OWASP SAMM — Software Assurance Maturity Model (v2)

Source: OWASP SAMM

OWASP SAMM is a vendor-neutral maturity model for measuring and improving a software assurance program. Version 2 organizes practice across five business functions (Governance, Design, Implementation, Verification, Operations), each with three security practices, scored against three maturity levels. It ships an assessment toolkit so a team can self-score and plan increments.

On this wiki SAMM is the peer maturity model to Microsoft SDL and a precursor referenced by NIST SSDF. It is one input to the Secure-SDLC Framework Stack synthesis.

The OWASP AI Exchange names SAMM alongside NIST SSDF in the references of its SEC DEV PROGRAM control, which requires AI secure-development practice to extend an existing secure-development program rather than stand up an isolated AI-specific one (/go/secdevprogram/). That places SAMM as a base program an AI assurance effort adds to, and it is why the Exchange’s AI-specific engineering particularities are stated as additions to a development program instead of as a separate model.

Seed page

Created to resolve dead links from NIST SSDF and Microsoft SDL. A full treatment would map SAMM’s five functions to the wiki’s CMM domains and note where it does and does not address agentic-AI assurance.

Sources