OWASP ASVS 5.0 · Top 10:2025 · LLM Top 10 2026

OWASP ASVS assessment: every requirement checked

A penetration test shows what an attacker could break. Your customer, auditor or board often asks something else: does the application meet an agreed standard? We verify it against OWASP ASVS 5.0 at the level you choose, and the report gives every requirement a result: pass, fail or not applicable.

// In short

What an OWASP ASVS assessment is

OWASP ASVS (Application Security Verification Standard) lists about 350 security requirements for web applications and services, in 17 chapters and three levels. An ASVS assessment checks every requirement at the chosen level and reports a result for each one. It is for teams that must prove their security level to a customer, an auditor or the board.

Version 5.0.0, May 2025, as of 24 September 2026. Source: OWASP ASVS 5.0.0.

// ASVS levels

Three levels, three different promises

Pick the level by the application's risk, not by ambition. Levels are cumulative: Level 2 includes Level 1, and Level 3 covers everything. Shares are taken from ASVS 5.0.0.

  1. 01L1

    Level 1: the baseline for every application

    About 20% of the requirements: first-layer defenses against common attacks. A good first step, although even Level 1 cannot always be fully verified from the outside without documentation or code.

    • A running application and a test account for each role
    • Documentation where a requirement calls for it
  2. 02L2

    Level 2: the target for most applications

    About 70% of the requirements, Level 1 and Level 2 together. Less common attacks and more demanding protections against common ones. You cannot verify it properly without access to documentation, code and people.

    • Documented security decisions
    • Access to code and configuration
    • Time from your team for questions
  3. 03L3

    Level 3: the highest level

    All requirements, including defense in depth and controls that are hard to implement. For applications that must demonstrate the highest level of security, usually those handling the most sensitive data and transactions.

    • Full access, as for Level 2
    • More time for architecture and code review

// Three OWASP documents

ASVS, Top 10 and LLM Top 10: what each one is for

It is easy to confuse a verification standard with a list of risks. We use each document for what it was written for (as of 24 September 2026).

ASVS 5.0: a verification standard

  • Requirements checked one by one
  • Result: pass, fail or not applicable, with the reasoning

Top 10:2025: a list of risks

  • An awareness document, not a test standard
  • We check that the test scope covers every category, from A01 Broken Access Control to A10 Mishandling of Exceptional Conditions

Top 10 for LLM Applications 2026

  • Chatbots, RAG search and agents
  • From LLM01 Prompt Injection to LLM10 Improper Output Handling, more under AI security

Sources: OWASP ASVS 5.0.0, OWASP Top 10:2025, OWASP Top 10 for LLM Applications 2026.

// How we verify

From choosing a level to the report

  1. Level and scope

    Based on the application's risk we agree the level and the ASVS chapters in scope. Chapters that do not apply, such as OAuth in an application without OAuth, are marked not applicable in the report.

  2. Requirement checks

    We combine hands-on testing of the running application with a review of documentation, configuration and code. A scanner is where we start, not the result.

  3. A requirement-by-requirement report

    Scope, level, the result of every requirement checked, and evidence and a recommendation for each failure. We show what works too, not just a list of defects.

  4. Retest

    We retest your fixes at no extra cost and update the requirement results in the report.

First step: one application at Level 1 or Level 2 in 4-5 weeks

  1. Choosing the level

    A conversation about the application's data and risk, a decision on Level 1 or 2 and the list of chapters in scope.

  2. Verifying the requirements at that level

    Testing of the running application and a review of documentation and configuration, plus code at Level 2.

  3. Report and walkthrough

    A result for every requirement and a list of failures with priorities and owners.

You end up with an ASVS report for one application, requirement by requirement, and a retest of your fixes

We agree a fixed scope and date in writing before we start. Request the first step

// Scope

What we do and what we don't

We do

  • Verification of web applications and APIs against ASVS 5.0 at Level 1, 2 or 3
  • A report with a result for every requirement at the chosen level
  • A check that the test scope covers the OWASP Top 10:2025
  • Chatbot, RAG and agent testing against the OWASP Top 10 for LLM Applications 2026
  • A retest of your fixes

We don't

  • Issue an "OWASP certificate": OWASP does not certify vendors, verifiers or software
  • Sign off "OWASP Top 10 compliance", because the Top 10 is a list of risks, not a test standard
  • Verify Level 2 or 3 without access to documentation and code
  • Run destructive tests in production

Real attack paths across a whole system are the job of a penetration test. We often combine both in one engagement.

// FAQ

Questions about OWASP ASVS

How is an ASVS assessment different from a penetration test?

A penetration test looks for ways to reach your data and reports what it found. An ASVS assessment checks every requirement at the chosen level and also shows what works as it should. A pentest answers "can someone break in?", ASVS answers "does the application meet the agreed standard?"

Which ASVS level should we choose?

The one that matches the application's risk. ASVS says most applications should strive for Level 2. Level 1 is the baseline and a good first step; keep Level 3 for applications that must demonstrate the highest level of security. We agree the level with you before we start.

Will we get an OWASP certificate?

No, and nobody else can issue one either. OWASP does not certify vendors, verifiers or software. You get a verification report against ASVS with the scope, the level and the result of every requirement, which you can share with a customer or an auditor.

What about the OWASP Top 10:2025?

It lists the most critical risks to web applications, from A01 Broken Access Control to A10 Mishandling of Exceptional Conditions. It is not a test standard, so "Top 10 compliance" says little. We use it to check that the test scope does not miss a category.

How do you test chatbots and agents?

Against the OWASP Top 10 for LLM Applications 2026, published on 3 August 2026: from prompt injection (LLM01) and sensitive information disclosure (LLM02) to excessive agency (LLM03). More under AI governance and AI security.

How long does it take and what drives the price?

The first step, one application at Level 1 or 2, takes 4 to 5 weeks. The number of days depends on the level, the chapters in scope and the number of user roles. You get the estimate in writing before we start.

Let's start with one application

Point us to the application and tell us who is asking about the standard: a customer, an auditor or the board. We reply within one business day, with questions about scope and access.

Request the first step

Prefer to talk first?

30 minutes on which ASVS level makes sense for your application.

Book a 30-minute call (opens in a new tab)