OWASP DevSecOps Verification Standard

OWASP DevSecOps Verification Standard - An OWASP incubator project

About OWASP DevSecOps Verification Standard

OWASP DevSecOps Verification Standard

The OWASP DevSecOps Verification Standard (DSOVS) is an open source framework that defines baseline requirements for any software project or organisation. You can use the DSOVS for:

πŸ’¬ Connect with Us

#project-devsecops-verification-standard @realjvo (Jamieson Vincenti O'Reilly, Project Lead) @yudhiy (Yudhi Yudhistira, Project Lead)

πŸŽ‰ Get Involved

Your contribution will help the DSOVS evolve as processes and technologies are ever changing. We welcome any kind of contribution and feedback to help make the DSOVS an even better open source project. Join our community today and be part of the journey For each phase, there are streams that the DSOVS assesses:## πŸ“– Table-of-Contents

Code/Build Phase

🚧 CODE-001 Secure Development Environment βœ… CODE-002 Hardcoded Secrets Detection 🚧 CODE-003 Manual Secure Code Review 🚧 CODE-004 Static Application Security Testing (SAST) 🚧 CODE-005 Software Composition Analysis (SCA) 🚧 CODE-006 Software License Compliance 🚧 CODE-007 Inline IDE Secure Code Analysis 🚧CODE-008 Container Security Scanning 🚧 CODE-009 Secure Dependency Management
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
Β© 2026, OWASP Foundation Inc. All rights reserved.