✳ Industry · OWASP ASVS

OWASP ASVS 5.0.0 verification requirements (not Top 10, not a certificate, not Level N immune)

An educational overview of OWASP ASVS 5.0.0 (dated May 2025, released 2025-05-30) as a requirements and verification project for web applications and services. L1, L2, and L3 are verification depth. This page is not the OWASP Top 10, not the LLM Top 10, not a certificate, not Level N immunity, and not an Atlas AppSec seal.

Industry · OWASP ASVSVerification requirements explainerLast reviewed

What category of verification project this is

The OWASP Application Security Verification Standard (ASVS) defines security requirements for web applications and services. Teams use it to design, develop, maintain, and verify application security against a chosen level. A requirement in ASVS must be verifiable, and that verification ends in a pass or fail decision. It is a requirements and verification project. It is not a limited awareness Top 10 list.

Who it commonly frames: AppSec path readers leaving the Top 10 explainer, buyers who treat the words OWASP verified as if they were an ASVS result, Foundations readers who met the name only as an outbound pointer, and Reference readers who already see that the Top 10 is not ASVS and had no labeled home for that sentence. This is an industry verification project. It is not a U.S. statute, and it is not a certification scheme.

What security people most often confuse: they fold a Top 10 checklist, an ASVS level, the LLM Top 10, and an Atlas lesson into one seal. This page keeps those objects apart. The Top 10 explainer at /learn/explainers/owasp-top-10/ stays the awareness list. The Reference card at /reference/frameworks/owasp-top-10-2025/ stays the framework summary. This explainer complements both. It does not replace either, and it does not reprint requirement text.

Edition pin

The edition string to teach is ASVS 5.0.0, dated May 2025. The version header says v5.0.0, released on May 30, 2025. The GitHub stable release tag is v5.0.0_release (2025-05-30). Official hubs are https://asvs.dev/ and https://github.com/OWASP/ASVS. Re-opened on 2026-09-26: asvs.dev still lists Latest Stable Version 5.0.0, and the GitHub releases page still lists v5.0.0_release as the stable release. If a newer stable patch (5.0.1 or later) appears, update this pin and treat the older claim as UNKNOWN.

The master branch is the bleeding-edge version, not the stable pin. The GitHub release tagged latest (regenerated 2026-09-03) says it is for testing and preview only, and it points production use to stable v5.0.0. asvs.dev names the next release target as patch 5.0.1. That patch is not a stable Atlas pin on this page. Do not teach the bleeding-edge tag as if it were ASVS 5.0.0.

L1, L2, and L3 are verification depth

ASVS 5.0.0 defines three verification levels, written L1, L2, and L3. Each higher level increases depth. The organization chooses a level from its own risk. ASVS does not prescribe one level for every application. The table on this page is slogan depth only. It does not list chapters, and it does not list requirement identifiers.

The same chapter describes the shares of the requirement set. Level 1 is a critical starting point and contains around 20% of the requirements (first-layer defenses against common attacks, and a lower barrier to entry). The chapter says most applications should be striving to reach Level 2, and that L1 plus L2 together are around 70% of the requirements. Level 3 is the highest assurance goal and the remaining around 30% of the requirements, often defense in depth or harder controls. Those percentages are shares of the ASVS 5.0.0 requirement set. They are not adoption statistics.

That Level 2 sentence is ASVS's own characterization. It is not an Atlas rule that readers finish L3. Atlas does not require L3 for a ShopCart build or for a private team. A hallway Level badge is not evidence. ShopCart and TrackPort still pick the verification depth the risk needs, then gather evidence for the controls that matter.

Name the theme, then pick a verification depth

After a Top 10 theme names the conversation, move to verifiable requirements at a chosen ASVS level for the controls that matter on that application. The Reference card already says to use a requirements project such as ASVS when you need testable depth beyond awareness. This page is the labeled home for that sentence. It does not replace the card at /reference/frameworks/owasp-top-10-2025/, and it does not replace the explainer at /learn/explainers/owasp-top-10/.

Practice stays on the AppSec lessons, without reprinting ASVS rows into them. A1 is the ShopCart threat model at /learn/topics/shopcart-threat-model/. A2 is dependencies at /learn/topics/dependencies-and-transitive-risk/. A3 is the promote split at /learn/topics/pipeline-write-vs-promote/. A4 is the SBOM decision at /learn/topics/sbom-evidence-and-priority/. Outcomes before controls stay on /learn/topics/outcomes-then-controls/ (F8a). The six-map comparison is /reference/frameworks/compare/.

The OWASP Top 10 for LLM Applications 2026 is a separate awareness list. The labeled home is /learn/explainers/owasp-llm-top-10/. Do not fold ASVS, Top 10:2025, and the LLM list into one homework set.

What this card is not

Not an ASVS course. Not a requirement dump. Not a chapter encyclopedia. Not a mapping spreadsheet. Not a Top 10 rewrite. Not an LLM Top 10 card. Not a replacement for the Top 10 explainer at /learn/explainers/owasp-top-10/ or the Reference framework card at /reference/frameworks/owasp-top-10-2025/. Not red-team exploit homework. Not permission to invent an adoption statistic. Not a claim that Level N means the product is immune. Not an Atlas attestation of ASVS completion.

Not a CSF 2.0 profile. Outcomes live on /learn/topics/outcomes-then-controls/ and on /reference/frameworks/nist-csf-2-0/. Not a CIS Implementation Group (/learn/explainers/cis-implementation-groups/). Not an ISO/IEC 27001 certificate (/learn/explainers/iso-27001/). Not an SP 800-53 baseline (/learn/explainers/sp-800-53/). Not an ATT&CK coverage score (/learn/explainers/mitre-attack/). The OWASP row on the six-map comparison says the purpose is awareness of common application risks, that the list is not ASVS and not the LLM Top 10, that certifiable is No, and that a typical misuse is treating the list as a complete test standard. A row is not this page.

Rewrite the one-line claim

Replace "we are Top 10, ASVS, LLM Top 10, OWASP verified, and Atlas AppSec compliant" with a reading sentence. We use ASVS 5.0.0 as a leveled verification and requirements project. That is different from OWASP Top 10:2025 awareness, from the LLM Top 10, from a finished ShopCart test, and from an Atlas seal.

When a slide says "OWASP verified" or "ASVS Level 2," privately ask which edition, which level, and which application evidence was verified, and whether the live need is awareness (Top 10), verification depth (ASVS), or a separate LLM list. Do not paste proprietary requirement matrices that contain customer data into Atlas.

Top 10 is not ASVS, not certified, and not Level N immune

Teaching table only. It does not assign a certificate, a finished verification, an LLM list result, a Level N badge, or an AppSec seal.

Seven phrases people fold into one OWASP badge. Not a seal, and not a requirement catalog.
Phrase people sayLiteracy correction
We checked the OWASP Top 10 boxes, so ASVS is doneOWASP Top 10:2025 is a limited awareness list. ASVS is a separate requirements and verification project with leveled depth. Explainer: /learn/explainers/owasp-top-10/. Reference card: /reference/frameworks/owasp-top-10-2025/. Six-map comparison: /reference/frameworks/compare/.
ASVS Level N done means the product is immune / secure foreverA level is a chosen verification depth against requirements. It is not product immunity, not forever safety, and not proof attackers will skip you.
We are OWASP verified / ASVS certified / Atlas AppSec sealedASVS is not an Atlas certificate and not a mail-order seal. Completing this lesson is not attested, not certified, and not OWASP verified. It is not an Atlas AppSec seal.
ASVS done means LLM Top 10 doneOWASP Top 10 for LLM Applications 2026 is a separate awareness list. Labeled home: /learn/explainers/owasp-llm-top-10/. Do not collapse the lists.
ASVS is just another Top 10 posterTop 10 starts a conversation. ASVS is for testable requirements and verification depth. The Reference card already separates the two. Card: /reference/frameworks/owasp-top-10-2025/. Explainer: /learn/explainers/owasp-top-10/.
We can paste the full ASVS requirement catalog / chapter encyclopedia as Atlas homeworkThis card does not reprint ASVS requirement lists, and it does not reprint chapter catalogs. Point readers to asvs.dev and the official release. No mapping spreadsheet belongs in this lesson.
Level badge on a vendor slide = our TrackPort verification is finishedA vendor badge is not evidence your application met the requirements you chose. Ask which level, which edition, and which evidence. Practice stays on /learn/topics/shopcart-threat-model/, /learn/topics/dependencies-and-transitive-risk/, /learn/topics/pipeline-write-vs-promote/, /learn/topics/sbom-evidence-and-priority/, and /learn/topics/outcomes-then-controls/.

Claims to retire

Top 10 checkboxes mean ASVS is done, and OWASP certified.

OWASP Top 10:2025 is a limited awareness list. ASVS 5.0.0 is a separate requirements and verification project. Neither one is a certificate from this page.

ASVS Level N means the product is immune, or secure forever.

A level is a chosen verification depth. It is not product immunity, and it is not forever safety.

ASVS, the Top 10, and the LLM Top 10 are the same homework.

They are different objects. Top 10:2025 names web risk themes. ASVS is leveled verification depth. OWASP Top 10 for LLM Applications 2026 is a separate awareness list. Do not collapse them.

This page replaces the Top 10 explainer or the Reference framework card.

The explainer at /learn/explainers/owasp-top-10/ and the card at /reference/frameworks/owasp-top-10-2025/ stay. This page is the labeled home beside them.

Atlas, or a vendor homepage shield, attests ASVS completion.

Atlas does not issue OWASP ASVS verified seals, Level N complete badges, or Atlas AppSec seals. Completing this lesson is not certified. A homepage shield is not evidence a requirement was verified on your application.

Full ASVS requirement catalogs should be pasted into Atlas lessons.

This card does not reprint ASVS requirement lists, and it does not reprint a chapter encyclopedia. Read the official release instead of pasting it into Atlas.

L1, L2, and L3 at slogan depth

Static level strip from ASVS 5.0.0 (What is the ASVS?). Literacy only. It does not list requirement identifiers, and it does not reprint requirement text.

Three verification levels. Not a certificate, and not product immunity.
LevelSlogan (ASVS 5.0.0)Boundary
L1Minimum requirements and a critical starting point. Around 20% of the requirements. First-layer defenses against common attacks. A lower barrier to entryA starting set. Not the whole standard, and not immunity.
L2The level ASVS says most applications should be striving to reach. L1 plus L2 are around 70% of the requirementsASVS's own characterization of L2. Not an Atlas rule that readers must finish L3, and not immunity.
L3Highest assurance goal. The remaining around 30% of the requirements. Often defense in depth or harder controlsA chosen depth. Not a rule that most readers must be L3, and not immunity.

CHECK THE CATEGORY

Which sentence matches this page?

Glossary and nearby pages

Use the agency page in the sources for the authoritative text. This page has no figure.

Find your next idea.

Tip: press / to open search. Escape closes this window.