If the presence of entanglement could be certified in a device-independent (DI) way, it is likely to provide various quantum information processing tasks with unconditional security. Recently, it was shown that a DI protocol, combining measurement-device-independent techniques with selftesting, is able to verify all entangled states, however, it imposes demanding requirements on its practical implementation. Here, we present a less-demanding protocol based on Einstein-Podolsky-Rosen (EPR) steering, which is achievable with current technology. Particularly, we first establish a complete framework for DI verification of EPR steering and show that all steerable states can be verified. Then, we analyze the three-measurement setting case, allowing for imperfections of self-testing. Finally, a four-photon experiment is implemented to device-independently verify EPR steering and to further demonstrate that even Bell local states can be faithfully verified. Our findings pave the way for realistic applications of secure quantum information tasks.