DASAF 100 · Version 1.0
Digital Application Operator Security Standard
Checks how an organization operates its applications and supporting systems against defined security requirements.
Who it applies to
Organizations that own, operate, or are responsible for security-sensitive digital applications.
What the certification covers
Production applications, APIs, infrastructure, access, incident response, and ongoing security operations.
Major control domains
- Governance
- Access control
- Application security
- Infrastructure
- Vulnerability management
- Incident response
What certification means
A certified organization has completed an assessment and satisfied the applicable requirements for this standard. Certification covers the stated Scope of Certification. It is not a guarantee that an organization will never have a security incident.
How certification works
Apply for assessment, agree the scope, provide evidence, complete the assessment, fix any non-conformities, and receive a separate certification decision. A Certificate of Conformity is issued only after approval.