ISO/IEC FDIS 33063
(Main)Information technology — Process assessment — Process assessment model for software testing
General Information
- Abstract
ISO/IEC 33063:2015 - defines a process assessment model that meets the requirements of ISO/IEC 33004 and that supports the performance of an assessment of process capability using the process measurement framework defined in ISO/IEC 33020. The process assessment model provides indicators for guidance on the interpretation of the process purposes and outcomes as defined in ISO/IEC/IEEE 29119‑2 and the process attributes as defined in ISO/IEC 33020, and - provides guidance, by example, on the definition, selection, and use of assessment indicators. A process assessment model comprises a set of indicators of process performance and process capability. The indicators are used as a basis for collecting the objective evidence that enables an assessor to assign ratings, following the requirements of ISO/IEC 33002. The set of indicators included in this International Standard is not intended to be an all-inclusive set nor is it intended to be applicable in its entirety. Subsets that are appropriate to the context and scope of the assessment should be selected. The process assessment model in this International Standard is directed at assessment sponsors and competent assessors who wish to select a model and associated documented process method for assessment (for either capability determination or process improvement). Any process assessment model for software testing meeting the requirements defined in ISO/IEC 33004 concerning models for process assessment may be used for assessment. Different models and methods might be needed to address differing business and testing needs. This assessment model is provided as an exemplar of a model meeting all the requirements expressed in ISO/IEC 33004.
- Status
- Not Published
- Technical Committee
- ISO/IEC JTC 1/SC 7 - Software and systems engineering
- Drafting Committee
- ISO/IEC JTC 1/SC 7/WG 10 - Process assessment
- Current Stage
- 5020 - FDIS ballot initiated: 2 months. Proof sent to secretariat
- Start Date
- 27-Aug-2026
- Completion Date
- 27-Aug-2026
Buy Documents
ISO/IEC FDIS 33063 - Information technology — Process assessment — Process assessment model for software testing
REDLINE ISO/IEC FDIS 33063 - Information technology — Process assessment — Process assessment model for software testing
Overview
ISO/IEC FDIS 33063 is an international standard published by ISO that establishes a comprehensive process assessment model for software testing. This standard is designed to help organizations assess and improve the capability of their software testing processes. It meets the requirements of ISO/IEC 33004 and aligns with the measurement framework set out in ISO/IEC 33020. ISO/IEC FDIS 33063 defines how to interpret process purposes and outcomes based on ISO/IEC/IEEE 29119‑2 and details process attributes to facilitate consistent and objective process assessment.
This process assessment model is especially valuable for assessment sponsors and qualified assessors seeking to select or apply a robust methodology for evaluating software testing processes. It provides a framework and example indicators that organizations can tailor to their specific business and testing needs, acknowledging that not all indicators or processes are relevant to every corporate context or project.
Key Topics
- Process Assessment Model Structure: ISO/IEC FDIS 33063 describes a two-dimensional process assessment model comprising a process dimension and a quality dimension.
- Process Dimension: Organized into groups such as organizational test processes, test management processes, and dynamic test processes, with references to ISO/IEC/IEEE 29119-2.
- Quality Dimension: Utilizes process attributes from ISO/IEC 33020 that enable measurement of process capability and performance.
- Assessment Indicators: The model provides two types of indicators:
- Process Performance Indicators: These relate directly to the process purposes and outcomes.
- Process Quality Indicators: These address how well process attributes have been achieved.
- Guidance on Indicator Selection: The standard includes examples and recommendations for defining, selecting, and applying assessment indicators based on the context and scope of each assessment.
- Supporting Documentation: ISO/IEC FDIS 33063 references supporting standards for terminology (ISO/IEC 33001), process frameworks (ISO/IEC 33020), and software testing processes (ISO/IEC/IEEE 29119-2).
Applications
- Software Process Improvement: Organizations can use ISO/IEC FDIS 33063 to systematically evaluate and enhance their software testing processes, identifying strengths, weaknesses, and opportunities for improvement.
- Capability Determination: The standard supports formal assessments of process capability using industry-accepted metrics, contributing to benchmarking and compliance initiatives.
- Assessment Tool Development: The model provides a foundation for creating tools or documentation to facilitate objective evidence gathering and assessment rating.
- Flexible Implementation: Recognizing the diversity of software projects and business objectives, ISO/IEC FDIS 33063 is intended to be adaptable. Organizations can apply subsets of the model or integrate additional assessment indicators as appropriate to their context.
- Alignment with International Best Practices: By referencing established standards such as ISO/IEC 33004, ISO/IEC 33020, and ISO/IEC/IEEE 29119-2, this assessment model ensures consistency and alignment with global software testing and assessment methodologies.
Related Standards
- ISO/IEC 33001: Information technology - Process assessment - Concepts and terminology.
- ISO/IEC 33004: Information technology - Process assessment - Requirements for process reference, process assessment and maturity models.
- ISO/IEC 33020: Information technology - Process assessment - Process measurement framework for assessment of process capability.
- ISO/IEC/IEEE 29119‑2: Software and systems engineering - Software testing - Part 2: Test processes.
- ISO/IEC 33002: Information technology - Process assessment - Requirements for performing process assessment.
By utilizing the ISO/IEC FDIS 33063 standard, organizations can strive for continuous process improvement in software testing, achieve greater assurance of process capability, and ensure alignment with internationally-recognized frameworks for process assessment in information technology.
Relations
- Effective Date
- 10-Aug-2024
Buy Documents
ISO/IEC FDIS 33063 - Information technology — Process assessment — Process assessment model for software testing
REDLINE ISO/IEC FDIS 33063 - Information technology — Process assessment — Process assessment model for software testing
Get Certified
Connect with accredited certification bodies for this standard

BSI Group
BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

BSCIC Certifications Pvt. Ltd.
Established 2006, accredited by NABCB, JAS-ANZ, EIAC, IAS. CDSCO Notified Body.

Intertek India Pvt. Ltd.
Delivers Assurance, Testing, Inspection & Certification since 1993 with 26 labs and 32 offices.
Sponsored listings
Frequently Asked Questions
ISO/IEC FDIS 33063 is a draft published by the International Organization for Standardization (ISO). Its full title is "Information technology — Process assessment — Process assessment model for software testing". This standard covers: ISO/IEC 33063:2015 - defines a process assessment model that meets the requirements of ISO/IEC 33004 and that supports the performance of an assessment of process capability using the process measurement framework defined in ISO/IEC 33020. The process assessment model provides indicators for guidance on the interpretation of the process purposes and outcomes as defined in ISO/IEC/IEEE 29119‑2 and the process attributes as defined in ISO/IEC 33020, and - provides guidance, by example, on the definition, selection, and use of assessment indicators. A process assessment model comprises a set of indicators of process performance and process capability. The indicators are used as a basis for collecting the objective evidence that enables an assessor to assign ratings, following the requirements of ISO/IEC 33002. The set of indicators included in this International Standard is not intended to be an all-inclusive set nor is it intended to be applicable in its entirety. Subsets that are appropriate to the context and scope of the assessment should be selected. The process assessment model in this International Standard is directed at assessment sponsors and competent assessors who wish to select a model and associated documented process method for assessment (for either capability determination or process improvement). Any process assessment model for software testing meeting the requirements defined in ISO/IEC 33004 concerning models for process assessment may be used for assessment. Different models and methods might be needed to address differing business and testing needs. This assessment model is provided as an exemplar of a model meeting all the requirements expressed in ISO/IEC 33004.
ISO/IEC 33063:2015 - defines a process assessment model that meets the requirements of ISO/IEC 33004 and that supports the performance of an assessment of process capability using the process measurement framework defined in ISO/IEC 33020. The process assessment model provides indicators for guidance on the interpretation of the process purposes and outcomes as defined in ISO/IEC/IEEE 29119‑2 and the process attributes as defined in ISO/IEC 33020, and - provides guidance, by example, on the definition, selection, and use of assessment indicators. A process assessment model comprises a set of indicators of process performance and process capability. The indicators are used as a basis for collecting the objective evidence that enables an assessor to assign ratings, following the requirements of ISO/IEC 33002. The set of indicators included in this International Standard is not intended to be an all-inclusive set nor is it intended to be applicable in its entirety. Subsets that are appropriate to the context and scope of the assessment should be selected. The process assessment model in this International Standard is directed at assessment sponsors and competent assessors who wish to select a model and associated documented process method for assessment (for either capability determination or process improvement). Any process assessment model for software testing meeting the requirements defined in ISO/IEC 33004 concerning models for process assessment may be used for assessment. Different models and methods might be needed to address differing business and testing needs. This assessment model is provided as an exemplar of a model meeting all the requirements expressed in ISO/IEC 33004.
ISO/IEC FDIS 33063 is classified under the following ICS (International Classification for Standards) categories: 35.080 - Software. The ICS classification helps identify the subject area and facilitates finding related standards.
ISO/IEC FDIS 33063 has the following relationships with other standards: It is inter standard links to ISO/IEC 33063:2015. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.
ISO/IEC FDIS 33063 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
FINAL DRAFT
International
Standard
ISO/IEC FDIS
ISO/IEC JTC 1/SC 7
Information technology — Process
Secretariat: BIS
assessment — Process assessment
Voting begins on:
model for software testing
2026-08-27
Technologies de l'information — Évaluation du procédé —
Voting terminates on:
Modèle d'évaluation du procédé pour l'essai de logiciel
2026-10-22
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
IN ADDITION TO THEIR EVALUATION AS
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
Reference number
FINAL DRAFT
International
Standard
ISO/IEC FDIS
ISO/IEC JTC 1/SC 7
Information technology — Process
Secretariat: BIS
assessment — Process assessment
Voting begins on:
model for software testing
Technologies de l'information — Évaluation du procédé —
Voting terminates on:
Modèle d'évaluation du procédé pour l'essai de logiciel
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
© ISO/IEC 2026
IN ADDITION TO THEIR EVALUATION AS
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
or ISO’s member body in the country of the requester.
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland Reference number
© ISO/IEC 2026 – All rights reserved
ii
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 The process assessment model . 1
4.1 Introduction .1
4.2 Structure of the process assessment model .2
4.2.1 General .2
4.2.2 Processes .3
4.2.3 Process dimension .4
4.2.4 Quality dimension .5
4.3 Assessment indicators .5
5 The process dimension . 6
5.1 General .6
5.2 Organizational test process group .7
5.2.1 OT.1 Organizational test process .7
5.3 Test management process group .8
5.3.1 TM.1 Test strategy and planning process .8
5.3.2 TM.2Testmonitoringand control process .10
5.3.3 TM.3 Test completion process .11
5.4 Dynamic test process group . 12
5.4.1 DT.1 Test design and implementation process . 12
5.4.2 DT.2Test environment and data management process . 13
5.4.3 DT.3 Test execution process .14
5.4.4 DT.4Test incident reporting process . 15
6 The quality dimension .15
Annex A (informative) Assessment guidelines . 17
Annex B (informative) Information product characteristics .20
Annex C (informative) Additional processes .25
Annex D (informative) Supplementary process definition .29
Bibliography .30
© ISO/IEC 2026 – All rights reserved
iii
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical activity.
ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations,
governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the various types
of ISO documents should be noted. This document was drafted in accordance with the editorial rules of the
ISO/IEC Directives, Part 2 (see www.iso.org/directivesor www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any
claimed patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not
received notice of (a) patent(s) which may be required to implement this document. However, implementers
are cautioned that this may not represent the latest information, which may be obtained from the patent
database available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held
responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT), seewww.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC1, Information technology,
Subcommittee SC 7, Software and systems engineering.
This second edition cancels and replaces the first edition (ISO/IEC 33063:2015), which has been technically
revised.
The main changes are as follows:
— update to reflect changes to ISO/IEC/IEEE 29119-2:2021 Software and systems engineering – Software
testing – Part 2: Test processes
— update to align to ISO/IEC 33020:2019 Information technology – Process assessment – Process
measurement framework for assessment of process capability
Any feedback or questions on this document should be directed to the user’s national standards
body. A complete listing of these bodies can be found at www.iso.org/members.html and
www.iec.ch/national-committees.
© ISO/IEC 2026 – All rights reserved
iv
Introduction
The set of International Standards ISO/IEC 33001 to ISO/IEC 33099 defines the requirements and
resources needed for process assessment. The overall architecture and content of the series is described in
ISO/IEC 33001.
This document defines a process assessment model for software testing, conformant with the requirements
of ISO/IEC 33004, for use in performing a conformant assessment in accordance with the requirements of
ISO/IEC 33002.
A process assessment model is related to one or more process reference models. The process reference model
defined in ISO/IEC/IEEE 29119-2 is used as the basis for the process assessment model in this document.
A process assessment model incorporates a process measurement framework conformant with the
requirements of ISO/IEC 33003 and is expressed as a process quality characteristic with a defined set of
process attributes.
A process assessment model includes a set of assessment indicators. Process performance indicators
address the process purpose and outcomes of each process in the process assessment model. Process
quality indicators demonstrate the achievement of the process attributes in the process measurement
framework. These indicators may also provide a reference source of practices when implementing a process
improvement program.
The assessment indicators are used as a basis for collecting objective evidence to support an assessor’s
judgement in assigning ratings of the performance and quality of an implemented process. The set of
indicators defined in this document is not intended to be an all-inclusive set and applicable in its entirety.
Subsets appropriate to the context and scope of the assessment should be selected, and potentially
augmented with additional indicators.
A process assessment is conducted according to a documented assessment process. A documented
assessment process identifies the rating method to be used in rating process attributes and identifies or
defines the aggregation method to be used in determining ratings.
ISO/IEC 33020 provides a process measurement framework for the assessment of process capability
which may be incorporated as a process measurement framework in this document. ISO/IEC 33020:2019,
Annex B includes a set of process quality indicators for each process attribute in the process measurement
framework.
NOTE As the processes described in this model are generic when practically applied to an assessment, they can be
applied to the different test levels or test levels or test types encountered in any project which is to be assessed. The
multiple applications of the processes can be documented in the assessment scope.
© ISO/IEC 2026 – All rights reserved
v
FINAL DRAFT International Standard ISO/IEC FDIS 33063:2026(en)
Information technology — Process assessment — Process
assessment model for software testing
1 Scope
This document defines a process assessment model for software testing, conformant with the requirements
of ISO/IEC 33004, for use in performing a conformant assessment in accordance with the requirements of
ISO/IEC 33002.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content constitutes
requirements of this document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
ISO/IEC/IEEE 29119-1, Software and systems engineering — Software testing — Part 1: General concepts
ISO/IEC/IEEE 29119-2, Software and systems engineering — Software testing — Part 2: Test processes
ISO/IEC 33001, Information technology — Process assessment — Concepts and terminology
3 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO/IEC 33001, ISO/IEC/IEEE 29119-1
and ISO/IEC/IEEE 29119-2 apply.
ISO and IEC maintain terminological databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https:// www .iso .org/ obp
— IEC Electropedia: available at https:// www .electropedia .org/
4 The process assessment model
4.1 Introduction
This document provides a basis for a process assessment model that is a two-dimensional model.
In one dimension, the process dimension, the processes are defined and classified into process
categoriestogetherwiththesetofassessmentindicatorsofprocessperformance. In the other dimension, the
quality dimension, for each process attribute in the process measurement framework a set of process quality
indicators is defined for the selected process quality characteristic.
© ISO/IEC 2026 – All rights reserved
Figure 1 — Structure of the process assessment model
Figure 1 shows the process assessment model as a two-dimensional model, the process dimension with its
relationship to ISO/IEC/IEEE 29119-2 test processes, and the quality dimension in relationship to a process
measurement framework.
Users of this document may freely reproduce the detailed descriptions contained in the assessment model as
part of any tool or other material to support the performance of process assessments, so that it can be used
for its intended purpose.
4.2 Structure of the process assessment model
4.2.1 General
This clause describes the detailed structure of the process assessment model and its key components.
The process dimension comprises the set of processes defined with the process purpose and process
outcomes together with a set of assessment indicators of process performance.
In accordance with ISO/IEC 33004, a process shall be described in terms of its purpose and process
outcomes, and the set of process outcomes shall be necessary and sufficient to achieve the purpose of the
process (ISO/IEC 33004:2015, 5.4).
The processes in this document are derived directly from ISO/IEC/IEEE 29119-2and meet the ISO/IEC 33004
requirements for process descriptions, process purposes and outcomes.
The process assessment model includes the following process groups defined in ISO/IEC/IEEE 29119-2
— the organizational test process group;
— the test management processes group;
— the dynamic test processes group.
Additionally. the static test processes group is added in an informative Annex C and D expanding the process
assessment model to accommodate standard verification practices such as reviews and static analysis.
© ISO/IEC 2026 – All rights reserved
The quality dimension comprising a set of process attributes for a selected process quality characteristic is
incorporated as a process measurement framework together with a set of process quality indicators.
NOTE ISO/IEC 33020 provides a process measurement framework for the assessment of process capability which
can be incorporated into this document. ISO/IEC 33020 also includes a set of process quality indicators for each
process attribute in the process measurement framework.
4.2.2 Processes
Figure 2 lists the processes from ISO/IEC/IEEE 29119-2 that are included in the process dimension of the
process assessment model for software testing.
Figure 2 — ISO/IEC/IEEE 29119-2process groups and processes
Test processes in this process assessment model are classified into organizational test (OT) process group,
test management (TM) process group and dynamic test (DT) process group, exactly following the structure
given in the process reference model.
The organizational test process group includes a single process performed for the creation and maintenance
of organizational test specifications, such as organizational test policies, organizational test strategies, and
other organization-wide specifications.
This group includes the process listed in Table 1.
Table 1 — Organizational test process group
Process Identifi-
Process name Source
cation
OT.1 Organizational test process ISO/IEC/IEEE 29119-2
The test management process group consists of processes that cover the management of testing. The
processes contain practices that may be used by anyone who manages the whole test project or a particular
test level, or test type within the project.
This group includes the processes listed in Table 2.
© ISO/IEC 2026 – All rights reserved
Table 2 — Test management process group
Process Identifi-
Process name Source
cation
TM.1 Test strategy and planning process ISO/IEC/IEEE 29119-2
TM.2 Test monitoring and control process ISO/IEC/IEEE 29119-2
TM.3 Test completion process ISO/IEC/IEEE 29119-2
The dynamic test process group consists of processes that prepare and maintain the test environment;
design, implement and execute the tests and/or report the incidents resulting from the test execution.
The dynamic test process group includes the processes listed in Table 3.
Table 3 — Dynamic test process group
Process Identifi-
Process name Source
cation
DT.1 Test design and implementation process ISO/IEC/IEEE 29119-2
DT.2 Test environment and data management process ISO/IEC/IEEE 29119-2
DT.3 Test execution process ISO/IEC/IEEE 29119-2
DT.4 Test incident reporting process ISO/IEC/IEEE 29119-2
As illustrated in the Annex A.2, the processes within the test management process group and dynamic test
process group are generic. Within the context of an assessment, they can be applied to the whole project,
different test levels, or test types depending on the characteristics of the project to be assessed.
For example, processes within the test management process can be applied to the management of projects
(e.g. master test level), of test levels such as unit testing or acceptance testing, or of types of testing such as
security testing and performance testing. The processes within the dynamic test process group can e.g. be
applied to integration testing or performance testing, security testing or other test levels/test types.
NOTE Application of the test management processes is unique for each situation with distinct characteristics,
hence Annex A.2, Process Application Guideline, is normative.
For practical purposes, three additional processes are added in an informative Annex C. The additional
processes include: problem resolution management process (TM.4)from ISO/IEC 15504-5, and work product
review process(STAT.1) from ISO/IEC 20246and the static analysis process (STAT.2)from Annex D. The
additional processes are included for the practical assessment of software test processes reflecting the
industry practice.
A guideline on the use of additional processes from other process assessment models is provided in
Annex A.3.
4.2.3 Process dimension
For the process dimension, all the processes in Figure 2 are included within the process dimension of the
process assessment model. The processes are classified into process groups. There are four process groups:
organizational test process group, test management process group, dynamic test process group, and static
test process group. The process groups and their associated processes are described in Clause 5and in
Annex C.
Each process in the process assessment model is described in terms of a purpose statement. These statements
contain the unique functional objectives of the process when performed in a particular environment. A list
of specific outcomes is associated with each of the process purpose statements, as a list of expected positive
results of the process performance.
Satisfying the purpose statement of a process represents the first step in building a level 1 process capability
where the expected outcomes are observable.
© ISO/IEC 2026 – All rights reserved
4.2.4 Quality dimension
For the quality dimension, the minimum requirement is that the process is performed, i.e. the implemented
process achieves its process purpose and the expected outcomes are observable.
Process attributes are features of a process that can be evaluated on a scale of achievement, providing a
measure of the quality of the process and are applicable to all processes.
Further details on the quality dimension can be found in Clause 6.
4.3 Assessment indicators
A process assessment model is based on the principle that the quality of a process can be assessed by
demonstrating the achievement of process attributes on the basis of evidences related to assessment
indicators.
There are two types of assessment indicators: process performance indicators and process quality
indicators. Process performance indicators address the process purpose and outcomes of each process in
the process dimension. Process quality indicators demonstrate the achievement of the process attributes in
the quality dimension.
The process performance indicators are:
— base practice (BP);
— information products (IP).
The performance of base practices (BPs) provide an indication of the extent of achievement of the process
purpose and process outcomes. Information products (IPs) are either used or produced (or both), when
performing the process. Information items that are the key outputs of the process are primarily used as
performance indicators.
Annex B provides the list of information products (IP) associated with the processes in Clause 5. The
information products are classified by categories. In addition, for each information item the process(es) that
generated it are listed.
Process quality indicators depend on the process quality characteristic of interest. The minimum
requirement is that at least one of the process attributes shall comprise the achievement of the defined
process purpose and process outcomes for the process; this is termed the process performance attribute
(see ISO/IEC 33003:2015, 4.2.1).
The process performance and process quality indicators represent types of objective evidence that may be
found in an instantiation of a process and therefore could be used to judge achievement of quality. Figure 3
shows how the assessment indicators are related to process performance and process quality.
© ISO/IEC 2026 – All rights reserved
Figure 3 — Assessment indicators
5 The process dimension
5.1 General
This clause defines the processes and the process performance indicators of the process assessment model.
The processes in the process dimension can be directly mapped to the processes defined in the process
reference model.
The processes are classified (for the purpose of this process assessment model) into process groups which
are listed in Clause 4.
The individual processes are described in terms of process name, process purpose, and process outcomes as
defined in ISO/IEC/IEEE 29119-2.
In addition, the process performance indicators of the process assessment model provide information in the
form of:
a) base practices for the process providing a definition of the tasks and activities needed to accomplish the
test process purpose and fulfil the process outcomes; each base practice is associated to one or more
process outcomes; and
b) information products that are the key outputs of the process, and are related to one or more process
outcomes; and
c) characteristics associated with each information product.
The process purposes, outcomes, the base practices and the information products associated with the
processes are included in this clause. The information product characteristics are contained in Annex B. The
base practices and information products constitute the set of indicators of process performance.
The associated information products listed in this clause may be used when reviewing potential inputs and
outputs of an organization's process implementation.
© ISO/IEC 2026 – All rights reserved
The associated information products provide objective guidance for outputs to look for and objective
evidence supporting the assessment of a particular process.
A documented assessment process and assessor judgment is needed to ensure that process context
(application domain, business purpose, development and testing methodology, size of the organization, etc.)
is explicitly considered when using this information.
This assessment process should not be considered as a checklist of what each organization must have but
rather as an example and starting point for considering whether, given the context, the information products
are necessary and contributing to the intended purpose of the process.
NOTE Consideration of assessing the additional test process areas in Annex C such as work product review
process (STAT.1), static analysis process (STAT.2) and problem resolution management process (TM.4) can be required
to guarantee the assessment of all the test processes.
5.2 Organizational test process group
5.2.1 OT.1 Organizational test process
Process ID OT.1
Process name Organizational test process
Process purpose The purpose of the organizational test process is to develop, monitor conformance
and maintain organizational test specifications, such as the organizational test poli-
cy and organizational test practices document.
Process outcomes As a result of the successful implementation of the organizational test process:
a) The requirements for organizational test specifications are identified.
b) The organizational test specifications are developed.
c) The organizational test specifications are agreed by stakeholder(s).
d) The organizational test specifications are made accessible.
e) Conformance to the organizational test specifications is monitored.
f) Updates to organizational test specifications are agreed to by stakeholders.
g) Updates to the organizational test specifications are made.
NOTE Updates to the organizational test specifications will only be made when needed.
Base practicesOT.1.BP1: Develop organizational test specification. Develop an organizational
test specification such as organizational test policy or organizational test practices,
processes, procedures and other assets.[Outcome: a, b, c]
OT.1.BP2: Monitor and control use of organizational test specification. Moni-
tor and control usage of organizational test specification to determine whether it is
being used effectively. [Outcome: d, e]
OT.1.BP3: Update organizational test specification. Update organizational test
specification by reviewing feedbacks. [Outcome: e, f, g]
Information prod- Organizational test policy [Outcome: a, b, c, d, e, f, g]
ucts
Organizational test practices document [Outcome: a, b, c, d, e, f, g]
© ISO/IEC 2026 – All rights reserved
5.3 Test management process group
5.3.1 TM.1 Test strategy and planning process
Process ID TM. 1
Process name Test strategy and planning process
Process purpose The purpose of the test strategy and planning process is to develop, agree, record
and communicate to relevant stakeholders the scope and approach to be taken to
testing, enabling early identification of resources, environments and other require-
ments of testing.
Process outcomes As a result of the successful implementation of the test strategy and planning process:
a) The scope of the testing is analysed and understood.
b) The stakeholders who will participate in designing the test strategy and the test
planning are identified and informed.
c) Risks that can be treated by testing are identified, analysed and classified with
an agreed level of risk exposure.
d) Test strategy, test environment, test tool and test data needs are identified.
EXAMPLE Tools, special equipment, test environment, office space.
e) Staffing and training needs are identified.
f) Each activity is scheduled.
g) Estimates are calculated and evidence to justify the estimates is recorded.
EXAMPLE Cost, staff, and timeline estimates.
h) The test plan is agreed to and distributed to all stakeholders.
Base practices NOTE Base practices in this process relate to the project level test planning and
also particular test planning of a test level (unit/integration/system/acceptance test
plan) or a test type (e.g. performance/security/usability test plan).
TM.1.BP1: Understand context. Understand and document the context and the
software testing requirements through reviewing the related documents (e.g. soft-
ware development plan, related test basis, etc.) and identifying and interacting with
the relevant stakeholders. [Outcome: a]
NOTE This activity should be an on-going activity throughout the lifetime of the
project and the tasks in this activity can, in principle, be carried out in any order.
TM.1.BP2: Organize test plan development. Organize activities for test plan devel-
opment ensuring early involvement of testing in the software development life cycle.
Test planning begins with development planning and is iteratively updated through-
out the software development life cycle to accommodate changing requirements and
continuous delivery paradigms. [Outcome: b]
TM.1.BP3: Identify and analyze risks. Identify, classify, evaluate and document
risks that are related to project and/or product, which can be treated by software
testing. [Outcome: c]
TM.1.BP4: Identify risk treatment approaches. Identify and document appropri-
ate means of treating the risks (such as test levels, test types, test techniques and
test completion criteria). [Outcome: c]
TM.1.BP5: Design test strategy. Design and document the test strategy and stand-
ard test process to be undertaken considering:
© ISO/IEC 2026 – All rights reserved
— overall test planning in the project level or test planning for particular test
level(s) and/or test type(s)
— functional and non-functional testing requirements
— early involvement of test planning and design activities in development life
cycle
Also include the strategy to be undertaken with regard to:
— selected test levels and test types
— test deliverables
— test design techniques
— entry and exit criteria
— test completion criteria
— degree of independence
— metrics to be collected
— test data requirements
— justified deviations from the organizational test practices
An initial estimate of the required resources to perform the complete set of actions
described in the test strategy should also be produced. [Outcome: d, e, f, g]
NOTE Where an organizational test process is available, existing process may be
tailored to fit to the project context and risk.
TM.1.BP6: Determine staffing and scheduling. Identify the roles and skills that
are required to carry out the testing described in the test strategy. Each test activity
in the test strategy should be scheduled. [Outcome: e, f, h]
NOTE Where appropriate, identify recruitment and/or training needs.
TM.1.BP7: Record test plan. Document identified risks, test strategy and all the test
decisions, final test estimates, test schedule and create the test plan. [Outcome: h]
TM.1.BP8: Gain consensus on test plan. Issue the draft test plan for review and
approval by stakeholders. [Outcome: h]
TM.1.BP9: Communicate test plan and make available. Publish the test plan in a
suitable form so that it is accessible to all stakeholders. [Outcome: h]
Information prod- Test strategy [Outcome a, b, c, d]
ucts
Test plan [Outcome a, b, c, d, e, f, g, h]
© ISO/IEC 2026 – All rights reserved
5.3.2 TM.2Testmonitoringand control process
Process ID TM.2
Process name Test monitoring and control process
Process purpose The purpose of the test monitoring and control process is to determine whether
testing progresses in accordance with the test plan and with organizational test
specifications (e.g. the organizational test policy and the organizational test prac-
tices). It also initiates control actions as necessary and identifies necessary updates
to the test plan (e.g. revise completion criteria or identify new actions to compen-
sate for deviations from the test plan).
The process is also used to determine whether testing progresses in accordance
with higher level test plans, such as the project test plan, and to manage the testing
performed at specific test levels (e.g. system testing) or for specific test types (e.g.
performance testing).
Process outcomes As a result of the successful implementation of the test monitoring and control process:
a) The means of collecting suitable measures to monitor test progress and
changing risk are set up.
b) Progress against the test plan is monitored.
c) New and changed test-related risks are identified, analysed and necessary
action(s) invoked.
d) Necessary control actions are identified.
e) Necessary control actions are communicated to the relevant stakeholders.
f) The decision to stop testing is approved.
g) Test progress and changes to the risks are reported to stakeholders.
Base practices TM.2.BP1: Set-up. Identify suitable measures for monitoring test progress against
the test plan and define means of identifying new and changing risks. [Outcome: a]
TM.2.BP2: Monitor. Monitor the progress of test processes (e.g. unit test, system
test, performance test, usability test, etc.) against the test plan, then identify and
document the divergence of actual testing from planned testing and analyse any
new risks. [Outcome: b, c]
TM.2.BP3: Control. Undertake the testing activities documented in the test plan
and control directives received from higher level management processes. Identify
and take corrective action to deal with any discrepancy between planned progress
and actual progress. [Outcome: d, e, f]
TM.2.BP4: Report. Document and communicate testing progress against the test
plan to stakeholders. [Outcome: g]
Information prod- Test status report [Outcome: a, b, c, d, e, f, g]
ucts
© ISO/IEC 2026 – All rights reserved
5.3.3 TM.3 Test completion process
Process ID TM. 3
Process name Test completion process
Process purpose The purpose of the test completion process is to make available useful
test assets for later use, leave the test environment in a satisfactory con-
dition and record and communicate the results of the testing to relevant
stakeholders. Test assets include test plans, test case specifications, test
scripts, test tools, test data and test environment infrastructure.
Process out- As a result of the successful implementation of the test completion process:
comes
a) Test assets are either archived or passed directly to the relevant
stakeholders.
b) The test environment is in its agreed state (e.g. so that it is available
for any following testing).
c) The test completion report is recorded.
d) The test completion report is approved.
e) The test completion report is communicated to relevant stakeholders.
Base practices TM.3.BP1: Archive test assets. Identify test assets that may be useful
in future or are expected to be reused at a later date. Then make them
available using appropriate version control systems and repositories.
[Outcome: a]
TM.3.BP2: Clean up test environment. Restore the test environment to
a pre-defined state on completion of all testing activities. [Outcome: b]
TM.3.BP3: Identify lessons learned. Document the outcomes of the
meeting for collecting lessons learned in the test completion report and
communicate to the relevant authorities. [Outcome: c, e]
TM.3.BP4: Report test completion. Summarize the information collect-
ed during the project into a test completion report, obtain approval of the
report and distribute to the relevant stakeholders. [Outcome: c, d, e]
NOTE Relevant information from test plans, test results, test status re-
ports, test completion reports, Incident reports, etc. can be used.
Information Test completion report [Outcome: a, b, c, d, e]
products
© ISO/IEC 2026 – All rights reserved
5.4 Dynamic test process group
5.4.1 DT.1 Test design and implementation process
Process ID DT.1
Process name Test design and implementation process
Process purpose The purpose of the test design and implementation process is to derive test proce-
dures that can be executed during the test execution process. As part of this process
the test basis is analysed, and a test model, test coverage items, test cases, and test
procedures are derived.
Process outcomes As a result of the successful implementation of the test design and implementation process:
a) The test basis for each test item is analysed.
b) A test model is created.
c) The test coverage items are identified.
d) Test cases are derived.
e) Test procedures are created.
Base practices DT.1.BP1: Create test model. Analyse the test basis, identify characteristics of the
test item that are to be tested based on test strategy and create the test model for
the test item. Record the traceability between the test basis and the test model. [Out-
come: a, b]
DT.1.BP2: Identify test coverage items. The test coverage items to be exercised
are identified from the test model by applying test design techniques (e.g. statement
testing, branch testing, decision testing, etc.) to achieve the test completion criteria
specified in the test plan. Record the traceability between the test basis, test model
and the test coverage items. [Outcome: c]
DT.1.BP3: Derive test cases. Derive one or more test cases by determining pre-con-
ditions, selecting input values and, where necessary, actions to exercise the selected
test coverage items, and by determining the corresponding expected testing results.
Record the traceability between the test basis, test model, test coverage items and
test cases. [Outcome: d]
DT.1.BP4: Create test procedures. Derive test procedures by ordering test cases
according to dependencies described by pre- and post-conditions and other testing
requirements, such as risks to be treated for testing. Record the traceability between
the test basis, test model, test coverage items, test cases, test procedures and/or
automated test scripts. [Outcome: e]
Information prod- Test model [Outcome: a, b]
ucts
Test coverage item [Outcome: c]
Test case[Outcome: d]
Test procedure[Outcome: e]
Traceability information [Outcome: a, b, c, d, e]
Test data requirements [Outcome: e]
Test environment requirements [Outcome: e]
© ISO/IEC 2026 – All rights reserved
5.4.2 DT.2Test environment and data management process
Process ID DT.2
Process name Test environment and data management process
Process purpose The purpose of the test environment and data management process is to establish
and maintain the required test environment and test data and to communicate their
status to all relevant stakeholders.
Process outcomes As a result of the successful implementation of the test environment and data management process:
a) The test environment is set-up in a state ready for testing.
b) The status of the test environment is communicated to all relevant stakeholders.
c) The test environment is maintained.
d) The test data is prepared and is in a state ready for testing.
e) The status of the test data is communicated to all relevant stakeholders.
f) The test data is maintained.
Base practices DT.2.BP1: Establish test environment. Plan, design, build, configure, and verify a
test environment based on defined requirements and testing needs. The status of the
test environment is recorded in the test readiness report and communicated to the
relevant stakeholders. [Outcome: a, b]
NOTE Test environments can be set up manually or as Infrastructure as Code (IaC).
DT.2.BP2: Prepare test data. Based on the test plan, the detailed requirements
generated as a result of the test design and implementation process, and the scale/
formality of the testing, plan the preparation of the test data and prepare the test
data. The status of the test data is communicated to the relevant stakeholders, such
as the testers and the test manager. [Outcome: d, e]
DT.2.BP3: Maintain test environment. Maintain the required test environment
for immediate and continuous use. A te
...
Style Definition
...
Style Definition
...
Style Definition
Style Definition
...
ISO/IEC / JTC1/SC7 WG 10JTC 1/SC 7
Style Definition
...
Style Definition
Secretariat: BIS .
Style Definition
...
Date: 2026-06-2208-13
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
Information technology – — Process assessment –— Process
...
Style Definition
assessment model for software testing
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
Technologies de l'information — Évaluation du procédé — Modèle d'évaluation du procédé pour l'essai de .
logiciel
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
FDIS stage Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Warning for WDs and CDs
Style Definition
...
This document is not an ISO International Standard. It is distributed for review and comment. It is subject to
Style Definition
...
change without notice and may not be referred to as an International Standard.
Style Definition
...
Recipients of this draft are invited to submit, with their comments, notification of any relevant patent rights of
Style Definition
...
which they are aware and to provide supporting documentation.
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
...
Style Definition
ISO #####-#:####(X)
2 © ISO #### – All rights reserved
Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: HeaderCentered, Left, Space After: 0 pt,
© ISO/IEC 2026
Line spacing: single
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication
Formatted: Right: 1.5 cm, Bottom: 1 cm, Gutter: 0 cm,
may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying,
Header distance from edge: 1.27 cm, Footer distance
or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO
from edge: 0.5 cm
at the address below or ISO’s member body in the country of the requester.
Formatted: Indent: Left: 0 cm, Right: 0 cm, Adjust
space between Latin and Asian text, Adjust space
ISO copyright office
between Asian text and numbers
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: + 41 22 749 01 11
Formatted: French (France)
EmailE-mail: copyright@iso.org
Formatted: French (France)
Website: www.iso.orgwww.iso.org
Formatted: French (France)
Published in Switzerland
Formatted: English (United Kingdom)
Formatted: English (United Kingdom)
Formatted: Font: 10 pt
Formatted: Font: 10 pt
Formatted: Font: 10 pt
Formatted: Font: 11 pt
Formatted: FooterPageRomanNumber, Space After: 0
pt, Line spacing: single
© ISO /IEC 2026 – All rights reserved
iii
Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: HeaderCentered, Space After: 0 pt, Line
Contents
spacing: single
Formatted: Space Before: 48 pt
Foreword . vi
Introduction . vii
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 The process assessment model . 1
4.1 Introduction . 1
4.2 Structure of the process assessment model . 3
4.3 Assessment indicators . 6
5 The process dimension . 8
5.1 General . 8
5.2 Organizational test process group . 9
5.3 Test management process group . 10
5.4 Dynamic test process group . 15
6 The quality dimension . 18
Annex A (informative) Assessment guidelines . 19
Annex B (informative) Information product characteristics . 22
Annex C (informative) Additional processes . 28
Annex D (informative) Supplementary process definition . 32
Bibliography . 33
Foreword . v
Introduction . vi
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 The process assessment model . 1
4.1 Introduction . 1
4.2 Structure of the process assessment model . 2
4.2.1 General . 2
4.2.2 Processes . 3
4.2.3 Process dimension. 5
4.2.4 Quality dimension . 5
4.3 Assessment indicators . 5
5 The process dimension . 6
5.1 General . 6
Formatted: Font: 10 pt
5.2 Organizational test process group . 7
5.2.1 OT.1 Organizational test process . 7 Formatted: Font: 10 pt
5.3 Test management process group . 8
Formatted: Font: 10 pt
5.3.1 TM.1 Test strategy and planning process . 8
Formatted: Font: 11 pt
5.3.2 TM.2 Test monitoring and control process . 9
5.3.3 TM.3 Test completion process . 10
Formatted: FooterPageRomanNumber, Space After: 0
pt, Line spacing: single
iv © ISO /IEC 2026 – All rights reserved
iv
Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: HeaderCentered, Left, Space After: 0 pt,
5.4 Dynamic test process group . 11
Line spacing: single
5.4.1 DT.1 Test design and implementation process . 11
5.4.2 DT.2 Test environment and data management process . 12
5.4.3 DT.3 Test execution process . 13
5.4.4 DT.4 Test incident reporting process . 14
6 The quality dimension . 14
Annex A (informative) Assessment guidelines . 16
A.1 General assessment guideline . 16
A.2 Process application guideline . 16
A.3 Use of additional processes from other process assessment models guideline . 18
Annex B (informative) Information product characteristics . 19
B.1 Information product categories . 19
B.2 Information product description . 20
Annex C (informative) Additional processes . 24
C.1 Static testing process group . 24
C.1.1 STAT.1 Work product review process . 24
C.1.2 STAT.2Static analysis process . 25
C.2 Test management process group . 26
C.2.1 TM.4 Problem resolution management process . 26
Annex D (informative) Supplementary process definition . 28
D.1 Static analysis process . 28
Bibliography . 29
Formatted: Font: 10 pt
Formatted: Font: 10 pt
Formatted: Font: 10 pt
Formatted: Font: 11 pt
Formatted: FooterPageRomanNumber, Space After: 0
pt, Line spacing: single
© ISO /IEC 2026 – All rights reserved
v
Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: HeaderCentered, Space After: 0 pt, Line
Foreword
spacing: single
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are members
of ISO or IEC participate in the development of International Standards through technical committees
established by the respective organization to deal with particular fields of technical activity. ISO and IEC
technical committees collaborate in fields of mutual interest. Other international organizations, governmental
and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the various types of
ISO documents should be noted. This document was drafted in accordance with the editorial rules of the
ISO/IEC Directives, Part 2 (see www.iso.org/directiveswww.iso.org/directivesor
www.iec.ch/members_experts/refdocswww.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the use of
(a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any claimed
patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not received
notice of (a) patent(s) which may be required to implement this document. However, implementers are
cautioned that this may not represent the latest information, which may be obtained from the patent database
available at www.iso.org/patents and https://patents.iec.ch.www.iso.org/patents and https://patents.iec.ch.
ISO and IEC shall not be held responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT),
seewww.iso.org/iso/foreword.html.www.iso.org/iso/foreword.html. In the IEC, see
www.iec.ch/understanding-standardswww.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC1, Information technology],,
Subcommittee SC 7, Software and systems engineering.
This second edition cancels and replaces the first edition (ISO/IEC 33063:2015), which has been technically
revised.
The main changes are as follows:
Formatted: Font: Cambria
— update to reflect changes to ISO/IEC/IEEE 29119-2:2021 Software and systems engineering – Formatted: List Continue 1, No bullets or numbering
Software testing – Part 2: Test processes
— update to align to ISO/IEC 33020:2019 Information technology – Process assessment – Process
measurement framework for assessment of process capability
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www.iso.org/members.htmlwww.iso.org/members.html and
Formatted: Font: 10 pt
www.iec.ch/national-committeeswww.iec.ch/national-committees.
Formatted: Font: 10 pt
Formatted: Font: 10 pt
Formatted: Font: 11 pt
Formatted: FooterPageRomanNumber, Space After: 0
pt, Line spacing: single
vi © ISO /IEC 2026 – All rights reserved
vi
Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: HeaderCentered, Left, Space After: 0 pt,
Introduction
Line spacing: single
The set of International Standards ISO/IEC 33001 to ISO/IEC 33099 defines the requirements and resources
needed for process assessment. The overall architecture and content of the series is described in ISO/IEC
33001.
This document defines a process assessment model for software testing, conformant with the requirements
of ISO/IEC 33004, for use in performing a conformant assessment in accordance with the requirements of
ISO/IEC 33002.
A process assessment model is related to one or more process reference models. The process reference model
defined in ISO/IEC/IEEE 29119-2 is used as the basis for the process assessment model in this document.
A process assessment model incorporates a process measurement framework conformant with the
requirements of ISO/IEC 33003 and is expressed as a process quality characteristic with a defined set of
process attributes.
A process assessment model includes a set of assessment indicators. Process performance indicators address
the process purpose and outcomes of each process in the process assessment model. Process quality
indicators demonstrate the achievement of the process attributes in the process measurement framework.
These indicators may also provide a reference source of practices when implementing a process improvement
program.
The assessment indicators are used as a basis for collecting objective evidence to support an assessor’s
judgement in assigning ratings of the performance and quality of an implemented process. The set of
indicators defined in this document is not intended to be an all-inclusive set and applicable in its entirety.
Subsets appropriate to the context and scope of the assessment should be selected, and potentially augmented
with additional indicators.
A process assessment is conducted according to a documented assessment process. A documented assessment
process identifies the rating method to be used in rating process attributes and identifies or defines the
aggregation method to be used in determining ratings.
ISO/IEC 33020 provides a process measurement framework for the assessment of process capability which
Formatted: Body Text, Adjust space between Latin and
may be incorporated as a process measurement framework in this document. ISO/IEC 33020:2019, Annex B
Asian text, Adjust space between Asian text and
includes a set of process quality indicators for each process attribute in the process measurement framework.
numbers
Formatted: Default Paragraph Font, Font: 11 pt
NOTE As the processes described in this model are generic when practically applied to an assessment, they can be
Formatted: Default Paragraph Font, Font:
applied to the different test levels or test levels or test types encountered in any project which is to be assessed. The
Formatted: Note, Adjust space between Latin and
multiple applications of the processes can be documented in the assessment scope.
Asian text, Adjust space between Asian text and
Formatted: Default Paragraph Font
Formatted: Normal
Formatted: Font: 10 pt
Formatted: Font: 10 pt
Formatted: Font: 10 pt
Formatted: Font: 11 pt
Formatted: FooterPageRomanNumber, Space After: 0
pt, Line spacing: single
© ISO /IEC 2026 – All rights reserved
vii
Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: HeaderCentered, Left, Space After: 0 pt,
Line spacing: single
Information technology – — Process assessment –— Process
Formatted: Main Title 1, Space After: 0 pt
assessment model for software testing
Formatted: Font: Bold
Formatted: Right: 1.5 cm, Bottom: 1 cm, Gutter: 0 cm,
1 Scope
Section start: New page, Header distance from edge:
1.27 cm, Footer distance from edge: 0.5 cm
This document defines a process assessment model for software testing, conformant with the requirements
of ISO/IEC 33004, for use in performing a conformant assessment in accordance with the requirements of
ISO/IEC 33002.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content constitutes
requirements of this document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
Formatted: English (United Kingdom)
ISO/IEC/IEEE 29119-1, Software and Systems Engineering –systems engineering — Software Testing –testing
Formatted: English (United Kingdom)
— Part 1: General concepts
Formatted: English (United Kingdom)
ISO/IEC/IEEE 29119-2, Software and Systems Engineering –systems engineering — Software Testing –testing
Formatted: RefNorm
— Part 2: Test Processesprocesses
Formatted: English (United Kingdom)
ISO/IEC 33001, Information technology -— Process assessment –— Concepts and terminology
Formatted: Font: Not Italic, English (United Kingdom)
Formatted: English (United Kingdom)
3 Terms and definitions
Formatted: English (United Kingdom)
For the purposes of this document, the terms and definitions given in ISO/IEC 33001, ISO/IEC/IEEE 29119-1
Formatted: English (United Kingdom)
and ISO/IEC/IEEE 29119-2 apply.
Formatted: English (United Kingdom)
ISO and IEC maintain terminological databases for use in standardization at the following addresses:
Formatted: Font: Not Italic, English (United Kingdom)
Formatted: English (United Kingdom)
— ISO Online browsing platform: available at https://www.iso.org/obphttps://www.iso.org/obp
Formatted: English (United Kingdom)
— IEC Electropedia: available at http://www.electropedia.org/https://www.electropedia.org/
Formatted: English (United Kingdom)
Formatted: English (United Kingdom)
4 The process assessment model
Formatted: Font: Font color: Auto
4.1 Introduction
Formatted: Body Text, Adjust space between Latin and
Asian text, Adjust space between Asian text and
This document provides a basis for a process assessment model that is a two-dimensional model. In one
numbers
dimension, the process dimension, the processes are defined and classified into process
Formatted: List Continue 1, No bullets or numbering
categoriestogetherwiththesetofassessmentindicatorsofprocessperformance. In the other dimension, the
Formatted: English (United Kingdom)
quality dimension, for each process attribute in the process measurement framework a set of
processqualityprocess quality indicators is defined for the selected process quality characteristic.
Formatted: English (United Kingdom)
Formatted: English (United Kingdom)
Formatted: English (United Kingdom)
Formatted: Font: 10 pt
Formatted: Font: 10 pt
Formatted: Font: 10 pt
Formatted: Font: 11 pt
Formatted: FooterPageNumber, Space After: 0 pt, Line
spacing: single
© ISO /IEC 2026 – All rights reserved
Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: HeaderCentered, Space After: 0 pt, Line
spacing: single
Figure 1 — Figure 1 — Structure of the process assessment model
Formatted: Figure title
Formatted: Body Text
Figure 1Figure 1 shows the process assessment model as a two-dimensional model, the process dimension
with its relationship to ISO/IEC/IEEE 29119-2 test processes, and the quality dimension in relationship to a Formatted: Font: English (United Kingdom)
process measurement framework.
Formatted: Font: 10 pt
Formatted: Font: 10 pt
Users of this document may freely reproduce the detailed descriptions contained in the assessment model as
part of any tool or other material to support the performance of process assessments, so that it can be used
Formatted: Font: 10 pt
for its intended purpose.
Formatted: Font: 11 pt
Formatted: FooterPageNumber, Space After: 0 pt, Line
spacing: single
2 © ISO /IEC 2026 – All rights reserved
Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: HeaderCentered, Left, Space After: 0 pt,
4.2 Structure of the process assessment model
Line spacing: single
Formatted: Dutch (Netherlands)
4.2.1 General
This clause describes the detailed structure of the process assessment model and its key components.
The process dimension comprises the set of processes defined with the process purpose and process outcomes
together with a set of assessment indicators of process performance.
In accordance with ISO/IEC 33004, a process shall be described in terms of its purpose and process outcomes,
and the set of process outcomes shall be necessary and sufficient to achieve the purpose of the process
(ISO/IEC 33004:2015, 5.4).
The processes in this document are derived directly from ISO/IEC/IEEE 29119-2and meet the ISO/IEC 33004
Formatted: English (United Kingdom)
requirements for process descriptions, process purposes and outcomes.
The process assessment model includes the following process groups defined in ISO/IEC/IEEE 29119-2
Formatted: Font: English (United Kingdom)
Formatted: Body Text
— the organizational test process group;
Formatted: List Continue 1, No bullets or numbering
— the test management processes group;
— the dynamic test processes group.
Additionally. the static test processes group is added in an informative Annex CAnnex C and DD expanding the
Formatted: Font: English (United Kingdom)
process assessment modeltomodel to accommodate standard verification practices such as reviews and static
Formatted: Font: English (United Kingdom)
analysis.
Formatted: Font: English (United Kingdom)
The quality dimension comprising a set of process attributes for a selected process quality characteristic is
Formatted: Body Text
incorporated as a process measurement framework together with a set of process quality indicators.
Formatted: Font: English (United Kingdom)
Formatted: Body Text, Adjust space between Latin and
NOTE ISO/IEC 33020 provides a process measurement framework for the assessment of process capability which Asian text, Adjust space between Asian text and
can be incorporated into this document. ISO/IEC 33020 also includes a set of process quality indicators for each process
numbers
attribute in the process measurement framework.
Formatted: Font: Cambria
4.2.2 Processes
Formatted: Dutch (Netherlands)
Figure 2Figure 2 lists the processes from ISO/IEC/IEEE 29119-2 that are included in the process dimension
Formatted: English (United Kingdom)
of the process assessment model for software testing.
Formatted: Font: 10 pt
Formatted: Font: 10 pt
Formatted: Font: 10 pt
Formatted: Font: 11 pt
Formatted: FooterPageNumber, Space After: 0 pt, Line
spacing: single
© ISO /IEC 2026 – All rights reserved
Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: HeaderCentered, Space After: 0 pt, Line
spacing: single
Formatted: Font: English (United Kingdom)
Formatted: Font: English (United Kingdom)
Formatted: Font: English (United Kingdom)
Formatted: Font: Not Bold, English (United Kingdom)
Formatted: Figure title, Left, None
Formatted: Font: English (United Kingdom)
Formatted: Body Text
Figure 2 –— ISO/IEC/IEEE 29119-2process groups and processes
Formatted: English (United Kingdom)
Test processes in this process assessment model are classified into organizational test (OT) process group, Formatted: Font: 10 pt
test management (TM) process group and dynamic test (DT) process group, exactly following the structure
Formatted: Font: 10 pt
given in the process reference model.
Formatted: Font: 10 pt
The organizational test process group includes a single process performed for the creation and maintenance Formatted: Font: 11 pt
of organizational test specifications, such as organizational test policies, organizational test strategies, and
Formatted: FooterPageNumber, Space After: 0 pt, Line
other organization-wide specifications.
spacing: single
4 © ISO /IEC 2026 – All rights reserved
Formatted
...
Formatted
...
Formatted
...
Formatted
...
Formatted
...
This group includes the process listed in Table 1.Table 1.
Formatted
...
Table 1 — Organizational test process group
Formatted
...
Formatted
Process
...
Process name Source
Identification
Formatted Table
...
OT.1 Organizational test process ISO/IEC/IEEE 29119-2 Formatted
...
Formatted
...
Formatted
...
The test management process group consists of processes that cover the management of testing. The
Formatted
processes contain practices that may be used by anyone who manages the whole test project or a particular .
test level, or test type within the project.
Formatted
...
Formatted
...
This group includes the processes listed in Table 2.Table 2.
Formatted
...
Table 2 — Test management process group
Formatted
...
Formatted
Process
...
Process name Source
Identification
Formatted
...
TM.1 Test strategy and planning process ISO/IEC/IEEE 29119-2
Formatted
...
TM.2 Test monitoring and control process ISO/IEC/IEEE 29119-2 Formatted
...
Formatted
TM.3 Test completion process ISO/IEC/IEEE 29119-2
...
Formatted
...
Formatted
...
The dynamic test process group consists of processes that prepare and maintain the test environment; design,
Formatted
...
implement and execute the tests and/or report the incidents resulting from the test execution.
Formatted Table
...
The dynamic test process group includes the processes listed in Table 3.Table 3.
Formatted
...
Formatted
Table 3 — Dynamic test process group .
Formatted
...
Process
Process name Source
Formatted
Identification .
Formatted
...
DT.1 Test design and implementation process ISO/IEC/IEEE 29119-2
Formatted
...
DT.2 Test environment and data management process ISO/IEC/IEEE 29119-2
Formatted
...
DT.3 Test execution process ISO/IEC/IEEE 29119-2
Formatted
...
DT.4 Test incident reporting process ISO/IEC/IEEE 29119-2
Formatted
...
Formatted
...
As illustrated in the Annex A.2, A.2, the processes within the test management process group and dynamic test
Formatted
...
process group are generic. Within the context of an assessment, they can be applied to the whole project,
Formatted
...
different test levels, or test types depending on the characteristics of the project to be assessed.
Formatted
...
For example, processes within the test management process can be applied to the management of projects
Formatted
...
(e.g. master test level), of test levels such as unit testing or acceptance testing, or of types of testing such as
Formatted
...
security testing and performance testing. The processes within the dynamic test process group can e.g. be
applied to integration testing or performance testing, security testing or other test levels/test types. Formatted
...
Formatted
...
NOTE Application of the test management processes is unique for each situation with distinct characteristics, hence
Formatted
Annex A.2, A.2, Process Application Guideline, is normative. .
Formatted
...
Formatted
...
© ISO /IEC 2026 – All rights reserved
Formatted
...
Formatted
...
Formatted
...
Formatted
...
Formatted Table
...
Formatted
...
Formatted
...
Formatted
...
Formatted
...
Formatted
...
Formatted
...
F tt d
Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: HeaderCentered, Space After: 0 pt, Line
spacing: single
For practical purposes, three additional processes are added in an informative Annex C.Annex C. The
Formatted: Font: English (United Kingdom)
additional processes include: problem resolution managementprocessmanagement process (TM.4)from
ISO/IEC 15504-5, and work product review process(STAT.1) from ISO/IEC 20246and the static analysis
Formatted: Font: English (United Kingdom)
process (STAT.2)from Annex D.Annex D. The additional processes are included for the practical assessment
Formatted: Body Text
of software test processes reflecting the industry practice.
Formatted: Font: English (United Kingdom)
A guideline on the use of additional processes from other process assessment models is provided in Annex
Formatted: Font: English (United Kingdom)
A.3. A.3.
Formatted: Font: English (United Kingdom)
4.2.3 Process dimension
Formatted: English (United Kingdom)
Formatted: English (United Kingdom)
For the process dimension, all the processes in Figure 2Figure 2 are included within the process dimension of
Formatted: Dutch (Netherlands)
the process assessment model. The processes are classified into process groups. There are four process
groups: organizational test process group, test management process group, dynamic test process group, and
Formatted: Font: English (United Kingdom)
static test process group. The process groups and their associated processes are described in Clause 5and in
Formatted: Body Text
Annex C.Annex C.
Formatted: Font: English (United Kingdom)
Each process in the process assessment model is described in terms of a purpose statement. These statements
Formatted: Font: English (United Kingdom)
contain the unique functional objectives of the process when performed in a particular environment. A list of
Formatted: English (United Kingdom)
specific outcomes is associated with each of the process purpose statements, as a list of expected positive
results of the process performance.
Satisfying the purpose statement of a process represents the first step in building a level 1 process capability
where the expected outcomes are observable.
Formatted: English (United Kingdom)
4.2.4 Quality dimension
Formatted: Dutch (Netherlands)
For the quality dimension, the minimum requirement is that the process is performed, i.e. the implemented
Formatted: Font: English (United Kingdom)
process achieves its process purpose and the expected outcomes are observable.
Formatted: Body Text, Adjust space between Latin and
Asian text, Adjust space between Asian text and
numbers
Process attributes are features of a process that can be evaluated on a scale of achievement, providing a
Formatted: Font: English (United Kingdom)
measure of the quality of the process and are applicable to all processes.
Formatted
...
Formatted: Font: English (United Kingdom)
Further details on the quality dimension can be found in Clause 6.Clause 6.
Formatted: English (United Kingdom)
Formatted
...
4.3 Assessment indicators
Formatted: Dutch (Netherlands)
A process assessment model is based on the principle that the quality of a process can be assessed by Formatted: Font: English (United Kingdom)
demonstrating the achievement of process attributes on the basis of evidences related to assessment
Formatted
...
indicators.
Formatted: Font: English (United Kingdom)
Formatted
...
There are two types of assessment indicators: process performance indicators and process quality indicators.
Formatted: Font: English (United Kingdom)
Process performance indicators address the process purpose and outcomes of each process in the process
dimension. Process quality indicators demonstrate the achievement of the process attributes in the quality Formatted
...
dimension.
Formatted: Font: 10 pt
Formatted: Font: 10 pt
The process performance indicators are: Formatted: Font: 10 pt
Formatted: Font: 11 pt
Formatted
...
6 © ISO /IEC 2026 – All rights reserved
Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: HeaderCentered, Left, Space After: 0 pt,
— base practice (BP);
Line spacing: single
Formatted: List Continue 1, No bullets or numbering
— information products (IP).
Formatted: List Continue 1, No bullets or numbering
The performance of base practices (BPs) provide an indication of the extent of achievement of the process
Formatted: Font: English (United Kingdom)
purpose and process outcomes. Information products (IPs) are either used or produced (or both), when
Formatted: Font: English (United Kingdom)
performing the process. Information items that are the key outputs of the process are primarily used as
Formatted: Body Text, Adjust space between Latin and
performance indicators.
Asian text, Adjust space between Asian text and
numbers
Annex BAnnex B provides the list of information products (IP) associated with the processes in Clause
Formatted: Font: English (United Kingdom)
5.Clause 5. The information products are classified by categories. In addition, for each information item the
Formatted: Body Text, Adjust space between Latin and
process(es) that generated it are listed.
Asian text, Adjust space between Asian text and
numbers
Formatted: Font: English (United Kingdom)
Process quality indicators depend on the process quality characteristic of interest. The minimum requirement
is that at least one of the process attributes shall comprise the achievement of the defined process purpose Formatted: Font: English (United Kingdom)
and process outcomes for the process; this is termed the process performance attribute (see ISO/IEC 33003
Formatted: Font: English (United Kingdom)
Clause:2015, 4.2.1).
Formatted: Body Text, Adjust space between Latin and
Asian text, Adjust space between Asian text and
numbers
The process performance and process quality indicators represent types of objective evidence that may be
found in an instantiation of a process and therefore could be used to judge achievement of quality. Figure
Formatted: Font: English (United Kingdom)
3Figure 3 shows how the assessment indicators are related to process performance and process quality.
Formatted: English (United Kingdom)
Formatted: Font: English (United Kingdom)
Formatted: Body Text, Adjust space between Latin and
Asian text, Adjust space between Asian text and
numbers
Formatted: Font: English (United Kingdom)
Formatted: Font: 10 pt
Formatted: Font: 10 pt
Formatted: Font: 10 pt
Formatted: Font: 11 pt
Formatted: FooterPageNumber, Space After: 0 pt, Line
spacing: single
© ISO /IEC 2026 – All rights reserved
Formatted: Font: 11 pt, Bold
Formatted: Font: 11 pt, Bold
Formatted: HeaderCentered, Space After: 0 pt, Line
spacing: single
Figure 3 — Assessment indicators
Formatted: Font: English (United Kingdom)
Formatted: Font: English (United Kingdom)
5 The process dimension
Formatted: Font: Not Bold, English (United Kingdom)
Formatted: Figure title, Left, None
5.1 General
This clause defines the processes and the process performance indicators of the process assessment model.
Formatted: Body Text
The processes in the process dimension can be directly mapped to the processes defined in the process
reference model.
The processes are classified (for the purpose of this process assessment model) into process groups which are
listed in Clause 4.Clause 4.
The individual processes are described in terms of process name, process purpose, and process outcomes as
defined in ISO/IEC/IEEE 29119-2.
In addition, the process performance indicators of the process assessment model provide information in the
form of:
Formatted: List Number 1, Indent: Left: 0 cm, First line:
a) base practices for the process providing a definition of the tasks and activities needed to accomplish the
0 cm, Line spacing: single, Numbered + Level: 1 +
test process purpose and fulfil the process outcomes; each base practice is associated to one or more
Numbering Style: a, b, c, … + Start at: 1 + Alignment:
process outcomes; and
Left + Aligned at: 0 cm + Indent at: 0 cm
b) information products that are the key outputs of the process, and are related to one or more process
Formatted: Body Text
outcomes; and
Formatted: Font: 10 pt
Formatted: Font: 10 pt
c) characteristics associated with each information product.
Formatted: Font: 10 pt
The process purposes, outcomes, the base practices and the information products associated with the
Formatted: Font: 11 pt
processes are included in this clause. The information product characteristics are contained in Annex
Formatted: FooterPageNumber, Space After: 0 pt, Line
spacing: single
8 © ISO /IEC 2026 – All rights reserved
Formatted
...
Formatted
...
Formatted
...
Formatted
...
Formatted
B.Annex B. The base practices and information products constitute the set of indicators of process .
performance.
Formatted
...
Formatted
...
The associated information products listed in this clause may be used when reviewing potential inputs and
Formatted
outputs of an organization's process implementation.
...
Formatted
...
The associated information products provide objective guidance for outputs to look for and objective evidence
Formatted
...
supporting the assessment of a particular process.
Formatted
...
A documented assessment process and assessor judgment is needed to ensure that process context
Formatted
...
(application domain, business purpose, development and testing methodology, size of the organization, etc.)
Formatted
...
is explicitly considered when using this information.
Formatted
...
This assessment process should not be considered as a checklist of what each organization must have but
Formatted
...
rather as an example and starting point for considering whether, given the context, the information products
Formatted Table
are necessary and contributing to the intended purpose of the process.
...
Formatted
...
NOTE Consideration of assessing the additional test process areas in Annex C such asworkAnnex C such as work
Formatted
product review process (STAT.1), static analysis process (STAT.2) and problem resolution management process (TM.4) .
can be required to guarantee the assessment of all the test processes.
Formatted
...
Formatted
...
Formatted
...
5.2 Organizational test process group
Formatted
...
5.2.1 OT.1 Organizational test process Formatted
...
Formatted
...
Process ID OT.1
Formatted
...
Process name Organizational test process
Formatted
...
Process purpose The purpose of the organizational test process is to develop, monitor conformance Formatted
...
and maintain organizational test specifications, such as the organizational test
Formatted
...
policy and organizational test practices document.
Formatted
...
Process outcomes As a result of the successful implementation of the organizational test process:
Formatted
...
a) The requirements for organizational
...







