Start a free trial
Menu

AQAP-2105

AQAP-2105 NATO requirements for quality plans

Suppliers and subcontractors on NATO contracts, preparing the Quality Plan that the GQAR and Acquirer evaluate before work starts

AQAP-2105 sets NATO's contract requirements for a supplier's Quality Plan and how it is prepared, submitted and reviewed through the contract life cycle.

Edition
C
Published
2019-01
Evaluated by
government-surveillance

What it is

A NATO contract deliverable, not a management system

AQAP-2105 sets NATO's requirements for a Quality Plan: the document a supplier produces on a contract to state how it will meet every contract requirement, including whichever AQAP-2310, AQAP-2110 or AQAP-2210 obligations the contract carries. It is covered by STANAG 4107, the NATO agreement nations ratify, and it is intended for use in contracts between an Acquirer and a Supplier, and between a Supplier and its own external providers.

It is worth being clear about what this publication is not. It does not create a quality management system and it sets no new technical requirements of its own. It documents how a supplier's existing management system, built to AQAP-2110 or AQAP-2310, applies to one specific contract, with what resources, processes and responsibilities. A supplier without a working management system has nothing to plan.

When it binds

AQAP-2105 has no independent force. A supplier is bound only when a contract, or a tender leading to one, names it, or names AQAP-2310, AQAP-2110 or AQAP-2210 alongside it. Even the extent of what applies is a contract matter: the publication states that all its requirements apply unless agreed otherwise and documented as part of the contract with the Acquirer. Once a contract does invoke it, the timing is not negotiable in the same way: the Quality Plan has to be prepared and submitted before any contract work starts.

Preparing the plan

Before drafting begins, the supplier reviews the whole contract and identifies risk, to work out what management, technical and other activities need planning. That review, and the risks it turns up, have to be kept as documented information, and any activity outside the supplier's usual business process has to be called out explicitly. How much the plan says is meant to track the contract: its size, the complexity of the product, the techniques involved, the supplier's own experience with similar work, and how much is subcontracted to external providers.

The plan gets reviewed and updated again at five points across the contract: planning; product design and development; process design and development; product and process validation; and ongoing production, use and post-delivery service. It has to link explicitly to the contract and the product, and state its precedence against other contract documents such as the Project Management Plan, the Configuration Management Plan and the Risk Management Plan.

Approval and keeping it current

Once the supplier's own authorised personnel sign the plan off, it goes to the government quality assurance representative (GQAR) and/or the Acquirer for evaluation, before work begins. Either can reject it, or a later revision, for failing to meet the contract or this publication. The supplier has to verify that everything in the plan is actually fit for purpose, available, and implemented by whoever is responsible for it, backed by internal audit records kept for the life of the contract and produced on request. Any change to the plan goes back through the same route, or the supplier's own defined change control procedure, without unnecessary delay, and has to be traceable by identity, approval status, version and issue date.

What the plan has to contain

Chapter 4 is the bulk of the publication, and works through the plan's required content subject by subject: a project description and the scope of the management system as it applies to the contract; how processes are identified, sequenced, monitored and improved, including counterfeit-materiel control for externally supplied products; document control and a document status list kept current at every phase transition; the organisational structure and responsibilities specific to the contract, including the independence of quality personnel; risk management; resourcing and measurement, including the metrological function; operational planning, including a requirement-to-solution compliance matrix; configuration management; design and development controls; dependability, where the contract calls for it; control of the supply chain; control of production and service provision; release of product, including non-conforming product control; improvement and corrective action; and performance evaluation, including customer satisfaction and internal audit.

Where a contract also requires a Software Project Quality Plan under AQAP-2210, the same chapter 4 structure covers the software-specific activities. There is no separate structure for software.

What an auditor looks for, and what the document leaves open

The GQAR or Acquirer looks for the plan's own amendment and review procedure, its internal audit records, and a document status list that is genuinely kept current, not produced for the review itself. What the publication does not specify is just as telling: it does not say who inside the supplier must author or hold the plan, what document format to use, or how much detail counts as enough, beyond being precise and detailed enough to reflect the ongoing contractual activities. Those choices are left to the contract and the supplier's own judgement.

How it fits with the wider AQAP family

AQAP-2105 does not stand alone. It works alongside AQAP-2310 (NATO Quality Assurance Requirements for Aviation, Space and Defence Suppliers), AQAP-2110 (NATO Quality Assurance Requirements for Design, Development and Production), and AQAP-2210 (NATO Supplementary Software Quality Assurance Requirements to AQAP-2110 or AQAP-2310). Its own definitions come from ISO 9000:2015 and from those three AQAPs, and it points to AS 9145 for more detail on the five contract phases it uses to schedule plan reviews.

How we help

Evidencing AQAP-2105 in practice means treating the Quality Plan as a controlled document: version history, a clear approval record, and reviews scheduled against the contract's own life-cycle phases rather than done once and forgotten. It means keeping the document status list current, holding internal audit records for the life of the contract, and being able to produce both the moment the GQAR or Acquirer asks.

ComplyTrain is a modern, auditable system of record for exactly that kind of work: controlled documents with version history and approval workflow, scheduled reviews, an internal audit module that keeps findings and evidence together, and a corrective-action trail that links a finding to what was done about it. Used this way, a supplier's Quality Plan, the procedures it references, and the audit records behind it live in one traceable system instead of scattered files and email threads.

What ComplyTrain does not do: it is not the GQAR, and it does not perform the government quality assurance evaluation. It does not write the plan's technical content, such as design controls or a risk management approach, and it does not decide which of AQAP-2310, AQAP-2110 or AQAP-2210 a given contract actually invokes. The applicable tier, and the standards that come with it, are set by the contract and the customer's quality clause, not by any vendor. The standards explorer shows what sits alongside AQAP-2105 in the catalogue - if you are working out what a specific contract requires, talk to us.

Standards it references

Questions

Is AQAP-2105 mandatory?

Only if a contract says so. AQAP-2105 binds through a contract clause, either directly or through AQAP-2310, AQAP-2110 or AQAP-2210, not by existing on its own. Outside a contract that names it, there is nothing to comply with.

What is the difference between AQAP-2105 and AQAP-2110?

AQAP-2110 sets NATO's quality assurance requirements for design, development and production, the management system a supplier runs. AQAP-2105 is different: it sets the requirements for the Quality Plan, the document that describes how that management system is applied to one specific contract.

Does NATO certify a supplier's Quality Plan under AQAP-2105?

No. The publication describes government quality assurance: the GQAR and/or the Acquirer evaluate the plan against the contract and can reject it, or a revision, if it falls short. That is a customer's own surveillance, not third-party certification, and it carries no certificate.

When does the Quality Plan need to be ready?

Before any work on the contract starts. It then gets reviewed and updated again at five points through the contract: planning, product design and development, process design and development, product and process validation, and ongoing production, use and post-delivery service.

Does AQAP-2105 apply to software contracts?

It can. If a contract requires a Software Project Quality Plan under AQAP-2210, the software-specific activities are covered within the same chapter 4 structure that AQAP-2105 sets out for every other contract. There is no separate software-specific structure.