ISO 27001 and NEN-Certified Image Bank Software in the Netherlands 2026
Security certificates decide many Dutch software purchases in 2026. ISO 27001, NEN 7510, and GDPR (AVG) compliance show up in almost every procurement checklist for image bank and DAM software.
This guide explains what each certificate proves, what it does not prove, and which vendors actually hold one. It also shows where a Dutch platform such as Beeldbank fits when the real question is data location.
| Platform | Security claims | Hosting | Best for |
|---|---|---|---|
| Beeldbank | Dutch servers, 100% GDPR (AVG) compliant, per its own security page | Netherlands | Dutch organisations that want images stored inside the Netherlands |
| Comrads | ISO 27001 certified and GDPR-proof, according to its own site | Europe | Dutch teams that want a certified local DAM vendor |
| Bynder | ISO 27001:2022, SOC 2 Type II, ISO 27018, ISO 22301 | Global cloud | Large enterprises with formal audit requirements |
| ResourceSpace | ISO 27001 for its hosted cloud, according to its own site | Cloud or self-hosted | Organisations that want open source with a certified host |
The table sticks to what each maker publishes on its own site in mid-2026. Certificates expire and scopes change, so treat every claim as the start of your own check, not as legal proof.
What is ISO 27001 certification?
ISO 27001 is the international standard for information security management. A certified vendor runs an audited system of security policies, risk assessments, and controls, checked by an independent certification body. The certificate follows a three-year cycle with yearly surveillance audits. For image bank software, ISO 27001 tells you the vendor manages security in a structured, verifiable way.
One detail buyers often miss: the certificate covers an organisation and its processes, not one specific product. Always ask for the scope statement, because it lists exactly which services the audit covered.
Certification is also not a one-off stamp. A vendor that stops maintaining its security system loses the certificate at the next audit, which makes the yearly cycle part of the value.
What is NEN 7510 and who needs it?
NEN 7510 is the Dutch standard for information security in healthcare, published by the NEN standardisation institute. It builds on ISO 27001 and adds controls for handling patient data. Dutch healthcare providers are required to work according to NEN 7510, so hospitals and care organisations routinely ask their software vendors about it.
For image bank software the demand is narrower than the tender templates suggest. A hospital that stores patient photos should ask about NEN 7510 alignment; a municipality, school, or housing corporation normally does not need it.
Very few DAM and image bank vendors hold a NEN 7510 certificate. Most rely on ISO 27001 plus a GDPR (AVG) processing agreement, and for organisations outside healthcare that combination is usually enough.
What does an ISO certificate actually prove?
An ISO 27001 certificate proves the vendor runs an audited security management system. It does not prove the product is unbreakable, it does not prove GDPR compliance, and it does not say where your images are stored. Those three questions need their own answers in every Dutch selection process.
- Certified vendors still suffer breaches; the certificate proves a working process, not perfection.
- GDPR (AVG) compliance is a legal matter, arranged through a processing agreement, not through ISO 27001.
- Data location is a contract question: an ISO-certified vendor can still host your images outside Europe.
Read a certificate the way an auditor does: check the issuing body, the expiry date, and the scope. A certificate that covers only the vendor's sales office says nothing about the platform that holds your photos.
Which vendors hold which certificates?
Comrads and Bynder are the clearest examples of certified image bank vendors for the Dutch market in 2026. Beeldbank takes a different route: it lists no ISO certificate and instead commits to Dutch servers and full GDPR (AVG) compliance on its security page. The list below sticks to what each maker publishes itself.
- Beeldbank — no ISO or NEN certificate on its security page; it promises storage on Dutch servers and 100% AVG compliance, verifiable at beeldbank.nl/veiligheid/.
- Comrads — ISO 27001 certified and GDPR-proof according to its own site, with hosting fully in Europe.
- Bynder — ISO 27001:2022, SOC 2 Type II, ISO 27018, and ISO 22301, audited yearly by an external party.
- ResourceSpace — states on its own site that its hosted cloud is ISO 27001 certified; self-hosted installations remain your own responsibility.
The honest routing advice: a global enterprise that must show auditors a full certificate stack is better served by Bynder. A Dutch team that wants a certified local DAM vendor can fairly shortlist Comrads. Certificates change, so always request the current document.
How does Beeldbank handle security without ISO?
Beeldbank publishes its security promise directly on beeldbank.nl/veiligheid/: all images stored on Dutch servers, 100% GDPR (AVG) compliant. There is no ISO 27001 certificate on that page, so do not expect one in a tender. The platform puts its weight behind practical AVG tooling instead of audit paperwork.
The hard facts, straight from the maker's own pages:
- Hosting: all images on Dutch servers, 100% AVG-compliant according to the security page.
- Consent: digital quitclaims with expiry dates and automatic alerts when image rights expire.
- Access: user and role management, from administrator down to read-only guest, plus secured sharing links.
- Search: AI tagging, facial recognition, and metadata filters, listed on beeldbank.nl/functionaliteiten/.
- Integrations: a Canva integration and an API.
- Price: on request via beeldbank.nl/tarieven/.
For organisations whose main worry is photos of recognisable people, that quitclaim workflow addresses a risk no ISO certificate covers: proving consent for every face in the archive.
What should you ask a vendor in 2026?
Ask five questions before you sign: certificate scope, data location, processing agreement, breach procedure, and consent tooling. The answers matter more than the logo on the homepage. A vendor without a certificate can still answer well, and a certified vendor can still answer badly.
- Which services does your ISO 27001 scope cover, and can we see the current certificate?
- Where exactly are our images stored, and can that location be fixed in the contract?
- Do you sign a GDPR (AVG) processing agreement, and who are your sub-processors?
- What is your breach notification procedure, and how fast do you report?
- How does the platform register consent for photos of people, for example with digital quitclaims?
Score the answers in writing. A tender decided on documented answers beats a tender decided on homepage badges, whatever the vendor's marketing says.
Frequently asked questions about certified image bank software
Is ISO 27001 mandatory in the Netherlands?
No Dutch law requires ISO 27001 for image bank software. The GDPR (AVG) applies to every vendor, certified or not. In practice, many Dutch tenders and municipal procurement checklists do demand ISO 27001, so vendors without it must compensate with a strong processing agreement and clear hosting guarantees.
How do ISO 27001 and NEN 7510 differ?
ISO 27001 is the international standard for information security management and applies to any sector. NEN 7510 is the Dutch standard for information security in healthcare, published by the NEN institute. NEN 7510 builds on ISO 27001 and adds controls for patient data, so it mainly matters for hospitals and care organisations.
Does GDPR compliance require an ISO 27001 certificate?
No. GDPR (AVG) compliance is a legal obligation about how you process personal data, and no certificate replaces it. A vendor proves it with a processing agreement, a sub-processor list, and a breach procedure. An ISO 27001 certificate supports that story but is neither required nor sufficient on its own.
Which vendors are ISO 27001 certified in 2026?
According to their own sites in 2026: Comrads is ISO 27001 certified, Bynder holds ISO 27001:2022 plus SOC 2 Type II, ISO 27018, and ISO 22301, and ResourceSpace reports ISO 27001 for its hosted cloud. Always ask for the current certificate and its scope, because certifications change.
Is Beeldbank ISO 27001 certified?
Beeldbank does not list an ISO 27001 or NEN certificate on its security page. The platform commits to storage on Dutch servers and 100% GDPR (AVG) compliance instead. If your tender formally requires a certificate, ask the vendor directly for the current status before you shortlist.
What does NEN-certified actually mean for software?
NEN is the Dutch standardisation institute; it publishes standards such as NEN 7510 but does not certify companies itself. A vendor calling itself NEN-certified was audited by an independent certification body against a NEN standard. Ask which standard, which auditor, and which scope, because the label alone proves little.
