How to Choose an ADA Authorised Laboratory background
Back to Journal
Compliance

How to Choose an ADA Authorised Laboratory

Adayptus Consulting
September 12, 2026
15 min read

The questions to ask a prospective App Defense Alliance laboratory, the answers that should reassure you, the answers that should make you walk away, and how to compare quotes that differ threefold on scope alone.

App Defense Alliance

The questions to ask, the answers that should reassure you, and the answers that should make you walk away.

In short. Check three things before anything else: that the lab is on ADA's published list, that it is authorised for your specific assessment type, and that no part of its fee depends on your verdict. If any of those fails, stop.

What is this decision about?

You are not buying a test. You are buying a report that somebody else will rely on, so what you are really buying is credibility. That means the cheapest quote is frequently not the best purchase, and the most expensive is not automatically the safest either.

ADA does not test apps itself. It publishes the requirements, then authorises independent laboratories to do the testing. A lab has to earn that authorisation, and part of earning it is holding accreditation to ISO/IEC 17025, the international standard for testing laboratories. The point of the arrangement is that the people judging your app have no commercial interest in the answer.

The three checks that come first

Step 1 — Confirm the lab is actually authorised

ADA publishes the list of authorised laboratories. Check the name on the list yourself rather than trusting a logo on a website or a claim in a proposal. This takes two minutes and it is the single most important check you will make.

Step 2 — Confirm it is authorised for your assessment type

Authorisation is per assessment type. A lab authorised for MASA is not automatically authorised for CASA or DASA. Ask directly, and verify against the list.

Step 3 — Confirm no fee depends on the outcome

Get it in writing. A fee contingent on a Pass destroys the independence that makes the report worth having, and an authorised lab is prohibited from offering it. If it is offered, that tells you something about the whole operation.

Where to check. The App Defense Alliance keeps its certification and laboratory information on its own site, at appdefensealliance.org/certification/certify-your-app. The authorisation document that used to sit in the requirements repository now points there, so treat the website as the current source and the repository as the place the requirements themselves live.

The questions worth asking, and the answers you want

Ask thisA good answer sounds like
Who will be my Quality Control Reviewer, and how are they independent of the testing team?A named role, someone who takes no part in the testing, with authority to withhold the report. If they cannot answer, they may not have an independent reviewer, which means they cannot properly release your report.
Which certifications does the team hold for my assessment type, and are they current?Specific certifications from the ADA list, with current expiry dates, and at least two qualified people so tester and reviewer can differ.
Can I see your conflict of interest clearance for my engagement?Yes, and it exists as a record made before acceptance. Hesitation here is meaningful.
What is your dispute process?A written process, decided by somebody independent of the engagement, with the programme notified on resolution.
How many retests are included, and how long do I have to use them?A specific number and a specific deadline. Vagueness here becomes an invoice later.
What exactly will be published, and what consent do you need from me?A clear statement, and a consent form you sign. Nothing about your app should be published without it.
What do you destroy at the end, and what do you keep?Build artefacts and credentials destroyed; evidence and report retained for a stated period. They should know the period without looking it up.
Which assurance levels do you offer for my profile, and which do I actually need?A clear answer that distinguishes AL1 from AL2, and an honest view of which applies to you. A lab that steers you to the most expensive level without explaining why is worth questioning.
Have you done my assessment type for a product like mine?Concrete relevant experience, described without naming other clients. A lab that names its other clients to you will name you to somebody else.
What happens if you find something critical mid-test?They tell you immediately rather than saving it for the report.
Will you tell me if you think I am not ready?Yes. A lab willing to say your app will fail, before taking the money, is worth more than one that is not.

Answers that should make you walk away

  • "We can guarantee you will pass." Nobody can. A guarantee means either they intend to pass you regardless of what they find, or they are lying to win the work. Both are disqualifying.
  • "Our fee is lower if you pass first time." A prohibited fee structure. It means the lab has a financial interest in your verdict.
  • "We can fix the problems and then certify you." Not permitted. A lab that advised on or remediated your application cannot validate it, because it would be reviewing its own work. Advice yes, hands on your code then a certificate, no.
  • "We can make the failed attempt go away." Records are retained. Offering to erase history is offering to falsify records, which should end the conversation.
  • "You do not need to worry about the details." You do. A lab unwilling to explain its process is either disorganised or hiding something.
  • Reluctance to put scope in writing. Scope disputes are the commonest source of engagement conflict. A lab that resists writing it down is protecting itself at your expense.
  • Naming other clients unprompted. If they breach somebody else's confidence to impress you, yours is worth no more to them.

How to compare quotes properly

Quotes for the same assessment can differ by a factor of three, and often the difference is not quality but scope. Normalise them before comparing:

CheckWhy it changes the real price
Number of retests includedThe commonest hidden difference. A cheap quote with one retest can cost more than an expensive one with three.
Deadline for using retestsRetests you cannot use in time are not included in any meaningful sense.
Requirements in scopeOne lab may have scoped fewer requirements. Compare the scope statements, not the totals.
Platforms or environments includedParticularly for desktop and mobile, each additional platform is real work.
Whether report review is includedIt must be, but confirm it is not an add-on line.
Whether a readiness or pre-assessment is bundledIf it is, note that this may make that lab ineligible to perform your formal validation.
Turnaround commitmentA cheaper quote with a twelve-week turnaround may miss your deadline entirely.
What happens if scope changes mid-engagementAsk how change is priced before you need to know.

Who is required to use an authorised lab?

Anybody who wants a result that counts. For the formal validation there is no alternative: an assessment by a non-authorised firm, however competent, does not produce an ADA validation. It may still be useful work, but it will not satisfy a platform gate or a customer asking for ADA validation specifically.

You may use anybody you like for readiness work, internal testing and remediation. Just be clear which you are buying, and be aware that a firm doing your readiness work usually becomes ineligible to do your formal validation. If you have not started that work yet, the four-week preparation plan covers what to do before anyone bills you at lab rates.

Which assessment you need comes first, and that depends on what you build. We have separate walkthroughs of CASA for web applications and APIs, DASA for desktop and server software, and the Cloud App and Config Profile for the infrastructure underneath. Products with both a client and a back end usually need more than one.

Frequently Asked Questions

Click any question to expand the answer.

QIs using an authorised lab required?

For the formal validation, yes, absolutely. There is no route to an ADA validation through an unauthorised firm.

QHow does choosing well help us?

A well-run lab finds more, explains it better, and produces a report your customers accept without argument. A badly-run one produces a thin report that gets questioned, and in the worst case one whose findings you cannot rely on.

QDo we have to use the same lab every year?

No. You can change at renewal and some companies do, to get a fresh perspective. The cost is that a new lab needs to understand your product again, so there is a real efficiency in staying.

QShould we use the cheapest?

Only after normalising the quotes using the table above. Once scope and retests genuinely match, price is a reasonable tiebreaker.

QCan a lab refuse to work with us?

Yes, and sometimes it must. If it has a conflict, lacks people qualified for your assessment type, or has no independent reviewer available, it is required to decline. A lab that declines for one of those reasons is behaving correctly.

QHow do we know the lab's accreditation is current?

Ask for the accreditation certificate and the scope of accreditation, then verify it on the accreditation body's own website. Accreditation can be suspended, and a certificate is a snapshot.

QDoes location matter?

Less than it used to, since most of this work is remote. It matters for time zones during an active engagement, and it can matter for data residency if your data cannot leave a jurisdiction. Ask where your data will be stored.

QWhat if we have a bad experience?

Use the lab's complaint process, which it is required to have and to make available on request. If that fails, the accreditation body takes complaints about accredited laboratories, and so does ADA about its authorised labs.

QWho actually sees the result?

That depends on the programme. Some results appear as a badge or a note on an app store listing that your users can see. Others are shared with the platform that asked you to get assessed, and are not public. Ask the lab what will be published before you start, and get it in writing. A good lab will not publish anything about your app without your written consent.

QWhat if we disagree with a finding?

You can dispute it. An authorised lab has to have a documented dispute process, and the person who decides your dispute must not be the person who made the finding. If the verdict changes, the lab has to update the report with ADA. Ask to see the dispute process before you engage a lab.

QDoes a pass mean our app is secure?

No, and be careful of anyone who tells you it does. A pass means your app met the requirements that were tested, in the version that was tested, on the date it was tested. It is not a guarantee. It is a meaningful, independently checked baseline, which is a different and more honest thing.

QCan we use our own internal security team instead?

Not for the formal validation. The whole value of these programmes is that the tester is independent of the developer. Your internal team is exactly the right people to do the preparation work and the fixing, but the validation itself has to come from an authorised lab.

QCan the lab help us fix the problems it found?

It can tell you what to change, and it should: specific remediation guidance for each failed requirement is a programme requirement, not a favour. What it must not do is implement the fix for you, because then it would be validating its own work. Advice yes, hands on your codebase no.

About Adayptus

Adayptus Consulting Private Limited is an application security testing firm based in Noida, India. We have been doing web, mobile and cloud security testing since 2018.

We are currently building our laboratory management system to ISO/IEC 17025:2017 and working towards authorisation as an App Defense Alliance Security Test Laboratory. We are not an ADA-authorised laboratory today. We will say so plainly on this page until that changes, because you should be able to trust what a security firm tells you about itself.

That is worth stating plainly on this page in particular. An article telling you to verify a lab's authorisation would be a poor place for us to blur our own status.

What we can do for you right now:

  • Readiness testing. We test your app against the relevant requirement set and tell you what would fail, before you pay for a formal validation. Finding out early is much cheaper than failing late. Depending on the profile that is web application, API or cloud configuration work aimed at a published bar.
  • Fixing what we find. We give you guidance specific to your application, pointing at the actual component and the actual change needed, not a link to a general guideline.
  • Evidence preparation. We help you assemble the documentation, architecture information and test accounts an authorised lab will ask for, so your validation does not stall on paperwork.

Please note. One thing we will tell you up front: if we do your readiness work, we cannot later be the lab that performs your formal ADA validation. Our impartiality rules stop us from validating an application we have already advised on. We would rather you knew that at the beginning than after you had paid us. If your priority is the formal validation, we will point you at an authorised lab and stay out of the way.

Attribution and source

Requirement identifiers, domain names and profile names in this article are drawn from material published by the App Defense Alliance in the ASA-WG repository at github.com/appdefensealliance/ASA-WG, licensed under Creative Commons Attribution-ShareAlike 4.0 International. The explanations and remediation advice are our own.

Programme requirements are versioned and they change. Before you rely on any specific detail in this article, check the current published requirements in the App Defense Alliance repository and its releases page, and the certification information on the App Defense Alliance website. Where this article describes how a process generally works, that shape is stable. Where it would matter to you whether a number or a version is exactly right, confirm it at the source.


Share this Insight
CybersecurityComplianceAdayptus Intelligence
A

Adayptus Consulting

Application Security Testing, Adayptus

Adayptus Consulting Private Limited is an application security testing firm based in Noida, India, working across web, mobile and cloud security testing since 2018. The firm is building its laboratory management system to ISO/IEC 17025:2017 and working towards authorisation as an App Defense Alliance Security Test Laboratory; it is not an ADA-authorised laboratory today.

Compliance

Know the Answer Before the Lab Does

We are not an ADA-authorised laboratory, and we will tell you that first. What we can do is test your app against the published requirement set so you walk into a formal validation knowing what it will find. Send us your scope and we will come back with timeline and an indicative quote.

  • Readiness testing against the published ADA requirement sets
  • Every delivered finding reproduced by hand — zero false positives
  • Evidence and documentation prepared for the lab
  • If you need the formal validation, we point you at an authorised lab
Direct Scoping Hotline: +91-9625999069 [email protected]

Request a scoping call

No obligation. A senior consultant replies — not a sales sequence.

Your details stay confidential. Covered by NDA — a senior consultant replies directly.

Zero False Positives Free Retest Included 100% NDA Protected