Parameter

What is OWASP ASVS?

OWASP Application Security Verification Standard

What OWASP ASVS is, its three verification levels, and how teams use it to scope penetration tests and secure development.

01Introduction

The OWASP Top 10 tells you what goes wrong in web apps. ASVS tells you what to check to show it hasn't. It's the most detailed open standard for testing application security.

02What is OWASP ASVS?

The OWASP Application Security Verification Standard (ASVS) is an open list of security requirements for designing, building and testing web applications and services. Version 5.0 was released in 2025.

Requirements cover areas such as authentication, session management, access control, input validation, cryptography, APIs and configuration. They are grouped into three levels: L1 as a baseline, L2 for applications handling sensitive data (the recommended default for most), and L3 for the most critical applications. It is a common scope for penetration testing and application security programs.

03How OWASP ASVS works

Teams use ASVS as both a build checklist and a test plan.

  1. 1.

    Pick a level

    Choose L1, L2 or L3 based on the data and risk of the application.

  2. 2.

    Design to it

    Use requirements in threat modeling and architecture reviews.

  3. 3.

    Test against it

    Verify requirements with SAST, DAST and penetration testing.

  4. 4.

    Report coverage

    Document which requirements pass, fail or don't apply.

04Threats and risks

ASVS categories match the flaws that cause real breaches.

  • Broken access control

    The top category in the OWASP Top 10. See broken access control.

  • Authentication weaknesses

    Flawed login, reset and MFA flows.

  • Injection

    SQL, command and template injection through unvalidated input.

  • Shallow testing

    Scanners that verify only a fraction of requirements, especially logic-based ones.

05How Parameter helps

Parameter tests the ASVS requirements that need an attacker's reasoning, not just a scanner.

  • Logic and access control

    The pentesting agents test roles, sessions and workflows in web apps and APIs.

  • At design and code time

    Sentinel flags requirement violations in pull requests.

  • Proven findings

    Each failed requirement comes with a working exploit and a fix.

[ AI Pentesting ]

See how Parameter AI Pentesting fits your OWASP ASVS program.

Autonomous agents that find, prove and fix what matters. Every finding ships with evidence.