ISO 9001
ISO 9001 quality management
ISO 9001 is the international standard for quality management systems. ComplyTrain is structured around its clause structure, so your QMS is audit-ready by design.
Standards · Defence
STANAG, STANREC, Allied Publications, AQAP and the ISO management-system standards, explained in plain words, with a catalogue of all of them. Every entry links to its source, and any of them can be requested in ComplyTrain. The certificate stays yours to earn.
Overview
Five things to know before the detail. Everything on this page hangs off them, and the explorer further down finds your own standards.
A tender, a contract or a customer's quality clause cites a standard by name. That name decides what you must meet, not this page and not us.
Most quality requirements build on ISO 9001. A certified ISO 9001 system is the usual starting point, in defence and outside it.
AQAP 2110 and AQAP 2310 add what a defence contract needs on top of ISO 9001 and EN 9100: the quality plan, configuration management and government quality assurance.
A STANAG is the agreement between NATO nations. The Allied Publication under it holds the technical requirements for what you supply.
Search the catalogue by number or name, browse it by area, or answer five questions. Each entry links to its source and can be requested in ComplyTrain.
Most companies meet these standards the same way: a contract, a tender or a customer's quality clause names one, and the name is all you get. This page explains what the names mean, how the families fit together and where the documents come from. The explorer below then finds the ones that match what you supply.
For most suppliers the first standard a customer asks about is ISO 9001, the international standard for a quality management system. It is one you can be certified against, it is the same in every industry, and almost every quality requirement in defence builds on it. A certified ISO 9001 system is the usual starting point, and a system that already follows it has done most of the work the defence families add to. See ISO 9001 and the ISO management-system standards.
EN 9100, published as AS9100 in the Americas, contains ISO 9001 in full and adds what aviation, space and defence require on top. NATO's own layer is the AQAP series, the Allied Quality Assurance Publications. AQAP 2110 sets the quality requirements for design, development and production and builds on ISO 9001. AQAP 2310 does the same for aviation, space and defence suppliers and builds on EN 9100. AQAP 2131 covers final inspection and test, AQAP 2210 adds software, and AQAP 2105 says what a quality plan must contain. Which AQAP applies to a contract is decided by the acquisition authority, not by the supplier. See AS9100 and EN 9100, the AQAP family, AQAP 2110 and AQAP 2310.
A STANAG is a NATO Standardization Agreement. It records that member nations agree to use a common procedure, or to build to a common specification, so that their forces can work together. A STANAG is a covering document: it carries the agreement and its ratification status, and it names the publication that holds the technical content. STANAG 4107, for example, is the agreement under which nations accept each other's government quality assurance and use the AQAPs at all. Nations ratify and implement STANAGs; a supplier meets one because a contract cites it, or cites the publication under it. About 980 are active today. Read more on how STANAGs work.
An Allied Publication, or AP, is the document with the requirements in it. The letters say what kind it is: AQAP for quality assurance, AEP for engineering, AOP for ordnance and ammunition, ATP for tactical procedures, AMedP for medical, ANEP for naval engineering, AECTP for environmental testing, ACMP for configuration management and ACodP for codification. A STANAG usually covers one publication, sometimes several, and a few publications stand on their own. The catalogue holds around 1,200 of them.
A STANREC is a NATO Standardization Recommendation: the non-binding form, recommended as good practice and not put to nations for ratification. A buyer can still write one into a contract, and then it binds you like any other clause. NATO also does not rewrite what industry already has: some STANAGs adopt an ISO, IEC, EN or SAE standard directly, around sixty in the catalogue, and a contract may then cite either name for the same requirement.
Three requirements reach a defence supplier from outside the NATO families and are in the explorer below for that reason. A NATO agency or a prime asks about information security, which means ISO/IEC 27001 and, for a supplier to the US Department of Defense, NIST SP 800-171; the cybersecurity page covers that world. A medical supplier is asked for ISO 13485, the device quality system; the pharma and medical device page covers it. And AQAP 2110 and ISO 9001 both ask for risk-based thinking, which the risk management page explains. The other ISO management systems, ISO 14001 environmental, ISO 45001 occupational health and safety and ISO 22301 business continuity, reach you through civil customers as often as defence ones.
NATO's Standardization Office lists every active standard in its public database, the NSDD, and serves the document itself for the unclassified ones, roughly a third of them. The rest come through your national standardization authority. ISO standards are bought from ISO or from your national standards body. Every entry in the explorer below links to its source.
Not this page, and not us. The contract and your customer's quality clause name the standards, and for AQAP the acquisition authority decides the level. What the explorer can do is show you the whole map: search it by number or name, browse it by area, or answer five questions about what you supply and see which areas suppliers like you are commonly asked about. Each entry links to its source, to its ComplyTrain page where one exists, and otherwise to a request. ComplyTrain holds a standard as a requirement tree with the evidence against each requirement. The certificate stays yours to earn.
Standards explorer
Search NATO's catalogue of STANAGs, STANRECs and Allied Publications together with the ISO management-system standards, browse it by area, or answer five questions about what you supply.
Nothing matches that. Try a number, a code, or browse by family.
Which standards apply to you is set by your contract and your customer's quality clause, and for AQAP the acquisition authority decides the level. Treat this as a map, not a verdict.
Five questions, pick everything that applies. Nothing is stored.
The areas suppliers like you are commonly asked about, and the standards in each. Confirm against your contract.
Which standards apply to you is set by your contract and your customer's quality clause, and for AQAP the acquisition authority decides the level. Treat this as a map, not a verdict.
Each page sets out what the standard asks of you and how a ComplyTrain workspace is organised around it. The catalogue above holds far more than these, and any entry in it can be requested. Adding a standard to a workspace is usually a matter of days, not a project.
ISO 9001
ISO 9001 is the international standard for quality management systems. ComplyTrain is structured around its clause structure, so your QMS is audit-ready by design.
AS9100 / EN 9100
One aerospace quality standard published under three names: AS9100 in the Americas, EN 9100 in Europe, JISQ 9100 in Asia-Pacific. It contains ISO 9001 in full and adds the requirements aviation, space and defence put on top.
AQAP
AQAP is NATO's family of Allied Quality Assurance Publications: the quality requirements a defence contract can place on a supplier. Which one applies depends on what you deliver and how complex the contract is, and the acquisition authority decides, not you.
AQAP 2110
AQAP 2110 is NATO’s quality assurance requirement for design, development and production. It builds on ISO 9001, and ComplyTrain gives you the framework to manage the additional contractual requirements it adds.
AQAP 2310
AQAP 2310 sets NATO's quality management requirements for aviation, space and defence suppliers. ComplyTrain ships its requirement tree and a Quality Plan built to AQAP 2105, with the evidence already assembled.
AQAP 2131
AQAP 2131 is NATO's quality assurance requirement set for final inspection and test. ComplyTrain ships its full requirement tree and document set, so the Certificate of Conformity you sign is backed by traceable evidence.
AQAP 2210
AQAP 2210 adds NATO's software-specific quality assurance requirements on top of AQAP 2110 or AQAP 2310. It is never cited on its own: it supplements the quality system those publications require, for the part of the deliverable that is software.
STANAG
A STANAG is a NATO Standardization Agreement: the terms under which member nations agree to a common military or technical procedure, or a common piece of equipment. Nations ratify and implement them, and the requirement reaches a supplier through the contract.
STANAG 4586
STANAG 4586 defines the interfaces that let one control station fly another nation's unmanned aircraft. ComplyTrain scopes its 24 requirements to the Level of Interoperability you declare.
STANAG 4609
STANAG 4609 defines how NATO motion imagery and its metadata are formatted for exploitation. ComplyTrain traces its 35 technical requirements to the procedure that implements each one.
STANAG 4671
STANAG 4671 sets the airworthiness requirements for military unmanned aircraft. ComplyTrain ships the USAR requirement tree and certification document set, so the compliance matrix an assessor asks for is the system's normal output.
A standard usually arrives as a contract condition or a regulator's letter rather than a project anyone planned for, and often at a company with no quality manager. Software is half the answer. Skylen's consultants are the other half, and because they build on ComplyTrain from day one you keep a live system your team owns rather than a binder and a departed consultant.
A clause-by-clause read of where you stand against the standard your contract or your regulator cites, turned into a prioritised plan you could act on with us or alone.
What an assessment coversOur consultants build the system with your team - procedures, document control, the records you need to keep and the review cadence - and prepare you for the audit or the inspection.
How an engagement worksWe run and maintain the system for you, so a small team can reach and hold a standard without hiring a quality manager.
What full-service meansNo. A STANAG is an agreement between NATO nations. It binds a nation once that nation has ratified it, and it reaches a company only through a contract that cites the STANAG or the publication under it. Read the clause, not the STANAG number: the clause says which edition and which parts apply.
The STANAG is the agreement; the Allied Publication is the standard. STANAG 4107, for example, is the agreement to accept each other's government quality assurance and to use the AQAPs. AQAP 2110 is one of the publications it covers, and it is AQAP 2110 that a contract asks you to meet. In the explorer a STANAG lists the publications it carries, and a publication names the STANAG it sits under.
Often both. AQAP 2110 builds on ISO 9001 and adds the requirements a defence contract needs on top, such as the quality plan, configuration management and the customer's right to government quality assurance. A quality system that already follows ISO 9001 is the usual starting point. Which AQAP applies, and whether a certified ISO 9001 system is required as well, is set by the acquisition authority in the contract. See AQAP 2110 and ISO 9001.
A NATO Standardization Recommendation: a publication NATO recommends as good practice without asking nations to ratify it. A STANREC has no force on its own, but a buyer can write it into a contract, and a contract clause binds you whatever the document is called.
NATO's public database, the NSDD, lists every active STANAG and Allied Publication and serves the unclassified documents directly. Every NATO entry in the explorer links to its page there, and to the document where NATO serves one. Restricted documents come through your national standardization authority. ISO standards are bought from ISO or your national standards body; the ISO entries link to ISO's catalogue.
No. Certification is issued by an accredited certification body, a licence by your authority, and government quality assurance is exercised by the acquisition authority. ComplyTrain is the system you build, run and evidence your compliance in, and Skylen's consultants can take you through the work. The certificate stays yours to earn.
Yes, and that is what the Request access button on every entry is for. Tell us which standard and where the requirement comes from, and we come back to you on what holding it in your workspace involves, usually within one business day. Adding a standard to a workspace is usually a matter of days, not a project. ComplyTrain holds a standard as a requirement tree with your evidence against each requirement, and the tree is what we build.