Does a 17-Year-Old Movement Need a DevOps Standard?

Does a 17-Year-Old Movement Need a DevOps Standard

Analyst(s): Vikram Rathnam, Mitch Ashley
Publication Date: October 6, 2026

The DevOps Institute, part of PeopleCert, has released The DevOps Standard, a free official book that brings ITIL (Version 5) ‘s AI governance agenda into software delivery. It does not cite the existing IEEE DevOps standard, and its human-centric model must evolve with AI-native development, or agents will outgrow it.

What Is Covered in This Article:

  • What the DevOps Institute published in The DevOps Standard, and how PeopleCert is distributing it.
  • Why PeopleCert is extending its ITIL and PRINCE2 certification business into AI-driven software delivery.
  • What The Futurum Group’s survey data shows about DevOps maturity, AI adoption in development, and agent governance.
  • How the book’s agent authorization model handles the verification bottleneck in AI-assisted delivery.
  • What enterprise technology leaders and platform vendors should do in response.

The News: The DevOps Institute, which PeopleCert acquired in February 2023, released The DevOps Standard (Version 1.0) in October 2026. PeopleCert describes the book as “the vendor-neutral model for the AI-driven world” and offers the digital edition free in exchange for a registration form. In an October 2026 LinkedIn post, Pascal Mevellec of PeopleCert called it “the first ever DEVOPS INSTITUTE Official Book.

The book defines the DevOps Institute (DOI) Operating Model around Nine Pillars of practice, a four-layer DevOps Blueprint, a maturity self-assessment, a 90-day transformation playbook, and a metrics reference that includes DevOps Research and Assessment (DORA) metrics and AI-specific measures. A chapter on AI-native DevOps defines controls for generative and agentic AI, including agent authorization by class of action. Marc Hornbeek is the lead contributor, and the book credits contributors from companies including Dynatrace, Cisco, Adobe, and Visa.

The book says it serves as the body of knowledge for the DevOps Institute certification portfolio within PeopleCert, which also owns ITIL and PRINCE2. PeopleCert released ITIL Foundation (Version 5) in February 2026, with AI Governance as the scheme’s only extension module.

Details are on PeopleCert’s page for The DevOps Standard.

Does a 17-Year-Old Movement Need a DevOps Standard?

Analyst Take: DevOps turns 17 this month, and PeopleCert now offers a formal DevOps standard. The first devopsdays met in Ghent, Belgium, on October 30 and 31, 2009.

PeopleCert is building an AI governance franchise across its portfolio. ITIL (Version 5) added AI governance to IT service management in 2026, and The DevOps Standard from the DevOps Institute carries the same agenda into software delivery. We view the move as commercially sound and the book as a well-built retrofit: useful today, but built on a human-centric delivery model that must evolve in parallel with the AI development lifecycle (AI DLC), or agents will outgrow it.

PeopleCert calls the book “the common language DevOps has been missing.” DevOps already has a formal standard. IEEE 2675-2021, adopted internationally as ISO/IEC/IEEE 32675 in 2022, defines DevOps processes for building and deploying software with compliance controls, and the book does not cite it.

Google Cloud’s DORA program also publishes an AI Capabilities Model, updated in November 2025, that names seven capabilities organizations need to get value from AI. A standard that wants to be the common language will have to explain how it relates to both.

PeopleCert Extends Its ITIL Franchise Into AI Delivery

PeopleCert is extending a commercial qualification franchise that includes the highly successful adopted ITIL, PRINCE2, and the DevOps Institute. Now, PeopleCert moves into AI-driven software engineering, and The DevOps Standard doubles as the curriculum for its DevOps Institute certifications.

Just as DevOps changed the process and flow of how software is created, built, and operated, rapid advances in AI-native development are upending development methods and delivery on a near-weekly basis. Teams adopting AI coding assistants and agents face tool sprawl across cloud, on-premises, and multi-vendor environments, while cloud providers and tool vendors offer adoption frameworks tied to their own ecosystems. PeopleCert is addressing that gap by placing the DOI Operating Model above individual toolchains as a neutral baseline for risk, governance, and maturity for DevOps and the move to AI.

ITIL governs how IT services run, PRINCE2 governs how projects run, and the book places DevOps as the delivery system that connects them. A DevOps standard with AI controls lets PeopleCert sell AI delivery governance to the IT governance buyers who already certify their teams on ITIL.

The Futurum Group’s survey data shows why the timing works. DevOps is mature in just over half of organizations. In the 2H 2026 Software Lifecycle Engineering Global Enterprise Decision Maker Survey (n=839, fielded June 2026), 58% of organizations rated their DevOps practices as standardizing or mastering (1H 2026 Software Lifecycle Engineering Decision Maker Survey Report, January 2026, document 1H26DMSLCEMA202601), yet governance has not kept pace with AI adoption.

In the same survey, 40% of organizations said AI generated or substantially modified most (51% or more) of the production code they merged during the previous 90 days. Only 18% rated their AI-agent governance practices as standardizing or mastering, making governance the least mature practice measured. That governance gap is the market PeopleCert wants.

The risk is pace. ITIL has rightfully taken criticism for being slow to adopt DevOps and update the framework. Certification frameworks have moved on to multi-year cycles, and ITIL went from v3 in 2007 to ITIL 4 in 2019. Then, it waited seven years for Version 5 and its AI module. A syllabus on that cycle, it will quickly trail agent platforms that ship changes every few months, and the gap between static compliance models and platform execution will widen.

Most Organizations Haven’t Made Verification Mandatory

In the same 2H 2026 survey, three-quarters of organizations reported a production incident in the past 12 months where AI was a contributing factor, yet only 43% make human review of AI-generated code mandatory. At most organizations, the review gate the book assumes is still optional.

Eliyahu M. Goldratt’s Theory of Constraints explains the pressure (The Goal, with Jeff Cox, 1984; Theory of Constraints, 1999). When one constraint is removed, another becomes the limit, and AI has moved software delivery’s limit from writing code to proving it works. Verification debt, a term Sonar credits to AWS CTO Werner Vogels for AI output no one has checked, grows faster than organizations can hire reviewers.

Organizations without mandatory review should start with the book’s agent authorization model now. It sorts agent actions by risk, from output a person reads and decides on, to changes a person must approve, to high-impact actions that need explicit sign-off from a named owner.

The DevOps Standard – Surviving the AI-Native Onslaught

AI bolted onto human-centric delivery models hits a ceiling that AI-native models don’t, and The DevOps Standard is built on human-centric design. Its own framing says so: AI changes the DevOps system “while the fundamentals still apply.”

The ceiling is human approval, and the person who performs the work. When every assisted code change needs a person to review and authorize it, the people approving agent work becomes the throughput limit, the same limit we flagged in our analysis of OpenAI’s agent platform this week. In the same survey, 58% of organizations expect AI to create 80% or more of their software within three years, and per-change approval won’t hold at that volume.

The book has a better answer, but treats it as the exception. For low-risk operational tasks, such as gathering diagnostics or restarting an approved non-critical service, people approve a type of action once and then review only the exceptions.

Extending that approach to code changes would help, but it wouldn’t be enough. As our colleague Fernando Montenegro argued in June 2026, people authorize an agent’s goal, and the agent then infers actions nobody anticipated, so a list of pre-approved action classes will miss some of what agents actually do. A second edition will need governance at the level of goals and outcomes, and it will be needed sooner than PeopleCert’s certification cycle suggests.

What Buyers and Vendors Should Do Now

For CIOs, CTOs, and engineering leaders:

  • Fund verification alongside generation. Keep scaling AI coding tools and agents, and put automated testing, contract testing, and pipeline policy enforcement in the same budget. Code generation without automated validation adds verification debt and production incidents.
  • Authorize agents by action class. Require platform and security teams to give every agent workflow-bound permissions, traceable provenance, a tested kill switch, and a named human owner for high-impact changes.
  • Pilot The DevOps Standard on one workflow before rolling it out. Baseline waiting time, rework, failed changes, and recovery, then track whether the assessment leads to funded improvements.

For platform and tool vendors, including GitHub, GitLab, Harness, Atlassian, and Dynatrace:

  • Publish agent evidence in open formats. Buyers running mixed stacks need provenance, agent context logs, and test results they can pull into their own release controls. Vendors should back the open OpenSSF proposal for an in-toto attestation that records AI authorship, alongside Supply-chain Levels for Software Artifacts (SLSA) provenance, and adopt OpenTelemetry’s generative AI conventions for agent traces.
  • Put policy hooks where developers work. Agents and automated remediation need policy checks, security scanning, and cost telemetry inside the developer workflow. Platforms without observable audit trails and reversible actions will struggle to pass enterprise risk and compliance reviews.

What to Watch:

  • Whether PeopleCert launches a certification built on The DevOps Standard, bundles it with ITIL (Version 5) AI Governance, and reports how many practitioners hold it by the end of 2027.
  • Whether PeopleCert addresses IEEE 2675 and DORA’s AI Capabilities Model, or positions The DevOps Standard as a replacement for both.
  • Whether DevOps vendors, including GitHub, GitLab, Harness, or Atlassian, publish agent evidence in open formats such as SLSA provenance or OpenTelemetry traces, or keep it inside their own platforms.
  • Whether regulated buyers in financial services or the public sector adopt the maturity self-assessment as audit evidence.
  • Whether a second edition moves beyond human approval toward governance designed for agent goals and volume, and how soon it ships.

See the complete details on the book from PeopleCert on PeopleCert’s website.


Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.
Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.

Other Insights From Futurum:

Atlassian Bets the Work Surface on Governed Agentic Workflows

OpenAI Moves Up the Stack and Competes With the Platforms It Powers

Platform Engineering Goes Mainstream: Strategy Beats Technology

Author Information

Vikram Rathnam is Research Director, Software Lifecycle Engineering at The Futurum Group. His research examines how software is built, tested, secured, and operated as AI agents move from assisting developers to doing the work. His coverage includes observability, platform engineering, and the control planes that govern agents. Before joining Futurum, he spent 24 years on the vendor side: ten in engineering at Silicon Labs and fourteen in product and partner strategy, with roles at Cisco, Secureworks, Dell, and CMIT Solutions. Across those roles, he managed B2B cybersecurity, IoT, and AI products, with partner and channel ecosystems as the common thread. At CMIT Solutions, he led product strategy across a franchise network of 180 locations. He reads a vendor’s roadmap as someone who has had to ship one and take it to market.

Mitch Ashley is VP and Practice Lead for the CIO & Technology Buyers and Software Lifecycle Engineering practices at The Futurum Group. A multi-time CIO and CTO with 30+ years leading technical organizations, Mitch built and operated production systems spanning cybersecurity for the U.S. Department of Defense, PKI services for the broadband and 5G industries, SaaS platforms, large-scale telecom and banking systems, and a national broadband network. His work with AI began early, developing expert systems that diagnosed and repaired complex mainframe environments. That operator foundation grounds his analysis in operational consequence, covering the technology buyer's world of software engineering, cybersecurity, DevOps, cloud, and AI.

Related Insights
NETSCOUT nGenius Copilot Caps a Three-Release Data-First Strategy
October 6, 2026

NETSCOUT nGenius Copilot Caps a Three-Release Data-First Strategy

Mitch Ashley, VP and Practice Lead, CIO & Technology Buyers and Software Lifecycle Engineering at Futurum, shares his insights on NETSCOUT nGenius Copilot and why its September AI sequence puts...
OPSWAT Firmware 4.3.0 Deepens OT/IT Data-Sharing for Industrial Diodes
October 6, 2026

OPSWAT Firmware 4.3.0 Deepens OT/IT Data-Sharing for Industrial Diodes

OPSWAT's MetaDefender NetWall Fend 4.3.0 adds UDP Multicast, Syslog, and MQTT support, enhancing secure data-sharing between operational and IT environments....
OPSWAT Targets Critical Infrastructure Gaps With MetaDefender Endpoint v7.6.2609
October 5, 2026

OPSWAT Targets Critical Infrastructure Gaps With MetaDefender Endpoint v7.6.2609

OPSWAT's MetaDefender Endpoint v7.6.2609 release introduces configurable media controls, air-gapped anti-malware updates, and expanded audit trails—addressing critical security gaps for enterprises in high-compliance sectors....
Scalian Names First CAIO to Scale AI in Critical Engineering
October 5, 2026

Scalian Names First CAIO to Scale AI in Critical Engineering

Scalian has named Clément Charruel as its first Chief AI Officer, positioning the engineering services firm to compete in a $344B software lifecycle engineering market by embedding AI across critical...
ServiceNow Flow: Can a One-Day Deploy Reshape Enterprise ITSM?
October 2, 2026

ServiceNow Flow: Can a One-Day Deploy Reshape Enterprise ITSM?

ServiceNow launched Flow on October 1, 2026, an AI-native conversational service desk requiring zero infrastructure and instant deployment, targeting AI-native teams and signaling a strategic defense against emerging challengers....
Qodo 3.0 Puts Governance at the Center of Agentic Code
October 2, 2026

Qodo 3.0 Puts Governance at the Center of Agentic Code

Qodo 3.0 fills a critical enterprise gap with governance-first AI agent code management, offering PR Triage, Agentic Toolbox, and analytics to address hallucination and reliability concerns cited by 55.4% of...

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.