![]()
Certificate NL 3069.1.1 covers the Kiteworks Control Plane and Zivver Secure Communications Services.
AMSTERDAM, NETHERLANDS, September 17, 2026 /EINPresswire.com/ -- Kiteworks, which empowers organizations to ensure regulatory compliance and manage risk across every exchange of sensitive data, today announced that it has achieved NEN 7510-1:2024 certification, the Netherlands' information-security management standard for healthcare organizations. The certificate was issued by Brand Compliance B.V., an independent accredited third party.
The certificate covers Kiteworks USA LLC and its affiliates, including Kiteworks Europe AG, Kiteworks PTE LTD, Kiteworks BG Ltd, Dracoon GmbH, 123formbuilder S.R.L., and Zivver B.V. It applies to two products that are both covered under the single certification: the Kiteworks Control Plane and Zivver Secure Communications Services.
The certification is critical for protecting Dutch healthcare organizations at a time of heightened cyber risk. In August 2025, a ransomware attack on Clinical Diagnostics, a Dutch laboratory that processes cervical cancer screening tests, exposed records containing national identification numbers and other sensitive data belonging to approximately 850,000 people. In May 2026 the Dutch Health and Youth Care Inspectorate (IGJ) concluded that Clinical Diagnostics had not complied with the legally required NEN 7510 information security standard at the time of the attack. The regulator identified several shortcomings, including the absence of an independent information security audit and insufficient periodic assessment of information security risks, and stated that working in accordance with NEN 7510 could have reduced both the likelihood and the impact of the incident.
The breach occurred not inside a hospital, but at a third-party laboratory entrusted with patient data, underscoring why information security requirements must extend across the wider healthcare ecosystem. Dutch regulators in fact are seeing more incidents like the Clinical Diagnostics case in industries outside of healthcare: the Dutch Data Protection Authority logged 39,407 data breach notifications across all industries in 2025, up from 37,839 in 2024.
“Every healthcare CISO I sit down with asks some version of the same question, not whether we say our platform is secure, but whether anyone independent has checked,” said Rick Goud, Field CTO, Kiteworks. “Zivver already had NEN 7510 certification, but the fact that Kiteworks also has it changes that conversation. The Kiteworks platform and affiliate solutions, including Zivver, were independently audited against the exact standard our customers are being held to themselves, so they don’t have to take our word for it.”
NEN 7510-1:2024 is an update to the Netherlands’ healthcare information-security standard, published in December 2024 and is following the exact same controls as ISO 27001:2022, but with specific additions/details for healthcare organizations. NEN 7510 compliance has been a legal requirement for Dutch healthcare providers since 2008, and since 2023 organizations must prove their compliance rather than simply attest to it. The standard also overlaps with the Netherlands' newer cybersecurity law implementing the EU's NIS 2 Directive, so meeting NEN 7510 helps satisfy some of those requirements too.
“Plenty of vendors will hand a Dutch healthcare CISO a checklist and call it compliance,” said Goud. “That’s not enough when the deadline is real and the number of breach notifications keep climbing. What healthcare CISOs and their organizations need is a platform that was independently audited the same way they’re about to be, not a patchwork of point tools that each pass their own narrow test while the data moving between them stays completely ungoverned. One governed platform means one audit trail, and one report an auditor can actually follow, not five separate logs stitched together after the fact.”
That's the differentiation. Most vendors offer software a Dutch healthcare organization can configure toward NEN 7510 compliance, but the software itself was never audited against the standard. Kiteworks' platform is the certified system, with one audit trail spanning email, file sharing, file transfer, forms, APIs, and agents and one report an auditor can follow, instead of piecing one together from separate tools with separate logins—and separate blind spots. Most organizations around the world can't do that today: half cannot produce a complete AI data access audit record within a single business day, and just 17% can produce one within an hour.
Data governance is especially challenging in Europe, according to a recent Kiteworks study on data security and compliance risk. European organizations report stronger general security controls than the rest of the world, but weaker AI governance, and just 26% have deployed purpose binding, the technical control that restricts AI agents to their authorized tasks and data. The certified Kiteworks platform closes that gap, applying the same access controls and audit trail that govern human users to the AI agents now touching patient data.
Learn more about Kiteworks' NEN 7510-1:2024 certification by reading the Compliance Brief.
About Kiteworks
Kiteworks' mission is to empower organizations to effectively manage risk in every send, share, receive, and use of private data. The Kiteworks platform provides customers with a secure data exchange that delivers data governance, compliance, and protection in a unified control plane. Kiteworks unifies, tracks, controls, and secures sensitive data moving within, into, and out of their organization, significantly improving risk management and ensuring regulatory compliance on all private data exchanges. Headquartered in Silicon Valley, Kiteworks protects over 100 million end-users and thousands of global enterprises and government agencies.
David Schutzman
Kiteworks
+1 203-550-8551
Visit us on social media:
Legal Disclaimer:
EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.
![]()
Media gallery

