Home › Frameworks › NEN 7510

NEN 7510 software for zorginstellingen in the Netherlands.

The healthcare-specific NEN 7510 controls (patient data, BSN handling, need-to-know access, NEN 7513 access logging, break-glass, continuity), recurring and with evidence, run alongside ISO 27001. For hospitals, huisartsenpraktijken and huisartsenposten, other care providers and digital-health vendors. Included from Pro, €99 a month.

At a glance

  • Management system: Policy, roles, risk management and the Statement of Applicability, aligned with ISO 27001:2022 clauses 4-10.
  • Healthcare measures: Patient-data classification, BSN handling, consent, need-to-know access, break-glass, healthcare incident reporting and continuity of clinical…
  • NEN 7513: Access logging on the electronic health record.
  • NEN 7510:2024 transition: Certificates against the 2017 version have to move to the 2024 version by 20 February 2027.

On this page

  1. What is NEN 7510?
  2. Who needs to comply
  3. Key NEN 7510 controls covered by Dazr
  4. What auditors look for
  5. How Dazr helps with NEN 7510

What is NEN 7510?

NEN 7510 is the Dutch standard for information security in healthcare (informatiebeveiliging in de zorg). Dutch care providers that process patient data electronically are expected to follow it, together with NEN 7512 (trusted data exchange) and NEN 7513 (logging of access to patient records).

NEN 7510:2024. The revised standard was published on 19 December 2024. It aligns with ISO 27001:2022, groups its measures into four themes (people, physical, technological, organisational) and contains 93 general measures plus 8 healthcare-specific ones. The implementation guidance that used to sit in NEN 7510-2 is no longer optional: deviations have to be justified in the Statement of Applicability (Kiwa). Certified organisations have until 20 February 2027 to move from NEN 7510:2017+A1:2020 to the 2024 version (Kiwa). See overstappen naar NEN 7510:2024.

Cyberbeveiligingswet (Cbw). The Dutch NIS2 law has applied since 15 August 2026. Healthcare is one of its sectors, so medium-sized and large care providers now carry NIS2 duties: registration, risk-management measures, board accountability and incident reporting. The Inspectie Gezondheidszorg en Jeugd (IGJ) supervises the healthcare entities in scope, and the healthcare regulation under the Cbw names compliance with NEN 7510 as one of the routes to meet the security duties (CMS). As of 1 October 2026.

What Dazr covers. Dazr's NEN 7510 set holds the 20 healthcare-specific controls. Enable ISO 27001 alongside for the 93 general measures that NEN 7510:2024 builds on.

Who needs to comply

  • Academic hospitals (UMCs) and STZ teaching hospitals
  • Regional and general hospitals
  • Huisartsenpraktijken and huisartsenposten (out-of-hours GP posts)
  • Other care providers that process patient data electronically, from mental-health care to dental and physiotherapy practices
  • Digital-health vendors selling into Dutch care providers

Key NEN 7510 controls covered by Dazr

Management systemPolicy, roles, risk management and the Statement of Applicability, aligned with ISO 27001:2022 clauses 4-10.
Healthcare measuresPatient-data classification, BSN handling, consent, need-to-know access, break-glass, healthcare incident reporting and continuity of clinical systems.
NEN 7513Access logging on the electronic health record.
NEN 7510:2024 transitionCertificates against the 2017 version have to move to the 2024 version by 20 February 2027.
CyberbeveiligingswetNIS2 duties for medium-sized and large care providers since 15 August 2026: registration, measures and incident reporting.

What auditors look for

NEN 7510 audits sample the same kinds of evidence as ISO 27001 audits, plus healthcare-specific checks: NEN 7513 access logging on the patient record and its periodic review, patient-data classification, BSN handling and break-glass procedures. Dazr holds the controls and the evidence for each.

How Dazr helps with NEN 7510

Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. NEN 7510 is one of its eleven frameworks, included from Pro, €99 a month. In practice that means:

  • Maintain the healthcare policy, roles and awareness training as recurring controls
  • Run the healthcare measures alongside ISO 27001 Annex A when both frameworks are enabled
  • Track NEN 7513 access-logging review as a recurring control with evidence link to the EHR audit log
  • Track Cbw incident reporting (24 hours, 72 hours, one month) next to the GDPR 72-hour clock in the incident register
  • Plan the move to NEN 7510:2024 with a Statement of Applicability per control

Back to the full Dazr Compliance overview › | Sign up free ›

NEN 7510 questions, answered.

Does NEN 7510 fall under the Cyberbeveiligingswet?

Indirectly. Since 15 August 2026 the Cyberbeveiligingswet applies to medium-sized and large care providers. The healthcare regulation under the Cbw lets you meet the security duties by complying with NEN 7510, among other routes, and the IGJ supervises. Smaller practices stay outside the Cbw but remain bound to NEN 7510 through the existing healthcare rules. As of 1 October 2026.

Can we run NEN 7510 alongside ISO 27001?

Yes, and most healthcare organisations should. Enable both; Dazr creates separate but related controls. The same evidence (e.g. an access-review log) often serves both.

When do we have to move to NEN 7510:2024?

If you hold a certificate against NEN 7510:2017+A1:2020, you have until 20 February 2027 to transition to NEN 7510:2024; your certification body plans the transition audit. Dazr keeps the healthcare controls and your evidence in one place while you do it.

Where is data hosted?

European Union. Workspace records are encrypted at rest with AES-256-GCM at the application layer; uploaded evidence files rely on the storage provider's at-rest encryption.

Is there NEN 7510 software for small care providers?

Yes. NEN 7510 is included from Pro at €99 a month with no implementation fee: the healthcare-specific controls, NEN 7513 log reviews and the move to NEN 7510:2024 run as recurring controls with evidence, next to ISO 27001. It suits huisartsenpraktijken, smaller care organisations and health-tech suppliers.

Ready to start your NEN 7510 program?

NEN 7510 is included in Pro (€99/mo, up to five frameworks and five users) and Enterprise (€499/mo); self-serve via Mollie, excl. VAT, cancel any time. Free and Basic cover ISO 27001, GDPR and NIS2. Custom is the only tier on a contract, priced on request.