Does your organisation have, or is it planning to obtain, a DigiD connection? If so, you must be able to demonstrate compliance with the security requirements set by Logius. A DigiD audit shows whether the IT security and processes surrounding your DigiD connection meet the applicable requirements.

RSM IT Audit supports organisations with the required ICT Security Assessment DigiD. We provide a structured approach, clear planning and timely reporting.

When is a DigiD audit mandatory?

Organisations with a DigiD connection must periodically demonstrate that they comply with the current Logius framework.

The requirements include:

  • an initial assessment within two months after activation of a new DigiD connection
  • an annual DigiD assessment, with reporting submitted between 1 January and 1 May
  • assessment against the current Logius framework

A timely DigiD audit helps prevent issues with your connection and supports the continuity of your DigiD services.

What is assessed during a DigiD audit?

The scope of the assessment depends on your situation and the structure of the DigiD chain. This may involve a full scope audit or an audit covering a limited part of the chain.

During the DigiD assessment, we assess among other things:

  • whether the required controls are in place to meet the Logius requirements
  • whether the standards that Logius requires to be tested for operating effectiveness have demonstrably operated during the required period

For a number of standards, a minimum assessment period of six months applies.

How does a DigiD audit work?

Good preparation helps keep the audit process clear and provides timely insight into any areas that may require attention.

RSM IT Audit supports you with:

  • performing the DigiD audit and preparing the report
  • timely delivery in accordance with Logius requirements
  • a baseline assessment or pre audit to prepare your organisation for the assessment
  • cooperation with specialised penetration testing providers where required

By establishing the scope, required documentation and planning in advance, you know what is expected from your organisation throughout the audit process.

Independent DigiD auditors

Independent and professional assessment is an important part of a DigiD audit. RSM's auditors are affiliated with NOREA, the Dutch professional association for IT auditors, and work in accordance with the applicable professional and ethical standards.

This means you can expect:

  • independent and objective audits
  • a strong focus on quality
  • compliance with professional standards for IT auditors

Our auditors also have experience with other audits within the public sector, including ENSIA audits and other IT audits.

Which organisations need a DigiD audit?

A DigiD audit is relevant for organisations that manage their own DigiD connection or are responsible for parts of the DigiD chain to which the Logius security requirements apply.

RSM supports organisations including:

  • government organisations
  • municipalities and executive agencies
  • healthcare and educational institutions
  • insurers and pension administrators
  • software providers
  • other organisations with a DigiD connection

Why choose RSM for your DigiD audit?

A personal and reliable audit partner

Throughout the audit process, you have clarity about what is required, which information needs to be provided and what the next steps are.

Experience in the public sector

Our auditors have experience with DigiD audits and other IT audits for organisations within the public sector.

A pragmatic approach

We structure the audit process so that the activities, planning and reporting are as clear as possible from the outset.

Need a DigiD audit?

Does your organisation have a DigiD connection and do you need to complete the mandatory security assessment? Contact the RSM IT Audit specialists to discuss what is required for your organisation.

Do you have a question? We will get back to you as soon as possible.

Frequently asked questions about DigiD audits

A DigiD audit is a mandatory ICT security assessment that determines whether an organisation with a DigiD connection complies with the security requirements set by Logius.

For a new DigiD connection, the first assessment must take place within two months after activation. After that, an assessment is carried out annually and the reporting is submitted between 1 January and 1 May.

The ICT Security Assessment DigiD is the official assessment of the IT security, processes and controls surrounding a DigiD connection.

The audit assesses, among other things, whether the required controls are in place and whether the standards that Logius requires to be tested for operating effectiveness have demonstrably operated during the required period.

A full scope audit assesses the complete DigiD chain within the audit scope. With a limited scope, only the relevant part of the chain is assessed, such as the user organisation.

Yes. RSM can perform a baseline assessment or pre audit before the formal assessment. This provides insight into potential areas for improvement before the DigiD audit takes place.