Kiteworks Achieves NEN 7510-1:2024 Certification for Healthcare Data Security in the Netherlands
Ask a Dutch healthcare CISO whether a vendor’s platform is secure, and most will nod politely and move on. Ask whether an independent auditor has verified that platform against the exact standard regulators use to judge the CISO’s own organization, and the conversation stops being polite. That is the question Kiteworks set out to answer for itself rather than leave to a sales deck.
Kiteworks, which helps organizations manage risk across every exchange of sensitive data, has achieved NEN 7510-1:2024 certification, the information security management standard Dutch healthcare organizations are legally required to meet. Brand Compliance B.V., an independent accredited third party, issued the certificate under number NL 3069.1.1. It covers Kiteworks USA LLC and its affiliates, including Kiteworks Europe AG, Kiteworks PTE LTD, Kiteworks BG Ltd, Dracoon GmbH, 123FormBuilder S.R.L., and Zivver B.V. Two products fall under that one certification, the Kiteworks Control Plane and Zivver Secure Communications Services.
NEN 7510 compliance has been a legal obligation for Dutch healthcare providers since 2008, but the bar rose in 2023, when organizations were required to start proving compliance rather than simply attesting to it. The 2024 update to the standard, published in December 2024, follows the same controls as ISO 27001, with healthcare-specific additions layered on top, and it overlaps with the Netherlands’ newer cybersecurity law implementing the EU’s NIS 2 Directive. For a healthcare organization already carrying GDPR obligations, that overlap is welcome. A single NEN 7510 audit program now does double duty toward NIS 2 evidence, rather than requiring a separate parallel exercise for each framework.
None of this is abstract for the healthcare CISOs and compliance officers reading this. A ransomware attack on a Dutch laboratory in August 2025, and a regulatory finding that followed it nine months later, spell out exactly what happens when information security requirements are treated as a checklist rather than an audited discipline. That incident is the backdrop against which this certification should be read, and it is worth walking through in detail before returning to what Kiteworks has certified.
Key Takeaways
1. Kiteworks now holds NEN 7510-1:2024 certification.
Certificate NL 3069.1.1, issued by independent accredited body Brand Compliance B.V., covers both the Kiteworks Control Plane and Zivver Secure Communications Services under a single certification.
2. The certification answers a question Dutch healthcare CISOs are already asking.
It gives customers proof that the platform itself, not just its configuration options, was independently audited against the same standard their own organizations must meet.
3. A real breach shows what non-compliance costs.
Regulators found that Clinical Diagnostics, a Dutch laboratory hit by ransomware in August 2025, had not complied with NEN 7510 at the time of the attack that exposed data on roughly 850,000 people.
4. Breach notifications in the Netherlands are rising, not falling.
The Dutch Data Protection Authority logged 39,407 breach notifications across all industries in 2025, up from 37,839 in 2024.
5. The gap extends to AI governance.
Kiteworks’ own 2026 survey data shows most organizations cannot produce a complete AI data access audit record quickly, and Europe’s own security strength has not yet carried over into AI-specific controls, a gap the certified platform is built to close.
The Breach That Exposed the Compliance Gap in Clinical Diagnostics’ Cervical Cancer Screening Incident
In August 2025, a ransomware attack hit a Dutch laboratory that processes cervical cancer screening tests for the country’s national screening program. The attack exposed records belonging to approximately 850,000 people, including national identification numbers, prompting the Dutch Data Protection Authority to open an investigation.
The more consequential finding came later. In May 2026, the Dutch Health and Youth Care Inspectorate, known as the IGJ, concluded that the laboratory, Clinical Diagnostics, had not complied with the legally required NEN 7510 information security standard at the time of the attack. The regulator’s shortcomings list was specific. No independent information security audit had been performed, and periodic assessment of information security risks was insufficient. The IGJ went further, stating that working in accordance with NEN 7510 could have reduced both the likelihood and the impact of the incident.
For a Chief Compliance Officer or Head of GRC, that finding is the whole argument in one sentence. NEN 7510 is not a nice-to-have framework a healthcare organization can defer, and it is not satisfied by good intentions or a policy document sitting in a shared drive. Regulators have now shown, in a documented enforcement finding against a named organization, that failing to maintain it changes outcomes when an attack happens. An inspectorate does not need to speculate about what an independent audit or a properly run risk assessment would have found. It can point to the incident report and say plainly that the absence of both made the breach worse than it needed to be.
The location of the breach matters as much as its scale. It did not happen inside a hospital. It happened at a third-party laboratory entrusted with patient data, a reminder that information security requirements must extend across the wider healthcare ecosystem, vendors and processors included, not stop at the hospital’s own walls. Every hospital, insurer, and health system that sent screening samples to that laboratory inherited a portion of this incident’s fallout, regardless of how well its own internal security program was run. And the Clinical Diagnostics case is not an isolated data point. The Dutch Data Protection Authority logged 39,407 data breach notifications across all industries in 2025, up from 37,839 the year before. Regulators in the Netherlands are seeing more incidents like this one, not fewer, which is exactly the environment in which a compliance officer must defend every vendor relationship touching patient data.
“Every healthcare CISO I sit down with asks some version of the same question, not whether we say our platform is secure, but whether anyone independent has checked,” said Rick Goud, Field CTO, Kiteworks. “Zivver already had NEN 7510 certification, but the fact that Kiteworks also has it changes that conversation. The Kiteworks platform and affiliate solutions, including Zivver, were independently audited against the exact standard our customers are being held to themselves, so they don’t have to take our word for it.”
What Data Compliance Standards Matter?
What NEN 7510-1:2024 Requires and Why the 2023 Proof Requirement Changed Everything
NEN 7510 is the Netherlands’ information security standard for healthcare organizations, a specific application of regulatory compliance law, and it has carried the force of law since 2008. For fifteen years, Dutch healthcare organizations could largely self-attest to compliance. That changed in 2023, when organizations became required to prove their compliance rather than simply declare it, a shift that turned NEN 7510 from a policy statement into an audit obligation.
The 2024 version of the standard, NEN 7510-1:2024, was published in December 2024. It follows the same control structure as ISO 27001 compliance, the international information security management standard, with specific additions and details layered in for healthcare organizations. Because the underlying controls track ISO 27001:2022 so closely, an organization that has done the work to meet NEN 7510 has also made significant progress against the broader international standard, and vice versa.
The standard also overlaps with the Netherlands’ implementation of the EU’s NIS 2 Directive, the cybersecurity law that expanded incident reporting and risk management obligations across critical sectors, healthcare among them. Meeting NEN 7510 helps satisfy some of those NIS 2 compliance requirements as well, which matters to any Dutch healthcare compliance officer trying to avoid maintaining parallel, overlapping audit programs for standards that share most of their DNA.
For a vendor, meeting this bar means submitting the actual platform, not a set of configuration guidelines, to an independent accredited auditor. That distinction is the center of what Kiteworks is announcing. It is also the distinction a compliance officer should be asking about in every vendor review from now on, because “our software can be configured to support NEN 7510” and “our software was independently audited against NEN 7510” are two very different sentences, and only one of them survives contact with a regulator’s follow-up questions.
Inside Certificate NL 3069.1.1 and What the Independent Audit Covered
Certificate NL 3069.1.1 was issued by Brand Compliance B.V., an independent accredited third party, following an audit against the NEN 7510-1:2024 standard. The certification decision came on August 1, 2026, the certificate itself was issued August 6, 2026, and it remains valid through July 31, 2029. The certificate’s scope is broad by design. It covers Kiteworks USA LLC and its affiliates, including Kiteworks Europe AG, Kiteworks PTE LTD, Kiteworks BG Ltd, Dracoon GmbH, 123FormBuilder S.R.L., and Zivver B.V.
Two products fall under that single certification, the Kiteworks Control Plane and Zivver Secure Communications Services. Zivver, the secure email and secure communications provider Kiteworks acquired, already held NEN 7510 certification on its own. What changes with this announcement is that the Kiteworks Control Plane itself, the governance and management layer spanning the broader platform, now carries the same independent certification, under the same audit, alongside Zivver.
That matters for any Dutch healthcare organization that has already standardized on Zivver for secure communications and is now evaluating a broader Kiteworks secure data exchange deployment for file sharing, managed file transfer, forms, and API-driven data movement. There is no longer a gap between what was audited and what the organization is deploying. A procurement team that once had to explain to an assessor why the secure email piece was certified and the rest of the data exchange environment was not can now point to one certificate covering both.
It is also worth being precise about what a certification like this does and does not claim. It confirms that Brand Compliance B.V. reviewed the named products against the NEN 7510-1:2024 control set and found them conformant at the time of the audit. It is not a guarantee against every future incident, and it does not relieve a healthcare organization of its own obligation to configure, deploy, and operate the platform correctly within its own environment. What it does remove is the uncertainty at the platform layer itself, the question of whether the software a customer is building its own compliance program on top of was ever independently checked in the first place.
Read the NEN 7510-1:2024 Compliance Brief for the full scope of what the certification covers.
One Platform, One Audit Trail, and Why Point Tools Fall Short on Evidence-Quality Compliance
The differentiation Kiteworks is claiming here is specific, and it is worth stating precisely because it is easy to overstate. Most vendors selling into Dutch healthcare offer software that a customer can configure toward NEN 7510 compliance. The software itself was never independently audited against the standard. The compliance burden, and the risk if an auditor disagrees with the customer’s configuration choices, sits entirely with the customer.
“Plenty of vendors will hand a Dutch healthcare CISO a checklist and call it compliance,” Goud said. “That’s not enough when the deadline is real and the breach notifications keep climbing. What they need is a platform that was independently audited the same way they’re about to be, not a patchwork of point tools that each pass their own narrow test while the data moving between them stays completely ungoverned. One governed platform means one audit trail, and one report an auditor can actually follow, not five separate logs stitched together after the fact.”
Kiteworks’ platform is the certified system, with a single audit trail spanning email, file sharing, file transfer, forms, APIs, and agents, and one report an auditor can follow instead of piecing one together from separate tools with separate logins and separate blind spots. That single-audit-trail model addresses a gap most organizations are living with today, and the gap is not a small one. According to Kiteworks Data Security and Compliance Risk: 2026 Annual Survey Report, half of organizations cannot produce a complete AI data access audit record within a single business day, and just 17% can produce one within an hour. When a regulator’s clock is measured in hours or days, an audit log that takes a week to assemble is not compliance evidence, no matter how compliant the underlying controls were.
Picture the alternative most Dutch healthcare organizations are living with instead. Separate logins for the email gateway, the file transfer server, the forms tool, and whatever system routes data to an AI application, each producing its own log format, on its own retention schedule, in its own console. When the IGJ or an internal auditor asks for a complete record of who accessed a specific patient’s data and when, someone must manually reconcile four or five systems that were never designed to talk to each other. That reconciliation work is where evidence quality quietly breaks down, not because the underlying controls were weak, but because no one can produce a single, coherent account of them fast enough to matter.
This is the argument that resonates with a Chief Compliance Officer or Head of GRC more than any capability list. A certified platform with a unified audit trail turns a multi-week evidence-gathering exercise into a single report, which is the difference between meeting a regulator’s deadline and missing it, and between an assessment that closes cleanly and one that drags into a formal enforcement finding.
Closing Europe’s AI Governance Gap in Regulated Healthcare Data
The certification lands at a moment when the compliance conversation in European healthcare is expanding to include AI. The 2026 Annual Survey Report found that European organizations’ dominant pattern is strong general security infrastructure paired with AI governance that has not kept pace, a mismatch the report ties to GDPR and NIS 2 driving compliance investment faster than technical AI controls. Across the full survey, just 26% of organizations, in Europe and elsewhere, have deployed purpose binding, the technical control that restricts AI agents to their authorized tasks and data.
The certified Kiteworks platform is built to close that specific gap, applying the same access controls and audit trail that already govern human users to the AI agents now touching patient data. That framing matters because regulators regulate data, not the identity of whoever or whatever is accessing it. NEN 7510, like HIPAA in the United States, does not carry an exemption for records an AI agent reads instead of a person. A CISO who has extended access controls and data governance to cover agentic access on a certified platform is in a materially stronger position when an assessor or an inspector like the IGJ comes asking who, or what, touched a given record and under what authorization.
Ownership of that AI access question is still unsettled inside most organizations. Different surveys put the CISO, the CIO, and the Chief AI Officer each in the primary-owner seat depending on who ran the survey, and plenty of healthcare organizations have no single named person accountable for agent behavior at all. A NEN 7510 certified platform does not resolve that internal accountability debate on its own, but it does mean whoever is ultimately assigned the job inherits a system where the access controls and the audit trail already exist, rather than having to build agent governance from nothing while the rest of the organization argues over who owns it.
To learn more about deploying a NEN 7510-1:2024 certified platform for Dutch healthcare data security, schedule a custom demo today.
Frequently Asked Questions
Certificate NL 3069.1.1, issued by independent accredited body Brand Compliance B.V., covers Kiteworks USA LLC and its affiliates, including Kiteworks Europe AG, Kiteworks PTE LTD, Kiteworks BG Ltd, Dracoon GmbH, 123FormBuilder S.R.L., and Zivver B.V. It applies to two products under one certification, the Kiteworks Control Plane and Zivver Secure Communications Services.
No. NEN 7510 compliance has been a legal requirement for Dutch healthcare providers since 2008, and since 2023 organizations must prove that compliance themselves rather than attest to it. A vendor’s independent certification is strong supporting evidence in that proof, and it removes the guesswork of whether the underlying platform meets the standard, but the healthcare organization still owns its own regulatory compliance program and its own audit. What a certified vendor changes is the shape of that audit. Instead of an assessor having to evaluate an unaudited product from scratch, the healthcare organization can point to an existing, independently issued certificate for the platform layer and focus its own audit effort on how it configured and operates that platform, which is a meaningfully smaller lift.
NEN 7510-1:2024, published in December 2024, follows the same controls as ISO 27001 compliance, with specific additions and details for healthcare organizations layered on top. It also overlaps with the Netherlands’ cybersecurity law implementing the EU’s NIS 2 Directive, so meeting NEN 7510 helps satisfy some NIS 2 obligations as well.
In May 2026, the Dutch Health and Youth Care Inspectorate (IGJ) concluded that Clinical Diagnostics, the laboratory hit by ransomware in August 2025, had not complied with NEN 7510 at the time of the attack, which exposed data on roughly 850,000 people, including national identification numbers. The regulator cited the absence of an independent information security audit and insufficient periodic assessment of information security risks, and stated that working in accordance with NEN 7510 could have reduced both the likelihood and the impact of the incident. For compliance officers evaluating vendors and processors, the finding reframes the question from whether a partner claims to follow good security practice to whether that practice has been independently checked. Kiteworks’ audit trail and ISO 27001 aligned controls are built to help customers avoid exactly that kind of finding.
The certification itself covers the Kiteworks Control Plane and Zivver Secure Communications Services, and that same platform applies the same access controls and audit trail that govern human users to AI agents accessing patient data. That matters given that just 26% of organizations, per Kiteworks Data Security and Compliance Risk: 2026 Annual Survey Report, have deployed purpose binding, the control that restricts AI agents to their authorized tasks and data. Learn more about how Kiteworks Compliant AI extends that same governance model to agentic access.
Additional Resources
- Blog Post The Tug-of-War Over Your Data: How the CLOUD and SHIELD Acts Pit Security vs. Privacy
- Blog Post Secure Sensitive Data by Mapping DSPM to Your Compliance Goals
- Brief Top 3 FERPA Violations and How to Avoid Them
- Blog Post Executive Order 14117: Protecting Americans’ Bulk Sensitive Personal Data
- Blog Post Need NIS2 Compliance? Start With ISO 27001