What SAMM Measures and How It’s Built
SAMM is a framework of 90 best practices for application security programs. Organizations start with 30 baseline activities and grow from there. Five business functions sit at the top, each with three security practices and two streams per practice. Each stream has three maturity levels. Level one is ad hoc. Level two adds systematic process. Level three introduces feedback loops. Security requirements at level three requires connections to penetration testing, training, and threat modeling. The symmetric model covers the full program, but effort per area varies considerably.
Scores, Target Posture, and the Budget Argument
After 90 questions, SAMM produces scores by business function and security practice, mapped onto a scorecard. Set target scores as yellow dots to visualize the gap to current state. Security teams can use that gap analysis as a budget argument, showing management current posture against target and the cost to close it. Two less obvious applications: SAMM assessments before mergers reveal a target’s security posture, and at least one company negotiated lower cyber insurance premiums using SAMM scores.
Assessment Tools and How to Run One
SAMM provides assessment tools from an Excel spreadsheet (also as Google Sheets) to SAMWISE, a self-hostable single-page app, to an open-source tool called SAMMY that tracks results against a target posture. The spreadsheet works, but sending it to development teams tends to fail. Running through all 90 questions line by line also fails. The recommended approach is workshop and interview style, run alongside the team being assessed, which doubles as security awareness training.
Mapping SAMM to NIST, Microsoft SDL, and OpenCRE
SAMM activities map to NIST SSDF, with a crosswalk built alongside NIST staff. Additional mappings cover Microsoft SDL and OWASP DSOMM, a DevSecOps-focused model that goes deeper on certain topics. OpenCRE, a common requirements enumeration project, links SAMM activities to the full set of regulations those activities satisfy. A single master mapping file covers all of these. For organizations already required to comply with one standard, entering through SAMM provides coverage across the others without running a separate assessment.
What 68 Benchmark Entries Reveal About Industry Scores
The SAMM benchmark now holds 68 entries, up from 25 in June 2024 and 30 in September 2024. Three-quarters are third-party assessments; one quarter is internal. The average composite score is 1.26, down from 1.43 as the dataset normalizes. Operations scores highest because organizations inherit it from traditional information security work. Defect management, strategy and metrics, and threat assessment score lowest. Most first-time assessments land between 0.8 and 1.2. Small companies rarely reach 2.0 because of the process overhead maturity level two requires.
Q&A
Is the scoring criteria too strict? The response noted SAMM measures process activities, not strict security outcomes, and suggested taking the specific concern offline. ▶ 27:19
Notable Quotes
The word runs on spreadsheets. Sebastien Deleersnyder · ▶ 12:14
developers will hate you if you do it Sebastien Deleersnyder · ▶ 13:54
We’re up to 68 entries in the benchmark. Brian Glass · ▶ 18:55
Key Takeaways
- SAMM’s 90 activities start at 30 for new programs and grow through three maturity levels.
- Quality criteria define what counts as a “yes” answer, preventing teams from gaming the score.
- The live benchmark shows most organizations score between 0.8 and 1.2 on their first assessment.
- Benchmark data should drive target posture decisions, not a chase for the maximum possible score.
- SAMM activities map to NIST SSDF, Microsoft SDL, OWASP DSOMM, and OpenCRE in a single file.
About the Speaker(s)
Sebastien Deleersnyder is co-founder and CTO of Toreon and a proponent of application security as a holistic approach. He started the Belgian OWASP chapter, was an OWASP Foundation Board member, and has given numerous public presentations on Application Security.