Do App Stores Require a Penetration Test?
Quick Answer
Mostly no. Apple's App Review does not require any independent security test to publish on the App Store. Google's Mobile Application Security Assessment (MASA) program is voluntary for almost every app — it lets a developer earn an independent-review badge, it doesn't gate publishing. The one mandatory case is narrow: VPN apps seeking Google Play's 'Verified' badge need MASA Level 2 validation plus install, review, account-type, and publication-age thresholds. Outside that, nobody is required to test a mobile client to ship it.
What Apple Actually Reviews
Apple's App Review process evaluates submissions against the App Review Guidelines — covering safety, privacy, business, design, and legal requirements, including declarations about use of encryption for export-compliance purposes. Nowhere in that process is a completed, independent penetration test or security audit a condition of approval. A well-tested app is more likely to pass review cleanly (crashes and obvious data leaks do get flagged), but "we did a pentest" is not a checkbox Apple asks for.
What MASA Is, and Who Can Perform It
The Mobile Application Security Assessment (MASA) program lets a developer have the public, published version of their app independently tested against the OWASP Mobile Application Security Verification Standard (MASVS) by a lab authorised by the App Defense Alliance. The lab submits a validation report directly to Google, and the developer can then display an independent security review badge in the app's Data Safety section on the Play Store. Users can view the badge and its details in the App Defense Alliance's public directory of validated apps.
Only App Defense Alliance-authorised labs can perform MASA. Optimum Web is not one of them, and we do not claim otherwise anywhere on this site.
The One Case Where It Is Mandatory
To display Google Play's "Verified" badge, a VPN app specifically must meet all five of the following conditions, and the MASA validation must be renewed annually to keep the badge:
| Requirement | Threshold |
|---|---|
| MASA validation level | Level 2 (of the MASVS-based tiers) |
| Installs | 10,000 or more |
| Reviews | 250 or more |
| Developer account type | Organization, not individual |
| Time since publication | 90 days or more, with annual re-validation to keep the badge |
Source: App Defense Alliance MASA documentation and Google Play Data Safety help center. These thresholds are set by Google and have changed before — verify against current guidance if this decision affects a launch date.
Who Actually Asks You to Test a Mobile App
Almost never the store itself. The real triggers are usually a corporate customer's vendor security questionnaire, a cyber insurer's renewal application, a regulator in a specific sector, or an investor's technical due diligence ahead of a funding round. If one of these has specifically named "mobile application penetration test" as a requirement, that's the conversation worth having with us directly — not the app stores themselves.
Where the Vulnerabilities Usually Are
A mobile app is rarely a standalone risk — it's a client talking to a backend and an API, and that server-side surface is where broken authentication, broken object-level authorization (BOLA/IDOR), and business-logic abuse most commonly show up. This is the part of a mobile product we test today.
Standard Web App + API Penetration Test — full REST/GraphQL coverage, business-logic testing, one free retest.
Price the Backend & API — from €4,500What We Do and Do Not Offer
We do offer
- Penetration testing of the backend and API behind a mobile app (SEC-PENT-03 / SEC-PENT-04)
- An honest scoping conversation about whether your specific mobile requirement is something we should handle, or refer elsewhere
We do not offer
- A dedicated mobile application (iOS/Android client) penetration testing tier — not published in our catalog this year
- Google Play MASA validation — only App Defense Alliance-authorised labs can issue this
- Any claim of partnership with, or authorisation from, the App Defense Alliance
Frequently Asked Questions
Does Apple require a penetration test?+
Does Google require one?+
What is MASA and who performs it?+
Can Optimum issue MASA validation?+
My app is not a VPN — do I need any of this?+
Do you test mobile apps?+
What about the backend and the API?+
Have a Mobile Requirement? Let's Talk First
We'll tell you plainly whether we're the right fit — at no cost either way.
