ACMP-2100
ACMP-2100 configuration management contractual requirements
Suppliers delivering under a NATO contract that names ACMP-2100
ACMP-2100 sets NATO's core contractual Configuration Management requirements, adapting ISO 10007:2003 with NATO-specific additions, and applies to a Supplier once a contract names it.
- Edition
- A
- Published
- 2017-03
- Evaluated by
- customer-audit
What it is
ACMP-2100 is NATO's Allied Configuration Management Publication - the core set of contractual Configuration Management (CM) requirements a Supplier meets once a contract names it. It does not invent its own CM process: Chapter 4 requires "a Configuration Management system... established, documented, applied, maintained, assessed and improved, and/or evaluated, in accordance with ISO 10007," and then amends that standard's own wording. Chapter 5 adds a short set of NATO-specific requirements on top. The current edition is Edition A, Version 2, promulgated 6 March 2017, superseding Edition A, Version 1.
It has no force by itself. Clause 1.3 states that the publication "is primarily intended for use in a contract between two or more parties" and that, "when referenced in a contract, this publication shall apply to all of the processes necessary for the Supplier to fulfil the contractual requirements." A Supplier can also adopt it voluntarily and internally, without a contract requiring it. Where the contract and the publication disagree, "the contract requirements shall prevail" - ACMP-2100 is a default, not an override. At the level of nations, adoption is itself an agreement: the Letter of Promulgation records that "the agreement of nations to use this publication is recorded in STANAG 4427."
Two parties, defined in the document's own terms
The Supplier is "an organization that acts in a contract as the provider of products to the acquirer." The Acquirer is "a governmental or NATO organization that defines the requirements for the delivery of a product by a supplier and enters into a contractual relationship with that supplier" - a note adds that the two can sometimes be part of the same organisation. "Product" is deliberately broad: the document's own examples run from "document" and "facility" to "firmware," "hardware," "software," "tool," "material," "process," "service" and "system."
Adopting ISO 10007, with two changes to its wording
ISO 10007:2003 is a normative reference, and Chapter 4 makes conformance to it the core requirement, with two specific and two general amendments. The specific changes replace ISO 10007's own wording on two points: paragraph 5.2's closing line now says its suggested configuration-management-plan structure "is only informative," and paragraph 5.3.2's opening paragraph is rewritten to spell out what product configuration information covers - "requirements, specifications, design drawings, parts lists, software documents and listings, models, markings, audit information, effectivity, test specifications, maintenance and operating handbooks." The general changes matter more day to day: everywhere ISO 10007 uses "should" or "may" in its sections 4 and 5, ACMP-2100 reads it as "shall," so what was optional guidance becomes mandatory unless the Acquirer says otherwise; and every "Life Cycle of the product" in ISO 10007 is read as "contract," scoping an obligation the civil standard frames as lifelong down to the length of the contract.
The NATO-specific requirements (Chapter 5)
Four short clauses carry the rest of the substance. Sub-suppliers: the Supplier has to pass its contractual CM requirements down the chain by referencing the stated requirement, and has to confirm the procedures are actually implemented at the sub-supplier's own facilities, not just written into a purchase order. Configuration Management Planning: the Supplier gives the Acquirer access to its Configuration Management Plan, the Acquirer can reject it outright, and the plan has to define the CM organisation and where it sits inside the Supplier's own structure. Product Configuration Information: for every configuration item, the Supplier develops and maintains configuration information that includes, as a minimum, the NCAGE code, uses only formally released information, and accounts for access limitations - security classification and proprietary licence constraints at minimum. Change Control: a change implemented before the Dispositioning Authority approves it is a risk the Supplier carries alone; there is no provision here for approval after the fact to remove that risk.
What an auditor looks for
Because ACMP-2100 names no accredited certification body, there is no "ACMP-2100 certified" status - evaluation runs directly between the Acquirer and the Supplier under the contract. Expect the Acquirer to ask for the Configuration Management Plan itself, and to exercise its right to reject it; documented configuration information per configuration item showing the NCAGE code and access-limitation controls; and a record trail proving a change was approved by the Dispositioning Authority before it was implemented, not after. Sub-supplier flow-down is checked two ways: the contractual clause that passed the requirement down, and confirmation it was actually put into practice at the sub-supplier's premises.
What the document does not cover
ACMP-2100 does not fix a review or expiry date for itself in the text supplied here. It leaves the detail of what belongs in a configuration baseline, and how configuration items are identified in the first place, to ISO 10007 and to the Supplier's own engineering judgement - this document adds contractual teeth, it does not do the configuration-management work itself. And it sets no periodic assessment cycle: oversight runs for the life of the contract, through the Configuration Management Plan the Acquirer holds and the changes the Dispositioning Authority approves.
How we help
ACMP-2100 asks for a Configuration Management Plan, per-item configuration information and change-control records - a management-system discipline, not a physical process. ComplyTrain is the system a Supplier runs that work in, not a substitute for the configuration-management judgement itself. Concretely: the Configuration Management Plan the Acquirer can reject lives as a controlled, versioned document with a clear owner and a review history; configuration information per item, including the NCAGE code and the access-limitation controls the document requires, sits as structured, auditable records rather than scattered files; and a change is not marked implemented until the Dispositioning Authority's approval is on record, giving the Supplier the evidence it did not carry the risk of moving early. The sub-supplier flow-down the document requires - the clause itself, and confirmation it was actually implemented - is the kind of documented, repeatable check ComplyTrain is built to hold.
What ComplyTrain does not do: it does not identify configuration items, decide what belongs in a baseline, act as the Dispositioning Authority, or perform the engineering judgement behind a configuration change. Those stay the Supplier's own configuration-management function.
Which tier of configuration management a contract requires, and what else sits alongside ACMP-2100, is set by the Acquirer's contract and quality clause, not by us. See what else sits in a typical NATO configuration-management package in the standards explorer, and talk to us about the evidence trail behind it.
Standards it references
- ISO 10007Binds
Questions
Is ACMP-2100 a certification, like ISO 9001?
No. ACMP-2100 names no accredited certification body and no scheme for certifying an organisation to it. Evaluation runs directly between the Acquirer and the Supplier under the contract: the Acquirer reviews and can reject the Configuration Management Plan, and the Dispositioning Authority approves changes before they are implemented.
Does ACMP-2100 apply to us?
That depends on the contract, not on the standard. ACMP-2100 only takes effect "when referenced in a contract," so whether it applies is a question for the tender or contract in front of you, not something the document answers on its own.
What is the difference between ACMP-2100 and ISO 10007?
ACMP-2100 adopts ISO 10007:2003 rather than replacing it, then amends specific wording and turns its "should" and "may" language into mandatory "shall" requirements once a contract invokes ACMP-2100. Chapter 5 then adds NATO-specific requirements - sub-supplier flow-down, Acquirer review of the Configuration Management Plan, minimum configuration-information content, and change-control risk - that ISO 10007 does not itself impose.
Who is the Dispositioning Authority?
NATO "considers the Dispositioning Authority to be a person who may be supported by a CCB, which is not mandatory unless stated in the contract." A change implemented before that authority approves it is a risk the Supplier carries alone.
Which parts of ACMP-2100 are actually mandatory?
Only Chapters 4 and 5. Clause 1.4 defines compliance with the publication for a contract as "the fulfilment of the requirements of Chapters 4 and 5" - the earlier chapters on purpose, references and terms are context, not obligations, and the document states plainly that "NOTEs are not contractual requirements."
