OWASP Continuous Penetration Testing Framework

OWASP Continuous Penetration Testing Framework - An OWASP incubator project

About OWASP Continuous Penetration Testing Framework

The landscape of Web Application security is ever changing and evolving. WebApp penetration testing is not what it used to be 5/10 years ago or even earlier. The organisations and/or the developers have adopted agile practices and methodologies, focusing on smaller incremental changes of the codebase following methodologies like Scrum etc. This practically means that the InfoSec and AppSec community need to adapt their practices and methodologies to reflect a well suited coverage when it comes to penetration testing and assessing those Web Applications. The Continuous Penetration Testing Framework project intends to be a standarisation of Continuous Penetration Testing across the AppSec community. It will describe all the relevant: While making sure it follows all the highest industry standards and best practices. This project will stimulate research around the future of AppSec and penetration testing, with a focus on the continuous aspect, following the development principles of Agility and the DevSecOps principles of Shift Left. It will go hand-in-hand with OWASP’s objectives of educating security professionals in effective Application Security practices and promoting Secure Coding principles in the Development community. It aims to act as an open and central point of knowledge transfer and exchange of opinions.

Project Resources

Project Information

Incubator Project
Classification
Incubator
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.
OWASP Continuous Penetration Testing Framework