SAMMY works best on screens 1024px wide or larger.

Assess maturity.
Prove compliance.
Manage product risk.

SAMMY turns OWASP SAMM and other security, risk, and compliance frameworks into clear, measurable actions. See where you stand, build SMART improvement plans, and demonstrate progress, all in one platform.

Free forever plan · No credit card required

SAMMY maturity assessment view

What you can do with SAMMY

One platform for maturity, risk and compliance

The same structure, scoring, and reporting run across every workflow, so a maturity assessment, a threat model, and a supplier audit all roll up into one view of your posture.

Maturity

Assess process maturity

Review, audit, and manage your security posture against industry standards, then demonstrate compliance with clear evidence.

  • Benchmark against OWASP SAMM and 25+ frameworks
  • Build SMART improvement plans
  • Demonstrate compliance to auditors and customers
Includes 3 scopes Free plan Compare plans →

Product risk

Model product threats

Run structured, repeatable threat analysis to understand where your product is exposed, and track how you address it.

  • Structured analysis of product risk
  • Repeatable workflow your whole team can follow
  • Link findings back to your maturity plan
Includes 1 product Free plan Compare plans →

Supply chain

Manage supply chain risk

Audit your suppliers and vendors against your own standards, and keep a live view of third-party risk across the organization.

  • Structured supplier and vendor audits
  • One central view of third-party risk
  • Roll supplier risk into your reporting
Available on Premium See plans →

Security teams worldwide run on SAMMY

Trusted to manage security, risk, and compliance programs at organizations of every size.

5+

Years active

4,000+

Organizations using SAMMY

10,000

Users on SAMMY

140,000+

Assessments run with SAMMY

Latest in SAMMY

Two highlights worth a closer look

SAMMY MCP

Plug SAMMY into your favorite LLM

Our MCP connector links SAMMY to any large language model, so you can push and pull your assessment data and put your AI tools to work on it: draft improvement plans, summarize gaps, generate reports, and answer questions about your posture in seconds.

Explore the MCP connector →
SAMMY

Assessment data

MCP

Connector

Your LLM

Any model

CRA compliance

Manage and demonstrate CRA compliance

The EU Cyber Resilience Act is here. SAMMY walks you through the requirements, tracks your evidence as you go, and produces the documentation you need to show conformity.

  • Review CRA requirements
  • Demonstrate compliance with evidence
  • Generate legal documentation
Explore CRA compliance →

Trusted by industry experts

Built by the key people behind OWASP SAMM

The leading OWASP SAMM assessment tool

SAMMY grew out of OWASP SAMM as an assessment tool, and it is now the leading OWASP SAMM platform used by organizations across the world. OWASP SAMM is the preferred maturity framework for assessing software development. The Codific team doesn't just use these standards, we help build them, contributing to both OWASP SAMM and the OWASP Top 10.

Aram Hovsepyan
Aram Hovsepyan

OWASP EU Founding Board Member · OWASP SAMM Core Team

Founder and CEO, Codific · PhD, Application Security

Brian Glas
Brian Glas

OWASP Top 10 Project Leader · OWASP SAMM Core Team

Application Security Leader · VP of Consulting Services

Comprehensive framework support

SAMMY adapts to a wide range of security frameworks, maturity models, and quality management systems, with mappings that let you assess once and report across many.

Program and maturity frameworks

OWASP SAMM NIST SSDF NIST CSF 2.0 NIST SP 800-34 CCB CyberFundamentals 2.0 DevSecOps Maturity Model BSIMM 15 NIS2 AI Maturity Model (AIMA) CMMC ISO 27001:2022 IEC 62443-4-1 Cyber Resilience Act PCI DSS v4.0.1 ASPICE CS NIST SP 800-161 (coming soon)

Control frameworks

OWASP ASVS Secure Controls Framework NIST SP 800-53 NIST SP 800-171 ISO 27002:2022 Cloud Controls Matrix CIS Critical Security Controls

Framework mappings

  1. 1 Standard mappings through the OpenCRE project
  2. 2 High-quality direct mappings between frameworks
  3. 3 Ultra-high-quality direct mappings with automated gap analysis across frameworks
Browse all frameworks →

* Subject to licensing limitations

Product Risk and Compliance

Do PRC right with SAMMY

Product risk and compliance shouldn't live in scattered spreadsheets. SAMMY brings maturity assessments, threat modeling, supplier risk, and regulatory compliance into one place, so you can see your whole security posture, act on it, and prove it. One platform. One source of truth. Built by the people who help write the standards.

Free forever plan · No credit card required

SAMMY mascot giving a thumbs up