DigiD pentest

Get a DigiD pentest

Organizations with a DigiD connection are legally required to perform an annual ICT security assessment per the DigiD normenkader from Logius, in cooperation with NOREA and the NCSC. Since 31 July 2023 normenkader version 4.0 applies, incorporating guidelines from the ICT Security Guidelines for Web Applications from the Dutch National Cyber Security Centre.

DongIT performs the technical pentest component of this assessment. We test your DigiD application against the technical security measures from the normenkader and deliver a report directly usable for your IT auditor. In cooperation with audit partner 2-Control we can handle the full DigiD assessment including TPM statement, so you have a single point of contact.

Our pentests are performed by OSCP-certified ethical hackers under our four-eyes principle. Reporting via our self-developed Security Reporter platform. CCV Keurmerk-accredited. Data stays in Europe.

DigiD logo

What we test in a DigiD pentest

A DigiD pentest assesses your application against the technical security measures from the DigiD normenkader v4.0. We focus specifically on the risks relevant to DigiD processing and the requirements from the NCSC ICT Security Guidelines for Web Applications.

  • Authentication and session management. Correctness of DigiD integration, session lifecycle, timeouts and logout flows.
  • Authorization and access control. Role separation, endpoint-level authorization checks and access to citizen data.
  • Input validation. Protection against SQL injection, cross-site scripting, CSRF and other injection attacks.
  • Transport security. TLS configuration, HSTS, certificate validation and secure headers.
  • Logging and monitoring. Adequate logging of authentication events, authorization failures and suspicious activity.
  • Server and application hardening. Configuration of web servers, application stack and components used.

For municipalities and executive agencies with broader government security requirements we can combine the DigiD engagement with a NIS2 pentest or BIO2 scope for ENSIA reporting.

Our approach: from pentest to TPM statement

We guide you through the full DigiD assessment. In cooperation with audit partner 2-Control you can opt for an end-to-end engagement in which all technical and organizational measures are assessed.

  1. Intake and scoping

    We discuss your DigiD application, integrations, user flows and which components fall within the assessment scope. We jointly determine the exact test scope and planning.

  2. Technical pentest

    Manual testing by OSCP-certified ethical hackers, supplemented with automated tooling. We test all technical measures from the DigiD normenkader v4.0 and the NCSC ICT Security Guidelines.

  3. Reporting for your IT auditor

    Delivery via Security Reporter with executive summary, technical findings (CVSS-scored) and remediation guidance. Findings explicitly mapped to the normenkader so your auditor has standardized evidence directly available.

  4. Remediation and retest

    Once you have resolved vulnerabilities, we validate that the remediation actually works. Time and materials, depending on the number and complexity of findings.

  5. TPM statement via 2-Control

    Based on our report, 2-Control performs additional assessment of organizational and procedural guidelines. When you meet all guidelines, you receive a TPM assurance statement (Third Party Memorandum) that you can hand over to your DigiD connection holders for the annual approval by Logius.

Who is required to perform a DigiD pentest?

The annual DigiD ICT security assessment obligation applies to all organizations with a DigiD connection. In practice this includes:

  • Municipalities and water boards. For citizen portals, filing modules and case management systems that use DigiD.
  • Executive agencies. UWV, SVB, DUO, Belastingdienst and other government services.
  • Healthcare institutions. For patient portals and online care environments that use DigiD for login.
  • Health insurers and pension funds. For customer environments that process citizen data.

Not sure whether your organization is subject to the assessment obligation? Contact us for a complimentary intake conversation. We help determine scope and approach.

Combining with other compliance engagements

For many organizations, the DigiD assessment overlaps with other compliance frameworks. We can structure your pentest engagement more efficiently by covering multiple frameworks in parallel:

DigiD and BIO2

For municipalities and water boards with ENSIA reporting. We assess against both DigiD normenkader v4.0 and Baseline Informatiebeveiliging Overheid 2 in the same engagement.

DigiD and NIS2

Executive agencies that qualify as essential entities under NIS2 can combine DigiD pentest and NIS2 reporting into one coordinated engagement.

More about NIS2 pentest

DigiD and ISO 27001

For organizations with an ISMS. Findings are double-mapped to DigiD normenkader and ISO 27001 Annex A controls.

More about ISO 27001 pentest

What does a DigiD pentest cost?

The price depends on the size of your DigiD environment, the number of integrations and whether additional compliance scopes (NIS2, BIO2, ISO 27001) are included. For clearly defined DigiD applications we offer standard packages. For more complex engagements with multiple applications or combined compliance scopes we work with a scoping conversation and a tailored quotation.

  • DigiD pentest standard, from €5,040 excl. VAT
  • Extensive DigiD engagement, from €7,200 excl. VAT
  • Enterprise and multi-scope engagements, tailored quotation

End-to-end DigiD assessment

In cooperation with 2-Control we offer the full DigiD ICT security assessment including TPM statement. One point of contact, one quotation.

Frequently asked questions about DigiD pentesting

Below are the most frequently asked questions about the DigiD pentest. For a complete overview please visit our FAQ page.

When should I have my DigiD pentest performed?

The DigiD ICT security assessment is an annual obligation. We recommend starting the pentest engagement at least three to four months before your submission deadline with Logius. This provides time for any remediation and the supplementary auditor statement.

What is the difference between a DigiD pentest and a TPM statement?

The pentest is the technical assessment that DongIT performs. The TPM statement (Third Party Memorandum) is the assurance report your IT auditor issues based on our findings and their own assessment of organizational measures. Both are required for your DigiD connection holders.

Do you work with 2-Control for the full assessment?

Yes. We work structurally with 2-Control for DigiD assessments. This means you can arrange the full engagement through a single point of contact: technical pentest via DongIT, organizational auditing and TPM statement via 2-Control. Both areas of expertise are coordinated on your schedule.

What if vulnerabilities are found during the pentest?

If findings are identified, you receive a report with remediation guidance. Once your team has resolved the vulnerabilities we perform a retest to validate that the fixes actually work. This retest is typically a prerequisite for your TPM statement.

Do you support DigiD normenkader v4.0?

Yes. Our DigiD pentest is fully aligned with the latest version of the normenkader (v4.0, in effect since 31 July 2023) and the associated NCSC ICT Security Guidelines for Web Applications.

Can you test multiple DigiD applications in parallel?

Yes. For municipalities and executive agencies with multiple applications we offer multi-scope engagements with shared intake, coordinated execution and one central final report.

How long does a DigiD pentest take?

Active testing time ranges from 24 hours for a compact DigiD application to 80 hours or more for extensive portals with multiple modules. Total duration from scoping conversation to final report and retest is typically 6 to 10 weeks.

Ready for your DigiD assessment?

Is your annual assessment deadline with Logius approaching? New to a DigiD connection and want to arrange the full engagement through one partner? Response within one business day. Quotation within three business days.