WASA — Web Application Security Assessment
Procurement-grade Web Application Security Assessment — design integrity, not just exploit-finding.
WASA is a structured, framework-mapped evaluation of how a web application withstands real-world attack behavior across architecture, business logic, APIs, session handling and authentication. In India's digital-health ecosystem, a WASA report from a CERT-In empanelled auditor is the security evidence ABDM (Ayushman Bharat Digital Mission) integrators submit to the National Health Authority on the way to milestone certification and production access — the artefact often called a web application security audit or 'safe to host' certificate. Macksofy is CERT-In empanelled, and delivers WASA reports that drop directly into ABDM submissions, enterprise procurement, RBI / SEBI / DPDP filings, and SOC 2 / ISO 27001 evidence packs — without the rework most pentest PDFs trigger.
- OWASP Top 10 (2021) + API Security Top 10 (2023)
- OWASP ASVS V4.0 (Application Security Verification Standard)
- SANS CWE Top 25
- NIST SP 800-53 (IA-5, SC-7) + NIST SP 800-115 v2 testing methodology
- ISO/IEC 27001:2022 Annex A.5, A.8 + ISO/IEC 27002:2022
- PCI DSS v4.0 (clauses 6.x + 8.2.6 session controls)
- OWASP Top 10 for LLM Applications (2025) — for AI surfaces in scope
- CERT-In empanelled submission format (for Indian regulator inputs)
- ABDM / NHA ecosystem security expectations — ABHA, HIP / HIU and consent-manager flows across the M1 / M2 / M3 API surface
- RBI Master Direction on IT Governance (Nov 2023) Annex-1 (for BFSI scopes)
What is a WASA (Web Application Security Assessment)?
A WASA (Web Application Security Assessment) is a structured security test of a web application against the OWASP Top 10 and ASVS, combining automated scanning with manual, expert-led exploitation. In India's ABDM digital-health ecosystem, a WASA report from a CERT-In empanelled auditor such as Macksofy is the evidence integrators file with the National Health Authority for M1/M2/M3 milestone sign-off.
WASA Audit is leverage, not paperwork.
A modern enterprise buyer (and an increasing share of Indian BFSI auditors) doesn't want a raw pentest PDF. They want a Web Application Security Assessment that proves design integrity, maps every finding to a recognised control framework (OWASP Top 10, ASVS V4.0, SANS CWE Top 25, ISO 27001 Annex A, PCI DSS), and surfaces compound risk — the chained low-severity flaws that combine into account takeover, lateral movement or tenant-bleed. The 2025 State of Continuous Pentesting report attributes 96% of vulnerabilities in the last 12 months to web applications, and most of them are not zero-days; they are weak session controls, exposed API metadata and misconfigured headers that look minor in isolation but combine into compound exposure. Macksofy's WASA programme is purpose-built for that reality, with dual-layered AI-augmented + manual testing, threat-modelled scoping, and RFP-ready reporting that satisfies enterprise InfoSec, CERT-In format submission and the RBI Master Direction on IT Governance (November 2023) Annex-1 evidence the inspector reads. The same WASA discipline is what India's digital-health builders need for a different reason: an application that integrates with ABDM — creating or linking ABHA numbers, acting as a Health Information Provider or User, or running consent-manager flows — is expected to produce a web application security audit certificate from a CERT-In empanelled auditor before the National Health Authority grants milestone certification and production access. NHA publishes those certificates for approved integrators, and the scope they cover is WASA scope: authentication, authorisation, session handling, encryption in transit and at rest, and the security of the M1 / M2 / M3 API surface itself. Macksofy holds the CERT-In empanelment that requirement turns on, so a HealthTech team does not have to run one assessment for the regulator and a second for its enterprise customers.
- B2B SaaS shipping enterprise security questionnaires (CAIQ, SIG, Shared Assessments)
- Fintech / lending / payment-aggregator licensees needing RBI-format AppSec evidence
- ABDM / ABHA integrators needing a CERT-In empanelled audit certificate for M1 / M2 / M3 sign-off
- HMIS, EMR, PHR, HIP / HIU and consent-manager builds on the ABDM sandbox-to-production path — hospitals, diagnostics chains and telehealth platforms seeking NHA production access
- Healthtech / US-PHI GCC operators needing HIPAA Security Rule §164.308–312 evidence
- BPO / KPO + IT-services majors with customer-third-party-AppSec-standard obligations
- Public-sector and ministry-adjacent operators on the Digital India ecosystem
- AI / LLM product companies adding OWASP LLM Top 10 (2025) coverage on AI surfaces
Aligned to the regulations that matter.
How we run a WASA Audit engagement.
Interactive walkthrough — every phase clickable, every activity documented, every artefact regulator-ready.
Wk 1 · Threat-Modelled Scoping
- Architecture review and trust-boundary mapping with CTO + AppSec lead
- Authorisation matrix discovery role-by-role (tenant / role / api-key / admin)
- Sensitive-data flow inventory (PII, PHI, payment, regulated-financial-data)
- Engagement letter with production safe-harbour + rules of engagement
- 01Wk 1 · Threat-Modelled Scoping
- Architecture review and trust-boundary mapping with CTO + AppSec lead
- Authorisation matrix discovery role-by-role (tenant / role / api-key / admin)
- Sensitive-data flow inventory (PII, PHI, payment, regulated-financial-data)
- Engagement letter with production safe-harbour + rules of engagement
- 02Wk 2 · AI-Augmented Recon & DAST Baseline
- Authenticated and unauthenticated surface map (Burp Pro, Caido, Nuclei)
- Misconfiguration, exposed-endpoint, insecure-header, CORS gap discovery
- Known-CVE / dependency-vulnerability triage against the deployed stack
- Dynamic attack-surface mapping for the manual phase to chain into
- 03Wk 3 · Manual Context-Aware Testing
- Authentication & session — brute-force, MFA flow tampering, session fixation, token replay, refresh-token rotation, JWT algorithm confusion
- Access control — broken object-level access (BOLA), IDOR chaining, tenant-bleed, SCIM impersonation, role-misassignment
- API behaviour — fuzzing, parameter pollution, endpoint over-exposure, rate-limit bypass
- Business logic — order manipulation, unauthorised workflow branching, billing abuse, design-flaw exploitation
- Error & info leakage — debug-trace exposure, verbose error handling, stack metadata in UI responses
- 04Wk 4 · Chained Exploit Modelling
- Combine low-severity findings into compound exploit narratives (account takeover, privilege escalation, data leakage)
- Map each chain to MITRE ATT&CK techniques where applicable
- Validate proof-of-exploit with reproducible curl / Burp .req / Python harness
- Tie every finding to the threat-model output and the framework control it violates
- 05Wk 5 · RFP-Ready Reporting
- Executive summary in buyer-readable language (InfoSec + procurement)
- Framework crosswalk per finding (OWASP, ASVS, SANS CWE Top 25, ISO 27001 Annex A, PCI DSS)
- CERT-In empanelled format + RBI Master Direction Annex-1 mapping where Indian scope applies
- Vendor-pack annex for customer-security-questionnaire attachment (CAIQ, SIG, Shared Assessments)
- 06Wk 6 · Remediation & Validation
- 60-day re-test of every Critical and High finding at no extra cost
- Updated severity scoring with clean validation output per finding
- Engineer-readable remediation guidance with reproducible repros
- Risk-register sync to the customer's GRC tool (Archer / ServiceNow IRM / Vanta / Drata)
What your WASA Audit engagement puts on the table.
- WASA report with framework-mapped findings (OWASP Top 10, ASVS V4.0, SANS CWE Top 25, ISO 27001 Annex A, PCI DSS)
- Reproducible exploit code (curl / Burp .req / Python) per High and Critical finding
- Chained-exploit narrative with MITRE ATT&CK technique mapping
- Threat-model output document — architecture, trust boundaries, authorisation matrix
- CERT-In empanelled submission-format report for Indian regulator scope
- CERT-In empanelled web application security audit certificate for ABDM submission — the 'safe to host' artefact NHA integrators file for M1 / M2 / M3 milestone sign-off, stating the environment tested
- Vendor-pack annex for enterprise procurement (CAIQ, SIG, Shared Assessments) attachment
- 60-day re-test of every Critical and High at no extra cost
- Post-engagement risk-register sync to GRC tool (Archer / ServiceNow IRM / Vanta / Drata)
Annual WASA tied to next SOC 2 Type II audit + customer-procurement evidence pack
Outcome: 23 chained-exploit findings closed pre-disclosure; report shipped as vendor-pack annex for 18 enterprise RFPs over the next 12 months; SOC 2 Type II audit cleared with zero AppSec findings carried forward.
WASA + CERT-In submission-format report + RBI Master Direction Annex-1 crosswalk
Outcome: Three settlement-flow abuse paths closed pre-disclosure; one indirect-prompt-injection-via-RAG path on the AI customer-service assistant closed; RBI DPSS thematic review cleared with zero clarifications.
WASA + HIPAA Security Rule §164.308–312 evidence + DPDP §16 cross-border-transfer attestation
Outcome: Three SCIM impersonation paths closed; HIPAA evidence pack accepted by two US-customer compliance functions on first read; DPDP §16 attestation accepted by sponsor DPO.
The shape of a WASA Audit engagement.
Every number below is grounded in how Macksofy actually runs the engagement — not aspirational marketing copy.
What we actually examine.
Each pillar is a distinct workstream inside the engagement — scoped, evidenced, and signed off independently before the audit pack is assembled.
- Authentication & session integrity3 pts
- Access control & multi-tenant authz3 pts
- API behaviour3 pts
- Business logic3 pts
- Error & info leakage3 pts
- AI / LLM application surface3 pts
- ABDM / ABHA integration surface4 pts
Where most procurement-questionnaire callouts originate — auth flows, MFA tampering, session lifecycle.
- Brute-force resistance, MFA flow tampering, credential stuffing
- Session fixation, token replay, refresh-token rotation
- JWT algorithm confusion, audience-claim handling, PKCE enforcement
Broken Object Level Authorisation (BOLA) remains OWASP API Top 10 #1 — exercised role-by-role.
- BOLA + IDOR chaining across every role boundary
- Tenant-bleed and shared-store impersonation
- SCIM impersonation paths in enterprise-customer-driven SaaS
Modern web apps are API surfaces — fuzzing, rate-limit and endpoint over-exposure are first-class scope.
- Input fuzzing, parameter pollution, mass-assignment
- Endpoint over-exposure and shadow-API discovery
- Rate-limit bypass and abuse-case testing on partner-API trust chains
The flaws automation cannot find — design-level abuse paths tied to real business impact.
- Order / billing / workflow manipulation
- Unauthorised workflow branching and state-machine abuse
- Privilege escalation through legitimate-looking sequences
Verbose errors and stack traces hand attackers the exploit blueprint — removed at source.
- Debug / verbose error suppression at the application boundary
- Stack-metadata and tech-stack-disclosure removal
- Header hygiene (HSTS, CSP, X-Frame-Options, X-Content-Type-Options)
OWASP Top 10 for LLM Applications (2025) coverage on any AI feature in scope.
- Direct + indirect prompt-injection (via RAG corpus or upstream customer data)
- Tool-use abuse on agent reasoning
- Training-data exfiltration via inference-API probing
For digital-health builds: the M1 / M2 / M3 API surface, tested as the security evidence NHA integrators file for milestone sign-off.
- ABHA creation, login and linking flows — auth, session and token handling on the identity path
- HIP / HIU data-exchange and consent-manager workflows, including consent-artefact integrity and replay
- Health-data encryption in transit and at rest, plus access control across the care-team role boundary
- Certificate states the environment actually tested — staging versus production is called out explicitly, not blurred
From kick-off to regulator-ready report.
The horizontal flow below shows the typical week-by-week shape of a WASA Audit engagement. Click any station for detail in the methodology section above.
Empanelled by CERT-In. Accredited by EC-Council.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
WASA Audit — what compliance leads ask before signing.
RBI Cyber Security Framework Audit
End-to-end RBI CSF audit — control assessment, SAR drafting, inspector defence.
Learn moreSEBI CSCRF Audit
CSCRF audit for stock brokers, depository participants, AMCs.
Learn moreSEBI System Audit Report (SAR)
The half-yearly / annual SAR your stock broker or DP can submit on the first read.
Learn moreWASA Audit evidence starts with hands-on testing.
A clean WASA Audit report rests on real technical assurance. These Macksofy assessments generate the vulnerability, penetration and control-effectiveness evidence your auditor expects to see.
Penetration Testing
Find what attackers will. Before they do.
Explore serviceVulnerability Assessment & Penetration Testing (VAPT)
VAPT done properly — not a scan with a cover page.
Explore serviceWeb Application Security Testing
Test web apps the way attackers (and bug bounty hunters) do.
Explore serviceMacksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- Thousands of professionals trained
- India + UAE engagements
