Framework AI Governance & Privacy Frameworks
OWASP SAMM
OWASP SAMM (Software Assurance Maturity Model) is an open framework for measuring and improving how an organization builds secure software.
The current model is organized into five business functions (Governance, Design, Implementation, Verification, Operations), each with three security practices, and each practice split into two streams, giving fifteen practices and thirty streams.
Every stream is scored on a maturity scale from 0 to 3, so an assessment yields a numeric profile and a roadmap rather than a pass or fail. SAMM version 2 was released in 2020 and has had minor updates since (verify the current version number on owaspsamm.org).
SAMM is not a certification scheme. Organizations use it to self-assess or hire a consultant to run interviews and score the streams.
In writing, a SAMM program typically produces a secure development policy, a strategy and metrics document, security requirements and threat modeling standards, secure build and deployment procedures, defect management rules, testing standards, incident and environment management procedures, and a scored assessment with an improvement roadmap.
help
Who has to comply
Voluntary. Any organization that develops or procures software. It is often used to benchmark a security program or to answer customer due diligence about secure development, and some enterprises write SAMM maturity targets into supplier requirements.
What the assessor asks to see
Where an assessment is run: application security strategy and metrics; policy and compliance documentation; training records; threat assessment and security requirements artifacts; secure architecture guidance; build and deployment pipeline controls; defect management data; architecture and requirements-driven test results; security testing reports; incident management, environment management, and operational enablement procedures; the scored SAMM worksheet and roadmap.
Assessors
Who assesses OWASP SAMM
None mandated. Self-assessment or any consultant; the project does not qualify or license assessors.
No firm has claimed a OWASP SAMM assessor listing yet. Claim yours →
Consultants
Who helps with OWASP SAMM
A moderate consultancy ecosystem, including firms whose staff contribute to the project. Typical engagement is a two to four week assessment (interviews, document review, scoring), followed by an improvement roadmap; some clients run annual reassessments. The project also publishes a free assessment toolbox.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a OWASP SAMM consultant listing yet. Claim yours →
Software
Tools for OWASP SAMM
Tools that name this framework in their own material.
No firm has claimed a OWASP SAMM tool listing yet. Claim yours →
Related reading
- OWASP SAMM: a comprehensive introductionExplains the five business functions, fifteen practices and the level 1 to 3 scoring, and how a SAMM assessment is run.Codific
- What is OWASP SAMM?Useful on how SAMM differs from a certifiable standard: you measure maturity and set targets rather than pass or fail.Fluid Attacks
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for OWASP SAMM
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with OWASP SAMM
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.