NowSecure just lately celebrated three years of contributing to the OWASP Cellular App Safety Undertaking which produces globally acknowledged requirements for safe cell app improvement and cell app safety testing. The corporate’s trade management as an OWASP MAS Advocate has superior cell safety and offered cell software threat administration options that align with OWASP requirements to scale back threat, strengthen privateness and guarantee compliance.
Led by Carlos Holguera, the OWASP MAS Undertaking co-chair and a NowSecure principal analysis engineer, the NowSecure contributions to OWASP cell safety initiatives will be partially quantified by GitHub metrics:
- 320+ pull requests
- 230+ opinions
- 42,000+ additions
- 29,500+ deletions
These numbers mirror greater than exercise — they show management. NowSecure has considerably superior OWASP MAS sources by contributing useful content material, reviewing group submissions and sustaining the general readability and high quality of the mission.
NowSecure has considerably superior OWASP MAS sources by contributing useful content material, reviewing group submissions and sustaining the general readability and high quality of the mission.
Why OWASP Cellular Software Safety Issues to Safety Leaders
The OWASP Cellular App Safety mission gives an authoritative, community-driven framework for securing cell purposes. It contains three core parts which have develop into important sources for cell safety leaders, practitioners and builders:
- MASVS: The Cellular Software Safety Verification Normal (MASVS) defines the safety controls required to safe a cell app throughout completely different menace fashions.
- MASTG: The Cellular Software Safety Testing Information (MASTG) gives detailed check instances and methodologies to evaluate app compliance in opposition to MASVS.
- MASWE: The Cellular App Safety Weak point Enumeration (MASWE) gives a structured taxonomy of identified cell safety weaknesses for higher vulnerability monitoring and remediation.

Collectively, these frameworks assist safety leaders:
- Set up constant, measurable cell software safety requirements throughout inner and third-party improvement groups
- Align cell software safety testing with regulatory compliance necessities equivalent to GDPR, HIPAA, PCI DSS, and CCPA
- Scale back threat publicity from cell threats by way of structured verification, safety assessments and remediation planning
- Allow DevSecOps and AppSec groups to shift left and implement safe coding practices earlier within the improvement lifecycle.
“The MAS Requirements assist reply the crucial query, ‘Have we carried out sufficient based mostly on the enterprise threat of the cell app?” says NowSecure CEO Alan Snyder. “The requirements keep present by way of group enter, allow vendor efficiency comparisons and supply proof of cheap care to auditors and regulators. Any critical cell app threat administration program ought to incorporate them.”
How NowSecure Helps & Contributes to OWASP MAS
As a longstanding OWASP MAS contributor and advocate, NowSecure performs a pivotal function in shaping the way forward for cell safety requirements. As talked about above, our crew has contributed greater than 320 GitHub pull requests, 230 opinions and tens of 1000’s of traces of additives and enhancements to the MASVS, MASTG and MASWE sources.
Our contributions have influenced practically each main evolution of the mission previously three years:
MASVS v2.0 & v2.1 Modernize Cellular AppSec Requirements
In 2023, OWASP launched MASVS v2.0 — a serious replace that launched a simplified, modular construction with clearly outlined MAS Testing Profiles to assist real-world cell threat fashions. NowSecure contributed technical insights, real-world testing situations and strategic steering that helped refine the usual and enhance its usability for cell builders and safety groups.
In early 2024, MASVS-PRIVACY v2.1 was addressed to handle privateness and information safety dangers — a contribution closely influenced by NowSecure’s work within the monetary, healthcare and high-tech sectors.
MASTG Refactor Enhances Sensible Testing and Usability
The Cellular Software Safety Testing Information underwent a serious refactor led partly by NowSecure. The updates included:
- Atomic Testing: Smaller, self-contained exams with clear traceability.
- Modular Framework: Separation of exams, methods, instruments, and app examples.
- Improved Searchability and Upkeep: Enabling quicker onboarding and simpler adoption for safety analysts.
These updates ease the method of conducting audits, automating assessments and tracing findings again to MASVS controls — accelerating time-to-insight and time-to-remediation.
MASWE Maps the Cellular Menace Panorama
NowSecure contributed considerably to the MASWE, a brand new enumeration designed to bridge the hole between safety necessities and concrete cell weaknesses. MASWE improves the traceability between MASVS and MASTG, making it simpler for groups to trace vulnerabilities throughout the SDLC and triage dangers with precision.
Check Apps and Allow Builders
To empower cell improvement and safety groups with hands-on expertise, NowSecure supported the creation of standardized MAS Check Apps for iOS and Android. These embrace:
- Skeleton purposes for speedy testing
- Embedded code samples to simulate vulnerabilities
- CI/CD integration by way of GitHub Actions
This funding helps cell groups study, check, and scale safe improvement practices in real-world environments.
Operationalize OWASP MAS with NowSecure Platform
As an enterprise chief, contributing to OWASP MAS is simply a part of the story. NowSecure built-in OWASP MAS requirements immediately into NowSecure Platform, an automatic cell app safety testing answer. This permits organizations to:
- Conduct steady testing aligned to MASVS Testing Profiles
- Automate assessments for inner, third-party and public apps
- Map findings to MASVS, MASTG and MASWE for audit-ready stories
- Help privateness testing with MASVS-PRIVACY integration
- Shift left with CI/CD and API-first integrations.
This strategy empowers CISOs and AppSec leaders to scale cell app safety efforts throughout the cell ecosystem and quickly launch safe apps with out slowing improvement.
Drive Strategic Cellular Safety Outcomes
By contributing to and aligning with OWASP MAS, NowSecure helps CISOs, safety leaders and DevSecOps leaders obtain these enterprise targets:
- Scale back Danger: Stop information breaches and privateness violations
- Guarantee Compliance: Meet requirements like OWASP MASVS, GDPR, HIPAA, and SOC 2
- Allow DevSecOps: Embed safety into the SDLC and CI/CD pipeline
- Enhance Safety Maturity: Set up a repeatable, scalable cell AppSec program
- Reveal Management: Align your program with world safety finest practices
Accomplice with NowSecure to Lead in Cellular Software Safety
The OWASP MAS mission continues to set the worldwide customary for cell AppSec — and NowSecure is proud to paved the way. Our specialists, instruments and contributions assist enterprise safety leaders construct and preserve resilient risk-based cell safety applications backed by confirmed requirements.
Discover how NowSecure will help your crew align with OWASP MASVS requirements, automate cell app safety testing and higher handle cell app threat by requesting a NowSecure Platform demo or cell PTaaS at present.