Digital Application Security Assurance Framework
Security assurance for the organizations behind digital applications.Trust across the digital application lifecycle.
DASAF sets clear requirements for organizations that operate, assess, or build security-sensitive digital applications.
One application lifecycle.
Three responsible roles.
Three standards. One framework.
Built around who is responsible.
Operate
Organizations that own, operate, or are responsible for security-sensitive digital applications.
Assess
Organizations that assess the application security of other organizations.
Build
Organizations that develop security-sensitive applications for themselves or for others.
Certification starts with assessment. It is issued only after the requirements of the chosen DASAF standard are satisfied.
From application to public proof.
A clear certification path.
Payment starts an assessment. It does not buy a certificate. A separate certification decision protects the value of every active record.
Start an application- 01
Application review
- 02
Assessment
- 03
Remediation
- 04
Certification decision
- 05
Certificate issued
- 06
Ongoing surveillance
Public and current.
Check a certification at its source.
Every Certificate of Conformity has a unique number and QR link. The verification page shows the current status, scope, standard version, dates, and Certification Body.
Verify an IDThis certifies that
Example Security Ltd.conforms to
DASAF 200
Application Security Assessment Provider Standard
Choose the standard that matches your role.