BSIMM16 Report
An analysis of the top software security initiatives
Building Security in Maturity Model (BSIMM) is a data-driven model developed through the analysis of real-world software security initiatives. For the 16th edition of our report, we analyzed the software security practices of 111 organizations across a variety of verticals. This report identifies the key trends and activities of your peers in these organizations to help you benchmark your own program. See how companies are addressing trends such as
- AI adoption in software development
- Software supply chain risk management and SBOM creation
- Regulatory compliance and self-attestation requirements
- The evolution of traditional security training to just-in-time and open collaboration
Download the latest BSIMM
What's Inside
The BSIMM16 report, published in January 2026, represents the latest evolution of this detailed measuring stick for software security. Through the analysis of these software security initiatives, the BSIMM16 report reveals
- The top 12 software security activities being used today
- AI continues to be a major focus for organizations and is driving new standards for technology adoption
- Notable growth in SBOM creation, driven by U.S. government self-attestation requirements
- Key actions organizations can take to improve their application security programs
FAQ
Building Security in Maturity Model (BSIMM) is the industry’s most comprehensive framework for measuring and benchmarking software security programs. It is a descriptive model that depicts real-world practices from organizations implementing successful software security initiatives (SSIs). Rather than a prescriptive, one-size-fits-all approach, BSIMM enables organizations to assess their current maturity level and compare it to organizations that have successfully built and evolved their software security programs. Organizations use BSIMM throughout their security journey—whether they’re establishing a new SSI from scratch or evolving mature programs to address emerging threats and technologies. The model provides a common vocabulary and methodology that facilitates communication with executives, board members, customers, partners, and regulators, and demonstrates concrete progress in securing the software development life cycle (SDLC). By grounding security strategy in observable, proven practices rather than theoretical “best practices,” BSIMM delivers actionable insights that drive meaningful improvements in your organization’s software security posture.