Product Service
SPCA software dual-mode authentication

SPCA software dual-mode authentication
Authoritative evaluation system for software enterprise capability maturity

Professional services are guaranteed
One on one full process guidance
Efficient and fast experience
SPCA (Software Process and Capability Maturity Assessment) is a localized software capability assessment system in China. It was launched in 2001 by the former Ministry of Information Industry in conjunction with the National Certification and Accreditation Administration, aiming to enhance the core competitiveness of domestic software enterprises. This certification is widely used in the standardization and continuous improvement of software development processes.
Product Introduction
I. Overview of SPCA Certification

1. Definition and Background
SPCA is a national level certification system developed under the leadership of China Electronics Standardization Institute (CESI), based on the international standard ISO/IEC 15504 (SPICE) and the Chinese national standard "Information Technology Software Process Capability Assessment Model" (SJ/T 11234-2021), integrating local industry practices to provide enterprises with a scientific and standardized process improvement framework.         


2. Origin and positioning of SPCA
SPCA is a software process capability assessment system jointly promoted by the International Organization for Standardization (ISO) and the China Electronics Standardization Institute (CESI), which integrates the international standard ISO/IEC 15504 (SPICE) with the Chinese national standards SJ/T 11234-2021 and SJ/T 11235-2021. Its goal is to measure the software process maturity of an organization through quantitative evaluation and provide scientific basis for process improvement.         
        
3. Dual model architecture
SPCA adopts a "dual-mode authentication" mode, which includes software process capability assessment (continuous) and software capability maturity assessment (phased), covering 22 process areas and involving four major categories: process management, project management, engineering, and suppor

II. Classification of SPCA Maturity Levels

SPCA adopts a five-level maturity model, gradually guiding enterprises to move from unordered management to continuous optimization:

图片.png

III. Core Values and Applicable Fields

1. Core values
• Enhance market competitiveness: Improve the bidding advantages of enterprises (some projects require SPCA level 3 or above), win customer trust, and expand international cooperation opportunities.
• Optimize processes and efficiency: By standardizing and quantifying management, reduce project delay rates and defect costs, and achieve cost reduction and efficiency improvement.
• Obtain policy dividends: Multiple local governments provide special subsidies (such as Hangzhou, Shenzhen, etc.), significantly covering certification costs and helping enterprises invest resources.
• Strengthen brand credibility: Obtain CNAS accreditation certificate, enhance corporate image, assist in financing and bank loan applications, and enhance market credibility.

2. Applicable fields
• Software development companies: improve delivery quality and efficiency, reduce project risks;
• IT service providers (such as cloud computing, AI, big data): standardize service processes and enhance customer trust;
• Digital transformation of traditional industries: helping enterprises in manufacturing, finance, healthcare and other fields build software development capabilities that comply with industry standards;
• Government and public project bidding: As an important additional item of enterprise qualification, it meets the mandatory requirements of bidding.


IV. Application Requirements for Each Level of SPCA

The following is a comprehensive explanation of the application requirements for SPCA (Software Process and Capability Maturity Assessment) certification, integrating the latest policy requirements and industry practices in 2025:

图片.png

Application suggestion:
Small and medium-sized enterprises: Priority should be given to applying for levels 2-3 to solidify the basic process.
Large enterprises/high compliance industries: Targeting levels 4-5, enhance quantitative management and innovation capabilities.
Bidding requirements: Fields such as finance, healthcare, and military industry typically require SPCA level 3 or higher.


V. Comparative Analysis of SPCA and CMMI

Both SPCA (Software Process Capability Assessment) and CMMI (Capability Maturity Model Integration) are important reference models for enterprises to enhance their software R&D and service capabilities. However, there are significant differences between the two in terms of origin, standard framework, and applicable scenarios. The following analysis will elaborate on their similarities and differences from multiple dimensions, aiming to help enterprises scientifically select a certification path.

图片.png


Certification materials
List of Certification Application Materials
(1) General materials

Corporate legal documents:

Business License
Organization Code Certificate
Tax Registration Certificate
Intellectual Property Certificate
Relevant Qualification Certificates
Legal Person Identity Certificate

Process system documents:

Quality Manual
Procedure Files
Work Instructions/Specifications
Organizational Policy Files
Training System Files

Project Practice Evidence:

Project documentation
Configuration management records
Quality assurance records
Measurement data
Internal audit and management review records
Customer feedback records

(2) Graded supplementary materials
LevelSpecial Material Requirements

Level 5

Process Improvement Proposal (PIP) and Implementation Effectiveness Comparison Report.

Root Cause Analysis (RCA) report (such as 5Why analysis, fishbone diagram).

Organizational level 'Technology Innovation Cases' (such as evidence of introducing AI testing and automation tools).

Optimized Process Performance Baseline (PPB) Update Record.

Level 4

Organizational level Process Performance Baseline (PPB) document (such as benchmark data for productivity and defect rates).

Project "Process Performance Model (PPM)" and prediction report (such as using control charts and regression analysis).

Quantitative Target Tracking Record (such as deviation analysis between actual performance and targets).

Raw data and verification records of data collection tools (such as JIRA, SonarQube logs).

Level 3

Organizational level Process Asset Library (such as standard templates, historical data).

Project 'Process Cutting Record' and approval documents (proving flexible adaptation according to organizational standards).

Organizational level Training System Evaluation Report (such as employee competency matrix, training effectiveness analysis).

Cross project Common Defect Analysis Report and improvement measures.

Level 2

Project level Quality Assurance Report (QA Audit Record).

Project Risk Register and Response Measures Record.

Project Configuration Management Plan and version control records (such as SVN/Git logs).

Project Measurement Analysis Report (including tracking data on progress, cost, and defects).

Certification process

(I.) Core process steps
1. Certification application
• The enterprise submits an Evaluation Application to the evaluation agency, clarifying the evaluation objectives and scope, and signs a contract after passing the review.
• Business license, project case, personnel social security certificate and other materials are required to be attached.

2. Preparatory examination
• The evaluation agency establishes an evaluation team, develops an evaluation plan, and conducts preliminary review to identify gaps between existing processes and SPCA standards.
• Key actions:
Improve the documentation system (including 18 types of documents such as quality manuals and risk management procedures);
Complete confidentiality training for personnel involved in classified matters (with an average of at least 16 hours per year).

3. On site evaluation
First meeting: The company showcases its improvement achievements, and the audit team clarifies the scope and selects an interview list.
Document verification: Randomly check project documents (requirement documents, test reports, customer acceptance forms, etc.) to verify the compliance of the R&D process.
Personnel interviews: covering key positions such as R&D, testing, and project managers, tracing requirement changes and code version consistency.
Final meeting: Announce non conformities and specify a 15 day deadline for rectification.

4. Evaluation decision and certification
After the technical committee reviews and evaluates the report, a CNAS accreditation certificate (valid for 3 years) will be issued.
Within 60 days after obtaining the certificate, one can apply for government subsidies (such as subsidies exceeding 300000 yuan in Hangzhou).

(II.) Special procedures and precautions
1. Additional processes for military software enterprises
• Need to pass on-site military inspections, including network attack and defense exercises, equipment interface compatibility testing, etc.
• Submit military software reliability testing report (failure rate ≤ 0.01%/thousand lines of code) and wartime emergency plan.

2. Requirements for upgrading digital audit
• The R&D environment needs to pass Level 3 certification for information security and be connected to the government certification platform.
• The proportion of remote video spot checks has been increased to 30%, and it is necessary to ensure the coverage of panoramic cameras in the conference room.

3. Continuous improvement and annual review
• Annual review materials (such as agile development cases and DevOps implementation records) need to be submitted annually.
• Rectification issues need to be closed within 15 working days (30 days for civilian use).


4. Special classification requirements
• Military software companies: must first obtain equipment manufacturing unit qualifications (A/B category), confidentiality qualification certification (level 2 or above), and the legal representative and personnel involved in confidentiality must have no overseas background.
• Frontier technology enterprises (such as artificial intelligence and quantum communication) can apply for green channels, with a 40% reduction in review cycles.


(III.) Optimization suggestions
• Rehearsal and training: Simulate the audit team's "five step traceability method" (requirements → design → code → testing → delivery) to ensure cross validation of each step.
• Application of technical tools: Use QMS system to generate process asset library, avoiding logical contradictions in manual writing.
• Policy utilization: Priority should be given to government recommended evaluation agencies (such as Cyber Certification Center) to accelerate mutual recognition of qualifications.



Continuous improvement requirements
  • Surveillance audit
    L3 and above enterprises shall undergo a surprise inspection once a year (with advance notice of ≤ 5 working days).
    The proportion of spot check projects is ≥ 30%, with a focus on the effectiveness of rectifying previous non conformities and the compliance of new project execution.
  • Certificate maintenance
    Ensure that internal audits/management reviews are carried out as planned (L3: at least 1 internal audit per year, 2 management reviews per year).
    Timely close all non conformities (usually requiring submission of corrective evidence within 60 days).
  • Upgrade mechanism
    The current level certificate has been valid for 12 months and there are no serious non conformities in the supervision and audit.
    Proof of continuous 12-month quantitative compliance is required
FAQ
QWhich level of SPCA is suitable for small and medium-sized enterprises to apply for?
ASuggest starting from levels 2-3:
Level 2 (repeatable level) establishes a basic project management process; Level 3 (defined level) achieves standardization of the entire lifecycle process; High level (4-5 levels) is suitable for large enterprises or organizations that need to participate in international competition.
QDoes SPCA certification require regular review?
Ayes. The SPCA certificate is valid for 3 years and requires supervision and evaluation every 12-18 months to ensure continuous compliance with standards. After expiration, it is necessary to reapply for certification to maintain the level or upgrade.
QWhat are the common challenges of SPCA certification?
ACultural resistance: Insufficient adaptability of the team to process norms; Data governance: Lack of ability to collect and analyze process data; Cost input: Small and medium-sized enterprises may face resource constraints; Solution: phased improvement, introduction of automation tools, and strengthening employee training.
QWhat should be done if the annual review fails?
AThe certificate will enter a "suspended" state (with a maximum retention period of six months), requiring rectification and payment of re examination fees.
Appointment Consultation
If you have any questions, special requirements, or need more detailed information about our services, just leave us a message. Let us know how to assist you, and we will reply to you as soon as possible.
Name
Company
Tel
E-mail
How did you come to our website?
Baidu
Sogou
Other
Content
点击更换验证码
Copy successfully

Wechat ID:Siterui888888

Add a wechat friend to get free plans and quotations

OK
Contact
Experts are by your side Add the expert's wechat to get help
Tel:
400-636-6998
If the line is busy or not answered in time, please add wechat
E-mail:
ruibao@szstr.com
Get Plan:
One more reference is always beneficial
Copy successfully
You will receive
定制化解决方案
专业认证顾问调研企业需求,根据企业所处行业、规模、发展阶段及目标市场,量身定制专属的资质认证方案,提供符合其特定要求的认证路径。
专业咨询指导
思特瑞团队成员经验丰富、技术精湛,能够准确把握客户需求并提供专业建议和全方位、全流程的咨询指导,为企业提供高质量的咨询服务。
透明化服务
清晰明确的费用结构,杜绝隐形收费,并根据客户的规模、行业特点和认证需求,提供合理的报价方案,确保企业在预算范围内获得优质服务。
长期顾问式合作
与企业建立长期稳定的合作关系,并随着企业的发展,提供相应的升级服务,助力企业在不同阶段实现可持续发展。
Get Plan
Company
Certification qualifications for consultation*
Name
Tel*
*indicates required fields