About this Framework
The OWASP Software Assurance Maturity Model (SAMM) v2.0 provides an open framework for integrating security practices into software development processes. Organised across five business functions (Governance, Design, Implementation, Verification, Operations), SAMM defines 15 security practices each with three maturity levels. It enables organisations to assess current security maturity, define measurable improvement targets, create roadmaps and track progress — applicable to Agile, DevOps, DevSecOps and traditional development methodologies of any scale.
Key Control Domains
Governance (Strategy & Metrics, Policy & Compliance, Education)
Design (Threat Assessment, Security Requirements, Architecture)
Implementation (Secure Build, Secure Deployment, Defect Management)
Verification (Architecture Assessment, Requirements-driven Testing, Security Testing)
Operations (Incident Management, Environment Management, Operational Management)
Who Needs This?
- Software development organisations at any size or maturity level
- DevSecOps and application security programme teams
- Product security managers building secure SDLC programs
- Organisations under PCI DSS, ISO 27001 or NIST SSDF requirements
- AppSec consulting firms conducting security maturity assessments
Compliance Benefits
- Free, open framework immediately applicable to any development methodology
- Covers the complete software development and operations lifecycle
- Enables measurable security improvement roadmaps with quantified maturity
- Direct alignment with NIST SSDF, ISO 27001 and PCI DSS secure coding requirements
Official Reference
OWASP SAMM Official Site
https://owaspsamm.org/
Assessment Details
Share this Assessment
Share this permanent link with your team, clients or auditors.
https://grcopilot.app/frameworks/owasp-software-assurance-maturity-model-samm