with in the region, there were no delays waiting for an unfamiliar assessor to get up to speed on either the standard or the sector.
If NEN 7510 has landed on your desk as a Dutch procurement requirement, the first useful question isn’t “how do we build this,” it’s “how much of this do we already have.” For most organisations with a mature ISMS, the answer is: most of it.
Got NEN 7510 in a contract and an existing ISO 27001 ISMS? Get in touch, we'll scope the real gap before you commit to anything.