Services / ISO 12207 assessment
ISO 12207 software life cycle process assessment, from $800
For software companies and in-house development teams: an independent assessment of how your software is specified, built, tested, released and maintained, against ISO/IEC/IEEE 12207.
From $800Assessment by EUROTECH

- Accredited by IAB and INTAQS
- Issuing certificates since 2004
- Online or on-site audits worldwide
- Verify any EUROTECH certificate
What the ISO 12207 assessment covers
ISO/IEC/IEEE 12207:2017 defines a common framework for software life cycle processes. It describes the processes an organization uses to acquire, supply, develop, operate, maintain and retire software, with a shared vocabulary that customers, suppliers and regulators can use when they discuss how software is built.
The framework groups processes into agreement processes, such as acquisition and supply, organizational project-enabling processes, such as life cycle model management, infrastructure, portfolio, human resource, quality and knowledge management, technical management processes, such as project planning, risk, configuration and information management, measurement and quality assurance, and technical processes, from business and stakeholder needs through requirements, architecture, design, implementation, integration, verification, transition, validation, operation, maintenance and disposal.
Our assessment compares your actual development practice with the processes that matter for your work and reports where they are well defined and followed, where they are informal and where gaps create risk for quality, security or delivery.
- Selection of the processes relevant to your products and customers
- Review of process descriptions, templates and tools
- Sampling of project evidence: requirements, design, code reviews, tests, releases
- Interviews with developers, testers, product owners and managers
- Written assessment report with findings, gaps and recommendations
The assessment can cover one product team or the whole engineering organization. Starting with one team gives a quick, focused result that can then be extended, while an organization-wide scope shows how consistent practice is across teams.
Assessment options and how 12207 relates to other standards
ISO 12207 is a reference model, so the useful question is which processes to assess. A product company might focus on requirements, design, verification and maintenance; a supplier delivering software under contract might also include agreement, configuration and transition processes. We agree the selection with you, so the report covers what your customers care about.
The framework does not prescribe a methodology. Agile, iterative and traditional approaches can all meet it, as long as the purpose and outcomes of each process are achieved. We assess outcomes and evidence, not whether you use a particular method.
Several standards build on 12207. Process capability assessments in the ISO/IEC 330xx family, and Automotive SPICE in the automotive sector, use process reference models derived from it. ISO 9001 and ISO/IEC 27001 can be combined with it, for example to show quality management and secure development together.
Open source components are part of almost every product, so we also look at how they are selected, tracked and updated, since licence and vulnerability management are now part of good life cycle practice.
What decides the price
An ISO 12207 assessment with EUROTECH starts at $800. Time depends on the scope of processes and the number of projects sampled.
- Number of processes selected for assessment
- Number of projects or products sampled
- Team size and number of development sites
- Regulated software, such as medical, automotive or financial systems
- Interviews online or in person
We confirm days and every fee in a written quote. Read access to your issue tracker, repository and test reports for the sampled projects shortens the assessment considerably.
Teams that build regulated or safety-related software usually need more time, because the evidence trail from requirements to verification has to be checked in more detail.
Teams spread across several sites or companies may need extra interviews to see how practice differs between them.
How ISO 12207 assessment works with us

Step 1
Scope and interviews
We agree the processes, projects and people to include, and quote the assessment in writing.

Step 2
Evidence review
We review life cycle descriptions, templates and records in your tools.

Step 3
Process walk-through
We follow sampled projects from requirements to release and maintenance.

Step 4
Findings and report
You receive a written report with findings, gaps and recommendations.
Customer and regulatory expectations by sector
We carry out ISO 12207 assessments for software organizations in the USA, Europe, Asia and Africa. Expectations depend on the sector more than on the country. Medical device software, automotive software, avionics and financial systems all have their own standards and regulators, and customers in those sectors often ask suppliers to describe their processes using the 12207 vocabulary.
Public sector buyers in several countries also use 12207 terms in tenders for software development and maintenance. An independent assessment helps answer those requirements with evidence.
Security expectations are rising everywhere, with rules on secure development and vulnerability handling for products sold in many markets. We look at how security activities are built into requirements, design, verification and maintenance.
Customers increasingly ask for a software bill of materials and evidence of vulnerability handling. The assessment shows whether your processes can produce these reliably.
Software that controls machines, vehicles or medical equipment often falls under product safety rules as well, which raise expectations on verification evidence.
What to expect during the assessment
We start with how you work: your life cycle model, process descriptions, definition of done, tools and roles. Then we sample one or two recent projects or releases and follow them through the selected processes, using records in your tools rather than prepared documents.
Expect questions such as: how are requirements captured and approved, how is traceability from requirement to test maintained, how are code reviews done and recorded, how are defects found after release fed back into development, how is configuration controlled across branches and environments, and how are releases approved.
Operations and maintenance are not forgotten. We look at how releases move into production, how incidents are handled and how fixes and changes for released versions are managed, because many quality problems surface there.
We close with a meeting and a written report that grades findings by importance and gives practical recommendations, with a statement describing what was assessed.
Findings are explained with the evidence behind them, so the team can see exactly what was missing and why it matters.
After the assessment
Turn the findings into a short improvement backlog and treat it like product work: prioritized, owned and reviewed regularly. Most teams get the most value from improving requirements quality, test coverage of critical functions and the feedback loop from production incidents.
A follow-up assessment after twelve months shows progress. If customers later ask for a formal capability rating, such as under ISO/IEC 33020 or Automotive SPICE, the work done here is a strong starting point.
Share the report with the whole team, not only managers. Developers and testers usually have the best ideas for fixing the gaps it shows.
Please note: ISO/IEC/IEEE 12207 is a process framework, not a management system certification standard. EUROTECH carries out an independent assessment against it and issues an assessment report and statement.
Questions buyers ask
Can you certify us to ISO 12207?
ISO/IEC/IEEE 12207 is a process framework, not a management system certification standard. We provide an independent assessment and report against it.
How much does an ISO 12207 assessment cost?
With EUROTECH it starts at $800. Processes, projects, team size, regulated software and interviews set the final price.
Which edition is current?
ISO/IEC/IEEE 12207:2017.
Does ISO 12207 require a waterfall method?
No. Agile, iterative and traditional approaches can all meet it, as long as process outcomes are achieved.
How does 12207 relate to Automotive SPICE?
Automotive SPICE uses a process reference model derived from 12207, with assessment rules of its own for the automotive sector.
Can the assessment be done online?
Yes. Most evidence lives in development tools, and interviews can be held by video.
Related services
- ISO 15504 assessment
From $800
- ISO 27001 certification
From $800
- ISO 9001 certification
From $800
Get a quote for ISO 12207 assessment
Tell us your company, sites and the standard you need. We reply with a written quote and the audit plan.
Prefer to talk? Call +1 307 205 1833
Monday to Friday, 09:00 to 18:00 (US Mountain Time)
