Start a free trial
Menu

AQAP-2110

AQAP 2110 NATO quality assurance

Defence suppliers delivering on NATO contracts.

AQAP 2110 is NATO’s quality assurance requirement for design, development and production. It builds on ISO 9001, and ComplyTrain gives you the framework to manage the additional contractual requirements it adds.

Edition
D
Published
2016-06
Evaluated by
government-surveillance
THIS DOCUMENT Agreement Holds requirements Organisation certificate Product or design assessed ALLIED QUALITY ASSURANCE PUBLICATION · EDITION D · 2016-06 AQAP-2110 NATO quality assurance requirements for design, development and AQAP-2110 sets NATO's quality management requirements for a supplier's design, development and production work, building on ISO 9001 and applying once a contract names it. AGREEMENT STANAG 4107 The agreement that puts this publication into force. WHERE THE REQUIREMENTS LIVE AQAP-2110 AQAP-2110 sets NATO's quality management requirements for a supplier's design, development and production work, building on ISO 9001 and applying once a contract names it. A supplier meets AQAP-2110 when a contract or national instruction names it, usually via STANAG 4107. Addressed to supplier, acquirer, national authority. Covered by STANAG 4107. The document describes Government Quality Assurance surveillance by the Acquirer or an appointed GQAR against the contract; it names no accredited body and no s. Reaches a supplier when a contract, tender or national instruction names it. Nobody is certified against this document. Nations report ratification; they do not issue a company certificate.

What it is

AQAP-2110 is the NATO Allied Quality Assurance Publication that sets out quality management requirements for a Supplier's design, development and production work. It does not stand alone: Chapter 4 establishes that the Supplier's quality management system has to meet ISO 9001:2015 "as necessary to satisfy the contract requirements," and Chapter 5 adds a further set of NATO-specific requirements on top of that ISO 9001 base. The current edition is Edition D, Version 1, promulgated 24 June 2016. On completion of a transition ending 21 September 2018 it superseded Edition 3 of AQAP-2110, AQAP-2120 and AQAP-2130, consolidating what had been three separate publications into one.

It has no force by itself. Section 1.3 states that the publication "is primarily intended for use in a contract between two or more parties" and that, "when referenced in a contract, this publication shall apply to all of the processes necessary for the Supplier to fulfil the contractual requirements." A Supplier can also adopt it voluntarily and internally without a contract requiring it. At the level of nations, adoption is itself an agreement: the Letter of Promulgation records that "the agreement of nations to use this publication is recorded in STANAG 4107." And where the contract and this publication disagree, the contract wins - AQAP-2110 is a default set of requirements, not an override.

Who it binds, and how

The document defines its own two parties. The Supplier is the "organisation that acts in a contract as the provider of products to the Acquirer." The Acquirer is "Governmental and/or NATO Organisations, that enter into a contractual relationship with a Supplier, defining the product and quality requirements." Where the Acquirer delegates day-to-day oversight, a Government Quality Assurance Representative (GQAR) acts on its behalf. Government Quality Assurance itself is defined as "the process by which the appropriate National Authorities establish confidence that the contractual requirements relating to quality are met" - so behind the GQAR sits a national authority, not a private certification body.

Because it binds through a contract clause, the practical question is never whether AQAP-2110 applies in general, but whether this specific tender or purchase order names it. The Quality Plan required under 5.4.1.1 is due before work starts, at contract initiation, so the point at which it becomes real is earlier than the point at which most Suppliers notice it: by the time it is in a signed contract, the underlying quality management system, the risk process and the configuration management arrangements it assumes need to already exist.

Built on ISO 9001, with NATO-specific additions

Chapter 4 requires the Supplier to have a QMS that satisfies ISO 9001:2015, with the Acquirer and/or GQAR reserving the right to reject that QMS as applied to the contract. Where it is rejected, the Supplier proposes corrective action to an agreed timescale, and contractual penalties can follow, as the contract defines them. Chapter 4.3 then lists a long, specific set of access rights the Supplier and any External Providers must give the GQAR and/or Acquirer: entry to facilities, information on how contract requirements are being met, unrestricted opportunity to evaluate compliance and verify product conformity, assistance for evaluation and testing, accommodation and equipment for performing GQA, and copies of documents including electronic media.

Chapter 5 layers NATO-specific requirements on that base. A management representative for GQA matters must be appointed with real organisational authority, reporting directly to top management. Risk management must start at contract review and run to ISO 31000:2009 principles unless the contract says otherwise, with a Risk Management Plan the GQAR/Acquirer can reject. Infrastructure has to include a segregation area for nonconforming product, and the calibration and measurement system has to meet ISO 10012:2003.

The Quality Plan and the compliance matrix

The Quality Plan is central to how the Supplier demonstrates compliance. It must be submitted before work starts - at a project or contract initiation meeting, or as the contract states - and it must describe the contract-specific quality requirements, the planning of product realisation (resources, verification, validation, monitoring, inspection, testing, acceptance criteria), and a requirement-and-solution compliance matrix that justifies fulfilment of every contractual requirement. That matrix can be annexed after the plan's initial issue, within a timescale agreed with the GQAR/Acquirer, which gives some room on timing without excusing its absence. Content requirements for the plan itself are set out in AQAP-2105, and the GQAR/Acquirer can reject the plan or any revision to it.

Configuration management and externally provided products

Configuration is managed to ACMP-2100 - planning, identification, change control, status accounting and configuration audit - through a Configuration Management Plan that can sit inside another document if appropriate. Where the Supplier sources a critical item, significant work content or an immature technical solution externally, it has to maintain knowledge of that supply chain, flow down the applicable contractual requirements including relevant AQAPs, and run a formal review confirming the flow-down happened. Only the Supplier that placed the order issues contractual instructions to that External Provider - a GQA activity happening at a subcontractor's site does not shift responsibility away from the Supplier.

One definition is worth reading closely: counterfeit materiel is defined to include misrepresentation by "any other means, including failing to disclose information" with the only exception being where it is demonstrated the misrepresentation did not result from dishonesty. That is a broader test than most people expect from the word "counterfeit," and the Supplier is required to run a process for avoiding, detecting, mitigating and dispositioning it.

Traceability, release and nonconforming product

Traceability is not a blanket requirement in this document - it becomes mandatory in one specific circumstance: "where the failure of an item or component could lead to the loss of equipment, performance or life." At release, only acceptable product may go out, a Certificate of Conformity is provided unless otherwise instructed, and the Supplier stays solely responsible for conformance even after delivery. Where the GQAR or Acquirer needs to perform final inspection or formal acceptance, the Supplier owes a minimum of 10 working days' notice, unless the contract sets a different figure.

Nonconforming product has to be identified, controlled and segregated under documented procedures the GQAR/Acquirer can disapprove if they judge the controls inadequate. Concessions to use, release or accept nonconforming product need authorisation unless otherwise agreed, and records of the authorised quantity or expiry date have to be kept - including for nonconforming product that reaches the Supplier from an External Provider.

What the document does not cover

AQAP-2110 does not describe a certification scheme. There is no accredited certification body in it, and no mechanism by which an organisation becomes "AQAP-2110 certified." What it describes throughout is Government Quality Assurance: direct evaluation by the Acquirer or a GQAR against the specific contract, not a third-party audit against a general scheme. It also does not fix a review or expiry date for itself in the text supplied here, and it leaves dependability requirements (covered in more detail by the Allied Dependability Management Publications) to apply only "if stated in the contract."

Put AQAP-2110 on a system that keeps the evidence

Documents, training, risks and evidence in one place, with the trail an auditor asks for.

How we help

ComplyTrain gives you the ISO 9001-structured quality system AQAP 2110 builds on, plus the tools to manage the requirements it adds:

  • The ISO 9001-structured QMS at the base - Quality Management
  • AQAP and contract-specific requirements captured and traced to evidence - Requirements Management
  • Configuration and controlled documents with full revision history and sign-off - Document Control
  • Risk to contract performance managed as a living register - Risk Management
  • Competence and training records for the people on the contract - Training Management

ComplyTrain is not itself AQAP 2110 certified, and does not need to be: it is the system you build and run your own AQAP 2110 program in. The certificate is yours to earn - ComplyTrain is where the evidence for it lives.

AQAP 2110 is the most commonly cited publication in NATO's family of Allied Quality Assurance Publications, but rarely the only one. That overview sets out how 2110, 2131, 2210, 2310 and 2105 relate, and why AQAP 2120 and AQAP 2130 no longer exist.

Standards it references

Request access to this standard

Tell us how you need to work with AQAP-2110 and what you need from it. We will come back to you about what ComplyTrain can do.

Questions

Is AQAP 2110 the same as ISO 9001?

No - but it is built on it. AQAP 2110 requires an ISO 9001-grade quality management system and adds defence-contract-specific requirements on top, such as configuration management and government quality assurance. ComplyTrain gives you the ISO 9001 base and the requirements tracking for the AQAP additions in one system.

Does ComplyTrain make us NATO or AQAP qualified?

No. Qualification is between your organisation and your customer or certification body. ComplyTrain is the system you run your AQAP 2110 quality program in and hold the evidence for - it does not, and cannot, grant a qualification.

How is AQAP 2110 conformance assessed - is it certified?

Not by a certification body in the ISO 9001 sense. AQAP 2110 is a contractual requirement, and conformance is assured through Government Quality Assurance - the customer’s national quality authority verifying your quality system and the specific contract, often at your premises. An ISO 9001 certificate usually evidences the underlying quality system; the AQAP additions are demonstrated to the customer.

What is Government Quality Assurance (GQA)?

GQA is the process by which a customer nation’s quality assurance authority gains confidence that a supplier meets the quality requirements of a defence contract - reviewing the quality system, witnessing key activities, and reserving the right of access to premises and records, including at sub-suppliers. AQAP 2110 sets out the supplier’s duty to support it.

What is the difference between AQAP 2110 and AQAP 2210?

AQAP 2110 covers quality assurance for design, development and production generally; AQAP 2210 adds the requirements specific to software. A supplier delivering software-intensive defence materiel is often held to both, with 2210 applied on top of the 2110 quality system.

Does AQAP-2110 apply to us?

That depends on the contract, not on the standard. AQAP-2110 only takes effect "when referenced in a contract," so whether it applies is a question for the tender or contract in front of you, not something the document answers on its own.

What does the Quality Plan need to cover?

It must describe the contract-specific quality requirements, the planning of product realisation, and a requirement-and-solution compliance matrix justifying how every contractual requirement is met. AQAP-2105 sets out the plan's detailed content requirements.

When is traceability mandatory under AQAP-2110?

Only where the failure of an item or component could lead to the loss of equipment, performance or life. AQAP-2110 does not require traceability as a blanket rule for every product.

Diagram: a six-step path to ISO 9001 certification forms the foundation, with AQAP 2110 built on top of it. AQAP 2110 adds configuration management, contract requirements and supplier flow-down, risk to contract performance, and Government Quality Assurance readiness.
ISO 9001 is the foundation; AQAP 2110 adds the defence-contract controls on top of it.ComplyTrain

Implementation

How to meet AQAP 2110 - a practical path

AQAP 2110 is met by an ISO 9001 system plus the defence-contract requirements, ready for Government Quality Assurance.

  1. Stand up the ISO 9001 base

    AQAP 2110 requires an ISO 9001-grade quality management system. Get that in place - or certified - first; it carries most of the weight.

  2. Add configuration management

    Control the product definition and every change to it, with full traceability and sign-off - the defence-specific discipline AQAP puts front and centre.

  3. Capture the contract requirements

    Take the AQAP and contract-specific requirements as a tracked set, flow them down to sub-suppliers, and trace each to the evidence that meets it.

  4. Be ready for Government Quality Assurance

    Manage risk to contract performance and keep the quality records - and the right of access to them - that a customer’s quality authority will come to verify.

If you need to get there and have no quality function

A standard usually arrives as a contract condition rather than a project anyone planned for, and often at a company with no quality manager. Software is half the answer. Skylen's consultants are the other half, and because they build on ComplyTrain from day one you keep a live system your team owns rather than a binder and a departed consultant.

  • Gap assessment

    A clause-by-clause read of where you stand against the standard your contract cites, turned into a prioritised plan you could act on with us or alone.

    What an assessment covers
  • Guided implementation

    Our consultants build the system with your team - procedures, document control, the records you need to keep and the review cadence - and prepare you for the certification audit.

    How an engagement works
  • Full-service quality function

    We run and maintain the quality system for you, so a small team can reach and hold a standard without hiring a quality manager.

    What full-service means

Manage your AQAP 2110 compliance in one system

See how ComplyTrain maps to your framework on a 30-minute demo, walked through on your own processes. Or start a trial and we will set up a workspace to match what you are working on.

What ComplyTrain does

One system for the whole compliance programme. Start with the module you need most.

  • Forms & Follow-up

    Collect information the same way every time, and decide in advance what happens next.

  • Controls & Assurance

    Know whether your controls are operating, not just whether a policy says they exist.

  • Project Planner

    Turn the compliance work you already know about into a plan with owners, dependencies and dates.

  • Product Compliance

    Know what you can offer, and hold the evidence behind every configuration you offer it in.

  • Reporting & Analytics

    Eight built-in reports across every module, scheduled, delivered, and filed where the evidence lives.

  • Media Monitoring

    The sector news that matters to your organisation - read and rated by AI, and delivered as a scheduled digest in your own language.

  • Grants & Tenders

    AI reads the tender pack and pulls out the requirements, deadlines and rules - then helps you draft the response from your own approved content, with you reviewing every step.

  • Stakeholder/Vendor Management

    One current register of the suppliers and partners you depend on - each risk-assessed, re-assessing itself on schedule, and wired straight into your risk register.

  • Requirements Management

    See every requirement you face - across every standard, plus your own contracts and policies - traced to the documents, evidence and processes that satisfy it.

  • Risk Management

    Identify, score, treat and review your risks in one place - with AI to help anyone run a proper assessment, and a defensible trail behind every decision.

  • Training Management

    Assign training, prove it was understood, and hold the competence records an auditor asks for.

  • Document Control

    Draft compliance documents with AI, keep every version under control, and export them beautifully branded - all in one place.

  • Quality Management

    Audits, corrective actions, processes and approvals in one quality system, organised around ISO 9001.

Latest from ComplyTrain

Other standards in Life-cycle management and quality assurance

  • AACP-02AACP-02 guidelines for mutual provision of contract audits
  • AAP-20AAP-20 NATO programme management framework
  • AAP-48AAP-48 NATO system life cycle processes
  • ACMP-2000ACMP-2000 policy on configuration management
  • ACMP-2009ACMP-2009 guidance on configuration management
  • ACMP-2100ACMP-2100 configuration management contractual requirements

Compliance work does not have to live in documents and spreadsheets

See ComplyTrain on your own processes in a 30-minute demo, with your quality or compliance lead.