Overview
ISO/IEC/IEEE 41062:2024 - Software engineering - Life cycle processes - Software acquisition defines a practical, process-oriented framework for acquiring software and software-related services from external suppliers. The standard describes activities, tasks, methods, and practices that acquirers can apply across competitive and sole-source procurements, regardless of type, size, complexity, or cost. It applies to software running on any computer system and to supply chains that may include custom software, off‑the‑shelf (OTS), Software as a Service (SaaS), and free/open‑source software (FOSS). Software services covered include development, sustainment (maintenance), integration, verification (testing) and operation. Security and safety are treated as attributes to be considered during acquisition (note: specific acquisition requirements for information assurance, safety, and cloud services are not included).
Key topics and technical requirements
- Software acquisition process structure: definition, tailoring, and sub‑processes for planning, evaluation/selection/contracting, implementation/acceptance, and operations/maintenance.
- Acquisition alternatives: pros and cons of custom development, OTS, SaaS, and FOSS and guidance on selecting the appropriate sourcing strategy.
- Planning & RFP: developing acquisition strategy and plans, feasibility studies, risk assessment, agile considerations, forming acquisition teams, and preparing RFI/RFQ/RFP and Statements of Work (SOW).
- Requirements: defining business, system, and software requirements; verification and validation (V&V) of requirements; defining acceptance criteria and procedures.
- Supplier identification & evaluation: advertising, pre‑qualification, proposal evaluation criteria and methods, alternative evaluation techniques, and additional information sources.
- Contracting & negotiation: preparing contractual requirements, negotiating terms, letters of understanding, and remedies for non‑performance.
- Implementation & acceptance: supplier performance evaluation, acceptance testing, process improvement, and applying non‑performance remedies.
- Risk management: identifying, assessing, and managing acquisition risks across all sub‑processes.
Practical applications - who uses it
- Procurement officers and acquisition managers to design compliant, repeatable software procurement processes.
- Project managers and systems engineers for selecting sourcing strategies and embedding acquisition activities into lifecycle plans.
- Contract managers and legal teams for drafting RFPs, RFIs, RFQs, SOWs, and contract clauses tied to technical acceptance criteria.
- Quality assurance and V&V teams to define acceptance tests and supplier performance metrics.
- Vendors and suppliers to align proposals with buyer expectations and accepted acquisition practices.
- Auditors and compliance officers for assessing acquisition process maturity and conformance.
Related standards
This standard complements other ISO/IEC/IEEE life‑cycle process guidance and procurement best practices by focusing specifically on the software acquisition lifecycle. Use ISO/IEC/IEEE 41062:2024 alongside organizational procurement policies and software life‑cycle standards for a cohesive acquisition strategy.
Keywords: ISO/IEC/IEEE 41062:2024, software acquisition, software procurement, RFP, OTS, SaaS, FOSS, supplier evaluation, contracting, acceptance, V&V, life cycle processes.