How SAMM Scores Application Security Maturity

▶ Watch (0:02)

SAMM organizes application security around security practices, each split into two streams and three maturity levels. Level one is opportunistic, level two is efficient, level three is mastered. Version 2 added a second scoring dimension alongside coverage: quality criteria. For the control verification stream, the coverage question is “do you test security controls.” The quality criteria ask whether you test authentication controls specifically and whether you retest when the application changes those controls. Both dimensions must pass before the activity scores as done.

Mapping SAMM to ISO, NIST, and EU Regulations

▶ Watch (3:46)

Organizations running ISO 27001 or preparing for DORA and the EU Cyber Resilience Act do not need to re-answer every SAMM question from scratch. The project maintains direct mappings to NIST SSDF and NIST CSF. NIST participated in the SSDF mapping, though neither organization certifies compliance against either framework. SSDF covers similar ground to SAMM but has no maturity levels. OpenCRE offers a hub where any two frameworks from a pool of 10 to 15 can generate mappings between each other, without SAMM as a middleman.

The Benchmark: What 30 Organizations Reveal

▶ Watch (8:09)

The SAMM benchmark collects anonymized assessment data from real organizations and publishes aggregate scores so teams can see where they stand. The current data set has 30 assessments. Most come from large multinationals with 1,000 to 10,000 developers. About two-thirds are third-party assessments done by practitioners, which the team treats as more objective. One medium-sized company submitted data, but the project does not publish that slice because a single entry would let anyone identify the organization from its score.

Where Application Security Programs Consistently Fall Short

▶ Watch (13:18)

The composite average across all 30 assessments is 1.44 out of 3. Operations scores highest at 1.8. The speakers believe the real-world average for unselected organizations sits below 1.0, since benchmark submitters tend to be confident programs. Verification is the worst-performing business function. Security requirements score high, but requirements testing is the lowest-scoring individual activity. Teams write requirements without testing against them. The most alarming finding: security metrics score near zero. Most organizations have not worked out how to measure whether their application security program is succeeding.

Notable Quotes

is that bad I don’t know to be honest Aram Hovsepyan · ▶ Watch (12:37)

we were also expecting the third party assessments to score lower Aram Hovsepyan · ▶ Watch (15:05)

it’s weird we still haven’t figured out how to measure our absc program Aram Hovsepyan · ▶ Watch (19:39)

Key Takeaways

  • The composite SAMM benchmark average is 1.44/3, but selection bias means real-world scores likely fall below 1.0
  • Security requirements score high while requirements testing scores lowest, revealing a gap between defining and verifying
  • Verification is the weakest business function across all benchmark segments
  • Security metrics score near zero; most teams lack a way to measure program success
  • SAMM maps to ISO 27001, NIST SSDF, DORA, and the EU Cyber Resilience Act to reduce duplicate assessments

About the Speaker(s)

Aram Hovsepyan is Founder and CEO of Codific, a Belgian cybersecurity product firm. He has spent 15 years in application security as a researcher, industry expert, and core contributor to the OWASP SAMM project.

Sebastien Deleersnyder is co-founder and CTO of Toreon. He started the Belgian OWASP chapter, served on the OWASP Foundation Board, and has given numerous public presentations on application security.