Start a free trial
Menu

AAP-48

AAP-48 NATO system life cycle processes

NATO programmes, agencies and nations running a defence acquisition, and the suppliers whose own processes interface with theirs

AAP-48 sets out the NATO process model, used alongside AAP-20, for running a defence system's life cycle from concept through disposal, built on ISO/IEC/IEEE 15288.

Edition
C
Published
2022-05
Evaluated by
government-surveillance

What it is

AAP-48, "NATO System Life Cycle Processes", is NATO's generic process model for running a defence system from pre-concept through retirement and disposal. It is not a specification for any one product. It is a customer-side process framework: 26 processes, grouped into Agreement Processes, Organisational Project-Enabling Processes, Project Processes and Technical Processes, that NATO programmes, agencies and nations use to manage acquisition, quality, configuration, risk, requirements, design, verification, logistics and disposal across a programme's whole life. It is built directly on ISO/IEC/IEEE 15288, "Systems Engineering - System Life Cycle Processes", which NATO adopts as its baseline and then extends with NATO/customer-specific activities the industrial standard does not cover.

AAP-48 does not stand alone

AAP-48 only makes sense read together with AAP-20, the NATO Programme Management Framework. AAP-20 defines the life cycle stages (Pre-Concept, Concept, Development, Production, Utilisation, Support, Retirement) and the milestones and decision gates between them; AAP-48 defines what has to happen inside each stage, process by process. Our catalogue records both documents as covered by STANAG 4728, "System Life Cycle Management - AAP-20 & AAP-48" - the agreement a nation actually commits to, and the route by which AAP-48 reaches a contract or a tender. Read on its own, AAP-48 creates no obligation: it says plainly that NATO and Nations "are encouraged to use this publication as a guide", and that it "intends to support and complement national acquisition policies and not replace them."

Who it is written for

AAP-48 addresses the customer side of a programme: "This publication should be used by NATO programmes, NATO Agencies, and Nations in the implementation of System Life Cycle Management." Industry is not the primary reader. Every process instead carries an "Industry perspective" note describing how a supplier's own processes - configuration data, quality evidence, risk input, design and logistics documentation - are expected to interface with the customer's. A supplier meets AAP-48 by feeding those processes well, not by following requirements written to it directly.

The four process groups

Agreement Processes cover Acquisition and Supply: qualifying suppliers, agreeing terms, and accepting delivery. Organisational Project-Enabling Processes - Life Cycle Model Management, Infrastructure, Portfolio, Human Resources, Knowledge and Quality Management - are processes an organisation runs across all its programmes, not just one. Project Processes run a given programme day to day: Programme Planning, Assessment and Control, Decision Management, Risk Management, Configuration Management, Information Management, Measurement, Quality Assurance, Through-Life Traceability, and Life Cycle Cost Management. Technical Processes are the engineering work: Business or Mission Analysis, Requirements Definition (stakeholder and system), Architecture and Design Definition, System Analysis, Implementation and Integration, Verification, Transition, Validation, Operation, Logistic Support and Maintenance, and Disposal.

The auditable core: quality, configuration and risk

Quality Management expects a documented plan built on ISO 9000:2015's quality principles, defined responsibility and authority for quality, and arrangements for corrective action "including the methodology for root cause analysis". Where a programme uses external providers, that plan has to make provision for Government Quality Assurance - the mechanism STANAG 4107 and its Allied Quality Assurance Publications define. Configuration Management is described in the most operational detail of any process: a Configuration Management Plan, identification and baselining of configuration items, a change control process running through a Configuration Control Board, status accounting able to reconstruct "complete baselines for each configuration item with roll-back possibilities", and Functional and Physical Configuration Audits before acceptance - all built on STANAG 4427 and the Allied Configuration Management Publications it covers. Risk Management requires a risk register and action item list kept current across the whole life cycle, referencing the same ARAMP-01 guidance NATO publishes for risk in acquisition programmes.

Verification and validation are kept deliberately distinct

AAP-48 is precise about a distinction readers often blur. Verification "provides evidence that a product, service or system element complies with the requirements" - it proves the system was built right. Validation "ensures a product, service or system satisfies the operational needs of the user in the intended environment" - it proves the right system was built. Both run largely in parallel with design and production, not as a single gate at the end.

Logistics and disposal

The Logistic Support and Maintenance Process is built directly on ALP-10, NATO's guidance on integrated logistics support, and requires a logistics strategy, an Integrated Logistic Support Plan, a maintenance plan, and a failure-reporting system to feed design changes back from the field. The Disposal Process requires disposal constraints, a disposal inventory, disposal procedures and records assigned to a named custodian - and is explicit that it "does not include any activities associated with a change of ownership resulting from gifting, resale or change of responsibilities", an exclusion easy to miss.

What it does not cover

AAP-48 sets out no retention periods for the plans, registers and records it calls for, does not name who outside the programme office reviews Configuration Control Board decisions, and sets no numeric quality, reliability or safety thresholds of its own - those come from the specific programme's requirements and contract. It also does not certify anything: no accreditation body assesses conformance with AAP-48, and progress is tracked through AAP-20's own milestones rather than an external audit of the document.

AAP-48 is published by the NATO Standardization Office and listed free of charge in the NATO Standardization Document Database. NATO's documents are not sold by ComplyTrain and we host no copies of them.

How we help

AAP-48 is a process framework, not a certifiable standard, so there is nothing to be "AAP-48 certified" against and no mapping we could honestly claim to it. What the document generates, stage after stage, is exactly the kind of paperwork that has to stay current to be worth anything: a Quality Management Plan, a Configuration Management Plan and its status records, a risk register, an Integrated Logistic Support Plan, a disposal inventory, and a traceability matrix running from stakeholder requirements through to verification evidence.

That is the work ComplyTrain supports in general: a controlled place to hold procedures and plans, a record of who changed what and when, training records for the people running a process, and an audit trail that shows a register or plan was actually kept, not written once and forgotten. A supplier working to a contract that references AAP-48 or AAP-20 can use ComplyTrain to version its own configuration management procedure, log completed risk reviews on schedule, and hold training records for staff running quality assurance or logistics support activities. What ComplyTrain does not do is the engineering itself: it will not define a system architecture, run a configuration audit, calculate a life cycle cost estimate, or execute a disposal - that stays with the programme office and its technical teams.

In defence, which of these processes and documents apply to a given programme is set by the contract and the customer's quality clause, not by AAP-48 alone. See the standards explorer for what sits alongside AAP-48 in the NATO life cycle document library, and talk to us about how ComplyTrain can support the evidence trail your contract actually requires.

Standards it references

Questions

What is AAP-48?

AAP-48, "NATO System Life Cycle Processes", is NATO's generic process model covering acquisition, quality, configuration, risk, requirements, design, verification, logistics and disposal across a defence system's life. It works alongside AAP-20, which defines the life cycle stages and milestones that AAP-48's processes are structured against.

Is AAP-48 mandatory?

Not by itself. NATO and Nations are "encouraged to use this publication as a guide", and it reaches a supplier only where a contract or tender invokes AAP-48, AAP-20, or STANAG 4728. Whether it applies to a given programme is a contractual question, not a general one.

What is the difference between AAP-48 and AAP-20?

AAP-20 is the NATO Programme Management Framework: it defines the life cycle stages, milestones and decision gates. AAP-48 defines the processes carried out inside those stages. NATO describes the two as used "hand in hand" - neither is complete without the other.

Does NATO certify organisations against AAP-48?

No. AAP-48 describes no certification or accreditation scheme. Where external providers are involved, the closest mechanism is Government Quality Assurance under STANAG 4107 - a national authority's surveillance against a contract's quality requirements, not third-party certification.

What edition of AAP-48 is current?

Edition C, Version 1, published in May 2022 by the NATO Standardization Office.

Where can I get a copy of AAP-48?

From the NATO Standardization Document Database, which lists it free of charge. NATO's documents are not sold by ComplyTrain and we do not host copies of them.