App Defense Alliance Authorized Lab
Google MASA certification from an ADA authorized Lab
MASA (Mobile Application Security Assessment) is Google Play's independent security review standard for Android apps. Show users your app was tested against it. NowSecure® takes you from first scan to certified listing, and works with your developers on everything in between.
The Android security standard
What android MASA certification is now
MASA, short for Mobile Application Security Assessment, is a security standard for Android mobile applications, governed by the App Defense Alliance (ADA) under the Linux Foundation. It defines a testable baseline with clear acceptance criteria, so a developer in one company and an assessor in another are working from the same requirements for the app's Google Play listing.
The current requirements are maintained by the Alliance's Application Security Assessment Working Group and published openly on GitHub. Certification is carried out by authorized labs and verified by TrustCB, the Alliance's external certification body. Every authorized lab must hold ISO/IEC 17025 accreditation and pass proficiency evaluations for the profiles it tests.
If you last looked at Android MASA certification in 2022, three things have changed. The requirements moved to the Alliance and were restructured. A formal certification body now sits behind the labs. And certified apps are listed publicly in the ADA Certified Products Portal, so your certification is visible outside your Play Store listing.
Requirements
The eight MASA control groups for Android apps
Every app is measured against the same Mobile Application Security Assessment (MASA) control groups, drawn from the OWASP MASVS. To certify, your app has to meet every requirement that applies to it.
Storage
Storing sensitive data securely and preventing unintentional leaks.
Cryptography
Using strong cryptography and managing keys according to current best practice.
Authentication and authorization
Following secure authentication and authorization protocols.
Network
Securing all network traffic to current standards.
Platform
Using IPC mechanisms, WebViews, and the user interface safely.
Code
Requiring an up-to-date platform, avoiding known vulnerable components, and validating untrusted input.
Resilience
Implementing anti-tampering and anti-analysis protections.
Privacy
Minimizing data access, being transparent about collection, and giving users control over their data.
Resilience and privacy are where most teams get surprised. They are the two groups least likely to be covered by a general application security program, and they are exactly where a mobile-only lab earns its keep.
The Android security standard
MASA AL1 or AL2: which Android assurance level do you need
Mobile Application Security Assessment (MASA) certification has two assurance levels. The level sets the depth of the review.
al1
Efficient baseline
How it works
The lab evaluates the public version of your app using automated tooling, paired with a developer questionnaire confirming compliance against the applicable requirements.
Best fit
Low-risk apps that hold little user data and have no sensitive functionality.
al2
Human analysis and remediation support
How it works
An authorized lab performs human analysis using specialist tooling, may come back to you with questions about how the app works, and gives you remediation steps for anything flagged. Once your app meets all requirements, the lab submits a validation report confirming eligibility for the security designation on your Data safety form.
Best fit
Apps that handle regulated or high-sensitivity data, hold authenticated sessions, move money, or are subject to customer security review.
Your level can change from year to year. An app certified at AL1 can move to AL2 at renewal, and the reverse is also true.
The process
How certification works with NowSecure
Scope and kickoff
Tell us your app, your target assurance level, and your release date. We confirm scope and turn around paperwork.
Pre-assessment scan
We test your app before the formal assessment, so you find out what would fail while you still have time to fix it. No surprises in the report that decides your certification.
Assessment
Our assessors test against the applicable MASA requirements. AL2 includes hands-on analysis by mobile security engineers, not just tooling output.
Findings and remediation guidance
You get a report with evidence for every failed requirement, plus specific guidance on what to change. Our team works directly with your developers rather than handing over a PDF and going quiet.
Retest
We re-verify the requirements you remediated.
Validation report
Once your app meets all applicable requirements, we submit the validation report.
Badge and listing
You update your Data safety section in the Play Console to indicate independent validation. Your certified app appears in the ADA Certified Products Portal.
Timeline. Assessment typically begins within 10 days of completed paperwork. For AL2, expect roughly 2 to 3 weeks from assessment to badge availability. Total elapsed time depends mostly on how fast your team can remediate.
What Android MASA certification covers
MASA (Mobile Application Security Assessment) covers client-side security, authentication to your backend, and the connectivity between them. That includes data storage, cryptography, network communication, platform interaction, code quality, resilience, and privacy practices.
MASA does not certify your backend infrastructure, your cloud configuration, or your web application. The Alliance runs separate standards for those, including CASA for web applications and a cloud configuration profile.
If your assessment surfaces issues that go deeper than the MASA baseline, or you want adversarial testing beyond a compliance floor, our mobile app penetration testing team can pick up where certification stops.
What you get
- Detailed findings report with evidence for every failed requirement.
- Remediation guidance written for developers, not for auditors.
- Direct access to the assessors who tested your app.
- Retest of remediated requirements.
- Validation report submitted on your behalf.
- Certification valid for 365 days
- Public listing in the ADA Certified Products Portal.
After you certify
Certification is annual, and it is spot checked
It expires
If your assessment surfaces issues that go deeper than the MASA baseline, or you want adversarial testing beyond a compliance floor, our mobile app penetration testing team can pick up where certification stops.
It is checked in between
The Alliance runs periodic spot checks. Authorized labs randomly scan certified apps and notify developers of findings. Certification reflects your security posture at a moment in time, and you are expected to hold that posture through the year.
Both of those are easier when mobile testing is part of your release process rather than an annual event. If you ship every two weeks, an annual certification you never test against between renewals is a certification you will scramble to keep.
NowSecure Platform runs automated mobile app security testing in your CI, so you see a regression the week it ships, not the week before your renewal is due.
The NowSecure difference
Why teams choose NowSecure
We help write the standard Android MASA is built on
MASA (Mobile Application Security Assessment) is grounded in the OWASP MASVS and the OWASP MASTG. NowSecure is an OWASP MAS Advocate and an active contributor to the project, including co-leadership of the mobile weakness enumeration work. Most labs read the standard. We help build it.
Remediation support, not a scorecard
A failed requirement is only useful if your developers know what to change. Our assessors work directly with your team through remediation and retest, because a certification you get in six weeks is worth more than a report you get in two.
Mobile is all we do
The authorized lab list includes general penetration testing firms, vulnerability management platforms, and multinational testing and inspection groups. NowSecure tests mobile apps and nothing else. Our engineers wrote and maintain Frida and Radare2, the instrumentation and reverse engineering tooling that mobile security work runs on.
Depth when the baseline is not enough
MASA is a floor. When you need more, the same team runs full-scope mobile penetration testing and OWASP MASVS-based assessments against the
same app.
Android MASA certification at a glance
| Full name | Mobile Application Security Assessment (MASA), for Android apps on Google Play. |
|---|---|
| Standard | MASA, maintained by the App Defense Alliance Application Security Assessment Working Group. |
| Built on | OWASP Mobile Application Security Verification Standard (MASVS) and the OWASP MASTG. |
| Control groups | Eight: Storage, Cryptography, Authentication and Authorization, Network, Platform, Code, Resilience, Privacy |
| Assurance levels | AL1 and AL2. |
| Certification validity | 365 days from date of issue. |
| Assessment start | Within 10 days of completed paperwork. |
| AL2 timeline | Typically 2 to 3 weeks from assessment to badge availability. |
| Certification body | TrustCB |
| Lab requirement | ISO/IEC 17025 accreditation and per-profile proficiency evaluation |
| Public listing | ADA Certified Products Portal |
| Investment | Contact us for scoping |
See what NowSecure Agentic AI surfaces in your mobile app portfolio.
Start with your highest-priority apps. See what AI surfaces from day one.
Resources
Mobile Application Risk Management Resources
Frequently asked questions about mobile application security testing
Have more questions? Get in touch with our team.