This document discusses 10 tips for benchmarking a software security program: 1) Use a commonly accepted methodology; 2) Evaluate real-world conditions, not just theory; 3) Learn from industry leaders; 4) Verify your starting point with detailed assessments; 5) Beware of inflated self-assessments and get an outside perspective; 6) Consider both overall results and specific strengths/weaknesses; 7) View results in your business context; 8) Devote time to analyzing results to plan next steps; 9) Communicate results to leadership to gain support; and 10) Re-assess every 2 years while also monitoring progress continuously. Benchmarking against other organizations provides meaningful context to improve software security strategies.