DigiD assessment: when it is mandatory, which standard and how supervision works

Compliance10 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

Organisations that let Dutch citizens log in with DigiD must have an annual ICT security assessment performed on the application and the environment it runs in. The report goes to Logius, which supervises the security of DigiD-connected services on behalf of the Ministry of the Interior. This article covers who the obligation applies to, which standard is tested, who may perform the assessment and where organisations run into trouble in practice.

Who the assessment obligation applies to

The obligation applies to every Dutch organisation with a DigiD connection, referred to by Logius as DigiD service providers. Municipalities, water authorities, health insurers, pension administrators, educational institutions and government agencies all fall under it. Organisations that are not directly connected but use DigiD through TVS must also meet the assessment obligation.

A frequent misconception is that the obligation sits with the supplier. If your citizen portal runs at a SaaS provider, you remain responsible for the report as the connection holder. You can rely on assurance your supplier has already obtained, but the connection is in your name and so is the obligation.

The DigiD Normenkader 3.0

Testing is done against the DigiD Normenkader 3.0. It consists of 21 security guidelines, commonly referred to as the 21 norms, and is based on the Dutch ICT Security Guidelines for Web Applications. Version 3.0 was adopted by the Ministry of the Interior and has applied since 1 August 2022.

The 21 norms span the full breadth of a web application and its environment: information security policy and governance, hardening of servers and applications, patch management, encryption of connections and storage, authentication and authorisation, logging and detection, and periodic security testing. Some norms are technical in nature, others are process-oriented. Organisations that focus only on the technology come unstuck on the process norms, and the other way around.

Who may perform the assessment

The assessment is performed under the responsibility of an RE auditor, an IT auditor registered with NOREA. The report must be prepared and signed by that RE auditor. An internal security scan, a penetration test report or a statement from your hosting provider does not replace it.

That does not mean the auditor does all the work. Penetration tests are often carried out by a specialised party, after which the auditor evaluates the design, execution and findings of that test and weighs them in the opinion. What matters is that the test matches the scope of the assessment and is recent enough.

What falls within scope

The scope is the application used to log in, plus the environment that application runs in. In practice that means the web application itself, the DigiD integration, the underlying servers and network components, and the management processes around them.

Chain partners are not excluded. If you work with a hosting provider, a managed service partner or a cloud provider, the components they deliver must demonstrably meet the norms. That can be through their own assessment or an assurance report that maps onto the DigiD norms. A data processing agreement without underlying evidence is not enough.

How supervision works

Logius supervises two things: whether the report arrives on time and what it says. The report is reviewed and responded to. Where there are shortcomings, Logius pushes for remediation and expects the organisation to resolve the findings and demonstrate that in a subsequent report. If remediation does not happen, the connection itself eventually comes into play, and with it the ability for citizens to log in to your service.

Common findings

A recurring pattern is a scope that is drawn too narrowly. Organisations include the web application but leave out the management environment, the test environment holding production data, or the interfaces. The auditor discovers this along the way, usually at a point where remediation before the deadline is no longer feasible.

A second pattern is logging that exists but is never used. Log files are written and retained, but nobody looks at them, there are no alerting rules and there is no follow-up procedure. The norm asks for more than storage.

A third is overdue patch management on components just outside the field of view: an ageing load balancer, a management tool, a library in the application that has not been updated for two years.

Fourth, there is regularly no recent penetration test covering the full scope, or the test was carried out but the findings were never demonstrably remediated and retested.

How to prepare

Start with the scope and set it before the auditor arrives. Map out which systems, interfaces and parties are involved in the DigiD login, and determine per component who supplies the evidence. Ask chain partners for their assurance well in advance, because that is usually the longest lead time.

Then walk through the 21 norms with one question in mind: what evidence could you produce today? Not whether it is arranged, but whether you can show it. Plan the penetration test so there is room for remediation and a retest before the report is due. Anyone who schedules the test two weeks before the deadline will almost certainly submit a report with open findings.

Source: Logius, ICT security assessments DigiD and DigiD Normenkader 3.0: https://www.logius.nl/onze-dienstverlening/toegang/digid/ict-beveiligingsassessments-digid/ict-beveiligingsassessments-digid-in-het-algemeen

Secure Audit performs DigiD assessments and supports organisations in preparing for them, from scoping and baseline measurement to remediation of findings. Get in touch to discuss where you stand.

Frequently asked questions

How often must a DigiD assessment be performed?+

Annually. Every DigiD service provider has an assessment carried out each year on the application and its environment and submits the report to Logius.

Who may perform a DigiD assessment?+

The report must be prepared and signed by an RE auditor, an IT auditor registered with NOREA. An internal scan, a standalone pentest report or a statement from your hosting provider does not suffice.

Which standard is tested in a DigiD assessment?+

The DigiD Normenkader 3.0, consisting of 21 security guidelines based on the Dutch ICT Security Guidelines for Web Applications. Version 3.0 has applied since 1 August 2022 and was adopted by the Ministry of the Interior.

Does the obligation apply if my portal runs at a SaaS supplier?+

Yes. The connection is in your organisation name and so is the obligation. You can rely on assurance from your supplier, but you remain responsible for the report to Logius.

Is a penetration test mandatory within the DigiD assessment?+

The assessment expects deeper testing than an automated scan. In practice you have a penetration test performed that matches the scope, after which the RE auditor evaluates its design, execution and findings and weighs them in the opinion.

Need help with compliance?

Need to comply with ISO 27001, ISO 42001, NEN 7510, NIS2 or DORA, or do you need a SOC 2 report? We guide you through the entire process: from gap analysis to implementation.

Explore Compliance Services

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us