DigiD assessment: who must have one, which deadlines apply and what Logius tests

Compliance11 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

Any organisation that lets Dutch citizens log in with DigiD has an ICT security assessment performed every year on the application and the environment it runs in. The report goes to Logius, which supervises DigiD-connected services on behalf of the Ministry of the Interior and Kingdom Relations. This article covers who the obligation applies to, the deadlines for new and existing connections, which standard is tested, who may perform the assessment, what Logius does with the report, and what changed in 2025 and 2026.

Who the assessment obligation applies to

The obligation applies to every Dutch organisation with a DigiD connection, which Logius calls DigiD service providers. Municipalities, water authorities, health insurers, pension administrators, educational institutions and government agencies all fall under it. Organisations that are not connected directly but use DigiD through the ToegangVerleningService (TVS) must meet the obligation too.

The obligation is tied to the connection, not to its use. A connection that Logius has registered as active but that is no longer used remains subject to assessment until the connection holder asks for deactivation. An organisation that retired an old citizen portal without deregistering the connection will simply receive a reminder letter.

A second misconception is that the obligation sits with the supplier. If the portal runs at a SaaS provider, the login goes through an identity broker or management is outsourced, the connection holder remains the owner and the party ultimately responsible. You can use assurance from your supplier, but the connection is in your name and so is the report.

New connection: a first report within two months

A new connection falls under article 5.6 of the DigiD Terms (or article 1.23 of the TVS Terms). Once Logius activates the connection, the holder has two months to submit a first assessment report. That first assessment tests all 21 norms on design and existence; a test of operating effectiveness is not yet required. The report must be submitted even if the assessment shows that not all norms are met.

If the first assessment is passed, Logius confirms by letter that article 5.6 has been satisfied and the connection becomes an existing connection. The letter also states the next submission date. That date is no earlier than twelve months after activation, and if it falls outside the regular submission window it moves to the window of the following year. A connection activated in October 2025 submits its first report in December 2025 and its first annual report, including operating effectiveness, between 1 January and 1 May 2027.

Existing connection: every year between 1 January and 1 May

An existing connection falls under article 5.5 (or 1.22 for TVS): submit an assessment report every year between 1 January and 1 May covering the previous calendar year. The test period runs at least until 31 December and the auditor issues the opinion no earlier than 1 January, so that December is included in the assessment.

Changes to the DigiD environment that do not result in a new connection number do not require an interim report; they are covered in the next annual assessment. A change of domain name or of interface (for example from CGI to SAML, or from a direct connection to TVS) does require a new connection number, and that counts as a new connection with the two-month deadline. If nothing changes from a security perspective, you can submit a migration request within two months to have the new connection treated as an existing one. That requires a statement from the auditor that the scope is unchanged and, where an identity broker is involved, a valid RSO for that broker.

The Normenkader 3.0 and the test of operating effectiveness

Testing is done against the DigiD Normenkader 3.0: 21 security guidelines based on the NCSC ICT Security Guidelines for Web Applications, adopted by the Ministry of the Interior and in force since 1 August 2022. Version 3.0 added norm B.01, an information security policy with specific attention to web applications, to the twenty norms of version 2.0. The norms themselves have not changed since; what has changed is how they are tested.

Since the 2025 submission window (covering 2024), five norms must also be tested on operating effectiveness: U/TV.01 (identity and access means), U/WA.02 (web application management), C.07 (monitoring of logging and detection), C.08 (change management) and C.09 (patch management). The review period for that test is at least six months, and Logius has announced that it will grow to a year over time, as is usual for assurance on operating effectiveness. A norm that fails on operating effectiveness cannot be fixed with a document update: a new review period is needed, which is why Logius asks for an interim test of design and existence in the meantime.

For the content of each norm and the evidence you need per group of norms, see the DigiD assessment checklist.

Who may perform the assessment and what the report looks like

The assessment is performed under the responsibility of an RE auditor, an IT auditor registered with NOREA. The report must be prepared and signed by that RE auditor. An internal scan, a penetration test report or a statement from your hosting provider does not replace it. NOREA and Logius jointly maintain the Handreiking ICT-beveiligingsassessment DigiD that auditors follow; the 2025 version is dated 29 August 2025.

The methodology is 3000D: a direct assurance engagement under NOREA Standard 3000, the Dutch implementation of ISAE 3000. The ENSIA variant for municipalities was an attestation engagement (3000A) on a statement by the municipal executive; that variant is being phased out, see below. The connection holder's report is called the RDV (report of the service provider). Where a third party delivers part of the environment, an RSO is added per service organisation. All documents are delivered as PDF/A and signed with a qualified electronic signature traceable to the EU Trusted List, personal to the signing RE auditor. Logius does not accept a signature in the name of the firm.

A penetration test is part of the assessment but does not have to be carried out by the auditor. The auditor evaluates the design, scope and findings of the test and weighs them in the opinion. What matters is that the test covers the full scope and is recent enough. The difference with a vulnerability scan is explained in penetration test versus vulnerability scan.

Service organisations and the RSO

The scope of the assessment is the application used to log in plus the environment it runs in: the web application, the DigiD integration, the servers and network components, and the management processes around them. If you work with a hosting provider, a SaaS supplier, an identity broker or a management partner, the components they deliver must demonstrably meet the norms.

That is done through a report of the service organisation, the RSO, previously known as a TPM (third party memorandum). An RSO is prepared by the supplier's RE auditor and used by several connection holders. The opinion date in the RSO may not differ by more than a year from the opinion date in the connection holder's report. Since 2023 an auditor can have a draft RSO pre-checked by Logius between 1 September and 1 November, provided the report is issued to several service providers. A data processing agreement or a general ISO 27001 certificate does not replace the RSO: the connection holder must be able to point out, per norm, which party supplies the evidence. Shortcomings at the service organisation are and remain the responsibility of the connection holder.

What Logius does with the report

Logius reviews the report and responds by letter. There are three outcomes. The report is not taken into consideration, for instance because a document is missing or does not meet the formal requirements; a deadline for correction then applies. Or the report has been reviewed and not all norms are met; Logius then sets a remediation period per norm and the RE auditor must retest those norms in a reassessment report. Or all norms are met; Logius then confirms that the DigiD Terms have been satisfied for that assessment year.

Logius advises starting remediation as soon as a norm is found not to comply, rather than waiting for the letter. That advice is sound for the five operating effectiveness norms, because remediation requires a new review period that does not fit within the remediation deadline. For that situation there is enhanced supervision: a holder that still cannot demonstrate operating effectiveness after the remediation period is given formal notice but may continue the service by showing every three months, through a reassessment, that the norm meets design and existence, until operating effectiveness has been demonstrated.

For a non-occurrence on existence (the measure exists, but no case arose during the period to which it could be applied) Logius always requires a re-audit for B.05 and C.08, and sometimes for U/TV.01 and U/WA.02, depending on when the connection was activated. On 2 December 2025 Logius corrected a passage in the NOREA guidance that suggested otherwise.

Anyone who does not submit on time receives a registered reminder letter giving formal notice, with one final deadline. After that comes a registered letter stating the date on which the connection will be deactivated. Logius sends those letters to the highest governing body, so to the executive board or the municipal executive, not to the IT department. In the event of an acute security risk with consequences for DigiD, Logius may disconnect the integration immediately without prior letter.

What changed in 2025 and 2026

There is no new set of norms. The 21 norms are the same as in 2022. The changes are in testing and accountability, and for some organisations those are more far-reaching than a new norm would have been.

For municipalities the ENSIA method for DigiD is being phased out. Since 2017 municipalities have reported through a statement by the municipal executive, endorsed by the auditor with an assurance statement. That proved labour-intensive and error-prone. In the 2026 submission window (covering 2025) municipalities may choose between ENSIA and 3000D; from the 2027 window (covering 2026) 3000D is mandatory. The auditor then becomes the author of the entire report again, using the same RDV template as non-municipalities, and the executive statement is decoupled from the accountability to Logius. The choice of method is made with the auditor beforehand; switching halfway through the audit is not allowed.

On 14 April 2026 Logius published rules for the "my environment" setup: several services or applications behind one connection number, for example through an identity broker. That is permitted, but every application behind the connection falls within scope and is named in the report, per application with the suppliers involved and a table of norms. An application added during the year must have a review period of at least six months for the operating effectiveness norms; if that period is too short, Logius treats the norm as not met. And anyone who removes an application to get rid of a shortcoming must demonstrate with a new audit statement that the remaining applications comply.

The review period for operating effectiveness is growing from six months to a year. Organisations that already have the five norms tested over a full calendar year will not need to change anything.

Where it goes wrong in practice

The first pattern is a scope drawn too narrowly. The web application is in, but the management environment, a test environment holding production data, the identity broker or an interface is not. The auditor discovers this along the way, usually at a point where remediation before 1 May is no longer feasible.

The second is the RSO that arrives late or not at all. The supplier has an ISO 27001 certificate or a SOC 2 report, but no report mapped to the 21 norms, or the opinion date is more than a year away from the connection holder's. Ask chain partners for their RSO first, because that is where the longest lead time sits.

The third is operating effectiveness that has not been built up. The change management procedure exists, but there are not six months of approved and tested changes to show, or logging runs but nobody followed up on alerts during the period. How to make monitoring demonstrable is covered in logging and monitoring for the audit. An operating effectiveness gap cannot be closed before the deadline and leads to enhanced supervision.

The fourth is the penetration test that was scheduled too late, does not cover the full scope, or whose findings were remediated but never retested. Plan the test so that remediation and retest fit before the opinion date.

How to prepare

Start with the scope and fix it before the auditor arrives: which applications sit behind the connection number, which integrations and parties are involved, and who supplies the evidence per norm. Count back from 1 May: the opinion date is after 31 December, the review period for the five operating effectiveness norms runs at least six months before that, and the RSO of every supplier must be available before that opinion date. Then walk through the 21 norms asking what evidence you could produce today, not whether it has been arranged.

Secure Audit performs DigiD assessments as RE auditor and supports preparation, from scoping to reviewing the RSOs of suppliers. See the IT audit services page.

Sources: Logius, ICT security assessments DigiD (general, how supervision works, submission and follow-up, announcements): https://www.logius.nl/onze-dienstverlening/toegang/digid/ict-beveiligingsassessments-digid

Frequently asked questions

Who is required to have a DigiD assessment?+

Every Dutch organisation with an activated DigiD connection, including organisations that use DigiD through TVS. The obligation is tied to the connection, not to its use: a connection that is no longer used but is still active remains subject to assessment until you request deactivation.

When must the DigiD assessment report reach Logius?+

For an existing connection every year between 1 January and 1 May, covering the previous calendar year, with an opinion date no earlier than 1 January. For a new connection within two months of activation; that first report tests design and existence only.

Which norms are tested on operating effectiveness?+

Five of the 21 norms in Normenkader 3.0: U/TV.01, U/WA.02, C.07, C.08 and C.09. The review period is at least six months and, according to Logius, will grow to a year over time. An operating effectiveness gap cannot be closed before the deadline, so those five processes must demonstrably run for months before the opinion date.

Who may perform a DigiD assessment?+

An RE auditor registered with NOREA. The report is prepared by that auditor and personally signed with a qualified electronic signature. A penetration test report or a statement from your hosting provider does not replace the assessment.

What is an RSO and do I need one from my supplier?+

An RSO (report of the service organisation, previously TPM) is the assurance report by the RE auditor of your supplier on the part of the environment that supplier delivers. You need one for every party that covers norms on your behalf, such as a hosting provider, SaaS supplier or identity broker. Its opinion date may not differ by more than a year from the one in your own report.

What happens if I do not submit the report on time?+

Logius sends a registered reminder to the highest governing body with a final deadline. If the report still does not arrive, a registered letter follows stating the date on which the DigiD connection will be deactivated. After that, citizens can no longer log in and you must request reactivation.

Need help with compliance?

Need to comply with ISO 27001, ISO 42001, NEN 7510, NIS2 or DORA, or do you need a SOC 2 report? We guide you through the entire process: from gap analysis to implementation.

Explore Compliance Services

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us
DigiD assessment: when required, deadlines and what Logius tests (2026) · Secure Audit