CMMI(Capability Maturity Model Integration)는 카네기 멜런 대학교 SEI(Software Engineering Institute)가 1991년 CMM 첫 발행·2002년 v1.1 CMMI 통합·2010년 v1.3·2018년 V2.0·2023년 12월 V3.0 (현재) 발행한 SW·시스템 엔지니어링 능력 성숙도 모델이다. 2018년부터 ISACA(Information Systems Audit and Control Association)·CMMI Institute 운영. 자발적 모델이지만 글로벌 SW·시스템·SI·SaaS·임베디드·자동차·항공·방산·통신·금융 IT 사실상 표준. 전 세계 약 11,000+ 조직 평가 — 인도 IT 산업 가장 강력 채택(TCS·Infosys·Wipro·HCL·Tech Mahindra Maturity Level 5+) + 미국 정부 입찰·국방 (CMMI Level 3+ 우대) + 글로벌 Boeing·Airbus·Lockheed·KAI·BAE·Northrop·NASA·Samsung·LG·SK·NAVER·카카오·LG CNS·삼성SDS·KT·SKT.
핵심은 CMMI가 SW·시스템 엔지니어링의 글로벌 단일 성숙도 모델이라는 점이다. 5 Maturity Levels (조직 차원):
- Level 1 — Initial (Ad-hoc·Unpredictable)
- Level 2 — Managed (Project Level·Reactive)
- Level 3 — Defined (Organization Level·Proactive)
- Level 4 — Quantitatively Managed (Measured·Controlled)
- Level 5 — Optimizing (Continuous Improvement)
6 Categories (V3.0):
- Doing (Engineering, Service Delivery, Selecting and Managing Suppliers, Ensuring Quality)
- Managing (Planning and Managing Work, Managing Business Resilience, Managing the Workforce)
- Enabling (Supporting Implementation, Managing Safety, Managing Security)
- Improving (Sustaining Habits and Persistence, Improving Performance)
- Sustaining (Sustaining Habits and Persistence)
- Building Workforce (People)
30 Practice Areas (PA) — Estimating·Planning·Monitor·Risk·Configuration·Verification·Validation·Process Quality·Decision Analysis·Requirements·Design·Product Integration·Technical Solution·Supplier Selection·Agreement·CCO·Service Delivery·Strategic Service Management·Continuity·Incident Resolution·Capacity·Workforce·Organizational Training·Governance·Implementation Infrastructure·Process Asset Development·Continuous Improvement·Managing Performance·Causal Analysis·Resolution. V3.0 신규 — Safety·Security PA + Workforce·Resilience 강화. Appraisal Method — Benchmark·Sustainment·Action·Evaluation. ISO 20000·ISO 27001·ISO 22301·DevSecOps·Agile·SCRUM 100% 정합. 한국 CMMI: 삼성SDS·LG CNS·SK C&C·KT M&S·NHN Cloud·NAVER Cloud·카카오엔터프라이즈·핸디소프트·다우데이타·NICE·LG U+·LIG넥스원·한화에어로스페이스·KAI·현대모비스·LG전자 임베디드 등 200+ 한국 조직 CMMI 보유. 본 가이드는 적용 결정·범위 → Maturity Level·6 Categories·30 PA → Implementation·Process Asset → Appraisal·인증 → ISO·DevSecOps·Agile 통합 5단계 로드맵으로, 중소·중견 한국 SW·시스템 엔지니어링 기업이 9~18개월 내 CMMI Level 2·3 + 글로벌 SW 진출하는 실무 경로를 제시한다.
왜 CMMI를 도입해야 하는가
글로벌 SW·시스템 엔지니어링 단일 성숙도 모델
- 11,000+ 평가 (글로벌)
- 인도 IT 100+ Maturity Level 5
- 미국 정부 입찰 우대 (Level 3+)
- 글로벌 항공·방산·자동차·통신·금융 IT 사실상 표준
CMMI는 SW·시스템 엔지니어링 글로벌 우산.
CMMI V3.0 (2023) 주요 변화
- Cybersecurity PA: Managing Security 신규
- Safety PA: Managing Safety 신규
- Workforce: Building Workforce Category 강화
- Resilience: Managing Business Resilience 강화
- People CMM 통합
- DevSecOps·Agile·SAFe·SCRUM 정합 강화
- Cloud·SaaS·AI/ML 추가
5 Maturity Levels
| Level | 명칭 | 특징 |
|---|---|---|
| 1 | Initial | Ad-hoc·Unpredictable·Reactive |
| 2 | Managed | Project Level·Basic·Reactive |
| 3 | Defined | Organization Level·Standard·Proactive |
| 4 | Quantitatively Managed | Statistical·Measured·Controlled |
| 5 | Optimizing | Continuous Improvement·Innovation |
각 Level 누적 — Level 3 = Level 2 + Level 3 추가.
6 Categories + 30 Practice Areas
Doing (Engineering·Service):
- Requirements Development and Management (RDM)
- Technical Solution (TS)
- Product Integration (PI)
- Verification·Validation (VV)
- Service Delivery Management (SDM)
- Strategic Service Management (STSM)
- Supplier Selection (SS)
- Supplier Agreement Management (SAM)
- Process Quality Assurance (PQA)
Managing (Planning·Resilience·Workforce):
- Estimating (EST)
- Planning (PLAN)
- Monitor and Control (MC)
- Risk and Opportunity Management (RSK)
- Continuity (CONT)
- Incident Resolution and Prevention (IRP)
- Capacity and Availability Management (CAM)
Enabling (Support·Safety·Security):
- Configuration Management (CM)
- Decision Analysis and Resolution (DAR)
- Causal Analysis and Resolution (CAR)
- Managing Safety (MS)
- Managing Security (MSEC)
Improving:
- Process Asset Development (PAD)
- Improving Performance (IPM)
- Managing Performance and Measurement (MPM)
Sustaining:
- Governance (GOV)
- Implementation Infrastructure (II)
Building Workforce (People):
- Organizational Training (OT)
- Workforce Empowerment (WE)
- Workforce Empowerment Practices (WEP)
CMMI Constellations
V2.0·V3.0 통합 Models:
- CMMI for Development (DEV): SW·HW 개발
- CMMI for Services (SVC): IT 서비스
- CMMI for Supplier Management (SPM): 공급사 관리
- People CMM (PCMM): 인적자원
- CMMI for Cybersecurity (CSEC): 사이버보안 (신규)
- CMMI for Safety (SAFE): 안전 (신규)
Appraisal Method (평가)
4 Appraisal Types:
1. Benchmark Appraisal:
- Official Maturity Level 인증
- 3 Days·2 Months 준비
- 유효기간 3년
2. Sustainment Appraisal:
- Maturity Level 유지
- 18~30개월
3. Action Plan Reappraisal:
- 부적합 시정
4. Evaluation Appraisal:
- Gap Analysis·Pre-Appraisal
Lead Appraiser·Appraisal Team
- Certified Lead Appraiser (ISACA 인정)
- Appraisal Team Member (ATM)
- Appraisal Team Leader (ATL)
Process Asset Library (PAL)
- 모든 Process Asset·Template·Guidance
- Confluence·SharePoint·ServiceNow
CMMI vs ISO 9001·ISO 20000·ISO 27001 비교
| 항목 | CMMI V3.0 | ISO 9001 | ISO 20000-1 | ISO 27001 |
|---|---|---|---|---|
| 발효 | 1991·2023 | 1987 | 2005·2018 | 2005·2022 |
| 형식 | Maturity Model | ISO 인증 | ISO 인증 | ISO 인증 |
| 영역 | SW·시스템 엔지니어링 | 품질 | IT 서비스 | 정보보안 |
| 한국 인지도 | 매우 높음 | 매우 높음 | 매우 높음 | 매우 높음 |
대부분의 한국 SW·SI: CMMI + ISO 9001 + ISO 20000 + ISO 27001 통합.
한국 SW·시스템 CMMI 성숙도 진단 — 5단계
| 단계 | 명칭 | 핵심 특징 | Maturity Level |
|---|---|---|---|
| Level 1 | CMMI 인식 없음 | Ad-hoc 개발 | Level 1 |
| Level 2 | 기본 프로세스 | 일부 PA | Level 1~2 |
| Level 3 | CMMI Level 2 | Project Level·Managed | Level 2 |
| Level 4 | CMMI Level 3 | Organization Level·Defined | Level 3 |
| Level 5 | CMMI Level 4·5 | Quantitatively Managed·Optimizing | Level 4·5 |
대부분의 한국 중소 SW는 Level 1~2. 5단계 로드맵은 Level 3 CMMI Level 2 1차 + Level 4·5 CMMI Level 3·4·5 도전.
Stage 1: Target Maturity Level·범위 (1~2개월)
1.1 적용 결정
자가 진단:
- SW 개발·시스템 엔지니어링·SI?
- 미국 정부 입찰?
- 글로벌 SW 진출?
1.2 Target Maturity Level 결정
Level 2 — Managed (입문):
- Project Level
- 9~12개월 구축
- 비용 €100K~€300K
Level 3 — Defined (표준):
- Organization Level
- 18~24개월
- 비용 €300K~€800K
Level 4·5 (선두):
- Statistical·Optimizing
- 3~5년
- 비용 €1M+
1.3 Constellation 결정
- CMMI for DEV·SVC·SPM·PCMM·CSEC·SAFE
1.4 갭 분석
한국 갭 분석 빈출 부적합 Top 15:
- Estimating (EST) — 부재
- Planning (PLAN) — Project Plan 부재
- Monitor and Control (MC) — Status Reporting 부재
- Risk and Opportunity (RSK) — Register 부재
- Configuration Management (CM) — Git·Branch·Version 부재
- Verification·Validation (VV) — Test·Review 부재
- Process Quality Assurance (PQA) — QA 부재
- Requirements (RDM) — Requirement Engineering 부재
- Technical Solution (TS) — Architecture·Design 부재
- Product Integration (PI) — Integration·CI/CD 부재
- Supplier (SS·SAM) — Vendor·Outsourcing 부재
- Service Delivery (SDM) — IT Service 부재
- Decision Analysis (DAR) — 부재
- Managing Safety·Security (MS·MSEC) — 부재 (V3.0)
- Process Asset Development (PAD) — Library 부재
1.5 Stage 1 산출물
- Target Maturity Level (Level 2 또는 3)
- Constellation 결정
- 30 PA 갭 분석
Stage 2: 6 Categories + 30 PA Implementation (3~6개월)
2.1 Doing — Engineering·Service
RDM·TS·PI·VV·PQA:
- Requirements Management·Engineering
- Architecture·Design (Enterprise Architect·Lucidchart)
- Coding·Review·Static Analysis
- Test (Unit·Integration·System·UAT)
- Configuration·Branch·Merge
2.2 Managing — Planning·Resilience·Workforce
EST·PLAN·MC·RSK·CONT·IRP·CAM:
- Function Point·Use Case Point·Story Point Estimation
- Microsoft Project·Jira·Asana
- Risk Register
- Capacity·Performance Monitoring (Datadog·New Relic)
2.3 Enabling — Support·Safety·Security (V3.0)
CM·DAR·CAR·MS·MSEC:
- Configuration Management (Git·Perforce)
- Decision Matrix·Analysis
- 5 Why·Ishikawa Causal Analysis
- MS — Managing Safety (DO-178C·ISO 26262 정합)
- MSEC — Managing Security (ISO 27001·NIST CSF·OWASP·DevSecOps 정합)
2.4 Improving
PAD·IPM·MPM:
- Process Asset Library
- KPI·Metrics
- Statistical Process Control (Level 4·5)
2.5 Sustaining
GOV·II:
- Sponsor·Governance Board
- Process Maturity Sustained
2.6 Building Workforce — People
OT·WE·WEP:
- Skills Inventory
- Training Plan
- Coursera·LinkedIn Learning·Udemy
2.7 Stage 2 산출물
- 30 PA 구현
- Process Asset Library
- Project·Service·Supplier Management
- Configuration·Change·Release
- Safety·Security PA (V3.0)
Stage 3: Process Asset + Performance + Statistical (Level 4·5) (3~6개월)
3.1 Process Asset Library (PAL)
- 모든 Process·Template·Guidance
- Confluence·SharePoint·ServiceNow·BMC Helix
3.2 Performance Management
KPI·Metrics:
- Schedule·Cost·Quality·Defect
- Customer Satisfaction
- Delivery·Time-to-Market
- CSAT·NPS
3.3 Statistical Process Control (Level 4)
- Control Chart·X-Bar·R
- Process Capability Index (Cp·Cpk)
- Statistical Tools (Minitab·SPSS·R·Python)
3.4 Continuous Improvement (Level 5)
- Causal Analysis and Resolution (CAR)
- Innovation
- DevOps·Lean·Agile·Six Sigma 통합
3.5 Stage 3 산출물
- PAL
- KPI·Metrics·Dashboard
- Statistical Control (Level 4)
- Continuous Improvement (Level 5)
Stage 4: Appraisal·Benchmark (1~2개월)
4.1 Lead Appraiser 선정
ISACA 인정 Certified Lead Appraiser:
- 한국 — Standards 기반·국제 인정
- 글로벌 — 미국·인도·EU 가용
비용: USD 50K~200K (Level별).
4.2 Pre-Appraisal (Evaluation)
- Gap Analysis
- Action Plan
- 3~6개월
4.3 Benchmark Appraisal
3 Days On-Site:
- Document Review
- Interview (Management·Project·Engineer)
- Observation·Affirmation
4.4 Appraisal Result
- Maturity Level 인증
- Strengths·Weaknesses
- Action Plan
4.5 PARS 등록
CMMI Performance and Reporting System (PARS):
- 공식 결과 등록
- Public 공개
- 글로벌 검색
4.6 Stage 4 산출물
- Lead Appraiser 계약
- Pre-Appraisal Report
- Benchmark Appraisal
- Maturity Level 인증
- PARS 등록
Stage 5: 통합·갱신 (지속)
5.1 매년 갱신
- Sustainment Appraisal (18~30개월)
- 3년 Benchmark 갱신
5.2 통합
- ISO 9001 + ISO 20000-1 + ISO 27001 + ISO 22301
- DevSecOps + Agile + SAFe + SCRUM + Kanban
- Lean + Six Sigma
- ITIL 4 + COBIT 2019 + SIAM
5.3 People CMM 통합
- Workforce Maturity
- HR·인적자본
5.4 Stage 5 산출물
- 매년 Sustainment
- 3년 Benchmark 갱신
- ISO·DevSecOps·Agile 통합
비용 — Maturity Level별 (Level 3 — 3년 누계)
중견 SW·SI (직원 100500명, 매출 100500억) — CMMI Level 3
| 항목 | 1년차 (만원) | 2년차 | 3년차 |
|---|---|---|---|
| 컨설팅 (CMMI Lead Appraiser) | 10,000 | 3,000 | 3,000 |
| Process Asset Development | 8,000 | 3,000 | 3,000 |
| ITSM·Project·Configuration 도구 (Jira·Confluence·Git) | 6,000 | 7,000 | 8,000 |
| KPI·Metrics·Dashboard | 3,500 | 2,500 | 2,500 |
| Training (개발자·QA·PM·Manager) | 4,500 | 3,500 | 3,500 |
| Benchmark Appraisal | 15,000 | - | 8,000 |
| Sustainment Appraisal | - | 5,000 | - |
| QA·Process·인력(2명) | 14,400 | 15,000 | 15,800 |
| 합계 | 61,400 | 39,000 | 43,800 |
| 3년 누계 | 약 14.4억 원 |
Level 4·5 (대기업·인도 IT)
3년 누계 약 50~150억 원.
ROI 시나리오
- 한국 SW 매출 €100M (글로벌 50%)
- CMMI Level 3 + ISO 9001·20000·27001 통합 → 글로벌 입찰·진출
- 매출 +€40M (3년)
- 마진율 15% → 영업이익 +€6M
CMMI vs ISO 9001 vs ISO 20000 vs Agile 비교 (재정리)
| 항목 | CMMI V3.0 | ISO 9001 | ISO 20000-1 | Agile·SAFe |
|---|---|---|---|---|
| 발효 | 1991·2023 | 1987 | 2005·2018 | 2001~ |
| 영역 | SW·시스템 | 품질 | IT 서비스 | Project |
| 형식 | Maturity Model | ISO | ISO | Methodology |
| 한국 인지도 | 매우 높음 | 매우 높음 | 매우 높음 | 매우 높음 |
한국 SW·시스템·SI 표준 조합:
- 성숙도: CMMI Level 2·3·4·5
- 품질·서비스: + ISO 9001 + ISO 20000-1
- 정보보안·연속성: + ISO 27001 + ISO 22301
- 항공·자동차: + AS 9100D + IATF 16949 + DO-178C·ISO 26262
- DevSecOps: + NIST SSDF + ISO/IEC 27034 + OWASP SAMM
한국 CMMI 성공 사례 (가상)
사례 A: SI (매출 €300M)
- 도입 동기: CMMI Level 3 + 정부 입찰 + 글로벌 진출
- 구축 기간: 18개월
- 비용: 1차 25억, 3년 누계 40억
- 추가: ISO 9001·20000·27001 통합
- 성과: 정부·금융·통신 SI 수주 확대
사례 B: 임베디드 SW (매출 €100M, 자동차·항공)
- 도입 동기: CMMI Level 3 + DO-178C·ISO 26262
- 구축 기간: 20개월
- 비용: 1차 20억
- 추가: AS 9100D + IATF 16949
- 성과: KAI·현대모비스·Tier 1 진입
사례 C: SaaS·MSP (ARR €30M)
- 도입 동기: CMMI Level 2 + Agile + DevSecOps
- 구축 기간: 12개월
- 비용: 1차 12억
- 추가: ISO 20000 + ISO 27001 + SOC 2
- 성과: 글로벌 엔터프라이즈 진입
자가 진단 체크리스트 (15문)
각 문항 0~2점, 합계 30점 만점.
Maturity Level·범위
- Target Maturity Level (2·3·4·5) + Constellation
6 Categories — Doing·Managing·Enabling
- RDM + TS + PI + VV + PQA
- EST + PLAN + MC + RSK + CONT
- CM + DAR + CAR
V3.0 신규 — Safety·Security
- MS (Managing Safety)
- MSEC (Managing Security)
Improving·Sustaining·People
- PAD + Process Asset Library
- IPM + MPM + KPI·Dashboard
- GOV + II
- OT + WE + WEP
Statistical·Continuous (Level 4·5)
- Statistical Process Control
- Causal Analysis + Continuous Improvement
Appraisal·통합
- Lead Appraiser + Pre-Appraisal
- Benchmark Appraisal + PARS
- ISO 9001·20000·27001 + DevSecOps·Agile 통합
점수 해석:
- 0
10: Level 1 — 912개월 구축 - 11
20: Level 2 — 1218개월 후 - 21~26: Level 3 — 정착
- 27~30: Level 4·5 — Statistical·Optimizing
마치며 — CMMI는 글로벌 SW·시스템의 단일 성숙도 모델
CMMI는 글로벌 SW·시스템 엔지니어링의 단일 성숙도 모델이다. V3.0(2023) Safety·Security 강화·DevSecOps·Agile 정합. 인도 IT·미국 정부·글로벌 항공·방산·자동차·통신·금융 사실상 표준.
본 5단계 로드맵을 통해 9~18개월 내 CMMI Level 2·3 + 글로벌 SW 진출이 현실적 목표다. 핵심 5가지:
- Target Maturity Level + 6 Categories + 30 Practice Areas
- Doing·Managing·Enabling·Improving·Sustaining·Building Workforce
- V3.0 신규 Safety + Security PA + DevSecOps·Agile 정합
- Process Asset Library + KPI + Statistical Process Control
- ISO 9001·20000·27001·22301 + DevSecOps + Agile + Lean·Six Sigma 통합
CMMI V3.0 + ISO 9001 + ISO 20000-1 + ISO 27001·27017·27018·27701 + ISO 22301 + ISO 56001 + ISO 42001 + CSA STAR + SOC 2 + FedRAMP + CMMC + AS 9100D + IATF 16949 + DO-178C + ISO 26262 + ISO/SAE 21434 + NIST CSF + NIST AI RMF + NIST Privacy Framework + ITIL 4 + COBIT + SIAM + DevSecOps + Agile + SAFe + Lean + Six Sigma 다중 컴플라이언스는 한국 SW·시스템 엔지니어링·SI·SaaS·임베디드·자동차·항공·방산·통신·금융 IT 기업의 글로벌 진출 최강 포트폴리오다.
통합 — SW·시스템·품질·서비스 시리즈
CMMI는 글로벌 SW·시스템 엔지니어링의 핵심 성숙도 모델이다.
ISO 경영시스템·서비스 통합:
- ISO 9001 품질경영시스템
- ISO 20000-1 IT 서비스 관리
- ISO 27001 정보보안경영시스템
- ISO 22301 비즈니스 연속성
- ISO 31000 리스크관리
- ISO 37001 반부패경영시스템
- ISO 56000 혁신경영시스템
- ISO 42001 AI 경영시스템
- ISO 30414 인적자본 보고
산업별 품질·QMS·임베디드:
- IATF 16949 자동차 품질경영시스템
- ISO 26262 자동차 기능안전
- ISO/SAE 21434 자동차 사이버보안
- TISAX 자동차 정보보안
- AS 9100D 항공우주 품질경영시스템
- DO-178C 항공 SW 인증
- DO-254 항공 HW 인증
- ISO/TS 22163 IRIS 철도 품질
- API Q1·Q2 석유·가스 품질
- ISO 19443 원자력 공급망 품질
- SEMI Standards 반도체
- ISO 13485 의료기기 품질경영시스템
- TL 9000 통신 품질
클라우드·미국 정부·정보보안:
- CSA STAR 클라우드 보안
- SOC 2 Type II 인증
- FedRAMP 미국 정부 클라우드
- CMMC 2.0 미국 DoD 사이버보안
- NIST CSF 2.0
- NIST AI RMF
- NIST Privacy Framework
CMMI V3.0 + ISO 9001 + ISO 20000-1 + ISO 27001·27017·27018·27701 + ISO 22301 + ISO 56001 + ISO 42001 + ISO 30414 + CSA STAR + SOC 2 + FedRAMP + CMMC + AS 9100D + IATF 16949 + DO-178C·DO-254 + ISO 26262 + ISO 21434 + NIST CSF + NIST AI RMF + NIST Privacy Framework + ITIL 4 + COBIT + DevSecOps + Agile + SAFe + Lean + Six Sigma 다중 컴플라이언스는 한국 SW·시스템 엔지니어링·SI·SaaS·임베디드·자동차·항공·방산·통신·금융 IT의 글로벌 진출 최강 통합 포트폴리오다.
