Skip to main content
NOREA guideline-compliant executionThorough DigiD assessments

DigiD Security assessment

ICT security assessments according to NOREA guidelines for DigiD connections

Every organization that uses DigiD for authentication must meet strict security requirements. The NOREA ICT Security Assessment Guideline for DigiD prescribes what must be tested. Logius only accepts TPM statements from recognized auditors. Neo Security has the expertise, experience and recognition to ensure your DigiD compliance.

We are your trusted partner for DigiD assessments. For all municipalities to central government and from healthcare to education.

We help you meet these security requirements and think along about addressing potential risks with concrete, actionable steps.

More than just DigiD?

In addition to specialized DigiD assessments, we offer complete penetration testing services for all your systems, applications and infrastructure.

View our Penetration Testing services →

Have Neo Security perform your DigiD Assessment?

ICT Security assessment

Complete assessment according to NOREA Guidelines for all DigiD connected organizations

  • Testing against DigiD Standards Framework
  • Analysis of technical controls
  • Assessment of organizational controls
  • Risk inventory and evaluation
  • Gap analysis with prioritization

Penetration test DigiD connection

In-depth technical test of your DigiD implementation and connections

  • SAML implementation verification
  • Session management testing
  • Authentication bypass attempts
  • Cryptographic validation
  • API security assessment

Assurance reporting

TPM statement for Logius according to required formats and standards

  • Third Party Statement (TPM)
  • Management letter
  • Technical findings report
  • Compliance matrix
  • Improvement plan with timelines

DigiD Compliance standards framework

We test all domains of the DigiD Standards Framework. Our structured approach ensures no control is missed and all risks are identified.

Governance

  • Information security policy
  • Risk management process
  • Incident response procedures
  • Business continuity planning
  • Compliance monitoring

Technical Controls

  • System access security
  • Cryptography implementation
  • Logging and monitoring
  • Vulnerability management
  • Configuration management

Operational Security

  • Change management
  • Patch management
  • Backup and recovery
  • Capacity planning
  • Supplier management

DigiD Specific

  • SAML 2.0 conformity
  • Metadata management
  • Certificate lifecycle
  • User session management
  • Privacy by design

Why Choose Neo Security?

100%

TPM Acceptance Rate

4 weeks

Average duration

€15K

All-in from

Duration of a DigiD assessment by Neo Security

Week 1-2

Preparation

  • Kick-off meeting with stakeholders
  • Documentation inventory
  • Arrange system access
  • Scope definition and planning

Week 3-4

Assessment execution

  • Interviews with key personnel
  • Technical configuration review
  • Perform penetration tests
  • Compliance testing standards framework

Week 5

Analysis & reporting

  • Findings consolidation
  • Risk scoring and prioritization
  • Draft report preparation
  • Internal quality review

Week 6

Delivery

  • Findings presentation
  • Finalize TPM statement
  • Discuss improvement plan
  • Knowledge transfer session

Assessment deliverables

TPM Statement

Official Third Party Statement for Logius per template

Format: PDF, digitally signed

Assessment Report

Detailed findings with risk ratings and recommendations

Format: PDF + Excel attachments

Management Summary

Executive summary for management and regulators

Format: PDF presentation

Technical Report

In-depth technical analysis for IT teams

Format: PDF + evidence bundle

Improvement Plan

Prioritized roadmap for remediation

Format: Excel with timelines

During a recent DigiD assessment, we not only guided the organization through the process but also structurally improved their security posture. Our pragmatic approach ensured a smooth Logius process without unnecessary complexity.

Neo Security

DigiD Assessment Team

Why Neo Security for DigiD Assessments?

Public sector expertise

Deep knowledge of government processes, compliance requirements and the specific challenges of public services.

NOREA, Logius and Neo Security as your partner

NOREA certified auditors with years of experience in DigiD assessments. Experience with Logius and streamlining these assessments, we gladly go beyond what the NOREA Guideline sometimes allows. We deliver you a truly honest picture of your security posture and deliver concrete, actionable improvements.

Continuous Support

Not just assessments, but ongoing (fair-use) support for security questions, whenever you need it you have standby. No problem.

Start your DigiD assessment

The deadline for your next TPM statement is approaching. Don't wait until the last moment. With our proven approach and experience we guarantee a smooth assessment process and timely delivery of all required documentation.

Quick Scan

Free pre-assessment check

Assessment Plan

Custom proposal within 48h

Gap Analysis

Identify risks upfront

Want a quick introduction? Just call to get in touch with our Security Specialists.

Phone: 020-7165487