DASAF 300 · Version 1.0

Secure Application Development Provider Standard

Checks whether secure development controls are repeatable across design, code, testing, release, and maintenance.

Who it applies to

Organizations that develop security-sensitive applications for themselves or for others.

What the certification covers

Requirements, architecture, secure coding, code review, CI/CD, secrets, release controls, and remediation.

Major control domains

  • Security requirements
  • Architecture
  • Secure development
  • CI/CD
  • Release control
  • Remediation

What certification means

A certified organization has completed an assessment and satisfied the applicable requirements for this standard. Certification covers the stated Scope of Certification. It is not a guarantee that an organization will never have a security incident.

How certification works

Apply for assessment, agree the scope, provide evidence, complete the assessment, fix any non-conformities, and receive a separate certification decision. A Certificate of Conformity is issued only after approval.