Skip to content
Framework · OWASP v2

SAMM

The Software Assurance Maturity Model: ninety activities across five business functions, measuring how software security is actually practised rather than which tools are owned.

90 Talarity controls mapped
Who it's for: Organisations building software that need a defensible, published model for measuring their secure-development programme.
Talarity coverage

Mapped, monitored, and audit-ready.

Every SAMM control has a place in Talarity — with cross-mapping, automated evidence, and continuous validation.

90
Talarity controls mapped

Talarity's pre-built control library covering SAMM, with linked evidence, owners, and testing schedules.

Cross-maps to
NIST SSDFISO 27001SOC 2

Answer once, prove everywhere. Talarity's mapping engine reuses your evidence across every framework you run.

Automated evidence
  • SAST / DAST / SCA scan output
  • Secure design and threat-model records
  • Training completion records
  • Vulnerability remediation metrics
  • Release and change approvals

Your SAMM dashboard

Every completed SAMM assessment updates this automatically — where you stand now, how that has changed, and which areas need work.

Click to enlarge
The Talarity dashboard for a completed OWASP SAMM assessment: the latest score, the trend across previous assessments, and a breakdown by control area
Common pain points

What gets easier with Talarity.

Pain

SAMM assessments are run in a spreadsheet once and never repeated.

Talarity

Each run is stored, scored and trended, so the second assessment is a comparison rather than a fresh start.

Pain

Scores are asserted without evidence, which makes them unusable with an auditor or a board.

Talarity

Activities carry attached evidence, and the score reflects what is substantiated.

Pain

SAMM and SSDF are maintained as two separate efforts.

Talarity

They are cross-mapped, so evidence gathered against one is available to the other.

SAMM — common questions

What are the five business functions?
Governance, Design, Implementation, Verification and Operations — each with its own security practices and activity streams.
Does Talarity score SAMM's maturity levels?
Yes. Activities roll up per practice and business function, and the dashboard shows the current position plus the trend across previous assessments.
Is SAMM a certification?
No. It is an open maturity model published by OWASP. It is used to measure and improve a programme, and its output is often referenced in SOC 2 and ISO 27001 work.

Working with SAMM

Step-by-step walkthroughs from the Talarity library.

Ready to ship SAMM?

Start a 7-day trial and run this framework end-to-end on your own evidence — then buy online in-app when you're ready.