Software engineering — Guidelines for the application of ISO 9001:2015 to computer software

This document provides guidance for organizations in the application of ISO 9001:2015 to the acquisition, supply, development, operation and maintenance of computer software and related support services. It does not add to or otherwise change the requirements of ISO 9001:2015. Annex A provides a table pointing to additional guidance on the implementation of ISO 9001:2015, available in ISO/IEC JTC 1/SC 7, ISO/IEC JTC 1/SC 27 and ISO/TC 176 International Standards. The guidelines provided in this document are not intended to be used as assessment criteria in quality management system registration/certification. However, some organizations can consider it useful to implement the guidelines proposed in this document and can be interested in knowing whether the resultant quality management system is compliant or not with this document. In this case, an organization can use both this document and ISO 9001 as assessment criteria for quality management systems in the software domain.

Ingénierie du logiciel — Lignes directrices pour l'application de l'ISO 9001:2015 aux logiciels informatiques

General Information

Publication Date
Current Stage
9093 - International Standard confirmed
Due Date
Completion Date
Ref Project


Buy Standard

ISO/IEC/IEEE 90003:2018 - Software engineering — Guidelines for the application of ISO 9001:2015 to computer software Released:11/29/2018
English language
69 pages
sale 15% off
sale 15% off
ISO/IEC/IEEE 90003:2018 - Software engineering -- Guidelines for the application of ISO 9001:2015 to computer software
English language
69 pages
sale 15% off
sale 15% off

Standards Content (Sample)

First edition
Software engineering — Guidelines
for the application of ISO 9001:2015
to computer software
Ingénierie du logiciel — Lignes directrices pour l'application de l'ISO
9001:2015 aux logiciels informatiques
Reference number
ISO/IEC 2018
IEEE 2018
© ISO/IEC 2018
© IEEE 2018
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting
on the internet or an intranet, without prior written permission. Permission can be requested from either ISO or IEEE at the
respective address below or ISO’s member body in the country of the requester.
ISO copyright office Institute of Electrical and Electronics Engineers, Inc
CP 401 • Ch. de Blandonnet 8 3 Park Avenue, New York
CH-1214 Vernier, Geneva NY 10016-5997, USA
Phone: +41 22 749 01 11
Fax: +41 22 749 09 47
Email: Email:
Website: Website:
Published in Switzerland
© ISO/IEC 2018 – All rights reserved
ii © IEEE 2018 – All rights reserved

Contents Page
Foreword .v
Introduction .vi
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 2
4 Context of the organization . 3
4.1 Understanding the organization and its context . 3
4.2 Understanding the needs and expectations of interested parties . 4
4.3 Determining the scope of the quality management system . 5
4.4 Quality management system and its processes . 6
4.4.1 Quality management system processes . 6
4.4.2 Information Management . 7
5 Leadership . 8
5.1 Leadership and commitment . 8
5.1.1 General. 8
5.1.2 Customer focus . 9
5.2 Policy . 9
5.2.1 Establishing the quality policy . 9
5.2.2 Communicating the quality policy .10
5.3 Organizational roles, responsibilities and authorities.10
6 Planning .11
6.1 Actions to address risks and opportunities .11
6.1.1 Risk identification .11
6.1.2 Risk treatment .12
6.2 Quality objectives and planning to achieve them .12
6.2.1 Establishing quality objectives .12
6.2.2 Implementation of quality objectives .13
6.3 Planning of changes .14
7 Support .14
7.1 Resources .14
7.1.1 General.14
7.1.2 People .15
7.1.3 Infrastructure .15
7.1.4 Environment for the operation of processes .16
7.1.5 Monitoring and measuring resources .17
7.1.6 Organizational knowledge .18
7.2 Competence .19
7.3 Awareness .20
7.4 Communication .20
7.5 Documented information .21
7.5.1 General.21
7.5.2 Creating and updating .22
7.5.3 Control of documented information .22
8 Operation .23
8.1 Operational planning and control .23
8.1.1 General.24
8.1.2 Evidence of conformity to requirements .25
8.2 Requirements for products and services .25
8.2.1 Customer communication .25
8.2.2 Determining the requirements for products and services .27
8.2.3 Review of the requirements for products and services .29
© ISO/IEC 2018 – All rights reserved
© IEEE 2018 – All rights reserved iii

8.2.4 Changes to requirements for products and services .31
8.3 Design and development of products and services .31
8.3.1 General.31
8.3.2 Design and development planning .32
8.3.3 Design and development inputs .35
8.3.4 Design and development controls .36
8.3.5 Design and development outputs .39
8.3.6 Design and development changes . .40
8.4 Control of externally provided processes, products and services .41
8.4.1 General.41
8.4.2 Type and extent of control .43
8.4.3 Information for external providers .43
8.5 Production and service provision .44
8.5.1 Control of production and service provision .44
8.5.2 Identification and traceability .47
8.5.3 Property belonging to customers or external providers .49
8.5.4 Preservation .50
8.5.5 Post-delivery activities .51
8.5.6 Control of changes .51
8.6 Release of products and services .52
8.7 Control of nonconforming outputs .53
8.7.1 Identification and control of nonconforming outputs .53
8.7.2 Retaining documented information for nonconforming outputs .54
9 Performance evaluation .54
9.1 Monitoring, measurement, analysis and evaluation .54
9.1.1 General.

First edition
Software engineering — Guidelines
for the application of ISO 9001:2015
to computer software
Ingénierie du logiciel — Lignes directrices pour l'application de l'ISO
9001:2015 aux logiciels informatiques
Reference number
ISO/IEC 2018
IEEE 2018
© ISO/IEC 2018
© IEEE 2018
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting
on the internet or an intranet, without prior written permission. Permission can be requested from either ISO or IEEE at the
respective address below or ISO’s member body in the country of the requester.
ISO copyright office Institute of Electrical and Electronics Engineers, Inc
CP 401 • Ch. de Blandonnet 8 3 Park Avenue, New York
CH-1214 Vernier, Geneva NY 10016-5997, USA
Phone: +41 22 749 01 11
Fax: +41 22 749 09 47
Email: Email:
Website: Website:
Published in Switzerland
© ISO/IEC 2018 – All rights reserved
ii © IEEE 2018 – All rights reserved

Contents Page
Foreword .v
Introduction .vi
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 2
4 Context of the organization . 3
4.1 Understanding the organization and its context . 3
4.2 Understanding the needs and expectations of interested parties . 4
4.3 Determining the scope of the quality management system . 5
4.4 Quality management system and its processes . 6
4.4.1 Quality management system processes . 6
4.4.2 Information Management . 7
5 Leadership . 8
5.1 Leadership and commitment . 8
5.1.1 General. 8
5.1.2 Customer focus . 9
5.2 Policy . 9
5.2.1 Establishing the quality policy . 9
5.2.2 Communicating the quality policy .10
5.3 Organizational roles, responsibilities and authorities.10
6 Planning .11
6.1 Actions to address risks and opportunities .11
6.1.1 Risk identification .11
6.1.2 Risk treatment .12
6.2 Quality objectives and planning to achieve them .12
6.2.1 Establishing quality objectives .12
6.2.2 Implementation of quality objectives .13
6.3 Planning of changes .14
7 Support .14
7.1 Resources .14
7.1.1 General.14
7.1.2 People .15
7.1.3 Infrastructure .15
7.1.4 Environment for the operation of processes .16
7.1.5 Monitoring and measuring resources .17
7.1.6 Organizational knowledge .18
7.2 Competence .19
7.3 Awareness .20
7.4 Communication .20
7.5 Documented information .21
7.5.1 General.21
7.5.2 Creating and updating .22
7.5.3 Control of documented information .22
8 Operation .23
8.1 Operational planning and control .23
8.1.1 General.24
8.1.2 Evidence of conformity to requirements .25
8.2 Requirements for products and services .25
8.2.1 Customer communication .25
8.2.2 Determining the requirements for products and services .27
8.2.3 Review of the requirements for products and services .29
© ISO/IEC 2018 – All rights reserved
© IEEE 2018 – All rights reserved iii

8.2.4 Changes to requirements for products and services .31
8.3 Design and development of products and services .31
8.3.1 General.31
8.3.2 Design and development planning .32
8.3.3 Design and development inputs .35
8.3.4 Design and development controls .36
8.3.5 Design and development outputs .39
8.3.6 Design and development changes . .40
8.4 Control of externally provided processes, products and services .41
8.4.1 General.41
8.4.2 Type and extent of control .43
8.4.3 Information for external providers .43
8.5 Production and service provision .44
8.5.1 Control of production and service provision .44
8.5.2 Identification and traceability .47
8.5.3 Property belonging to customers or external providers .49
8.5.4 Preservation .50
8.5.5 Post-delivery activities .51
8.5.6 Control of changes .51
8.6 Release of products and services .52
8.7 Control of nonconforming outputs .53
8.7.1 Identification and control of nonconforming outputs .53
8.7.2 Retaining documented information for nonconforming outputs .54
9 Performance evaluation .54
9.1 Monitoring, measurement, analysis and evaluation .54
9.1.1 General.

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.