OWASP SAMM
OWASP SAMM is an open-source software security maturity model framework under the OWASP Foundation, providing organizations globally with a technology-agnostic, measurement-driven approach to improving application security across five business functions.
- Company typePrivate
- Founded2020
- Headquarters—
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What OWASP SAMM does
OWASP SAMM (Software Assurance Maturity Model) is an open-source framework project stewarded under the OWASP Foundation that provides organizations with a prescriptive, measurable approach to analyzing and improving their software security posture. The framework is technology-agnostic and structured around five business functions — Governance, Design, Implementation, Verification, and Operations — with each security practice evaluated on a 0–3 maturity scale. Core deliverables include the maturity model itself (maintained as YAML files on GitHub and rendered via Hugo for the public website), an assessment methodology, a SAMM Fundamentals training course, the Benchmark Initiative (30 public assessments with an average score of 1.44/3.0 as of the May 2025 Benchmark Report), Stream and Agile guidance documents, and the annual SAMM User Day event. The project is distributed under the Creative Commons Attribution-ShareAlike 4.0 license and is localized into multiple languages via Crowdin.
The project's user base spans enterprises, public-sector bodies, and security practitioners worldwide, with no commercial gating on access or use. Its go-to-market is purely community-driven: adoption is driven by word-of-mouth, conference presence, and content publishing rather than a sales motion. Revenue mechanics consist of organizational sponsorship tiers (Platinum, Gold, Silver, Bronze, Community), with the current disclosed roster including Gold sponsor Codific and Silver sponsors Checkmarx, Micro Focus (Fortify), Minded Security, NCC Group, PwC, SafeStack, Security Innovation, Splunk, and Toreon. Development is largely volunteer-led by project maintainers, with no disclosed paid headcount or commercial product line; there are no paid tiers, no enterprise licensing, and no proprietary extensions monetized by the project itself.
OWASP SAMM firmographics
Firmographics- Name
- OWASP SAMM
- Legal name
- OWASP Foundation
- Website
- https://owaspsamm.org
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- OWASP SAMM is an open-source software security maturity model framework under the OWASP Foundation, providing organizations globally with a technology-agnostic, measurement-driven approach to improving application security across five business functions.
- Ownership category
- akta.pro rank
OWASP SAMM industry classification
Industry- Product category
- Application Security
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Engineering, Accounting, Research, Management (8700)
- akta.pro primary industry
- Security Maturity Assessments & Benchmarking (BPAKADAO)
Keywords
OWASP SAMM business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Operations, Personnel, Technology or R&D, Marketing or Sales
Revenue model
- Sponsorships and Donations: OWASP SAMM is funded through organizational sponsorships at multiple tiers (Platinum, Gold, Silver, Bronze, Community). The project uses these funds for outreach, promotion, research grants, SAMM hosting, tools, templates, documents, and Core Team in-person sprints. Development is primarily carried out by dedicated volunteers.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Annual | Free Open-Source Framework |
Go-to-market motion1 record
Distribution channels4 records
Marketing channels10 records
OWASP SAMM product offering
Product offeringCore offering
OWASP SAMM provides a prescriptive, technology-agnostic software security maturity model framework that helps organizations analyze and improve their software security posture. The framework evaluates maturity on a 0-3 scale across five business functions (Governance, Design, Implementation, Verification, Operations) and 15 security practices, and is supported by assessment tools, a benchmark initiative, and a free Fundamentals Course. All materials are published under the CC BY-SA 4.0 license.
Product overview
OWASP SAMM is an open-source security assurance maturity model framework (not a commercial software product) that provides organizations with a prescriptive and measurable way to analyze and improve their software security posture. The core offering is the SAMM Core Framework, a technology-agnostic model organized into five business functions (Governance, Design, Implementation, Verification, and Operations), each containing security practices with maturity levels 0–3. Supporting products include the free Fundamentals Course (self-paced training), Assessment methodology (interview-based measurement), Benchmark Initiative (anonymized industry comparisons), Stream Guidance documents (tool recommendations and best practices), Agile Guidance (adaptation for iterative development), and the annual SAMM User Day community event. The model is maintained as YAML files on GitHub, rendered via Hugo, and distributed via static website and PDF downloads. Published under CC BY-SA 4.0 license.
Differentiator
Problem solved
Functional benefit
Products and services
- Software Assurance Maturity Model (SAMM) Core Framework A prescriptive security maturity model that provides a structured, technology-agnostic approach for organizations to analyze and improve their software security posture. Covers five business functions: Governance, Design, Implementation, Verification, and Operations, each containing security practices with maturity levels 0 to 3.
- SAMM Fundamentals Course A free, self-paced online course designed to help newcomers learn the basics of OWASP SAMM and begin implementing security maturity practices in their organizations.
- SAMM Assessment A structured interview-based methodology for measuring an organization's current software security posture across all business functions and security practices, producing maturity scores from 0 to 3.
- SAMM Benchmark Initiative A data collection and analysis initiative that aggregates anonymized SAMM assessment results to enable organizations to compare their maturity against industry peers and track progress over time.
- SAMM Agile Guidance Practical guidance document explaining how to adapt SAMM security practices for Agile software development environments, including sprint integration, threat modeling in iterations, and security requirements in stories.
- SAMM Stream Guidance Concrete guidance documents providing tool recommendations, best practices, standards mappings, and prerequisites for achieving specific maturity levels within each SAMM stream. Includes both team-authored and community-contributed guidance.
- SAMM PDF Download Official PDF documentation of the SAMM model for offline reference, available via the Tools & Downloads section.
Quantifiable outcome
- Average SAMM score across 30 organizations: 1.44 out of 3.0
- +2 more outcomes
Companies that use OWASP SAMM
Customer profileNamed customers2 records
Segments3 records
Ideal customer profiles3 records
OWASP SAMM technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
OWASP SAMM partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- OWASP DSOMM (DevSecOps Maturity Model)flagshipJoint User Day event at OWASP Global AppSec USA 2026, bringing together SAMM and DSOMM communities for a full day of talks, networking, and knowledge sharing on security maturity models.
Scale indicators3 records
OWASP SAMM competitors and assessment
Company assessmentBroad incumbents
- Microsoft Security Development Lifecycle (SDL): Microsoft's vendor-specific secure development framework. Widely adopted as a reference model and frequently mapped against SAMM, representing the largest single-vendor incumbent in the security maturity model space.
- Snyk: Developer security platform providing AppSec tooling that often integrates with SAMM-style maturity programs. Represents the broader incumbent AppSec tooling market that overlaps with SAMM's practitioner ecosystem.
- SAFECode: Industry consortium (Microsoft, Adobe, SAP, Siemens, others) publishing foundational secure development guidance and principles. Comparable to SAMM as an industry-level framework for software assurance practices, though focused on principles rather than measurable maturity scoring.
- OpenSSF (Linux Foundation): Linux Foundation initiative consolidating open-source security efforts, including CII best practices and supply chain security frameworks. Thematically adjacent to OWASP SAMM and an increasingly influential peer in the open software security ecosystem.
Direct peers
- ISO/IEC 27034 Application Security: International standard for application security, providing a normative framework organizations can certify against. SAMM's mapping documents reference ISO 27034, positioning the two as peers in the application-security-standards ecosystem.
- Software Improvement Group (SIG): Software quality and security benchmarking consultancy whose staff (e.g., Rob van der Veer) actively contribute to SAMM. SIG operates in the adjacent benchmarking/assessment space, often using or referencing SAMM in client engagements.
- OWASP ASVS: OWASP Application Security Verification Standard — sister OWASP project providing a verification-focused security standard that complements SAMM's maturity-model approach, frequently used together by organizations building SDLC security programs.
- OWASP DSOMM (DevSecOps Maturity Model): Sister OWASP project covering DevSecOps maturity with overlapping assessment methodology. SAMM and DSOMM are explicitly co-marketed (joint User Day at AppSec USA 2026), making them the closest direct peer in the maturity model space.
- Synopsys BSIMM: Building Security In Maturity Model — the most prominent proprietary software security maturity model and direct conceptual competitor to SAMM, with overlapping practices around governance, design, implementation, verification, and operations.
- NIST Secure Software Development Framework (SSDF): U.S. federal standard (SP 800-218) describing secure software development practices. SSDF is the closest government-backed peer, often mapped to or alongside SAMM by practitioners, and increasingly referenced in U.S. procurement (e.g., EO 14028).
Market position
Strengths4 records
Weaknesses4 records
Key risks5 records
Key highlights6 records
Customer concentration
OWASP SAMM social profiles
Digital presenceOWASP SAMM financial estimates
Financial estimateRevenue estimate
Valuation estimate
OWASP SAMM leadership team
Management profileNumber of profiles
Profiles4 records
OWASP SAMM funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
OWASP SAMM M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about OWASP SAMM
What does OWASP SAMM do?
OWASP SAMM provides a prescriptive, technology-agnostic software security maturity model framework that helps organizations analyze and improve their software security posture. The framework evaluates maturity on a 0-3 scale across five business functions (Governance, Design, Implementation, Verification, Operations) and 15 security practices, and is supported by assessment tools, a benchmark initiative, and a free Fundamentals Course. All materials are published under the CC BY-SA 4.0 license.
Is OWASP SAMM a public or private company?
OWASP SAMM is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was OWASP SAMM founded?
OWASP SAMM was founded in 2020. It employs 11 to 50 people.
How does OWASP SAMM make money?
One revenue line is on record: sponsorships and Donations.
Who are OWASP SAMM's main competitors?
Broad incumbents on record are Microsoft Security Development Lifecycle (SDL), Snyk, SAFECode and OpenSSF (Linux Foundation). Direct peers are ISO/IEC 27034 Application Security, Software Improvement Group (SIG), OWASP ASVS, OWASP DSOMM (DevSecOps Maturity Model), Synopsys BSIMM and NIST Secure Software Development Framework (SSDF).
Does OWASP SAMM have an API?
No public API is recorded for OWASP SAMM.
What industry is OWASP SAMM in?
OWASP SAMM's product category is Application Security. Its primary akta.pro industry code is BPAKADAO, Security Maturity Assessments & Benchmarking. Its NAICS code is 5415 and its SIC code is 8700.