The OWASP Thick Client Application Security Verification Standard (TCASVS) provides a framework for testing the security controls of desktop and thick client applications, and gives developers a clear set of requirements for building them securely.
The OWASP Thick Client Application Security Verification Standard (TCASVS) is an open standard for securing desktop and thick client applications. It provides a practical framework for designing, building, and testing security controls across areas like architecture, secure development lifecycle, threat modeling, CI/CD, and configuration management. Until now, there was no dedicated standard for thick client apps.
The ASVS covers web applications and the MASVS targets mobile, but neither is a great fit for thick client testing. The TCASVS fills that gap with a standard purpose-built for those applications.
The project is mainly maintained by a single project leader Dave Hanson. However, he is heavily supported by his active AppSec team at Bentley Systems who include Samuel Aubert, Einaras Bartkus, and John Cotter. An early and substantial contributer Thomas Chauchefoin now works for Trail of Bits.
The project is also supported by the OWASP community and the OWASP Foundation. Special thanks to Starr Brown for her support in her capacity as Director of Projects.
The first public version that was suitable for use was released in September 2024. The project is in the process of refining the standard and adding more content.
2026 sees us align our work to the flagship ASVS projects architecture, making it easier for downstream consumers to adopt the TCASVS.
The project is looking for contributors to help with the migration to ASVS architecture.

Bentley is the leading provider of infrastructure engineering software, advancing infrastructure for better quality of life and sustainability. Visit bentley.com to learn more.