Organizations that work with medical data sooner or later run into the question: do we need ISO 27001 or NEN 7510? Sometimes a client explicitly asks for one of the two, sometimes it is in a tender, and sometimes it is unclear why one standard would exclude the other. The confusion is understandable, because the two standards resemble each other strongly and overlap for a large part. Yet there are substantial differences that determine what the right choice is for your organization. In this article we explain what both standards entail, where they overlap, where they diverge and how to arrive at a well-founded choice.
## What is ISO 27001?
ISO 27001 is the international standard for an information security management system (ISMS). The standard describes how an organization keeps a structured and demonstrable grip on information security: from risk assessment and setting policy to implementing controls and continuously improving them. ISO 27001 is sector-independent and recognized worldwide. The current version is ISO 27001:2022, with an updated set of controls in Annex A.
The characteristic feature of ISO 27001 is that the standard does not prescribe exactly which measures you must take, but that you determine what is proportionate based on a risk analysis. In the Statement of Applicability (SoA) you record which measures you apply and why. Certification runs through an accredited certification body.
## What is NEN 7510?
NEN 7510 is the Dutch standard for information security in healthcare. The standard is explicitly based on ISO 27001 and the associated set of controls from ISO 27002, but adds healthcare-specific requirements. These are additional measures suited to working with personal health information: think of stricter requirements around access to patient data, logging of who has viewed which data, and the handling of medical professional confidentiality.
NEN 7510 consists of several parts. NEN 7510-1 describes the requirements for the management system, comparable to ISO 27001. NEN 7510-2 contains the controls, derived from ISO 27002 and supplemented with healthcare-specific detail. For Dutch healthcare providers, NEN 7510 is in practice the standard that serves as the fulfillment of the legal obligation to provide appropriate security for health data.
## The overlap: the foundation is the same
The most important thing to understand is that NEN 7510 and ISO 27001 share the same foundation. Both revolve around a management system with risk-driven decision-making, the same process structure of plan, do, check and act, and largely the same controls. Whoever has ISO 27001 in order already has the vast majority of NEN 7510 in place too. The structure of the management system requirements is nearly identical, which makes combining both standards very workable.
That also explains why an integrated approach in healthcare is often logical. You build one management system that meets both standards, with NEN 7510 as the healthcare-specific layer on top of the ISO 27001 foundation. So you do not need to set up two separate systems.
## The differences: sector, origin and emphasis
Where does the difference lie then? On three points. First the scope: ISO 27001 is generic and international, NEN 7510 is specific to the Dutch healthcare sector. Second the origin and recognition: ISO 27001 is an internationally recognized certificate that carries meaning worldwide, while NEN 7510 mainly holds authority within the Netherlands and the healthcare chain. Third the substantive emphasis: NEN 7510 places extra weight on the confidentiality and traceability of patient data, with more concrete requirements around authorization, logging and professional confidentiality than the generic ISO standard.
In practice this means that a healthcare institution operating only in the Netherlands often has enough with NEN 7510, while a supplier doing business internationally benefits from ISO 27001, possibly supplemented with NEN 7510 if healthcare clients ask for it.
## What do you need?
The choice depends on who you serve and what is asked of you. A healthcare provider that falls under Dutch legislation for health data generally ends up with NEN 7510, because that standard concretely fulfills the legal obligation to provide appropriate security. A software supplier or hosting party delivering services to healthcare regularly has NEN 7510 prescribed in the contract or the tender, and will therefore have to be able to demonstrate it.
An organization operating internationally or serving other sectors besides healthcare often chooses ISO 27001 as a basis, because that certificate is more widely recognized. If you serve both healthcare and other sectors, an integrated certification against ISO 27001 and NEN 7510 is usually the most efficient route. You set up the work once and cover both.
It is important not to approach the choice merely as a box-ticking exercise. The question is not only which certificate hangs on the wall, but whether your information security genuinely aligns with the risks of working with health data. A well-designed management system provides that assurance; the certificate is the demonstrable confirmation of it.
## From choice to certification
Once the standard choice is clear, the process broadly follows the same path as any ISO certification: a gap analysis to determine where you stand, setting up or supplementing the management system, an internal audit to test whether it works, and finally the certification audit by an accredited body. With an integrated approach you carry out those steps once for both standards. That saves considerably in lead time and internal effort.
Secure Audit guides healthcare organizations and their suppliers in the choice between and the implementation of ISO 27001 and NEN 7510, including integrated processes. The certification audit itself is carried out by an accredited certification body. Get in touch for a no-obligation conversation about your situation.
Frequently asked questions
Is NEN 7510 mandatory for healthcare organizations?+
NEN 7510 is not literally mandated by law, but in practice serves as the standard that fulfills the legal obligation to provide appropriate security for health data. Clients and tenders in healthcare ask for it as standard, which effectively makes it a requirement.
Can you certify ISO 27001 and NEN 7510 at the same time?+
Yes, and that is often the most efficient route. Because NEN 7510 is based on ISO 27001, you can set up one management system that meets both standards and have an integrated audit carried out.
If I have ISO 27001, do I automatically comply with NEN 7510?+
Largely, but not entirely. NEN 7510 adds healthcare-specific requirements, including around access to patient data, logging and professional confidentiality. You must explicitly implement and demonstrate those additional measures.
What is the difference between NEN 7510, NEN 7512 and NEN 7513?+
NEN 7510 is the overarching standard for information security in healthcare. NEN 7512 specifically covers trust in electronic data exchange between healthcare parties, and NEN 7513 covers the logging and recording of access to electronic patient records.
Which standard does a software supplier for healthcare choose?+
That depends on the client demand. If the supplier mainly delivers to Dutch healthcare parties, NEN 7510 is usually required. If the supplier also works internationally or outside healthcare, ISO 27001 as a basis with NEN 7510 on top is usually the best combination.
Need help with compliance?
Need to comply with ISO 27001, ISO 42001, NEN 7510, NIS2 or DORA, or do you need a SOC 2 report? We guide you through the entire process: from gap analysis to implementation.
Explore Compliance ServicesAbout the author
Partner | IT Auditor