AJP-6
AJP-6 Allied joint doctrine for communication and information systems
NATO joint commanders and staffs planning, resourcing and running communication and information systems for Allied operations
AJP-6 is NATO's Allied Joint doctrine for communication and information systems, giving joint commanders and staffs doctrinal guidance for planning, resourcing and running CIS in support of Allied operations.
- Edition
- B
- Published
- 2024-04
What it is
What AJP-6 is, and who it is written for
AJP-6, Allied Joint Doctrine for Communication and Information Systems, is one of NATO's keystone doctrine publications: it "provides the cornerstone for communication and information systems (CIS) supporting Allied joint operations," in the document's own words. It is written primarily "as guidance for joint NATO commanders and staffs," not for industry, though the doctrine is also described as instructive for coalition operations and as a reference for civilian mission participants. Edition B, Version 1 (April 2024) is the current edition; it is effective upon receipt and supersedes Edition A, Version 1. It is "a keystone publication directly subordinated to AJP-01" (the capstone Allied Joint Doctrine), and sits alongside AJP-2, AJP-4, AJP-5 and, especially, AJP-10 and AJP-3.
How it binds
AJP-6 does not bind a company. It binds through ratification: nations record their agreement to use it in STANAG 2525 - "the agreement of nations to use this publication is recorded in STANAG 2525," as the Letter of Promulgation states. A supplier or contractor meets AJP-6 only when a NATO or coalition tasking, a support contract, or an assignment to a CIS function puts them inside the planning and employment structure the document describes; nothing in the text imposes a requirement on industry directly. A separate NATO document defining "non-NATO entities" (the term this doctrine uses for mission participants outside the Alliance) lists, among others, contractors on operations, exercises and transformational activities - but AJP-6 itself addresses the commands those contractors support, not the contractors.
CIS principles and characteristics
Chapter 1 sets out ten qualities communication and information systems should have to support command and control: capable, interoperable, agile, scalable, service-oriented, autonomous, timely, ready, secure, and resilient. Each carries a working definition. Agility, for example, is the ability to "respond dynamically to changes in scales of effort, operational tempo, posture, and outages," and resilience is tied to business continuity and disaster-recovery procedures "included in exercises as part of readiness" rather than left as a plan on paper.
Information assurance and CIS security
The document names five elements of information assurance - personnel, physical, information, CIS and industrial security - but only defines CIS security, built on the classic triad of confidentiality, integrity and availability, with authentication and non-repudiation as the by-products of combining them. CIS security measures are expected to produce standard log files that get aggregated and correlated to build a consistent, up to date picture of the cyberspace domain. Cryptography is treated as pervasive rather than exceptional: it is "used at all levels (i.e., from strategic to tactical, and in static and deployed) and for mostly all communication services," with key generation, distribution and dissemination named as part of the discipline.
Interoperability, in levels
AJP-6 separates interoperability into three technical aspects - syntactic, structural and semantic - and a four-level scale from Level 0 (not interoperable, forces operating independently) to Level 3 (integrated, common networks, capabilities, procedures and language). It is achieved through technical standards, operational or configuration procedures, and gateways, and the document is candid about a failure mode worth knowing: a manual "swivel chair" workaround, physically re-keying data between systems, can leave interoperability stuck at Level 0 even where the rest of a mission's technology is working fine.
Roles across strategic, operational and tactical command
Chapter 2 assigns responsibility by level. Strategically, the North Atlantic Council sets direction, the Consultation, Command and Control Board coordinates C3 policy, Allied Command Operations conducts operations under SACEUR, and the NATO Communications and Information Agency delivers C3 capability and CIS services under an Agency Supervisory Board. Operationally, the J6 staff leads CIS planning for the joint force commander, supported by the NATO Communication and Information Systems Group and, once deployed, a Deployable CIS Support Group. Tactically, each component commander manages the CIS under their own command and shares responsibility for the interoperability point with whichever formation they connect to.
Planning and employing CIS support
Chapter 3's planning cycle nests inside the wider operational planning process: mission analysis, orientation, the commander's planning guidance, concept development, plan development and plan review, producing a CIS estimate, information exchange requirements and a CIS support plan (SUPPLAN) or equivalent annex. CIS planning "should be based primarily on existing NATO CIS," turning to national or commercial assets only where NATO assets fall short. Chapter 4 then covers how CIS is actually employed: command facilities (static, deployable and mobile, across four communications tiers), exercises treated as full-CIS events, and the four stages of a deployment - pre-deployment, deployment, execution and drawdown - each with its own CIS activity. Annex A maps these stages directly against the planning phases of AJP-5 and the operations stages of AJP-3.
What this doctrine points to
AJP-6 is covered by STANAG 2525, the agreement nations ratify to use it. It is subordinated to AJP-01, nests inside the planning process of AJP-5, aligns with the operations stages of AJP-3, and names AJP-2, AJP-4 and AJP-10 among the keystone documents it relates to. A companion publication, AJP-6.1, was in development at the time of this edition to cover CIS service management and control in more depth. For interoperability and message-format detail it points to STANAG 5524 (NISP), STANAG 5525 (JC3IEDM), STANAG 7149 and APP-11 (the NATO Message Catalogue), and AAP-31 for CIS terminology. It also cites AJP-3.6, AJP-3.3, AJP-3.20 and AJP-10.1 for electronic warfare, air, cyberspace and information-operations interoperability respectively, and STANAG 2521, STANAG 4406, APP-15 and AAP-47 for supporting technical and procedural detail.
What auditors and assessors actually check
Nothing in AJP-6 sets up a certification or audit scheme for an organisation. The one certification process it names is technical, not organisational: "National CIS must comply with NATO standards and undergo a certification process before they can connect to NATO core services, regardless of security domain." That is a system-connection check run by NATO's own technical authority, and passing it is not the same as being "AJP-6 certified" - no such certification exists to hold. The closest thing to an assessment in practice is interoperability testing and validation before deployment, recorded in joining, membership and exit instructions (JMEIs) "for future reference and fault-finding."
How we help
AJP-6 addresses NATO commanders and staffs, not companies, so ComplyTrain's role here is indirect. It matters where an organisation supports a NATO or coalition CIS function - engineering deployable systems, training CIS personnel, or providing planning support under contract - and needs to hold the evidence that it did its part of that work properly. In practice, that looks like documented internal procedures for producing the planning inputs a J6 staff or supported command would ask for, training records showing personnel hold the CIS qualifications the doctrine names as an exercise focus area, and a controlled record of which edition of AJP-6, and which related publications, a team was working to at a given time.
ComplyTrain does not plan, deploy or operate CIS, does not write a CIS support plan, and does not stand in for the J6 staff work this doctrine describes - that work happens in the operations centre and in the field, not in software. The tier of doctrine and standards that actually applies on a given contract is set by the customer and the tasking, not by this page. The standards explorer shows what else sits alongside AJP-6 in the catalogue, and we are glad to talk through how it fits your specific contract.
Standards it references
- AJP-6.1Background
- AJP-01Background
- AJP-3Background
- AJP-5Background
- AAP-47Background
- STANAG 5524Background
- STANAG 5525Background
- STANAG 7149Background
- APP-11Background
- AAP-31Background
- APP-15Background
- AJP-2Background
- AJP-4Background
- AJP-10Background
- AEP-07Background
- STANAG 2521Background
- AJP-10.1Background
- AJP-3.6Background
- STANAG 4406Background
- AJP-3.3Background
- AJP-3.20Background
Questions
Is AJP-6 mandatory?
Only through ratification, not by default. Nations record their agreement to use it in STANAG 2525, and a nation can ratify a STANAG with reservations, so there is no blanket answer. For a supplier or contractor, AJP-6 becomes relevant only when a NATO or coalition contract or tasking says so.
What is the difference between AJP-6 and AJP-6.1?
AJP-6 is the keystone doctrine covering communication and information systems as a whole. AJP-6.1, covering CIS service management and control specifically, was still in development under a Military Committee Joint Standardization Board tasking at the time of this edition, with parts of what it will cover folded into AJP-6 in the meantime.
Can a company be certified to AJP-6?
No. The document names no certification scheme for organisations. The only certification process it mentions is a technical one, for national CIS connecting to NATO core services, run by NATO's own technical authority rather than an accredited certification body.
What edition superseded AJP-6, Edition A?
Edition B, Version 1, published in April 2024, is the current edition. It is effective upon receipt and supersedes Edition A, Version 1, which nations were instructed to destroy under their own document-destruction procedures.
Does AJP-6 cover information security standards like ISO 27001?
No. AJP-6 is military CIS doctrine for planning and running communications and information systems in support of operations. It defines CIS security around confidentiality, integrity and availability, but it does not map onto ISO 27001, NIST or any other organisational information-security control set.
