Skip to main content

WASP Application Security Verification Standard (ASVS)

WASP Application Security Verification Standard (ASVS)
info

Available on Premium subscription plan and in Atlassian Jira application Cybersecurity Controls for Jira.

The OWASP Application Security Verification Standard (ASVS) is a globally recognized open standard for assessing and verifying application security controls throughout the lifecycle of web applications and APIs. It provides a comprehensive set of security requirements and verification criteria that helps organizations engineer and validate secure applications.



OWASP Application Security Verification Standard (ASVS):

What is its purpose?

It can be used for a variety of reasons, but the most common are those listed below.

ASVS categorizes security requirements into multiple assurance levels, allowing teams to choose the right depth of verification based on application risk and sensitivity:

  • Level 1: Basic security suitable for low-risk applications
  • Level 2: Standard security with deeper requirements
  • Level 3: Advanced security for high-risk or highly regulated systems

Security assessments & testing

OWASP ASVS Enables structured verification across critical security domains.

Development guidance

Helps developers incorporate secure controls early in the SDLC.

Procurement & compliance

Acts as a clear baseline for specifying security requirements in contracts.


Industries

OWASP ASVS is suitable for any organization that builds or maintains web applications or services — from startups and SMEs to large enterprises in sectors such as finance, healthcare, e-commerce, public sector, and more.


Unicis solution

In the Unicis apps below, you can find The Criteria Catalogue C5:2020 best security controls.

Frameworks

General Data Protection Regulation (GDPR)Minimum Viable Secure Product (MVSP)ISO/IEC 27001NIST Cybersecurity Framework v2.0EU NIS 2 DirectiveThe CIS Critical Security Controls for Effective Cyber DefenseC5 (Cloud Computing Compliance Controls Catalogue)System and Organization Controls 2 Type 2OWASP Application Security Verification Standard (ASVS)EU Cyber Resilience ActEU Digital Operational Resilience Act (DORA)Payment Card Industry Data Security StandardCloud Controls Matrix (CCM)ISO/IEC 42001 Artificial Intelligence Management System (AIMS)MITRE ATT&CKCustom Frameworks