App Defense Alliance MASA AL1

Android apps

MASA AL1 Security Assessment for Android Apps

Get automated security testing, MASA requirement validation, evidence review, clear remediation findings, and one retest — starting at $499 per Android application.

Backed byan accredited security firm.
AccreditationCREST-accredited
AssessmentPCI QSA
PlatformAndroid applications
Governing bodyApp Defense Alliance (ADA)
Assessment basisOWASP mobile application security standards
Retest1 included per application
Remediation windowUp to 60 days

The definition

What is MASA AL1?

MASA (Mobile Application Security Assessment) is a security assessment framework defined by the App Defense Alliance, built on established OWASP mobile application security standards. MASA Assurance Level 1 (AL1) is a streamlined assessment path for Android applications that combines automated security testing with developer self-attestation and supporting evidence, covering data storage, cryptography, authentication, network communication, platform interaction, and secure configuration.
  • Platform

    Android applications

  • Governing body

    App Defense Alliance (ADA)

  • Assessment basis

    OWASP mobile application security standards

  • Retest

    1 included per application

MASA AL1 pricing

Simple pricing based on the number of Android applications you need assessed.

1–2 Apps

$499per app

Talk to us
Plan highlights
  • MASA AL1 assessmentIncluded
  • Automated security testingIncluded
  • MASA requirement validationIncluded
  • Self-attestation & evidence reviewIncluded
  • Findings report & remediation guidanceIncluded
  • Retest1 included per app
  • Remediation windowUp to 60 days

5+ Apps

Custom

Get Volume Pricing
Plan highlights
  • MASA AL1 assessmentIncluded
  • Automated security testingIncluded
  • MASA requirement validationIncluded
  • Self-attestation & evidence reviewIncluded
  • Findings report & remediation guidanceIncluded
  • RetestBased on scope
  • Remediation windowBased on scope
Feature1–2 Apps3–4 Apps5+ Apps
Best forDevelopers and organizations with one or two Android appsOrganizations managing multiple Android applicationsOrganizations, developers, and publishers with larger Android portfolios
Retest1 included per app1 included per appBased on scope
Remediation windowUp to 60 daysUp to 60 daysBased on scope
MASA AL1 assessment
Automated security testing
MASA requirement validation
Self-attestation & evidence review
Findings report & remediation guidance

Every standard assessment includes one remediation retest per application. Additional retests are $199 per application.

What counts as one app?

Each distinct Android application is treated as one MASA AL1 assessment. Pricing applies per Android application, not per organization or developer account. iOS applications are outside the scope of this service.

apps$0
apps$0
apps$0
apps$0

What does the MASA AL1 assessment cover?

Your Android application is evaluated against the applicable MASA AL1 requirements.

  • Data storage & privacy

    How the application handles sensitive information, credentials, cryptographic keys, and other protected data — including secure storage, application logs, sensitive information displayed through the UI, and privacy-related controls.

  • Cryptography

    The application's use of cryptography, including hardcoded cryptographic keys, deprecated algorithms, and insecure cryptographic implementations.

  • Authentication & session management

    Authentication mechanisms, credentials, and session-management controls, evaluated against the applicable requirements where relevant.

  • Network communications

    Security of communications between the application and remote services, including TLS implementation and certificate validation.

  • Android platform interaction

    How the application interacts with the Android platform, including permissions, exported functionality, external inputs, and inter-process communication.

  • Code quality & build settings

    Applicable security-related application configuration and build characteristics, including release configuration, debugging functionality, and third-party components.

How the MASA AL1 assessment works

A simple digital process from purchase to completed assessment.

  1. Step 1Day 1

    Choose the number of apps

    Select the number of Android applications you want assessed. 1–4 apps can be purchased directly online; 5+ apps route to volume pricing.

  2. Step 2After purchase

    Submit application details

    Access Secusy and provide what the assessment needs — Google Play details, the app package or build, test credentials, app information, a completed self-attestation, supporting evidence, and assessment authorization.

  3. Step 3In progress

    MASA AL1 assessment runs

    Your application is evaluated against the applicable MASA AL1 requirements, combining automated security testing with review and validation of requirements, declarations, and supporting evidence.

  4. Step 4On completion

    Findings delivered

    If requirements aren't satisfied, you receive clear findings showing what needs to be addressed, so your development team understands the issue and the requirement it maps to.

  5. Step 5Up to 60 days

    Remediate & retest

    Fix the identified issues and submit the updated build or evidence through Secusy. One remediation retest per application is included, focused on validating the requirements that weren't satisfied.

  6. Step 6Final

    Assessment complete

    Once the applicable requirements are satisfied, we complete the MASA AL1 assessment and validation process, and issue applicable validation documentation.

Included

What you get

Standard assessment includes

  • MASA AL1 assessment for one Android application
  • Automated application security testing
  • MASA requirement validation
  • Self-attestation review
  • Supporting evidence review
  • Analyst validation of assessment results
  • Findings report
  • Remediation guidance
  • One remediation retest
  • Final assessment review
  • Applicable validation documentation following successful completion

Scope boundaries

What's not included

If your application requires a higher assurance level, see MASA AL2 Assessment. If deeper security testing is required, a Mobile Application Penetration Test can be purchased separately.

  • Vulnerability remediation
  • Application development
  • Source-code modification
  • Secure coding implementation
  • Manual penetration testing outside the MASA AL1 scope
  • Full source-code security review
  • Unlimited consulting
  • Unlimited retesting
  • iOS application testing
  • Additional Android applications not purchased as part of the assessment

Intake

Before you start

To avoid delays, be ready to provide the information and access required to assess your application. Incomplete information, inaccessible functionality, or invalid test credentials may delay the assessment.

You will normally provide

  1. Access to the Android application
  2. Application/build information
  3. Valid test credentials where authentication is required
  4. Required developer declarations
  5. Supporting evidence
  6. A contact who can answer assessment questions
  7. An updated application build, if remediation is required

MASA AL1 vs. MASA AL2 vs. mobile application penetration testing

All three validate Android app security, but at different depths. Choose MASA AL1 for the streamlined, fixed-price requirement. Choose MASA AL2 when your OAuth scope or platform requires higher-assurance, lab-led validation. Choose a mobile application penetration test when you need broader security assurance beyond the defined MASA scope.

FeatureMASA AL1MASA AL2Mobile App Pentest
Best forMASA AL1 requirementHigher-assurance MASA requirementDeeper application security assurance
Primary purposeValidate applicable MASA AL1 requirementsHigher-assurance, lab-led MASA validationIdentify exploitable security vulnerabilities
ScopeDefined MASA requirementsDefined MASA requirements, lab-ledBroader application attack surface
Testing approachStandardized AL1 assessmentHigher-assurance lab assessmentExpert-led security testing
Automated testingYesYesYes
Lab-led / manual testingLimitedYesExtensive
Business logic testingNot the primary purposeWhere required by scopeIncluded where applicable
MASA validationYesYesNo
Starting price$499/app$2,999/app$1,499/platform

Questions

Frequently asked questions