View all pentests
Get a DigiD pentest
Organizations that use DigiD must have an ICT security assessment performed annually. A DigiD pentest provides technical evidence for this assessment. We align the testing with the applicable Logius DigiD framework, the relevant NOREA guidance and the scope agreed in advance with you and your RE auditor.

DongIT performs the technical testing and delivers a report with findings and remediation advice for your IT auditor. For the full DigiD assessment, we work with audit partner 2-Control. During intake, we agree which audit activities and reports are needed for your situation.
Our pentests are performed by OSCP-certified ethical hackers under our four-eyes principle. Reporting via our self-developed Security Reporter platform. CCV Keurmerk-accredited. Data stays in Europe.
What we test in a DigiD pentest
A DigiD pentest assesses your application against the technical security measures from the applicable DigiD framework. We focus specifically on the risks relevant to DigiD processing and the requirements from the NCSC ICT Security Guidelines for Web Applications.
- Authentication and session management. Correctness of DigiD integration, session lifecycle, timeouts and logout flows.
- Authorization and access control. Role separation, endpoint-level authorization checks and access to citizen data.
- Input validation. Protection against SQL injection, cross-site scripting, CSRF and other injection attacks.
- Transport security. TLS configuration, HSTS, certificate validation and secure headers.
- Logging and monitoring. Adequate logging of authentication events, authorization failures and suspicious activity.
- Server and application hardening. Configuration of web servers, application stack and components used.
For municipalities and executive agencies with broader government security requirements we can combine the DigiD engagement with a NIS2 pentest or BIO2 scope for ENSIA reporting.
Our approach: from pentest to TPM statement
We guide you through the full DigiD assessment. In cooperation with audit partner 2-Control you can opt for an end-to-end engagement in which all technical and organizational measures are assessed.
Intake and scoping
We discuss your DigiD application, integrations, user flows and which components fall within the assessment scope. We jointly determine the exact test scope and planning.
Technical pentest
Manual testing by OSCP-certified ethical hackers, supplemented with automated tooling. We test all technical measures from the applicable DigiD framework and the NCSC ICT Security Guidelines.
Reporting for your IT auditor
Delivery via Security Reporter with executive summary, technical findings (CVSS-scored) and remediation guidance. Findings explicitly mapped to the normenkader so your auditor has standardized evidence directly available.
Remediation and retest
Once you have resolved vulnerabilities, we validate that the remediation actually works. Time and materials, depending on the number and complexity of findings.
TPM statement via 2-Control
Based on our report, 2-Control performs additional assessment of organizational and procedural guidelines. When you meet all guidelines, you receive a TPM assurance statement (Third Party Memorandum) that you can hand over to your DigiD connection holders for the annual approval by Logius.
Who is required to perform a DigiD pentest?
The annual DigiD ICT security assessment obligation applies to all organizations with a DigiD connection. In practice this includes:
- Municipalities and water boards. For citizen portals, filing modules and case management systems that use DigiD.
- Executive agencies. UWV, SVB, DUO, Belastingdienst and other government services.
- Healthcare institutions. For patient portals and online care environments that use DigiD for login.
- Health insurers and pension funds. For customer environments that process citizen data.
Not sure whether your organization is subject to the assessment obligation? Contact us for a complimentary intake conversation. We help determine scope and approach.
Combining with other compliance engagements
For many organizations, the DigiD assessment overlaps with other compliance frameworks. We can structure your pentest engagement more efficiently by covering multiple frameworks in parallel:
DigiD and BIO2
For municipalities and water boards with ENSIA reporting. We assess against both applicable DigiD framework and Baseline Informatiebeveiliging Overheid 2 in the same engagement.
DigiD and NIS2
Executive agencies that qualify as essential entities under NIS2 can combine DigiD pentest and NIS2 reporting into one coordinated engagement.
DigiD and ISO 27001
For organizations with an ISMS. Findings are double-mapped to DigiD normenkader and ISO 27001 Annex A controls.
What does a DigiD pentest cost?
The price depends on the size of your DigiD environment, the number of integrations and whether additional compliance scopes (NIS2, BIO2, ISO 27001) are included. For clearly defined DigiD applications we offer standard packages. For more complex engagements with multiple applications or combined compliance scopes we work with a scoping conversation and a tailored quotation.
- DigiD pentest standard, from €5,040 excl. VAT
- Extensive DigiD engagement, from €7,200 excl. VAT
- Enterprise and multi-scope engagements, tailored quotation
End-to-end DigiD assessment
In cooperation with 2-Control we offer the full DigiD ICT security assessment including TPM statement. One point of contact, one quotation.
Frequently asked questions about DigiD pentesting
Below are the most frequently asked questions about the DigiD pentest. For a complete overview please visit our FAQ page.
When should I have my DigiD pentest performed?
DigiD requires an annual ICT security assessment. We recommend planning the pentest well before your submission deadline, preferably three to four months in advance. This leaves time for remediation, any retest and your auditor's assessment. Check the deadline applicable to your connection with Logius.
What is the difference between a DigiD pentest, the assessment and an RSO (formerly TPM)?
The pentest is the technical assessment for vulnerabilities. The full DigiD assessment also includes an authorized IT auditor's evaluation of the other applicable requirements. When services are outsourced, a service organization report (RSO, formerly TPM) can provide evidence for the outsourced part. A pentest report does not automatically replace an assessment report or RSO; the reports you need depend on your role and outsourcing arrangements.
Do you work with 2-Control for the full assessment?
Yes. We work with 2-Control for DigiD assessments. DongIT performs the technical pentest, and 2-Control handles the audit work and associated assurance reporting. During intake, we agree which components and reports are needed for your role as a connection holder or service organization.
What if vulnerabilities are found during the pentest?
You receive findings with risk assessments and remediation advice. After remediation, a retest can confirm whether the agreed findings have been resolved. Align the schedule and evidence needed with your auditor, who assesses the implications for the DigiD assessment.
Which DigiD framework do you use?
We align the pentest with the applicable Logius DigiD framework and NOREA guidance for the ICT security assessment. The framework defines the requirements; the guidance describes how the audit is performed. These documents have separate version numbers. Before testing, we agree the applicable requirements, scope and reporting with you and your auditor. See the current Logius assessment guidance.
Can you test multiple DigiD applications in parallel?
Yes. For municipalities and executive agencies with multiple applications we offer multi-scope engagements with shared intake, coordinated execution and one central final report.
How long does a DigiD pentest take?
Active testing time ranges from 24 hours for a compact DigiD application to 80 hours or more for extensive portals with multiple modules. Total duration from scoping conversation to final report and retest is typically 6 to 10 weeks.
Ready for your DigiD assessment?
Is your annual assessment deadline with Logius approaching? New to a DigiD connection and want to arrange the full engagement through one partner? Response within one business day. Quotation within three business days.
Nederlands