Identity & Access

SAML

Security Assertion Markup Language

Formal standard Global OASIS Since 2002

The XML standard for exchanging authentication and authorisation assertions between an identity provider and a service provider. It is what most enterprise single sign-on still runs on.

It matters here because access control evidence starts with authentication: an auditor asking who could reach a data set is really asking which identity provider vouched for them, and what the assertion claimed.

At a glance

Category
Identity & Access
Jurisdiction
Global
Governance
OASIS
Status
SAML 2.0 OASIS Standard (2005)
First released
2002

Links

Related frameworks

Other entries under Identity & Access.

See SAML in context

Open the interactive Data Landscape for Regulation to compare SAML against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.