SAMM
The Software Assurance Maturity Model: ninety activities across five business functions, measuring how software security is actually practised rather than which tools are owned.
Mapped, monitored, and audit-ready.
Every SAMM control has a place in Talarity — with cross-mapping, automated evidence, and continuous validation.
Talarity's pre-built control library covering SAMM, with linked evidence, owners, and testing schedules.
Answer once, prove everywhere. Talarity's mapping engine reuses your evidence across every framework you run.
- SAST / DAST / SCA scan output
- Secure design and threat-model records
- Training completion records
- Vulnerability remediation metrics
- Release and change approvals
Your SAMM dashboard
Every completed SAMM assessment updates this automatically — where you stand now, how that has changed, and which areas need work.
What gets easier with Talarity.
SAMM assessments are run in a spreadsheet once and never repeated.
Each run is stored, scored and trended, so the second assessment is a comparison rather than a fresh start.
Scores are asserted without evidence, which makes them unusable with an auditor or a board.
Activities carry attached evidence, and the score reflects what is substantiated.
SAMM and SSDF are maintained as two separate efforts.
They are cross-mapped, so evidence gathered against one is available to the other.
SAMM — common questions
- What are the five business functions?
- Governance, Design, Implementation, Verification and Operations — each with its own security practices and activity streams.
- Does Talarity score SAMM's maturity levels?
- Yes. Activities roll up per practice and business function, and the dashboard shows the current position plus the trend across previous assessments.
- Is SAMM a certification?
- No. It is an open maturity model published by OWASP. It is used to measure and improve a programme, and its output is often referenced in SOC 2 and ISO 27001 work.
Working with SAMM
Step-by-step walkthroughs from the Talarity library.
- Compliance·8 min readPackage your audit evidence once — for the auditor, regulator, or customerAn auditor asks for your evidence and it's scattered across framework reports, vendor attestations, policy sign-offs, and resilience tests. Evidence Distribution Packages assemble the signed artifacts you already produced into one immutable package, then hand it to each audience as a redacted, watermarked, time-limited copy — with a record of who received what.
- Compliance·7 min readFramework readiness to audit package — the whole cycle on one screenAudit prep usually means a spreadsheet scramble — chasing evidence, tracking which controls are covered, re-checking what's expired. Talarity keeps a live readiness picture for every framework (SOC 2, ISO 27001, CIS, and more) — coverage, gaps, evidence freshness — and packages it into an auditor-ready export in one click.
- Compliance·7 min readContinuous compliance is a tooling problem, not a process problemEvery compliance program eventually decides it needs to be 'continuous.' Most then try to fix it with process. The actual fix is upstream — in the tools that make evidence freshness a default, not a sprint.
- Compliance·14 min readThe evidence nobody can deleteA legal hold is a promise that a specific piece of evidence will still exist months from now, made to people who will check. This is where you place one in Talarity, what the record has to survive, and — just as important — what a hold does not freeze.
Ready to ship SAMM?
Start a 7-day trial and run this framework end-to-end on your own evidence — then buy online in-app when you're ready.