DASAF 200 · Version 1.0
Application Security Assessment Provider Standard
Checks whether a provider can assess digital applications with competence, safety, care, and clear evidence.
Who it applies to
Organizations that assess the application security of other organizations.
What the certification covers
Methodology, assessor competence, authorization, evidence handling, reporting, quality review, and retesting.
Major control domains
- Methodology
- Authorization
- Assessor competence
- Evidence
- Reporting
- Quality assurance
What certification means
A certified organization has completed an assessment and satisfied the applicable requirements for this standard. Certification covers the stated Scope of Certification. It is not a guarantee that an organization will never have a security incident.
How certification works
Apply for assessment, agree the scope, provide evidence, complete the assessment, fix any non-conformities, and receive a separate certification decision. A Certificate of Conformity is issued only after approval.