Software Quality Assurance (SQA): Verification, Validation, ISO 9000 & SEI-CMM
Software quality is not achieved by testing the product only at the end. Quality must be planned, monitored and improved throughout software development. Software Quality Assurance provides the organised activities, standards, reviews, audits and process controls used to help a software team build reliable and acceptable software.
Software Quality Assurance (SQA) is a planned and systematic approach used to ensure that software processes and software products follow defined requirements, procedures, standards and quality practices.
In simple words, SQA asks: “Are we following the right processes to build quality software?”
What is Software Quality?
Before understanding SQA, we first need to understand what software quality means.
Software quality is generally concerned with how well software satisfies its specified requirements, user needs and expected quality characteristics.
Good software should not only provide the required features. It should also behave reliably, securely, efficiently and consistently according to the requirements defined for that particular project.
Why is Software Quality Important?
Software is used in banking, education, healthcare, transportation, communication, government systems and almost every modern organisation.
Poor-quality software can cause much more than a small inconvenience. Depending on the system, defects may lead to financial loss, wrong information, service interruption, security problems or loss of user trust.
Reduces Defects
Early quality activities help identify problems before they become expensive.
Improves Reliability
Better processes help software behave more consistently.
Improves Customer Confidence
Users are more likely to trust software that consistently meets expectations.
Reduces Rework
Preventing defects is generally better than fixing large problems late.
Supports Standards
SQA helps organisations apply agreed processes, procedures and quality policies.
Supports Improvement
Quality data can help teams improve the software development process over time.
Software Quality Assurance Explained
Software Quality Assurance is not one single activity.
It is a collection of planned activities used across the software development process to provide confidence that suitable quality practices are being followed.
SQA is strongly focused on defect prevention and process quality, while testing is mainly used to identify defects and verify software behaviour.
Quality Assurance vs Quality Control
Students often use Quality Assurance and Quality Control as if they mean exactly the same thing. They are related, but their main focus is different.
| Basis | Quality Assurance (QA) | Quality Control (QC) |
|---|---|---|
| Main Focus | Process quality | Product quality |
| Main Goal | Prevent defects | Identify defects |
| Approach | Proactive | More detection-oriented |
| Examples | Standards, audits, process reviews, procedures | Testing, product inspection, defect checking |
| Main Question | Are proper processes being followed? | Does the product meet required quality? |
QC = Detect
SQA vs Software Testing
Testing is an important quality activity, but testing alone is not the complete Software Quality Assurance process.
| Basis | SQA | Software Testing |
|---|---|---|
| Scope | Broad | More focused |
| Focus | Processes, standards and quality practices | Behaviour and defects in software |
| When Used | Throughout the development life cycle | At appropriate development and testing stages |
| Examples | Audit, review, standards, metrics, improvement | Unit, integration, system and acceptance testing |
Verification and Validation in Software Engineering
Verification and Validation are two of the most important quality concepts in software engineering.
They are related, but they answer different questions.
Verification
Verification checks whether software work products are being developed correctly according to specified requirements, plans, designs and standards.
Main question:“Are we building the product right?”
Validation
Validation checks whether the resulting software satisfies its intended use and user needs in the relevant environment.
Main question:“Are we building the right product?”
Validation = Right Product
Verification Explained with Example
Verification is concerned with checking software development work products against specified requirements or standards.
Verification can be performed without executing the final software in many cases.
Examples of Verification Activities
- Requirement review
- Design review
- Code review
- Walkthrough
- Inspection
- Static analysis
- Document review
Suppose the SRS states that a password must contain at least 8 characters.
During design and code review, the team checks whether the implementation has been designed and written according to this requirement.
This is part of verification.
Validation Explained with Example
Validation focuses on whether the software actually solves the intended problem and satisfies user needs.
It commonly involves executing or evaluating the software in realistic conditions.
Examples of Validation Activities
- System testing
- Acceptance testing
- Prototype evaluation
- User evaluation
- Operational scenario testing
A college develops an attendance application.
The software may technically work exactly according to its design, but if teachers find that the application cannot support their actual attendance workflow, the product may fail validation.
Verification vs Validation
| Basis | Verification | Validation |
|---|---|---|
| Main Question | Are we building the product right? | Are we building the right product? |
| Focus | Conformance to specifications | Satisfaction of intended use and user need |
| Typical Activities | Reviews, inspections, static analysis | System and acceptance evaluation |
| Execution Required? | Not always | Often involves executing or evaluating working software |
| Defect Type Found | Specification, design and implementation problems | Mismatch with user needs or intended use |
Static and Dynamic Quality Activities
Static Activities
Static activities examine software work products without necessarily executing the program.
- Requirement review
- Design inspection
- Code review
- Static code analysis
Dynamic Activities
Dynamic activities evaluate software by executing it.
- Unit testing
- Integration testing
- System testing
- Acceptance testing
Major Activities of Software Quality Assurance
An SQA programme can contain many activities depending on the organisation, project size and software risk.
Quality Planning
Decide the quality goals, standards, methods, responsibilities and checks that will be used.
Process Definition
Define appropriate software processes, procedures and development practices.
Reviews
Examine requirements, design, code and other work products before defects spread.
Audits
Check whether agreed processes and quality practices are actually being followed.
Testing Support
Ensure suitable testing processes, evidence and defect management are used.
Configuration Management
Help ensure that versions and changes to important software items are controlled.
Defect Tracking
Record and analyse defects to understand product and process problems.
Quality Measurement
Use suitable metrics to understand trends and support improvement.
Training
Ensure team members understand relevant processes, methods and standards.
Process Improvement
Use lessons and evidence to improve development practices over time.
Software Quality Assurance Process
Software Quality Assurance Plan
An SQA Plan describes how quality assurance will be organised for a project.
It provides a practical plan for maintaining and evaluating quality throughout development.
Software Reviews
A software review is a structured examination of a software work product.
Reviews help identify defects before those defects move into later development stages.
Requirement Review
Checks requirements for issues such as ambiguity, incompleteness, inconsistency and lack of testability.
Design Review
Checks whether the software design is suitable for the requirements and whether important design problems exist.
Code Review
Examines source code for defects, maintainability issues, security problems or violations of coding practices.
Walkthrough vs Inspection
| Basis | Walkthrough | Inspection |
|---|---|---|
| Formality | Usually less formal | More structured and formal |
| Main Purpose | Understand work and identify issues | Systematically detect defects |
| Preparation | Can be relatively light | Usually requires defined preparation and roles |
| Leadership | Often led by the author | Often uses a defined moderator or inspection process |
What is a Software Quality Audit?
A quality audit checks whether software activities and work products comply with defined procedures, standards, plans or contractual expectations.
Review: Is this work product technically acceptable?
Audit: Are required processes and standards being followed?
Defect Prevention in SQA
A mature quality approach does not wait for testing to find every defect.
The team tries to understand why defects happen and then improves the process so that similar problems occur less frequently.
Root Cause Analysis
Root Cause Analysis tries to identify the underlying reason behind a quality problem.
A project repeatedly finds missing validation in user-input forms.
Simply fixing each form removes individual defects.
Root cause analysis may show that the development checklist does not contain input-validation requirements and code reviews are not checking them.
Updating the process can help prevent similar defects in future modules.
Software Quality Metrics
Metrics provide measurable information that can help teams understand software quality and process performance.
A metric should be selected because it supports a useful decision, not simply because it is easy to count.
Defect Density
Defect Density = Number of Defects ÷ Selected Software Size Measure
The size measure may vary between organisations and projects. Therefore, metric definitions should always be documented.
Cost of Software Quality
Quality work requires effort, but poor quality also creates cost.
Quality-related cost is often discussed in four broad categories.
Prevention Cost
Training, standards, quality planning and process improvement.
Appraisal Cost
Reviews, audits, inspections and testing activities.
Internal Failure Cost
Defects found before software reaches the customer.
External Failure Cost
Problems discovered after release or delivery.
Spending reasonable effort to prevent and identify defects early can reduce the much larger cost of failures discovered late.
ISO 9000 and Software Quality Assurance
ISO 9000 is often discussed in software engineering because software organisations also need systematic quality-management processes.
However, students should understand one important point:
ISO 9000 provides fundamentals and vocabulary for quality management systems.
ISO 9001 contains requirements for a Quality Management System.
Current ISO 9000 and ISO 9001 Editions
| Standard | Main Purpose | Current Edition Discussed Here |
|---|---|---|
| ISO 9000 | Quality management fundamentals and vocabulary | ISO 9000:2026 |
| ISO 9001 | Quality management system requirements | ISO 9001:2026 |
If your syllabus still specifically refers to ISO 9000:2015 or ISO 9001:2015, follow the version asked in the question.
For an updated answer, you can mention that newer 2026 editions are now published.
What is the ISO 9000 Family?
The ISO 9000 family is a group of standards related to quality management systems.
These standards help organisations establish a systematic approach to managing quality, customer expectations, processes and continual improvement.
Seven Quality Management Principles
The ISO quality-management framework is based on seven important principles.
Understand customer needs and work to meet relevant expectations.
Leaders create direction and an environment that supports quality objectives.
Competent and involved people contribute to organisational quality.
Activities should be understood and managed as connected processes.
Organisations should continuously look for opportunities to improve.
Decisions should use relevant data and evidence rather than assumptions alone.
Important relationships with interested parties should be managed effectively.
Customer Focus – Leadership – Engagement – Process Approach – Improvement – Evidence – Relationship Management
How ISO 9001 Relates to Software Organisations
ISO 9001 is not a programming standard and does not tell developers which programming language, database or framework to use.
Its focus is the organisation's quality management system.
A software organisation can apply quality-management principles to activities such as:
- Requirement management
- Project planning
- Design and development controls
- Supplier management
- Document and record control
- Customer feedback
- Corrective action
- Measurement and improvement
Can an Organisation Be ISO 9000 Certified?
Students often say “ISO 9000 certification”, but this needs a clearer explanation.
In the ISO 9000 family, ISO 9001 contains the requirements against which an organisation's Quality Management System can be certified.
ISO 9000 itself mainly provides quality-management fundamentals and vocabulary.
Benefits of a Quality Management System
- More consistent organisational processes
- Better process documentation
- Stronger customer focus
- Defined responsibilities
- Evidence-based improvement
- Better handling of nonconformities
- Greater focus on continual improvement
What is SEI-CMM?
SEI-CMM refers to the Software Capability Maturity Model developed by the Software Engineering Institute at Carnegie Mellon University.
The model was designed to help organisations understand and improve the maturity of their software development processes.
Instead of asking only whether one software product is good, CMM asks a broader question:
Important Historical Note About SEI-CMM
The Software CMM is historically very important in software engineering and is still commonly taught in university courses.
The classic Software CMM was later evolved into the broader CMMI – Capability Maturity Model Integration framework.
Therefore, when your syllabus asks specifically for SEI-CMM, write the classic five Software CMM maturity levels.
Five Levels of SEI Capability Maturity Model
Initial → Repeatable → Defined → Managed → Optimizing
Level 1 – Initial
At Level 1, the software process is generally not consistently defined or controlled.
Success may depend heavily on individual effort, experience and emergency problem solving.
One talented developer knows how everything works.
If that developer leaves, the organisation struggles because processes are not properly documented or institutionalised.
Level 2 – Repeatable
At Level 2, basic project-management practices are established.
Successful practices from similar projects can be repeated because basic discipline exists in important project-management areas.
Classic Level 2 Key Process Areas
- Requirements Management
- Software Project Planning
- Software Project Tracking and Oversight
- Software Subcontract Management
- Software Quality Assurance
- Software Configuration Management
Software Quality Assurance itself appeared as a key process area at Level 2 of the classic Software CMM.
Level 3 – Defined
At Level 3, software processes are documented, standardised and integrated into an organisation-wide process.
Projects may tailor the organisation's standard process according to defined guidelines.
Classic Level 3 Key Process Areas
- Organization Process Focus
- Organization Process Definition
- Training Program
- Integrated Software Management
- Software Product Engineering
- Intergroup Coordination
- Peer Reviews
Level 4 – Managed
At Level 4, the organisation uses quantitative measures to understand and control software processes and software quality.
Classic Level 4 Key Process Areas
- Quantitative Process Management
- Software Quality Management
At Level 3, the process is defined.
At Level 4, the organisation starts managing that process using quantitative data.
Level 5 – Optimizing
Level 5 focuses on continuous process improvement.
The organisation uses process data, defect information and innovation to improve software development continuously.
Classic Level 5 Key Process Areas
- Defect Prevention
- Technology Change Management
- Process Change Management
SEI-CMM Levels at a Glance
| Level | Name | Main Idea |
|---|---|---|
| 1 | Initial | Ad hoc and unpredictable process |
| 2 | Repeatable | Basic project management discipline |
| 3 | Defined | Organisation-wide documented standard process |
| 4 | Managed | Quantitative process and quality management |
| 5 | Optimizing | Continuous process improvement |
What is Process Maturity?
Process maturity describes how well an organisation's software process is defined, managed, measured, controlled and improved.
A mature software organisation does not depend only on individual heroics.
It tries to make successful development practices repeatable and organisational.
Easy Way to Understand CMM Progression
We somehow make it work
We can repeat success
We have standard processes
We measure the process
We continuously improve it
SEI-CMM vs CMMI
Students should not assume that CMM and CMMI are exactly the same model.
| Basis | Software CMM | CMMI |
|---|---|---|
| Meaning | Capability Maturity Model for Software | Capability Maturity Model Integration |
| Historical Focus | Software process maturity | Integrated process-improvement framework |
| Relationship | Earlier model | Evolved from and integrated earlier maturity models |
| Exam Use | Classic five levels frequently asked | Often studied separately in modern process-improvement topics |
ISO 9001 vs SEI-CMM
Both are related to quality and organisational processes, but their purpose and structure are different.
| Basis | ISO 9001 | SEI Software CMM |
|---|---|---|
| Main Focus | Quality Management System requirements | Software process maturity improvement |
| Structure | QMS requirements | Five maturity levels |
| Industry | Applicable across many sectors | Historically focused on software organisations |
| Certification / Assessment | Organisations can be certified against ISO 9001 | Historically used process maturity assessments |
| Main Question | Does the organisation operate a conforming quality-management system? | How mature is the software process? |
SQA Across the Software Development Life Cycle
Quality assurance should not begin only when coding is finished.
Different SQA activities can be applied at every major development stage.
| SDLC Stage | Possible SQA Activities |
|---|---|
| Requirements | Requirement review, ambiguity check, traceability review |
| Design | Design review, architecture evaluation, standards checking |
| Coding | Code review, static analysis, coding-standard checks |
| Testing | Test planning, defect tracking, coverage evaluation |
| Deployment | Release checks, configuration verification |
| Maintenance | Change control, regression testing, quality monitoring |
Role of Software Configuration Management in Quality
Software Configuration Management helps control changes to important software items.
Without configuration control, teams may accidentally test one version, deploy another version and document a third version.
- Source-code versions
- Requirements documents
- Design documents
- Test cases
- Release versions
- Approved changes
Change Control and SQA
Who is Responsible for Software Quality?
Quality is not only the responsibility of the tester or SQA team.
Analyst
Helps create clear and testable requirements.
Developer
Writes maintainable code and follows engineering practices.
Tester
Evaluates software and identifies quality problems.
Project Manager
Plans resources, quality activities and project controls.
SQA Team
Monitors processes, standards, audits and quality practices.
Management
Provides quality policy, resources and organisational support.
Common Mistakes Students Make in SQA
Mistake 1: SQA Means Only Testing
Testing is only one part of the larger software-quality process.
Mistake 2: Verification and Validation Are the Same
Verification focuses on building according to specification. Validation focuses on satisfying intended use and user needs.
Mistake 3: ISO 9000 and ISO 9001 Are the Same Standard
ISO 9000 provides fundamentals and vocabulary, while ISO 9001 contains QMS requirements.
Mistake 4: Calling ISO 9000 the Certification Standard
Certification within this family is against ISO 9001 requirements.
Mistake 5: Writing CMM Levels in the Wrong Order
Remember: Initial → Repeatable → Defined → Managed → Optimizing.
Mistake 6: Confusing CMM with CMMI
Software CMM is an earlier model. CMMI evolved from and integrated earlier capability-maturity approaches.
Mistake 7: Thinking Quality is Only the Tester's Job
Quality depends on requirements, design, coding, testing, management and organisational processes.
Advantages of Software Quality Assurance
- Helps prevent defects.
- Improves process consistency.
- Supports compliance with standards and procedures.
- Encourages early defect detection.
- Improves software reliability.
- Reduces avoidable rework.
- Improves documentation and traceability.
- Supports measurement and process improvement.
- Improves customer confidence.
- Supports more predictable software development.
Challenges of Software Quality Assurance
- SQA activities require time and resources.
- Poorly designed procedures can create unnecessary documentation.
- Metrics can be misleading if selected incorrectly.
- Teams may resist process changes.
- Standards alone cannot guarantee a defect-free product.
- Quality processes must be tailored to project risk and context.
Complete SQA Example: Online Examination System
Suppose a university is developing an Online Examination System.
The SQA approach may include the following activities.
Requirements Review
Check whether exam timing, authentication, question submission, result calculation and administrator requirements are clearly defined.
Quality Planning
Define security, availability, performance and reliability expectations.
Design Review
Review system architecture, database design and failure-handling strategy.
Code Review
Review authentication, exam-timer logic, submission logic and critical modules.
Testing
Perform appropriate unit, integration, system, security, performance and acceptance testing.
Audit
Check whether required project processes, review records and quality procedures have been followed.
Measure Defects
Analyse major defect categories and identify repeated problems.
Improve Process
Use the findings to improve requirements, coding checklists, review practices or testing strategy for future releases.
Exam-Oriented Definition of SQA
Software Quality Assurance (SQA) is a planned and systematic set of activities used to provide confidence that software processes and products conform to specified requirements, standards and procedures.
2 Marks: What is Verification?
Verification is the process of checking whether software work products conform to specified requirements and are being developed correctly. It is commonly remembered as: “Are we building the product right?”
2 Marks: What is Validation?
Validation determines whether the software satisfies its intended use and actual user needs. It is commonly remembered as: “Are we building the right product?”
5 Marks: Verification vs Validation
Verification checks conformance with specifications and includes activities such as reviews, inspections and static analysis.
Validation checks whether the completed software satisfies the intended use and user needs and commonly involves system or acceptance evaluation.
5 Marks: Explain ISO 9000
ISO 9000 is part of the ISO 9000 family of quality-management standards. ISO 9000 provides fundamentals and vocabulary for quality management systems. The family is based on quality-management principles such as customer focus, leadership, engagement of people, process approach, improvement, evidence-based decision making and relationship management.
5 Marks: Explain SEI-CMM Levels
- Level 1 – Initial: Process is largely ad hoc and unpredictable.
- Level 2 – Repeatable: Basic project-management practices are established.
- Level 3 – Defined: Organisation-wide standard software processes are documented.
- Level 4 – Managed: Software processes and quality are quantitatively measured and controlled.
- Level 5 – Optimizing: Continuous process improvement becomes the main focus.
10 Marks: Explain Software Quality Assurance
For a long-answer question, write in this sequence:
- Define software quality.
- Define SQA.
- Explain objectives of SQA.
- Explain QA vs QC.
- Explain Verification and Validation.
- Explain reviews and audits.
- Explain SQA activities.
- Explain software-quality metrics.
- Mention ISO 9000 quality management.
- Explain SEI-CMM maturity levels.
- Write advantages and conclusion.
Fast Exam Memory Tricks
QC = Detect
Verification = Right Way
Validation = Right Product
Initial → Repeatable → Defined → Managed → Optimizing
ISO Quality Management Principles memory pattern
Important Quality Concepts at a Glance
| Concept | Main Focus |
|---|---|
| SQA | Systematic quality assurance across software processes |
| QA | Defect prevention and process improvement |
| QC | Product checking and defect detection |
| Verification | Are we building the product right? |
| Validation | Are we building the right product? |
| ISO 9000 | Quality-management fundamentals and vocabulary |
| ISO 9001 | Quality Management System requirements |
| SEI-CMM | Software process maturity |
| CMMI | Integrated process-improvement framework evolved from earlier models |
Quick Revision Notes
- SQA stands for Software Quality Assurance.
- SQA is a planned and systematic approach to software quality.
- QA mainly focuses on process and defect prevention.
- QC mainly focuses on product checking and defect detection.
- Verification asks: Are we building the product right?
- Validation asks: Are we building the right product?
- Reviews can detect defects without executing the final software.
- Audits check conformance with defined procedures, standards and plans.
- SQA should be applied throughout the SDLC.
- ISO 9000 provides quality-management fundamentals and vocabulary.
- ISO 9001 provides QMS requirements.
- The current editions discussed here are ISO 9000:2026 and ISO 9001:2026.
- ISO quality management is based on seven major principles.
- Classic SEI Software CMM contains five maturity levels.
- Level 1 = Initial.
- Level 2 = Repeatable.
- Level 3 = Defined.
- Level 4 = Managed.
- Level 5 = Optimizing.
- Software Quality Assurance is a classic Level 2 key process area in SW-CMM v1.1.
- Software CMM later evolved into the broader CMMI framework.
Frequently Asked Questions
What is Software Quality Assurance?
Software Quality Assurance is a planned and systematic set of activities used to provide confidence that software processes and products follow defined requirements, standards and quality practices.
What is the difference between QA and QC?
QA mainly focuses on improving processes and preventing defects, while QC focuses more directly on checking products and detecting defects.
What is verification in software engineering?
Verification checks whether software work products conform to their specifications and are being developed correctly.
What is validation in software engineering?
Validation checks whether the software satisfies its intended use and actual user needs.
What is the difference between verification and validation?
Verification asks whether the product is being built correctly according to specifications, while validation asks whether the correct product is being built for the user's actual need.
Is testing the same as SQA?
No. Testing is an important quality activity, but SQA also includes planning, standards, reviews, audits, metrics, process improvement and other quality-management activities.
What is ISO 9000?
ISO 9000 provides fundamentals and vocabulary for quality management systems and belongs to the ISO 9000 family of quality-management standards.
What is ISO 9001?
ISO 9001 specifies requirements for establishing, implementing, maintaining and continually improving a Quality Management System.
What is the current ISO 9000 edition?
The current edition discussed in this article is ISO 9000:2026.
What is the current ISO 9001 edition?
The current edition discussed in this article is ISO 9001:2026.
Can an organisation get ISO 9000 certification?
Certification within the ISO 9000 family is performed against ISO 9001 requirements rather than ISO 9000 fundamentals and vocabulary.
What is SEI-CMM?
SEI-CMM is the Software Capability Maturity Model developed by the Software Engineering Institute to help organisations understand and improve software-process maturity.
What are the five levels of SEI-CMM?
The five classic Software CMM levels are Initial, Repeatable, Defined, Managed and Optimizing.
What is Level 1 of CMM?
Level 1 is Initial. Software processes are generally ad hoc and success may depend heavily on individual effort.
What is Level 2 of CMM?
Level 2 is Repeatable. Basic project-management practices are established so successful practices can be repeated on similar projects.
What is Level 3 of CMM?
Level 3 is Defined. Standard software processes are documented and used across the organisation.
What is Level 4 of CMM?
Level 4 is Managed. Process and software-quality performance are understood using quantitative measurement.
What is Level 5 of CMM?
Level 5 is Optimizing. The organisation focuses on continuous software-process improvement and defect prevention.
What is the difference between CMM and CMMI?
Software CMM is an earlier software-process maturity model. CMMI later evolved from and integrated earlier maturity-model approaches into a broader process-improvement framework.
Conclusion
Software Quality Assurance is much broader than simply testing a finished application. It is a planned approach to quality that begins with requirements and continues through design, coding, testing, deployment and maintenance.
Verification and Validation are central to this process. Verification helps determine whether the software is being built correctly according to specifications, while validation helps determine whether the software actually satisfies its intended use and user needs.
Quality-management frameworks such as the ISO 9000 family help organisations think about quality systematically. Students should remember that ISO 9000 provides fundamentals and vocabulary, while ISO 9001 contains Quality Management System requirements.
The classic SEI Software Capability Maturity Model adds another important idea: software quality improves when development processes themselves become more mature. Its five levels move from an ad hoc Initial process toward an Optimizing organisation focused on continuous improvement.
QA = Prevent defects.
QC = Detect defects.
Verification = Are we building the product right?
Validation = Are we building the right product?
CMM = Initial → Repeatable → Defined → Managed → Optimizing.
Reference Standards and Sources
ISO 9000:2026 — Quality management — Fundamentals and vocabulary.
ISO 9001:2026 — Quality management systems — Requirements.
Software Engineering Institute, Carnegie Mellon University — Capability Maturity Model for Software, Version 1.1.
Software Engineering Institute — Key Practices of the Capability Maturity Model, Version 1.1.
