What are the requirements to be Verified
The Veracode Verified program has three (3) levels which customers can strive for their applications to attain, each demonstrating a different level of risk addressed in the application security program.
Verified Requirements by level:
Verified Standard:
- Assess first party code using static analysis
- documents that don't allow Very High flaws in first-party code
- establish a scanning cadence of at least every six (6) months
- provides developer with remediation guidance (consultation calls)
Verified Team:
- Requirements for Verified Standard, plus
- Document that an applicaiton doesn't include Very High or High flaws
- have a 60-day remediation grace period to remain in compliance
- establish a scanning cadence of at least every 90 days
- identify a security champion within the development team to serve as a peer resource to development team members, ensuring secure coding practices across the development lifecycle
- provide training on secure coding for the identified Security Champion
- assess open source components for improved security and document that they don't contain any Very High or High vulnerabilities
Verified Continuous
- Requirements for Verified Team, plus
- integrate security tools into development workflows
- complete a post-production security assessment (dynamic analysis or penetration test)
- document that your application(s) doesn't include any Very High, High, or Medium flaws
- undergo Veracode's biannual mitigation review
- have a 30-day remediation grace period to remain in compliance
- provide advanced training on secure coding for Security Champions
- establish a scanning cadence of at least every 60 days
- provide development teams with training on secure coding
- assess open source components for security, and document that open source components don't contain Very High, High, and Medium vulnerabilities
Veracode customers can submit a request to have their application(s) be recognized for Verified status through the Veracode Community, option Verified. Please be aware that the ability to see the Verified request form is limited to Veracode customers (company email addresses needed when registering/logging into the Community). If you are a Veracode customer, have logged into the Veracode Community using your company email and are still having trouble, please contact support .
Further questions about the program can be posted in the Verified Exchange group .
Further questions about the program can be posted in the Verified Exchange group .
Topics (1)
Related Articles
License Issues is green, but licenses show high license risk 1KNumber of Views SCA - Unrecognized License 664Number of Views Grace Period in New Policy 971Number of Views How to check the status of your Veracode Verified application 598Number of Views What is a scannable module? 771Number of Views
This topic isn't available in this community.
Related Topics
Ask the Community
Get answers, share a use case, discuss your favorite features, or get input from the Community.
.png)