Siam Thanat Hack Co., Ltd.

Penetration Testing Requirements for NDID Members

NDID is infrastructure for digital identity proofing and authentication that connects participating service providers in different roles.

Executive Summary and Mandate Overview
Target Audience NDID Members: Relying Parties (RP), Identity Providers (IdP), Authoritative Sources (AS)
Mandatory Frequency At least annually prior to node onboarding or annual re-certification
Required Scope NDID Proxy Nodes, HSM Key Modules, OAuth2 and OIDC Endpoints, Encryption Gateways
Non-Compliance Risk Suspension from NDID network and revocation of cross-organizational ID verification rights

Preparing assessment evidence for NDID

Onboarding criteria can differ by member role and package. The latest NDID criteria must be the controlling document for scope, tester eligibility, and report format.

Thai infographic explaining: Preparing assessment evidence for NDID
Visual summary: Preparing assessment evidence for NDID
  • Define the member systems connected to the NDID Platform and do not extend testing to an NDID Node unless the received criteria explicitly requires it.
  • Confirm tester eligibility and independence under the criteria NDID accepts, including certification evidence where required.
  • Test relevant web, mobile, API, network, and operating-system layers using the method named in the package, such as OSSTMM, NIST SP 800-115, or OWASP guidance.
  • Treat Critical, High, and Medium findings under the criteria, document any permitted low-risk rationale, and submit the final report with retest evidence through the onboarding process.

NATIONAL DIGITAL ID

NDID is infrastructure for digital identity proofing and authentication that connects participating service providers in different roles.

What members prepare for a security assessment

  • Test the member applications, web systems, network layer, and operating systems involved in the NDID Platform connection. The NDID Node is excluded unless the issued criteria state otherwise.
  • The onboarding criteria supplied by the user call for an external juristic-person testing provider and evidence of tester qualifications such as GPEN, eCPPT, OSCP, or another certification accepted by NDID for the member role.
  • Testing follows OSSTMM or NIST SP 800-115 with the OWASP Web/Mobile Testing Guide, or PTES/ISSAF, according to the criteria issued to the member.
  • Critical, High, and Medium findings must be corrected. Low findings are corrected or supported by a recorded rationale, and corrected vulnerabilities are retested.
  • The member submits the final Penetration Test Report and tester certificate to NDID. The supplied criteria state at least annually and after significant changes.
Confirm the current criteria

Details may differ by member role and onboarding package. This summary reflects the criteria supplied by the user, not a publicly controlled document. Members should follow the latest criteria received from NDID.

Requirements and Testing Scope Matrix

Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.

Reference Mandate Title Scope Required Testing Cycle
NDID Security Standard 2.0 Security Requirements for Relying Party (RP) Members NDID Proxy Node, Application Integration, Webhook Endpoints At least annually
NDID IdP and AS Rules Security Requirements for Identity Providers (IdP) and Authoritative Sources (AS) HSM Key Modules, OAuth2 and OIDC Endpoints, Encryption Gateways At least annually prior to re-certification

Compliance Readiness Self-Assessment

Select items your organization has completed to evaluate your readiness score.

0%

Official source documents

See NDID platform standards and membership on the official NDID website.

Go to the official source