STANAG 4368
STANAG 4368 safety design requirements for rocket and missile ignition systems
Government sponsors and their design organisations bringing a new rocket or guided missile motor ignition system through a NATO nation's safety approval process
STANAG 4368 is NATO's ratified agreement setting safety design requirements for rocket and guided missile ignition systems, with each ratifying nation's National Safety Approving Authority certifying individual designs, not a company certificate.
- Edition
- 3
- Published
- 2011-08-01
- Evaluated by
- government-surveillance
What it is
STANAG 4368 is a NATO Standardization Agreement, currently Edition 3, promulgated on 1 August 2011 and unclassified. It sets out the safety design requirements that ignition systems for rocket and guided missile solid propellant motors used in non-nuclear systems must meet. Most STANAGs are thin covers that point to a separate Allied Publication for the actual technical content; this one is not. STANAG 4368 carries its safety design requirements directly in its own text, across a section headed "Details of the Agreement", while still drawing on a set of companion NATO standards for the qualification and testing of the individual components inside the system.
Why the agreement exists
An ignition system that arms or fires when it should not is a hazard to the people around it and to the platform it is fitted to. STANAG 4368 exists so that NATO nations design new rocket and guided missile motor ignition systems to one shared safety baseline rather than each nation working from its own. Nations that ratify the STANAG agree to design ignition systems in accordance with its requirements, and the agreement applies to new developments initiated after ratification, not retrospectively to systems already in service.
Who it addresses
A STANAG binds a nation, not a company, and STANAG 4368 is explicit about the two roles inside a ratifying nation that carry it forward. The National Safety Approving Authority (NSAA) is, in the document's own definition, the national authority responsible for approving service use of an ammunition item or component; each ratifying nation names one, and Annex A lists the authorities for Canada, Denmark, Germany, France, the United Kingdom, Italy, the Netherlands, Norway and the United States. The sponsor is the government entity responsible for the development and/or acquisition of the munition or weapon system, and it is the sponsor who takes a proposed ignition system design to the NSAA for approval. The requirements of the STANAG fall, in practice, on whoever designs the ignition system on the sponsor's behalf.
A nation counts as having implemented STANAG 4368 once it has issued instructions that all future non-nuclear rockets and guided missiles entering service must be designed to it. Until a sponsor's tender or contract invokes the STANAG for a specific programme, it has no direct hold on a supplier.
What it excludes
The agreement states its own boundary plainly. It excludes nuclear weapon systems; flares and signals dispensed by hand; and three further categories of device, agreed case by case with the NSAA as not presenting sufficient hazard to warrant it: certain thrusters and gas generators, rocket-assisted projectiles and rocket-propelled grenades, and pyrotechnic countermeasure devices.
The kinds of requirement it sets
STANAG 4368 works through a numbered sequence of clauses, and each addresses a distinct part of an ignition system's safety case rather than a single design solution:
- Design review and certification. New designs, safety-affecting modifications, and new applications of a previously approved design are presented to the NSAA with supporting evidence, from the outset of development. Where a design does not meet a requirement but the NSAA still judges it safe and suitable for service, the non-compliance and the reasoning behind accepting it are recorded and shared with other NATO nations that justifiably need to see them.
- The system and its components. The ignition system is defined broadly as the aggregate of devices across the munition, the launcher and the launch platform that generate and control the signals which cause the motor to function, and it must include an Ignition Safety Device. The explosives used in it have to be qualified against STANAG 4170, the initiator has to be characterised against STANAG 4560, and components have to demonstrate chemical compatibility consistent with STANAG 4147.
- Safety analyses. A set of safety analyses covers the system's whole life cycle, identifying and controlling hazardous conditions, and extends to any embedded computer, software or programmable logic that contributes to a safety feature - drawing, where electronic logic controls a safety function, on guidance such as AOP-15 and AOP-52.
- Robustness, arming control and fail-safety. The design has to remain safe across the conditions and service environments it will meet, follow a set of principles aimed at preventing unintended or premature arming, and consider fail-safe approaches.
- Numerical safety targets and testing. Separate numerical safety failure-rate targets apply to the ignition system and to the Ignition Safety Device, established by analysis and verified by test so far as practicable. The Ignition Safety Device's own safety and suitability testing follows STANAG 4157, using test procedures described in AOP-20 or an NSAA-approved national equivalent.
- Unexploded ordnance and disposal readiness. The design has to keep the incidence of unexploded ordnance at a level the user and the NSAA accept, and include features that let explosive ordnance disposal personnel handle an accident, an extreme situation or a dud round safely and, where practical, tell whether the system is armed. New or altered designs go to the national EOD research and development authority for technical advice on those aspects, and the STANAG requires assurance that the system cannot be assembled or installed in an armed condition by mistake.
- Other design and documentation requirements. These cover dissipating stored firing energy once it is no longer needed, behaviour after an inadvertent ground impact for tube-launched munitions, designing and documenting the system for quality control, inspection and future maintenance, formal design approval at the outset of development, and electrical connectors designed so they cannot be connected in a way that compromises safety.
This names what each clause covers rather than what it says: the specific thresholds, arming sequences and safety-feature mechanisms are the substance of the design case an NSAA reviews, not something published here.
How a design is evaluated
The NSAA certifies the compliance of an individual ignition system design, not of a company or its management system. The document's own words are that "designs shall be certified by the NSAA for compliance with this STANAG", reviewed from the start of development and again for any safety-affecting change. This is government safety assessment of a specific design case, not a certification scheme: there is no accreditation an organisation joins and no certificate a company keeps on file.
How we help
STANAG 4368 sets safety design requirements directly, and the substantive work - the hazard and failure analyses, the component qualification against the standards it draws on, and the National Safety Approving Authority's review and certification of a design - is engineering and national-authority work, not something a compliance platform performs.
What ComplyTrain gives a sponsor or design organisation is a controlled place to run the process around that engineering: version-controlled design-review submissions and supporting evidence, a record of every safety analysis, test report and NSAA exchange from the start of development through any later safety-affecting change, and training records for staff working the procedure. Where a design departs from a requirement, ComplyTrain holds the documented rationale STANAG 4368 requires a nation to record and share.
ComplyTrain does not run hazard analyses, calculate a safety failure rate, or certify a design - the NSAA does that. In defence, the tier that applies to a given programme and the standards that come with it are set by the contract and the customer's quality clause. Use the standards explorer to see what sits alongside STANAG 4368, or talk to us about the programme you are building evidence for.
Standards it references
- STANAG 4147Binds
- STANAG 4157Binds
- STANAG 4170Binds
- STANAG 4560Binds
- AECTP-250Background
- AEP-04Background
- AOP-15Background
- AOP-07Background
- AOP-20Background
- AOP-52Background
- AOP-43Background
Questions
Is STANAG 4368 mandatory?
Only through ratification and, for a supplier, a contract. STANAG 4368 binds a nation once that nation ratifies it and issues instructions implementing it, and it reaches a supplier because a sponsor's tender or contract invokes it for a new ignition system development, not because the STANAG exists.
Does STANAG 4368 carry a certification a company can hold?
No. The National Safety Approving Authority certifies the compliance of an individual ignition system design, not the company that designs or builds it. There is no accreditation scheme here for an organisation to join, and no certificate for a business to keep on file.
What is the difference between STANAG 4368 and the standards it references?
STANAG 4368 sets the safety design requirements for the ignition system as a whole. The standards it points to, including STANAG 4170, STANAG 4560 and STANAG 4147, qualify or characterise the individual explosives, initiators and components used inside it.
When does STANAG 4368 apply to a design?
It applies to new ignition system developments initiated after a nation ratifies it, not retrospectively to designs already in service. The National Safety Approving Authority is engaged from the start of development, not once a design is finished.
Where can I get STANAG 4368?
From NATO's Standardization Document Database, which lists the catalogue and serves the document free of charge. We do not sell it or host a copy.
