What is OWASP MASVS?
Short answer
OWASP MASVS (Mobile Application Security Verification Standard) is the OWASP security standard for mobile apps. The current release, version 2.1.0 from January 2024, has 24 controls in eight groups, from data storage to privacy. Teams use it as a baseline to build and test Android and iOS apps. It is not a certification.
What MASVS is
MASVS is published by the OWASP Mobile Application Security (MAS) project. OWASP describes it as a set of guidelines and best practices for assessing and improving the security of mobile apps. It is meant to be used as a metric, as guidance and as a baseline.
The MAS project has three parts that work together:
- MASVS, the standard. It says what a secure mobile app should do, in high-level controls.
- MASTG, the Mobile Application Security Testing Guide. It is OWASP's manual for testing those controls on Android and iOS.
- MASWE, the Mobile Application Security Weakness Enumeration. It lists common security and privacy weaknesses in mobile apps. OWASP calls it the bridge between MASVS and MASTG.
MASVS covers the app itself, the part that runs on the phone. Backend servers and APIs are out of its scope. For those, OWASP points to its web standards, such as the Application Security Verification Standard (ASVS).
The eight control groups
Version 2.1.0 organises its 24 controls into eight groups. Each control has an ID such as MASVS-STORAGE-1.
| Group | What it covers | Controls |
|---|---|---|
| MASVS-STORAGE | Secure storage of sensitive data on the device | 2 |
| MASVS-CRYPTO | Cryptography used to protect sensitive data | 2 |
| MASVS-AUTH | Authentication and authorization in the app | 3 |
| MASVS-NETWORK | Secure communication between the app and remote endpoints | 2 |
| MASVS-PLATFORM | Secure interaction with the operating system and other apps | 3 |
| MASVS-CODE | Secure data processing and keeping the app up to date | 4 |
| MASVS-RESILIENCE | Resilience against reverse engineering and tampering | 4 |
| MASVS-PRIVACY | Controls that protect user privacy | 4 |
The privacy group is the newest. It arrived with version 2.1.0 in January 2024. Version 2.0.0, from April 2023, had restructured the standard and simplified its controls.
From levels to MAS testing profiles
Older versions of MASVS had verification levels called L1, L2 and R. Version 2.0.0, from April 2023, moved them out of the standard and into the testing side of the project. There they became MAS testing profiles, which say which tests apply to an app. OWASP revised the profiles again in 2026.
| Profile | Name | Who is treated as the attacker |
|---|---|---|
| MAS-L1 | Essential Security | Other apps installed on the device |
| MAS-L2 | Advanced Security | The operating system cannot be trusted, and attackers may have physical access |
| MAS-R | Resilient Security | The user of the device, for example reverse engineers and cheaters |
| MAS-P | Baseline Privacy | Not attacker-centred: protecting users' personal data |
OWASP recommends MAS-L1 as a baseline for all mobile apps. MAS-L2 is meant for apps that handle high-risk sensitive data and contain sensitive functionality, such as many health or finance apps. A profile does not cover every control: MAS-L1, for example, currently covers 12 of the 24, according to OWASP MASWE. There are also specialised profiles, such as MAS-EUDIW for the EU Digital Identity Wallet. For the highest assurance, OWASP recommends a custom profile based on a threat model.
What MASVS is not
- Not a certification. OWASP states that it "does not certify any vendors, verifiers or software". Nobody can hold an official OWASP MASVS certificate.
- Not a backend standard. Servers and APIs need their own testing, for example against OWASP ASVS.
- Not something a tool can finish alone. OWASP says it is not possible to complete MASVS verification with automated tools alone, since every mobile app is different.
- Not a guarantee. OWASP notes that MASVS cannot guarantee absolute security. It is a baseline.
How to use MASVS
- Decide what matters. A short threat model shows which data and functions need protecting.
- Pick a profile. MAS-L1 as the baseline, plus MAS-L2, MAS-R or MAS-P where your risks call for it.
- Build with it. Use the controls as requirements while you design and code.
- Test against it. Use MASTG test cases, or have the release build assessed against the chosen profile.
- Record the result per control. A useful report says, for each control, whether it was met, not met, or could not be tested, and why.
How Vybebat uses MASVS
Our Standard tier gives all 24 OWASP MASVS v2.1 controls a verdict or a written reason why they could not be tested. The MAS-L1 testing profile, currently 12 of those controls, is the baseline. Controls outside it are checked where the release build allows. A person confirms every finding.
For full verification, OWASP recommends an open book review with access to source code and developers. We deliberately review the release build you ship, without your source code, and the report states exactly what was and was not tested. See what Standard covers and the pricing.
Common questions
- Which version of MASVS is current?
- Version 2.1.0, released on 18 January 2024, is the latest release. It added the MASVS-PRIVACY group.
- Is there an official MASVS certification?
- No. OWASP does not certify vendors, testers or software. A provider may assess an app against MASVS, but it must not claim official OWASP certification.
- What is the difference between MASVS and MASTG?
- MASVS says what a secure app should do. MASTG explains how to test it, with technical test cases for Android and iOS.
- What happened to MASVS L1 and L2?
- Version 2.0.0 moved the levels out of the standard. They continue as MAS testing profiles: MAS-L1, MAS-L2, MAS-R, and MAS-P, which was introduced alongside the MASVS-PRIVACY group in version 2.1.0.
Sources
- OWASP MASVS, official site
- OWASP MASVS releases on GitHub (v2.1.0, v2.0.0)
- OWASP MASVS, Using the MASVS
- OWASP MASVS, Assessment and Certification
- OWASP MAS Testing Profiles
- OWASP MASWE on GitHub
Vybebat is not affiliated with, endorsed or certified by the OWASP Foundation. We check these facts against the sources above and update the guide when they change.