APSA 200 · Version 1.0

Application Security Assessment Provider Standard

Checks whether a provider can assess digital applications with competence, safety, care, and clear evidence.

Who or what it applies to

Organizations that assess the application security of other organizations.

What the certification covers

Methodology, assessor competence, authorization, evidence handling, reporting, quality review, and retesting.

Major control domains

  • Methodology
  • Authorization
  • Assessor competence
  • Evidence
  • Reporting
  • Quality assurance

What certification means

The provider has met the APSA 200 requirements for the assessment services stated in its approved scope.

How certification works

Apply for assessment, agree the scope, provide evidence, complete the assessment, fix any non-conformities, and receive a separate certification decision. A Certificate of Conformity is issued only after approval.