APSA 300 · Version 1.0

Secure Application Development Provider Standard

Checks whether secure development controls are repeatable across design, code, testing, release, and maintenance.

Who or what it applies to

Organizations that develop security-sensitive applications for themselves or for others.

What the certification covers

Requirements, architecture, secure coding, code review, CI/CD, secrets, release controls, and remediation.

Major control domains

  • Security requirements
  • Architecture
  • Secure development
  • CI/CD
  • Release control
  • Remediation

What certification means

The provider has met the APSA 300 requirements for the development services stated in its approved scope.

How certification works

Apply for assessment, agree the scope, provide evidence, complete the assessment, fix any non-conformities, and receive a separate certification decision. A Certificate of Conformity is issued only after approval.