✓ OSCP · OSWE · OSEP certified | Joost performs every test himself — no juniors | Response within 1 business day | Based in Haarlem

What Is a DigiD IT Security Assessment?

What Is a DigiD IT Security Assessment?

If your organisation uses DigiD — the digital login system for government services — you’re required to have an IT security assessment carried out annually. This is a requirement from Logius, the manager of DigiD. But what does such an assessment actually involve?

The legal obligation

Organisations that integrate DigiD into their services (such as municipalities, health insurers, UWV connections or educational institutions) must demonstrate every year that their DigiD connection meets the Standard for IT Security Assessments DigiD (NIBAD). This standard is based on the BIO (Baseline Information Security for Dutch Government) and contains technical and organisational requirements.

What is assessed?

The assessment covers two main areas:

  • Technical security — including a mandatory penetration test of the web application and associated infrastructure. This is a white box or grey box pentest where the tester has access to relevant documentation.
  • Organisational measures — think access management, patch policy, incident response and logging.

The role of the penetration test

NIBAD requires a recognised party to carry out a penetration test on the DigiD web application. The findings are included in the assessment report sent to Logius. If a serious vulnerability is found and not resolved in time, Logius can revoke the DigiD connection.

MonkeysICT performs DigiD assessments in accordance with the NIBAD standard. See our dedicated page on the DigiD pentest & IT security assessment.

Who needs to have a DigiD assessment carried out?

  • Municipalities and government organisations with a DigiD connection
  • Health insurers and healthcare institutions
  • Educational institutions (DUO connection)
  • Pension funds and social security organisations
  • Suppliers managing systems on behalf of the above parties

When must the assessment be completed?

Every year, before 1 May, the assessment report must be submitted to Logius. Start well in advance — a pentest and assessment take time, and any vulnerabilities need to be resolved before submission.

What does it deliver?

  • Demonstrable compliance with Logius requirements
  • Insight into the real security status of your DigiD environment
  • A concrete improvement plan for vulnerabilities found
  • Continuity of your DigiD connection

Related articles and services

Scroll to Top