OWASP SAMM
About SAMM
  • What is SAMM
  • The team
The Model Docs Blog
Community
  • User Day
  • SAMM Users
  • Practitioners
  • Sponsors
  • Benchmark
Getting Started
Step 1: Prepare
Step 2: Assess
Step 3: Set the Target
Step 4: Define the Plan
Step 5: Implement
Step 6: Roll Out
Fundamentals Course
In Depth
Defining Scope
Roles & Skills
Assessment Guide
Conducting Interviews
Example Interview Questions
Overview
SAMM to Assignments
Assignment Profiles
FAQ
Mappings
Assessment Tools
SAMM PDF
How to Contribute
GitHub Repositories
SAMM Agile Guidance
Stream Guidance
The Model

Documentation

Welcome to the OWASP SAMM documentation. Choose a topic below to get started.

Quick Start Guide

A practical guide to planning, executing, and rolling out a SAMM assessment.

Fundamentals Course

Free self-paced SAMM Fundamentals course with over 5 hours of video

Preparation

Prepare your SAMM implementation: define scope, map roles, and build the foundation for a successful assessment.

Assessment

How to conduct, score, and interpret SAMM assessments.

Skills Framework

Map SAMM streams to roles, responsibilities, and skill requirements.

Reference

Frequently asked questions and mappings to other security frameworks

Tools & Downloads

The SAMM PDF, assessment tools, spreadsheets, and other downloads for OWASP SAMM

Contributing

How to contribute to the OWASP SAMM project

Guidance

In-depth guidance for implementing SAMM in specific contexts and methodologies.

OWASP

This is an OWASP project. OWASP is an open community dedicated to enabling organizations to conceive, develop, acquire, operate, and maintain applications that can be trusted.

Navigation

  • About SAMM
  • The Model
  • Docs
  • Assessment

Help

  • FAQ
  • Contributing
  • Contact

Connect

  • GitHub
  • Slack
  • LinkedIn
  • YouTube
  • Meetup

OWASP SAMM is published under the CC BY-SA 4.0 license and we share the OWASP Privacy Policy.

We use analytics cookies to understand how visitors use this site. See our privacy policy.

Cookie preferences

Necessary

Required for the site to work. Cannot be disabled.

Always on
Analytics

Helps us understand how visitors use the site (Google Analytics and Scarf page-view pixels on SAMM model pages). No personally identifiable information is collected.