Application & API Security
OWASP SAMM
Software Assurance Maturity Model
A maturity model for secure software delivery across five business functions (governance, design, implementation, verification, operations), each with streams scored at three maturity levels.
Its purpose is direction rather than certification: measure where you are, choose the next increment, re-measure. The output is a roadmap, which is what most secure-development clauses in regulation actually expect you to have.
At a glance
- Category
- Application & API Security
- Jurisdiction
- Global
- Governance
- OWASP
- Status
- Version 2 (2020)
- First released
- 2009
Links
Related frameworks
Other entries under Application & API Security.
- OWASP LLM Top 10: OWASP Top 10 for LLM Applications
- OWASP API Top 10: OWASP API Security Top 10
- OWASP ASVS: Application Security Verification Standard
- OWASP ML Top 10: OWASP Machine Learning Security Top 10
See OWASP SAMM in context
Open the interactive Data Landscape for Regulation to compare OWASP SAMM against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.