GRCCopilot
Sign In
Open Web Application Security Project (OWASP)

OWASP Software Assurance Maturity Model (SAMM)

The open framework for measuring and improving software security maturity across development organisations

Start Assessment Create Free Account
13
Controls
39
Questions
Active
Status
May 2031
Expires

About this Framework

The OWASP Software Assurance Maturity Model (SAMM) v2.0 provides an open framework for integrating security practices into software development processes. Organised across five business functions (Governance, Design, Implementation, Verification, Operations), SAMM defines 15 security practices each with three maturity levels. It enables organisations to assess current security maturity, define measurable improvement targets, create roadmaps and track progress — applicable to Agile, DevOps, DevSecOps and traditional development methodologies of any scale.

Key Control Domains

Governance (Strategy & Metrics, Policy & Compliance, Education)
Design (Threat Assessment, Security Requirements, Architecture)
Implementation (Secure Build, Secure Deployment, Defect Management)
Verification (Architecture Assessment, Requirements-driven Testing, Security Testing)
Operations (Incident Management, Environment Management, Operational Management)

Who Needs This?

  • Software development organisations at any size or maturity level
  • DevSecOps and application security programme teams
  • Product security managers building secure SDLC programs
  • Organisations under PCI DSS, ISO 27001 or NIST SSDF requirements
  • AppSec consulting firms conducting security maturity assessments

Compliance Benefits

  • Free, open framework immediately applicable to any development methodology
  • Covers the complete software development and operations lifecycle
  • Enables measurable security improvement roadmaps with quantified maturity
  • Direct alignment with NIST SSDF, ISO 27001 and PCI DSS secure coding requirements

Official Reference

OWASP SAMM Official Site
https://owaspsamm.org/

Assessment Details

Issuer / AuthorityOpen Web Application Security Project (OWASP)
FrameworkOWASP Software Assurance Maturity Model (SAMM)
Controls13
Questions39
StatusActive
Assessment Start25 May 2026
Assessment Expires25 May 2031

Share this Assessment

Share this permanent link with your team, clients or auditors.

https://grcopilot.app/frameworks/owasp-software-assurance-maturity-model-samm

Sign in to begin this assessment

Create a free GRC Copilot account to access this and 50+ other security and compliance frameworks.