OWASP SAMM
About SAMM
  • What is SAMM
  • The team
The Model Docs Blog
Community
  • User Day
  • SAMM Users
  • Practitioners
  • Sponsors
  • Benchmark

About SAMM

SAMM is the Software Assurance Maturity Model: a prescriptive, community-driven framework for measuring and improving an organization’s software security posture. Start with an overview or meet the people behind the project.

Start here

Get oriented with the model and the people behind it

What is SAMM

An overview of the Software Assurance Maturity Model: mission, structure, and how organizations use it.

The team

The volunteers and contributors who maintain SAMM, shape the roadmap, and run the community.

References

Background, terminology, and version history

FAQ

Answers to the questions we hear most often about adopting and interpreting SAMM.

Mapping versions 1.5 to 2.0

How practices and activities map between the 1.5 and 2.0 editions of the model.

Version 1.5

Archived materials for the previous major version of the model.

Acronyms and abbreviations

A glossary of the terms and abbreviations used across the SAMM model and documentation.

OWASP

This is an OWASP project. OWASP is an open community dedicated to enabling organizations to conceive, develop, acquire, operate, and maintain applications that can be trusted.

Navigation

  • About SAMM
  • The Model
  • Docs
  • Assessment

Help

  • FAQ
  • Contributing
  • Contact

Connect

  • GitHub
  • Slack
  • LinkedIn
  • YouTube
  • Meetup

OWASP SAMM is published under the CC BY-SA 4.0 license and we share the OWASP Privacy Policy.

We use analytics cookies to understand how visitors use this site. See our privacy policy.

Cookie preferences

Necessary

Required for the site to work. Cannot be disabled.

Always on
Analytics

Helps us understand how visitors use the site (Google Analytics and Scarf page-view pixels on SAMM model pages). No personally identifiable information is collected.