✳ Industry · OWASP Top 10

OWASP Top 10:2025 awareness list (not a certificate, not ASVS, not the LLM Top 10)

An educational overview of OWASP Top 10:2025, the 8th installment, as a limited awareness list of web application risk themes. A01 through A10 are category labels. Checking ten boxes is not a finished test, not a certificate, not ASVS, not the LLM Top 10, and not an Atlas AppSec seal.

Industry · OWASP Top 10Awareness list explainerLast reviewed

What category of awareness document this is

The OWASP Top 10 is a standard awareness document for developers and web application security. The 2025 list page says it represents a broad consensus about the most critical security risks to web applications. It is meant to educate and to start conversations. It is not a complete testing standard.

Who it commonly frames: AppSec path readers who already meet a theme on a ShopCart lesson, Foundations readers who saw the name only as a row on the six-map comparison, and buyers or vendors who treat a Top 10 slide as a certificate. This is an industry awareness list. It is not a U.S. statute, and it is not a certification scheme.

What security people most often confuse: they fold ten checked boxes, an ASVS testing result, the LLM Top 10, and an Atlas lesson into one seal. This page keeps those objects apart. The Reference card at /reference/frameworks/owasp-top-10-2025/ remains the framework summary. This explainer complements that card. It does not replace it, and it does not reprint category bodies.

Edition pin

The edition string to teach is OWASP Top 10:2025. The introduction calls this the 8th installment of the OWASP Top 10. That string matches the Atlas Reference edition OWASP Top 10:2025. Official hubs are https://owasp.org/Top10/2025/ and https://top10.owasp.org/2025/ (the same list). Re-opened on 2026-09-26: the owasp.org list URL redirects to https://top10.owasp.org/2025/, and the introduction on that host still says this is the 8th installment. If a newer installment appears, update this pin and treat the older claim as UNKNOWN.

One line from the introduction, not an encyclopedia: the 2025 installment adds or expands themes such as Software Supply Chain Failures and Mishandling of Exceptional Conditions. The list page writes A09 as Security Logging and Alerting Failures. The introduction also uses an ampersand in one heading of that same name. Ranking shifts, weakness identifier lists, and contributor statistics stay on the official introduction. This page does not reprint them, and it does not invent an adoption percentage from the contributor thank-you list.

A01 through A10 are category labels

The ten names in the table on this page are the official OWASP Top 10:2025 category labels. They are awareness category labels, not a finished test plan. This page stops at the name. It does not reprint the risk text, the example attacks, or the weakness lists on the official category pages.

AppSec lessons already use two of these names without reprinting the bodies. A1, the ShopCart threat model at /learn/topics/shopcart-threat-model/, points at A06:2025 Insecure Design. A2, A3, and A4 point at A03:2025 Software Supply Chain Failures: /learn/topics/dependencies-and-transitive-risk/, /learn/topics/pipeline-write-vs-promote/, and /learn/topics/sbom-evidence-and-priority/. Open those lessons for the practice. This page does not rewrite them.

A hallway poster that checks all ten boxes is still a poster. The label tells people which conversation they are in. It does not close a test, and it does not require anyone to memorize ten category essays.

Name the theme, then keep the evidence

Pick one real or synthetic application risk. Use a Top 10:2025 theme as a shared name for the conversation, then move to verifiable evidence: a threat model, a test note, or an SBOM decision. The Reference card says to link awareness to SAST, DAST, or SCA evidence rather than to a poster in the hallway.

ShopCart can carry one risk under a 2025 category label, then point at the threat model, the dependency inventory, the promote split, or the SBOM decision. TrackPort can do the same for a parser, a session, or an access-control note. Those lessons stay the practice. A poster of ten boxes is not that evidence.

When the question needs testable depth, the OWASP Application Security Verification Standard (ASVS) is a separate requirements and verification project. This page names ASVS only. It does not teach ASVS requirements, and it does not pin an ASVS edition (that year is UNKNOWN here, matching the Reference card, which also names ASVS without a year). The OWASP Top 10 for LLM Applications 2026 is a separate awareness list. Prompt injection stays on /learn/topics/prompt-injection-and-retrieval/. Do not fold that list into A01 through A10.

What this card is not

Not a Top 10 encyclopedia. Not a weakness-list dump. Not an ASVS course. Not an LLM Top 10 rewrite. Not a replacement for the Reference framework card at /reference/frameworks/owasp-top-10-2025/. Not red-team exploit homework. Not proof that attackers will skip you. Not permission to invent an adoption statistic from the contributor thank-you list on the introduction. Not an Atlas attestation of Top 10 completion.

Not a CSF 2.0 profile. Outcomes live on /learn/topics/outcomes-then-controls/ and on /reference/frameworks/nist-csf-2-0/. Not a CIS Implementation Group (/learn/explainers/cis-implementation-groups/). Not an ISO/IEC 27001 certificate (/learn/explainers/iso-27001/). Not an SP 800-53 baseline (/learn/explainers/sp-800-53/). Not an ATT&CK coverage score (/learn/explainers/mitre-attack/). The six-map comparison is /reference/frameworks/compare/. The OWASP row there says the purpose is awareness of common application risks, that the list is not ASVS and not the LLM Top 10, that certifiable is No, and that a typical misuse is treating the list as a complete test standard. A row is not this page.

Rewrite the one-line claim

Replace "we are OWASP, Top 10, ASVS, LLM Top 10, and Atlas AppSec compliant" with a reading sentence. We use OWASP Top 10:2025 as a limited web-risk awareness list (A01 through A10 labels). That is different from ASVS testing depth, from the LLM Top 10 2026, and from a finished TrackPort test.

When a slide says "Top 10 compliant," privately ask which theme was actually tested, on which application evidence, and whether the live need is awareness, ASVS-depth requirements, or a separate LLM list. Do not paste proprietary scan exports that contain customer data into Atlas.

Ten boxes are not secure, not ASVS, not the LLM Top 10, and not an Atlas seal

Teaching table only. It does not assign a certificate, a finished test, an ASVS result, an LLM list result, or an AppSec seal.

Six phrases people fold into one OWASP badge. Not a seal, and not a category essay.
Phrase people sayLiteracy correction
We checked the ten boxes, so the application is secure / certifiedOWASP Top 10:2025 is an awareness list. Checking ten themes is not a finished test and not a certification. The comparison row lists certifiable as No. Reference card: /reference/frameworks/owasp-top-10-2025/. Six-map comparison: /reference/frameworks/compare/.
Top 10 done means ASVS doneASVS is a separate requirements and verification project for testable depth. This page names it only. It does not dump ASVS requirements, and it does not pin an ASVS edition.
Top 10 done means LLM Top 10 doneOWASP Top 10 for LLM Applications 2026 is a separate awareness list. Do not collapse the lists. Prompt injection stays on /learn/topics/prompt-injection-and-retrieval/.
Top 10 is a complete AppSec standardThe Reference card says this list is not a complete application-security standard, and not a substitute for threat modeling a specific API. Practice stays on /learn/topics/shopcart-threat-model/, /learn/topics/dependencies-and-transitive-risk/, /learn/topics/pipeline-write-vs-promote/, and /learn/topics/sbom-evidence-and-priority/.
Atlas Top 10 lesson = AppSec sealAtlas does not issue AppSec seals. Completing a lesson is not a secure product. Foundations readers who met the name on the six-map page can keep outcomes on /learn/topics/outcomes-then-controls/.
We can paste the full OWASP risk text / CWE lists as Atlas homeworkThis card does not reprint OWASP risk text, and it does not list CWE identifiers. Read the official list instead of pasting it into Atlas.

Claims to retire

Ten checkboxes mean a secure product, or an OWASP certificate.

OWASP Top 10:2025 is a limited awareness list. Checking ten themes is not a finished test and not a certification. The comparison row lists certifiable as No.

The Top 10, ASVS, and the LLM Top 10 are the same homework.

They are different objects. Top 10:2025 names web risk themes. ASVS is a separate requirements project for testable depth. OWASP Top 10 for LLM Applications 2026 is a separate awareness list. Do not collapse them.

This page replaces the Reference OWASP framework card.

The card at /reference/frameworks/owasp-top-10-2025/ stays the framework summary. This page is literacy beside that card.

Atlas, or a vendor homepage shield, attests Top 10 completion.

Atlas does not issue AppSec seals or OWASP Top 10 compliant seals. Completing this lesson is not certified. A homepage shield is not evidence a test ran on your application.

Full OWASP category text and CWE lists should be pasted into Atlas lessons.

This card does not reprint the full OWASP risk text, and it does not list CWE identifiers. Read the official pages instead of pasting them into Atlas.

A01:2025 through A10:2025, as labels

Official 2025 category names, slogan depth only. This table does not reprint OWASP risk text, and it does not list CWE identifiers.

Ten awareness category labels. Not a finished test, and not a certification.
IDOfficial name (2025)Boundary
A01:2025Broken Access ControlAwareness category label. Not a finished test.
A02:2025Security MisconfigurationAwareness category label. Not a finished test.
A03:2025Software Supply Chain FailuresAwareness category label. Not a finished test. Supply-chain practice stays on the AppSec path.
A04:2025Cryptographic FailuresAwareness category label. Not a finished test.
A05:2025InjectionAwareness category label. Not a finished test.
A06:2025Insecure DesignAwareness category label. Not a finished test. Threat-model practice stays on the AppSec path.
A07:2025Authentication FailuresAwareness category label. Not a finished test.
A08:2025Software or Data Integrity FailuresAwareness category label. Not a finished test.
A09:2025Security Logging and Alerting FailuresAwareness category label. Not a finished test.
A10:2025Mishandling of Exceptional ConditionsAwareness category label. Not a finished test. A 2025 theme on this list. Not an error-handling catalog.

CHECK THE CATEGORY

Which sentence matches this page?

Glossary and nearby pages

Use the agency page in the sources for the authoritative text. This page has no figure.

Find your next idea.

Tip: press / to open search. Escape closes this window.