# TS ISO/IEC 15504 SPICE Consulting

**URL:** https://securesys.com.tr/en/services/ts-iso-iec-15504-spice-consulting

**SPICE Software Process Assessment, Process Improvement, Organisational Maturity and Certification Readiness**

A successful software company is not simply one that writes good code.

Genuinely sustainable software development depends on requirements being managed correctly, projects being planned, changes being controlled, software architecture being governed, test processes being applied, defects being tracked, configuration being managed, quality assurance activities being carried out — and all of this being made measurable.

When the success of a software project depends on individuals, when processes vary from team to team, or when project management rests entirely on the personal methods of a project manager, the organisation carries a significant operational risk.

**TS ISO/IEC 15504 SPICE** is a process assessment approach that allows software-developing organisations to have their processes assessed, their process capability measured, and their organisational maturity levels improved.

SecureSys provides end-to-end SPICE consulting to help software-developing organisations assess their current processes, identify their gaps, standardise their processes and **prepare for TS ISO/IEC 15504 SPICE assessment and certification**.

Our consulting approach does not focus solely on writing procedures.

The real software development lifecycle is assessed across:

**Requirements → Analysis → Design → Development → Test → Release → Maintenance → Change Management**

The objective is not a set of documents prepared to pass an audit, but a measurable and sustainable **software process management system** that software teams can genuinely apply in their daily work.

### What Is SPICE?

**SPICE – Software Process Improvement and Capability Determination** is a process assessment approach for evaluating software and system development processes.

The fundamental purpose of the SPICE approach is to assess how systematic, manageable, measurable and sustainable an organisation's software development processes are.

It looks not only at the outcomes of software development processes, but at how those outcomes are produced.

An organisation may, for example, have developed a successful software product.

If, however, requirements are not recorded, test scenarios are not created, changes are not tracked and project management depends entirely on individual experience, the same success may not be repeatable on the next project.

SPICE focuses on exactly that point:

**turning a successful outcome from a matter of chance into a repeatable corporate process.**

### What Is TS ISO/IEC 15504 SPICE?

In Türkiye, SPICE process assessment and organisational maturity certification is widely known as **TS ISO/IEC 15504 SPICE**.

The standard provides a systematic method for assessing software processes and determining organisational process capability.

SPICE assessments do not look only at which procedures an organisation holds.

They assess whether the processes are genuinely applied, whether records exist, whether outputs are measured, and whether the processes are sustainable across the organisation.

### Is ISO/IEC 15504 Still Current?

Many parts of the ISO/IEC 15504 series have been withdrawn by ISO, and the process assessment approach has moved to the more recent **ISO/IEC 33000 family**.

In Türkiye, however, the term **TS ISO/IEC 15504 SPICE** continues to be used in the process assessment and organisational maturity certifications issued by TSE.

It is therefore important for organisations to distinguish between two things:

**the TSE SPICE certification practice in Türkiye**

and

**the international ISO/IEC 330xx process assessment standard family.**

SecureSys consulting work takes both the current TSE practice and current process assessment principles into account.

### What Is ISO/IEC 33000?

The **ISO/IEC 33000 standard family** develops and extends the ISO/IEC 15504 series in the areas of process assessment, process capability and organisational maturity.

This family of standards addresses:

- Process assessment concepts,
- Assessment methods,
- Process reference models,
- Process assessment models,
- Process capability levels,
- Organisational maturity assessments

When examining SPICE today, it is therefore important to look not only at ISO/IEC 15504 but also at the **ISO/IEC 330xx process assessment** family.

### What Is TS ISO/IEC 15504 SPICE Consulting?

SPICE consulting is the service of assessing an organisation's existing software development and management processes, identifying the gaps, and establishing the processes required to reach the target process maturity level.

SecureSys analyses the organisation's real software development structure as part of its SPICE consulting.

Processes such as the following can be assessed:

- Project management,
- Requirements management,
- Software development,
- System design,
- Software design,
- Code development,
- Software testing,
- System testing,
- Configuration management,
- Change management,
- Quality assurance,
- Risk management,
- Problem management,
- Measurement and reporting

### Why Is SPICE Necessary?

In many software firms, processes develop organically over time.

One team may use Jira while another uses a spreadsheet.

One team may record requirements in detail while another works from customer emails.

Test scenarios may be created for one project while another goes live on nothing more than the developer's own testing.

This structure may look manageable while the company is small, but significant problems emerge as it grows.

**Knowledge becomes person-dependent.**

When a key employee leaves, process knowledge can be lost.

**Quality varies between projects.**

One team may succeed while another cannot reach the same quality level.

**Project delays increase.**

When planning and measurement mechanisms are inadequate, delays cannot be seen in advance.

**Mistakes are repeated.**

Without root cause analysis and process improvement, the same problems recur across different projects.

**Management does not get accurate data.**

Project progress comes to depend on personal opinion rather than real indicators.

SPICE helps manage these problems systematically.

### Who Is SPICE Suitable For?

SPICE is suitable in particular for organisations that carry out software development.

The main target organisations are:

- Software development companies,
- Defence industry firms,
- Companies developing software for the public sector,
- Financial technology companies,
- Technology firms,
- R&D companies,
- System integrators,
- ERP developers,
- SaaS firms,
- Mobile application developers,
- Web software companies,
- Industrial software producers,
- Automotive software firms,
- Organisations developing critical system software.

Organisational process maturity can become an important criterion in supplier evaluations, particularly in public sector and defence industry projects.

### What Is a SPICE Gap Analysis?

A **SPICE gap analysis** is the identification of the differences between an organisation's existing software processes and the target SPICE process requirements.

SecureSys examines the existing processes in detail as part of the SPICE gap analysis.

For example:

- How are requirements captured?
- How are requirement changes managed?
- How are project plans prepared?
- How are risks tracked?
- Are design records kept?
- Are code changes traceable?
- Are test scenarios created?
- Are test results recorded?
- Is there configuration management?
- Is the release process defined?
- Are quality assurance activities independent?
- Are metrics tracked?
- Are processes improved regularly?

The answers to these questions reveal the current level of process maturity.

### SPICE Process Assessment

One of the fundamental aims of the SPICE approach is to measure process capability.

Process assessment can be carried out across:

**the process dimension**

and

**the capability dimension**

The process dimension expresses which processes will be assessed.

The capability dimension shows the extent to which those processes are managed and institutionalised.

Assessing the two dimensions together reveals not only which processes the organisation has, but how mature they are.

### SPICE Capability Levels

In the SPICE process assessment approach, process capability is assessed within a graduated structure.

The capability levels generally follow this logic.

**Level 0 – Incomplete Process**

The process is not applied, or does not operate at a level that achieves its purpose.

Work may be individual and there may be no systematic process.

**Level 1 – Performed Process**

The process achieves its basic purpose.

Process management may, however, be person-dependent.

**Level 2 – Managed Process**

The process is now planned, monitored and controlled.

Outputs are managed and recorded.

**Level 3 – Established Process**

The process is based on standard processes defined across the organisation.

Projects are managed according to corporate processes rather than individual methods alone.

**Level 4 – Predictable Process**

Processes are measured and managed quantitatively.

Management can develop predictions about process performance on the basis of historical data.

**Level 5 – Innovating Process**

Processes are analysed continuously and improved systematically.

The aim is not merely to maintain the standard but to improve performance continuously.

### What Is an Organisational Maturity Level?

Process capability level and organisational maturity are distinct concepts.

Process capability assesses how developed a particular process is, whereas organisational maturity shows how systematically the organisation manages its processes as a whole.

Organisational maturity levels play an important role in the TSE SPICE assessment approach in Türkiye.

The organisation develops its processes according to the level it is targeting and enters the assessment scope accordingly.

### SPICE Level 1

At the first levels, the aim is to ensure that software development activities produce defined outputs.

Processes are expected to fulfil their basic purpose.

In the requirements management process, for example, requirements coming from the customer need to be captured and recorded systematically.

Advanced measurement and optimisation mechanisms may not yet be in place.

### SPICE Level 2

At Level 2, processes are not only applied but **managed**.

At this stage, the following become more systematic:

- Planning,
- Responsibilities,
- Resources,
- Monitoring,
- Records management,
- Control of work products

For software firms, this level is an important turning point.

Work begins to move away from personal methods and towards manageable processes.

### SPICE Level 3

At SPICE Level 3, the aim is for processes to be defined and standardised across the organisation.

At this level, how a project is managed does not depend solely on the project manager's experience.

The organisation has standard processes for:

- Project management,
- Requirements management,
- Testing,
- Configuration,
- Risk,
- Quality

Projects proceed by making appropriate adaptations of these standard processes.

Level 3 is therefore an important milestone in terms of institutionalisation.

### SPICE Level 4

At Level 4, processes begin to be measured quantitatively.

Measures such as the following can be used:

- Defect density,
- Test coverage,
- Requirements volatility,
- Project delay rates,
- Rework rates,
- Defect closure times,
- Release success rates

The aim is for management to be able to monitor process performance on the basis of data.

### SPICE Level 5

SPICE Level 5 represents a continuous improvement and optimisation approach.

At this level, the organisation does not merely apply and measure its processes.

It analyses the measurement results and improves process performance continuously.

This can include identifying the root causes of recurring defects, assessing automation opportunities, adopting new development methods and optimising processes on the basis of measurements.

### Requirements Management

Requirements management is one of the most critical areas in SPICE consulting.

A significant proportion of the problems experienced in software projects can be traced to incorrect or incomplete requirements.

In effective requirements management:

- Requirements are recorded.
- Requirements are uniquely identified.
- Requirements are analysed.
- Requirement changes are controlled.
- Requirements are linked to design and tests.
- Traceability is established.

### Requirements Traceability

In a software project, it has to be possible to answer this question:

**Which requirement does this test case verify?**

And likewise:

**Which customer requirement gave rise to this function?**

This relationship is requirements traceability.

Using a traceability matrix, the following relationship can be established:

**Requirement → Design → Code → Test**

This approach improves quality considerably, particularly in critical software projects.

### Project Management

Project management is one of the core processes under SPICE.

Project management must handle the following together:

- Scope,
- Time,
- Resources,
- Cost,
- Risk,
- Dependencies,
- Quality

Preparing the project plan only at project start-up is not sufficient.

The plan needs to be updated regularly and compared against the real position.

### Risk Management

Risk management is one of the most commonly neglected areas in software projects.

Risks should not be described simply as "the project may be delayed".

Risks such as the following should be assessed regularly:

- A key developer leaving,
- A third-party API changing,
- Technology dependency,
- Performance problems,
- Security vulnerabilities,
- Requirement uncertainty,
- Integration delays

Risks need to be tracked with their likelihood, impact, owner and action.

### Software Design Processes

How the software is designed also matters in a SPICE assessment.

A design that exists only in the developer's head is not sustainable.

Depending on the size of the system, design outputs such as the following can be produced:

- Architecture diagram,
- Component design,
- Database design,
- API design,
- Interface definitions,
- Data flow

This documentation makes the software easier to maintain and knowledge easier to transfer between teams.

### Software Development Process

Coding activity needs to be tied to a standard development approach.

Practices such as the following can be assessed:

- Coding standards,
- Branch strategy,
- Pull requests,
- Code review,
- Static code analysis,
- Secure coding,
- Dependency management

In modern SPICE implementations, these processes can also be automated using DevOps and DevSecOps tooling.

### Configuration Management

Configuration management is one of the fundamental control points of software development.

It must be known which software version is running at which customer.

It must be traceable which change was published in which release.

The following structures are therefore important:

- Source code management,
- Version control,
- Release management,
- Baseline management,
- Build management

Git, GitLab, GitHub, Azure DevOps or similar platforms can be used to support process management.

### Change Management

Change is inevitable in every software project.

What matters is that changes are not made without control.

The change management process can establish the following flow:

**Request → Impact Analysis → Approval → Development → Test → Release**

The cost of a change, its effect on the schedule and its technical risks can then be assessed in advance.

### Software Test Process

From a SPICE perspective, testing is not simply "opening the application and seeing whether it works".

Test activity must be planned and traceable.

The following records can be produced:

- Test plan,
- Test scenario,
- Test case,
- Expected result,
- Actual result,
- Defect,
- Retest

Linking tests to requirements is particularly important.

### Unit Test, Integration Test and System Test

In a software quality assurance approach, testing can be carried out at different levels.

**Unit test**

The testing of the smallest functional units within the code.

**Integration test**

Assesses whether system components work correctly with one another.

**System test**

The application is tested as a whole against the requirements.

**Acceptance test**

Aims to verify that customer or business unit requirements have been met.

Defining these test levels according to the project improves process quality.

### Quality Assurance

Quality control and quality assurance are not the same thing.

Testing largely controls the quality of the product.

Quality assurance assesses **whether the processes are being applied correctly**.

A QA team can check matters such as:

- Have the requirements processes been applied?
- Is the project plan current?
- Are the test records complete?
- Has a review been carried out?
- Has release approval been obtained?

### Problem and Defect Management

Closing software defects is not sufficient on its own.

Defects need to be analysed.

Recurring defects can indicate a process problem.

The following approaches can therefore be used:

- Bug classification,
- Root cause analysis,
- Trend analysis,
- Corrective action

As SPICE maturity increases, defect data is expected to be used for process improvement.

### Measurement and Metric Management

It is difficult to manage a process effectively if you cannot measure it.

Meaningful KPIs and metrics can be defined for the organisation as part of SPICE consulting.

For example:

- Requirements change rate
- Defect density
- Defect leakage
- Test pass rate
- Test coverage
- Release success rate
- Project schedule variance
- Effort variance
- Change request rate
- Mean time to resolve a defect

Rather than tracking hundreds of unnecessary metrics, however, the focus should be on measurements that support decision-making.

### SPICE and Agile

One of the most frequently asked questions is whether SPICE and Agile can be used together.

The answer is **yes**.

SPICE does not mandate a particular software development methodology.

Scrum, Kanban or a hybrid development model can be used.

What matters is that the process outcomes are achieved.

If Scrum is in use, for example, practices such as the following can be linked to the process requirements:

- Product backlog,
- Sprint planning,
- Definition of done,
- Sprint review,
- Retrospective

### SPICE and DevOps

SPICE and DevOps are not alternatives to one another.

DevOps focuses on automating and accelerating the processes between development and operations teams.

SPICE assesses the maturity and manageability of processes.

DevOps practices such as CI/CD pipelines, automated testing, artifact repositories, infrastructure as code and deployment automation can strongly support SPICE processes.

### SPICE and DevSecOps

Integrating security into the development lifecycle is important in modern software projects.

Where needed, the SecureSys approach can integrate DevSecOps practices such as:

- SAST,
- DAST,
- SCA,
- Secret scanning,
- Container security,
- Dependency security,
- Secure code review

into the software development processes.

Process quality and software security are then improved together.

### The Difference Between SPICE and ISO 9001

ISO 9001 focuses on the general quality management system.

SPICE focuses on assessing the capability and maturity of software and system development processes.

A software company may hold ISO 9001 certification while its software development processes remain at a low maturity level.

SPICE focuses in far greater detail on software development activity.

### The Difference Between SPICE and ISO 27001

ISO/IEC 27001 is an information security management system standard.

SPICE focuses on the assessment and improvement of software development processes.

Used together, they can form a complementary structure:

**SPICE → software process quality**

**[ISO 27001](/en/services/iso-27001-isms-consulting-service) → information security**

### The Difference Between SPICE and CMMI

SPICE and CMMI are process improvement and maturity approaches used for similar purposes.

Both aim to move organisations' processes away from person-dependence and towards something measurable and institutional.

Their assessment models, terminology and certification/assessment ecosystems differ, however.

In Türkiye, the term **TS ISO/IEC 15504 SPICE** is particularly well recognised in public sector and software projects.

### The Difference Between SPICE and Automotive SPICE

**Automotive SPICE – ASPICE** is a process assessment model specific to the automotive sector.

It is widely used in automotive software and electronic system development processes.

TS ISO/IEC 15504 SPICE is a more general software process assessment framework.

Organisations that need Automotive SPICE therefore have to consider the separate ASPICE methodology.

### How Does the SPICE Compliance Process Work?

SecureSys SPICE consulting projects are generally carried out in the following stages.

**\1. Scope Definition**

The organisation's target maturity level and assessment scope are defined.

**\2. Current-State Analysis**

The organisation's real software development processes are examined.

**\3. SPICE Gap Analysis**

Existing processes are compared against the target requirements.

**\4. Roadmap Development**

The gaps are classified by risk and priority.

**\5. Process Design**

Missing or inadequate processes are established.

**\6. Documentation**

Policies, procedures, templates and record structures are prepared.

**\7. Tool Integration**

Jira, Azure DevOps, GitLab, GitHub or the other platforms in use are linked to the processes.

**\8. Pilot Project**

The processes prepared are applied on selected projects.

**\9. Creation of Records**

Evidence demonstrating that the processes are genuinely applied is produced.

**\10. Internal Assessment**

The processes are checked from a SPICE assessment perspective.

**\11. Corrective Action**

The gaps are closed.

**\12. Certification Readiness**

The organisation is prepared for formal assessment.

### SPICE Consulting Deliverables

Depending on project scope, the following deliverables can be prepared:

- SPICE Gap Analysis Report
- SPICE Compliance Matrix
- Process Inventory
- Software Lifecycle Process
- Project Management Procedure
- Requirements Management Procedure
- Risk Management Procedure
- Configuration Management Procedure
- Change Management Procedure
- Software Development Procedure
- Test Management Procedure
- Quality Assurance Procedure
- Problem Management Procedure
- Measurement and Analysis Procedure
- Release Management Process
- Requirements Traceability Matrix
- Risk Register
- Project Plan Templates
- Test Plan and Test Case Templates
- Configuration Management Plan
- Quality Assurance Plan
- Process KPI Matrix
- Internal Assessment Report
- Corrective Action Plan
- TSE SPICE Assessment Readiness Report

### SPICE Certification Readiness

The aim of SecureSys SPICE consulting is not merely to complete the procedures of an organisation entering assessment.

The processes need to be made **applicable and demonstrable**.

In an audit, saying "we have a change management procedure" may not be enough.

Change requests need to be, in real projects:

- recorded,
- analysed,
- approved,
- implemented,
- tested,
- closed

Considerable importance is therefore placed on producing real project records and evidence during the consulting process.

### The TSE SPICE Certificate

In Türkiye, the Turkish Standards Institution provides **TS ISO/IEC 15504 SPICE Software Process Assessment and Organisational Maturity certification**.

Assessments carried out by TSE examine whether the organisation meets the target maturity level.

The certification decision is made independently by TSE.

SecureSys provides consulting and preparation services to help the organisation become ready for that assessment.

### SPICE in Public Sector Tenders

Software process maturity can become important particularly in large-scale public sector IT projects.

On large software projects, public bodies want to have confidence not only in the service provider's technical staff but also in its corporate software development capacity.

A SPICE certificate can demonstrate that the organisation's software development, project management, requirements management, test and quality processes have been assessed systematically.

TS ISO/IEC 15504 SPICE can therefore be an important indicator of corporate capability, particularly for companies developing software for the public sector.

### SPICE in the Defence Industry

Defence industry projects generally require:

- Long project durations,
- Complex requirements,
- Critical systems,
- Intensive configuration management,
- Traceability,
- Verification and validation

Process maturity is therefore critically important in defence projects.

The SPICE approach can help make software development processes institutional and repeatable.

### How Long Does SPICE Consulting Take?

The duration of SPICE consulting varies according to:

- Company size,
- Number of teams,
- Number of projects,
- Current process level,
- Target maturity level,
- The quality of existing records

The preparation time for a software company whose processes are already reasonably established is not the same as for an organisation working entirely through personal methods.

Carrying out a preliminary gap analysis at project start-up is therefore the soundest approach.

### The Most Common Mistake in SPICE Consulting

The most common mistake is treating a SPICE project as a documentation project alone.

Preparing a large number of procedures does not equate to high process maturity.

A process must be:

**defined → applied → evidenced → measured → improved.**

In the SecureSys approach, therefore, what matters is not the number of documents but whether the processes work on real projects.

### Why SecureSys SPICE Consulting?

SPICE consulting should not be delivered on the basis of knowing the standard alone.

The consultant also needs to understand the real software development lifecycle, project management, test processes, the DevOps approach and software security.

The SecureSys SPICE consulting approach assesses the following disciplines together:

**GRC + software development + project management + DevOps + DevSecOps + software testing + cyber security**

The processes created therefore do not remain documents to be used only at audit.

They can be turned into operational processes that work within Jira, GitLab, GitHub, Azure DevOps or the organisation's existing tooling.

Our approach is based on the model:

**Measure → Identify Gaps → Design the Process → Apply → Evidence → Assess → Improve**

### Frequently Asked Questions

#### What is SPICE?

SPICE is the abbreviation for Software Process Improvement and Capability Determination. It is an approach used to assess software processes, measure process capability and improve processes.

#### What is TS ISO/IEC 15504?

TS ISO/IEC 15504 is the SPICE standard and certification approach used in Türkiye for software process assessment and the determination of organisational maturity.

#### What is a TS ISO/IEC 15504 SPICE certificate?

It is the certificate issued when software development processes have been assessed and the organisation meets a given organisational maturity level.

#### Is ISO/IEC 15504 still valid?

On the ISO side, many parts of the ISO/IEC 15504 series have been withdrawn and developed further through the ISO/IEC 33000 family. In Türkiye, however, TSE continues to provide certification under the name TS ISO/IEC 15504 SPICE.

#### What is ISO/IEC 33000?

The ISO/IEC 33000 family is the international standard family that develops the ISO/IEC 15504 approach in the areas of process assessment, process capability and organisational maturity.

#### What is a SPICE gap analysis?

It is the exercise of identifying the differences between an organisation's existing software development processes and the target SPICE process requirements.

#### What is a SPICE maturity level?

It is a levelling approach that shows how defined, manageable, measurable and continuously improvable an organisation's processes are.

#### What is SPICE Level 2?

It refers to the level at which processes are not only applied but also planned, monitored and managed.

#### What is SPICE Level 3?

It is the maturity level at which processes are standardised across the organisation and defined corporate processes are applied systematically on projects.

#### Can SPICE and Agile be used together?

Yes. SPICE does not mandate a particular development methodology. It can be applied alongside Scrum, Kanban or hybrid methods.

#### Can SPICE and DevOps be used together?

Yes. DevOps automation and CI/CD processes can support many SPICE processes being applied more effectively and measurably.

#### Are SPICE and CMMI the same?

No. Although they share similar process improvement goals, their models, terminology and assessment methods differ.

#### Are Automotive SPICE and TS ISO/IEC 15504 the same?

No. Automotive SPICE is a process assessment model customised for the automotive sector.

#### Who issues the SPICE certificate?

In Türkiye, TSE provides TS ISO/IEC 15504 SPICE Software Process Assessment and Organisational Maturity certification.

#### What does SPICE consulting cover?

It can cover activities such as gap analysis, process design, project management, requirements management, development, testing, quality assurance, configuration management, risk management, measurement, process improvement and assessment readiness.

### Institutionalise Your Software Processes With TS ISO/IEC 15504 SPICE

Tying software development success to talented developers alone is not a sustainable model.

As the team grows, the number of projects increases and customer expectations rise, strong processes become necessary.

SPICE answers the following fundamental questions for organisations:

Are your requirements genuinely being managed?

Can you measure project status?

Are software changes under control?

Are tests linked to requirements?

Is quality the developer's responsibility alone?

Does the process keep working when an employee leaves?

Can your projects be repeated at the same quality standard?

Are you learning from defects and improving your processes?

Through its **TS ISO/IEC 15504 SPICE consulting, SPICE gap analysis, software process improvement, organisational maturity assessment and TSE SPICE certification readiness** services, SecureSys helps software-developing organisations move their processes from a person-dependent structure to a corporate, measurable and sustainable model.

#### Determine Your Current Maturity Level With a SPICE Gap Analysis

Rather than guessing where you should start, measure your existing software processes first.

**See your process.****Identify your gaps.****Institutionalise.****Measure.****Improve continuously.**

**Request a TS ISO/IEC 15504 SPICE Consulting Proposal**

To assess the current state of your software development processes, reach your target SPICE maturity level and prepare for the TSE assessment process, [get in touch](/en/contact) with the SecureSys team.

**Entrust software quality not to individuals, but to strong and measurable processes.**
