Skip to content
Opens in a new window
#08 - 08 - DSOMM - DevSecOps Maturity Model
29 July 2026

#08 - 08 - DSOMM - DevSecOps Maturity Model

DevSecOps Podcast

About
How mature is your DevSecOps program, and how do you know what to improve next?
In this episode, we talk with Timo Pagel, creator of DSOOM, the DevSecOps Maturity Model, about why organizations need structured guidance to build security into software development without turning maturity into a bureaucratic checkbox exercise.
We explore why many companies delay maturity assessments until their development environment becomes difficult to control, how security evaluations should reflect each organization’s actual context, and why copying a generic framework rarely produces meaningful improvement.
Timo also shares how DevSecOps maturity models must evolve as AI becomes part of everyday software development. As teams increasingly rely on AI-assisted coding, maturity models need to address new risks, practices, and responsibilities associated with AI-generated code.
The conversation also covers a topic that maturity models often ignore: failure. Progress does not come from pretending every initiative worked perfectly. It comes from learning what failed, adapting the approach, and using those lessons to build stronger and more resilient engineering practices.
A practical conversation about DevSecOps maturity, realistic assessments, AI-assisted development, organizational growth, and the value of learning from mistakes.


Become a supporter of this podcast: https://www.spreaker.com/podcast/devsecops-podcast--4179006/support.

Apoio: Nova8, Snyk, Conviso, Gold Security, Digitalwolk e PurpleBird Security.