The annual DigiD audit: What does that process look like from start to finish?  

DigiD Audit

The DigiD audit is an annual review that is mandatory for organizations that have a DigiD connection. This audit tests whether your organization complies with the security guidelines prescribed by Logius. But why are these requirements relevant in the first place? Simply put: because trust in digital services stands or falls with how well you secure information. In this blog, we will guide you through all phases of this assessment, so you know exactly what to expect and how to best prepare your organization. 

Need help with your DigiD audit?

Our consultants are happy to help you.

Contact us

Legal basis and objective 

Every year, organizations that have a DigiD connection are required to conduct a Digid audit. This is not a casual assessment, but a legal requirement. The audit is conducted according to Logius' Standards Framework 3.0, which consists of 21 security rules. The role of Logius in this? They monitor that everyone plays by the same rules and supervise these audits. 

Step 1 Intake & scope determination 

A good start is half the battle. This is certainly true for the DigiD assessment. During the intake you and the auditor determine which connection(s) are part of the audit. We also identify databases and interfaces. Experience shows that a kick-off with all internal (and if relevant external) parties involved eases the process and ensures that everyone knows where they stand.  

Step 2: Pre-audit in preparation 

The pre-audit is like a dress rehearsal for the ‘official’ DigiD audit. During this step, you perform a self-assessment, possibly with guidance from the auditor. This gives you immediate insight into possible pain points. Think of it as a medical check-up before you start a tough sports match: any problems will surface early and you can immediately take measures to solve them. 

The big advantage? During the formal audit, you won't be surprised, and you can address any vulnerabilities in advance. This not only saves you time and money but also significantly increases the chances of a positive final result. In addition, this ensures that the documentation is already pre-sorted, thereby increasing the efficiency of the audit – shorter turnaround times!  

Step 3: The DigiD Audit!  

Using NOREA's framework, auditors test the design, existence, and operation of the implemented measures. The independent auditor is registered with NOREA (RE title). They inspect documents, conduct interviews, and observe system configurations. These activities are properly recorded in an audit tool or execution template.  

During the DigiD audit The 21 specific security guidelines of Logius are checked one by one. This includes access control, secure system configuration, and the security of third-party contracts.  

As part of the DigiD audit, technical penetration tests are also performed on the DigiD environment. For this, some audit firms employ their own pentesters, or work with an external party. These pen tests are not only mandatory from Logius, they mainly provide valuable insights. This prevents attackers from discovering vulnerabilities before you do. The results are included in the formal audit report, and help your organization become stronger and more secure. 

Step 4: Reporting & certification 

After completing the audit, you will receive the DigiD audit report. This report provides an opinion on compliance with Logius' standards. This audit report is then submitted to Logius. Once you have submitted the report, Logius carefully assesses whether everything has gone by the book. Sometimes there will be additional questions, but eventually you will receive feedback officially confirming that your organization meets the DigiD requirements.  

TPM Declaration DigiD 

Some organizations work with shared DigiD connections or external providers of DigiD services. In those cases, a TPM (Third Party Memorandum) statement is often required. You can think of this statement as a kind of quality mark for suppliers providing services on behalf of other organizations. 

A TPM statement makes your organization's life a lot easier. You no longer have to perform the same audit repeatedly for different clients. One thorough audit is sufficient, saving you significant time and costs. Moreover, it clearly demonstrates to partners that your services are reliable. 

Step 5: Aftercare & Support 

Findings may have emerged during the audit with respect to Logius' security standards, requiring improvements to be made before the approval statement can be issued. Once you have implemented the improvements, an additional check takes place by means of a retest. Here, the auditor checks whether all previous findings have actually been resolved.  

DigiD Support and Monitoring 

A good compliance strategy means paying continuous attention to your security. That's why support and monitoring is important. It's like the maintenance of your car: if you only go to the garage when something breaks down, you end up much more expensive than if you have regular maintenance done. 

DigiD support and monitoring ensure your security is always up-to-date. Incidents are quickly noticed and immediately addressed. Furthermore, this ensures smooth preparation for future audits. This not only saves you stress but also unexpected costs and downtime. 

Annual cycle  

The DigiD assessments recur annually. This ensures periodic compliance with the security guidelines. The annual-recurring nature of the DigiD audits means that it is often efficient to have the same auditor for a number of years - often the investment in the first year is higher than the successive years.  

The annual DigiD audit can be a recurring headache, but it can be done differently! Want to know more? Get in touch with us! 

    Want to learn more about the annual DigiD audit? Follow us on social media.