Initial preparations
Before you can start integrating DigiD through the Signicat eID and Wallet Hub, you must complete the preparatory steps like signing contractual agreements and obtaining the relevant digital certificates.
When you apply to implement DigiD, you need to establish a communication channel with Logius, the provider of DigiD, and also with the Signicat Onboarding team.
This page describes the onboarding steps necessary before your developers can start testing and implementing DigiD.
It is important to note that you must first integrate with DigiD in a pre-production/test environment. Only after you have received approval on your pre-production setup, can you start building the integration in a production environment.
1. Sign agreements with Signicat
To receive access to Signicat services and connect to DigiD, you first need to enter in contractual agreements with Signicat. In particular, you need to sign the following documents:
- An agreement contract
- A data processing agreement (DPA) (signed by a legal representative)
To get started with these agreements, contact our sales team:
Note that DigiD is restricted to organisations that offer services in the public domain, such as governmental, educational or healthcare-related institutions and pension funds.
2. Comply with Logius requirements
Before you can connect to DigiD, your organisation must comply with the mandatory branding, security and infrastructure requirements of Logius.
Your connection needs to meet the criteria specified in the following documents:
After your integration is live in production, you must submit an assessment report issued by a Register EDP-auditor to Logius within two months. Your organisation should arrange the audit as part of the integration process.
Note that organisations connected to DigiD must also undergo an annual ICT security assessment. You can find more information in the official connection procedure for DigiD.
The Signicat integration of DigiD specs undergoes a separate yearly assessment for which we supply our DigiD Generieke Rapporten voor de Serviceorganisatie (RSO, formerly TPM) report to our service providers. You use the Signicat RSO report in your audit with Logius.
Due to Logius' requirements, no Signicat logo should appear on the web pages you display publicly to end-users. Therefore, you must create a custom theme for your account before your audit with Logius.
Follow the steps described in the Theming documentation to create and apply a theme without the Signicat logo.
3. Register with RvIG
When you integrate with DigiD, you process the BSN (Dutch national identity number) of your end-users. To process the BSN as personal data, it is necessary to register with the Dutch governmental organisation Rijksdienst voor Identiteitsgegevens (RvIG).
As part of the registration process, RvIG checks whether your organisation can be authorised to request a person's BSN during authentication. You can find the application form for BSN eligibility in the Aanvraagformulier Toetsing BSN-gerechtigdheid.
4. Configure your Signicat account
If you are new to Signicat, sign up for a free Signicat account by completing the following initial preparations:
- Sign up to the Signicat Dashboard and register your profile. For more details, see the Get started with Signicat guide.
- In the Signicat Dashboard, make sure you have set up an organisation.
Logius offers two separate DigiD environments:
- Pre-production (test environment)
- Production
Signicat matches this design with two separate types of account:
- Sandbox account
- Production account
Note that you must first connect, test and get approval in a pre-production/sandbox account before you proceed with the integration in a production account.
The section below guides you through your account configuration in the Signicat Dashboard.
Create a sandbox account with a custom domain
To test DigiD in the pre-production environment, you need to complete these steps
- Log in to the Signicat Dashboard.
- Create a sandbox account. For detailed instructions, see the Create an account documentation.
Existing customers
If you are an existing Signicat customer, you may reuse your existing sandbox account.
- Add a custom domain to your sandbox account. To learn how to do this, see the custom domain documentation.
Custom domain
Note that you must add a custom domain. Accounts with a Signicat subdomain (for example,
mycompany.signicat.com) cannot be used to connect to DigiD.Using Let's Encrypt certificatesIf you wish to use Let's Encrypt certificates as TLS server certificates for DigiD, you must use a
.nldomain. Learn more in the Logius documentation.
Once you have created a sandbox account with a custom domain, you can proceed to create a Certificate Signing Request (CSR) so that you can obtain PKIo certificates for DigiD.