CARL does not replace the frameworks below. It sits alongside them — it is the piece that was missing: a codebase-native, machine-checkable, agent-era readiness standard. Where these frameworks overlap with CARL, their outputs can be incorporated as evidence into a CARL assessment. Where they answer different questions than CARL, the combination is strictly more useful than CARL alone.
This section covers, factually and without polemic:
vs. CMMICARL's level names and gated progression are adapted from CMMI. CARL is codebase-native; CMMI is process-native.vs. Microsoft's Agentic AI Adoption Maturity ModelMicrosoft covers organizational adoption of AI. CARL covers the technical substrate agents work on top of.vs. SLSA and OpenSSF ScorecardSLSA and Scorecard overlap with CARL's Security pillar. CARL is broader — eight pillars, not just supply chain.vs. DORADORA is a delivery-metric set. CARL's Delivery & Measurement pillar explicitly references DORA at L3 (Reviewed).
The short version
| If you want to answer… | Use |
|---|---|
| "How ready is this codebase for agent-assisted development?" | CARL |
| "How mature is our engineering process?" | CMMI (or CARL L3 Reviewed as a modern proxy) |
| "How ready is our organization to adopt AI agents broadly?" | Microsoft's model (complementary to CARL) |
| "How secure is our build supply chain?" | SLSA + OpenSSF Scorecard (feed results as CARL SEC-pillar evidence) |
| "How healthy is our delivery practice?" | DORA metrics (captured as CARL DLM criteria at L3 Reviewed) |