Assess an architecture's control completeness against OWASP ASVS and an organization's security-practice maturity against OWASP SAMM. Use when a design review needs to state *how much* verification is enough (ASVS level) and whether secure-architecture practice is repeatable or one-off (SAMM maturity) — not just a single design's threats and controls.