GitHub

Secure Pipeline Verification Standard - Interactive Reference

The OWASP Secure Pipeline Verification Standard (SPVS) (v1.0) is a framework of security requirements and controls that help teams design, build, and operate secure CI/CD pipelines. It provides a basis for verifying pipeline security controls and gives DevSecOps teams a list of requirements for secure delivery.

Level 1 — Foundational

Essential baseline controls for organizations beginning their pipeline security journey.

Use for: Startups, small teams, initial DevOps implementations, internal tools

Level 2 — Standard

Comprehensive security practices for mature development environments handling sensitive data.

Use for: Enterprise applications, SaaS platforms, apps handling PII/PHI, regulated industries

Level 3 — Advanced

Maximum security posture for critical infrastructure and high-risk systems.

Use for: Financial systems, healthcare platforms, government, critical infrastructure
Showing: 0 of 0
1 0
2 0
3 0
0 Completed
0% complete
ID Chapter Section Description Level References
Loading data...