---
source_url: "https://www.gsa.gov/technology/it-contract-vehicles-and-purchasing-programs/it-security/application-security-testing?utm_source=openai"
title: "Application Security Testing | GSA"
mirrored_at: 2026-08-05T01:02:24.664Z
host: www.gsa.gov
cited_in_42a: true
mirror_canonical: "https://index.42a.ai/www.gsa.gov/technology/it-contract-vehicles-and-purchasing-programs/it-security/application-security-testing__q__utm_source_openai"
---

> **Original source:** https://www.gsa.gov/technology/it-contract-vehicles-and-purchasing-programs/it-security/application-security-testing?utm_source=openai

## Support your agency’s AST program

**Application Security Testing**, or **AST**, is testing, analyzing, and reporting the security level of an application as it moves from early development stages through deployment and maintenance.

An **effective AST program** incorporates products, services, and solutions that continuously assess and address application vulnerabilities through the entire software development life cycle. An AST program should:

-   Reduce the number of vulnerabilities in released applications.
-   Mitigate the potential impact of the exploitation of undetected or unevaluated vulnerabilities.
-   Identify and address the root causes of vulnerabilities to prevent future recurrences.
-   Provide greater insight into the agency’s application security posture.

Successful AST programs go beyond automation — agencies also need to hire cybersecurity experts to manually analyze how government applications work and how they can be exploited. Each agency may have a different approach to their AST program, and GSA’s contract options offer a variety of sophisticated tools that statically and dynamically analyze applications for detectable weaknesses.

## Buy AST solutions

Agencies can buy AST products and services through our technology contracts and purchasing programs:

-   [Multiple Award Schedule - Information Technology](https://www.gsa.gov/node/84639)
    -   [Highly Adaptive Cybersecurity Services](https://www.gsa.gov/node/86906)
    -   [Wireless Mobility Solutions](https://www.gsa.gov/node/84432)
-   [Governmentwide Acquisition Contracts](https://www.gsa.gov/node/87591)
-   [Enterprise Infrastructure Solutions](https://www.gsa.gov/node/87099)

Our [Application Security Testing buyer’s guide](https://buy.gsa.gov/docviewer?id=56497&docTitle=Application%20Security%20Testing%20Buyer%27s%20Guide%20\(GSA%202025\)&category=Information%20Technology,IT%20Services&docType=Buyer%27s%20Guide) provides key considerations when implementing an AST program. It also helps agencies identify and procure AST offerings to improve their application security posture.

To make your acquisition experience easier and more efficient, our [AST Statement of Work template \[PDF\]](https://buy.gsa.gov/docviewer?id=56498&docTitle=Template%20for%20Application%20Security%20Testing%20Statement%20of%20Work%20\(GSA%202023\)&category=Information%20Technology,IT%20Services&docType=Statement%20of%20Work%20\(SOW\)) provides typical language for a cybersecurity solicitation and examples of specific activities and deliverables associated with AST services.

## Resources

-   [“Improving the Nation’s Cybersecurity” \[PDF\]](https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity) directs Federal agencies to advance security measures that drastically reduce the risk of successful cyber attacks against the Federal government’s digital infrastructure.
-   “[Moving the U.S. Government Toward Zero Trust Cybersecurity Principles \[PDF\]](https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf)” — Office of Management and Budget Memo M-22-09 provides agencies further guidance to improve their application security. Specifically, it charges agencies to operate dedicated AST programs and utilize high-quality firms specializing in application security for independent third-party evaluation.
-   “[Recommendations for Mitigating the Risk of Software Vulnerabilities](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-218.pdf)”> — National Institute of Standards and Technology Special Publication 800-218 provides a core set of high-level secure software development practices that can be integrated into each SDLC implementation.
-   “[Guidelines on Minimum Standards for Developer Verification of Software](https://nvlpubs.nist.gov/nistpubs/ir/2021/NIST.IR.8397.pdf)” — NIST Internal Report 8397 describes recommendations for software verification techniques and additional information about the techniques with references for further information.
-   “[Technical Guide to Information Security Testing and Assessment](https://csrc.nist.gov/publications/detail/sp/800-115/final) — NIST Special Publication 800-115 assists organizations in planning and conducting technical information security tests and examinations, analyzing findings, and developing mitigation strategies.
-   “[Develop and Publish a Vulnerability Disclosure Policy](https://www.cisa.gov/binding-operational-directive-20-01)” — Cybersecurity and Infrastructure Security Agency Binding Operational Directive 20-01 directs agencies to publish the status of vulnerabilities listed in a Vulnerability Disclosure Policy. CISA BOD 22-01, “Reducing the Significant Risk of Known Exploited Vulnerabilities” requires agencies to identify and address known exploited vulnerabilities within a defined timeframe.