OWASP Global Board Elections
A general overview of how OWASP Board elections work. For this year’s dates, vacancies, and candidates, open the current election page.
About Board elections
Since its founding in 2001, OWASP has grown from an open community and software security resource into a globally recognized, credible source for application security standards, all built by a passionate volunteer-led community that welcomes anyone to attend chapter meetings, contribute to projects, participate in conferences, or start something new.
Guiding this mission is the Global Board of Directors: seven volunteers chosen through democratic elections open to the community. Serving on the Board is an opportunity for OWASP leaders to shape the Foundation's strategic direction, champion its open and vendor-neutral values, and play a pivotal role in advancing software security worldwide.
This page is a general overview of how OWASP Board elections work. For this year's dates, vacancies, and candidates, see the current election page below. If in doubt, the OWASP Bylaws and Board Directors Policy are authoritative.
Board elections by year
The Global Board of Directors
The OWASP Foundation Board of Directors currently consists of seven elected volunteers who each serve a two-year term, with a maximum of two terms in any ten-year period. These unpaid volunteers dedicate themselves to the organizational mission, set the strategic direction of the organization, and ensure the financial integrity of the Foundation.
Board terms are staggered, so each alternating year there are either three or four vacancies to be filled at the annual election. Directors elected in a given year take office on January 1 of the following year.
Detailed information on meeting requirements, roles and responsibilities, term limits, and elections is found in the OWASP Foundation Bylaws and the Board Directors Policy. The Board of Directors Code of Conduct and details of the orientation and onboarding process are found on our Governance page.
Please reach out to our current Board Members if you'd like additional information on what it's like to be a Global Board member at the OWASP Foundation.
Who can run?
Candidate qualifications are defined in the Board Directors Policy, Section A.1. In summary, candidates must:
- Be an OWASP Individual (voting) Member in good standing, and have maintained that membership continuously for the 12 months ending on Membership Day (September 30) of the election year, and throughout the election process. Complimentary Members are not eligible.
- Nominate themselves. Third-party nominations are not accepted.
- Demonstrate a history of active volunteer contribution to the OWASP community (for example chapter or project leadership, conference organizing, committee or working group service) for at least 9 months in the preceding year or 24 months in the previous 5 years, or equivalent contributions as described in the policy.
- Not be a paid OWASP Foundation employee (two-thirds full-time equivalent or more), during employment and for 12 months after.
- Not have an upheld Code of Conduct violation within the four years preceding Membership Day. Three or more upheld violations result in permanent ineligibility.
- Be able to communicate with the Board, staff, and community in English (CEFR B2 or better).
The candidate requirements are significantly more stringent than in the past, so please check that you meet them before submitting your candidacy. The OWASP Foundation verifies each candidate's qualifications before announcing candidates to the community.
Candidacy materials
To be eligible, candidates must complete their candidate page on the OWASP Elections website by the published deadlines, including:
- A professional biography and background.
- A statement of their plans and why they wish to be elected.
- Answers to the standard candidate questions defined by the Executive Director.
- Answers to the top community-submitted questions (up to six, sorted by popularity), together with a short online video (1-3 minutes) describing their positions.
Failure to submit the required materials by the published deadlines will result in disqualification from the election. Candidates are also expected to participate in a recorded virtual Town Hall to answer questions from the community.
General election timeline
The milestones below are set by the Board Directors Policy, Section B.2 and fall on these dates (or the closest business day) each election year:
August 15
Call for Candidates published
August 31
Candidate registration deadline
September 1-10
Verification of candidate qualifications
September 10
Candidates announced to the community
September 15-30
Community questions collected
September 30
Membership Day (membership deadline to vote and to satisfy candidate standing requirements)
October 1-15
Candidates publish answers to community questions and their videos; Town Hall / candidate debate held
October 6
Candidate Debate Community Town Hall (recorded)
October 15
Voting opens
October 30
Voting closes
No later than the first business day after November 3
Full results announced to the community
January 1
New Directors take office
Who can vote?
OWASP Individual Members in good standing on Membership Day (September 30) of the election year are eligible to vote. The Individual Member class includes the Standard, Regional, Student, Lifetime, and Distinguished Lifetime subclasses. Complimentary Members are not Voting Members under the Bylaws and do not have voting rights.
Each Voting Member has one vote per election. If you are not an Individual Member yet, we encourage you to join before Membership Day.
How to vote
Eligible voting members will receive an email to their registered email address from owasp@simplyvoting.com with the subject "BALLOT FOR OWASP [YEAR] Board Election". This email includes a personal link to cast your vote. Please do NOT share this link with anyone. It is a specific link JUST FOR YOU!
Eligible voting members will also receive an email from the OWASP Foundation notifying them that their ballot has been sent. If you believe you are eligible but did not receive a ballot, please contact us.
How votes are counted
Voting is by secret ballot of Voting Members, open for 14 to 20 days. Ballots are counted using a ranked choice / "single transferable vote" method: voters rank their preferred candidates, and preferences are redistributed during counting until all vacancies are filled. Beginning in 2026, candidate names are randomly ordered on each ballot to avoid position bias.
Full results, including the votes cast for each candidate and the total ballots cast, are published within three business days of the close of voting. The Executive Director or their designee certifies the result. Voting history is private; no one other than you knows your vote.
Recent policy changes
New Bylaws (effective July 8, 2024):
- Introduced the concept of Voting Members (Individual Members with voting rights).
- Established that only Voting Members can vote or run for the Board.
Board Directors Policy (approved December 16, 2025):
- Defines significantly more stringent candidate and director qualifications, verified by the Foundation before candidates are announced.
- Establishes the standard election timeline and requires ranked choice / single transferable vote counting.
- Requires Directors to maintain their voting membership in good standing throughout their term; a Director who does not may have their seat vacated under Sections 4.5 and 4.6 of the Bylaws.
- Requires background checks for all elected candidates and appointed Directors before taking their seat.
New for 2026:
- Although not dictated by policy, candidate names are randomly ordered on each ballot to avoid bias in the voting process.
References
This page is an explanatory overview. The relevant sections of the Bylaws are:
- OWASP Bylaws - Privileges of Individual Membership
- OWASP Bylaws - Nomination and Election Procedures
- OWASP Bylaws - Nomination, election, and term of office of Directors
The relevant sections of the Board Directors Policy are: