DASAF standards
One lifecycle. Three responsible roles.
Each standard sets requirements for a different organization in the application lifecycle. Choose the role your organization performs.
DASAF 100
Digital Application Operator Security Standard
Organizations that own, operate, or are responsible for security-sensitive digital applications.
DASAF 200Application Security Assessment Provider Standard
Organizations that assess the application security of other organizations.
DASAF 300Secure Application Development Provider Standard
Organizations that develop security-sensitive applications for themselves or for others.