Book an Appointment

The OWASP Map for Development Teams

Top 10, ASVS, Cheat Sheet Series, Developer Guide, WSTG, SAMM and tools such as Dependency-Track and ZAP: what each project delivers – and how these building blocks connect into an end-to-end process in everyday development work.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

2.8M+tested applications behind the Top 10:2025 data set
345verifiable requirements across 17 chapters (ASVS 5.0.0)
120continuously maintained cheat sheets (as of July 2026)
15security practices across five business functions (SAMM v2)

The OWASP Foundation maintains dozens of open projects around secure software development – from awareness documents and verifiable standards to ready-to-use tools. In practice, many teams know the Top 10 but not which project is meant for requirements, testing, onboarding or maturity measurement. As a result, the Top 10 gets misread as a checklist while ASVS, WSTG and SAMM go unused. This article puts the most important building blocks into context and shows how to combine them along the development lifecycle into a consistent approach – free of license costs and vendor-neutral.

The Essentials at a Glance

Six topic blocks — tap to expand.

The OWASP Toolbox at a Glance

Five building blocks, one process — each tab shows what the project delivers and what it is meant for.

Awareness
  • An awareness document, not a standard: the Top 10 names the biggest risk categories for web applications, derived from data analyses and community surveys.
  • The 2025 edition — the eighth overall — draws on data from more than 2.8 million tested applications and considers 589 CWEs; new are “Software Supply Chain Failures” (A03) and “Mishandling of Exceptional Conditions” (A10), while “Broken Access Control”, now also covering SSRF, remains in first place.
  • It works as an entry point and shared vocabulary with management and auditors — for verifiable requirements and testing, OWASP itself points to ASVS and WSTG.
2025 edition589 CWEsBroken Access ControlSSRFSupply Chain Failures

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

OWASP Foundation · 2025

OWASP Top 10:2025

Eighth edition of the risk ranking; based on data from more than 2.8 million tested applications and 589 CWEs considered, with new categories including “Software Supply Chain Failures” (A03).

OWASP Foundation · 2025

OWASP Application Security Verification Standard 5.0.0

345 verifiable requirements across 17 chapters with three verification levels; released on 30 May 2025.

OWASP Foundation · 2026

OWASP Cheat Sheet Series

Continuously maintained collection of 120 topic-specific implementation guides (as of July 2026) with index views by ASVS, Top 10 and Proactive Controls.

OWASP Foundation · 2020

OWASP Web Security Testing Guide v4.2

Stable reference methodology for testing web applications (published on 3 December 2020) with unique test IDs; version 5.0 in development.

OWASP Foundation · 2024

OWASP Software Assurance Maturity Model (SAMM) v2

Maturity model with five business functions, 15 security practices and three maturity levels; current model release v2.2.0 from 6 July 2024.

ZAP / Checkmarx (zaproxy.org) · 2024

ZAP Has Joined Forces With Checkmarx

Official project announcement on the transition of the former OWASP project ZAP to Checkmarx (24 September 2024); ZAP remains open source and free of charge.

Integrate OWASP building blocks into your development process?

We support you in bringing ASVS requirements, WSTG-based testing and a SAMM assessment into your development processes. Contact us for a no-obligation initial consultation.