The DigiD Standard Framework 3.0 consists of 21 standards from the NCSC ICT security guidelines for web applications. A pentest primarily provides evidence for the technical standards: input and output validation and cryptography in the web application (U/WA.03 through U/WA.05), configuration and hardening of the web server and platform (U/PW.02, U/PW.03, U/PW.05, and U/PW.07), network zoning and hardening (U/NW.03, U/NW.05, and U/NW.06), and patch management (C.09). In addition, the pentest itself demonstrates that you comply with standard C.04.