Have a DigiD pentest performed

We test like an attacker attacks and report like a RE auditor reads. This way, every vulnerability becomes evidence for your DigiD assessment. We are only satisfied when your web application is demonstrably DigiD-compliant.

DigiD penetration test

DigiD pentest: ready for your assessment on time

Experienced ethical hackers test the resilience of your DigiD web application. We link all findings to the standards from the DigiD Assessment Framework 3.0, ensuring your RE-auditor can directly use the report for the assessment.

Schedule a no-obligation consultationDownload Buyer’s Guide

Retest standard included·Reporting within 5 working days·According to the CCV certification mark

CCV-gecertificeerde pentester van Warpnet aan het werk aan een DigiD pentest

SOME OF OUR CLIENTS

N8nYdenticNieuw WoelwijckRijksoverheidEffectoryVentolinesPatchmanager
Warpnet pentest netwerk diagram

How does a DigiD pentest by Warpnet work?

Every specialist can record risks. Fix them? That is our specialty.

  1. We work with you to determine the scope, target environment and desired results of the pentest.
  1. We collect data about the target using public sources (this is known as OSINT).
  1. We scan for recent and current vulnerabilities using
    AI scanners and manual inspection.
  1. Our ethical hackers exploit vulnerabilities, which allows them to gain access to systems and data.
  1. You will receive a detailed report in which we explain all vulnerabilities along with next steps.

How Warpnet one step further is going

  1. We support you in remedying the risks identified during the test by offering technical insight and advice.
  1. After the recommendations have been applied, we will perform a retest, which
    ensures that the vulnerabilities have truly been resolved.
35+
Driven specialists
750+
Happy customers
5.000+
Assessments carried out
100.000+
Vulnerabilities discovered

Why Warpnet for DigiD pentesting?

CharacteristicWarpnetOther parties
ApproachCustomization combined with advanced AI toolsAutomatic scans, exploit attempts
RetestIncluded, with heart report for your RE auditorNot included or available at an additional cost
MethodologyNCSC guidelines, OSSTMM, PTES, and OWASPAn often superficial checklist
ReportingAudit-ready and linked to the DigiD Standard FrameworkTechnical report without context
Presentation of EvidenceScreenshots, CLI output, and attack scenariosOutput from automatic scanners
SupportGuidance during recovery and with questions from your auditorThe process ends with the PDF report

Certifications & methodologies

CCVOSCPOSSTMMPTESOWASPMeow

Penetration test types for environments such as:

For DigiD

Web application pentest

  • Realistic attack scenarios exposing vulnerabilities from the OWASP Top 10, CWE, and SANS Top 25, including around the DigiD login flow
  • Fixes are quickly validated using clear proofs of concept (PoCs) for developers and a retest
  • Audit-ready for DigiD, BIO, ISO 27001, and SOC 2; performed in accordance with NIST SP 800-115

Mobile application pen test

  • iOS and Android apps, including those with DigiD login, tested for insecure storage, API abuse, and app logic errors
  • Specific remedial steps to better protect sensitive user data
  • In accordance with the OWASP Mobile Top 10, PTES, CVSS, and the GDPR

API Penetration Test

  • Shadow and zombie APIs mapped to prevent data leaks and unauthorized access
  • Authenticated, manual tests of REST, SOAP, and GraphQL APIs and the integrations behind your DigiD portal
  • Following the OWASP API Security Top 10, BIO, SOC 2, and the GDPR

Cloud pentest

  • AWS, Azure and GCP environments running your DigiD web application tested for misconfigurations, privilege escalation and exposed services
  • Step-by-step recovery plan for a demonstrably secure cloud environment
  • Following the OWASP Kubernetes Top 10, CIS Benchmarks, NIST, BIO, ISO 27001, and SOC 2

Network pentest

  • On-premises and hybrid networks tested for zoning (DMZ), misconfigurations, lateral movement and privilege escalation
  • Risk-prioritized recommendations that IT and security teams can get started with immediately
  • Standards: NCSC guidelines, NIST SP 800-115, PTES, CIS Controls, and BIO

AI and LLM pentest

  • Vulnerabilities in AI applications, chatbots, and LLM pipelines exposed
  • Tested for, among other things, prompt injection, model manipulation, data leaks, and multi-stage exploit chains
  • Threat modeling and concrete remediation advice, aligned with ISO/IEC 42001, the EU AI Act, SOC 2, and the GDPR

Pentest services for industries such as:

Government & Municipalities

  • Citizen portals, e-forms, and case management systems behind DigiD tested against the 21 standards from Normenkader 3.0
  • Report that your RE auditor can use directly for the assessment and your ENSIA accountability
  • Standards: NCSC guidelines, BIO, OWASP, PTES

Care

  • Securing patient portals with DigiD login and APIs in web, mobile, and cloud environments
  • Detecting hidden exposure of medical data and demonstrating compliance with DigiD, NEN 7510, and the GDPR
  • Standards: OWASP, PTES, NIST, CVSS

Pensions & Insurers

  • My environments and policy portals with DigiD login protected against business logic flaws and BOLA/IDOR risks
  • Concrete fixes and demonstrable compliance with DigiD, ISO 27001, DORA and the GDPR
  • Standards: OWASP, PTES, CVSS

SaaS & Technology

  • Pentests per release or at fixed times, so that your DigiD connection continues to comply with the standard throughout the year
  • Technical evidence for the service organization's assessment report (SOC report) that your customers submit to their auditor
  • Standards: OWASP, PTES, CVSS, NIST SP 800-115

Not only suitable for DigiD, but also:

AVGISO 27001PCI DSSBIODORANIS2NEN 7510

Success story: Patchmanager

Developers of cable and asset management solutions

2024

Start of the collaboration

3

Black box pentests as a starting point

24/7

Monitoring by the Warpnet SOC

The challenge

Right in the middle of the process toward ISO 27001 certification, Patchmanager wanted to structurally strengthen the digital resilience of both the organization's internal network and the product — with regular, in-depth pentests as the foundation.

The Approach

The collaboration began with three black-box penetration tests and, as trust grew, expanded to include gray-box and white-box testing. During the white-box test, Warpnet was granted full access to the architecture, source code, and accounts to identify risks.

The outcome

Each test delivered a clear, risk-based report that allowed Patchmanager to get to work immediately. The collaboration evolved into 24/7 SOC services featuring continuous monitoring, response, and the complete remediation of risks and incidents.

“We are very happy with the collaboration with Warpnet. The team has in-depth expertise and truly looks at how they can help us. They communicate well, are flexible, and always do more than they are supposed to do.”

Jerry SeagerJerry Seager
CTO, Patch Manager

Trusted by 750+ CTOs and CISOs

Marco Vellinga

Spindle

“The team was very helpful and met every deadline. They went above and beyond by expanding the scope of the test to address unexpected issues—even though they were not obligated to do so. A truly reliable and pleasant team to work with.”

Erik Rademaker

Envitron

“Warpnet approached the task very seriously and pulled out all the stops to make the test as realistic as possible. Through observation, they discovered how they could gain alternative access to our premises. In the course of this, they succeeded in placing a listening device on the network..

Jasper Zondervan

New Woelwijck

“Warpnet's pen test provided us with a clear picture of the bottlenecks in our security so that we could improve it further. We immediately fixed the high-risk points in the week that followed. So we know that our residents and staff can live and work safely and that we comply with NEN 7510.”

Noud Huisman

Enshore

“Without Warpnet, we would estimate needing at least two additional employees, and that would only be staff who can determine what needs to be resolved – without even addressing the actual fixing of problems.”

Certifications & Accreditations

Contact us

You will hear from one of our experts within one business day.

Het team van Warpnet

Contact form

Name(Required)

Frequently Asked Questions

DigiD pentest FAQs

Is a retest included?

Yes. After your team has implemented the recommendations, we can perform a retest upon request to confirm that the vulnerabilities have indeed been resolved. With the retest report, you can show your RE auditor that the findings were resolved within the testing period.

What standards does a DigiD pentest assess against?

The DigiD Standard Framework 3.0 consists of 21 standards from the NCSC ICT security guidelines for web applications. A pentest primarily provides evidence for the technical standards: input and output validation and cryptography in the web application (U/WA.03 through U/WA.05), configuration and hardening of the web server and platform (U/PW.02, U/PW.03, U/PW.05, and U/PW.07), network zoning and hardening (U/NW.03, U/NW.05, and U/NW.06), and patch management (C.09). In addition, the pentest itself demonstrates that you comply with standard C.04.

What does a DigiD pentest by Warpnet cost?

After a no-obligation intake you will receive a quote, and that is the price you pay. The price depends on the number of DigiD connections and the size of the web application and infrastructure. Reporting, explanation and retesting are included as standard. Below you will find general price indications for a one-off pentest and Pentesting as a Service (continuous pentesting).

One-time pentest: v.a. €3,200
Pentesting as a Service: approx. €1,250 per month

Packages & Pricing

When must the DigiD pentest be completed?

You must submit the assessment report for the previous year to Logius between January 1st and May 1st. Therefore, the pentest must have been performed, and the most important findings resolved, before your RE auditor gives their opinion. For a new connection, a term of two months after activation applies. Spring is a busy period for auditors and pentesters. Therefore, it is preferable to schedule the pentest in the autumn, so that time remains for remediation and retesting.

What is the difference between a DigiD pentest and the DigiD assessment?

The DigiD ICT security assessment is an audit by a Registered EDP Auditor (RE) on all 21 standards: in design, in existence, and for five standards in operation. The DigiD pentest is part of this. Our ethical hackers test the technical standards in practice and provide the evidence upon which the auditor bases their judgment. Warpnet performs the pentest, while the audit itself is conducted by your RE auditor. We collaborate with the auditor of your choice in the process.

We supply software to DigiD connection holders. What does that mean for us?

As a service organization, you provide your customers with a service organization assessment report (SOAR, formerly TPM) regarding the measures for which you are responsible. The pentest on your application and infrastructure serves as the technical evidence for this. If you provide a standardized SaaS solution to multiple connected parties, a multi-client assessment may suffice. We align the scope with your situation so that your customers can submit their reporting to Logius on time.