Live Webinar: Go inside the biggest OWASP MAS update yet with the person who led it. Live Webinar: Go inside the biggest OWASP MAS update yet with the person who led it. Register Now →
magnifying glass icon

App Defense Alliance Authorized Lab

Google MASA certification from an ADA authorized Lab

MASA (Mobile Application Security Assessment) is Google Play's independent security review standard for Android apps. Show users your app was tested against it. NowSecure® takes you from first scan to certified listing, and works with your developers on everything in between.

The Android security standard

What android MASA certification is now

MASA, short for Mobile Application Security Assessment, is a security standard for Android mobile applications, governed by the App Defense Alliance (ADA) under the Linux Foundation. It defines a testable baseline with clear acceptance criteria, so a developer in one company and an assessor in another are working from the same requirements for the app's Google Play listing.

The current requirements are maintained by the Alliance's Application Security Assessment Working Group and published openly on GitHub. Certification is carried out by authorized labs and verified by TrustCB, the Alliance's external certification body. Every authorized lab must hold ISO/IEC 17025 accreditation and pass proficiency evaluations for the profiles it tests.

If you last looked at Android MASA certification in 2022, three things have changed. The requirements moved to the Alliance and were restructured. A formal certification body now sits behind the labs. And certified apps are listed publicly in the ADA Certified Products Portal, so your certification is visible outside your Play Store listing.

Requirements

The eight MASA control groups for Android apps

Every app is measured against the same Mobile Application Security Assessment (MASA) control groups, drawn from the OWASP MASVS. To certify, your app has to meet every requirement that applies to it.

Background

Storage

Storing sensitive data securely and preventing unintentional leaks.

Background-1

Cryptography

Using strong cryptography and managing keys according to current best practice.

Background-2

Authentication and authorization

Following secure authentication and authorization protocols.

Background-3

Network

Securing all network traffic to current standards.

Background-4

Platform

Using IPC mechanisms, WebViews, and the user interface safely.

Background-5

Code

Requiring an up-to-date platform, avoiding known vulnerable components, and validating untrusted input.

Background-6

Resilience

Implementing anti-tampering and anti-analysis protections.

Background-7

Privacy

Minimizing data access, being transparent about collection, and giving users control over their data.

Resilience and privacy are where most teams get surprised. They are the two groups least likely to be covered by a general application security program, and they are exactly where a mobile-only lab earns its keep.

The Android security standard

MASA AL1 or AL2: which Android assurance level do you need

Mobile Application Security Assessment (MASA) certification has two assurance levels. The level sets the depth of the review.

al1

Efficient baseline

How it works

The lab evaluates the public version of your app using automated tooling, paired with a developer questionnaire confirming compliance against the applicable requirements.

Best fit

Low-risk apps that hold little user data and have no sensitive functionality.

al2

Human analysis and remediation support

How it works

An authorized lab performs human analysis using specialist tooling, may come back to you with questions about how the app works, and gives you remediation steps for anything flagged. Once your app meets all requirements, the lab submits a validation report confirming eligibility for the security designation on your Data safety form.

Best fit

Apps that handle regulated or high-sensitivity data, hold authenticated sessions, move money, or are subject to customer security review.

Your level can change from year to year. An app certified at AL1 can move to AL2 at renewal, and the reverse is also true.

The process

How certification works with NowSecure

Background

Scope and kickoff

Tell us your app, your target assurance level, and your release date. We confirm scope and turn around paperwork.

Background-1

Pre-assessment scan

We test your app before the formal assessment, so you find out what would fail while you still have time to fix it. No surprises in the report that decides your certification.

Background-2

Assessment

Our assessors test against the applicable MASA requirements. AL2 includes hands-on analysis by mobile security engineers, not just tooling output.

Background-3

Findings and remediation guidance

You get a report with evidence for every failed requirement, plus specific guidance on what to change. Our team works directly with your developers rather than handing over a PDF and going quiet.

Background-4

Retest

We re-verify the requirements you remediated.

Background-5

Validation report

Once your app meets all applicable requirements, we submit the validation report.

Background-6

Badge and listing

You update your Data safety section in the Play Console to indicate independent validation. Your certified app appears in the ADA Certified Products Portal.

Timeline. Assessment typically begins within 10 days of completed paperwork. For AL2, expect roughly 2 to 3 weeks from assessment to badge availability. Total elapsed time depends mostly on how fast your team can remediate.

What Android MASA certification covers

MASA (Mobile Application Security Assessment) covers client-side security, authentication to your backend, and the connectivity between them. That includes data storage, cryptography, network communication, platform interaction, code quality, resilience, and privacy practices.

MASA does not certify your backend infrastructure, your cloud configuration, or your web application. The Alliance runs separate standards for those, including CASA for web applications and a cloud configuration profile.

If your assessment surfaces issues that go deeper than the MASA baseline, or you want adversarial testing beyond a compliance floor, our mobile app penetration testing team can pick up where certification stops.

What you get

  • Detailed findings report with evidence for every failed requirement.
  • Remediation guidance written for developers, not for auditors.
  • Direct access to the assessors who tested your app.
  • Retest of remediated requirements.
  • Validation report submitted on your behalf.
  • Certification valid for 365 days
  • Public listing in the ADA Certified Products Portal.

After you certify

Certification is annual, and it is spot checked

Background

It expires

If your assessment surfaces issues that go deeper than the MASA baseline, or you want adversarial testing beyond a compliance floor, our mobile app penetration testing team can pick up where certification stops.

Background-1

It is checked in between

The Alliance runs periodic spot checks. Authorized labs randomly scan certified apps and notify developers of findings. Certification reflects your security posture at a moment in time, and you are expected to hold that posture through the year.

Both of those are easier when mobile testing is part of your release process rather than an annual event. If you ship every two weeks, an annual certification you never test against between renewals is a certification you will scramble to keep.

NowSecure Platform runs automated mobile app security testing in your CI, so you see a regression the week it ships, not the week before your renewal is due.

The NowSecure difference

Why teams choose NowSecure

We help write the standard Android MASA is built on

MASA (Mobile Application Security Assessment) is grounded in the OWASP MASVS and the OWASP MASTG. NowSecure is an OWASP MAS Advocate and an active contributor to the project, including co-leadership of the mobile weakness enumeration work. Most labs read the standard. We help build it.

Remediation support, not a scorecard

A failed requirement is only useful if your developers know what to change. Our assessors work directly with your team through remediation and retest, because a certification you get in six weeks is worth more than a report you get in two.

Mobile is all we do

The authorized lab list includes general penetration testing firms, vulnerability management platforms, and multinational testing and inspection groups. NowSecure tests mobile apps and nothing else. Our engineers wrote and maintain Frida and Radare2, the instrumentation and reverse engineering tooling that mobile security work runs on.

Depth when the baseline is not enough

MASA is a floor. When you need more, the same team runs full-scope mobile penetration testing and OWASP MASVS-based assessments against the
same app.

Android MASA certification at a glance

MASA certification specifications
Full name Mobile Application Security Assessment (MASA), for Android apps on Google Play.
Standard MASA, maintained by the App Defense Alliance Application Security Assessment Working Group.
Built on OWASP Mobile Application Security Verification Standard (MASVS) and the OWASP MASTG.
Control groups Eight: Storage, Cryptography, Authentication and Authorization, Network, Platform, Code, Resilience, Privacy
Assurance levels AL1 and AL2.
Certification validity 365 days from date of issue.
Assessment start Within 10 days of completed paperwork.
AL2 timeline Typically 2 to 3 weeks from assessment to badge availability.
Certification body TrustCB
Lab requirement ISO/IEC 17025 accreditation and per-profile proficiency evaluation
Public listing ADA Certified Products Portal
Investment Contact us for scoping

We rarely get things that are ready to go out of the box, then we received the Now Secure solution, we were up and running the same day.”

Derrick Smith
Chief Operating Officer NSight365

NowSecure Workstation enables me to provide fast assessments to my team on a number of key mobile app security features.”

Ben Derr
Security Engineer

One of the best things about moving to NowSecure is not having to fan through a 110-page security audit to figure out what bugs and security issues you need to address.”

Eric Caron
Senior Director of IT Solutions

NowSecure continuously monitors The Habit Mastery app for security and privacy vulnerabilities and gives it a clean bill of health, giving our users confidence that their data is secure while they build and maintain positive habits.

Sharon Lipinski
Founder and CEO, Habit Mastery Consulting

tidepool
caribou coffee
habit mastery consulting

See what NowSecure Agentic AI surfaces in your mobile app portfolio.

Start with your highest-priority apps. See what AI surfaces from day one.

Union

Resources

Mobile Application Risk Management Resources

b8b3fd0a4c2248aa56551a9347055caf6ec238ec
Solutions Brief

Mobile App Risk Management Solutions Brief

eBook

Ungoverned: How AI Widens the Mobile App Gap

Case Study

Bell Canada Dials Into Mobile App Risk Management

Frequently asked questions about mobile application security testing

What is MASA certification?

Not the MASA you were thinking of?

How long does MASA certification take?

How much does MASA certification cost?

How long is MASA certification valid?

What is the difference between MASA AL1 and AL2?

Does Google see my code or my vulnerabilities?

Which apps should get MASA certified?

Do I need to be on the Play Store already?

What happens if my app fails?

What is the ADA Certified Products Portal?

Is Android MASA the same as CASA?

Who can perform a MASA assessment?

Have more questions? Get in touch with our team.