HomeFrameworksAI Governance & Privacy FrameworksOWASP LLM Top 10

Framework  AI Governance & Privacy Frameworks

OWASP LLM Top 10

The OWASP Top 10 for Large Language Model Applications is a community-maintained awareness list of the most serious security risks in applications built on LLMs. The project began in 2023 and now sits under the OWASP GenAI Security Project.

The 2025 edition, released in late 2024, leads with prompt injection and sensitive information disclosure and adds entries for system prompt leakage and vector and embedding weaknesses, alongside supply chain, data and model poisoning, improper output handling, excessive agency, misinformation, and unbounded consumption.

A 2026 edition has been published by the project (verify the current list on genai.owasp.org). Coalfire's page cites an older version label (v1.1).

It is not a compliance standard and has no assessor. Organizations use it as a threat checklist for secure design reviews, penetration test scopes, and vendor questionnaires.

What it tends to produce in writing is an AI application threat model, secure development requirements for LLM features, output handling and tool-permission policies, and test reports showing each category was probed.

AI-compiled
Share
Sponsored
OWASP
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with OWASP LLM Top 10
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Voluntary. Developers, security teams, and buyers of LLM-based applications. Some customer security questionnaires and internal secure development policies reference it by name.

What the assessor asks to see

Where a customer asks for coverage: architecture and data flow of the LLM application; threat model referencing the ten categories; input and output handling controls; tool and agent permission design; supply chain records for models, plugins, and datasets; retrieval and vector store access controls; rate limiting and cost controls; penetration test or red team report mapped to the list; remediation tracking.

Assessors

Who assesses OWASP LLM Top 10

None. No certification. Penetration testers and red teams use it as a scope, but any firm may do so and no body qualifies them for this list specifically.

No firm has claimed a OWASP LLM Top 10 assessor listing yet. Claim yours →

Consultants

Who helps with OWASP LLM Top 10

Application security consultancies and AI red-teaming firms offer assessments mapped to the list. Engagements are usually a threat modeling workshop plus a penetration test of the LLM features, lasting days to a few weeks.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

SecurafyUSANot yet verified
What they do
MSP / vCISO
Who they help
Securafy is an MSP / vCISO based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
CISOSHAREUSANot yet verified
What they do
VCISO
Who they help
CISOSHARE is a vCISO based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Software

Tools for OWASP LLM Top 10

Tools that name this framework in their own material.

No firm has claimed a OWASP LLM Top 10 tool listing yet. Claim yours →

Related reading

  1. Mapping to the OWASP Top 10 for LLM applicationsMaps each listed risk to concrete architectural controls, which is the step most summaries of the list skip.Amazon Web Services
  2. The OWASP Top 10 for LLMs: CSA's defense playbookWalks the ten risks and the defences for each, with the reasoning behind prioritising prompt injection first.Cloud Security Alliance
  3. OWASP's 2026 LLM Top 10 and new agent control standardCovers what changed in the newest edition and how the agent control standard sits beside the list.Cloud Security Alliance

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for OWASP LLM Top 10

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with OWASP LLM Top 10

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.