Control over AI
Blog
Compliance and AI 9 min read

NEN 7510 in 2026: the new standard, the deadlines, and what healthcare arranges now

Dutch healthcare is in two transitions at once: the revised NEN 7510:2024 with a certification deadline in February 2027, and the Cyberbeveiligingswet taking effect on 15 August. What the standard asks and how to make it demonstrable.

NEN 7510, the Dutch standard for information security in healthcare: the key milestones
Quick answer

NEN 7510 is the Dutch standard for information security in healthcare, and it is anchored in law: providers processing patient data electronically must demonstrably comply. The healthcare inspectorate IGJ supervises; certification is not mandatory, demonstrability is. Since 16 December 2024 there is a revised version, NEN 7510:2024, aligned with ISO 27001:2022. Certificate holders are expected to have adapted their management system by now, and from 20 February 2027 certification is only possible against the new version. On top of that, the Cyberbeveiligingswet reaches mid-sized and large healthcare providers from 15 August 2026.

01

NEN 7510 is anchored in law: demonstrable compliance is mandatory, certification is not

02

NEN 7510:2024 aligns with ISO 27001:2022: four themes, 93 plus 8 controls

03

From 20 February 2027, certification is only possible against the new version

04

The Cyberbeveiligingswet reaches healthcare from 15 August 2026

05

Patient data in AI tools sits squarely inside the standard's scope

Whoever runs information security in Dutch healthcare has two calendars side by side. One belongs to NEN 7510: the revised standard from December 2024, with a certification window closing in February 2027. The other belongs to the Cyberbeveiligingswet, which takes effect on 15 August 2026 and reaches healthcare too. Two movements, one underlying question: can you show that the protection of patient data actually works?

What NEN 7510 is, and why there is no way around it

NEN 7510 is the Dutch standard for information security in healthcare, based on ISO 27001 and extended with healthcare-specific controls. Unlike most standards, it is not optional: for providers processing patient data electronically, NEN 7510 is anchored in law, among others through the decree on electronic data processing by healthcare providers.

The healthcare inspectorate IGJ supervises and expects you to demonstrably work on a management system that meets the standard. Note the distinction: certification is not mandatory, demonstrability is. A certificate is one way to organise that demonstrability, not a goal in itself. In practice, chain partners and buyers do ask for it more and more.

What changed in NEN 7510:2024

On 16 December 2024, the revised standard appeared, aligned with ISO 27001:2022. The structure was cleaned up considerably: fourteen chapters became four themes (organisational, people, physical, and technological), and the controls were consolidated into 93 general controls plus eight healthcare-specific ones. New are controls around cloud, threat intelligence, and data leakage prevention, themes that barely existed in the old 2017 version.

For organisations already on ISO 27001:2022, the switch is manageable. For those still on the old structure, it is more than a textual update: the risk analysis, the statement of applicability, and the internal audits all move with it.

  1. NEN 7510:2017

    The previous version of the standard, based on ISO 27001:2013. The starting point for information security in Dutch healthcare for years.

  2. New

    NEN 7510:2024 published

    The revised standard aligns with ISO 27001:2022: four themes, 93 general and eight healthcare-specific controls.

  3. Implementation window closed

    One year after publication, certificate holders are expected to have adapted their management system to the new version.

  4. The Cyberbeveiligingswet takes effect

    Through this law, NIS2 also reaches mid-sized and large healthcare providers. NEN 7510 is the starting point for meeting the duty of care.

  5. You are here
  6. Certification against NEN 7510:2024 only

    From this date, certification bodies may only certify against the new version of the standard.

The implementation and certification windows follow from the publication of NEN 7510:2024 on 16 December 2024.

The Cyberbeveiligingswet joins in

Healthcare is one of the eighteen sectors under the Cyberbeveiligingswet, the Dutch transposition of NIS2 that takes effect on 15 August 2026. Mid-sized and large providers get a duty of care, a reporting duty for significant incidents, and a registration duty with the NCSC.

Good news for anyone who took NEN 7510 seriously: the law's duty of care and the standard's management system overlap heavily. If you demonstrably work to NEN 7510, most of the foundation for the Cyberbeveiligingswet is already in place. The full picture of that law is in the Netherlands has its NIS2 law.

The blind spot: AI on the work floor

The standard governs systems, processes, and roles. But the biggest day-to-day risk sits in an action no process description covers: a clinician letting a public chatbot summarise a referral letter, or pasting patient details into a prompt to speed up a report. Patient data is special category data, and NEN 7510 demands strict control of exactly this kind of processing.

A policy that says "no patient data in AI" is a start, not control. You want to see which AI tools are actually used, and you want a measure at the moment it goes wrong: while typing, before sending. How the standard and AI use come together is covered in more depth in BIO and NEN 7510: AI and privacy in government and healthcare.

What to arrange now

  1. Map the transition to NEN 7510:2024. New structure, updated risk analysis, statement of applicability, and audits. Certified? Then you want to be over well before 20 February 2027.
  2. Check whether the Cyberbeveiligingswet reaches you and register through mijn.ncsc.nl.
  3. Include AI use in your risk analysis. Which tools are used, with which data, and what has been agreed about them?
  4. Make awareness concrete. Not a yearly e-learning, but a signal at the moment someone types sensitive data somewhere.
  5. Organise the demonstrability. The IGJ, the auditor, and soon the supervisor under the Cyberbeveiligingswet all ask the same thing: show that it works.

Getting sight of AI use does not have to be manual work. The AI Tools module shows which AI tools are in use, checked against a catalog of more than 700 assessed tools, without ever putting an individual employee on screen.

Search tool, vendor or categoryโ€ฆ
700+ tools
ChatGPT๐Ÿ‡บ๐Ÿ‡ธ
HighAllowed
Claude๐Ÿ‡บ๐Ÿ‡ธ
MediumAllowed
DeepSeek๐Ÿ‡จ๐Ÿ‡ณnew
CriticalNot allowed
Perplexity๐Ÿ‡บ๐Ÿ‡ธnew
MediumNo decision yet
Mistral๐Ÿ‡ซ๐Ÿ‡ท
LowNo decision yet
Midjourney๐Ÿ‡บ๐Ÿ‡ธ
MediumNo decision yet

Every tool, scored for risk

700+ AI tools, each scored Low to Critical, with nothing pre-approved or pre-blocked until someone decides.

More about AI Tools

From observing to substantiating

Demonstrability is the hardest requirement in healthcare, because collecting evidence costs time nobody has. BeeSensible turns it around: what happens on the work floor becomes the substantiation. Sensitive data gets a highlight while someone types, in AI tools, email, and chat, and the aggregated figures show that the measure works. Always as counts, never the text, never one person, and with no per-employee breakdown anywhere.

See

Which AI tools are actually in use, how often, and at what risk. Every tool scored against a catalog of more than 700.

See the AI Tools module
Decide

Every tool's status is the organisation's own call: allowed, limited, not allowed. The risk score is advice, never a verdict.

Help

That decision shows up while someone works: a notice on the tool, a highlight while you type. Never a block.

See Realtime Privacy
Substantiate

The same observations become substantiation: aggregated figures per framework and per measure. Never the text, never one person.

Dashboard ยท Accountability GDPRNIS2AI Act
  • Register of AI services

    Vendor, hosting, and a decision per tool

    Substantiated
  • AI literacy

    Highlights at the moment of typing and figures on how they were handled

    Substantiated
  • Appropriate security

    Critical data highlighted and handled before sending

    Substantiated
  • Data breach procedure

    BeeSensible provides the early signal; reporting and follow-up remain your own process

    Not substantiated
One set of observations, usable as substantiation in every framework. BeeSensible supports compliance; it does not make you compliant by itself.

Further reading: BIO and NEN 7510: AI and privacy in government and healthcare and the Netherlands has its NIS2 law.

FAQ

Common questions

Is NEN 7510 mandatory?

Yes. For healthcare providers processing patient data electronically, NEN 7510 is anchored in Dutch law, among others through the decree on electronic data processing by healthcare providers. You must demonstrably comply. Certification is not mandatory, but it is a common way to organise that demonstrability.

What is new in NEN 7510:2024?

The revised standard, published on 16 December 2024, aligns with ISO 27001:2022. The controls were consolidated into 93 general controls across four themes (organisational, people, physical, and technological), plus eight healthcare-specific controls.

How long is the old certificate valid?

Certification bodies may certify against the old version until 20 February 2027; after that only against NEN 7510-1:2024. Certificate holders were asked to adapt their management system within a year of publication, so by December 2025.

What does NEN 7510 have to do with the Cyberbeveiligingswet?

Healthcare is one of the sectors under the Cyberbeveiligingswet, the Dutch transposition of NIS2 that takes effect on 15 August 2026. Mid-sized and large providers get a duty of care, a reporting duty, and a registration duty. A management system based on NEN 7510 is the natural starting point for meeting that duty of care.

Does every healthcare organisation need to be certified?

No. The law asks for demonstrable compliance, not a certificate. The IGJ expects you to demonstrably work on an information security management system that meets the standard. In practice, partners and buyers do increasingly ask for a certificate.

Can patient data go into an AI tool?

As a rule, not into a public or personal AI tool. Patient data is special category data with extra protection under the GDPR, and NEN 7510 requires strict control of exactly this kind of processing. Only in an approved, managed environment with the right agreements can it be appropriate.