What it is
AQAP-2110 is the NATO Allied Quality Assurance Publication that sets out quality management requirements for a Supplier's design, development and production work. It does not stand alone: Chapter 4 establishes that the Supplier's quality management system has to meet ISO 9001:2015 "as necessary to satisfy the contract requirements," and Chapter 5 adds a further set of NATO-specific requirements on top of that ISO 9001 base. The current edition is Edition D, Version 1, promulgated 24 June 2016. On completion of a transition ending 21 September 2018 it superseded Edition 3 of AQAP-2110, AQAP-2120 and AQAP-2130, consolidating what had been three separate publications into one.
It has no force by itself. Section 1.3 states that the publication "is primarily intended for use in a contract between two or more parties" and that, "when referenced in a contract, this publication shall apply to all of the processes necessary for the Supplier to fulfil the contractual requirements." A Supplier can also adopt it voluntarily and internally without a contract requiring it. At the level of nations, adoption is itself an agreement: the Letter of Promulgation records that "the agreement of nations to use this publication is recorded in STANAG 4107." And where the contract and this publication disagree, the contract wins - AQAP-2110 is a default set of requirements, not an override.
Who it binds, and how
The document defines its own two parties. The Supplier is the "organisation that acts in a contract as the provider of products to the Acquirer." The Acquirer is "Governmental and/or NATO Organisations, that enter into a contractual relationship with a Supplier, defining the product and quality requirements." Where the Acquirer delegates day-to-day oversight, a Government Quality Assurance Representative (GQAR) acts on its behalf. Government Quality Assurance itself is defined as "the process by which the appropriate National Authorities establish confidence that the contractual requirements relating to quality are met" - so behind the GQAR sits a national authority, not a private certification body.
Because it binds through a contract clause, the practical question is never whether AQAP-2110 applies in general, but whether this specific tender or purchase order names it. The Quality Plan required under 5.4.1.1 is due before work starts, at contract initiation, so the point at which it becomes real is earlier than the point at which most Suppliers notice it: by the time it is in a signed contract, the underlying quality management system, the risk process and the configuration management arrangements it assumes need to already exist.
Built on ISO 9001, with NATO-specific additions
Chapter 4 requires the Supplier to have a QMS that satisfies ISO 9001:2015, with the Acquirer and/or GQAR reserving the right to reject that QMS as applied to the contract. Where it is rejected, the Supplier proposes corrective action to an agreed timescale, and contractual penalties can follow, as the contract defines them. Chapter 4.3 then lists a long, specific set of access rights the Supplier and any External Providers must give the GQAR and/or Acquirer: entry to facilities, information on how contract requirements are being met, unrestricted opportunity to evaluate compliance and verify product conformity, assistance for evaluation and testing, accommodation and equipment for performing GQA, and copies of documents including electronic media.
Chapter 5 layers NATO-specific requirements on that base. A management representative for GQA matters must be appointed with real organisational authority, reporting directly to top management. Risk management must start at contract review and run to ISO 31000:2009 principles unless the contract says otherwise, with a Risk Management Plan the GQAR/Acquirer can reject. Infrastructure has to include a segregation area for nonconforming product, and the calibration and measurement system has to meet ISO 10012:2003.
The Quality Plan and the compliance matrix
The Quality Plan is central to how the Supplier demonstrates compliance. It must be submitted before work starts - at a project or contract initiation meeting, or as the contract states - and it must describe the contract-specific quality requirements, the planning of product realisation (resources, verification, validation, monitoring, inspection, testing, acceptance criteria), and a requirement-and-solution compliance matrix that justifies fulfilment of every contractual requirement. That matrix can be annexed after the plan's initial issue, within a timescale agreed with the GQAR/Acquirer, which gives some room on timing without excusing its absence. Content requirements for the plan itself are set out in AQAP-2105, and the GQAR/Acquirer can reject the plan or any revision to it.
Configuration management and externally provided products
Configuration is managed to ACMP-2100 - planning, identification, change control, status accounting and configuration audit - through a Configuration Management Plan that can sit inside another document if appropriate. Where the Supplier sources a critical item, significant work content or an immature technical solution externally, it has to maintain knowledge of that supply chain, flow down the applicable contractual requirements including relevant AQAPs, and run a formal review confirming the flow-down happened. Only the Supplier that placed the order issues contractual instructions to that External Provider - a GQA activity happening at a subcontractor's site does not shift responsibility away from the Supplier.
One definition is worth reading closely: counterfeit materiel is defined to include misrepresentation by "any other means, including failing to disclose information" with the only exception being where it is demonstrated the misrepresentation did not result from dishonesty. That is a broader test than most people expect from the word "counterfeit," and the Supplier is required to run a process for avoiding, detecting, mitigating and dispositioning it.
Traceability, release and nonconforming product
Traceability is not a blanket requirement in this document - it becomes mandatory in one specific circumstance: "where the failure of an item or component could lead to the loss of equipment, performance or life." At release, only acceptable product may go out, a Certificate of Conformity is provided unless otherwise instructed, and the Supplier stays solely responsible for conformance even after delivery. Where the GQAR or Acquirer needs to perform final inspection or formal acceptance, the Supplier owes a minimum of 10 working days' notice, unless the contract sets a different figure.
Nonconforming product has to be identified, controlled and segregated under documented procedures the GQAR/Acquirer can disapprove if they judge the controls inadequate. Concessions to use, release or accept nonconforming product need authorisation unless otherwise agreed, and records of the authorised quantity or expiry date have to be kept - including for nonconforming product that reaches the Supplier from an External Provider.
What the document does not cover
AQAP-2110 does not describe a certification scheme. There is no accredited certification body in it, and no mechanism by which an organisation becomes "AQAP-2110 certified." What it describes throughout is Government Quality Assurance: direct evaluation by the Acquirer or a GQAR against the specific contract, not a third-party audit against a general scheme. It also does not fix a review or expiry date for itself in the text supplied here, and it leaves dependability requirements (covered in more detail by the Allied Dependability Management Publications) to apply only "if stated in the contract."