International quality standards, what they actually certify, and what they do not.
π Where this lives: ISO certification is usually a commercial requirement rather than an engineering choice β government tenders and large enterprise procurement frequently will not consider an uncertified supplier. That produces a specific and well-documented failure mode: organisations that certify the paperwork while changing nothing about how they work. Understanding what the standard does and does not guarantee is therefore practical knowledge, not bureaucratic trivia, and it is the difference between using a standard and performing it. Search "ISO 9001 certification does not guarantee product quality".
ISO 9000 and ISO 9001
The ISO 9000 FAMILY is a generic set of quality management
standards, applicable to any organisation producing anything β
software, cars, or cement. Its principle is that a documented,
followed and improved process produces consistent output.
THE KEY MEMBERS:
ISO 9000 fundamentals and vocabulary β the concepts and
the definitions
ISO 9001 the REQUIREMENTS standard, and the only one you
can be CERTIFIED against. Specifies what a
quality management system (QMS) must contain.
ISO 9004 guidance for performance improvement β advice,
not requirements
ISO 90003 guidelines for applying ISO 9001 TO COMPUTER
SOFTWARE. This is the software-specific
interpretation, and it exists because ISO 9001
speaks in manufacturing terms that need
translating.
ISO 9001 REQUIREMENTS β the areas an auditor examines:
management responsibility Β· quality system Β· contract
review Β· design control Β· document and data control Β·
product identification and traceability Β· process control Β·
inspection and testing Β· corrective and preventive action Β·
control of quality records Β· internal quality audits Β·
training Β· servicing Β· statistical techniques
THE SEVEN QUALITY MANAGEMENT PRINCIPLES underlying the modern
(2015) revision:
1. customer focus
2. leadership
3. engagement of people
4. process approach
5. improvement
6. evidence-based decision making
7. relationship management
THE CENTRAL MECHANISM is the PLANβDOβCHECKβACT cycle
(Deming/Shewhart), applied to every process:
PLAN establish objectives and the processes to deliver
them
DO implement them
CHECK monitor and measure against the objectives, and
report results
ACT take action to improve performance
ISO 9001 is essentially a requirement that PDCA be documented
and demonstrably operating.
WHAT ISO 9001 CERTIFICATION ACTUALLY MEANS β and this is the
most examinable judgement in the topic:
IT MEANS: the organisation has a documented process, it
follows the process it documented, it keeps records, and
it has a mechanism for corrective action and improvement.
IT DOES NOT MEAN: the process is a GOOD process, or that
the product is of high quality.
β An organisation can be fully certified while following a
thoroughly documented bad process consistently. ISO 9001
certifies CONSISTENCY, not EXCELLENCE. This is the
standard criticism, and it is a fair one.
THE DOCUMENTATION HIERARCHY:
QUALITY MANUAL the top-level statement of the QMS
PROCEDURES how each process is carried out
WORK INSTRUCTIONS detailed task-level guidance
RECORDS evidence that the procedures were followed
The records are what an audit actually inspects. "If it is
not written down, it did not happen" is the auditor's
operating principle.
QUALITY MANAGEMENT AND SOFTWARE DEVELOPMENT, per Sommerville:
Quality management provides an independent check on the
software development process. The quality management process
checks the project deliverables to ensure they are consistent
with organisational standards and goals. The quality team
should be INDEPENDENT of the development team so they can
take an objective view β and can report on quality without
being subject to the project's schedule pressure.
The software-specific standards
ISO/IEC 25010 β SYSTEM AND SOFTWARE QUALITY MODELS (the
successor to ISO 9126). Defines the quality characteristics that
the quality-attributes topic listed. EIGHT product quality
characteristics:
FUNCTIONAL SUITABILITY completeness, correctness,
appropriateness
PERFORMANCE EFFICIENCY time behaviour, resource
utilisation, capacity
COMPATIBILITY co-existence, interoperability
USABILITY learnability, operability, user
error protection, accessibility
RELIABILITY maturity, availability, fault
tolerance, recoverability
SECURITY confidentiality, integrity,
non-repudiation, accountability,
authenticity
MAINTAINABILITY modularity, reusability,
analysability, modifiability,
testability
PORTABILITY adaptability, installability,
replaceability
Its value is as a CHECKLIST and a shared vocabulary: a
non-functional requirements review that walks these eight
characteristics will find the categories nobody thought about.
ISO 25010 also defines QUALITY IN USE β effectiveness,
efficiency, satisfaction, freedom from risk, context coverage
β which is quality as experienced rather than as built.
ISO/IEC 12207 β SOFTWARE LIFE CYCLE PROCESSES. Defines a
comprehensive set of processes across the software life cycle,
grouped as:
agreement processes (acquisition, supply)
organisational project-enabling processes
technical management processes
technical processes (requirements, architecture, design,
implementation, integration, verification, validation,
transition, operation, maintenance, disposal)
It is a REFERENCE MODEL for processes, not a prescription of
one lifecycle β you select and tailor.
ISO/IEC 15504 / SPICE β SOFTWARE PROCESS IMPROVEMENT AND
CAPABILITY DETERMINATION. Provides a framework for assessing
process capability, now largely superseded by ISO/IEC 33000.
Rates each process on a capability scale 0β5:
0 incomplete Β· 1 performed Β· 2 managed Β· 3 established Β·
4 predictable Β· 5 optimising
Note the parallel with CMMI's levels in the next topic β the
key structural difference is that SPICE rates EACH PROCESS
SEPARATELY (a continuous representation), whereas CMMI's
staged representation gives the organisation ONE level.
OTHER STANDARDS WORTH NAMING:
ISO/IEC 27001 information security management systems β
increasingly a procurement requirement
alongside 9001
ISO/IEC 29119 software testing standards
IEEE 830 software requirements specifications (the
SRS structure from ACtE0801)
IEEE 1012 verification and validation
IEEE 828 configuration management plans (see the
CM topics ahead)
DO-178C airborne systems software; the source of
the MC/DC coverage requirement
IEC 62304 medical device software life cycle
ISO 26262 road-vehicle functional safety
What certification costs and returns
A REALISTIC PICTURE, because "should we certify?" is a genuine
decision.
THE COSTS of ISO 9001 certification for a 60-person software
organisation:
gap analysis and consultancy ~ 30 person-days
documenting processes ~ 80 person-days
training all staff 60 Γ 0.5 = 30 person-days
internal audit programme 4/yr Γ 5 = 20 person-days/yr
external certification audit ~ 8 person-days +
audit fees
annual surveillance audits ~ 4 person-days/yr
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
first-year effort β 168 person-days β 8 person-months
ongoing β 24 person-days/year
At the semi-detached productivity from the cost modelling
topic (~209 LOC/person-month at 50 KLOC), 8 person-months is
roughly 1.7 KLOC of foregone development β a real but not
enormous cost for an organisation of that size.
THE RETURNS, honestly split:
GENUINE
Β· processes get written down, which helps onboarding and
continuity β the "standards assist continuity"
argument from the SQA topic
Β· the corrective-action requirement forces root-cause
analysis, which is the statistical SQA method
Β· internal audits find process drift before customers do
Β· access to tenders that require certification, which is
often the actual reason
OVERSTATED
Β· "certified means high quality" β it does not, as
established above
Β· defect rates do not fall from certification alone; they
fall from the practices (reviews, testing, measurement)
that a good QMS happens to require
THE FAILURE MODE, named: CERTIFICATION THEATRE. The
organisation writes procedures nobody follows, and before each
audit produces the records the auditor wants to see. The cost
is paid and none of the benefit is obtained β and worse,
engineers learn that quality processes are performative, which
poisons genuine improvement efforts afterwards.
THE DIAGNOSTIC: ask whether the process documentation is
consulted between audits. If the only time anyone opens the
quality manual is when an auditor is due, it is theatre.
HOW TO CERTIFY WELL β the practical answer:
DOCUMENT WHAT YOU ACTUALLY DO, then improve it. Teams that
write aspirational procedures end up with a document that
contradicts reality, and then must either change reality or
falsify records. Teams that document current practice get a
truthful baseline that PDCA can then improve β which is
what the standard was designed for.
ISO vs CMMI, the comparison examiners like:
ISO 9001 generic, applies to any industry;
PASS/FAIL certification; audited by an external
registrar; asks "do you follow your documented
process?"
CMMI software/systems specific; a MATURITY LEVEL
1β5, so it measures degree rather than
compliance; appraised against defined practice
areas; asks "how capable is your process?"
They are complementary rather than competing: ISO 9001 asks
whether you are consistent, CMMI asks how good you are, and
an organisation can hold both.
The distinction to carry: ISO 9001 certifies that you follow the process you wrote down, not that the process is any good. A thoroughly documented bad process, consistently followed, passes the audit. That is not a reason to dismiss the standard β consistency is genuinely valuable β but it is why certification and quality are different claims.
π Go further: the practice that turns documented process from theatre into something real is compliance as code. Instead of a procedure stating that all changes are reviewed, branch protection makes an unreviewed merge impossible; instead of a record asserting that tests were run, the CI log is the immutable evidence; instead of an access-control procedure, the infrastructure definition is the access control. The audit trail becomes a by-product of doing the work rather than a separate activity β which removes the gap between what the manual says and what happens. Search "compliance as code audit evidence CI pipeline".
π‘ Exam angle: distinguish the members of the ISO 9000 family β 9000 (vocabulary), 9001 (the certifiable requirements standard), 9004 (improvement guidance), 90003 (applying 9001 to software). State the PDCA cycle and the areas ISO 9001 covers. The most likely discussion question is what certification does and does not guarantee β that it certifies consistency and documented process, not product quality. Know ISO 25010's eight quality characteristics, that ISO 12207 defines life cycle processes, and that ISO 15504/SPICE rates capability 0β5 per process. Be able to compare ISO 9001 with CMMI: generic vs software-specific, pass/fail vs maturity level.
Syllabus points
ISO 9000/9001 for software
Create a free account to tick topics off, take notes as you read, watch the video lessons and get a day-by-day study plan built around your exam date.
Related topics in Testing, Cost Estimation, Quality & Configuration Management