Penetration Testing Requirements for NDID Members
NDID is infrastructure for digital identity proofing and authentication that connects participating service providers in different roles.
Preparing assessment evidence for NDID
Onboarding criteria can differ by member role and package. The latest NDID criteria must be the controlling document for scope, tester eligibility, and report format.

- Define the member systems connected to the NDID Platform and do not extend testing to an NDID Node unless the received criteria explicitly requires it.
- Confirm tester eligibility and independence under the criteria NDID accepts, including certification evidence where required.
- Test relevant web, mobile, API, network, and operating-system layers using the method named in the package, such as OSSTMM, NIST SP 800-115, or OWASP guidance.
- Treat Critical, High, and Medium findings under the criteria, document any permitted low-risk rationale, and submit the final report with retest evidence through the onboarding process.
NATIONAL DIGITAL ID
NDID is infrastructure for digital identity proofing and authentication that connects participating service providers in different roles.
สิ่งที่สมาชิกต้องเตรียมสำหรับ Security Assessment
- ทดสอบระบบ Application, Web, Network layer และ Operating System ของสมาชิกที่เกี่ยวข้องกับระบบที่เชื่อมต่อกับ NDID Platform โดยไม่รวม NDID Node เว้นแต่เกณฑ์ที่ได้รับระบุเป็นอย่างอื่น
- เกณฑ์ onboarding ที่ผู้ใช้ให้มาระบุให้ใช้ผู้ทดสอบจากนิติบุคคลภายนอก และแนบหลักฐานคุณสมบัติผู้ทดสอบ เช่น GPEN, eCPPT, OSCP หรือใบรับรองอื่นตามรายการที่ NDID ยอมรับสำหรับบทบาทนั้น
- แนวทางทดสอบอ้างอิง OSSTMM หรือ NIST SP 800-115 ร่วมกับ OWASP Web/Mobile Testing Guide หรือใช้ PTES/ISSAF ตามเกณฑ์ฉบับที่ NDID ส่งให้สมาชิก
- Critical, High และ Medium ต้องได้รับการแก้ไข ส่วน Low ต้องแก้ไขหรือบันทึกเหตุผล พร้อม Retest ช่องโหว่ที่แก้ไขแล้ว
- จัดส่ง Final Penetration Test Report และใบรับรองผู้ทดสอบให้ NDID พิจารณา โดยเกณฑ์ที่ให้มาระบุความถี่อย่างน้อยปีละครั้งและหลัง Significant Change
รายละเอียดอาจแตกต่างตามบทบาทสมาชิกและ onboarding package ข้อความนี้สรุปจากเกณฑ์ที่ผู้ใช้ให้มา ไม่ใช่เอกสารสาธารณะฉบับควบคุม สมาชิกควรใช้ Criteria ล่าสุดที่ได้รับจาก NDID เป็นหลัก
Requirements and Testing Scope Matrix
Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.
| Reference | Mandate Title | Scope Required | Testing Cycle |
|---|---|---|---|
| NDID Security Standard 2.0 | Security Requirements for Relying Party (RP) Members | NDID Proxy Node, Application Integration, Webhook Endpoints | At least annually |
| NDID IdP and AS Rules | Security Requirements for Identity Providers (IdP) and Authoritative Sources (AS) | HSM Key Modules, OAuth2 and OIDC Endpoints, Encryption Gateways | At least annually prior to re-certification |
Compliance Readiness Self-Assessment
Select items your organization has completed to evaluate your readiness score.
