OWASP SAMM

A Software Assurance Maturity Model (SAMM) that provides an effective and measurable way for all types of organizations to analyse and improve their software security posture.

About OWASP SAMM

Software Assurance Maturity Model

Our mission is to provide an effective and measurable way for you to analyze and improve your secure development lifecycle. SAMM supports the complete software lifecycle and is technology and process agnostic. We built SAMM to be evolutive and risk-driven in nature, as there is no single recipe that works for all organizations.

Check out the OWASP SAMM v2 model online:

Get OWASP SAMM new delivered to your mailbox

Join us on the OWASP SAMM project Slack channel

Join our monthly calls

  • The monthly call is on each 2nd Wednesday of the month at 21h30 CET / 3:30pm ET.

  • Register through our SAMM MeetUp to join the Zoom call.

  • The call is open for everybody interested in SAMM or who wants to work on SAMM.

The Software Assurance Maturity Model (SAMM) is an open framework to help organizations formulate and implement a strategy for software security that is tailored to the specific risks facing the organization. SAMM helps you:

  • Evaluate an organization’s existing software security practices

  • Build a balanced software security assurance program in well-defined iterations

  • Demonstrate concrete improvements to a security assurance program

  • Define and measure security-related activities throughout an organization

Dell uses OWASP’s Software Assurance Maturity Model (Owasp SAMM) to help focus our resources and determine which components of our secure application development program to prioritize., (Michael J. Craigue, Information Security & Compliance, Dell, Inc.)

Project Leaders

Seba Deleersnyder

Email

Bart De Win

Email

Project Information

Flagship Project
Classification
Standards
Language
Markdown, HTML, and JavaScript
License
CC-BY-SA-4.0
Latest Version
2.2.0
Contributors
25
GitHub Stars
109
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.
OWASP SAMM