NEN 7510
NEN 7510:2024 is the Dutch standard for information security in healthcare: ISO 27001 extended with care-specific controls for patient data, medical devices and chain care.
About this standard
NEN 7510 in brief
Dutch healthcare providers are legally required to apply NEN 7510. The 2024 revision aligns with ISO 27001:2022 and counts 101 controls in the library.
Because NEN 7510 maps onto the shared control set, you immediately see the overlap with ISO 27001 and the GDPR, and therefore what a healthcare organisation already working ISO-compliant still needs to arrange.
In the library
Verified counts
101 controls
NEN 7510-1:2024 — Medische informatica — Informatiebeveiliging in de zorg — Deel 1: Managementsysteem (Bijlage A: zorgspecifieke beheersmaatregelen) (version 2024).
182 links
To 90 shared controls, the bridge to other frameworks.
41 frameworks
This standard does not stand alone: the library counts 1,807 controls and 2,224 cross-references.
Structure
Domains in NEN 7510:2024
- Organisatorische beheersmaatregelen (43) (43)
- Technologische beheersmaatregelen (35) (35)
- Fysieke beheersmaatregelen (14) (14)
- Mensgerichte beheersmaatregelen (9) (9)
Related standards
ISO 27001 · NIS2 and the Dutch Cybersecurity Act · GDPR · DORA · BIO and BIO2 · ISO 42001 · Wpg (Dutch Police Data Act) · All standards
Get started with NEN 7510
Request a demo or see how CRAFT supports this standard.
Frequently asked questions
Is NEN 7510 mandatory for healthcare providers?
Yes. Dutch law requires healthcare providers to apply NEN 7510 when processing patient data electronically. Health insurers and suppliers in the care chain also encounter it through contracts.
What does NEN 7510 add to ISO 27001?
NEN 7510 adopts the structure and controls of ISO 27001/27002 and extends them with care-specific requirements, for example around access to patient records, medical devices and data exchange in the chain. The 2024 revision counts 101 controls in the library.
How do I see the overlap between NEN 7510, ISO 27001 and the GDPR?
The Audirium library maps NEN 7510 onto the shared control set and links GDPR articles to controls. A healthcare organisation already working ISO-compliant immediately sees what NEN 7510 still requires.