The Mobile Application Security Verification Standard - the industry benchmark for mobile app security testing.
The OWASP Mobile Application Security Verification Standard (MASVS) is a comprehensive framework that defines security requirements for mobile applications. It provides a baseline for mobile app security that can be used throughout the development lifecycle.
MASVS v2.0 organizes security controls into categories covering storage, cryptography, authentication, network security, platform interaction, code quality, resilience, and privacy. It's widely adopted by security professionals and required by many enterprise clients.
Core security domains covered by the standard
Secure storage of sensitive data on mobile devices.
Proper implementation of cryptographic controls.
Secure user authentication and session management.
Secure network communication and data transmission.
Secure interaction with the mobile platform.
Secure coding practices and code protection.
Protection against reverse engineering and tampering.
Protection of user privacy and personal data.
Scan your mobile app against all OWASP MASVS requirements with our automated testing platform.
Start MASVS ScanWe use necessary storage for security and login. With your permission, we also use analytics to understand page journeys and marketing pixels to measure ad campaigns.