Start a free trial
Menu

STANAG 5524

STANAG 5524 adopted non-NATO digital standards for the NISP

Participating Allies and NATO bodies that ratify and implement NATO's catalogue of adopted non-NATO digital standards (the NISP)

STANAG 5524 is NATO's agreement committing Allied nations to adopt a catalogue of non-NATO digital standards (the NISP) for systems that interface with NATO; it binds nations, not suppliers, directly.

Edition
6
Published
2026-08-26

What it is

STANAG 5524 is a NATO Standardization Agreement, currently Edition 6, promulgated 26 August 2026. It is not itself a technical specification. It is the agreement by which NATO's participating Allies agree to adopt a defined set of non-NATO digital standards into NATO's own catalogue of interoperability standards and profiles, the NISP. Read on its own, STANAG 5524 requires almost nothing of a supplier directly: its obligations run to nations, and it reaches a contractor only once a nation has implemented it and a specific contract or tender invokes one of the standards its annex adopts.

Who it binds, and how

STANAG 5524 is explicit that ratification and implementation are national acts. The letter of promulgation states that the enclosed agreement "has been ratified by Allies, as reflected in the NATO Standardization Documents Database (NSDD)". Allies that have not yet reported their position are invited to "examine their ratification of the STANAG and, if they have not already done so, advise the NSO of their intention regarding its ratification and implementation." Implementation is a further, separate act: the STANAG "is implemented by a nation when it has issued instructions that all relevant future systems, which interface to NATO and other national systems when engaged in NATO operations, will conform to the adopted standards in this STANAG in accordance with the containing profiles detailed in the NISP." So "is STANAG 5524 mandatory" has no single answer: it depends on whether a nation has ratified and implemented it, and, for a supplier, on whether a specific contract or tender then invokes one of the standards the annex adopts. The agreement is "effective upon receipt for use by the participating Allies and NATO bodies" once that has happened, and partner nations are separately invited to report their implementation the same way.

Why the agreement exists: C3 interoperability

The stated aim is "to respond to the following interoperability requirements." The STANAG defines what it calls C3 Interoperability as "the ability of two or more entities to share and exchange, data and information so that those entities can operate coherently, effectively and efficiently together to achieve Alliance objectives." It adds that "C3 Interoperability addresses all interoperability dimensions technical, procedural and human simultaneously." To achieve it, the document says, "both NATO and non-NATO digital technology standards and profiles must be implemented." The Digital Policy Committee publishes the NISP itself, "prescribing the necessary standards and profiles in order to achieve C3 interoperability including development and operation of communication and information systems (CIS)." As the document puts it, "Participating nations are required to use the NISP for developing capabilities that support NATO's missions (i.e. NATO-led operations, projects, programs, contracts and other related tasks)." STANAG 5524 and its annex are where the non-NATO half of that catalogue lives.

What the annex actually contains

Annex A, "the Adopted Non-NATO Digital Standards", current to "NISP VERSION 17", is organised alphabetically by publishing organisation - close to fifty of them, from the 3rd Generation Partnership Project (3GPP) through the XMPP Standards Foundation - and, within each, by the standard's own short code. Each entry gives a title, usually a version or edition, and, where one exists, an external link to the publisher; the annex supplies no requirement text, rationale or profile detail of its own beyond that citation.

The range gives a sense of what counts as a digital technology standard here: mobile and mission-critical communications specifications from 3GPP, including MCPTT and 5G system architecture; IETF RFCs covering everything from TLS and DNSSEC to HTTP and OAuth; ISO/IEC document and media formats such as PDF, JPEG and Office Open XML; W3C web and XML security specifications; OASIS web-services and threat-intelligence formats, including SAML and STIX; geospatial standards from the Defence Geospatial Information Working Group (DGIWG) and the Open Geospatial Consortium; secure-voice signalling specifications published through the CIS3 C&I Partnership; and simulation-interoperability standards from SISO. Running to several hundred entries across close to fifty organisations, the annex is not something a page can usefully reproduce; our standards explorer is where to check whether we hold a specific one individually.

A reader working from a code alone should check the version or edition against the specific annex entry: several codes appear more than once with different version numbers or links attached - two IEEE 802.3-2018 entries with different external links, three versions of XMPP's XEP-0004, and two differently-versioned TMF621 entries among them - and the document does not say which supersedes which within a given NISP baseline.

Editions, supersession and reporting

This edition, Edition 6, dated 26 August 2026, "supersedes the following document: STANAG 5524, Edition 5 dated 8 January 2025", a turnover that reflects how often the civil and industry standards it adopts move, more than any change to the agreement's own machinery. MC 0593, Minimum Level of Command and Control (C2) Service Capabilities in Support of Combined Joint NATO-led Operations, appears under the heading Other Related Documents rather than as part of the agreement itself; it is outside our catalogue at the time of writing, so it is named here without a link. National ratification and implementation responses go through NATO's own channels: "National responses are recorded in the NATO Standardization Documents Database (NSDD)." "Allies shall provide ratification details through the electronic reporting tool (e-Reporting)." Separately, "Allies and NATO bodies shall provide implementation details through the electronic reporting tool (e-Reporting)." Partner nations are invited to report theirs the same way. The NATO Effective Date (NED) field for this STANAG is marked "Not applicable."

What it does not cover

STANAG 5524 names no test method, no severity level and no assessment scheme of its own, because it is a cover agreement rather than a technical or quality specification, and it does not reproduce the content of the standards it adopts - each is obtained from its own publisher, on that publisher's own terms. Its only stated check is that "This STANAG is to be reviewed in accordance with AAP-03. The result of the review is to be recorded within the NSDD." That is a periodic review of the agreement's own currency, not an audit of any organisation, system or product. Whatever evaluation a specific system undergoes against the individual standards the annex adopts - an interoperability test event, a conformance statement, a NISP profile assessment - belongs to the NISP profiles and whatever process a nation or a contract puts in place, not to STANAG 5524 itself.

How we help

STANAG 5524 adopts standards; it does not itself specify anything a supplier builds to, and it obliges nations rather than organisations. The actual engineering work - implementing TLS 1.3, following the right PDF/A profile for long-term document preservation, building to a DGIWG geospatial web service, or whatever else a given NISP profile calls for - is systems and software engineering, driven by the profile and the contract, not something a compliance platform performs on a customer's behalf.

Where ComplyTrain fits is the evidence trail behind that engineering work: a documented record of which standards and versions a given system was built against, controlled design and interface-control procedures, training records for the engineers implementing them, and a corrective-action trail when an interoperability test finds a gap. ComplyTrain gives an organisation a place to hold that as controlled documentation, track competence against it, and keep the audit trail a customer's quality assurance representative or an interoperability test authority will ask to see.

ComplyTrain does not implement any of the several hundred standards the annex adopts, run an interoperability test event, or decide which NISP profile a given capability needs. Which of those standards apply to a specific programme is set by the contract and the customer's quality clause, not by this page - our standards explorer shows what else sits alongside STANAG 5524, and we are glad to talk through what a specific programme actually calls for.

Questions

Is STANAG 5524 mandatory?

Not on its own. A STANAG binds a nation once that nation has ratified and implemented it, and it reaches a supplier only when a contract or tender invokes one of the standards its annex adopts. Whether it applies to a given programme is a question for the contract, not for this page.

What is Annex A of STANAG 5524?

Annex A is "the Adopted Non-NATO Digital Standards", a list running to several hundred standards and versions from close to fifty organisations, current to NISP Version 17. It gives each standard's title, usually a version, and, where one exists, a link to its publisher, and nothing more.

Can an organisation be certified to STANAG 5524?

No. STANAG 5524 describes no certification or accreditation scheme, for the agreement or for the standards its annex adopts. Its only stated check is a periodic review of the agreement's own currency under AAP-03. NATO does not certify a nation, an organisation or a system against a STANAG.

What edition of STANAG 5524 is current?

Edition 6, promulgated 26 August 2026, which supersedes Edition 5 of 8 January 2025.

What is the NISP?

The NISP, NATO Interoperability Standards and Profiles, is the Digital Policy Committee's comprehensive catalogue of the standards and profiles needed to achieve C3 interoperability, including the development and operation of communication and information systems. STANAG 5524's Annex A holds the non-NATO digital standards adopted into that catalogue, current to NISP Version 17.

Does STANAG 5524 cover NATO's own standards too?

No. Annex A is explicitly the Adopted Non-NATO Digital Standards: standards published by outside bodies such as 3GPP, IETF, ISO/IEC, ITU, W3C, OASIS and the Open Geospatial Consortium, which NATO has adopted into the NISP. This document does not describe a parallel STANAG for NATO-authored standards.