DigiD pentest

Technical testing to support your annual DigiD assessment

Get a DigiD pentest

Organizations that use DigiD must have an ICT security assessment performed annually. A DigiD pentest provides technical evidence for this assessment. We align the testing with the applicable Logius DigiD framework, the relevant NOREA guidance and the scope agreed in advance with you and your RE auditor.

Illustration of a login flow with an authentication device and examination of access to an application.

DongIT performs the technical testing and delivers a report with findings and remediation advice for your IT auditor. For the full DigiD assessment, we work with audit partner 2-Control. During intake, we agree which audit activities and reports are needed for your situation.

Our pentests are performed by OSCP-certified ethical hackers under our four-eyes principle. Reporting via our self-developed Security Reporter platform. CCV Keurmerk-accredited. Data stays in Europe.

What we test in a DigiD pentest

A DigiD pentest assesses your application against the technical security measures from the applicable DigiD framework. We focus specifically on the risks relevant to DigiD processing and the requirements from the NCSC ICT Security Guidelines for Web Applications.

  • Authentication and session management. Correctness of DigiD integration, session lifecycle, timeouts and logout flows.
  • Authorization and access control. Role separation, endpoint-level authorization checks and access to citizen data.
  • Input validation. Protection against SQL injection, cross-site scripting, CSRF and other injection attacks.
  • Transport security. TLS configuration, HSTS, certificate validation and secure headers.
  • Logging and monitoring. Adequate logging of authentication events, authorization failures and suspicious activity.
  • Server and application hardening. Configuration of web servers, application stack and components used.

For municipalities and executive agencies with broader government security requirements we can combine the DigiD engagement with a NIS2 pentest or BIO2 scope for ENSIA reporting.

Our approach: from pentest to TPM statement

We guide you through the full DigiD assessment. In cooperation with audit partner 2-Control you can opt for an end-to-end engagement in which all technical and organizational measures are assessed.

  1. Intake and scoping

    We discuss your DigiD application, integrations, user flows and which components fall within the assessment scope. We jointly determine the exact test scope and planning.

  2. Technical pentest

    Manual testing by OSCP-certified ethical hackers, supplemented with automated tooling. We test all technical measures from the applicable DigiD framework and the NCSC ICT Security Guidelines.

  3. Reporting for your IT auditor

    Delivery via Security Reporter with executive summary, technical findings (CVSS-scored) and remediation guidance. Findings explicitly mapped to the normenkader so your auditor has standardized evidence directly available.

  4. Remediation and retest

    Once you have resolved vulnerabilities, we validate that the remediation actually works. Time and materials, depending on the number and complexity of findings.

  5. TPM statement via 2-Control

    Based on our report, 2-Control performs additional assessment of organizational and procedural guidelines. When you meet all guidelines, you receive a TPM assurance statement (Third Party Memorandum) that you can hand over to your DigiD connection holders for the annual approval by Logius.

Who is required to perform a DigiD pentest?

The annual DigiD ICT security assessment obligation applies to all organizations with a DigiD connection. In practice this includes:

  • Municipalities and water boards. For citizen portals, filing modules and case management systems that use DigiD.
  • Executive agencies. UWV, SVB, DUO, Belastingdienst and other government services.
  • Healthcare institutions. For patient portals and online care environments that use DigiD for login.
  • Health insurers and pension funds. For customer environments that process citizen data.

Not sure whether your organization is subject to the assessment obligation? Contact us for a complimentary intake conversation. We help determine scope and approach.

Combining with other compliance engagements

For many organizations, the DigiD assessment overlaps with other compliance frameworks. We can structure your pentest engagement more efficiently by covering multiple frameworks in parallel:

DigiD and BIO2

For municipalities and water boards with ENSIA reporting. We assess against both applicable DigiD framework and Baseline Informatiebeveiliging Overheid 2 in the same engagement.

DigiD and NIS2

Executive agencies that qualify as essential entities under NIS2 can combine DigiD pentest and NIS2 reporting into one coordinated engagement.

More about NIS2 pentest

DigiD and ISO 27001

For organizations with an ISMS. Findings are double-mapped to DigiD normenkader and ISO 27001 Annex A controls.

More about ISO 27001 pentest

What does a DigiD pentest cost?

The price depends on the size of your DigiD environment, the number of integrations and whether additional compliance scopes (NIS2, BIO2, ISO 27001) are included. For clearly defined DigiD applications we offer standard packages. For more complex engagements with multiple applications or combined compliance scopes we work with a scoping conversation and a tailored quotation.

  • DigiD pentest standard, from €5,040 excl. VAT
  • Extensive DigiD engagement, from €7,200 excl. VAT
  • Enterprise and multi-scope engagements, tailored quotation

End-to-end DigiD assessment

In cooperation with 2-Control we offer the full DigiD ICT security assessment including TPM statement. One point of contact, one quotation.

Frequently asked questions about DigiD pentesting

Below are the most frequently asked questions about the DigiD pentest. For a complete overview please visit our FAQ page.

When should I have my DigiD pentest performed?

DigiD requires an annual ICT security assessment. We recommend planning the pentest well before your submission deadline, preferably three to four months in advance. This leaves time for remediation, any retest and your auditor's assessment. Check the deadline applicable to your connection with Logius.

What is the difference between a DigiD pentest, the assessment and an RSO (formerly TPM)?

The pentest is the technical assessment for vulnerabilities. The full DigiD assessment also includes an authorized IT auditor's evaluation of the other applicable requirements. When services are outsourced, a service organization report (RSO, formerly TPM) can provide evidence for the outsourced part. A pentest report does not automatically replace an assessment report or RSO; the reports you need depend on your role and outsourcing arrangements.

Do you work with 2-Control for the full assessment?

Yes. We work with 2-Control for DigiD assessments. DongIT performs the technical pentest, and 2-Control handles the audit work and associated assurance reporting. During intake, we agree which components and reports are needed for your role as a connection holder or service organization.

What if vulnerabilities are found during the pentest?

You receive findings with risk assessments and remediation advice. After remediation, a retest can confirm whether the agreed findings have been resolved. Align the schedule and evidence needed with your auditor, who assesses the implications for the DigiD assessment.

Which DigiD framework do you use?

We align the pentest with the applicable Logius DigiD framework and NOREA guidance for the ICT security assessment. The framework defines the requirements; the guidance describes how the audit is performed. These documents have separate version numbers. Before testing, we agree the applicable requirements, scope and reporting with you and your auditor. See the current Logius assessment guidance.

Can you test multiple DigiD applications in parallel?

Yes. For municipalities and executive agencies with multiple applications we offer multi-scope engagements with shared intake, coordinated execution and one central final report.

How long does a DigiD pentest take?

Active testing time ranges from 24 hours for a compact DigiD application to 80 hours or more for extensive portals with multiple modules. Total duration from scoping conversation to final report and retest is typically 6 to 10 weeks.

Ready for your DigiD assessment?

Is your annual assessment deadline with Logius approaching? New to a DigiD connection and want to arrange the full engagement through one partner? Response within one business day. Quotation within three business days.