APSA 200 · Version 1.0
Application Security Assessment Provider Standard
Checks whether a provider can assess digital applications with competence, safety, care, and clear evidence.
Who or what it applies to
Organizations that assess the application security of other organizations.
What the certification covers
Methodology, assessor competence, authorization, evidence handling, reporting, quality review, and retesting.
Major control domains
- Methodology
- Authorization
- Assessor competence
- Evidence
- Reporting
- Quality assurance
What certification means
The provider has met the APSA 200 requirements for the assessment services stated in its approved scope.
How certification works
Apply for assessment, agree the scope, provide evidence, complete the assessment, fix any non-conformities, and receive a separate certification decision. A Certificate of Conformity is issued only after approval.