ACMP-2000
ACMP-2000 policy on configuration management
Nations, NATO Authorities and programme Acquirers responsible for configuration management on NATO defence programmes
NATO's policy making configuration management mandatory across a defence programme's full life cycle; it cannot itself be used in a contract, so the contractual requirements sit one level down in ACMP-2100.
- Edition
- A
- Published
- 2017-03
What it is
A policy, not a requirements document
ACMP-2000 is NATO's Allied Configuration Management Publication setting out the policy behind configuration management (CM) on NATO defence programmes. Edition A, Version 2 was promulgated on 6 March 2017 and superseded Edition A, Version 1. It applies "to Nations and NATO Authorities of defence related capabilities in NATO operations," and it says something most documents in this family do not have to say: "this Publication may not be used in contracts." That single line matters more than anything else on this page. If you are a supplier reading a tender or a quality clause and you see ACMP-2000 named, the actual, testable requirements are not in it, they are in ACMP-2100 (the Core Set of Configuration Management Contractual Requirements), with ACMP-2009 as guidance on applying them. Nations record their agreement to use all three under STANAG 4427.
What it commits Nations and Acquirers to
ACMP-2000 implements NATO's Policy for Systems Life Cycle Management and the agreement in STANAG 4728 to make CM "a mandatory management process for the full Life Cycle of NATO programmes and systems." The document is short and direct about what that means in practice:
- A Life Cycle Configuration Management Plan (LCCMP) must exist "at every level of programme
management," giving the Acquirer its framework for CM activity for the whole life of the system.
- Preparing, maintaining and executing the LCCMP "cannot be outsourced." The Acquirer develops it and
uses it "as the basis for all contractual CM requirements that are placed on Suppliers."
- The Acquirer must appoint a Configuration Authority (CA) "mandated to make all CM decisions." The
CA can vary by life-cycle stage and can delegate authority to subordinate groups, while keeping the right to overrule or amend what those groups recommend. What it cannot do is delegate responsibility: authority and accountability are treated as separate things.
- CM is explicitly "a through life concept that is applied to all Life Cycle stages," with
traceability of requirements running "from Pre-concept to Retirement." It is also, in the document's own words, "not a stand-alone process operating in isolation": it draws on information from every other life-cycle process to keep product configurations current.
The rationale chapter is worth a mention because it is unusually concrete for a policy document: CM is credited with reducing life-cycle cost, preventing duplicated effort and schedule delay, and providing traceability, with Unique Identification under STANAG 2290 given as the worked example.
What it does not cover
ACMP-2000 defines terms (Acquirer, Product, Release, Supplier), falling back to ISO 9000 and AS/EN 9100 definitions "unless stated otherwise," but it does not specify CM procedures, deliverables, formats, or acceptance criteria. It does not describe how a CA is assessed, what a CM audit looks at, or what evidence a supplier produces. None of that is a gap in the writing: this document sits above that layer by design, and points the reader at ACMP-2100 and ACMP-2009 for it.
How it is evaluated
Nobody is assessed against ACMP-2000 itself. It describes no audit, surveillance, inspection or certification mechanism, and it cannot be cited in a contract in the first place. Where CM requirements do reach a supplier, they are evaluated under ACMP-2100, through government quality assurance surveillance conducted by or on behalf of the Acquirer, not through third-party certification. There is no accredited body that certifies "ACMP-2000 compliance," because the document was never built to be certified against.
Standards it references
ACMP-2000 sits above ACMP-2100, the document that actually carries contractual CM requirements, and ACMP-2009, NATO's guidance on applying them; both are agreed alongside ACMP-2000 under STANAG 4427. It implements the CM element of STANAG 4728, System Life Cycle Management, which in turn covers AAP-20 and AAP-48. It cites STANAG 2290 for Unique Identification as an example of the traceability CM delivers, and its definitions fall back to EN 9100 and ISO 9000 unless stated otherwise. C-M(2005)0108, ANSI/EIA-649, GEIA-HB-649, DEF STAN 05-57 and MIL-HDBK-61 are named as further reading but sit outside our catalogue.
How we help
ACMP-2000 is policy: there is nothing in it for a compliance platform, or anyone else, to implement directly. What changes once a contract or an LCCMP actually specifies CM tasks is a familiar shape of work, and that is where ComplyTrain fits. The LCCMP itself lives as a controlled document with version history; configuration change requests and their dispositions get logged and stay traceable back to the requirement they affect; people acting as, or under, a Configuration Authority have their training recorded; and the evidence a government quality assurance representative would ask for against ACMP-2100 sits in one place instead of scattered across email threads and shared drives.
ComplyTrain does not run configuration management for a programme, decide what a Configuration Authority approves, or produce the LCCMP the Acquirer is required to develop and maintain itself: clause 2.1 is explicit that this cannot be outsourced, and no software changes that. Which CM obligations apply, and at what tier, is set by the contract and the customer's quality clause, not by this page. See how ACMP-2100 and ACMP-2009 sit alongside ACMP-2000 in the standards explorer, or talk to us about how the resulting records get held and evidenced.
Standards it references
- STANAG 4728Background
- STANAG 2290Background
- AAP-48Background
- ACMP-2100Background
- ACMP-2009Background
- AAP-20Background
- EN 9100Background
Questions
Is ACMP-2000 mandatory?
It binds Nations and NATO Authorities through their agreement recorded in STANAG 4427, not through a contract: the document states plainly that it "may not be used in contracts." A supplier only meets NATO configuration management obligations because a contract invokes ACMP-2100, not ACMP-2000 itself.
What is the difference between ACMP-2000 and ACMP-2100?
ACMP-2000 is the policy: it says configuration management is mandatory across a NATO programme's life cycle and assigns ownership to the Acquirer and its Configuration Authority. ACMP-2100 is the Core Set of Configuration Management Contractual Requirements, the document a tender or contract actually cites when it wants CM work done and evidenced.
Can a company be certified to ACMP-2000?
No. The document describes no certification, audit or surveillance mechanism, and it cannot appear in a contract for anyone to be assessed against. Government quality assurance surveillance against ACMP-2100, run by or for the Acquirer, is the mechanism that actually checks CM work on a programme.
What edition of ACMP-2000 is current?
Edition A, Version 2, promulgated 6 March 2017. It superseded Edition A, Version 1, which nations were instructed to destroy on receipt of the new version according to their local procedure.
Who has to maintain the Life Cycle Configuration Management Plan?
The Acquirer. ACMP-2000 states that preparing, maintaining and executing the LCCMP "cannot be outsourced," and that the Acquirer uses it as the basis for every contractual CM requirement placed on suppliers.
