제조업 CMMI(능력 성숙도 모델 통합) V3.0 인증 실무 완벽 가이드 — 5 Maturity Levels·6 Categories에서 글로벌 SW·시스템 엔지니어링 진출까지 5단계 로드맵

중소·중견 한국 SW·시스템 엔지니어링·SI·SaaS·임베디드·자동차·항공·방산·통신·금융 IT 기업의 CMMI V3.0(2023) Capability Maturity Model Integration 인증 5단계 로드맵. 1991년 SEI·2002년 v1.1·2010년 v1.3·2018년 V2.0·2023년 V3.0 발행, ISACA 운영, 5 Maturity Levels(Initial·Managed·Defined·Quantitatively Managed·Optimizing), 6 Categories·30 Practice Areas, CMMI Development·Services·Supplier·People·Cybersecurity·Safety + Appraisal Method (Benchmark·Sustainment·Action·Evaluation) + ISO 20000·ISO 27001·DevSecOps·Agile 통합.

CMMI(Capability Maturity Model Integration)는 카네기 멜런 대학교 SEI(Software Engineering Institute)가 1991년 CMM 첫 발행·2002년 v1.1 CMMI 통합·2010년 v1.3·2018년 V2.0·2023년 12월 V3.0 (현재) 발행한 SW·시스템 엔지니어링 능력 성숙도 모델이다. 2018년부터 ISACA(Information Systems Audit and Control Association)·CMMI Institute 운영. 자발적 모델이지만 글로벌 SW·시스템·SI·SaaS·임베디드·자동차·항공·방산·통신·금융 IT 사실상 표준. 전 세계 약 11,000+ 조직 평가 — 인도 IT 산업 가장 강력 채택(TCS·Infosys·Wipro·HCL·Tech Mahindra Maturity Level 5+) + 미국 정부 입찰·국방 (CMMI Level 3+ 우대) + 글로벌 Boeing·Airbus·Lockheed·KAI·BAE·Northrop·NASA·Samsung·LG·SK·NAVER·카카오·LG CNS·삼성SDS·KT·SKT.

핵심은 CMMI가 SW·시스템 엔지니어링의 글로벌 단일 성숙도 모델이라는 점이다. 5 Maturity Levels (조직 차원):

  • Level 1 — Initial (Ad-hoc·Unpredictable)
  • Level 2 — Managed (Project Level·Reactive)
  • Level 3 — Defined (Organization Level·Proactive)
  • Level 4 — Quantitatively Managed (Measured·Controlled)
  • Level 5 — Optimizing (Continuous Improvement)

6 Categories (V3.0):

  • Doing (Engineering, Service Delivery, Selecting and Managing Suppliers, Ensuring Quality)
  • Managing (Planning and Managing Work, Managing Business Resilience, Managing the Workforce)
  • Enabling (Supporting Implementation, Managing Safety, Managing Security)
  • Improving (Sustaining Habits and Persistence, Improving Performance)
  • Sustaining (Sustaining Habits and Persistence)
  • Building Workforce (People)

30 Practice Areas (PA) — Estimating·Planning·Monitor·Risk·Configuration·Verification·Validation·Process Quality·Decision Analysis·Requirements·Design·Product Integration·Technical Solution·Supplier Selection·Agreement·CCO·Service Delivery·Strategic Service Management·Continuity·Incident Resolution·Capacity·Workforce·Organizational Training·Governance·Implementation Infrastructure·Process Asset Development·Continuous Improvement·Managing Performance·Causal Analysis·Resolution. V3.0 신규 — Safety·Security PA + Workforce·Resilience 강화. Appraisal Method — Benchmark·Sustainment·Action·Evaluation. ISO 20000·ISO 27001·ISO 22301·DevSecOps·Agile·SCRUM 100% 정합. 한국 CMMI: 삼성SDS·LG CNS·SK C&C·KT M&S·NHN Cloud·NAVER Cloud·카카오엔터프라이즈·핸디소프트·다우데이타·NICE·LG U+·LIG넥스원·한화에어로스페이스·KAI·현대모비스·LG전자 임베디드 등 200+ 한국 조직 CMMI 보유. 본 가이드는 적용 결정·범위 → Maturity Level·6 Categories·30 PA → Implementation·Process Asset → Appraisal·인증 → ISO·DevSecOps·Agile 통합 5단계 로드맵으로, 중소·중견 한국 SW·시스템 엔지니어링 기업이 9~18개월 내 CMMI Level 2·3 + 글로벌 SW 진출하는 실무 경로를 제시한다.

왜 CMMI를 도입해야 하는가

글로벌 SW·시스템 엔지니어링 단일 성숙도 모델

  • 11,000+ 평가 (글로벌)
  • 인도 IT 100+ Maturity Level 5
  • 미국 정부 입찰 우대 (Level 3+)
  • 글로벌 항공·방산·자동차·통신·금융 IT 사실상 표준

CMMI는 SW·시스템 엔지니어링 글로벌 우산.

CMMI V3.0 (2023) 주요 변화

  • Cybersecurity PA: Managing Security 신규
  • Safety PA: Managing Safety 신규
  • Workforce: Building Workforce Category 강화
  • Resilience: Managing Business Resilience 강화
  • People CMM 통합
  • DevSecOps·Agile·SAFe·SCRUM 정합 강화
  • Cloud·SaaS·AI/ML 추가

5 Maturity Levels

Level명칭특징
1InitialAd-hoc·Unpredictable·Reactive
2ManagedProject Level·Basic·Reactive
3DefinedOrganization Level·Standard·Proactive
4Quantitatively ManagedStatistical·Measured·Controlled
5OptimizingContinuous Improvement·Innovation

각 Level 누적 — Level 3 = Level 2 + Level 3 추가.

6 Categories + 30 Practice Areas

Doing (Engineering·Service):

  • Requirements Development and Management (RDM)
  • Technical Solution (TS)
  • Product Integration (PI)
  • Verification·Validation (VV)
  • Service Delivery Management (SDM)
  • Strategic Service Management (STSM)
  • Supplier Selection (SS)
  • Supplier Agreement Management (SAM)
  • Process Quality Assurance (PQA)

Managing (Planning·Resilience·Workforce):

  • Estimating (EST)
  • Planning (PLAN)
  • Monitor and Control (MC)
  • Risk and Opportunity Management (RSK)
  • Continuity (CONT)
  • Incident Resolution and Prevention (IRP)
  • Capacity and Availability Management (CAM)

Enabling (Support·Safety·Security):

  • Configuration Management (CM)
  • Decision Analysis and Resolution (DAR)
  • Causal Analysis and Resolution (CAR)
  • Managing Safety (MS)
  • Managing Security (MSEC)

Improving:

  • Process Asset Development (PAD)
  • Improving Performance (IPM)
  • Managing Performance and Measurement (MPM)

Sustaining:

  • Governance (GOV)
  • Implementation Infrastructure (II)

Building Workforce (People):

  • Organizational Training (OT)
  • Workforce Empowerment (WE)
  • Workforce Empowerment Practices (WEP)

CMMI Constellations

V2.0·V3.0 통합 Models:

  • CMMI for Development (DEV): SW·HW 개발
  • CMMI for Services (SVC): IT 서비스
  • CMMI for Supplier Management (SPM): 공급사 관리
  • People CMM (PCMM): 인적자원
  • CMMI for Cybersecurity (CSEC): 사이버보안 (신규)
  • CMMI for Safety (SAFE): 안전 (신규)

Appraisal Method (평가)

4 Appraisal Types:

1. Benchmark Appraisal:

  • Official Maturity Level 인증
  • 3 Days·2 Months 준비
  • 유효기간 3년

2. Sustainment Appraisal:

  • Maturity Level 유지
  • 18~30개월

3. Action Plan Reappraisal:

  • 부적합 시정

4. Evaluation Appraisal:

  • Gap Analysis·Pre-Appraisal

Lead Appraiser·Appraisal Team

  • Certified Lead Appraiser (ISACA 인정)
  • Appraisal Team Member (ATM)
  • Appraisal Team Leader (ATL)

Process Asset Library (PAL)

  • 모든 Process Asset·Template·Guidance
  • Confluence·SharePoint·ServiceNow

CMMI vs ISO 9001·ISO 20000·ISO 27001 비교

항목CMMI V3.0ISO 9001ISO 20000-1ISO 27001
발효1991·202319872005·20182005·2022
형식Maturity ModelISO 인증ISO 인증ISO 인증
영역SW·시스템 엔지니어링품질IT 서비스정보보안
한국 인지도매우 높음매우 높음매우 높음매우 높음

대부분의 한국 SW·SI: CMMI + ISO 9001 + ISO 20000 + ISO 27001 통합.

한국 SW·시스템 CMMI 성숙도 진단 — 5단계

단계명칭핵심 특징Maturity Level
Level 1CMMI 인식 없음Ad-hoc 개발Level 1
Level 2기본 프로세스일부 PALevel 1~2
Level 3CMMI Level 2Project Level·ManagedLevel 2
Level 4CMMI Level 3Organization Level·DefinedLevel 3
Level 5CMMI Level 4·5Quantitatively Managed·OptimizingLevel 4·5

대부분의 한국 중소 SW는 Level 1~2. 5단계 로드맵은 Level 3 CMMI Level 2 1차 + Level 4·5 CMMI Level 3·4·5 도전.


Stage 1: Target Maturity Level·범위 (1~2개월)

1.1 적용 결정

자가 진단:

  • SW 개발·시스템 엔지니어링·SI?
  • 미국 정부 입찰?
  • 글로벌 SW 진출?

1.2 Target Maturity Level 결정

Level 2 — Managed (입문):

  • Project Level
  • 9~12개월 구축
  • 비용 €100K~€300K

Level 3 — Defined (표준):

  • Organization Level
  • 18~24개월
  • 비용 €300K~€800K

Level 4·5 (선두):

  • Statistical·Optimizing
  • 3~5년
  • 비용 €1M+

1.3 Constellation 결정

  • CMMI for DEV·SVC·SPM·PCMM·CSEC·SAFE

1.4 갭 분석

한국 갭 분석 빈출 부적합 Top 15:

  1. Estimating (EST) — 부재
  2. Planning (PLAN) — Project Plan 부재
  3. Monitor and Control (MC) — Status Reporting 부재
  4. Risk and Opportunity (RSK) — Register 부재
  5. Configuration Management (CM) — Git·Branch·Version 부재
  6. Verification·Validation (VV) — Test·Review 부재
  7. Process Quality Assurance (PQA) — QA 부재
  8. Requirements (RDM) — Requirement Engineering 부재
  9. Technical Solution (TS) — Architecture·Design 부재
  10. Product Integration (PI) — Integration·CI/CD 부재
  11. Supplier (SS·SAM) — Vendor·Outsourcing 부재
  12. Service Delivery (SDM) — IT Service 부재
  13. Decision Analysis (DAR) — 부재
  14. Managing Safety·Security (MS·MSEC) — 부재 (V3.0)
  15. Process Asset Development (PAD) — Library 부재

1.5 Stage 1 산출물

  • Target Maturity Level (Level 2 또는 3)
  • Constellation 결정
  • 30 PA 갭 분석

Stage 2: 6 Categories + 30 PA Implementation (3~6개월)

2.1 Doing — Engineering·Service

RDM·TS·PI·VV·PQA:

  • Requirements Management·Engineering
  • Architecture·Design (Enterprise Architect·Lucidchart)
  • Coding·Review·Static Analysis
  • Test (Unit·Integration·System·UAT)
  • Configuration·Branch·Merge

2.2 Managing — Planning·Resilience·Workforce

EST·PLAN·MC·RSK·CONT·IRP·CAM:

  • Function Point·Use Case Point·Story Point Estimation
  • Microsoft Project·Jira·Asana
  • Risk Register
  • Capacity·Performance Monitoring (Datadog·New Relic)

2.3 Enabling — Support·Safety·Security (V3.0)

CM·DAR·CAR·MS·MSEC:

  • Configuration Management (Git·Perforce)
  • Decision Matrix·Analysis
  • 5 Why·Ishikawa Causal Analysis
  • MS — Managing Safety (DO-178C·ISO 26262 정합)
  • MSEC — Managing Security (ISO 27001·NIST CSF·OWASP·DevSecOps 정합)

2.4 Improving

PAD·IPM·MPM:

  • Process Asset Library
  • KPI·Metrics
  • Statistical Process Control (Level 4·5)

2.5 Sustaining

GOV·II:

  • Sponsor·Governance Board
  • Process Maturity Sustained

2.6 Building Workforce — People

OT·WE·WEP:

  • Skills Inventory
  • Training Plan
  • Coursera·LinkedIn Learning·Udemy

2.7 Stage 2 산출물

  • 30 PA 구현
  • Process Asset Library
  • Project·Service·Supplier Management
  • Configuration·Change·Release
  • Safety·Security PA (V3.0)

Stage 3: Process Asset + Performance + Statistical (Level 4·5) (3~6개월)

3.1 Process Asset Library (PAL)

  • 모든 Process·Template·Guidance
  • Confluence·SharePoint·ServiceNow·BMC Helix

3.2 Performance Management

KPI·Metrics:

  • Schedule·Cost·Quality·Defect
  • Customer Satisfaction
  • Delivery·Time-to-Market
  • CSAT·NPS

3.3 Statistical Process Control (Level 4)

  • Control Chart·X-Bar·R
  • Process Capability Index (Cp·Cpk)
  • Statistical Tools (Minitab·SPSS·R·Python)

3.4 Continuous Improvement (Level 5)

  • Causal Analysis and Resolution (CAR)
  • Innovation
  • DevOps·Lean·Agile·Six Sigma 통합

3.5 Stage 3 산출물

  • PAL
  • KPI·Metrics·Dashboard
  • Statistical Control (Level 4)
  • Continuous Improvement (Level 5)

Stage 4: Appraisal·Benchmark (1~2개월)

4.1 Lead Appraiser 선정

ISACA 인정 Certified Lead Appraiser:

  • 한국 — Standards 기반·국제 인정
  • 글로벌 — 미국·인도·EU 가용

비용: USD 50K~200K (Level별).

4.2 Pre-Appraisal (Evaluation)

  • Gap Analysis
  • Action Plan
  • 3~6개월

4.3 Benchmark Appraisal

3 Days On-Site:

  • Document Review
  • Interview (Management·Project·Engineer)
  • Observation·Affirmation

4.4 Appraisal Result

  • Maturity Level 인증
  • Strengths·Weaknesses
  • Action Plan

4.5 PARS 등록

CMMI Performance and Reporting System (PARS):

  • 공식 결과 등록
  • Public 공개
  • 글로벌 검색

4.6 Stage 4 산출물

  • Lead Appraiser 계약
  • Pre-Appraisal Report
  • Benchmark Appraisal
  • Maturity Level 인증
  • PARS 등록

Stage 5: 통합·갱신 (지속)

5.1 매년 갱신

  • Sustainment Appraisal (18~30개월)
  • 3년 Benchmark 갱신

5.2 통합

  • ISO 9001 + ISO 20000-1 + ISO 27001 + ISO 22301
  • DevSecOps + Agile + SAFe + SCRUM + Kanban
  • Lean + Six Sigma
  • ITIL 4 + COBIT 2019 + SIAM

5.3 People CMM 통합

  • Workforce Maturity
  • HR·인적자본

5.4 Stage 5 산출물

  • 매년 Sustainment
  • 3년 Benchmark 갱신
  • ISO·DevSecOps·Agile 통합

비용 — Maturity Level별 (Level 3 — 3년 누계)

중견 SW·SI (직원 100500명, 매출 100500억) — CMMI Level 3

항목1년차 (만원)2년차3년차
컨설팅 (CMMI Lead Appraiser)10,0003,0003,000
Process Asset Development8,0003,0003,000
ITSM·Project·Configuration 도구 (Jira·Confluence·Git)6,0007,0008,000
KPI·Metrics·Dashboard3,5002,5002,500
Training (개발자·QA·PM·Manager)4,5003,5003,500
Benchmark Appraisal15,000-8,000
Sustainment Appraisal-5,000-
QA·Process·인력(2명)14,40015,00015,800
합계61,40039,00043,800
3년 누계약 14.4억 원

Level 4·5 (대기업·인도 IT)

3년 누계 약 50~150억 원.

ROI 시나리오

  • 한국 SW 매출 €100M (글로벌 50%)
  • CMMI Level 3 + ISO 9001·20000·27001 통합 → 글로벌 입찰·진출
  • 매출 +€40M (3년)
  • 마진율 15% → 영업이익 +€6M

CMMI vs ISO 9001 vs ISO 20000 vs Agile 비교 (재정리)

항목CMMI V3.0ISO 9001ISO 20000-1Agile·SAFe
발효1991·202319872005·20182001~
영역SW·시스템품질IT 서비스Project
형식Maturity ModelISOISOMethodology
한국 인지도매우 높음매우 높음매우 높음매우 높음

한국 SW·시스템·SI 표준 조합:

  • 성숙도: CMMI Level 2·3·4·5
  • 품질·서비스: + ISO 9001 + ISO 20000-1
  • 정보보안·연속성: + ISO 27001 + ISO 22301
  • 항공·자동차: + AS 9100D + IATF 16949 + DO-178C·ISO 26262
  • DevSecOps: + NIST SSDF + ISO/IEC 27034 + OWASP SAMM

한국 CMMI 성공 사례 (가상)

사례 A: SI (매출 €300M)

  • 도입 동기: CMMI Level 3 + 정부 입찰 + 글로벌 진출
  • 구축 기간: 18개월
  • 비용: 1차 25억, 3년 누계 40억
  • 추가: ISO 9001·20000·27001 통합
  • 성과: 정부·금융·통신 SI 수주 확대

사례 B: 임베디드 SW (매출 €100M, 자동차·항공)

  • 도입 동기: CMMI Level 3 + DO-178C·ISO 26262
  • 구축 기간: 20개월
  • 비용: 1차 20억
  • 추가: AS 9100D + IATF 16949
  • 성과: KAI·현대모비스·Tier 1 진입

사례 C: SaaS·MSP (ARR €30M)

  • 도입 동기: CMMI Level 2 + Agile + DevSecOps
  • 구축 기간: 12개월
  • 비용: 1차 12억
  • 추가: ISO 20000 + ISO 27001 + SOC 2
  • 성과: 글로벌 엔터프라이즈 진입

자가 진단 체크리스트 (15문)

각 문항 0~2점, 합계 30점 만점.

Maturity Level·범위

  1. Target Maturity Level (2·3·4·5) + Constellation

6 Categories — Doing·Managing·Enabling

  1. RDM + TS + PI + VV + PQA
  2. EST + PLAN + MC + RSK + CONT
  3. CM + DAR + CAR

V3.0 신규 — Safety·Security

  1. MS (Managing Safety)
  2. MSEC (Managing Security)

Improving·Sustaining·People

  1. PAD + Process Asset Library
  2. IPM + MPM + KPI·Dashboard
  3. GOV + II
  4. OT + WE + WEP

Statistical·Continuous (Level 4·5)

  1. Statistical Process Control
  2. Causal Analysis + Continuous Improvement

Appraisal·통합

  1. Lead Appraiser + Pre-Appraisal
  2. Benchmark Appraisal + PARS
  3. ISO 9001·20000·27001 + DevSecOps·Agile 통합

점수 해석:

  • 010: Level 1 — 912개월 구축
  • 1120: Level 2 — 1218개월 후
  • 21~26: Level 3 — 정착
  • 27~30: Level 4·5 — Statistical·Optimizing

마치며 — CMMI는 글로벌 SW·시스템의 단일 성숙도 모델

CMMI는 글로벌 SW·시스템 엔지니어링의 단일 성숙도 모델이다. V3.0(2023) Safety·Security 강화·DevSecOps·Agile 정합. 인도 IT·미국 정부·글로벌 항공·방산·자동차·통신·금융 사실상 표준.

본 5단계 로드맵을 통해 9~18개월 내 CMMI Level 2·3 + 글로벌 SW 진출이 현실적 목표다. 핵심 5가지:

  1. Target Maturity Level + 6 Categories + 30 Practice Areas
  2. Doing·Managing·Enabling·Improving·Sustaining·Building Workforce
  3. V3.0 신규 Safety + Security PA + DevSecOps·Agile 정합
  4. Process Asset Library + KPI + Statistical Process Control
  5. ISO 9001·20000·27001·22301 + DevSecOps + Agile + Lean·Six Sigma 통합

CMMI V3.0 + ISO 9001 + ISO 20000-1 + ISO 27001·27017·27018·27701 + ISO 22301 + ISO 56001 + ISO 42001 + CSA STAR + SOC 2 + FedRAMP + CMMC + AS 9100D + IATF 16949 + DO-178C + ISO 26262 + ISO/SAE 21434 + NIST CSF + NIST AI RMF + NIST Privacy Framework + ITIL 4 + COBIT + SIAM + DevSecOps + Agile + SAFe + Lean + Six Sigma 다중 컴플라이언스는 한국 SW·시스템 엔지니어링·SI·SaaS·임베디드·자동차·항공·방산·통신·금융 IT 기업의 글로벌 진출 최강 포트폴리오다.


통합 — SW·시스템·품질·서비스 시리즈

CMMI는 글로벌 SW·시스템 엔지니어링의 핵심 성숙도 모델이다.

ISO 경영시스템·서비스 통합:

산업별 품질·QMS·임베디드:

클라우드·미국 정부·정보보안:

CMMI V3.0 + ISO 9001 + ISO 20000-1 + ISO 27001·27017·27018·27701 + ISO 22301 + ISO 56001 + ISO 42001 + ISO 30414 + CSA STAR + SOC 2 + FedRAMP + CMMC + AS 9100D + IATF 16949 + DO-178C·DO-254 + ISO 26262 + ISO 21434 + NIST CSF + NIST AI RMF + NIST Privacy Framework + ITIL 4 + COBIT + DevSecOps + Agile + SAFe + Lean + Six Sigma 다중 컴플라이언스는 한국 SW·시스템 엔지니어링·SI·SaaS·임베디드·자동차·항공·방산·통신·금융 IT의 글로벌 진출 최강 통합 포트폴리오다.