# NEN 7510 awareness training: what the standard and the IGJ ask (2026)

> NEN 7510-1:2024 has applied since 1 December 2024, with awareness in control 6.3. What the standard and the Dutch healthcare inspectorate ask, and how to make training auditable.

- Canonical: https://cyberpulse.it/en/nen-7510-awareness-training
- Dutch version: https://cyberpulse.it/nen-7510-awareness-training
- Published: 2026-08-09
- Updated: 2026-08-25
- Publisher: CyberPulse (https://cyberpulse.it)

NEN 7510 is the Dutch healthcare information security standard, and staff awareness is an explicit part of it. Since 1 December 2024, NEN 7510-1:2024 has applied; it follows the structure of ISO 27002:2022 and places awareness in control 6.3. The Dutch Health and Youth Care Inspectorate (IGJ) expects you to be able to demonstrate compliance. This page explains what that means for your practice, institution or healthcare IT organisation, and how to make awareness training auditable.

The standard applies to healthcare providers in the Netherlands, but it does not stop at the Dutch border: if you supply software or IT services to a Dutch healthcare provider from abroad, you will meet NEN 7510 in their contracts and processing arrangements.

## NEN 7510-1:2024: what has changed?

Since 1 December 2024 the revised standard has applied: NEN 7510-1:2024, together with NEN 7510-2:2024. If your policies and procedures are still based on the previous version, this is the moment to bring your documentation, including your training programme, into line with the new structure.

The key change for awareness: part 1 now follows the structure of ISO 27002:2022. Awareness, education and training therefore sit in control 6.3: the same control you meet in [ISO 27001 awareness training](/en/iso-27001-awareness-training). That is practical news for healthcare organisations working with both frameworks: you set up your training approach once and serve two standards with it.

| Element | Situation since 1 December 2024 |
|---|---|
| Applicable version | NEN 7510-1:2024 + NEN 7510-2:2024 |
| Structure | Follows ISO 27002:2022 |
| Awareness | Control 6.3: awareness, education and training |
| Supervision | The IGJ expects demonstrable compliance |
| Independent assessment | At least once every 3 years |

Who is this relevant for? The full breadth of healthcare: GP, dental and physiotherapy practices, mental health institutions, long-term and elderly care organisations, hospitals, and the healthcare IT suppliers that process patient data on behalf of care providers. Wherever staff work with medical data day in, day out, the human side of information security matters at least as much as the technology. A record left open on an unattended workstation, a phishing email clicked during a busy clinic, an export on a USB stick: there is a reason the standard addresses this kind of risk with a control of its own.

In audits and tenders, make sure you are working from the right version. References to control numbers from the previous version no longer match the ISO 27002:2022 structure, and assessors notice that immediately.

## Which requirements apply to awareness? (control 6.3)

Control 6.3 is titled 'Information security awareness, education and training'. The core of the requirement:

> Personnel and relevant interested parties receive appropriate awareness, education and training, with regular updates, relevant to their job function.
> – control 6.3 (ISO 27002:2022 structure, followed by NEN 7510-1:2024)

That single sentence contains three requirements your programme has to cover.

### 1. Everyone takes part, including 'relevant interested parties'

The control is not limited to employees on permanent contracts. In healthcare, think of locums, agency staff, students on placement, volunteers and external practitioners with access to patient data. If someone can get into your systems, they belong in your training programme.

### 2. Relevant to the job function

One generic e-learning for the whole organisation is not what the control intends. 'Relevant to their job function' means that a receptionist who verifies identities all day and gives information over the phone needs different emphases from a clinician, and that a healthcare IT administrator with elevated rights deserves a different programme again. Differentiate at minimum between clinical staff, support functions, IT and the management body.

### 3. Regular updates

Training once on joining is not enough: the control explicitly asks for regular updates. Threats change (phishing gets more convincing, working practices shift) and knowledge fades. A continuous programme of short, frequent learning moments works better in practice than one mandatory afternoon a year.

ISO 27002 adds, under control 6.3, that understanding should be tested. An attendance list proves attendance, not understanding; a quiz or test does. And anyone who is ISO 27001 certified alongside NEN 7510, or wants to be, knows clause 7.2(d) of that standard: retain documented information as evidence of competence. Test results per employee are exactly that evidence.

### Practical examples: what awareness in healthcare is about

The abstract requirement becomes concrete as soon as you translate it into situations your staff meet every day. Use scenarios like these as course material: they make the training recognisable and testable:

- **The open patient record session.** A clinician is called away while updating a record and leaves the workstation open in a room others walk through. The desired reflex (always lock, however briefly you step away) is behaviour you train, not technology you install.
- **Curiosity versus need.** A public figure is admitted, or a colleague is on another ward. Access to patient data belongs with your role in that patient's care; training makes it discussable why 'just a quick look' without a need is not on: before anyone is tempted.
- **The 'family member' on the phone.** Reception takes a call from someone claiming to be a patient's son, asking for information. Training reception staff to verify and call back on a known number is worth more than a general lecture on phishing.
- **Community care on the road.** A district nurse works on a tablet between client addresses, sometimes on someone else's wi-fi, with family looking on in the living room. Logging in safely, shielding the screen and sharing nothing through personal apps are the core skills here: a very different context from the office.
- **The export for the meeting.** An employee wants to take an overview containing patient data to an external meeting and puts it on a USB stick or sends it to a private email address. Training teaches the safe alternative, and how to use it.

Note: these are training examples, not extra requirements from the standard. The standard asks for appropriate, role-specific awareness: scenarios like these are how you make 'appropriate' real, from consulting room to district team.

## What does the IGJ expect?

The Dutch Health and Youth Care Inspectorate (IGJ) expects demonstrable compliance with NEN 7510. In practice that makes the standard anything but optional: it is anchored in regulation, including the Wabvpz (the Dutch act on additional provisions for processing personal data in healthcare) and the Decree on electronic data processing by healthcare providers. If you process or exchange patient data electronically, there is no way around it.

Three points to remember:

- **Demonstrable is the key word.** 'We take security seriously' is not an answer a regulator accepts. You have to be able to show what you have arranged: policy, controls and staff awareness.
- **Independent assessment at least once every three years.** Compliance with the standard must be assessed independently on a periodic basis. Make sure your training file is in order before that assessment, not after.
- **Awareness is part of the standard.** Control 6.3 belongs to the compliance you demonstrate. An organisation that has everything technically locked down but cannot produce training records has a visible gap.

For a smaller practice this can feel heavy, but scale works in your favour: with fifteen staff, a watertight training record is quicker to set up than in a hospital. What counts is not the size of your programme, but whether you can show per person that it is running. Start small (phishing, locking screens, reporting) and expand by job group.

The GDPR comes on top of that. Healthcare organisations process health data, and the GDPR too expects [demonstrable awareness as an appropriate organisational measure](/en/gdpr-security-awareness-training) under Article 32. The data protection officer supervises exactly that under Article 39. The good news: two frameworks, one solution. A well-documented awareness programme serves NEN 7510 and the GDPR at the same time.

## Making training auditable

The common thread in both the standard and the supervision is evidence. Assessors generally want to see four things:

1. **A training plan**: who trains when, in what, and why that fits the job function.
2. **Participation records**: recorded per employee: what was taken, and when.
3. **Evidence of competence**: test or quiz results and certificates per role.
4. **Effectiveness measurement**: proof that the programme works, for instance through phishing simulations that measure behaviour rather than knowledge alone.

### Checklist: how to make awareness auditable

- Map who has access to patient data, including locums, agency staff and external parties.
- Assign an appropriate training programme per job group.
- Register participation and results per employee, preferably automatically.
- Test understanding with quizzes and record the results as evidence of competence.
- Plan regular updates rather than a single moment each year.
- Measure behaviour with periodic phishing simulations.
- Keep certificates and reports centrally, ready for the independent assessment.

That administrative part need not be manual work. CyberPulse automatically records training participation, quiz results, certificates and phishing outcomes per employee: precisely the evidence an assessor or regulator asks for. With weekly micro-learning you also meet the regular-updates requirement of control 6.3 as a matter of course. [Start a free trial](/trial) and watch your training file build itself.

Want the wider picture: which laws and standards set training requirements alongside NEN 7510, from the Dutch Cybersecurity Act to ISO 27001? Read the overview [is security awareness training mandatory?](/en/security-awareness-training-mandatory)

## Frequently asked questions

### Is NEN 7510 legally mandatory?

NEN 7510 is a standard, not a law. But it is anchored in regulation: the Wabvpz and the Decree on electronic data processing by healthcare providers refer to it, among others, and the Dutch Health and Youth Care Inspectorate (IGJ) expects demonstrable compliance. In practice, therefore, the standard is not optional for care providers that process patient data electronically: you must be able to show that you meet it, including the awareness requirements of control 6.3.
### What changed with NEN 7510-1:2024?

Since 1 December 2024, NEN 7510-1:2024 applies, together with NEN 7510-2:2024. The main change: part 1 now follows the structure of ISO 27002:2022. Awareness, education and training therefore sit in control 6.3, the same control as in ISO 27001. Check that your policy, documentation and training programme refer to the new structure.
### How often must an independent assessment take place?

An independent assessment of compliance must take place at least once every three years. Make sure your training administration (participation records, test results and certificates) is complete before that assessment. Awareness is part of the standard through control 6.3 and therefore counts towards what you demonstrate.
### Must all employees take an awareness training course?

Control 6.3 covers personnel and relevant interested parties. In healthcare that means locums, agency staff, students on placement, volunteers and external practitioners with access to patient data as well. The training must be appropriate to the job function (a receptionist, a clinician and an IT administrator need different emphases) and must be repeated regularly.
### What is the difference between NEN 7510 and ISO 27001?

NEN 7510 is the Dutch information security standard for healthcare. Since the 2024 version, part 1 follows the structure of ISO 27002:2022, which means the awareness requirement (control 6.3) lines up with ISO 27001. ISO 27001 certification is voluntary but often contractually driven; compliance with NEN 7510 is expected by the IGJ in Dutch healthcare and is anchored in regulation. One well-designed training programme can serve both frameworks.
### How do I demonstrate that my team is trained?

With four kinds of evidence: a training plan, participation records per employee, test or quiz results as evidence of competence, and effectiveness measurements such as phishing simulation results. A platform that records this automatically saves manual work: CyberPulse registers participation, quiz results, certificates and phishing outcomes per employee, so your file is ready for the independent assessment.

## Sources

- [IGJ, questions about NEN 7510](https://www.igj.nl/vraag-en-antwoord/vragen-over-nen-7510)
- [NEN, NEN 7510-1:2024](https://www.nen.nl/nen-7510-1-2024-nl-331311)
- [EUR-Lex, GDPR (Regulation (EU) 2016/679)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679)
