Security standards move. A report citing the 2017 OWASP Top 10 or the pre-2022 ISO 27001 controls tells a careful reader the work is out of date. These are the editions we test and audit against today, and why each one earns its place.
01
OWASP Top 10:2025
The awareness baseline for web application risk. Broken access control is still number one; software supply chain failures and mishandled exceptional conditions are new.
02
OWASP ASVS 5.0
The Application Security Verification Standard — hundreds of testable requirements in three levels. What turns “we tested it” into “we verified these specific controls”.
03
OWASP API Security Top 10 (2023)
The API-specific list, led by broken object level authorisation. Essential for any product with a mobile app or a public API.
04
OWASP Web Security Testing Guide
The testing methodology itself: how each category of weakness is actually tested, so coverage is repeatable rather than down to one tester’s habits.
05
NIST CSF 2.0
NIST’s Cybersecurity Framework, updated in 2024 with a sixth function, Govern. Our default for giving leadership an honest picture of maturity.
06
NIST SP 800-115
NIST’s technical guide to security testing and assessment, which shapes how we plan, run and report engagements.
07
ISO/IEC 27001:2022
The international standard for an information security management system, with 93 Annex A controls in four themes. Certification is what European and enterprise customers often require.
08
SOC 2
The AICPA attestation over the Trust Services Criteria — security, availability, processing integrity, confidentiality and privacy. Issued by CPA firms; we prepare you for it.
09
PCI DSS v4.0.1
The card industry standard. Its future-dated requirements, including payment-page script controls 6.4.3 and 11.6.1, became mandatory on 31 March 2025.
10
CIS Controls v8.1
Eighteen prioritised controls. Implementation Group 1 is the most practical definition of essential cyber hygiene for a smaller organisation.
11
MITRE ATT&CK
A shared vocabulary of real attacker techniques, used to describe attack paths and to check that detection covers how attacks actually happen.
12
CVSS v4.0
The scoring system for severity, released in 2023. We score with it, then explain in plain words what the number means for your environment.