Platform
Android applications
App Defense Alliance MASA AL2
Android apps
Get your Android application independently tested and validated against MASA Assurance Level 2 requirements through a structured, lab-led security assessment — $2,999 per app, with one retest included.
The definition
Android applications
App Defense Alliance (ADA)
Higher-assurance, lab-led testing
1 included per application
Transparent pricing for individual Android applications, with custom pricing available for larger application portfolios.
$2,999per app
Custom
| Feature | 1–2 Apps | 3+ Apps |
|---|---|---|
| Best for | Developers and organizations with one or two Android apps | Organizations, developers, and publishers with larger Android portfolios |
| Platform | Android | Android |
| Retest | 1 included per app | Defined in scope |
| MASA AL2 assessment | ||
| Automated security testing | ||
| Lab-led security testing | ||
| MASA requirement validation | ||
| Evidence review | ||
| Findings report & remediation guidance | ||
| Final validation |
Each application receives its own MASA AL2 assessment and one remediation retest. Further retesting beyond the included retest can be purchased separately.
Each distinct Android application is treated as one MASA AL2 assessment. Pricing applies per Android application, not per organization or developer account. iOS applications are outside the scope of this service.
Your Android application is tested against the applicable MASA AL2 security requirements.
How the application stores, processes, and exposes sensitive information — covering applicable controls relating to sensitive information, credentials, cryptographic material, application logs, and other protected data.
Applicable cryptographic controls, including weak algorithms, insecure cryptographic implementation, and inappropriate handling of cryptographic keys.
Where applicable, authentication mechanisms, credential handling, and session-management controls.
Security of communications between the Android application and remote services, including applicable TLS and certificate-validation controls.
How the application interacts with the Android platform, including applicable permissions, exported components, external inputs, and inter-process communication.
Applicable application security configuration, release settings, debugging functionality, and security-relevant implementation characteristics.
A structured digital process from purchase to completed validation.
Need MASA AL2 for one or two Android applications? Purchase directly online for $2,999 per application. For three or more applications, request pricing.
Access Secusy and provide what the assessment needs — Google Play details, the application package or build, test credentials, functionality information, supporting evidence, testing instructions, and assessment authorization.
Our security team performs the applicable MASA AL2 testing, combining appropriate security testing techniques with analyst-led validation. Unlike AL1's streamlined approach, AL2 requires greater lab involvement in testing and validating the application's security controls.
If the application does not satisfy an applicable requirement, you receive findings explaining what needs to be addressed so your development team can remediate the issues.
Your development team fixes the identified security issues and provides the updated application or supporting evidence. Development and remediation are not included in the standard assessment.
We retest the applicable failed requirements — one remediation retest per application is included. Once the application satisfies the applicable requirements, we complete the MASA AL2 validation process.
Included
Standard assessment includes
Scope boundaries
If you need broader security assurance, consider a Mobile Application Penetration Test in addition to MASA.
Intake
To begin the assessment efficiently, be ready to provide the information and access required to test your application. Incomplete information, inaccessible application functionality, or invalid credentials may delay the assessment.
You will normally provide
Both assessment levels evaluate mobile application security, but they provide different levels of assurance. Your required assurance level should be determined by the applicable MASA requirement rather than price alone.
| Feature | MASA AL1 | MASA AL2 |
|---|---|---|
| Assessment approach | Streamlined | Higher-assurance lab assessment |
| Automated testing | Yes | Yes |
| Lab-led testing | Limited | Yes |
| Requirement validation | Lab validated | |
| Human testing effort | Lower | Higher |
| Starting price | $499/app | $2,999/app |
| Retest | 1 included | 1 included |
| Online purchase | Yes | Yes, for 1–2 apps |
Need AL1 instead? View MASA AL1.
MASA AL2 includes security testing, but it has a defined objective: assessing the application against applicable MASA security requirements. A mobile application penetration test has a broader objective of discovering exploitable vulnerabilities across the application's attack surface.
| Feature | MASA AL2 | Mobile App Pentest |
|---|---|---|
| Primary objective | MASA requirement validation | Vulnerability discovery |
| Scope | Defined MASA requirements | Broader application attack surface |
| Automated testing | Yes | Yes |
| Expert-led testing | Yes | Yes |
| Business logic testing | Where required by scope | Typically included |
| MASA validation | Yes | No |
| Broader attack scenarios | Limited to assessment scope | Yes |
If you require MASA AL2 validation, purchase the MASA AL2 assessment. If you need broader security assurance, consider a Mobile Application Penetration Test in addition.
Questions