OWASP Application Security Verification Standard (ASVS)

The OWASP Application Security Verification Standard (ASVS) Project provides a basis for testing web application technical security controls and also provides developers with a list of requirements for secure development.

About OWASP Application Security Verification Standard (ASVS)

Project Leaders

Daniel Cuthbert

Project Leader

Email

Elar Lang

Project Leader

Email

Josh Grossman

Project Leader

Email

Project Information

Flagship Project
Classification
Documentation
Language
HTML
License
Creative Commons Attribution Share Alike 4.0 International
Latest Version
5.0.0 (Bleeding Edge)
Contributors
141
GitHub Stars
3626
Downloads
43972

Requirements

  • Web application security knowledge
  • Understanding of security testing methodologies
  • Familiarity with security controls and frameworks
  • Basic knowledge of web application architecture
  • Security assessment tools and techniques
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.
OWASP Application Security Verification Standard (ASVS) | OWASP Foundation