CMMI Maturity and Capability Levels

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Two views

Maturity Levels (staged)

Organization-wide. One rating across the org.

Capability Levels (continuous)

Per process area. Different ratings per area.

Five maturity levels (staged)

Level 1 โ€” Initial

Ad hoc, chaotic, depends on individual heroes. Some processes work; success depends on individual effort.

Level 2 โ€” Managed

Project-level discipline. Requirements managed, work planned, performance tracked.

Process areas (CMMI Development v2.0 examples):

  • Estimating
  • Planning
  • Monitor and Control
  • Supplier Agreement Management
  • Requirements Development and Management
  • Configuration Management
  • Process Quality Assurance
  • Measurement and Analysis

Level 3 โ€” Defined

Standard processes for the org. Tailored per project from organizational standard.

Additional process areas:

  • Decision Analysis and Resolution
  • Risk Management
  • Verification and Validation
  • Product Integration
  • Technical Solution
  • Governance
  • Implementation Infrastructure

Level 4 โ€” Quantitatively Managed

Quantitative process management. Statistical control. Sub-process performance objectives.

Process areas:

  • Causal Analysis and Resolution
  • Managing Performance and Measurement
  • Quantitative process management

Level 5 โ€” Optimizing

Continuous quantitative improvement based on understanding common causes of variation.

CMMI 3.0 changes

  • Streamlined process areas for clarity.
  • Cybersecurity capability area added.
  • Data management capability area added.
  • Sustainability dimension.
  • Workforce capability area.
  • Safety capability area.
  • Agile-friendly terminology.

Appraisal levels

Org achieves a maturity level rating via appraisal:

  • Benchmark Appraisal โ€” formal rating; valid 3 years.
  • Sustainment Appraisal โ€” between benchmarks.
  • Evaluation Appraisal โ€” lighter assessment.

Certified Lead Appraiser conducts. Results published in CMMI Institute database (if org consents).

Capability Level scoring per process area

For each process area:

  • Level 0 Incomplete
  • Level 1 Performed
  • Level 2 Managed
  • Level 3 Defined
  • Higher levels possible

Capability views support targeted improvement.

Cross-references

CMMI vs ASPICE

  • Common SPICE roots.
  • ASPICE auto-specific; CMMI general.
  • Both use SPICE-style capability levels.

CMMI vs ITIL

  • CMMI for Services overlaps ITIL.
  • ITIL operational; CMMI process maturity.
  • Combined adoption common in service-management contexts.

CMMI vs ISO 27001

  • Limited direct overlap.
  • ISO 27001 InfoSec management; CMMI process maturity.
  • CMMI 3.0 cybersecurity capability area provides bridge.

US DoD procurement signal

CMMI Level 3+ historically common DoD contractor requirement:

  • DoD acquisition programs reference CMMI.
  • Defense Federal Acquisition Regulation Supplement (DFARS) references.
  • CMMC complements (cybersecurity-specific).

SRE and AI-agent fit notes

For US DoD / aerospace contexts:

  • CMMI vocabulary load-bearing.
  • AI features in CMMI scope if delivering software.

For non-DoD:

  • Limited applicability.
  • SPICE-equivalent maturity discipline available via other frameworks.

Stefan-context implementation sketch

  • Limited direct relevance.
  • For US-aerospace-adjacent clients: CMMI familiarity useful.

See also