DigiD Pentest & IT Security Assessment
Do you use DigiD for citizen authentication? Then you are required to have an IT security assessment for DigiD carried out annually. MonkeysICT performs these assessments in accordance with LOGIUS guidelines.
What is a DigiD assessment?
LOGIUS requires all organisations with a DigiD connection to undergo an annual security test. This applies to:
- Municipalities and government organisations
- Healthcare providers (via BSN connection)
- UWV, the Dutch Tax Administration and implementing bodies
- Educational institutions with DigiD access
The assessment follows the IT security guidelines for web applications and includes both a penetration test and a configuration review.
What do we test in a DigiD pentest?
- Authentication and session management around the DigiD connection
- SAML/BSN integration and token validation
- Authorization and access management after login
- Input validation and injection risks (OWASP Top 10)
- Transport security (TLS configuration, certificates)
- Logging and monitoring on the DigiD interfaces
Process and reporting
After the assessment you receive a report that meets LOGIUS submission requirements. The report includes a management summary, technical findings with CVSS scores and a compliance matrix. We also support you with submitting the assessment report to LOGIUS.
FAQ
Am I required to have a DigiD pentest carried out?
Yes. Every organisation with a DigiD connection is required to submit an annual IT security assessment to LOGIUS. Without an approved assessment, your DigiD connection can be terminated.
How long does a DigiD assessment take?
A DigiD pentest usually takes 2 to 4 days depending on the size of the application. The report is available within 5 business days after completion.
Does the report meet LOGIUS requirements?
Yes. Our report is drawn up in accordance with the LOGIUS reporting template and contains all sections required for submission.
Can you also help with remediating findings?
Yes, we provide concrete remediation advice and offer an optional retest after remediation to confirm findings have been resolved before the next submission.
Also see: web application pentest | pentest for government | request a quote
