AEP-83
AEP-83 light unmanned aircraft systems airworthiness requirements
Organisations that design, produce or maintain a light fixed-wing unmanned aircraft system, and the national Certifying Authority that reviews it for a Military Type Certificate
AEP-83 sets NATO's minimum airworthiness requirements for light fixed-wing drones under 150 kg, reviewed by a national Certifying Authority before it issues a Military Type Certificate.
- Edition
- C
- Published
- 2023-10
- Evaluated by
- notified-body
What it is
AEP-83 is the NATO Allied Engineering Publication that sets the minimum technical airworthiness requirements for a fixed-wing light unmanned aircraft system (UAS): a maximum take-off weight of no more than 150 kg and an impact energy above a 66 J threshold (§1, Scope), intended to fly regularly in non-segregated airspace. Rather than a prescriptive checklist, it works through high-level "Essential Requirements for Airworthiness" and, for each one, a detailed argument an Applicant can use to satisfy it and an acceptable set of supporting evidence. The document repeatedly calls itself "this STANAG" in its own text, but the agreement nations actually ratify is STANAG 4703, which covers it; AEP-83 is the technical content underneath.
The document addresses the "Applicant" - the organisation, or natural person, undertaking design, production or maintenance of the UAS type - together with the national Certifying Authority that reviews the evidence, the engine and propeller manufacturers that supply compliance declarations for their own equipment, and the UA Operator who flies within the limits recorded in the Flight Manual. It reaches a company through a national acquisition programme, not by existing: the Netherlands' recorded reservation states that its Military Aviation Authority will require AEP-83's implementation for UAS acquisitions falling under STANAG 4703, but that it will apply its own separate national Military Type Certificate regulations rather than follow the document's Type Certificate provisions as written. Belgium similarly reserves the right to categorise its UAS by use and scenario rather than by the document's criteria alone. This is Edition C, Version 1, promulgated October 2023; the document does not state what edition it superseded.
Structures, propulsion and systems
Every requirement traces back to a "design usage spectrum" the Applicant has to define first: missions, in-flight and on-ground conditions, environments and mass configurations. Structural margins are then substantiated against that spectrum. Unless a more rational method is agreed with the Certifying Authority, specific minimum factors apply: an ultimate load factor of safety of at least 1.5 for structure whose failure would be Hazardous or worse, or at least 1.25 for other structure (UL2.3); a positive symmetric manoeuvring load factor of at least 3.8 and a negative factor of at least -1.5 (UL5.2); and a bird-strike design case built around a 0.2 kg bird (UL13.2). Composite primary structure needs either a factor-of-safety multiplier of at least 6.0, or design to specific damage-tolerance strain limits set out in a table (UL13.1). Every manufactured part, assembly and the complete UAS has to be produced under a quality system approved to AS/EN-9100 or equivalent (UL.10).
The installed engine, whether reciprocating, electric or turbine, and the propeller each have their own dedicated annex of design and bench-test requirements, typically including a 50-hour endurance test (UL.RE.22; UL.EE.22) followed by a teardown inspection. Fuel and battery systems carry detailed requirements down to unusable-fuel-quantity testing and a mandatory low-battery warning threshold.
Safety assessment and software assurance
A System Safety Assessment covering the whole UAS - the aircraft, control station, data link and any other necessary equipment - is mandatory, built from a Functional Hazard Assessment, a Failure Mode Effect and Criticality Analysis, a Fault Tree Analysis and a Common Cause Analysis. Every catastrophic failure condition has to sit within a cumulative safety budget set by weight: 10⁻⁴ per flight hour below 15 kg maximum take-off weight, or 0.0015 divided by the weight in kg between 15 kg and 150 kg (Annex G, UL.HRS.2). Software and complex hardware get a Development Assurance Level assigned from a table keyed to failure-condition severity and to how many independent components share a failure mode, following an agreed process such as RTCA DO-178/ED-12. The command-and-control data link needs an automatic reacquisition strategy and an agreed loss strategy if reacquisition fails, and the operator display carries a defined minimum data set - airspeed, position, propulsion status, battery state, data-link health - refreshed at a rate consistent with safe operation.
Flight performance and continued airworthiness
Stalling speeds, take-off and landing distances over a 15 m (50 ft) obstacle (UL.42, UL.46), climb rates, glide range, navigation accuracy and minimum control speed all carry defined test methods and go into the Flight Manual. The aircraft has to remain stable and controllable, including in manual direct-piloting mode where that exists, with flight-envelope protection designed so its limits are smooth and don't interact adversely with each other. An emergency recovery capability - a flight-termination function, a predefined recovery procedure, or both - has to work across the full flight envelope and be safeguarded against inadvertent activation.
Once in service, the Applicant has to promulgate maintenance schedules and instructions, repair and replacement instructions, troubleshooting information, structural inspection intervals, and a dedicated "Airworthiness Limitations" section listing every mandatory replacement time and inspection interval, kept current for the operational life of the type design.
Organisations
Design, production and maintenance organisations have to hold the facilities, personnel and record-keeping their scope of work needs, operate an auditable Safety Management System and Plan agreed with the Certifying Authority, keep interfaces with other relevant organisations, and run an occurrence-reporting system - though maintenance training organisations are excluded from the interface and reporting conditions specifically. Design and production organisations are also expected to hold AS/EN 9100 certification, or equivalent, with system safety as an explicit objective of the quality policy (ER.3.1.1, UL.61).
What it does not cover
AEP-83 names eleven areas it deliberately leaves out (§2, Introduction): control-station security; protecting the command-and-control link from interference; airspace integration and segregation, including "sense and avoid"; training and licensing of UAS crew and maintenance staff; approval of operating, maintenance and design organisations as such; frequency spectrum allocation; noise, emission and environmental certification; non-safety-critical launch and landing equipment; payload operation itself; carriage or release of weapons or other stores; and sea-basing. A programme still needs those covered some other way.
Who certifies what
AEP-83 is assessed through Type Certification, not third-party accredited certification. A national Certifying Authority reviews the Applicant's evidence against the Essential Requirements and, if satisfied, issues a Military Type Certificate, or equivalent national document, covering the specific UAS type design assessed, its configuration, a statement of compliance, and the issuing agency and date of issue (§2, Introduction). A Restricted Type Certificate is possible where some requirements are not met, negotiated case by case for sparsely populated areas of non-segregated airspace and recorded on the Certificate Data Sheet (§5), and the Certifying Authority may also audit the Applicant's Safety Management System at its own discretion (UL.62). This certifies the aircraft type design reviewed, not an organisation's management system, and no software, ComplyTrain included, can hold or grant it on an organisation's behalf: certification runs entirely through each nation's own Certifying Authority, and AEP-83 names no NATO-level scheme of its own.
Standards it references
STANAG 4703 is the Allied agreement AEP-83 sits under, and a Netherlands reservation ties acquisition scope directly to it. STANAG 4671, the airworthiness code for larger NATO military UAS, is one of the source documents AEP-83 was derived from. STANAG 4670 is named directly for UA Operator training guidance. EN 9100, referenced throughout as AS/EN-9100, is the quality management certification design, production and maintenance organisations are expected to hold.
AEP-83 is published by NATO and listed free of charge in the NATO Standardization Document Database. NATO's documents are not sold by ComplyTrain and we host no copies of them.
How we help
AEP-83 is an operational and technical airworthiness code, not a management system: the structural analysis, the flight-test campaign, the propulsion endurance testing and the System Safety Assessment a Military Type Certificate depends on happen in the design office, on the test range and in the safety-engineering team, not in software. ComplyTrain does not run any of that engineering work, does not assemble the compliance evidence for the Essential Requirements, and does not produce, hold or stand in for the Type Certificate itself.
What it supports is the documentation and organisational trail AEP-83 asks the Applicant's organisation to keep: the procedures and quality records an AS/EN 9100-approved quality system produces, the Safety Management Plan and its agreed milestones, training and competence records for people doing safety-related work, and the audit trail a Certifying Authority might ask to see if it exercises its discretion to audit the Safety Management System. It also gives you a place to hold the "Airworthiness Limitations" instructions, maintenance schedules and occurrence reports the document calls for, so continued-airworthiness obligations don't rely on someone's inbox.
Which tier of certification a given acquisition programme actually needs, and what else STANAG 4703 brings with it, is set by the acquiring nation's Certifying Authority and the contract, not by this page. See the standards explorer for what sits alongside AEP-83, and talk to us about the evidence trail behind it.
Standards it references
- STANAG 4671Background
- EN 9100Background
- STANAG 4670Background
Questions
Is ComplyTrain, or any software, AEP-83 certified?
No. AEP-83 certifies a specific UAS type design, not an organisation, a management system or a piece of software. A national Certifying Authority reviews the design evidence directly and issues a Military Type Certificate, or equivalent national document, for that aircraft type; nothing in the document describes a scheme for certifying anything else.
Does meeting AEP-83 mean my UAS is certified?
Not on its own. Compliance with AEP-83's Essential Requirements is the technical basis an Applicant presents, but the certificate itself only exists once a national Certifying Authority has reviewed that evidence and formally issued a Military Type Certificate or equivalent document. Satisfying the requirements is necessary; it is not the same act as being certified.
What's the difference between AEP-83 and STANAG 4703?
STANAG 4703 is the Allied agreement nations ratify; AEP-83 is the Allied Engineering Publication it covers, and carries the actual technical airworthiness requirements. A nation implements AEP-83 because it has agreed to STANAG 4703, not the other way round.
Can a UAS still be certified if it doesn't meet every requirement?
AEP-83 allows for a Restricted Type Certification, negotiated case by case with the Certifying Authority, typically for operation limited to sparsely populated areas of non-segregated airspace. Any non-compliance or operating restriction has to be approved by the Certifying Authority and recorded on the Certificate Data Sheet, not left undocumented.
Is AEP-83 mandatory?
Only through a route that makes it so. AEP-83 itself does not bind a supplier; a nation ratifies STANAG 4703 and then applies AEP-83 through its own Certifying Authority, typically because an acquisition programme requires it. Whether it applies to a given programme is a question for the contract and the procuring nation's Certifying Authority, not for the document on its own.
