OWASP SAMM
What is OWASP SAMM?
OWASP Software Assurance Maturity Model. It comprises 5 controls organised across 5 domains, published by OWASP Foundation, and applies in International.
How OWASP SAMM maps to other frameworks
All 5 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 5 domains OWASP SAMM groups its controls into
Frameworks that share controls with OWASP SAMM
Each of these has at least one control mapped to a control in OWASP SAMM. The number is how many OWASP SAMM controls are shared, counted from the mapping graph.
Where OWASP SAMM overlaps with the standards you already hold
What OWASP SAMM means in your sector
What OWASP SAMM means for your job
Questions people ask about OWASP SAMM
What is OWASP SAMM?
How many controls does OWASP SAMM have?
Where does OWASP SAMM apply?
What frameworks does OWASP SAMM map to?
How do I get started with OWASP SAMM compliance?
Query OWASP SAMM programmatically
OWASP SAMM, its 5 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
OWASP SAMM API reference and MCP config →What OWASP SAMM requires, control by control
Each page carries the requirement text for one OWASP SAMM control and what an assessor expects to see as evidence.
- OWASPSAMM-1 Governance: Strategy, Policy, Compliance, Education, Champions
- OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
- OWASPSAMM-4 Verification: Architecture Assessment, Requirements-Driven Testing, Security Testing
- OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management
How ready are you for OWASP SAMM?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.