A five-level ladder for how capable a development organisation actually is.
π Where this lives: CMMI shaped the global software outsourcing industry. When Indian software firms competed for US and European contracts in the 1990s and 2000s, a CMMI Level 5 appraisal was the credential that made a company credible at scale, and hundreds achieved it. That history is also the source of the main criticism β that some organisations optimised for the appraisal rather than for capability. Both things are true, and understanding the model well enough to see the difference is the point of studying it. Search "CMMI level 5 appraisal criticism process improvement".
The model and its levels
CMMI β the CAPABILITY MATURITY MODEL INTEGRATION, from the
Software Engineering Institute at Carnegie Mellon, successor to
the original CMM (1991). It is a PROCESS IMPROVEMENT framework:
it describes what a capable process looks like, without
prescribing how to achieve it.
THE UNDERLYING PREMISE: the quality of a software product is
largely determined by the quality of the process used to
develop it. Improve the process and the product improves
β repeatably, rather than by heroics.
THE FIVE MATURITY LEVELS (the STAGED representation):
LEVEL 1 β INITIAL
The process is ad hoc and occasionally chaotic. Few processes
are defined and success depends on INDIVIDUAL EFFORT AND
HEROICS. Schedules and budgets are typically exceeded.
β Every organisation is at Level 1 by default; it is not an
achievement but a starting point. Note that Level 1
organisations can and do ship good software β but they
cannot do it PREDICTABLY, and cannot say in advance whether
the next project will go well.
LEVEL 2 β MANAGED (originally "Repeatable")
Basic project management processes are established to track
cost, schedule and functionality. The necessary process
discipline is in place to REPEAT EARLIER SUCCESSES on
projects with similar applications.
β the key word is PROJECT. Discipline exists per project, and
practices may differ between projects.
Process areas: requirements management, project planning,
project monitoring and control, supplier agreement
management, measurement and analysis, process and product
quality assurance, configuration management.
LEVEL 3 β DEFINED
The process for both management and engineering activities is
DOCUMENTED, STANDARDISED AND INTEGRATED into an
ORGANISATION-WIDE standard software process. All projects use
an approved, tailored version of that process.
β the shift from Level 2 to Level 3 is from PROJECT-level
discipline to ORGANISATION-level. This is the level most
commonly targeted, and the biggest single jump in effort.
Process areas add: requirements development, technical
solution, product integration, verification, validation,
organisational process focus and definition, organisational
training, integrated project management, risk management,
decision analysis and resolution.
LEVEL 4 β QUANTITATIVELY MANAGED
Detailed measures of the software process and product quality
are collected. Both are QUANTITATIVELY UNDERSTOOD AND
CONTROLLED using statistical techniques.
β the shift is to STATISTICAL control: you know the mean and
the variance of your process, so you can predict outcomes
with stated confidence rather than hoping.
Process areas: organisational process performance,
quantitative project management.
LEVEL 5 β OPTIMISING
CONTINUOUS PROCESS IMPROVEMENT is enabled by quantitative
feedback from the process and from piloting innovative ideas
and technologies.
β the organisation deliberately experiments, measures the
result, and adopts what works. Defect causes are
systematically analysed and prevented.
Process areas: organisational performance management, causal
analysis and resolution.
THE PROGRESSION IN ONE LINE EACH:
1 unpredictable Β· 2 disciplined per project Β·
3 standardised across the organisation Β·
4 measured and statistically controlled Β·
5 continuously improving
THE LEVELS ARE CUMULATIVE β you cannot be Level 4 without
satisfying Levels 2 and 3.
The two representations, and the structure
CMMI offers TWO REPRESENTATIONS of the same content, and the
distinction is regularly examined:
STAGED REPRESENTATION
The organisation is assessed and given a single MATURITY
LEVEL 1β5. Process areas are grouped into levels, and you
must satisfy all process areas at a level (and below) to
claim it.
β a single, comparable number β which is why procurement
likes it
β a predefined improvement roadmap: you know what to do next
β forces you to improve areas you may not need yet, in order
to reach the next level
CONTINUOUS REPRESENTATION
Each PROCESS AREA is separately rated on a CAPABILITY LEVEL
(0 incomplete, 1 performed, 2 managed, 3 defined). An
organisation gets a PROFILE across process areas rather than
one number.
β improve the areas that matter to your business first
β finer-grained and more honest
β no single number to advertise, and profiles are hard to
compare between organisations
β this is the representation that matches ISO 15504/SPICE.
THE STRUCTURE OF THE MODEL:
PROCESS AREAS a cluster of related practices in an
area (e.g. Configuration Management,
Risk Management). CMMI-DEV defines
around 22 of them.
SPECIFIC GOALS unique to a process area β what that
area must achieve
SPECIFIC PRACTICES the activities that achieve a specific
goal
GENERIC GOALS apply to multiple process areas β
concerned with institutionalising the
practices
GENERIC PRACTICES the activities that achieve generic
goals, such as providing resources,
assigning responsibility, training
people, and monitoring
THE GENERIC GOALS ARE THE INTERESTING PART: they are what
distinguish "we did this once" from "this is how we work".
A practice performed but not resourced, trained, monitored
and reviewed is not institutionalised, and CMMI will not
credit it.
CMMI CONSTELLATIONS β CMMI-DEV (development), CMMI-ACQ
(acquisition), CMMI-SVC (services).
APPRAISAL is done using SCAMPI (Standard CMMI Appraisal Method
for Process Improvement), with classes A, B and C at
decreasing rigour and cost. Only a SCAMPI A appraisal produces
a published maturity level rating.
What moving up a level actually buys β and costs
THE PUBLISHED EVIDENCE, in the form organisations report it.
Typical findings when moving from Level 1 to Level 3 or higher
include reduced schedule variance, reduced defect density, and
improved productivity β with the largest effects on
PREDICTABILITY rather than on raw speed.
WORKED β what "predictability" means numerically. Consider two
organisations each estimating ten projects at 100 person-months:
LEVEL 1: actual outcomes (person-months)
62, 88, 95, 110, 134, 141, 158, 176, 203, 233
mean = 140.0
deviations from the mean: β78, β52, β45, β30, β6, 1,
18, 36, 63, 93
sum of squared deviations = 25,988
variance = 25,988/10 = 2,598.8
standard deviation = β2,598.8 = 50.98
coefficient of variation = 50.98/140.0 = 0.364
LEVEL 4: actual outcomes
104, 108, 112, 115, 118, 121, 124, 127, 131, 140
mean = 120.0
variance = 108.0, standard deviation = 10.39
coefficient of variation = 10.39/120.0 = 0.087
THE MEAN BARELY MOVED β 140 to 120, a 14.3% improvement in
average effort. THE VARIABILITY COLLAPSED β a standard
deviation of 50.98 down to 10.39, very nearly FIVE TIMES
tighter, and the coefficient of variation fell from 0.364 to
0.087, a factor of 4.2.
WHY THAT MATTERS MORE THAN THE MEAN: with Ο = 51, a
commitment to deliver in 150 person-months has a real chance
of needing 230 β the worst observed outcome is 1.8Ο above the
mean. To promise a date safely you must pad enormously, so
your quoted price is uncompetitive even though your average
cost is fine. With Ο = 10.4, a commitment of 150 sits
2.9Ο above the Level 4 mean of 120, so essentially nothing
exceeds it β the SAME quoted figure that was reckless at
Level 1 is now safe. PROCESS MATURITY BUYS THE ABILITY TO MAKE
PROMISES β which is exactly what a customer is paying for,
and why maturity levels matter commercially.
THE COSTS, honestly:
Β· reaching Level 3 is commonly a multi-year programme with
a dedicated process group
Β· appraisal itself is expensive, and must be renewed
Β· documentation and measurement overhead falls on
engineers, who will resent it if it produces nothing they
can use β which is the standards problem from the SQA
topic
Β· SMALL ORGANISATIONS may find the overhead
disproportionate; CMMI was designed with large defence
contractors in mind
THE CRITICISMS, which you should be able to state:
Β· IT MEASURES PROCESS, NOT OUTCOME. An organisation can be
Level 5 and build a product nobody wants. Maturity is
about predictability, not about product judgement.
Β· APPRAISAL GAMING. Where a level is a contractual
requirement, the incentive is to obtain the rating rather
than the capability β the same failure mode as
certification theatre.
Β· IT CAN DISCOURAGE ADAPTABILITY if interpreted as
"document everything and never deviate". The model does
not require that, but rigid implementations do.
Β· POOR FIT WITH SMALL, FAST-CHANGING PRODUCT WORK, where
the cost of process documentation is high relative to
team size.
CMMI AND AGILE β the reconciliation, since students often
assume they conflict. They address different questions: agile
methods are a set of PRACTICES, CMMI is a framework for
assessing CAPABILITY. An agile team can satisfy CMMI process
areas β a definition of done is process and product quality
assurance, a retrospective is causal analysis and resolution, a
burndown chart is project monitoring and control, and version
control with CI is configuration management. The SEI published
guidance specifically on this. What CMMI demands is that the
practice be INSTITUTIONALISED β resourced, trained, monitored β
which is a fair demand of any practice.
The variance result is the one to remember. Moving from Level 1 to Level 4 improved the average effort by only 14% but tightened the standard deviation eightfold. Customers are not buying your average; they are buying a date you can commit to β which is why predictability, not speed, is what maturity delivers.
π Go further: the empirical successor to CMMI's question is the DORA programme's four metrics β deployment frequency, lead time for changes, change failure rate, time to restore service β which classify organisations as Elite through Low performers. The important finding is that these are not a trade-off: the fastest organisations also have the lowest change failure rates, contradicting the intuition that speed costs stability. Where CMMI asks how mature your process documentation is, DORA measures outcomes at the delivery boundary β and it reached a similar conclusion by a very different route, that disciplined process and good outcomes travel together. Search "DORA elite performers speed and stability not a tradeoff".
π‘ Exam angle: name and describe all five maturity levels β initial, managed/repeatable, defined, quantitatively managed, optimising β with the defining characteristic of each; this is the single most asked question in the topic. Be precise about the Level 2 β 3 shift (project-level to organisation-wide) and the Level 3 β 4 shift (to statistical control). Distinguish the staged representation (one maturity level, comparable) from the continuous representation (a capability profile per process area). Explain the model's structure β process areas, specific goals and practices, generic goals and practices β and note that generic goals are about institutionalisation. Be ready to state the criticisms and to compare CMMI with ISO 9001.
Syllabus points
CMMI maturity levels
Create a free account to tick topics off, take notes as you read, watch the video lessons and get a day-by-day study plan built around your exam date.
Related topics in Testing, Cost Estimation, Quality & Configuration Management