VERAFIED Methodology
VERAFIED is the industry’s first standards-based mark of security quality for both internally developed and third-party software applications. By leveraging industry standards, Veracode provides a pragmatic and repeatable method for organizations developing or procuring software to measure, compare and reduce risks related to application security.
Veracode uses static binary analysis, dynamic analysis and/or manual penetration testing to identify security flaws in software applications. The basis for the VERAFIED security mark is the Security Quality Score (SQS) which aggregates the severities of all security flaws found during the assessment and normalizes the results to a scale of 0 to 100. Applications found to have no “very high”, “high” or “medium” severity vulnerabilities, nor any OWASP Top 10 or CWE/SANS Top 25 vulnerabilities that could be discovered using Veracode’s automated analysis may earn the VERAFIED mark. For applications of the highest criticality the VERAFIED HIGH ASSURANCE marks for CWE/SANS 25 or for OWASP Top 10 indicate the software has been found to have no “very high”, “high”, or “medium” severity vulnerabilities, nor any CWE/SANS TOP 25 or OWASP TOP 10 vulnerabilities that could be discovered using Veracode’s automated static binary analysis, automated dynamic web application analysis (if applicable) and additional manual application penetration testing to identify flaws in business logic and design.
Standards-based Ratings
The VERAFIED assessment is based on respected industry standards including MITRE’s Common Weakness Enumeration (CWE) for classification of software weaknesses and FIRST’s Common Vulnerability Scoring System (CVSS) for severity and ease of exploitability and NIST's definitions of assurance levels. Veracode is the only organization to combine these standards into a meaningful and practical way to assess software security across internally developed and externally purchased applications.
Learn more about how Veracode is leveraging CWE, CVSS and NIST to provide a trusted security rating for organizations developing and buying software.
Veracode Security Solutions
Website Security
Application Analysis
Dynamic Analysis
Internet Security
Malicious Code
Security Threat Guides


