Skip to content
Guide

What is OWASP MASVS?

7 min read Published

Short answer

OWASP MASVS (Mobile Application Security Verification Standard) is the OWASP security standard for mobile apps. The current release, version 2.1.0 from January 2024, has 24 controls in eight groups, from data storage to privacy. Teams use it as a baseline to build and test Android and iOS apps. It is not a certification.

What MASVS is

MASVS is published by the OWASP Mobile Application Security (MAS) project. OWASP describes it as a set of guidelines and best practices for assessing and improving the security of mobile apps. It is meant to be used as a metric, as guidance and as a baseline.

The MAS project has three parts that work together:

  • MASVS, the standard. It says what a secure mobile app should do, in high-level controls.
  • MASTG, the Mobile Application Security Testing Guide. It is OWASP's manual for testing those controls on Android and iOS.
  • MASWE, the Mobile Application Security Weakness Enumeration. It lists common security and privacy weaknesses in mobile apps. OWASP calls it the bridge between MASVS and MASTG.

MASVS covers the app itself, the part that runs on the phone. Backend servers and APIs are out of its scope. For those, OWASP points to its web standards, such as the Application Security Verification Standard (ASVS).

The eight control groups

Version 2.1.0 organises its 24 controls into eight groups. Each control has an ID such as MASVS-STORAGE-1.

OWASP MASVS v2.1.0 control groups
GroupWhat it coversControls
MASVS-STORAGESecure storage of sensitive data on the device2
MASVS-CRYPTOCryptography used to protect sensitive data2
MASVS-AUTHAuthentication and authorization in the app3
MASVS-NETWORKSecure communication between the app and remote endpoints2
MASVS-PLATFORMSecure interaction with the operating system and other apps3
MASVS-CODESecure data processing and keeping the app up to date4
MASVS-RESILIENCEResilience against reverse engineering and tampering4
MASVS-PRIVACYControls that protect user privacy4

The privacy group is the newest. It arrived with version 2.1.0 in January 2024. Version 2.0.0, from April 2023, had restructured the standard and simplified its controls.

From levels to MAS testing profiles

Older versions of MASVS had verification levels called L1, L2 and R. Version 2.0.0, from April 2023, moved them out of the standard and into the testing side of the project. There they became MAS testing profiles, which say which tests apply to an app. OWASP revised the profiles again in 2026.

Default MAS testing profiles
ProfileNameWho is treated as the attacker
MAS-L1Essential SecurityOther apps installed on the device
MAS-L2Advanced SecurityThe operating system cannot be trusted, and attackers may have physical access
MAS-RResilient SecurityThe user of the device, for example reverse engineers and cheaters
MAS-PBaseline PrivacyNot attacker-centred: protecting users' personal data

OWASP recommends MAS-L1 as a baseline for all mobile apps. MAS-L2 is meant for apps that handle high-risk sensitive data and contain sensitive functionality, such as many health or finance apps. A profile does not cover every control: MAS-L1, for example, currently covers 12 of the 24, according to OWASP MASWE. There are also specialised profiles, such as MAS-EUDIW for the EU Digital Identity Wallet. For the highest assurance, OWASP recommends a custom profile based on a threat model.

What MASVS is not

  • Not a certification. OWASP states that it "does not certify any vendors, verifiers or software". Nobody can hold an official OWASP MASVS certificate.
  • Not a backend standard. Servers and APIs need their own testing, for example against OWASP ASVS.
  • Not something a tool can finish alone. OWASP says it is not possible to complete MASVS verification with automated tools alone, since every mobile app is different.
  • Not a guarantee. OWASP notes that MASVS cannot guarantee absolute security. It is a baseline.

How to use MASVS

  1. Decide what matters. A short threat model shows which data and functions need protecting.
  2. Pick a profile. MAS-L1 as the baseline, plus MAS-L2, MAS-R or MAS-P where your risks call for it.
  3. Build with it. Use the controls as requirements while you design and code.
  4. Test against it. Use MASTG test cases, or have the release build assessed against the chosen profile.
  5. Record the result per control. A useful report says, for each control, whether it was met, not met, or could not be tested, and why.

How Vybebat uses MASVS

Our Standard tier gives all 24 OWASP MASVS v2.1 controls a verdict or a written reason why they could not be tested. The MAS-L1 testing profile, currently 12 of those controls, is the baseline. Controls outside it are checked where the release build allows. A person confirms every finding.

For full verification, OWASP recommends an open book review with access to source code and developers. We deliberately review the release build you ship, without your source code, and the report states exactly what was and was not tested. See what Standard covers and the pricing.

Common questions

Which version of MASVS is current?
Version 2.1.0, released on 18 January 2024, is the latest release. It added the MASVS-PRIVACY group.
Is there an official MASVS certification?
No. OWASP does not certify vendors, testers or software. A provider may assess an app against MASVS, but it must not claim official OWASP certification.
What is the difference between MASVS and MASTG?
MASVS says what a secure app should do. MASTG explains how to test it, with technical test cases for Android and iOS.
What happened to MASVS L1 and L2?
Version 2.0.0 moved the levels out of the standard. They continue as MAS testing profiles: MAS-L1, MAS-L2, MAS-R, and MAS-P, which was introduced alongside the MASVS-PRIVACY group in version 2.1.0.

Sources

  1. OWASP MASVS, official site
  2. OWASP MASVS releases on GitHub (v2.1.0, v2.0.0)
  3. OWASP MASVS, Using the MASVS
  4. OWASP MASVS, Assessment and Certification
  5. OWASP MAS Testing Profiles
  6. OWASP MASWE on GitHub

Vybebat is not affiliated with, endorsed or certified by the OWASP Foundation. We check these facts against the sources above and update the guide when they change.