OWASP MASVS assessment.

Know which mobile security requirements your application meets, where the gaps are and how to address them.

The OWASP Mobile Application Security Verification Standard provides a common reference for evaluating Android and iOS security controls.

An assessment is useful when your engineering, security or procurement team needs evidence against defined requirements, rather than a list of vulnerabilities alone. We agree the applicable requirements, application versions, platforms and available access before testing.

The MASVS control groups cover:

  • Storage of sensitive data and use of cryptography.
  • Authentication and secure network communication.
  • Platform interaction and code security.
  • Resilience to reverse engineering and tampering, and user privacy.

See which agreed requirements were met, where gaps remain and what your team can do to address them. We document supporting evidence, test conditions and limitations so you can understand what the results cover.

MASVS defines what to verify. The OWASP Mobile Application Security Testing Guide (MASTG) describes testing techniques and procedures.

Explore the technology behind our assessments

Get it right from the source.

Your assessment is carried out by specialists who contribute to defining OWASP MASTG tests. We apply that knowledge to align our testing with the standard’s requirements.

OWASP recognized vulnit as a MAS Advocate for sustained contributions. Explore those contributions.

How does this differ from a mobile penetration test?

A MASVS assessment evaluates controls against agreed requirements. A mobile application penetration test investigates exploitable vulnerabilities and their impact. We agree with your team what to assess before testing starts.

Does MASVS cover our backend APIs?

MASVS assesses the mobile client. Backend and API testing is agreed separately.

What access should we prepare?

Start with the application builds, platforms and requirements you want assessed. We agree the test accounts and supporting material needed for the scope, including source code and architecture information where relevant.

A necessary cookie remembers your choice for up to 180 days. Privacy policy.