For MASA AL2, the lab will test the public version of the app (available in the Play Store) and provide assessment feedback directly to developers, including remediation steps for any flagged issues. Once the app meets all requirements, the lab will send a Validation Report directly to Google, confirming eligibility for the security badge on the developer's data safety form. The process typically takes 2-3 weeks from initial assessment to badge availability.
Process:
Initiation
Contact an Authorized Lab to initiate the assessment process. Work directly with the lab to finalize funding arrangements and complete any necessary paperwork. The lab will then allocate resources for the assessment.
Evaluation
An ADA Authorized Lab conducts a human analysis using specialized tools to identify security vulnerabilities. The lab may request clarification from the developer regarding app functionality. Upon completion of the evaluation on of these scenarios is possible:
- No issues found: The developer can move on to the completion step.
- Remediation: If any issues are found, the lab will provide a test report directly to the developer with remediation suggestions. The developer has 60 days from the date of the test report to address any identified issues.
Completion
The lab issues a validation report to Google confirming that the app meets the security requirements. The developer can showcase this achievement in the Google Play Store by answering "Yes" to the question "Has your app (or library/SDK) been independently validated against an external global security standard?" in the Console Data Safety Section. This will enable the Independent Security Review badge in the Data Safety section.The application is listed in the ADA Directory.
-
Note: Developers within Google, to enable the badge go to the Data Collection and Security section of their assessment, answer 'Yes' to the "Has your app (or library/SDK) been independently validated against an external global security standard?" question, review and update the label, send for review, and after approval, export and confirm for publishing.
Click here to learn more about MASA and see answers to common questions.