OWASP Global AppSec USA 2026

November 2nd – November 6th, 2026
San Francisco, CA

OWASP Global AppSec USA 2026 brings the application security community to San Francisco, November 2–6. What to expect, pricing, who should attend, and where container security fits.

OWASP Global AppSec USA 2026

OWASP Global AppSec USA 2026: what to expect

OWASP’s flagship US conference is the premier gathering for application security and DevSecOps - training days plus a two-day conference of talks on secure development, supply chain security, and the tools and standards (like the OWASP Top 10) the community maintains.

Key takeaways

  • OWASP Global AppSec USA 2026 is the premier US AppSec/DevSecOps conference, in San Francisco November 2–6.
  • Passes run ~$800–$1,300; training is separate, members get discounts.
  • The audience is AppSec engineers, DevSecOps practitioners, and developers.
  • Supply chain security and SBOMs are headline themes.
  • Echo makes the container image as secure as the code - CVE-free and signed.

Dates, location, and pricing

  • Dates: November 2–6, 2026 (training days plus main conference)
  • Location: San Francisco, CA, USA
  • Pricing: Estimate - confirm on official site. Conference passes typically run ~$800–$1,300, with separate paid training, member discounts, and lower rates for early registration.

Who should attend

Application security engineers, DevSecOps practitioners, secure-development-focused developers, and security leaders responsible for the software they ship.

Themes to watch

  • Secure software development and the OWASP Top 10.
  • Software supply chain security, including SBOMs and dependencies.
  • DevSecOps tooling and automation across the pipeline.
  • AI security in application development.

Networking and after-parties

OWASP events are strongly community-driven, with project summits, chapter meetups, and evening socials that connect the global AppSec community.

Where container security fits into the conversation

AppSec has expanded well beyond source code - the container image is now part of the application’s attack surface, and OWASP’s supply chain track treats image provenance and SBOMs as first-class concerns.

Echo delivers on exactly that: CVE-free, FIPS-validated images with full SBOM transparency in SPDX and CycloneDX and signed provenance via cosign and sigstore, so the container shipping your application is as secure as the code inside it.

FAQ

When and where is OWASP Global AppSec USA 2026? It runs November 2–6, 2026 in San Francisco, California, combining training days with a two-day main conference. Organized by the OWASP Foundation, it’s the premier US gathering for the application security and DevSecOps community, covering secure development, supply chain security, and OWASP’s open standards and tools.

How much do OWASP Global AppSec tickets cost? Confirm 2026 pricing on the official site. Conference passes typically run around $800–$1,300, with hands-on training sold separately. OWASP members and early registrants receive discounts, keeping it more accessible than many commercial security conferences while still funding the foundation’s work.

Who should attend OWASP Global AppSec USA? It’s aimed at application security engineers, DevSecOps practitioners, security-minded developers, and the leaders responsible for the software their organizations ship. With strong secure-development and supply chain tracks, it’s especially valuable for teams building security into the pipeline rather than bolting it on afterward.