App Defense Alliance MASA AL2

Android apps

MASA AL2 Security Assessment for Android Apps

Get your Android application independently tested and validated against MASA Assurance Level 2 requirements through a structured, lab-led security assessment — $2,999 per app, with one retest included.

Backed byan accredited security firm.
AccreditationCREST-accredited
AssessmentPCI QSA
PlatformAndroid applications
Governing bodyApp Defense Alliance (ADA)
Assessment approachHigher-assurance, lab-led testing
Retest1 included per application
ValidationLab-validated MASA requirements

The definition

What is MASA AL2?

MASA (Mobile Application Security Assessment) is a security assessment framework defined by the App Defense Alliance, built on established OWASP mobile application security standards. MASA Assurance Level 2 (AL2) provides a higher level of assurance than AL1 through greater lab-led security testing and independent validation of applicable MASA requirements by an authorized lab, covering data storage, cryptography, authentication, network communication, Android platform interaction, and application security configuration.
  • Platform

    Android applications

  • Governing body

    App Defense Alliance (ADA)

  • Assessment approach

    Higher-assurance, lab-led testing

  • Retest

    1 included per application

MASA AL2 pricing

Transparent pricing for individual Android applications, with custom pricing available for larger application portfolios.

3+ Apps

Custom

Get Pricing
Plan highlights
  • PlatformAndroid
  • MASA AL2 assessmentIncluded
  • Automated security testingIncluded
  • Lab-led security testingIncluded
  • MASA requirement validationIncluded
  • Evidence reviewIncluded
  • Findings report & remediation guidanceIncluded
  • RetestDefined in scope
  • Final validationIncluded
Feature1–2 Apps3+ Apps
Best forDevelopers and organizations with one or two Android appsOrganizations, developers, and publishers with larger Android portfolios
PlatformAndroidAndroid
Retest1 included per appDefined in scope
MASA AL2 assessment
Automated security testing
Lab-led security testing
MASA requirement validation
Evidence review
Findings report & remediation guidance
Final validation

Each application receives its own MASA AL2 assessment and one remediation retest. Further retesting beyond the included retest can be purchased separately.

What counts as one app?

Each distinct Android application is treated as one MASA AL2 assessment. Pricing applies per Android application, not per organization or developer account. iOS applications are outside the scope of this service.

apps$0
apps$0

What does the MASA AL2 assessment cover?

Your Android application is tested against the applicable MASA AL2 security requirements.

  • Data storage & privacy

    How the application stores, processes, and exposes sensitive information — covering applicable controls relating to sensitive information, credentials, cryptographic material, application logs, and other protected data.

  • Cryptography

    Applicable cryptographic controls, including weak algorithms, insecure cryptographic implementation, and inappropriate handling of cryptographic keys.

  • Authentication & session management

    Where applicable, authentication mechanisms, credential handling, and session-management controls.

  • Network communications

    Security of communications between the Android application and remote services, including applicable TLS and certificate-validation controls.

  • Android platform interaction

    How the application interacts with the Android platform, including applicable permissions, exported components, external inputs, and inter-process communication.

  • Code quality & application configuration

    Applicable application security configuration, release settings, debugging functionality, and security-relevant implementation characteristics.

How the MASA AL2 assessment works

A structured digital process from purchase to completed validation.

  1. Step 1Day 1

    Purchase your assessment

    Need MASA AL2 for one or two Android applications? Purchase directly online for $2,999 per application. For three or more applications, request pricing.

  2. Step 2After purchase

    Complete digital onboarding

    Access Secusy and provide what the assessment needs — Google Play details, the application package or build, test credentials, functionality information, supporting evidence, testing instructions, and assessment authorization.

  3. Step 3In progress

    We perform the AL2 security assessment

    Our security team performs the applicable MASA AL2 testing, combining appropriate security testing techniques with analyst-led validation. Unlike AL1's streamlined approach, AL2 requires greater lab involvement in testing and validating the application's security controls.

  4. Step 4On completion

    Receive your findings

    If the application does not satisfy an applicable requirement, you receive findings explaining what needs to be addressed so your development team can remediate the issues.

  5. Step 5After findings

    Remediate the issues

    Your development team fixes the identified security issues and provides the updated application or supporting evidence. Development and remediation are not included in the standard assessment.

  6. Step 6Final

    Retest & complete AL2 validation

    We retest the applicable failed requirements — one remediation retest per application is included. Once the application satisfies the applicable requirements, we complete the MASA AL2 validation process.

Included

What you get

Standard assessment includes

  • MASA AL2 assessment for one Android application
  • Automated application security analysis
  • Lab-led security testing
  • Validation against applicable MASA requirements
  • Supporting evidence review
  • Security findings report
  • Remediation guidance
  • One remediation retest
  • Final assessment review
  • Applicable validation documentation following successful completion

Scope boundaries

What's not included

If you need broader security assurance, consider a Mobile Application Penetration Test in addition to MASA.

  • Application development
  • Vulnerability remediation
  • Source-code modification
  • Secure coding implementation
  • Unlimited security consulting
  • Unlimited retesting
  • Testing outside the applicable MASA scope
  • Additional applications not purchased as part of the engagement
  • Full mobile application penetration testing outside the MASA scope

Intake

Before you start

To begin the assessment efficiently, be ready to provide the information and access required to test your application. Incomplete information, inaccessible application functionality, or invalid credentials may delay the assessment.

You will normally provide

  1. Access to the Android application
  2. Required application/build information
  3. Valid test credentials
  4. Information about application functionality
  5. Supporting evidence
  6. Required assessment authorization
  7. A technical contact who can respond to assessment questions
  8. An updated application build, if remediation is required

MASA AL1 vs. MASA AL2

Both assessment levels evaluate mobile application security, but they provide different levels of assurance. Your required assurance level should be determined by the applicable MASA requirement rather than price alone.

FeatureMASA AL1MASA AL2
Assessment approachStreamlinedHigher-assurance lab assessment
Automated testingYesYes
Lab-led testingLimitedYes
Requirement validationLab validated
Human testing effortLowerHigher
Starting price$499/app$2,999/app
Retest1 included1 included
Online purchaseYesYes, for 1–2 apps

Need AL1 instead? View MASA AL1.

MASA AL2 vs. mobile application penetration testing

MASA AL2 includes security testing, but it has a defined objective: assessing the application against applicable MASA security requirements. A mobile application penetration test has a broader objective of discovering exploitable vulnerabilities across the application's attack surface.

FeatureMASA AL2Mobile App Pentest
Primary objectiveMASA requirement validationVulnerability discovery
ScopeDefined MASA requirementsBroader application attack surface
Automated testingYesYes
Expert-led testingYesYes
Business logic testingWhere required by scopeTypically included
MASA validationYesNo
Broader attack scenariosLimited to assessment scopeYes

If you require MASA AL2 validation, purchase the MASA AL2 assessment. If you need broader security assurance, consider a Mobile Application Penetration Test in addition.

Questions

Frequently asked questions