What is NEN 7510?
NEN 7510 is the Dutch standard for information security in healthcare (informatiebeveiliging in de zorg). Dutch care providers that process patient data electronically are expected to follow it, together with NEN 7512 (trusted data exchange) and NEN 7513 (logging of access to patient records).
NEN 7510:2024. The revised standard was published on 19 December 2024. It aligns with ISO 27001:2022, groups its measures into four themes (people, physical, technological, organisational) and contains 93 general measures plus 8 healthcare-specific ones. The implementation guidance that used to sit in NEN 7510-2 is no longer optional: deviations have to be justified in the Statement of Applicability (Kiwa). Certified organisations have until 20 February 2027 to move from NEN 7510:2017+A1:2020 to the 2024 version (Kiwa). See overstappen naar NEN 7510:2024.
Cyberbeveiligingswet (Cbw). The Dutch NIS2 law has applied since 15 August 2026. Healthcare is one of its sectors, so medium-sized and large care providers now carry NIS2 duties: registration, risk-management measures, board accountability and incident reporting. The Inspectie Gezondheidszorg en Jeugd (IGJ) supervises the healthcare entities in scope, and the healthcare regulation under the Cbw names compliance with NEN 7510 as one of the routes to meet the security duties (CMS). As of 1 October 2026.
What Dazr covers. Dazr's NEN 7510 set holds the 20 healthcare-specific controls. Enable ISO 27001 alongside for the 93 general measures that NEN 7510:2024 builds on.
Who needs to comply
- Academic hospitals (UMCs) and STZ teaching hospitals
- Regional and general hospitals
- Huisartsenpraktijken and huisartsenposten (out-of-hours GP posts)
- Other care providers that process patient data electronically, from mental-health care to dental and physiotherapy practices
- Digital-health vendors selling into Dutch care providers
Key NEN 7510 controls covered by Dazr
What auditors look for
NEN 7510 audits sample the same kinds of evidence as ISO 27001 audits, plus healthcare-specific checks: NEN 7513 access logging on the patient record and its periodic review, patient-data classification, BSN handling and break-glass procedures. Dazr holds the controls and the evidence for each.
How Dazr helps with NEN 7510
Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. NEN 7510 is one of its eleven frameworks, included from Pro, €99 a month. In practice that means:
- Maintain the healthcare policy, roles and awareness training as recurring controls
- Run the healthcare measures alongside ISO 27001 Annex A when both frameworks are enabled
- Track NEN 7513 access-logging review as a recurring control with evidence link to the EHR audit log
- Track Cbw incident reporting (24 hours, 72 hours, one month) next to the GDPR 72-hour clock in the incident register
- Plan the move to NEN 7510:2024 with a Statement of Applicability per control
Back to the full Dazr Compliance overview › | Sign up free ›