OWASP MASVS
What is OWASP MASVS?
OWASP Mobile Application Security Verification Standard. It comprises 8 controls organised across 8 domains, published by OWASP Foundation, and applies in International.
How OWASP MASVS maps to other frameworks
All 8 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 8 domains OWASP MASVS groups its controls into
Where OWASP MASVS overlaps with the standards you already hold
What OWASP MASVS means in your sector
What OWASP MASVS means for your job
Questions people ask about OWASP MASVS
What is OWASP MASVS?
How many controls does OWASP MASVS have?
Where does OWASP MASVS apply?
What frameworks does OWASP MASVS map to?
How do I get started with OWASP MASVS compliance?
Query OWASP MASVS programmatically
OWASP MASVS, its 8 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
OWASP MASVS API reference and MCP config →What OWASP MASVS requires, control by control
Each page carries the requirement text for one OWASP MASVS control and what an assessor expects to see as evidence.
- OWASPMASVS-1 MASVS-STORAGE: Storage of Sensitive Data
- OWASPMASVS-2 MASVS-CRYPTO: Cryptography Usage
- OWASPMASVS-3 MASVS-AUTH: Authentication and Authorization
- OWASPMASVS-4 MASVS-NETWORK: Network Communication
- OWASPMASVS-6 MASVS-CODE: Code Quality, Build Settings, and Updates
- OWASPMASVS-7 MASVS-RESILIENCE: Resilience Against Reverse Engineering
- OWASPMASVS-8 MASVS-PRIVACY: Privacy and Data Protection
How ready are you for OWASP MASVS?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.