Same DNA, different lineage. What separates Automotive SPICE from CMMI — origin, scope, the levels — and which one an automotive supplier is actually contractually on the hook for.
ASPICE (Automotive SPICE) and CMMI (Capability Maturity Model Integration) are both models for assessing how capable an organization's engineering processes are — but they come from different worlds. ASPICE is automotive-specific, governed by the German VDA, derived from ISO/IEC 15504 / 330xx, and scores individual processes on capability levels CL0–CL5 (continuous representation). CMMI comes from the SEI (now ISACA), is industry-agnostic, and traditionally scores whole-organization maturity on levels 1–5 (staged), as well as capability. In automotive, OEMs contractually demand ASPICE — that is the forcing function; CMMI rarely appears in a car supply chain.
They look similar enough that people use the names interchangeably — and then get burned in a sourcing negotiation. Both are process-assessment models with five-ish levels. The differences that matter are where they come from, what they measure, and which one your OEM will actually assess you against.
Both descend from the same idea: don't judge software by the artifact, judge the process that produced it. CMMI grew out of the Software Engineering Institute's Capability Maturity Model (CMM) at Carnegie Mellon. ASPICE descends from SPICE — ISO/IEC 15504, now the ISO/IEC 330xx family — tailored for automotive by the VDA. So they measure similar things (is the process performed, managed, established, predictable, improving) but were built for different buyers.
| ASPICE | CMMI | |
|---|---|---|
| Full name | Automotive SPICE (Software Process Improvement & Capability dEtermination) | Capability Maturity Model Integration |
| Origin / owner | VDA (German OEMs); ISO/IEC 15504 → 330xx heritage | SEI at Carnegie Mellon → now ISACA |
| Scope | Automotive embedded software & systems | Industry-agnostic (defense, IT, services, aerospace…) |
| Structure | Per-process capability levels CL0–CL5 (continuous) | Org maturity levels 1–5 (staged) + capability view |
| Assessment | VDA-guided assessor, Intacs certification scheme | SCAMPI / CMMI appraisal by certified lead appraiser |
| Where you meet it | Automotive OEM sourcing & supplier audits | Defense/government contracts, large IT & services orgs |
| Mandatory? | Contractually imposed by OEMs on suppliers | Usually voluntary / customer- or tender-driven |
| Certificate? | No formal certificate — assessment results only | Formal maturity-level rating (e.g. “CMMI Level 3”) |
The level ladders run almost parallel. ASPICE capability: CL0 Incomplete → CL1 Performed → CL2 Managed → CL3 Established → CL4 Predictable → CL5 Innovating. CMMI maturity: L1 Initial → L2 Managed → L3 Defined → L4 Quantitatively Managed → L5 Optimizing. The rough mapping people reach for is CL2 ≈ L2 (managed) and CL3 ≈ L3 (defined) — but ASPICE rates each process individually, while CMMI's staged model rates the whole organization. (For the CL1→CL2 jump specifically, see what ASPICE is and missed a capability level?.)

Almost always ASPICE — because the OEM contract says so. That's the whole reason it has teeth: it's a supplier control tool. CMMI shows up only if you also serve defense, aerospace, or large IT/government buyers who ask for a maturity rating. If your customer is a car maker, ASPICE is the forcing function; CMMI is a nice-to-have at best.

Here's what nobody puts in the comparison chart: both are assessment frameworks, and both get abused the same way. Teams treat the model as a build manual and drown in ceremony. There is no official blueprint in either — it's a checklist an assessor grades you against. And the pen-and-paper work products (change, review, communication records) get recreated as Excel and signed PDFs no matter which badge is on the door.
“There is no official blueprint anywhere — in ASPICE or CMMI. It's a checklist assessors grade you against. Treating it as a build manual is what manufactures the pain.”The practitioner view
Neither framework fails or succeeds on templates. It fails or succeeds on whether the evidence exists — traceable, consistent, and current. That's a production problem, not a paperwork problem. AI agents that generate assessment-ready work products as a byproduct of the build — with confidence scores and audit trails — close that gap for ASPICE and CMMI alike. Suppliers don't want more process people; they want the evidence to exist. That's what Vera delivers.
No. ASPICE descends from SPICE (ISO/IEC 15504, now ISO/IEC 330xx), tailored for automotive by the VDA. CMMI descends from the SEI's Capability Maturity Model. They share the idea of grading process capability but have separate lineages.
You can be assessed against both, and organizations serving multiple industries sometimes are. Note ASPICE produces assessment results rather than a formal certificate, while CMMI issues a maturity-level rating.
They're hard in different ways. ASPICE rates each process individually against detailed automotive base practices and work products; CMMI's staged model rates whole-organization maturity. For an automotive team, ASPICE is usually the more demanding and the more consequential.
Generally no. Automotive OEMs write a required ASPICE capability level into supplier contracts; a CMMI rating does not satisfy that requirement.
No. ASPICE assessments produce results and a capability profile, not a certificate you can frame. CMMI, by contrast, issues a formal maturity-level rating.
Grounded in the standard, honest about the theater: What is ASPICE · Automating ASPICE with AI agents · Agile ASPICE · Best ASPICE tools