Application & API Security

OWASP SAMM

Software Assurance Maturity Model

Community Global OWASP Since 2009

A maturity model for secure software delivery across five business functions (governance, design, implementation, verification, operations), each with streams scored at three maturity levels.

Its purpose is direction rather than certification: measure where you are, choose the next increment, re-measure. The output is a roadmap, which is what most secure-development clauses in regulation actually expect you to have.

At a glance

Category
Application & API Security
Jurisdiction
Global
Governance
OWASP
Status
Version 2 (2020)
First released
2009

Links

Related frameworks

Other entries under Application & API Security.

See OWASP SAMM in context

Open the interactive Data Landscape for Regulation to compare OWASP SAMM against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.