OWASP Thick Client Application Security Verification Standard (TCASVS)

The OWASP Thick Client Application Security Verification Standard (TCASVS) provides a framework for testing the security controls of desktop and thick client applications, and gives developers a clear set of requirements for building them securely.

About OWASP Thick Client Application Security Verification Standard (TCASVS)

Project Resources

Project Leaders

Dave Hanson

Email

Project Information

Incubator Project
Classification
Standards
Language
TeX
License
Creative Commons Attribution Share Alike 4.0 International
Latest Version
1.8
Contributors
7
GitHub Stars
31
Downloads
1323
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.