DevOps security audit: now tested against OWASP ASVS 5.0.0
An audit is only as good as the standard it measures against. Starting today, our DevOps security audit tests against the latest version of the OWASP Application Security Verification Standard: ASVS 5.0.0, released May 2025. Every finding also carries a CWE label, an NCSC measure and a CVSS severity band. That sounds like paperwork, but it is exactly what separates a scanner that alarms from a report your vulnerability register can ingest directly.
Lees deze pagina in het Nederlands
Run free auditWhy ASVS 5.0.0 matters
Most scanners on the market still reference ASVS 4.0.3, the predecessor from 2019. Understandable: version 5.0.0 arrived in May 2025 as the first major revision in six years, and it tore up the entire numbering scheme. What used to be chapter 9 (communications security) is now chapter 12; configuration moved from 14 to 13; the requirements for cookies, headers and external scripts now live together in chapter 3.
A vendor that puts 'ASVS' on its website today without a version number is almost certainly testing against a seven-year-old standard. Our DevOps audit is one of the first to update and re-verify all 44 references in the engine against the official ASVS 5.0.0 source. Not renumbered one by one, but remapped, requirement by requirement.
CWE labels: from loose text to data
Every finding in our report now carries a CWE number (Common Weakness Enumeration): the worldwide catalogue of weakness types. A leak via a missing Strict-Transport-Security header is no longer 'high risk, header missing', but CWE-319: Cleartext Transmission of Sensitive Information. Click the label and you land on the MITRE page with all the background.
Why that matters: a CWE label is machine-readable. Your ticketing system, SIEM or vulnerability register ingests it directly. Security tools that do not emit CWE deliver loose text that someone has to translate by hand. When reporting to a client, an auditor or an ISO 27001 assessor, that is the difference between an afternoon of copy-paste and an import.
NCSC guidelines: the Dutch layer
ASVS and CWE are international. But anyone serving the Dutch public sector, or a client with Dutch requirements, deals with the NCSC ICT security guidelines for web applications. Every security finding that touches them now cites the concrete measure: U/NW.03 for encrypted transport, U/PW.03 for web server configuration and headers, U/PW.07 for secret management.
One scan, three reference frames: the international standard (ASVS), the weakness type (CWE) and the national measure (NCSC). That mapping is where the commercial value of an audit report lives.
CVSS severity bands: honest about what a scanner knows
Each finding's severity is now shown with a CVSS band: High (7.0-10.0), Medium (4.0-6.9) or Low (0.1-3.9). CVSS is the industry-standard 0.0 to 10.0 score for severity.
Deliberately a band, not an exact number: an exact CVSS score requires verifying exploitability, which an external scan cannot honestly establish. Tools that compute a precise 8.7 without touching the vulnerability are simulating precision that does not exist. The band is the most honest thing measurable from the outside.
Honest about the limits of every scanner
The same goes for our coverage claim. Broken access control tops the OWASP Top 10:2025 as the biggest risk category, and it is precisely the category no scanner can test automatically: a scanner does not know who is allowed to see what. Business logic flaws neither.
Any vendor promising '100% OWASP coverage' is lying. Our report prefers to say it ourselves: we cover the externally measurable subset of ASVS 5.0.0 Level 1, and we explicitly state which checks could not run. That honesty is not a weakness; it is the reason our report survives being read by an engineer or an auditor.
What the upgrade means in practice
All changes live in a central standards map in the engine. Each of the 40+ checks pulls its references from there, which means future standard revisions are applied in one place instead of scattered across the codebase.
For existing users nothing changes in the workflow: the same scan, the same report, but every security finding now shows the ASVS 5.0.0 requirement, the CWE type, the applicable NCSC measure and the CVSS band. SARIF export carries the CWE labels as tags, so they flow into automated tooling.
Why we rank among the best
The audit market is full of scanners making the same promises. The measurable differences lie elsewhere: in the version of the standard you test against, whether your output is machine-readable, and whether the report is honest about its own limits.
On all three, this DevOps audit now scores at the top: the most current standard (ASVS 5.0.0, verified), machine-readable output (CWE in report and SARIF, three reference frames per finding) and explicit honesty about what cannot be tested automatically. It is that combination, plus the evidence per finding, that we call ourselves the best of the best, and it is verifiable in every free report.
Frequently asked questions
- What is OWASP ASVS 5.0.0?
- The Application Security Verification Standard, version 5.0.0, was released in May 2025 as the first major revision in six years. It is the testable standard for web application security requirements. Our DevOps security audit tests the externally measurable subset of Level 1.
- Why is a CWE label useful?
- CWE is the worldwide catalogue of weakness types. With a CWE number per finding, your ticketing, SIEM or vulnerability register can ingest the output automatically, and you find the technical background at MITRE. Without CWE, a report is loose text that has to be translated by hand.
- Are NCSC guidelines mandatory?
- The NCSC ICT security guidelines for web applications are not law, but for the Dutch public sector and many clients they are the yardstick. Our report cites the relevant measure per finding (such as U/PW.03), so you can report against that framework directly.
- What is CVSS and why a band instead of an exact score?
- CVSS expresses severity on a 0.0 to 10.0 scale. An exact score requires verifying exploitability; an external scan cannot honestly establish that. That is why we show the severity band (such as 7.0-10.0 for high) instead of a falsely precise score.
- Is the DevOps audit suitable for ISO 27001 or third-party audits?
- Yes, that is exactly what the upgrade was built for: standard version numbers, CWE labels, NCSC measures and CVSS bands per finding make the report directly usable as evidence in an ISO 27001 assessment or a client audit question.
- Do I need to change anything about my scans?
- No. The upgrade lives in the engine and the reporting. Your next scan automatically shows ASVS 5.0.0, CWE, NCSC and CVSS in every security finding, including the free Quick scan.
Curious what is on your own site? Paste a URL and you have a report within a minute.
Run free audit