Search all 478 artefacts by title, document ID or content.
Printed on the standard letterhead. Page furniture, margins and repeating table headers come from the same stylesheet the PDF service uses.
Pensieve Labs
The operating system for hospitals
STM-NO-001
v1.0.0 | 01 August 2026
STM-NO-001 v1.0.0, Last Modified On 01 August 2026, Tier: Public
Edsol Edtech Pvt. Ltd.holds no certification and no accepted self-declaration against Normen as at01 August 2026. This statement says what Normen is, how it binds a supplier, exactly which requirementsPensieve Labsmeets and which it does not, and what it costs to close the gap. A supplier declaration that claims blanket conformance is worth nothing to a Norwegian buyer and the directorate's own guidance discourages buyers from asking for one.
| DM-1 Dedicated | DM-2 Shared | DM-3 Customer Cloud | DM-4 On-Premise |
|---|---|---|---|
| Yes | Yes | (several requirements shift to the customer) | (the physical and infrastructure requirements are the customer's) |
Pensieve LabsNormen is the Norwegian health and care sector's own binding information security and privacy norm, administered by the health directorate with a sector steering group. Its current version is 7.0, and the stated purpose of that revision was to bring it into line with the Norwegian digital security legislation. It is compiled in alignment with ISO/IEC 27001 and ISO/IEC 27002, which tells a supplier what vocabulary the buyer is thinking in.
Normen contains on the order of three hundred "shall" requirements.
Normen is not a statute. It binds by contract, in two ways:
Edsol Edtech Pvt. Ltd. in the databehandleravtale.Normen's own text is explicit that the processor is responsible for ensuring that sub-suppliers meet their obligations, and that failure to implement required measures is a material breach of the agreement and the supplier must remedy the deficiency at its own expense so that processing can resume.
Read that again, because it is a pricing input. Normen non-conformity is drafted as a remedy-at-your-own-cost material breach. Any Norwegian contract
Pensieve Labssigns will contain it. It must be priced, and it must be scoped:Pensieve Labsaccepts the obligation against a named version and a named requirement mapping, not against "Normen" in the abstract. Section 7.
The directorate publishes a supplier guide whose section map is the checklist Pensieve Labs is
measured against.
| Section | Topic | What Pensieve Labs must be able to show |
Where it is |
|---|---|---|---|
| 4 | Risk management: risk assessment and privacy impact assessment | A risk-assessment input pack for the deployment, and processor input to the controller's impact assessment | DPA-EU-001 clause 10 |
| 5 | Agreements and governance: management system, internal control, processing record, contract, processing agreements | A documented management system, an Article 30(2) processor record, a Norwegian processing agreement | WPR-GL-005, REG-GL-206, DPA-EU-001 |
| 6 | Requirements for ICT and technical solutions: cloud services, medical device classification, API security | Cloud architecture and residency statement, a medical device qualification memorandum, an interface security specification | DIS-EU-008, DIS-EU-028, DIS-GL-018 |
| 7 to 10 | Establishing a new system, equipment at the customer, remote access, service and repair | An implementation plan, a remote-access model, a service procedure | DIS-GL-033, RBK-GL-001 |
| 11 | Normen's requirements in procurement | A requirement-by-requirement response | Section 4 |
The norm's fact sheets are approved and managed by its steering group. Of the full set, five decide a
Pensieve Labs deal, and Pensieve Labs prepares against them specifically rather than against the
whole library.
| Fact sheet subject | Why it decides the deal | Pensieve Labs's answer |
|---|---|---|
| Use of a data processor | It is the instrument through which the whole norm becomes binding on Pensieve Labs |
DPA-EU-001, with the Norwegian overlay in its Annex IV-2 |
| Supplier follow-up: security-relevant reporting | It defines what Pensieve Labs must report to the customer, and on what cadence |
DIS-EU-016 for incidents; the annual assurance response in STM-EU-002 Section 8 |
| Access management | The controller must be able to demonstrate that only the right people saw the right records | DIS-GL-012, and the hospital configures entitlements |
| Logging and inspection of logs | The controller must be able to inspect the log itself | DIS-GL-013: immutable, hospital-visible, exportable without Pensieve Labs's cooperation |
| Measures on conversion and replacement of a patient record system | This is the migration gate, and it is the one nobody prepares for. It is what a hospital holds a supplier to when replacing an incumbent record system | A conversion and migration plan produced per deal, with data-quality acceptance criteria, a reconciliation method, a rollback position and a decommissioning record |
The migration fact sheet deserves specific attention. A Norwegian hospital replacing an incumbent
record system will hold Pensieve Labs to a documented conversion plan covering completeness,
correctness, traceability of transformation, and what happens to the source system afterwards.
Pensieve Labs produces it before migration begins, not during, and CHK-GL-013 carries the validation
items.
Pensieve Labs answers, and how a buyer should askThe directorate publishes the mapping workbooks that Norwegian buyers paste into their tender documents: the norm's requirements mapped against procurement requirements, against ISO/IEC 27001 and against the ISO/IEC 27002 controls, together with a guide to using the norm's requirements in procurement.
Pensieve Labs's method: answer that workbook line by line, before a tender exists, with one of
four verdicts per requirement, and publish the summary.
| Verdict | Meaning | What accompanies it |
|---|---|---|
| Met | Implemented and evidenced | The artefact that evidences it |
| Met with a customer dependency | Implemented, but requires the customer to configure or operate something | The named dependency and where it is documented |
| Not applicable | The requirement addresses a role Pensieve Labs does not hold, or a deployment model not in scope |
The reason |
| Not met | Honestly, not met | The gap, the compensating control if any, and a dated plan or an explicit statement that there is none |
A response with no "not met" rows is not a response. A Norwegian buyer who receives three hundred "met" verdicts concludes the supplier did not read the workbook.
Use the directorate's own guidance to shrink the review. It advises buyers not to write "the supplier shall comply with Normen" but to specify concrete, evaluable requirements matched to the service type. When a hospital sends a blanket conformance demand,
Pensieve Labscites that guidance and proposes the mapped requirement matrix instead. That is a legitimate, sourced way to convert an unanswerable demand into an answerable one, and the matrix is more onerous than the blanket demand, not less.
The directorate cites the Norwegian cloud security community's mapping of Normen to the cloud controls matrix, on the basis that it lets customers and suppliers speak the same language when procuring cloud services.
That is the highest-leverage fact in the Norwegian section, because the associated self-assessment
questionnaire is free, self-completed and publicly postable. Completing and publishing it converts
Pensieve Labs's "no certifications" position into a sector-recognised vocabulary at effectively zero
cost, in a country that has officially blessed the mapping.
QRE-GL-005 is Pensieve Labs's self-assessment. The Norwegian-specific action is to publish the
crosswalk from it to the Normen requirement numbers, so a Norwegian buyer can read one document and
find its own requirement identifiers.
The local-government association and the health directorate have been developing a supplier self-declaration form as part of a framework for safe digitalisation, intended to give a unified way to verify information-security and privacy compliance. The directorate's framing is commercially explicit: suppliers who meet the requirements gain a competitive advantage.
It was not available in submittable form as at 01 August 2026. [UNVERIFIED: check monthly. no/README.md Section 6 item 4.]
Direct answer to the question a founder will ask: no, a Normen self-declaration is not currently a
substitute for a security certificate, because the scheme does not yet exist in submittable form. But that
framing is the wrong one. No Norwegian statute, no Normen requirement and no health network supplier term
makes ISO/IEC 27001 a condition of supply. It is a de facto procurement requirement in the public segment
and negotiable in the private one. no/README.md Section 5 ranks what Norway offers instead.
When the scheme opens, Pensieve Labs files on day one. It is the cheapest Norwegian credibility
instrument available and it will be asked about from the day it exists.
Pensieve Labs will sign, and what it will not| Will sign | Will not sign |
|---|---|
| Conformance to a named version of the norm, against an agreed requirement mapping recorded in the Order Form or an addendum | A blanket "the supplier shall comply with Normen" with no version and no mapping |
| The remedy-at-own-cost obligation, scoped to the agreed mapping | An unbounded remedy obligation against a moving requirement set |
| An obligation to state plainly which requirements are met and which are not, and to update it on change | A representation that every requirement is met |
| An obligation to flow the agreed requirements down to sub-processors and to verify them | An obligation to certify sub-processors against the norm |
| Cooperation with the customer's own risk assessment, on a stated cadence | An obligation to perform the customer's risk assessment or impact assessment |
| An audit right, including for the customer's supervisory authority | Unlimited on-site audit of a hyperscale infrastructure provider, which Pensieve Labs cannot procure |
Version control matters. The norm is revised, and a revision can add requirements. MSA-EU-001 clause
5.9 commits Pensieve Labs to renegotiate a flow-down without charge where the underlying obligation
changes; the same principle is applied to a Normen version change, and the Order Form records the version
in force at the effective date.
An honest summary. The line-by-line response is [TO BE SUPPLIED] and is a market-entry deliverable.
| Family | Position | Principal gap |
|---|---|---|
| Governance, management system, internal control | Met, documented and mapped to ISO/IEC 27001 Annex A, without certification | No certificate; WPR-GL-005 states what compensates |
| Processing agreements, processing record, sub-processor governance | Met | None |
| Risk assessment and privacy impact assessment input | Met | None |
| Access management | Met | None |
| Logging and log inspection | Met | None |
| Cloud services and data residency | Met | Support is operated from outside the EEA under controls; a customer wanting EEA-only support pays an uplift. DIS-EU-008 Section 8 |
| Remote access | Met | None |
| Medical device classification | Met as a document | DIS-EU-028 |
| Interface and integration security | Met | The national-service integrations themselves are not built; STM-NO-002 |
| Establishing a new system, conversion and replacement | Met as a method; the per-deal plan is produced per deal | No Norwegian migration has been performed |
| Physical security | Met via the infrastructure provider for DM-1/DM-2; the customer's in DM-4 |
DIS-GL-020 |
| Emergency procedures on loss of ICT | Met | No Norwegian-language runbook yet |
| Norwegian-language documentation and support | Not met | A market-entry cost, not a per-deal one |
| National service integrations and registry reporting | Not met | STM-NO-002, DIS-NO-003 Section 5 |
9.1 No certification and no accepted self-declaration. Stated on the first page and repeated here.
9.2 The line-by-line response does not yet exist. Until it does, Pensieve Labs should not
represent that it has answered the norm. Producing it is 20 to 40 elapsed days of consultant and engineering
time and it is market-entry work, not per-deal work.
9.3 Version drift. This statement is written against version 7.0. A new version reopens Section 8.
9.4 Normen is in Norwegian. The working documents, the workbooks and the fact sheets are Norwegian. The translation cost is real and is routinely underestimated.
9.5 This is not Norwegian legal advice.
| ID | Artefact |
|---|---|
STM-NO-002 |
Norsk Helsenett and HelseID: Supplier Status |
DIS-NO-003 |
Pasientjournalloven Conformance Disclosure |
DPA-EU-001 |
Data Processing Agreement: EU/EEA, Annex IV-2 |
DIS-EU-008 |
Data Residency Statement (EEA) |
DIS-GL-033 |
Remote Access & Support Model |
DIS-GL-012, DIS-GL-013 |
Access control; audit logging |
QRE-GL-005 |
Cloud controls self-assessment |
WPR-GL-005 |
Assurance Overview |
CHK-GL-013 |
Data Migration Validation Checklist |
Issued by Edsol Edtech Pvt. Ltd..
| Role | Name | Signature | Date |
|---|---|---|---|
| Security owner | Roadmap security owner |
||
| Authorised signatory | [TO BE SUPPLIED] |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 01 August 2026 |
Security | First issue. How the norm binds through the processing agreement, the remedy-at-own-cost pricing point, the five deciding fact sheets including the migration gate, the four-verdict response method, the endorsed cloud-controls crosswalk, and an honest family-by-family position. |