DigiD SAML integration Assurance levels Assessment-ready

Custom DigiD integration development

Appfront builds custom connections of your portal or application to DigiD, so that citizens can log in securely with the login method they already know. We integrate via Logius's official DigiD SAML interface, at the assurance level that suits your service, with PKIoverheid certificates, watertight logging and a set-up that passes the annual DigiD assessment.

What is a DigiD integration?

DigiD is the government facility that allows citizens to identify themselves digitally to government and designated organisations. DigiD is managed by Logius, part of the Ministry of the Interior and Kingdom Relations. A citizen logs in with the method they know, such as a username and password, SMS verification or the DigiD app, and your organisation can be certain which citizen it is dealing with.

In practice, a DigiD integration means your application connects as a service provider to Logius's DigiD SAML interface. When logging in, your application redirects the citizen to DigiD; after successful authentication at the agreed assurance level, you receive the citizen's BSN (citizen service number) back and can show them their personal environment. The four levels, Basic, Middle, Substantial and High, determine how strongly the identity has been verified; for privacy-sensitive data, at least Substantial is required.

Appfront builds in line with the official Logius documentation and the DigiD standards framework. We set up the SAML integration, certificates, logging and error handling so that the connection is not only technically correct but also passes the mandatory annual ICT security assessment. That way every citizen logs in reliably, even at peak moments such as the tax return period or a local election.

Secure login for citizens

Citizens log in using a sign-in method they already know and trust. Your organisation receives the citizen service number (BSN) back with certainty, without having to manage passwords or login credentials yourself.

Four assurance levels

Basic, Medium, Substantial or High — you choose the level that suits the sensitivity of your data. For medical or other particularly sensitive data, Logius requires at least Substantial, including the verified DigiD app.

Connecting to Logius

We guide the entire connection process with Logius: from the application and the exchange of signed metadata with PKIoverheid certificates, through to the first go-live in production and the annual assessment.

Our development process for DigiD integrations

We work with a proven methodology that removes uncertainty early and delivers a connection that passes the assessment. From determining the right assurance level and applying to Logius through to going live and ongoing management, every step is aimed at an integration that your organisation can understand and account for itself.

1
Analysis & level

We determine which assurance level your service requires, which applications need to connect and which data you want to display after sign-in, and align the application to Logius on that basis.

2
Architecture

We design the SAML integration, arrange the PKIoverheid certificates and signed metadata, and define a logging and error-handling strategy in line with the standards framework.

3
Development

Implementation with automated tests, structured logging and monitoring, initially against DigiD's pre-production environment. You will see working builds along the way.

4
Go-live & assessment

Controlled connection to the production environment, followed by ongoing management, certificate management and annual preparation for the DigiD assessment.

What a DigiD integration delivers in practice

Every DigiD integration is tailored to your application, the assurance level you need and the systems around it. Below are the features we most often deliver for organisations that want citizens to log in securely.

SAML connection to DigiD

Full connection to the DigiD SAML interface: your application as a service provider, signed metadata exchange with PKIoverheid certificates and correct processing of the authentication response, including the returned BSN (citizen service number).

Tailored assurance level

Configuration at Basic, Medium, Substantial or High, enforced per application or even per action. For example, you can allow sign-in at Medium while only displaying sensitive data after a step up to Substantial.

Session and authorisation management

Secure session management with correct timeouts, single logout and linking of the BSN to your own user administration. Citizens see only their own records, with strictly separated rights and authorisations.

Logging & audit trail

Complete, tamper-resistant logging of authentications and relevant events, as the standards framework prescribes. The audit trail serves as evidence during the annual DigiD assessment and in incident investigations.

DigiD Machtigen & eIDAS

Optionally extendable with DigiD Machtigen (DigiD authorisation), so that someone can act on behalf of another person, and with eIDAS for citizens from other EU member states who gain access to your service with their national login means.

Certificate & metadata management

Monitoring the validity of your PKIoverheid certificates and renewing them in time, plus correct management of the metadata exchanged with DigiD. This prevents an expired certificate from taking citizens' login facility offline.

Typical use cases in practice

A DigiD integration looks different for every organisation. There are a number of contexts we see often, wherever citizens need to log in securely to view their own data or file.

Municipal citizen portals

MyEnvironment portals where residents handle their affairs: reporting a change of address, requesting an extract or tracking the status of an application. DigiD guarantees that the citizen is who they say they are. Also read about software for municipalities and building a municipality website.

Healthcare & Patient Portals

Patient portals and secure environments where people view their medical records, test results or appointments. As this involves special category personal data, we default to a minimum of Substantial with the verified DigiD app.

Education & Student Finance

Educational institutions and implementing organisations where students and parents manage enrolments, applications and financial arrangements. DigiD links login to the citizen service number (BSN), so every file belongs to the right person.

Pensions & insurers

Pension funds and designated insurers that give members and policyholders secure access to their personal overview. Citizens log in with DigiD to view their pension statement, policies or claims, without separate accounts.

Technology we use

We build DigiD integrations on Logius's official SAML 2.0 interface, combined with the backend stack that suits you. The exact choice depends on your existing application and infrastructure, so that your own team can manage the connection and account for it during the assessment.

DigiD SAML interface (SAML 2.0) PKIoverheid certificates (G1 root) Signed metadata exchange Assurance levels Basic through High DigiD app & ID check DigiD Machtigen (authorisation) eIDAS integration Java / .NET / PHP / Node.js / Python XML signing & encryption TLS 1.2+ (back-channel) Pre-production & production environments Complete audit logging Single logout & session management DigiD assessment framework Monitoring & alerting Certificate rotation

Why choose Appfront for your DigiD integration?

Appfront has extensive experience building integrations for (semi-)public sector organisations in the Netherlands. We always start with a thorough analysis of your existing systems and the right assurance level. A DigiD connection must not only be technically correct, but also pass the mandatory assessment and work in practice for your residents or participants.

For every integration we write clear documentation and make sure your own team, or a future supplier, can understand, manage and account for the connection to the auditor. No black box, but transparent code and clear agreements on certificate management, monitoring and logging.

You work with a single point of contact who understands both the technology of the SAML interface and the requirements of the standards framework. That keeps communication lines short, prevents miscommunication and speeds up decisions when choices have to be made during the connection process.

See also our wider services around eHerkenning integrations, MijnOverheid integrations, SURFconext integrations and custom software. Or get in touch for a no-obligation consultation.

  • Experience with the DigiD SAML interface and the assessment framework
  • Familiar with PKIoverheid certificates and signed metadata
  • Set up at the correct assurance level (Basic through High)
  • Guidance on connecting to Logius and the annual assessment
  • Secure by default: complete logging, encryption and access control
  • Structured error handling and monitoring from day one
  • Clear documentation that your team and the auditor can read
  • A fixed point of contact, no account managers passed around
  • Ongoing management, certificate management and further development
  • A way of working aligned with your existing IT landscape

Security and privacy in DigiD integrations

With DigiD, everything revolves around citizens' identities and the citizen service number (BSN), which is highly sensitive personal data. Connecting to DigiD is therefore bound to a mandatory annual ICT security assessment: an independent auditor tests your service against the DigiD assessment framework, and the report must be submitted to Logius within two months of connecting to the production environment. Appfront builds the integration to be assessment-proof, with complete logging, encryption, strict access control and the documentation the auditor needs.

The technical security of the interface rests on PKIoverheid: the service provider supplies signed metadata with a PKIoverheid certificate, and the back-channel connections run over TLS with machine certificates under the G1 root. We document the data flows around the BSN so that your processing register is complete and you demonstrably comply with the GDPR. The audit logging serves as evidence during the assessment and in any incident investigation.

Also read how we approach AI for municipalities and government, or take a look at our custom software for water boards. Questions about your situation? Get in touch.

Alongside DigiD, the European Digital Identity Wallet is on its way, with many public service providers obliged to accept recognised wallets. What this requires, and why you should build that route alongside your existing login methods, is covered in accepting the EUDI wallet in your software.

  • Annual DigiD assessment against the assessment framework
  • PKIoverheid certificates and signed metadata
  • Encryption in transit (TLS 1.2+) and at rest
  • Complete, tamper-resistant audit logging
  • Role-based access and least-privilege principles
  • Monitoring and alerting for anomalies
  • Timely certificate rotation and metadata management
  • Documentation for your record of processing activities

Frequently Asked Questions About DigiD Integrations

Answers to the questions we receive most often about DigiD connections.

A DigiD integration is a technical connection between your web application and DigiD, the government facility from Logius that lets citizens log in digitally and securely. The integration runs via the DigiD SAML interface: your application acts as the service provider and DigiD as the identity provider. After successful authentication, your application receives the citizen service number (BSN) of the logged-in citizen at the agreed assurance level. An integration requires registration with Logius and an annual ICT security assessment.

DigiD is intended for citizens logging in to government and designated organisations. If you want business owners, companies or professionals to log in on behalf of an organisation, you use eHerkenning, the B2G counterpart of DigiD. Many organisations offer both. Appfront builds both DigiD and eHerkenning integrations and can combine them in a single login screen.

DigiD has four assurance levels: Basic (logging in with a username and password), Medium (username, password and SMS verification or the DigiD app), Substantial (the DigiD app with an identity document checked through ID verification) and High (logging in with an eID on an identity document). The required level depends on the sensitivity of the data; for particularly privacy-sensitive data such as medical records, Logius requires at least Substantial. We determine the appropriate level together with you using the Assurance Levels Guidance.

The integration runs via the DigiD SAML interface, based on the SAML 2.0 standard. Your application exchanges signed metadata with DigiD, and a PKIoverheid certificate is mandatory for signing. The back-channel TLS connections use machine certificates under the PKIoverheid G1 root. We implement the integration in the backend stack that suits you (Java, .NET, PHP, Node.js or Python) and set up logging and monitoring as the standards framework requires. Logius is working on an OIDC interface; until that is widely available, SAML is the standard.

The cost depends on the assurance level you need, the number of applications that need to connect, the complexity of your existing system, and the support you want with the connection process and the annual ICT security assessment. Ongoing management, monitoring and certificate management also factor in. We always provide a clear quote following a no-obligation analysis of your situation.

Every online service connected to DigiD must undergo an annual ICT security assessment (the DigiD assessment). An independent auditor tests the service against the standards framework, and the assessment report must be submitted to Logius within two months of connecting to the production environment. Appfront builds the integration to be assessment-ready, with appropriate logging, encryption, access control and documentation, and supports you in supplying the evidence the auditor needs.

Yes. Appfront regularly takes over existing DigiD connections, even where they were originally set up by another party. We review the SAML configuration, certificates, logging and error handling, document the current setup and propose improvements. From then on, we handle changes, timely renewal of PKIoverheid certificates, monitoring and preparation for the annual DigiD assessment.

DigiD is intended for government organisations and organisations with a public or statutory task that are permitted to process the citizen service number, such as municipalities, healthcare providers, educational institutions, pension funds and certain insurers. Connection is handled through Logius, which checks for each organisation whether you are entitled to connect. Appfront supports the entire process, from the application and technical connection through to going live and the assessment.

Ready to build your DigiD integration?

Tell us which application you want to connect to DigiD and what assurance level your service requires. We're happy to think along with you on the interface, the PKIoverheid certificates and the annual assessment. A no-obligation first conversation gives you a clear picture of the options within half an hour.

Edit content