For Dutch healthcare organisations, two things come together in 2026: the transition to the new NEN 7510 and the Cyberbeveiligingswet (Cbw), the Dutch law implementing NIS2. That is less duplicate work than it seems. The healthcare regulation under the Cbw deliberately builds on NEN 7510, and the standard was revised in 2024 to, in the words of the explanatory notes, "align better with the requirements arising from the NIS2 Directive". This page sets out what changed, which deadlines apply and what you can use as a gap list.
What changed in NEN 7510:2024
| Topic | NEN 7510:2017+A1:2020 | NEN 7510:2024 |
|---|---|---|
| Basis | ISO/IEC 27001:2013 and 27002:2013 | ISO/IEC 27001:2022, 27002:2022 and the draft ISO/IEC DIS 27799, with additional healthcare requirements (Kiwa) |
| Structure of controls | Fourteen chapters | Four themes: organisational, people, physical, technological |
| Number of controls | Based on the 114 ISO controls of 2013, with healthcare-specific additions | 93 general and 8 healthcare-specific controls; 14 general ISO controls have been adapted for healthcare (Kiwa) |
| Implementation guidance (NEN 7510-2) | Optional | No longer optional: in the Statement of Applicability you state whether you follow the guidance and why you deviate (Kiwa) |
According to Kiwa, the new standard also helps organisations with the Wabvpz (the Dutch act on client data in healthcare), the Wegiz (the act on electronic data exchange in healthcare) and the NIS2 Directive.
The eight healthcare-specific controls
Published statements of applicability based on NEN 7510-1:2024 list the healthcare-specific controls with the prefix HLT. Kiwa mentions topics including emergency communication, external incident reporting, management training and zero trust principles. They are:
- 5.38 Analysis and specification of information security requirements
- 5.39 Uniquely identifying care recipients
- 5.40 Validation of displayed or printed data
- 5.41 Publicly available health information
- 5.42 Communication in emergencies
- 5.43 External incident reporting
- 6.9 Management training
- 8.35 Zero trust principles
The titles above are our English renderings; always check the exact numbering and text in your own copy of the standard. According to the explanatory notes to the Cyberbeveiligingsregeling voor de zorg, anyone can view NEN 7510 free of charge.
Two parts, one whole
NEN 7510-1 contains the normative framework: the ISMS requirements and the controls in Annex A. NEN 7510-2 explains those controls with implementation guidance. The Cyberbeveiligingsregeling voor de zorg assumes both parts are applied in full: "Where this regulation refers to NEN7510, this includes both NEN7510-1 and NEN7510-2." Deviations from NEN 7510-2 must be justified in the Statement of Applicability.
Transition period
| Date | What | Source |
|---|---|---|
| 16 December 2024 | Publication of NEN 7510-1:2024 | Kiwa |
| 15 August 2026 | Cyberbeveiligingswet in force; the healthcare regulation refers to NEN 7510 | Stb. 2026, 187; Stcrt. 2026, 28763 |
| 20 February 2027 | End of certification under accreditation against NEN 7510:2017+A1:2020; certificate holders must have transitioned | Kiwa |
Kiwa advises transitioning at your next (re)certification, and reports that a separate transition audit costs an extra half day of audit time; an initial audit applies the new standard straight away. Other certification bodies may use different practical arrangements; check with yours. Note: this is about certificates. The legal duty under the Wabvpz and the Besluit elektronische gegevensverwerking door zorgaanbieders is to comply with NEN 7510, with or without a certificate.
Gap list: from 2017 to 2024
If you already run an ISMS based on NEN 7510:2017, this is a practical order for your gap analysis.
1. Management system (NEN 7510-1, clauses 4 to 10)
- Review interested parties and their requirements again, including the Wegiz and the Cbw
- Define an approach for planning changes to the ISMS
- Work out criteria for processes and the control of outsourced processes
- Revise the risk assessment: include the supply chain too (the healthcare regulation refers to NEN 7510:2024, 6.1.2 for this)
2. Statement of Applicability
- Convert the SoA to the new structure of 93 + 8 controls
- State per control whether you follow the NEN 7510-2 guidance; justify deviations
- Trace controls from 2017 that were removed or merged: where does the implementation sit now?
3. Controls that are new in ISO 27002:2022
- 5.7 Threat intelligence
- 5.23 Information security for use of cloud services
- 5.30 ICT readiness for business continuity
- 7.4 Physical security monitoring
- 8.9 Configuration management
- 8.10 Information deletion
- 8.11 Data masking
- 8.12 Data leakage prevention
- 8.16 Monitoring activities
- 8.23 Web filtering
- 8.28 Secure coding
4. Healthcare-specific controls
- Emergency communication (5.42): channels that work when email, telephony or the electronic patient record go down
- External incident reporting (5.43): link it to the Cbw reporting duty and the GDPR breach notification
- Management training (6.9): align it with the training duty for board members in Art. 24 Cbw
- Zero trust (8.35), unique identification of care recipients (5.39) and validation of displayed or printed data (5.40)
5. Scope
- If your organisation falls under the Cbw, extend the scope to all network and information systems, not only the electronic patient record and exchange systems. The explanatory notes to the healthcare regulation mention HR systems as an example.
The Cyberbeveiligingswet for healthcare
Who is in scope?
Healthcare is listed in Annex 1 of the Cbw. The sector includes healthcare providers within the meaning of the Wkkgz (the Dutch Healthcare Quality, Complaints and Disputes Act), EU reference laboratories, pharmaceutical research and manufacturing, and manufacturers of critical medical devices. The size threshold: 50 FTEs or more, or fewer than 50 FTEs but both an annual turnover and a balance sheet total above €10 million, including partner and linked enterprises. Large organisations (250 FTEs or more, or more than €50 million in turnover and €43 million balance sheet total) are essential, medium-sized ones important. The Ministry of Health (VWS) estimates that around 1,200 entities in healthcare and the manufacturing subsector face additional obligations. Not sure? Run the NIS2 scope checker.
What the healthcare regulation requires
- Duty of care: measures that demonstrably meet NEN 7510, ISO 27001 and 27002, or are demonstrably equivalent (Art. 2.1). Certification is not a requirement, but it is one way to demonstrate compliance.
- Significant incidents (Art. 2.2): among other things, when a critical business process is fully or partly down for more than four hours, when systems crucial to service delivery are compromised or destroyed, when the confidentiality of special categories of personal data or citizen service numbers (BSN) has been compromised by a suspected malicious act, or in case of permanent injury, hospital admission or death.
- Additional content of reports (Art. 2.3 to 2.5): including how the incident was discovered, which support you need from the CSIRT, the consequences for suppliers and customers and, in the final report, how your risk analyses and continuity plan worked and which lessons you draw.
- Supervision and CSIRT: the IGJ supervises. Z-CERT will be the CSIRT for healthcare; until its formal designation, reports in the NCSC portal are also picked up by Z-CERT.
See also reporting incidents under the Cbw and the GDPR and the crosswalk of the duty of care next to NEN 7510.
Smaller healthcare providers
If your practice or institution is below the size threshold, the Cbw does not apply. The NEN 7510 duty under the Wabvpz does: "Small-scale healthcare providers, however, are already required under the Wabvpz to comply with NEN 7510", according to the explanatory notes to the healthcare regulation. What that looks like for a small practice is covered in NEN 7510 for Dutch GP practices.
A realistic transition plan
- Now: determine whether you fall under the Cbw and register on MijnNCSC. Plan the transition with your certification body.
- Within three months: gap analysis of your SoA against NEN 7510-1:2024 and NEN 7510-2; update the risk analysis including the supply chain.
- Within six months: implement new controls (especially 5.23, 5.30, 8.9, 8.16 and the HLT controls); align the reporting procedure with the Cbw deadlines; schedule board training.
- Before 20 February 2027: transition audit with your certification body, if you are certified.
Sources
- Kiwa, NEN 7510 for healthcare sector information security updated
- Kiwa, Herziene NEN 7510 gepubliceerd (in Dutch)
- Kiwa, Wat betekent de nieuwe NEN 7510:2024 voor certificaathouders? (in Dutch)
- Cyberbeveiligingsregeling voor de zorg, Staatscourant 2026, 28763
- Cyberbeveiligingswet, Staatsblad 2026, 187
- Cyberbeveiligingsbesluit, Staatsblad 2026, 189
- Besluit elektronische gegevensverwerking door zorgaanbieders, Staatsblad 2017, 446
- NCSC, Valt mijn organisatie onder de Cyberbeveiligingswet? (in Dutch)
As of 1 October 2026. This page is general information, not legal advice. Laws, regulations and sector rules can change; always check the current source.