🚀 Submit a Challenge — SecDim AppSec Village CTF at DEF CON 34 and Win a ROG Xbox Ally

Security Standards, Made Hands-On

Map your developer security training to the standards your organisation is measured against. Every SecDim challenge is a real app with a real vulnerability, so coverage means demonstrated capability, not watched videos.

Standards coverage

Choose Your Standard

Map your developer security training to the standards your auditors, customers and board actually measure you against.

2025 edition

OWASP Top 10

Cover every OWASP Top 10:2025 category with hands-on secure coding challenges. Your developers find and fix real vulnerabilities in the language they ship in, and you get evidence of capability, not just completion.

Explore the mapping →
2025 edition

OWASP LLM Top 10

Train your team against the OWASP Top 10 for LLM Applications 2025. Developers harden real AI apps against prompt injection, poisoned models and rogue MCP tools before attackers try the same in production.

Explore the mapping →
2024 edition

OWASP Mobile Top 10

Cover the OWASP Mobile Top 10 (2024) with hands-on Android and iOS challenges. Developers fix real vulnerabilities in real mobile apps and build the habits that keep your releases off the incident report.

Explore the mapping →
2023 edition

OWASP API Top 10

Map your API security training to the OWASP API Security Top 10 (2023). Developers fix BOLA, broken authentication, SSRF and more in real APIs, the same flaws behind the breaches that make headlines.

Explore the mapping →
4.0 edition

PCI-DSS

PCI-DSS v4.0 Requirement 6.2.2 requires annual, role- and language-specific secure coding training for every developer who touches cardholder data systems. Every SecDim challenge below is a real vulnerability in a real app, mapped to the vulnerability classes Requirement 6.2.4 names by name.

Explore the mapping →
Trust Services Criteria edition

SOC 2

SOC 2 auditors test CC1.4 and CC2.2: can you demonstrate that your people's security competence was developed, and communicated, not assumed? SecDim gives your engineering org dated, per-developer evidence. Every challenge is a real vulnerability, fixed and verified.

Explore the mapping →
2022 edition

ISO/IEC 27001

ISO/IEC 27001:2022 Annex A Control 8.28 requires secure coding principles to be established and applied. Certification auditors expect a named framework, training records and a falling trend in findings, not a policy document nobody follows.

Explore the mapping →
SP 800-218 edition

NIST SSDF

NIST's Secure Software Development Framework requires role-based secure coding training (PO.2) and defines exactly what "well-secured" source code, review and testing look like (PW.4–PW.9). It's the baseline behind Executive Order 14028's self-attestation for anyone selling software to the U.S. federal government.

Explore the mapping →
Don't see your standard?

We Can Map Our Content to It

If your organisation is measured against a different framework, tell us which one and we will map SecDim's challenges and courses to it for your team.