OWASP Top 10:2025
The OWASP Top 10 is the standard awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications. The 2025 edition includes two new categories: Software Supply Chain Failures (A03) and Mishandling of Exceptional Conditions (A10), with significant reorganization from the 2021 edition.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
OWASP content is used under the Creative Commons Attribution-ShareAlike 4.0 International License (CC BY-SA 4.0). Original material © OWASP Foundation. See owasp.org for the authoritative source.
Framework Domains (7)
Authentication and Session Management
Risks related to identity verification and authentication weaknesses
| Code | Title |
|---|---|
| A07:2025 | Authentication Failures |
Authorization and Access Control
Risks related to broken access control and security misconfiguration
| Code | Title |
|---|---|
| A01:2025 | Broken Access Control |
| A02:2025 | Security Misconfiguration |
| FHIR-SEC-3.1 | Security Labels |
| FHIR-SEC-3.2 | Consent-Based Access Control |
| FHIR-SEC-3.3 | Scope-Based Authorization |
Cryptography and Data Protection
Risks related to cryptographic failures and data exposure
| Code | Title |
|---|---|
| A04:2025 | Cryptographic Failures |
Design and Architecture
Risks related to insecure design patterns and integrity failures
| Code | Title |
|---|---|
| A06:2025 | Insecure Design |
| A08:2025 | Software or Data Integrity Failures |
Injection and Input Handling
Risks related to injection attacks and insecure input processing
| Code | Title |
|---|---|
| A05:2025 | Injection |
Monitoring and Error Handling
Risks related to insufficient logging and improper error handling
| Code | Title |
|---|---|
| A09:2025 | Security Logging and Alerting Failures |
| A10:2025 | Mishandling of Exceptional Conditions |
Supply Chain and Dependencies
Risks related to third-party components and software supply chain
| Code | Title |
|---|---|
| A03:2025 | Software Supply Chain Failures |
| AESCSF-SC-1 | Supply Chain Risk Management |
| AESCSF-SC-2 | Third-Party Assessment |
| AESCSF-SC-3 | Dependency Mapping |
Maps to 618 other frameworks
Frequently Asked Questions
What is OWASP Top 10:2025?
OWASP Top 10:2025 is a compliance framework from International with 7 domains and 16 controls. The OWASP Top 10 is the standard awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications. The 2025 edition includes two new categories: Software Supply Chain Failures (A03) and Mishandling of Exceptional Conditions (A10), with significant reorganization from the 2021 edition. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does OWASP Top 10:2025 have?
OWASP Top 10:2025 has 16 controls organised across 7 domains. The largest domains are Authorization and Access Control (5 controls), Supply Chain and Dependencies (4 controls), Design and Architecture (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does OWASP Top 10:2025 map to?
OWASP Top 10:2025 maps to 618 other compliance frameworks. The top mapping partners are ASD Information Security Manual (ISM) (69% coverage), CSA CCM v4 (69% coverage), NIS2 Directive Implementing Acts (69% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with OWASP Top 10:2025 compliance?
Start your OWASP Top 10:2025 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about OWASP Top 10:2025 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 16 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required