DASAF 200 · Version 1.0

Application Security Assessment Provider Standard

Checks whether a provider can assess digital applications with competence, safety, care, and clear evidence.

Who it applies to

Organizations that assess the application security of other organizations.

What the certification covers

Methodology, assessor competence, authorization, evidence handling, reporting, quality review, and retesting.

Major control domains

  • Methodology
  • Authorization
  • Assessor competence
  • Evidence
  • Reporting
  • Quality assurance

What certification means

A certified organization has completed an assessment and satisfied the applicable requirements for this standard. Certification covers the stated Scope of Certification. It is not a guarantee that an organization will never have a security incident.

How certification works

Apply for assessment, agree the scope, provide evidence, complete the assessment, fix any non-conformities, and receive a separate certification decision. A Certificate of Conformity is issued only after approval.