Start a free trial
Menu

AQAP-2310

AQAP 2310 quality management for defence suppliers

Aviation, space and defence suppliers bidding for or delivering NATO contracts that require a quality management system the acquirer can accept.

AQAP 2310 sets NATO's quality management requirements for aviation, space and defence suppliers. ComplyTrain ships its requirement tree and a Quality Plan built to AQAP 2105, with the evidence already assembled.

Edition
B
Published
2022-01
Evaluated by
government-surveillance
THIS DOCUMENT Agreement Holds requirements Organisation certificate Product or design assessed ALLIED QUALITY ASSURANCE PUBLICATION · EDITION B · 2022-01 AQAP-2310 NATO quality assurance requirements for aviation, space and defence AQAP-2310 sets NATO's quality management requirements for aviation, space and defence suppliers, building on AS9100/EN9100 and applying once a contract names it. AGREEMENT STANAG 4107 The agreement that puts this publication into force. WHERE THE REQUIREMENTS LIVE AQAP-2310 AQAP-2310 sets NATO's quality management requirements for aviation, space and defence suppliers, building on AS9100/EN9100 and applying once a contract names it. A supplier meets AQAP-2310 when a contract or national instruction names it, usually via STANAG 4107. Addressed to supplier, acquirer, national authority. Covered by STANAG 4107. The document describes Government Quality Assurance surveillance by the Acquirer or an appointed GQAR against the contract; it names no accredited certification. Reaches a supplier when a contract, tender or national instruction names it. Nobody is certified against this document. Nations report ratification; they do not issue a company certificate.

What it is

AQAP-2310 is the NATO Allied Quality Assurance Publication that sets out quality management requirements for a Supplier working in aviation, space or defence. It does not stand alone: Chapter 4 establishes that the Supplier's quality management system has to meet AS9100 Rev D, "or equivalent standard eg EN9100:2018," as necessary to satisfy the contract requirements, and Chapter 5 adds a further set of NATO-specific requirements on top of that base. That makes it the aerospace-sector twin of AQAP-2110: the two publications share almost the same Chapter 5, differing chiefly in which civil standard underpins Chapter 4 - AS9100/EN9100 here, ISO 9001 there.

It has no force by itself. Section 1.3 states that the publication "is primarily intended for use in a contract between two or more parties" and that, "when referenced in a contract, this publication shall apply to all of the processes necessary for the Supplier to fulfil the contractual requirements." A Supplier can also use it internally, without a contract requiring it, to cover the quality aspects of its own management system. Where the contract and this publication disagree, the contract wins - AQAP-2310 is a default set of requirements, not an override. The current edition is Edition B, Version 2, promulgated January 2022; the copy read for this page does not state which earlier edition it superseded, and its national letter of promulgation was left reserved rather than filled in.

Who it binds, and how

The document defines its own two parties. The Supplier is the "organisation that acts in a contract as the provider of products to the Acquirer." The Acquirer is "Governmental and/or NATO Organisations, that enter into a contractual relationship with a Supplier, defining the product and quality requirements." Where the Acquirer delegates day-to-day oversight, a Government Quality Assurance Representative (GQAR) acts on its behalf. Government Quality Assurance itself is defined as "the process by which the appropriate National Authorities establish confidence that the contractual requirements relating to quality are met" - so behind the GQAR sits a national authority, not a private certification body.

Because it binds through a contract clause, the practical question is never whether AQAP-2310 applies in general, but whether this specific tender or purchase order names it. The Quality Plan required under 5.4.1.1 is due before work starts, so the point at which AQAP-2310 becomes real is earlier than the point at which most Suppliers notice it: by the time it is in a signed contract, the underlying AS9100 or EN9100 quality management system, the risk process and the configuration management arrangements it assumes need to already exist. The NATO Standardization Document Database records STANAG 4107 as this publication's cover - the same agreement that carries AQAP-2110.

Built on AS9100/EN9100, with NATO-specific additions

Chapter 4 requires the Supplier to have a QMS that satisfies AS9100 Rev D or the equivalent EN9100:2018, with the Acquirer and/or GQAR reserving the right to reject that QMS as applied to the contract. Where it is rejected, the Supplier proposes corrective action to an agreed timescale, and contractual penalties can follow, as the contract defines them. Chapter 4.3 then lists a long, specific set of access rights the Supplier and any External Providers must give the GQAR and/or Acquirer: entry to facilities, information on how contract requirements are being met, unrestricted opportunity to evaluate compliance and verify product conformity, assistance for evaluation and testing, accommodation and equipment for performing GQA, and copies of documents including electronic media.

Chapter 5 layers NATO-specific requirements on that base. A management representative for GQA matters must be appointed with organisational authority, reporting directly to top management. Risk management must be considered from contract review onward and run to ISO 31000:2009 principles unless the contract says otherwise, with a Risk Management Plan the GQAR/Acquirer can reject. Infrastructure has to include a segregation area for nonconforming product, and the calibration and measurement system has to meet ISO 10012:2003.

The Quality Plan and the compliance matrix

The Quality Plan is central to how the Supplier demonstrates compliance. It must be submitted before work starts - at a project or contract initiation meeting, or as the contract states - and it must describe the contract-specific quality requirements, the planning of product realisation (resources, verification, validation, monitoring, inspection, testing, acceptance criteria), and a requirement-and-solution compliance matrix that justifies fulfilment of every contractual requirement. That matrix can be annexed after the plan's initial issue, within a timescale agreed with the GQAR/Acquirer. Content requirements for the plan itself are set out in AQAP-2105, and the GQAR/Acquirer can reject the plan or any revision to it.

Configuration management and externally provided products

Configuration is managed to ACMP-2100 - planning, identification, change control, status accounting and configuration audit - through a Configuration Management Plan that can sit inside another document if appropriate. Where the Supplier sources a critical item, significant work content or an immature technical solution externally, it has to maintain knowledge of that supply chain, flow down the applicable contractual requirements including relevant AQAPs, and run a formal review confirming the flow-down happened. Only the Supplier that placed the order issues contractual instructions to that External Provider - GQA activity at a subcontractor's site does not shift responsibility away.

The document defines counterfeit materiel to include misrepresentation by "any other means, including failing to disclose information" with the only exception being where it is demonstrated the misrepresentation did not result from dishonesty - a broader test than most people expect from the word "counterfeit." Unlike AQAP-2110, the text supplied here does not attach a separate mandatory avoidance-and-detection process to that definition; it stands as a definition alone.

Traceability, release and nonconforming product

Traceability is not a blanket requirement - it becomes mandatory in one specific circumstance: "where the failure of an item or component could lead to the loss of equipment, performance or life." At release, only acceptable product may go out, a Certificate of Conformity is provided unless otherwise instructed, and the Supplier stays solely responsible for conformance even after delivery. Final inspection or formal acceptance by the GQAR or Acquirer needs a minimum of 10 working days' notice, unless the contract sets a different figure, and the Supplier must still notify quality or safety issues that occur post-delivery.

Nonconforming product has to be identified, controlled and segregated under documented procedures the GQAR/Acquirer can disapprove if the controls look inadequate. Concessions to use, release or accept nonconforming product need authorisation unless otherwise agreed, with records of the authorised quantity or expiry date kept - including for nonconforming product that reaches the Supplier from an External Provider.

What the document does not cover

AQAP-2310 does not describe a certification scheme. There is no accredited certification body in it, and no mechanism by which an organisation becomes "AQAP-2310 certified." What it describes throughout is Government Quality Assurance: direct evaluation by the Acquirer or a GQAR against the specific contract, not a third-party audit against a general scheme. It also leaves dependability requirements, covered in more detail by the Allied Dependability Management Publications, to apply only "if stated in the contract."

Where to get it

AQAP-2310 is published by the NATO Standardization Office and, like all NATO standardization documents, is free of charge. The NATO Standardization Document Database is the authoritative source; we credit NATO for the catalogue and do not sell or host a copy of the document ourselves.

Put AQAP-2310 on a system that keeps the evidence

Documents, training, risks and evidence in one place, with the trail an auditor asks for.

How we help

The AQAP 2310 requirement tree and document set are prebuilt and ship with the standard. The centrepiece is a Quality Plan built to AQAP 2105, the NATO quality plan standard, whose sections are mapped to 16 of the 20 requirements.

  • All 20 requirements by clause, with criticality, and the evidence attached to each - Requirements Management
  • A Quality Plan template built to AQAP 2105, mapped across most of the standard - Document Control
  • Procedures for configuration management, external provider control, internal audit, nonconforming product, root cause analysis and corrective action, and risk management - Document Control
  • A Certificate of Conformity form and a GQA readiness checklist - Document Control
  • GQAR and acquirer complaints handled as tracked customer complaints with root-cause responses - QMS
  • Risk management as a live framework rather than a document, which section 5.6 expects - Risk Management

Because evidence has to be readily available rather than merely retained, the useful property is not storage but connection: each requirement points at the documents and records that satisfy it, and gap analysis over the tree shows what is unevidenced before somebody else finds it.

ComplyTrain holds no certification against AQAP 2310, AS9100 or EN9100. It is the system you build and run your own compliant quality management system in.

AQAP 2310 is one publication in NATO's family of Allied Quality Assurance Publications, and it is often applied alongside others: AQAP 2210 supplements it wherever the deliverable contains software. That overview sets out how the family fits together, and which publication applies to what.

Standards it references

Request access to this standard

Tell us how you need to work with AQAP-2310 and what you need from it. We will come back to you about what ComplyTrain can do.

Questions

Do we need AS9100 certification to satisfy AQAP 2310?

No. Section 4.1 requires a quality management system compliant with AS9100 rev D or EN9100:2018, but it explicitly does not require third-party certification against them. You need a compliant system and the evidence that it operates. Whether you also pursue certification is a commercial decision, not an AQAP 2310 obligation.

Can the acquirer really reject our quality management system?

Yes. Section 4.2 provides for it, and requires objective evidence to be readily available. In practice rejection follows from not being able to show the system working when asked, which is why the difference between evidence that is retained and evidence that is connected to the requirement it satisfies matters so much.

What is AQAP 2105 and why does the Quality Plan matter this much?

AQAP 2105 is the NATO standard for quality plans. In AQAP 2310 the Quality Plan carries most of the weight: its sections map to 16 of the 20 requirements. Getting the plan right is the majority of the work, which is why ComplyTrain ships a template built to AQAP 2105 rather than a blank document.

How are GQAR complaints meant to be handled?

As customer complaints, in the same register, with root cause analysis in the response and corrective actions tracked to closure. Section 5.5 expects the complaint register to include GQAR and acquirer complaints rather than keeping them in a separate channel, and the responses to show root-cause content rather than acknowledgement.

Can AQAP 2310 credit work we have already done for ISO 9001?

Not automatically, and ComplyTrain does not present it as though it does. The standards overlap in substance, and the same evidence often serves both, but cross-standard credit is not something we claim on your behalf. Each requirement is evidenced in its own right.

How much is prebuilt?

The requirement tree and every document template ship with the standard, approved and mapped to the requirements they satisfy. You provide scope, your own content and your evidence. Provisioning is done by our team rather than self-served, so the standard arrives switched on and complete.

Does AQAP-2310 apply to us?

That depends on the contract, not on the standard. AQAP-2310 only takes effect "when referenced in a contract," so whether it applies is a question for the tender or contract in front of you, not something the document answers on its own.

What is the difference between AQAP-2310 and AQAP-2110?

They share almost the same NATO-specific Chapter 5, but Chapter 4 rests on a different base standard: AQAP-2310 requires a QMS meeting AS9100 Rev D or EN9100:2018, the aerospace and defence sector standard, while AQAP-2110 requires plain ISO 9001:2015. Which one a contract names depends on the sector and the Acquirer's requirement.

When is traceability mandatory under AQAP-2310?

Only where the failure of an item or component could lead to the loss of equipment, performance or life. AQAP-2310 does not require traceability as a blanket rule for every product.

The process

Building a quality management system the acquirer will accept

AQAP 2310 is judged on whether your system can show its own operation on demand. These are the four things that decide that.

  1. Scope it and plan it

    Record which requirements apply and why, then build the Quality Plan. Because AQAP 2105 sections map across most of the standard, the plan is the spine of the whole submission rather than one document among many.

  2. Put the supporting procedures in place

    Configuration management, external provider control, internal audit, nonconforming product, corrective action and risk management each have a template built to the requirement they satisfy, approved by a named person in your organisation.

  3. Make the evidence readily available

    Attach approval records, acceptance criteria and external provider approvals to the requirements they evidence. Readily available is the test in section 4.2, and it is a property of how evidence is connected, not of where it is stored.

  4. Close the loop on complaints and findings

    Complaints from the GQAR or the acquirer belong in the same register as customer complaints, with root cause analysis and corrective actions tracked to closure. The shipped NATO CAPA workflow is built for exactly this path.

If you need to get there and have no quality function

A standard usually arrives as a contract condition rather than a project anyone planned for, and often at a company with no quality manager. Software is half the answer. Skylen's consultants are the other half, and because they build on ComplyTrain from day one you keep a live system your team owns rather than a binder and a departed consultant.

  • Gap assessment

    A clause-by-clause read of where you stand against the standard your contract cites, turned into a prioritised plan you could act on with us or alone.

    What an assessment covers
  • Guided implementation

    Our consultants build the system with your team - procedures, document control, the records you need to keep and the review cadence - and prepare you for the certification audit.

    How an engagement works
  • Full-service quality function

    We run and maintain the quality system for you, so a small team can reach and hold a standard without hiring a quality manager.

    What full-service means

Talk to us about AQAP 2310

AQAP 2310 is provisioned by our team, so we start with a conversation rather than a signup form. Book a 30-minute demo to see the requirement tree and the AQAP 2105 Quality Plan on your own contract, or get in touch and we will tell you whether it fits.

What ComplyTrain does

One system for the whole compliance programme. Start with the module you need most.

  • Forms & Follow-up

    Collect information the same way every time, and decide in advance what happens next.

  • Controls & Assurance

    Know whether your controls are operating, not just whether a policy says they exist.

  • Project Planner

    Turn the compliance work you already know about into a plan with owners, dependencies and dates.

  • Product Compliance

    Know what you can offer, and hold the evidence behind every configuration you offer it in.

  • Reporting & Analytics

    Eight built-in reports across every module, scheduled, delivered, and filed where the evidence lives.

  • Media Monitoring

    The sector news that matters to your organisation - read and rated by AI, and delivered as a scheduled digest in your own language.

  • Grants & Tenders

    AI reads the tender pack and pulls out the requirements, deadlines and rules - then helps you draft the response from your own approved content, with you reviewing every step.

  • Stakeholder/Vendor Management

    One current register of the suppliers and partners you depend on - each risk-assessed, re-assessing itself on schedule, and wired straight into your risk register.

  • Requirements Management

    See every requirement you face - across every standard, plus your own contracts and policies - traced to the documents, evidence and processes that satisfy it.

  • Risk Management

    Identify, score, treat and review your risks in one place - with AI to help anyone run a proper assessment, and a defensible trail behind every decision.

  • Training Management

    Assign training, prove it was understood, and hold the competence records an auditor asks for.

  • Document Control

    Draft compliance documents with AI, keep every version under control, and export them beautifully branded - all in one place.

  • Quality Management

    Audits, corrective actions, processes and approvals in one quality system, organised around ISO 9001.

Latest from ComplyTrain

Other standards in Life-cycle management and quality assurance

  • AACP-02AACP-02 guidelines for mutual provision of contract audits
  • AAP-20AAP-20 NATO programme management framework
  • AAP-48AAP-48 NATO system life cycle processes
  • ACMP-2000ACMP-2000 policy on configuration management
  • ACMP-2009ACMP-2009 guidance on configuration management
  • ACMP-2100ACMP-2100 configuration management contractual requirements

Compliance work does not have to live in documents and spreadsheets

See ComplyTrain on your own processes in a 30-minute demo, with your quality or compliance lead.