NEN 7510 Certification

Would you like to obtain a NEN 7510 certification or are you curious why other organizations choose this? The NEN 7510 standard is mandatory for healthcare. ICT service providers must also be able to demonstrate that they comply with this. With a certification from DigiTrust you can easily and independently demonstrate that information security within your organization is in order.

More than 450 organizations have proceeded before you

Certificeringstraject - DigiTrust

The standards explained

What is NEN 7510?

The NEN 7510 is a Dutch standard developed by the NEN. This standard is, the standard in the field of information security in healthcare. The standard is based on ISO27001 in design, but has additional care-specific measures. The standard is intended for Healthcare Providers and for the Managers of personal health information, the ICT service providers. With a NEN 7510 certification you demonstrate that you have a well-functioning management system for information security, in which personal health information, such as patient data, is properly secured at your company.

Is een NEN 7510 certificering verplicht?

Nowadays, both those responsible for an electronic exchange system and healthcare providers must comply with NEN 7510 and NEN 7512 based on the Electronic Data Processing Healthcare Providers Decree. The person responsible for an electronic exchange system must also work with a healthcare service provider that is authorized on the basis of criteria established in accordance with NEN 7512.
In response to recent debacles, the government wants healthcare providers or those responsible for an electronic exchange system to handle personal health information with increasing care. A NEN 7510 is the way to show clients and society that there is a well-functioning management system for information security.

Call us directly to speak with one of our specialists.

The steps explained

How do I obtain the NEN7510 standard?

You can order the NEN 7510 standard free of charge via NEN.

How can you obtain a NEN 7510 certification?

First you must ensure that you have a working ISMS (information security management system) that meets the standard requirements. You can do this yourself or you can be guided by a consultancy firm.
If you believe that you meet the standard, you can have it assessed by DigiTrust. Our certification process has a number of logical steps.

During the Pre-audit we check whether you are ready for certification. What is the status of the management system? Are there possibly still things that are not in order? DigiTrust can determine together with you which topics should be discussed during this pre-audit. We also determine the duration together. This is usually around 2 to 4 days to get a good idea of the management system and all control measures. After each pre-audit, DigiTrust provides you with a clear audit report, which describes in detail where you may not yet be working in accordance with the requirements.

Tip; this is a frequently chosen option. This will allow you to really start the process and immediately get a good idea of where you stand as an organization.

Initial certification

DigiTrust tests whether the system works and functions according to the requirements. These assessment also includes the assessment of all work in your office and at the execution location. The initial certification consists of 2 parts. The phase 1 and phase 2 audit.

During the phase 1 audit we take a broad look at your management system (ISMS) and whether you are really ready for the phase 2 audit. We will also work together to create the audit plan for phase 2. Who do we need and when?

During the phase 2 audit we test the ISMS and all control measures

Phase 1

During the phase 1 audit we take a broad look at your management system (ISMS) and whether you are really ready for the phase 2 audit. We will also work together to create the audit plan for phase 2. Who do we need and when?

Phase 2

During the phase 2 audit we test the ISMS and all control measures.

Issuance certificate

If the assessment is positive, the auditor will nominate the organization for certification. The certification manager carries out a quality check on the file. If everything is in order, you will receive the certification.

Surveillance audit 1

During the term of the certificate, which is usually three years, DigiTrust will conduct an annual audit. During a surveillance audit we take a sample of the various standard elements. If the assessment is positive, the current certificate will be continued.

Surveillance audit 2

DigiTrust will come by for the reassessment approximately three months before the certificate expires. This assessment is of the same scope as that in step 2 and should ensure that the certificate is extended for three years in the event of a positive result.

Investment in NEN 7510 certification

Curious about the costs for a NEN 7510 certification? We can help you with this in an affordable way. The number of audit days are calculated based on the context of your organization and the number of FTE within your organization.

We are always transparent in the calculation and the quotation drawn up. Have we interpreted everything correctly, do we understand the context of your organization well? Together we discuss the calculation, the scope of the certification and the process of the upcoming audits and certification. Transparency is the basis for trust.

Questions about a NEN 7510 Certification or curious about the possibilities?

Our specialists are happy to tell you more about this. Call us on 088-224 56 00, send us an email to or use our online contact form.

More than 450 organizations have proceeded before you.