Enquire Us

CMMI-DEV vs CMMI-SVC

CMMI-DEV and CMMI-SVC are not two separate standards. They are two views of the same model, CMMI, which is owned and administered by ISACA through the CMMI Institute. CMMI V3.0 was released in 2023 and groups its practices into domains, including Development, Services, Suppliers, Data, People, Security, Safety and Virtual. An organisation is rated by a CMMI Certified Lead Appraiser using the Benchmark appraisal method, and the resulting maturity or capability level is published in ISACA’s Published Appraisal Results System (PARS). No ISO certification body issues a CMMI rating, and there is no accreditation body sitting behind it.

What is CMMI-DEV?

CMMI-DEV is the Development view of the CMMI model. It applies to organisations that engineer a product or a system: software product companies, engineering services firms, product R and D units and systems integrators. On top of the core practice areas that every CMMI adoption uses, the Development view brings in practice areas that only make sense when you are building something:

  • Technical Solution (TS), which designs and builds solutions that meet the requirements.
  • Product Integration (PI), which assembles components into a working whole.
  • Verification and Validation (VV), which confirms that the solution was built correctly and that it does what the customer actually needs.

An appraisal against the Development view results in a rating expressed as a CMMI level for Development, for example Maturity Level 3 Development. That is the phrasing that appears in PARS and the phrasing that tender documents usually quote.

What is CMMI-SVC?

CMMI-SVC is the Services view of the same model. It applies to organisations whose output is an ongoing service rather than a delivered product: managed IT services, BPO and shared services centres, facilities and logistics operators, and support desks. The practice areas specific to this view deal with running and sustaining a service:

  • Service Delivery Management (SDM), which delivers services and manages the service delivery system.
  • Strategic Service Management (STSM), which develops standard services aligned to business needs.
  • Incident Resolution and Prevention (IRP), which resolves and prevents disruptions promptly so that service delivery continues.
  • Continuity (CONT), which anticipates and addresses disruptions to critical business operations.

A Services appraisal produces a rating such as Maturity Level 3 Services, again recorded in PARS.

CMMI-DEV vs CMMI-SVC compared

AttributeCMMI-DEVCMMI-SVC
Relationship to the modelDevelopment domain view of CMMIServices domain view of the same CMMI model
Owner of the modelISACA, through the CMMI InstituteISACA, through the CMMI Institute
Typical adopterSoftware product firms, engineering services, systems integrators, product R and D unitsManaged IT services, BPO and shared services centres, support desks, facilities and logistics operators
Practice areas specific to the viewTechnical Solution, Product Integration, Verification and ValidationService Delivery Management, Strategic Service Management, Incident Resolution and Prevention, Continuity
Core practice areasShared with every other CMMI viewShared with every other CMMI view
Assessment methodBenchmark appraisal led by a CMMI Certified Lead AppraiserBenchmark appraisal led by a CMMI Certified Lead Appraiser
ResultA maturity or capability level rating for DevelopmentA maturity or capability level rating for Services
Validity of a Benchmark ratingThree yearsThree years
Public registerISACA Published Appraisal Results System (PARS)ISACA Published Appraisal Results System (PARS)
Surveillance auditsNone. CMMI has no surveillance regimeNone. CMMI has no surveillance regime

Can an organisation hold both?

Yes. Because Development and Services are views of one model rather than competing standards, an organisation can be appraised against both. Many IT companies do exactly this: the product engineering unit is appraised against the Development view and the managed services or support unit against the Services view. The core practice areas, the appraisal method and the evidence conventions are shared, so the second view reuses most of the process infrastructure built for the first.

Two practical points to plan around. First, the appraisal is scoped to an organisational unit and to a set of projects or service instances sampled from that unit, so the scope statement matters more than the view label. Second, the rating from a Benchmark appraisal is valid for three years, so a combined appraisal keeps both views on the same renewal clock rather than two separate ones.

Which view applies to you?

Work backwards from what your organisational unit actually delivers and from what your client is asking to see.

  • Choose the Development view if the unit designs, builds, integrates and tests a product or system, and if requirements, design, integration and testing are the work that carries the risk.
  • Choose the Services view if the unit operates a service to an agreed service level, and if incident handling, capacity, service continuity and the service catalogue are where the risk sits.
  • Choose both if you run product engineering and managed services in the same organisational unit, or if different clients ask for different ratings.
  • Read the tender text carefully. A requirement that says CMMI Level 3 without naming a view is usually satisfied by either, but a requirement that names CMMI-SVC is not satisfied by a Development rating, and the reverse is also true.

Frequently Asked Questions

Is CMMI-SVC a different standard from CMMI-DEV?

No. Both are views of a single model, CMMI, which is owned and administered by ISACA through the CMMI Institute. CMMI V3.0 organises practices into domains including Development and Services. The two views share the same core practice areas and the same appraisal method, and differ in the practice areas that are specific to building a product versus running a service.

Who carries out a CMMI-DEV or CMMI-SVC appraisal?

A CMMI Certified Lead Appraiser authorised by ISACA leads the appraisal team using the Benchmark appraisal method. CMMI is not audited by ISO certification bodies, and there is no accreditation body behind it in the way there is for ISO management system certification.

How long is a CMMI rating valid, and where can it be checked?

A Benchmark appraisal rating is valid for three years. Ratings from Benchmark and Sustainment appraisals are published in ISACA’s Published Appraisal Results System (PARS), so a client can verify an organisation’s level, view and appraisal date independently. Evaluation appraisal results are not published there.

Does CMMI have Stage 1 and Stage 2 audits or annual surveillance?

No. Those are features of ISO management system certification under ISO/IEC 17021-1. A CMMI appraisal is a single appraisal event run by a Lead Appraiser against a defined organisational unit and sample, with no surveillance audits in between.

Can one appraisal cover both the Development and the Services view?

Yes. The appraisal scope can include practice areas from more than one domain, so an organisation that both builds products and operates services can be rated for both in a single exercise. The scope, the organisational unit and the sampled projects or service instances all have to be agreed with the Lead Appraiser in advance.

Which view should a managed services provider choose?

The Services view, in most cases. Its specific practice areas, Service Delivery Management, Strategic Service Management, Incident Resolution and Prevention, and Continuity, map directly to how a managed services operation is run. A provider that also builds software for clients may add the Development view for that part of the organisation.

Univate advises on both sides of this comparison across its international markets. Book a free consultation for a scoped view of what applies to your organisation.

Univate Global delivers ISO certifications, data privacy compliance, and cybersecurity frameworks across 9 markets.