Standards · Knowledge base

Mobile Security Standards & Frameworks

Plain-English explainers of the standards that define mobile app security, from OWASP MASVS to PCI DSS and GDPR, and how Mobexa maps findings to each one. Written and maintained by the Mobexa research team.

Every Mobexa finding maps to a recognised control. These explainers describe the standards behind those mappings. Select any one for the full write-up.

StandardType
OWASP MASVS

The OWASP standard that defines what a secure mobile app should do, grouped into control areas.

Mobile standard
OWASP MASTG

The OWASP guide that explains how to test each MASVS requirement on a real app.

Mobile standard
OWASP Mobile Top 10

The ten most common mobile app security risk categories, used as a checklist.

Mobile standard
PCI DSS (mobile)

The payment-card security standard, applied to apps that handle card or payment data.

Regulation
GDPR (mobile)

The EU data-protection regulation, applied to apps that handle personal data.

Regulation
ISO 27001 (mobile)

The information-security management standard, and where mobile app testing fits.

Framework
NIST SSDF

The NIST framework of practices for building software securely.

Framework
HIPAA (mobile)

The US health-data rule, applied to apps that handle protected health information.

Regulation
KVKK (mobile)

Turkey data-protection law, applied to apps that handle personal data.

Regulation
DORA (mobile)

The EU operational-resilience regulation for financial firms, and where mobile testing fits.

Regulation
SOC 2

The trust-services criteria used to show a service handles data securely.

Framework
NIST 800-163 (App Vetting)

NIST guidance for vetting a mobile app before it is approved for use.

Framework
CCPA (mobile)

California privacy law, applied to apps that handle personal information.

Regulation
PSD2 (mobile)

EU payment rules, including strong customer authentication, applied to banking apps.

Regulation
OWASP ASVS

The general application security verification standard, alongside the mobile MASVS.

Framework
App Store & Play requirements

The security and privacy rules the app stores enforce, including data safety and privacy labels.

Store requirement
ISO 27034

The standard for building security into the application lifecycle.

Framework

New to the terms? Start with the glossary. See how mapping works in framework coverage.