DASAF 300 · Version 1.0
Secure Application Development Provider Standard
Checks whether secure development controls are repeatable across design, code, testing, release, and maintenance.
Who it applies to
Organizations that develop security-sensitive applications for themselves or for others.
What the certification covers
Requirements, architecture, secure coding, code review, CI/CD, secrets, release controls, and remediation.
Major control domains
- Security requirements
- Architecture
- Secure development
- CI/CD
- Release control
- Remediation
What certification means
A certified organization has completed an assessment and satisfied the applicable requirements for this standard. Certification covers the stated Scope of Certification. It is not a guarantee that an organization will never have a security incident.
How certification works
Apply for assessment, agree the scope, provide evidence, complete the assessment, fix any non-conformities, and receive a separate certification decision. A Certificate of Conformity is issued only after approval.