The original model (v1.0) was written by Pravir Chandra and dates back from 2009. Over the last 10 years, it has proven a widely distributed and effective model for improving secure software practices in different types of organisations throughout the world. Translations and supporting tools have been contributed by the community to facilitate adoption and alignment. With version 2.0, we further improve the model to deal with some of its current limitations.

After a period of intensive discussions and with input from practitioners and the OWASP community during summits in Europe and the US on the best way forward, we take a new approach for version 2.0 based on the following improvements.

For the SAMM benchmark initiative, the team is working on providing a community-driven dataset solution that we intend to launch with the release of v2.0 of the model (June 2019). The solution will provide open access to anonymized data where contributors will have more advanced access to the data.

Finally, we are working towards a model where frequent updates of the model are supported through small increments on specific parts of the model. The intent is to keep the model rather stable (and only change this with major versions of the model), but have a living model by supporting regular updates to explanation, tooling and guidance by the community.

We are working hard towards v2.0 of the model with a small set of core contributors. You can contribute to the project by providing us feedback on what we distribute and tell us what works for you and what not (and why).

The OWASP SAMM project team.