- What they do
- MSP / vCISO
- Who they help
- Securafy is an MSP / vCISO based in USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Framework AI Governance & Privacy Frameworks
OWASP LLM Top 10
The OWASP Top 10 for Large Language Model Applications is a community-maintained awareness list of the most serious security risks in applications built on LLMs. The project began in 2023 and now sits under the OWASP GenAI Security Project.
The 2025 edition, released in late 2024, leads with prompt injection and sensitive information disclosure and adds entries for system prompt leakage and vector and embedding weaknesses, alongside supply chain, data and model poisoning, improper output handling, excessive agency, misinformation, and unbounded consumption.
A 2026 edition has been published by the project (verify the current list on genai.owasp.org). Coalfire's page cites an older version label (v1.1).
It is not a compliance standard and has no assessor. Organizations use it as a threat checklist for secure design reviews, penetration test scopes, and vendor questionnaires.
What it tends to produce in writing is an AI application threat model, secure development requirements for LLM features, output handling and tool-permission policies, and test reports showing each category was probed.
help
Who has to comply
Voluntary. Developers, security teams, and buyers of LLM-based applications. Some customer security questionnaires and internal secure development policies reference it by name.
What the assessor asks to see
Where a customer asks for coverage: architecture and data flow of the LLM application; threat model referencing the ten categories; input and output handling controls; tool and agent permission design; supply chain records for models, plugins, and datasets; retrieval and vector store access controls; rate limiting and cost controls; penetration test or red team report mapped to the list; remediation tracking.
Assessors
Who assesses OWASP LLM Top 10
None. No certification. Penetration testers and red teams use it as a scope, but any firm may do so and no body qualifies them for this list specifically.
No firm has claimed a OWASP LLM Top 10 assessor listing yet. Claim yours →
Consultants
Who helps with OWASP LLM Top 10
Application security consultancies and AI red-teaming firms offer assessments mapped to the list. Engagements are usually a threat modeling workshop plus a penetration test of the LLM features, lasting days to a few weeks.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
- What they do
- VCISO
- Who they help
- CISOSHARE is a vCISO based in USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Software
Tools for OWASP LLM Top 10
Tools that name this framework in their own material.
No firm has claimed a OWASP LLM Top 10 tool listing yet. Claim yours →
Related reading
- Mapping to the OWASP Top 10 for LLM applicationsMaps each listed risk to concrete architectural controls, which is the step most summaries of the list skip.Amazon Web Services
- The OWASP Top 10 for LLMs: CSA's defense playbookWalks the ten risks and the defences for each, with the reasoning behind prioritising prompt injection first.Cloud Security Alliance
- OWASP's 2026 LLM Top 10 and new agent control standardCovers what changed in the newest edition and how the agent control standard sits beside the list.Cloud Security Alliance
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for OWASP LLM Top 10
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with OWASP LLM Top 10
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.