What we measure against
One connected environment, five standards. You do not have to pick which one to do first, because the same evidence often counts for several at once.
The five standards
Why NIS2: it is law now, and it sits with the board
The Cyberbeveiligingswet, the Dutch implementation of NIS2, entered into force on 15 August 2026. Anyone falling under it carries a duty of care, a registration duty and a reporting duty with three deadlines. What differs from earlier rules is mostly where the responsibility sits. The management body has to approve the measures itself, supervise their implementation, and within two years of entry into force follow training on identifying and assessing risk. Cybersecurity is no longer something that can be left with IT.
If you do not fall under it yourself, it still reaches you. The directive obliges organizations that do fall under it to manage the risks in their supply chain, and they translate that into requirements in their purchasing contracts. Anyone supplying an essential or important entity gets those questions regardless.
- The ten measure categories from Article 21(2), each with evidence underneath
- The 24-hour, 72-hour and final-report chain tracked from the moment you record an incident
- Your supply chain risk evidenced from the same vendor register
Why ISO 27001: without a certificate some buyers will not seat you
ISO 27001 is what a buyer asks for when they do not want to assess for themselves whether your house is in order. In tenders and larger purchasing processes a certificate is often the form that evidence is asked in, and where it is set as a hard requirement there is no conversation about the substance any more. Outside of tenders the same question returns in the security review your larger customers run before they sign.
The Dutch government now holds itself to the same yardstick. The Baseline Informatiebeveiliging Overheid 2 is structured along ISO 27001 and ISO 27002, and became mandatory for government organizations with the arrival of the Cyberbeveiligingswet. A supplier already working to an ISO standard therefore only has to demonstrate the difference with the BIO, rather than running a second track alongside it.
- The clauses and Annex A, one hundred requirements in total, each tied to its evidence
- A Statement of Applicability you can send along, with the justification for every exclusion
- A statement about the 2022 edition, and it says so
Why NEN 7510: in Dutch healthcare this standard is in the law
For healthcare this is not a judgement call. The Dutch decree on electronic data processing by healthcare providers states in Article 3 that a healthcare provider ensures safe and careful use of its healthcare information system in accordance with NEN 7510 and NEN 7512. The standard is named in regulation, and that carries into the chain: healthcare institutions impose the same requirement on their suppliers and processors contractually, often as a condition in the data processing agreement.
There is a clock running as well. NEN 7510-1:2024 replaced the edition our clause numbering is based on, and existing certificates have to be converted by 20 February 2027 at the latest. We still measure against the older numbering and say so, so you know where your score comes from while you plan that transition.
- The ISO requirements plus three healthcare-specific ones, on patient-data logging and network separation
- The same integrations, so no second track alongside ISO 27001
- The edition measured against is recorded with every decision
Why DORA: your customer is required to demand this of you
DORA has applied since 17 January 2025 and is aimed at financial entities, but it reaches their ICT suppliers just as hard. The regulation prescribes what a contract with an ICT service provider has to contain as a minimum: a description of the service and the locations it is delivered from, service levels, security guarantees, access and audit rights, assistance during incidents, notice periods and termination arrangements.
Supply software, hosting or management to a bank, an insurer, a payment provider or a pension administrator, and those requirements arrive with you through the contract, even if you do not consider yourself a financial party. An audit right your customer is obliged to secure is a good deal easier to grant when the evidence is already sitting there.
- Eleven topics around ICT risk, incidents and outsourced services
- Your vendor register counts directly as evidence here
- The same measurement, so no separate track alongside NIS2
Why GDPR: your data processing agreement already demands this
Security under the GDPR is not a recommendation. Article 32 asks for appropriate technical and organizational measures, and Article 28 obliges a processor to commit to exactly that in the data processing agreement with its controller. So the odds are you have already promised it, just without a way to show at any moment that it holds. The fine ceiling in Article 83 sits at twenty million euro or four percent of worldwide annual turnover, whichever is higher.
What we can and cannot do here is stated plainly. A measurement proves your security of processing and part of your data protection by design. Lawfulness, information duties, data subject rights, a processing register and a DPIA are process and document obligations no technical measurement can see. Those are in the catalog too, without evidence, so you can see what still has to be done by hand.
- Twenty-five operational obligations, not ninety-nine articles largely aimed at regulators
- What can be proven automatically is proven automatically
- The rest is listed without evidence, so you can see what is still missing
SecureTenant is not a certification body and a score is not a certificate. What we deliver is continuous evidence you can show your auditor, and visibility into what is still missing. For NIS2, coverage means a measure category has at least one piece of evidence, which is a lower bar than per-control coverage under ISO 27001.
