BSIMM
What is BSIMM?
Building Security In Maturity Model. It comprises 36 controls organised across 4 domains, and applies in International.
How BSIMM maps to other frameworks
All 36 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 4 domains BSIMM groups its controls into
Where BSIMM overlaps with the standards you already hold
What BSIMM means in your sector
What BSIMM means for your job
Questions people ask about BSIMM
What is BSIMM?
How many controls does BSIMM have?
Where does BSIMM apply?
What frameworks does BSIMM map to?
How do I get started with BSIMM compliance?
Query BSIMM programmatically
BSIMM, its 36 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
BSIMM API reference and MCP config →What BSIMM requires, control by control
Each page carries the requirement text for one BSIMM control and what an assessor expects to see as evidence.
- AA1-1 Perform security feature review
- AA1-4 Use a risk-ranking methodology for applications
- AA2-1 Perform architecture analysis using STRIDE or equivalent
- AM1-2 Create a data classification scheme and inventory
- AM1-3 Identify potential attackers
- AM1-5 Gather and use attack intelligence
- CMVM1-1 Create or use an incident response capability for software
- CMVM1-2 Identify software defects found in operations and feed them back to development
- CMVM1-3 Track software bugs found in operations through the fix process
- CMVM3-4 Operate a bug bounty program
How ready are you for BSIMM?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.