For the complete documentation index, see llms.txt. You can also append .md to any page URL to get its markdown version.
Skip to main content
For the complete documentation index, see llms.txt.

For the complete documentation index, see llms.txt

Initial preparations

Before you can start integrating DigiD through the Signicat eID and Wallet Hub, you must complete the preparatory steps like signing contractual agreements and obtaining the relevant digital certificates.

When you apply to implement DigiD, you need to establish a communication channel with Logius, the provider of DigiD, and also with the Signicat Onboarding team.

This page describes the onboarding steps necessary before your developers can start testing and implementing DigiD.

Pre-production and production

It is important to note that you must first integrate with DigiD in a pre-production/test environment. Only after you have received approval on your pre-production setup, can you start building the integration in a production environment.

1. Sign agreements with Signicat​

To receive access to Signicat services and connect to DigiD, you first need to enter in contractual agreements with Signicat. In particular, you need to sign the following documents:

  1. An agreement contract
  2. A data processing agreement (DPA) (signed by a legal representative)

To get started with these agreements, contact our sales team:

Contact an expert

Which organisations can offer DigiD?

Note that DigiD is restricted to organisations that offer services in the public domain, such as governmental, educational or healthcare-related institutions and pension funds.

2. Comply with Logius requirements​

Before you can connect to DigiD, your organisation must comply with the mandatory branding, security and infrastructure requirements of Logius.

Your connection needs to meet the criteria specified in the following documents:

After your integration is live in production, you must submit an assessment report issued by a Register EDP-auditor to Logius within two months. Your organisation should arrange the audit as part of the integration process.

Note that organisations connected to DigiD must also undergo an annual ICT security assessment. You can find more information in the official connection procedure for DigiD.

Signicat's assessment

The Signicat integration of DigiD specs undergoes a separate yearly assessment for which we supply our DigiD Generieke Rapporten voor de Serviceorganisatie (RSO, formerly TPM) report to our service providers. You use the Signicat RSO report in your audit with Logius.

Required: DigiD theming

Due to Logius' requirements, no Signicat logo should appear on the web pages you display publicly to end-users. Therefore, you must create a custom theme for your account before your audit with Logius.

Follow the steps described in the Theming documentation to create and apply a theme without the Signicat logo.

3. Register with RvIG​

When you integrate with DigiD, you process the BSN (Dutch national identity number) of your end-users. To process the BSN as personal data, it is necessary to register with the Dutch governmental organisation Rijksdienst voor Identiteitsgegevens (RvIG).

As part of the registration process, RvIG checks whether your organisation can be authorised to request a person's BSN during authentication. You can find the application form for BSN eligibility in the Aanvraagformulier Toetsing BSN-gerechtigdheid.

4. Configure your Signicat account​

New customers

If you are new to Signicat, sign up for a free Signicat account by completing the following initial preparations:

  1. Sign up to the Signicat Dashboard and register your profile. For more details, see the Get started with Signicat guide.
  2. In the Signicat Dashboard, make sure you have set up an organisation.

Logius offers two separate DigiD environments:

  • Pre-production (test environment)
  • Production

Signicat matches this design with two separate types of account:

  • Sandbox account
  • Production account
How to proceed

Note that you must first connect, test and get approval in a pre-production/sandbox account before you proceed with the integration in a production account.

The section below guides you through your account configuration in the Signicat Dashboard.

Create a sandbox account with a custom domain​

To test DigiD in the pre-production environment, you need to complete these steps

  1. Log in to the Signicat Dashboard.
  2. Create a sandbox account. For detailed instructions, see the Create an account documentation.
    Existing customers

    If you are an existing Signicat customer, you may reuse your existing sandbox account.

  3. Add a custom domain to your sandbox account. To learn how to do this, see the custom domain documentation.
    Custom domain

    Note that you must add a custom domain. Accounts with a Signicat subdomain (for example, mycompany.signicat.com) cannot be used to connect to DigiD.

    Using Let's Encrypt certificates

    If you wish to use Let's Encrypt certificates as TLS server certificates for DigiD, you must use a .nl domain. Learn more in the Logius documentation.

Once you have created a sandbox account with a custom domain, you can proceed to create a Certificate Signing Request (CSR) so that you can obtain PKIo certificates for DigiD.

Next step​