Enquire Us

CMMI vs ISO 9001

CMMI and ISO 9001 are often put side by side because both are about process discipline, but they are different kinds of instrument with different owners and different assessment regimes. CMMI is a capability maturity model owned and administered by ISACA through the CMMI Institute, and an organisation is rated by a CMMI Certified Lead Appraiser using the Benchmark appraisal method. ISO 9001 is an international standard published by the International Organization for Standardization, and an organisation is certified by a certification body that is itself accredited by a national accreditation body. One produces a maturity level published in a public register, the other produces a certificate on a three year cycle.

What is CMMI?

CMMI is a model of organisational capability. Its practices are grouped into practice areas, and practice areas are grouped into domains such as Development, Services, Suppliers, Data, People, Security and Safety. CMMI V3.0 was released in 2023.

An organisation is not audited against CMMI. It is appraised. A CMMI Certified Lead Appraiser authorised by ISACA leads an appraisal team through the Benchmark appraisal method, samples projects or service instances from a defined organisational unit, and awards a rating. The staged representation produces one of five maturity levels: Initial, Managed, Defined, Quantitatively Managed and Optimizing. The continuous representation produces capability levels for selected practice areas.

A Benchmark appraisal rating is valid for three years. Benchmark and Sustainment results are published in ISACA’s Published Appraisal Results System (PARS), which is how a client verifies a claimed level. There is no accreditation body, no Stage 1 or Stage 2 audit and no annual surveillance in the CMMI scheme.

What is ISO 9001?

ISO 9001 specifies the requirements for a quality management system. The edition in force is ISO 9001:2015, the fifth edition, titled Quality management systems, Requirements. A revision is at Final Draft International Standard stage on ISO’s project page, so the designation to quote in contracts should be checked against iso.org rather than assumed.

The standard follows the harmonised structure used across ISO management system standards, with clauses covering context of the organisation, leadership, planning, support, operation, performance evaluation and improvement. It is built around a process approach, risk based thinking and the Plan Do Check Act cycle, and its measure of success is conformity of products and services and customer satisfaction.

Certification works differently from appraisal. An accredited certification body carries out a Stage 1 readiness review and a Stage 2 audit of the operating system. A certificate is normally valid for three years, subject to annual surveillance audits, with a recertification audit before the three years expire. The certification body is accredited by a national accreditation body, and accreditation bodies recognise each other through the International Accreditation Forum, which is what gives a certificate its cross border value.

CMMI vs ISO 9001 compared

AttributeCMMIISO 9001
What it isA capability maturity modelAn international management system standard
OwnerISACA, through the CMMI InstituteInternational Organization for Standardization (ISO)
Current versionCMMI V3.0, released 2023ISO 9001:2015, with a revision at Final Draft International Standard stage
SubjectCapability and maturity of engineering, service and management practicesQuality management system, conformity of products and services, customer satisfaction
AssessmentBenchmark appraisal led by a CMMI Certified Lead AppraiserStage 1 and Stage 2 certification audit by an accredited certification body
Who performs itA Lead Appraiser authorised by ISACAA certification body accredited by a national accreditation body under the IAF arrangements
ResultA maturity level from 1 to 5, or capability levels per practice areaA certificate of conformity
ValidityThree years for a Benchmark appraisal ratingThree years, subject to annual surveillance audits
Ongoing checksNone between appraisalsAnnual surveillance audits and a recertification audit
Public verificationISACA Published Appraisal Results System (PARS)The issuing certification body and its accreditation body
Graded scaleYes, maturity and capability levelsNo, conformity is pass or fail

Can an organisation hold both?

Yes, and many IT and engineering organisations do. The two are complementary rather than competing. ISO 9001 establishes the management system frame: documented information, internal audit, management review, corrective action, customer feedback. CMMI goes deeper into how engineering and service delivery work is actually performed, and it asks for quantitative management at the higher levels in a way ISO 9001 does not.

Where they overlap, the evidence is reusable. Internal audit records, management review minutes, supplier management records, training records, measurement data and corrective action records all serve both. What is not reusable is the assessment itself: an ISO 9001 audit cannot produce a CMMI rating, and a CMMI appraisal cannot produce an ISO 9001 certificate.

Which one applies to you?

  • ISO 9001 first if your buyers are procurement departments across many sectors, if you need a certificate that a purchasing officer anywhere can recognise, or if a tender names an accredited certificate as a qualification criterion.
  • CMMI first if you sell software engineering or IT services and your clients ask for a maturity level, which is common in government and defence linked IT procurement and among large enterprise buyers of engineering services.
  • Both if you need the broad recognition of an accredited certificate and the delivery credibility of a published maturity level. Sequencing ISO 9001 first is usually easier, because the management system disciplines it installs are assumed by CMMI.
  • Check who verifies the claim. A client can verify a CMMI level in PARS and can verify an ISO 9001 certificate with the certification body and its accreditation body. Claims that cannot be verified through either route should be treated with caution.

Frequently Asked Questions

Is CMMI an ISO standard?

No. CMMI is a capability maturity model owned and administered by ISACA through the CMMI Institute. It is not published by the International Organization for Standardization and it is not issued by ISO certification bodies such as BSI, SGS or Bureau Veritas.

Is a CMMI level a certification?

Strictly it is an appraisal rating, not a certificate. A CMMI Certified Lead Appraiser leads a Benchmark appraisal and the resulting maturity or capability level is published in ISACA’s Published Appraisal Results System. ISO 9001, by contrast, results in a certificate issued by an accredited certification body.

How long does each one last?

A CMMI Benchmark appraisal rating is valid for three years. An ISO 9001 certificate is normally valid for three years as well, but it is subject to annual surveillance audits by the certification body and a recertification audit before it expires. CMMI has no surveillance audits.

Does ISO 9001 have levels like CMMI?

No. ISO 9001 is a conformity standard: an organisation either meets the requirements or it does not, and there is no graded scale. CMMI reports a maturity level from 1 to 5 in the staged representation, or capability levels for individual practice areas in the continuous representation.

Which edition of ISO 9001 should we work to?

ISO 9001:2015 is the edition in force. ISO’s project page shows a revision at Final Draft International Standard stage, so before committing to a contract wording it is worth confirming the current designation on iso.org and with your certification body, along with any transition arrangements.

If we already hold ISO 9001, how much of it counts towards CMMI?

The management system evidence carries over well: internal audit, management review, corrective action, training records, supplier management and measurement data. What CMMI adds is depth in engineering and service delivery practice and, at the higher maturity levels, quantitative management of process performance. The appraisal itself is separate and cannot be combined with an ISO 9001 audit.

Univate advises on both sides of this comparison across its international markets. Book a free consultation for a scoped view of what applies to your organisation.

Univate Global delivers ISO certifications, data privacy compliance, and cybersecurity frameworks across 9 markets.