Revised Assurance Levels Regulatory Assistance Tool
The Assurance Levels Regulatory Assistance Tool helps service providers classify their digital services. The update made the tool more user-friendly and effective.
The Digital Government Act ( Wet Digitale Overheid or Wdo) ensures that Dutch citizens and businesses can log in safely and reliably when accessing services provided by (semi-)government organisations. To this end, citizens are provided with trustworthy electronic identification methods (eID), offering substantial or high-level assurance of a user’s identity.
These identification methods give public service providers more certainty about someone’s identity. Additionally, this act mandates open standards, achieved by implementing the European directive on the accessibility of government websites and apps in the Netherlands.
The first part of the Wdo concerns safe login to services at (semi-)government organisations and the application of standards, such as information security standards.
The regulation is a so-called framework law, regulating general principles, responsibilities, and procedures, but not detailed rules. This allows for flexibility with new developments while ensuring that important values and certainties for citizens, such as user-friendliness, reliability, safety, privacy, and digital inclusion, are always safeguarded. The Wdo:
This regulation covers safe login to services at (semi-)government institutions. The Wdo specifies which of these institutions will be subject to the new rules for access to their electronic services. These include:
The implementation of the Wdo as a framework law takes place in lower-level legislation, such as general administrative orders (AMvB’s) and ministerial decrees. This allows space for innovation, different choices, and new facilities and functionalities.
This proposal enables public and private login methods for digital interactions with, for example, municipalities and healthcare institutions. Only methods checked by the government for safety and reliability are admitted for public use. Although logging into services of commercial/private entities such as online stores is not regulated by this law, citizens can also log in with the approved private methods, delivering a wider effect and giving an advantage for safe login.
Obligations regarding safety standards will come into effect on July 1. For instance, the HTTPS standard becomes legally mandatory for all publicly accessible government websites and web applications. This standard, also known as ‘the padlock’ in the URL address bar, ensures that the connection between the visitor’s browser and the government organisation’s website is well-secured. This prevents criminals from accessing private data or manipulating requested information.
In addition to HTTPS, government organisations must also use the HSTS standard, making sure that browsers connect directly via HTTPS after a first website visit. Furthermore, the HTTPS configuration must comply with the TLS guidelines and Web Application Guidelines of the National Cyber Security Centre (NCSC). See also the Frequently Asked Questions about the HTTPS and HSTS obligation for government websites (in Dutch).
The Temporary Decree on Digital Accessibility of the Government has been converted into the Digital Government Act. Thus, from July 1, the Wdo became the legal basis for the Decree. With the enactment of the Wdo, nothing changes in the legal obligation, the word ‘Temporary’ is omitted, and the Decree on Digital Accessibility of the Government remains in force.
After enactment:
The law aligns with European developments in digital government services and access to digital government services. The admitted public and private login methods must meet the European requirements for login methods (eIDAS Regulation).
The Wdo will be implemented in phases. It will be applicable to an entity once it is technically and organisationally prepared to comply. The departments, public service providers, and Logius will jointly develop a plan containing a timeline. The timeline will specify when particular sections of the regulation will come into effect for each institution. Service providers are expected to complete their preparatory work for these sections of the law, as well as for the associated implementation regulations in line with the established timeline. For more information, refer to the transitional provisions of the Digital Government Act.
The overall responsibility for managing the Generic Digital Infrastructure (GDI) and the eID provisions lies with the Minister of the Interior and Kingdom Relations (BZK).
Caribbean News - 18 April 2025
The Assurance Levels Regulatory Assistance Tool helps service providers classify their digital services. The update made the tool more user-friendly and effective.
Caribbean News - 19 March 2025
The government is extending the transition period for DigiD login level ‘low’ by 3 years. Contribute your ideas for improvements online via the internet consultation.
Caribbean News - 11 March 2025
As its director, Rob Kerstens was involved in developing the new System Access. Recently stepped down from his duties, he offers his reflection on the situation.
Featured Stories - 15 July 2024
The Digital Government Act is the core of the new System Access, which consolidates existing systems such as eIDAS. Discover its progress and how it lays a future-proof foundation for secure digital services.
If you're working on digitalising the government and got something on your mind, please share your thoughts with us.