Mature

OWASP SAMM Assessment

We assess your secure software development practices and create an achievable roadmap to improve SSDLC maturity.

Introduction

Maturity frameworks

OWASP SAMM (owaspsamm.org) is a structured framework for assessing and improving Secure Software Development Lifecycle (SSDLC) maturity across business functions.

Action

Assessment process

OWASP SAMM gives teams a way to assess current software assurance practices, define a target state, and turn gaps into an implementation roadmap.

1. Initial consultation

Purpose

Agree on the scope, owners, and timeline before assessment interviews begin.

Activities

Define the scope
Choose the scope of the assessment: the whole enterprise, one application, one project, or one team.
Identify stakeholders
Identify the stakeholders who own the assessment goals and need to provide evidence.
Plan the assessment
Confirm stakeholder availability, then share the action plan and timeline.

2. SAMM assessment

Purpose

Measure the maturity of your chosen scope across the 15 SAMM software security practices.

Activities

Evaluate current practices
Interview the stakeholders who know how work happens today. Teams with enough internal context can run a self-assessment. SAMM offers lightweight and detailed assessments; choose the detailed, evidence-based version when you need high confidence in the scores.
Determine maturity level
Score each security practice with the SAMM maturity scoring system. Activity scores come from multiple-choice answers, roll up into each practice area, and combine into the overall score.

3. Maturity report

Purpose

After the evaluation, we prepare a report that shows your current software assurance posture, strengths, gaps, and improvement areas.

Activities

Document current practices
Record the practices, evidence, and context behind each score.
Prepare a shareable report
Prepare an executive summary and detailed report with graphics that explain the current situation.

4. Improvement roadmap

Purpose

Choose a target score and select the activities that fit your risk, resources, and goals.

Activities

Activity prioritization
Identify the improvement opportunities that will reduce the most risk or unlock the most progress.
Define the target
Set or update the target by choosing the activities your organization should implement next. Most roadmaps include more lower-level activities than higher-level activities, and the final selection should account for dependencies between them.

Model

The Model

Each activity has three maturity levels. Each level describes the benefit, acceptance criteria, and implementation guidance.

Why

Benefits and use cases

Use OWASP SAMM to translate cybersecurity standards and frameworks into specific, measurable, and achievable steps.

NIST SP 800-53

Requires secure development practices, particularly in the SA (System and Services Acquisition) family, which includes controls for system development life cycle security.

NIST Cybersecurity Framework (CSF)

Encourages secure development practices under the "Protect" function, particularly in the area of Secure Software Development and Supply Chain Risk Management.

ISO/IEC 27001

Requires the implementation of secure development policies under control A.14.2 (Security in Development and Support Processes).

CIS Controls (Center for Internet Security)

Control 16: Application Software Security, includes requirements for adopting secure development practices in the software development lifecycle.

EU Cyber Resilience Act (CRA)

The EU Cyber Resilience Act mandates the implementation of a secure development lifecycle (SDLC) to ensure that software products and connected devices meet cybersecurity standards throughout their entire lifecycle.

FISMA (Federal Information Security Management Act)

Requires federal agencies to implement security controls, including secure development practices, as part of their risk management and information system security lifecycle.

PCI DSS (Payment Card Industry Data Security Standard)

Version 4.0 includes specific requirements for secure software development and requires organizations to integrate security throughout the SDLC for payment applications.

Executive Order 14028 (Improving the Nation’s Cybersecurity)

This U.S. Executive Order mandates the use of secure development practices for government contractors and agencies, particularly regarding supply chain security and software development.

HIPAA (Health Insurance Portability and Accountability Act)

The HIPAA Security Rule requires covered entities to implement policies and procedures that secure ePHI, which can include secure development lifecycle practices in software handling health data.

CMMC (Cybersecurity Maturity Model Certification)

Requires the implementation of secure development practices at higher maturity levels to protect federal contract information and controlled unclassified information.

FedRAMP (Federal Risk and Authorization Management Program)

Mandates that federal cloud service providers follow secure development practices as part of their overall security controls for government systems.

Price

OWASP SAMM Assessment packages

Prepare your development lifecycle for upcoming requirements.

Compact

€5700 +VAT

High-level assessment of one selected scope with a visual report.

  • Initial consultation
  • Assessment of 5 business functions
  • Current SSDLC posture and gap report
  • Roadmap suggestion based on assessment interviews
Request a quote

Complete

€6900 +VAT

Assessment, documentation, and roadmap planning with post-assessment review calls.

  • Everything in Compact, plus:
  • Tailored roadmap planning based on the client's security risk appetite
  • 3 post-assessment calls to validate improvements and discuss strategy
Request a quote

Customized

Let's talk

A custom engagement for evidence review, project management, SSDLC policy writing, or other needs specific to your organization.

Schedule a call

Next steps

Implement controls

We work with Codific to deliver and implement SAMMY, Codific’s platform for assessments, roadmap planning, and maturity program tracking.

Codific SAMMY assessment flow, horizontal

Tell us what you need to implement next.

Schedule a call

Details

FAQ

1. How do ISO and SAMM complement each other?
The October 2022 revision of ISO/IEC 27001 introduced simpler domains, more usable language, and new controls, including a dedicated secure coding control. ISO 27001 gives organizations the management system, ownership, and audit structure. OWASP SAMM gives software teams detailed guidance for secure development practices. Organizations can use both to connect risk management to the day-to-day work of building software.
2. How do we determine an assessment scope?
Start with the goal of the assessment and the decisions the results need to inform. For a first SAMM assessment, one team or one product often gives the clearest signal. Consider customer type, geography, regulatory obligations, development model, and management style. Document the context so the same scope can be reassessed later and compared honestly.
3. How does SAMM map to other standards?
OWASP SAMM maps to OpenCRE, NIST SSDF, BSIMM, and other standards and guidelines. OpenCRE, the Open Common Requirement Enumeration, gives teams a common way to compare security standards. By linking SAMM streams to OpenCRE, teams can find related requirements in NIST SSDF, ISO 27001, PCI DSS, OWASP ASVS, and NIST SP 800-53. For example, the SAMM Threat Assessment stream connects to the CRE for threat modeling processes, which maps to NIST SSDF PW1.1 and ISO/IEC 27001 A.14.2.5.
4. How does SAMM relate to NIST SSDF?

OWASP SAMM provides a detailed mapping to NIST SSDF, so teams can see how SAMM streams relate to SSDF tasks.

SAMM turns SSDF into a maturity path. Teams assess current maturity, choose a target state, and prioritize the activities that move them toward it.

The mapping uses Informative References to connect SAMM activities with SSDF tasks and supporting materials.

5. What is the difference between SAMM and BSIMM?

BSIMM is descriptive. It observes and reports software security activities across organizations, which makes it suited to benchmarking and industry comparison.

SAMM is prescriptive. It gives organizations defined maturity levels for assessing, building, and measuring software security practices.

BSIMM gives teams a common vocabulary for comparison. SAMM gives teams a roadmap for improvement.

Make it happen

Request a quote

We’ll prepare a quote for your purchasing team within 24 hours. No spam afterward.

Prefer email? Write to us and we'll get back within one business day.

Email info@securehabits.nl