Digital Application Security Assurance Framework
Security assurance for the organizations behind digital applications.Trust across the digital application lifecycle.
DASAF sets clear requirements for organizations that operate, assess, or build security-sensitive digital applications.
One application lifecycle.
Three responsible roles.
Three standards. One framework.
Built around who is responsible.
Operate
Organizations that own, operate, or are responsible for security-sensitive digital applications.
Assess
Organizations that assess the application security of other organizations.
Build
Organizations that develop security-sensitive applications for themselves or for others.
Certification starts with assessment. It is issued only after the requirements of the chosen DASAF standard are satisfied.
From application to public proof.
A clear certification path.
Payment starts an assessment. It does not buy a certificate. A separate certification decision protects the value of every active record.
Start an application- 01
Application review
- 02
Assessment
- 03
Remediation
- 04
Certification decision
- 05
Certificate issued
- 06
Ongoing surveillance
Public and current.
Check a certification at its source.
Every Certificate of Conformity has a unique number and QR link. The verification page shows the current status, scope, standard version, dates, and Certification Body.
View a verification recordThis certifies that
Example Security Ltd.conforms to
DASAF 200
Application Security Assessment Provider Standard
Choose the standard that matches your role.