Application & API Security

OWASP ASVS

Application Security Verification Standard

Community Global OWASP Since 2009

A catalogue of application security requirements organised into verification levels, written so each requirement can be tested rather than asserted.

Unlike the Top 10 lists, ASVS is a requirements standard: it is what you put in a supplier contract or a definition of done when "secure" has to survive contact with an auditor.

At a glance

Category
Application & API Security
Jurisdiction
Global
Governance
OWASP
Status
Version 5.0 (2025)
First released
2009

Links

Related frameworks

Other entries under Application & API Security.

See OWASP ASVS in context

Open the interactive Data Landscape for Regulation to compare OWASP ASVS against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.