What category of verification project this is
The OWASP Application Security Verification Standard (ASVS) defines security requirements for web applications and services. Teams use it to design, develop, maintain, and verify application security against a chosen level. A requirement in ASVS must be verifiable, and that verification ends in a pass or fail decision. It is a requirements and verification project. It is not a limited awareness Top 10 list.
Who it commonly frames: AppSec path readers leaving the Top 10 explainer, buyers who treat the words OWASP verified as if they were an ASVS result, Foundations readers who met the name only as an outbound pointer, and Reference readers who already see that the Top 10 is not ASVS and had no labeled home for that sentence. This is an industry verification project. It is not a U.S. statute, and it is not a certification scheme.
What security people most often confuse: they fold a Top 10 checklist, an ASVS level, the LLM Top 10, and an Atlas lesson into one seal. This page keeps those objects apart. The Top 10 explainer at /learn/explainers/owasp-top-10/ stays the awareness list. The Reference card at /reference/frameworks/owasp-top-10-2025/ stays the framework summary. This explainer complements both. It does not replace either, and it does not reprint requirement text.
Edition pin
The edition string to teach is ASVS 5.0.0, dated May 2025. The version header says v5.0.0, released on May 30, 2025. The GitHub stable release tag is v5.0.0_release (2025-05-30). Official hubs are https://asvs.dev/ and https://github.com/OWASP/ASVS. Re-opened on 2026-09-26: asvs.dev still lists Latest Stable Version 5.0.0, and the GitHub releases page still lists v5.0.0_release as the stable release. If a newer stable patch (5.0.1 or later) appears, update this pin and treat the older claim as UNKNOWN.
The master branch is the bleeding-edge version, not the stable pin. The GitHub release tagged latest (regenerated 2026-09-03) says it is for testing and preview only, and it points production use to stable v5.0.0. asvs.dev names the next release target as patch 5.0.1. That patch is not a stable Atlas pin on this page. Do not teach the bleeding-edge tag as if it were ASVS 5.0.0.
L1, L2, and L3 are verification depth
ASVS 5.0.0 defines three verification levels, written L1, L2, and L3. Each higher level increases depth. The organization chooses a level from its own risk. ASVS does not prescribe one level for every application. The table on this page is slogan depth only. It does not list chapters, and it does not list requirement identifiers.
The same chapter describes the shares of the requirement set. Level 1 is a critical starting point and contains around 20% of the requirements (first-layer defenses against common attacks, and a lower barrier to entry). The chapter says most applications should be striving to reach Level 2, and that L1 plus L2 together are around 70% of the requirements. Level 3 is the highest assurance goal and the remaining around 30% of the requirements, often defense in depth or harder controls. Those percentages are shares of the ASVS 5.0.0 requirement set. They are not adoption statistics.
That Level 2 sentence is ASVS's own characterization. It is not an Atlas rule that readers finish L3. Atlas does not require L3 for a ShopCart build or for a private team. A hallway Level badge is not evidence. ShopCart and TrackPort still pick the verification depth the risk needs, then gather evidence for the controls that matter.
Name the theme, then pick a verification depth
After a Top 10 theme names the conversation, move to verifiable requirements at a chosen ASVS level for the controls that matter on that application. The Reference card already says to use a requirements project such as ASVS when you need testable depth beyond awareness. This page is the labeled home for that sentence. It does not replace the card at /reference/frameworks/owasp-top-10-2025/, and it does not replace the explainer at /learn/explainers/owasp-top-10/.
Practice stays on the AppSec lessons, without reprinting ASVS rows into them. A1 is the ShopCart threat model at /learn/topics/shopcart-threat-model/. A2 is dependencies at /learn/topics/dependencies-and-transitive-risk/. A3 is the promote split at /learn/topics/pipeline-write-vs-promote/. A4 is the SBOM decision at /learn/topics/sbom-evidence-and-priority/. Outcomes before controls stay on /learn/topics/outcomes-then-controls/ (F8a). The six-map comparison is /reference/frameworks/compare/.
The OWASP Top 10 for LLM Applications 2026 is a separate awareness list. The labeled home is /learn/explainers/owasp-llm-top-10/. Do not fold ASVS, Top 10:2025, and the LLM list into one homework set.
What this card is not
Not an ASVS course. Not a requirement dump. Not a chapter encyclopedia. Not a mapping spreadsheet. Not a Top 10 rewrite. Not an LLM Top 10 card. Not a replacement for the Top 10 explainer at /learn/explainers/owasp-top-10/ or the Reference framework card at /reference/frameworks/owasp-top-10-2025/. Not red-team exploit homework. Not permission to invent an adoption statistic. Not a claim that Level N means the product is immune. Not an Atlas attestation of ASVS completion.
Not a CSF 2.0 profile. Outcomes live on /learn/topics/outcomes-then-controls/ and on /reference/frameworks/nist-csf-2-0/. Not a CIS Implementation Group (/learn/explainers/cis-implementation-groups/). Not an ISO/IEC 27001 certificate (/learn/explainers/iso-27001/). Not an SP 800-53 baseline (/learn/explainers/sp-800-53/). Not an ATT&CK coverage score (/learn/explainers/mitre-attack/). The OWASP row on the six-map comparison says the purpose is awareness of common application risks, that the list is not ASVS and not the LLM Top 10, that certifiable is No, and that a typical misuse is treating the list as a complete test standard. A row is not this page.
Rewrite the one-line claim
Replace "we are Top 10, ASVS, LLM Top 10, OWASP verified, and Atlas AppSec compliant" with a reading sentence. We use ASVS 5.0.0 as a leveled verification and requirements project. That is different from OWASP Top 10:2025 awareness, from the LLM Top 10, from a finished ShopCart test, and from an Atlas seal.
When a slide says "OWASP verified" or "ASVS Level 2," privately ask which edition, which level, and which application evidence was verified, and whether the live need is awareness (Top 10), verification depth (ASVS), or a separate LLM list. Do not paste proprietary requirement matrices that contain customer data into Atlas.
Top 10 is not ASVS, not certified, and not Level N immune
Teaching table only. It does not assign a certificate, a finished verification, an LLM list result, a Level N badge, or an AppSec seal.
| Phrase people say | Literacy correction |
|---|---|
| We checked the OWASP Top 10 boxes, so ASVS is done | OWASP Top 10:2025 is a limited awareness list. ASVS is a separate requirements and verification project with leveled depth. Explainer: /learn/explainers/owasp-top-10/. Reference card: /reference/frameworks/owasp-top-10-2025/. Six-map comparison: /reference/frameworks/compare/. |
| ASVS Level N done means the product is immune / secure forever | A level is a chosen verification depth against requirements. It is not product immunity, not forever safety, and not proof attackers will skip you. |
| We are OWASP verified / ASVS certified / Atlas AppSec sealed | ASVS is not an Atlas certificate and not a mail-order seal. Completing this lesson is not attested, not certified, and not OWASP verified. It is not an Atlas AppSec seal. |
| ASVS done means LLM Top 10 done | OWASP Top 10 for LLM Applications 2026 is a separate awareness list. Labeled home: /learn/explainers/owasp-llm-top-10/. Do not collapse the lists. |
| ASVS is just another Top 10 poster | Top 10 starts a conversation. ASVS is for testable requirements and verification depth. The Reference card already separates the two. Card: /reference/frameworks/owasp-top-10-2025/. Explainer: /learn/explainers/owasp-top-10/. |
| We can paste the full ASVS requirement catalog / chapter encyclopedia as Atlas homework | This card does not reprint ASVS requirement lists, and it does not reprint chapter catalogs. Point readers to asvs.dev and the official release. No mapping spreadsheet belongs in this lesson. |
| Level badge on a vendor slide = our TrackPort verification is finished | A vendor badge is not evidence your application met the requirements you chose. Ask which level, which edition, and which evidence. Practice stays on /learn/topics/shopcart-threat-model/, /learn/topics/dependencies-and-transitive-risk/, /learn/topics/pipeline-write-vs-promote/, /learn/topics/sbom-evidence-and-priority/, and /learn/topics/outcomes-then-controls/. |
Claims to retire
Top 10 checkboxes mean ASVS is done, and OWASP certified.
OWASP Top 10:2025 is a limited awareness list. ASVS 5.0.0 is a separate requirements and verification project. Neither one is a certificate from this page.
ASVS Level N means the product is immune, or secure forever.
A level is a chosen verification depth. It is not product immunity, and it is not forever safety.
ASVS, the Top 10, and the LLM Top 10 are the same homework.
They are different objects. Top 10:2025 names web risk themes. ASVS is leveled verification depth. OWASP Top 10 for LLM Applications 2026 is a separate awareness list. Do not collapse them.
This page replaces the Top 10 explainer or the Reference framework card.
The explainer at /learn/explainers/owasp-top-10/ and the card at /reference/frameworks/owasp-top-10-2025/ stay. This page is the labeled home beside them.
Atlas, or a vendor homepage shield, attests ASVS completion.
Atlas does not issue OWASP ASVS verified seals, Level N complete badges, or Atlas AppSec seals. Completing this lesson is not certified. A homepage shield is not evidence a requirement was verified on your application.
Full ASVS requirement catalogs should be pasted into Atlas lessons.
This card does not reprint ASVS requirement lists, and it does not reprint a chapter encyclopedia. Read the official release instead of pasting it into Atlas.
L1, L2, and L3 at slogan depth
Static level strip from ASVS 5.0.0 (What is the ASVS?). Literacy only. It does not list requirement identifiers, and it does not reprint requirement text.
| Level | Slogan (ASVS 5.0.0) | Boundary |
|---|---|---|
| L1 | Minimum requirements and a critical starting point. Around 20% of the requirements. First-layer defenses against common attacks. A lower barrier to entry | A starting set. Not the whole standard, and not immunity. |
| L2 | The level ASVS says most applications should be striving to reach. L1 plus L2 are around 70% of the requirements | ASVS's own characterization of L2. Not an Atlas rule that readers must finish L3, and not immunity. |
| L3 | Highest assurance goal. The remaining around 30% of the requirements. Often defense in depth or harder controls | A chosen depth. Not a rule that most readers must be L3, and not immunity. |
CHECK THE CATEGORY
Which sentence matches this page?
Glossary and nearby pages
- OWASP Top 10 explainer (awareness list, not replaced by this page)
- OWASP Top 10 Reference card (framework summary, not replaced by this page)
- Compare the six maps (a row is not this project)
- Map the shop: trust boundaries on a synthetic checkout API (A1)
- What you didn't import still ships with you (A2)
- Who can write, who can promote (A3)
- An SBOM is inventory, not a control (A4)
- Outcomes first, then controls (F8a)
- Application and software supply-chain path
- OWASP GenAI LLM Top 10 2026 explainer (awareness list, not this project)
- NIST AI RMF 1.0 explainer (voluntary framework, not this project)
- NIST SSDF Version 1.1 explainer (software practice vocabulary, not this project)
- Privacy is not a CIA checkbox
Use the agency page in the sources for the authoritative text. This page has no figure.