Penetration Testing Requirements for NDID Members
NDID is infrastructure for digital identity proofing and authentication that connects participating service providers in different roles.
Preparing assessment evidence for NDID
Onboarding criteria can differ by member role and package. The latest NDID criteria must be the controlling document for scope, tester eligibility, and report format.

- Define the member systems connected to the NDID Platform and do not extend testing to an NDID Node unless the received criteria explicitly requires it.
- Confirm tester eligibility and independence under the criteria NDID accepts, including certification evidence where required.
- Test relevant web, mobile, API, network, and operating-system layers using the method named in the package, such as OSSTMM, NIST SP 800-115, or OWASP guidance.
- Treat Critical, High, and Medium findings under the criteria, document any permitted low-risk rationale, and submit the final report with retest evidence through the onboarding process.
NATIONAL DIGITAL ID
NDID is infrastructure for digital identity proofing and authentication that connects participating service providers in different roles.
What members prepare for a security assessment
- Test the member applications, web systems, network layer, and operating systems involved in the NDID Platform connection. The NDID Node is excluded unless the issued criteria state otherwise.
- The onboarding criteria supplied by the user call for an external juristic-person testing provider and evidence of tester qualifications such as GPEN, eCPPT, OSCP, or another certification accepted by NDID for the member role.
- Testing follows OSSTMM or NIST SP 800-115 with the OWASP Web/Mobile Testing Guide, or PTES/ISSAF, according to the criteria issued to the member.
- Critical, High, and Medium findings must be corrected. Low findings are corrected or supported by a recorded rationale, and corrected vulnerabilities are retested.
- The member submits the final Penetration Test Report and tester certificate to NDID. The supplied criteria state at least annually and after significant changes.
Details may differ by member role and onboarding package. This summary reflects the criteria supplied by the user, not a publicly controlled document. Members should follow the latest criteria received from NDID.
Requirements and Testing Scope Matrix
Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.
| Reference | Mandate Title | Scope Required | Testing Cycle |
|---|---|---|---|
| NDID Security Standard 2.0 | Security Requirements for Relying Party (RP) Members | NDID Proxy Node, Application Integration, Webhook Endpoints | At least annually |
| NDID IdP and AS Rules | Security Requirements for Identity Providers (IdP) and Authoritative Sources (AS) | HSM Key Modules, OAuth2 and OIDC Endpoints, Encryption Gateways | At least annually prior to re-certification |
Compliance Readiness Self-Assessment
Select items your organization has completed to evaluate your readiness score.
