01Introduction
The OWASP Top 10 tells you what goes wrong in web apps. ASVS tells you what to check to show it hasn't. It's the most detailed open standard for testing application security.
02What is OWASP ASVS?
The OWASP Application Security Verification Standard (ASVS) is an open list of security requirements for designing, building and testing web applications and services. Version 5.0 was released in 2025.
Requirements cover areas such as authentication, session management, access control, input validation, cryptography, APIs and configuration. They are grouped into three levels: L1 as a baseline, L2 for applications handling sensitive data (the recommended default for most), and L3 for the most critical applications. It is a common scope for penetration testing and application security programs.
03How OWASP ASVS works
Teams use ASVS as both a build checklist and a test plan.
- 1.
Pick a level
Choose L1, L2 or L3 based on the data and risk of the application.
- 2.
Design to it
Use requirements in threat modeling and architecture reviews.
- 3.
- 4.
Report coverage
Document which requirements pass, fail or don't apply.
04Threats and risks
ASVS categories match the flaws that cause real breaches.
Broken access control
The top category in the OWASP Top 10. See broken access control.
Authentication weaknesses
Flawed login, reset and MFA flows.
Injection
SQL, command and template injection through unvalidated input.
Shallow testing
Scanners that verify only a fraction of requirements, especially logic-based ones.
05How Parameter helps
Parameter tests the ASVS requirements that need an attacker's reasoning, not just a scanner.
Logic and access control
The pentesting agents test roles, sessions and workflows in web apps and APIs.
At design and code time
Sentinel flags requirement violations in pull requests.
Proven findings
Each failed requirement comes with a working exploit and a fix.

