APSA 300 · Version 1.0
Secure Application Development Provider Standard
Checks whether secure development controls are repeatable across design, code, testing, release, and maintenance.
Who or what it applies to
Organizations that develop security-sensitive applications for themselves or for others.
What the certification covers
Requirements, architecture, secure coding, code review, CI/CD, secrets, release controls, and remediation.
Major control domains
- Security requirements
- Architecture
- Secure development
- CI/CD
- Release control
- Remediation
What certification means
The provider has met the APSA 300 requirements for the development services stated in its approved scope.
How certification works
Apply for assessment, agree the scope, provide evidence, complete the assessment, fix any non-conformities, and receive a separate certification decision. A Certificate of Conformity is issued only after approval.