🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Mobile Apps & App Stores

Do App Stores Require a Penetration Test?

Quick Answer

Mostly no. Apple's App Review does not require any independent security test to publish on the App Store. Google's Mobile Application Security Assessment (MASA) program is voluntary for almost every app — it lets a developer earn an independent-review badge, it doesn't gate publishing. The one mandatory case is narrow: VPN apps seeking Google Play's 'Verified' badge need MASA Level 2 validation plus install, review, account-type, and publication-age thresholds. Outside that, nobody is required to test a mobile client to ship it.

What Apple Actually Reviews

Apple's App Review process evaluates submissions against the App Review Guidelines — covering safety, privacy, business, design, and legal requirements, including declarations about use of encryption for export-compliance purposes. Nowhere in that process is a completed, independent penetration test or security audit a condition of approval. A well-tested app is more likely to pass review cleanly (crashes and obvious data leaks do get flagged), but "we did a pentest" is not a checkbox Apple asks for.

What MASA Is, and Who Can Perform It

The Mobile Application Security Assessment (MASA) program lets a developer have the public, published version of their app independently tested against the OWASP Mobile Application Security Verification Standard (MASVS) by a lab authorised by the App Defense Alliance. The lab submits a validation report directly to Google, and the developer can then display an independent security review badge in the app's Data Safety section on the Play Store. Users can view the badge and its details in the App Defense Alliance's public directory of validated apps.

Only App Defense Alliance-authorised labs can perform MASA. Optimum Web is not one of them, and we do not claim otherwise anywhere on this site.

The One Case Where It Is Mandatory

To display Google Play's "Verified" badge, a VPN app specifically must meet all five of the following conditions, and the MASA validation must be renewed annually to keep the badge:

RequirementThreshold
MASA validation levelLevel 2 (of the MASVS-based tiers)
Installs10,000 or more
Reviews250 or more
Developer account typeOrganization, not individual
Time since publication90 days or more, with annual re-validation to keep the badge

Source: App Defense Alliance MASA documentation and Google Play Data Safety help center. These thresholds are set by Google and have changed before — verify against current guidance if this decision affects a launch date.

Who Actually Asks You to Test a Mobile App

Almost never the store itself. The real triggers are usually a corporate customer's vendor security questionnaire, a cyber insurer's renewal application, a regulator in a specific sector, or an investor's technical due diligence ahead of a funding round. If one of these has specifically named "mobile application penetration test" as a requirement, that's the conversation worth having with us directly — not the app stores themselves.

Where the Vulnerabilities Usually Are

A mobile app is rarely a standalone risk — it's a client talking to a backend and an API, and that server-side surface is where broken authentication, broken object-level authorization (BOLA/IDOR), and business-logic abuse most commonly show up. This is the part of a mobile product we test today.

Standard Web App + API Penetration Test — full REST/GraphQL coverage, business-logic testing, one free retest.

Price the Backend & API — from €4,500

What We Do and Do Not Offer

We do offer

  • Penetration testing of the backend and API behind a mobile app (SEC-PENT-03 / SEC-PENT-04)
  • An honest scoping conversation about whether your specific mobile requirement is something we should handle, or refer elsewhere

We do not offer

  • A dedicated mobile application (iOS/Android client) penetration testing tier — not published in our catalog this year
  • Google Play MASA validation — only App Defense Alliance-authorised labs can issue this
  • Any claim of partnership with, or authorisation from, the App Defense Alliance

Frequently Asked Questions

Does Apple require a penetration test?+
No. Apple's App Review process checks the app against the App Review Guidelines — covering privacy, content, and export-compliance declarations for cryptography use — but there is no requirement to complete an independent security test or penetration test as a condition of publishing on the App Store.
Does Google require one?+
Not as a general rule. Google operates the Mobile Application Security Assessment (MASA) program, which lets a developer have their app independently validated against the OWASP MASVS standard by an authorised lab, and then display an independent-review badge in the Play Store's Data Safety section. Participation is voluntary for the overwhelming majority of apps.
What is MASA and who performs it?+
MASA is Google Play's Mobile Application Security Assessment program. An authorised lab (a member of the App Defense Alliance) tests the public version of the app from the Play Store against OWASP MASVS, then submits a validation report directly to Google. Only labs authorised by the App Defense Alliance can perform this — it is not something any security firm can self-declare.
Can Optimum issue MASA validation?+
No. We are not an App Defense Alliance-authorised lab, and we do not claim to be. If your organisation specifically needs MASA validation for the Play Store badge, you need an authorised lab — we can tell you plainly that this isn't us rather than imply otherwise.
My app is not a VPN — do I need any of this?+
Almost certainly not as a store requirement. The mandatory case is narrow: it applies specifically to VPN apps seeking the Play Store "Verified" badge, which requires MASA Level 2, 10,000+ installs, 250+ reviews, an organization-type developer account, and 90+ days since publication, re-validated annually. Outside that specific badge, MASA participation is voluntary.
Do you test mobile apps?+
Not the mobile client (the iOS or Android app itself) — we don't currently offer a dedicated mobile application penetration testing tier. What we do test today is the backend and API behind the app, which is where most real vulnerabilities in mobile products tend to concentrate anyway. If a customer questionnaire, insurer, or regulator specifically requires testing of the mobile client itself, contact us and we'll tell you plainly whether we're the right fit or should point you elsewhere — at no cost.
What about the backend and the API?+
Yes, and this is usually the more consequential half of the attack surface. Our Standard Web App + API Penetration Test (SEC-PENT-03) covers the REST/GraphQL API surface, business logic, and cross-tenant isolation issues that a mobile app's backend typically exposes — authentication flaws, broken object-level authorization, and business-logic abuse most often live here, not in the client binary.

Have a Mobile Requirement? Let's Talk First

We'll tell you plainly whether we're the right fit — at no cost either way.