When you need it
Security in your delivery process depends on who is working that week. Some repositories run scanners and others do not, nobody owns the exceptions, and when a customer asks how you build secure software, the answer is a promise rather than evidence.
What sets the quote
- Sized from counts you already know: teams, engineers, CI platforms and active repositories.
- One week: up to 5 teams or 50 engineers, one CI platform and 10 sampled repositories.
- Two weeks: up to 15 teams or 150 engineers, up to 2 CI platforms and 20 sampled repositories.
- Larger organisations, or more CI platforms, are quoted after the call.
What changes
- You know the current and target maturity level for each OWASP SAMM practice, backed by evidence from your repositories and pipelines rather than interviews alone.
- You can answer customer questions about secure development with a practice-by-practice mapping to NIST SSDF.
- You know which gaps need tools and which need ownership, habits or time.
- You have a 90-day plan ordered by risk and effort, ready for your backlog.
What you get
- OWASP SAMM scorecard with the current and target level for each security practice
- NIST SSDF (SP 800-218) mapping that shows which practices are in place, partly in place or missing
- Gap list with evidence, a suggested owner and the effort for each gap
- 90-day plan ordered by risk and effort
- One-page summary for management
- All gaps as a CSV file for your ticket system
- A 90-minute readout with your engineering and security leads
The gap check shows where to start. When the biggest gaps sit in the pipelines, the usual next step is a pipeline security check or a secure CI/CD pipeline. When they sit in ownership and habits, it is the DevSecOps operating model.
Not included
- Closing the gaps (quoted separately, often as a secure CI/CD pipeline or a DevSecOps operating model)
- Penetration testing (we can refer you to a certified partner)
- Application code review
- Compliance certification or audit opinions
What we need from you
- Read access to the sampled repositories and their pipelines, for example the Read role on GitHub, Reporter on GitLab or the Readers group in Azure DevOps.
- A 45-minute screen-share with a CI platform admin to walk through the organisation settings that read-only roles cannot see.
- 45-minute interviews with your engineering lead, your security owner and a sample of team leads: up to 5 in one week and up to 10 in two weeks.
- Your secure development guidelines or policies, if you have them.
How it works
Free 30-minute call, then a written fixed quote based on your team, engineer and repository counts.
Interviews based on the OWASP SAMM assessment questions.
Evidence checks in the sampled repositories and pipelines, then a score per practice and agreed target levels.
Gap list, 90-day plan and a 90-minute readout.
At a glance
- Duration
- 1–2 weeks
- Price
- Fixed quote after a free 30-minute call
- Delivered by
- Our lead architect
Related services
Pipeline security check
A one-week review of one CI/CD platform, from organisation settings to runners and secrets, with findings mapped to the OWASP Top 10 CI/CD Security Risks and SLSA.
Keyless pipelines and secrets cleanup
Your pipelines move from long-lived cloud keys to short-lived federated tokens, with secret scanning and dependency gates that stop new leaks and risky dependencies before merge.
Secure CI/CD pipeline
A pipeline that scans every change, builds each image once, promotes it by digest and asks for approval before production, for one app in 2–3 weeks or up to 10 repositories in 4–5 weeks.