STANAG 6514
STANAG 6514 and the doctrine for cyberspace operations
Participating NATO nations and the forces and bodies they direct; a defence supplier meets it only where a contract or tender names AJP-3.20
STANAG 6514 is NATO's agreement committing member nations to implement AJP-3.20, the Allied joint doctrine for cyberspace operations; it binds nations, not suppliers, and is not an information security standard.
- Edition
- 1
- Published
- 2020-01-29
What it is
The agreement behind AJP-3.20
STANAG 6514 commits NATO nations to implement AJP-3.20, Edition A, the Allied joint doctrine for cyberspace operations. The agreement itself runs to a handful of pages and holds no doctrine: it states an aim, names the publication, and sets out how a nation ratifies and implements it. Its aim is given as an interoperability requirement, "to provide an overarching framework for cyberspace operations, cyberspace operations principles and planning considerations, roles and responsibilities in joint operations, as well as relationship between cyberspace activities and the joint functions."
A STANAG is the instrument, not the content. Nations ratify it, implement it through their own regulations and procedures, and a company encounters it only because a contract or a tender invokes the doctrine it carries. Ratification and implementation are separate, a nation may ratify with reservations, and so the question "is STANAG 6514 mandatory" has a contractual answer and no general one.
Not an information security standard
This is the point worth stating first on a site like this one. AJP-3.20 is military doctrine: how NATO plans and conducts operations in and through cyberspace as a joint operational domain, alongside land, sea, air and space. It is not a management-system standard, and nothing in this cover or the doctrine it names maps onto ISO 27001, NIST guidance, or any organisational information-security control set. A reader arriving from a security questionnaire or a customer audit will not find that mapping here, because it does not exist.
What implementation means here
The agreement defines its own test. It "is implemented when it becomes part of national regulations, procedures, mechanisms as well as internal education, training, and exercises programs." Allies and NATO bodies "shall provide implementation details through the electronic reporting tool (e-Reporting)"; partner nations "are invited to provide their implementation details through the electronic reporting tool (e-Reporting)" - invited rather than obliged.
Ratification is a separate, earlier step: "Nations are invited to examine their ratification of the STANAG and, if they have not already done so, advise the NSO of their intention regarding its ratification and implementation," with responses recorded in the NATO Standardization Document Database.
Where it sits among the other agreements
STANAG 6514 does not stand alone. Its cover names a long list of sibling Allied joint doctrine publications as related: AJP-2 for intelligence, counter-intelligence and security; AJP-2.4 for signals intelligence; AJP-2.7 for joint intelligence, surveillance and reconnaissance; AJP-3 for the conduct of operations; AJP-3.5 for special operations; AJP-3.6 for electronic warfare; AJP-3.9 for joint targeting; AJP-3.10 for information operations; AJP-3.12 for military engineering; AJP-3.14 for force protection; AJP-3.19 for civil-military cooperation; AJP-3.21 for military police; AJP-5 for the planning of operations; and AJP-6 for communication and information systems. Every one of these is listed as informing context, not a binding requirement. The agreement is also reviewed under AAP-03.
What it does not do
It describes no certification, no notified body, no government quality assurance and no audit of an organisation. Its only stated check is its own periodic review under AAP-03, recorded in the NSDD. Edition 1 was promulgated on 29 January 2020, and the cover states plainly that it supersedes no earlier document.
How we help
There is no compliance obligation here for a company, and no information-security framework to map onto a platform, so we will not invent either. The honest connection is narrower: where a programme expects people to be familiar with the doctrine a contract names, what a customer can ask to see is a documented procedure and a record of who was trained on it.
ComplyTrain holds exactly that: controlled documents, training records against them, and the audit trail those produce over time, for whatever body of standards a programme's quality clause actually requires. It does not write military doctrine, plan cyberspace operations, or carry out technical cyber defence work, and it makes no claim that AJP-3.20's content is implemented in software.
Which documents a contract or a security questionnaire actually invokes, and what comes with them, is set by that contract and the customer's quality clause, never by us. The standards explorer shows what sits alongside this agreement, and we are glad to talk through what a specific tender is asking for.
Standards it references
- STANAG 2190Background
- AJP-2Background
- STANAG 6504Background
- AJP-2.4Background
- STANAG 7107Background
- AJP-2.7Background
- STANAG 2490Background
- AJP-3Background
- STANAG 2523Background
- AJP-3.5Background
- STANAG 6018Background
- AJP-3.6Background
- STANAG 2524Background
- AJP-3.9Background
- STANAG 2518Background
- STANAG 2238Background
- AJP-3.12Background
- STANAG 2528Background
- AJP-3.14Background
- STANAG 2509Background
- AJP-3.19Background
- STANAG 2296Background
- AJP-3.21Background
- STANAG 2526Background
- AJP-5Background
- STANAG 2525Background
- AJP-6Background
- AAP-03Background
Questions
Is STANAG 6514 binding on my company?
No. It binds the nations that ratify it. It reaches a company only when a contract or a tender invokes AJP-3.20 or the doctrine it carries.
Does STANAG 6514 map onto ISO 27001, NIST, or an information security framework?
No. STANAG 6514 covers AJP-3.20, NATO's military doctrine for cyberspace operations, not an information security management standard. Nothing in the cover or the doctrine it names sets out an organisational control set, and no such mapping exists.
What is in STANAG 6514 that is not in AJP-3.20?
Only the machinery: the aim, the agreement to implement, the ratification and implementation steps, and the review clause. The doctrine itself is in AJP-3.20.
Is there a certificate for STANAG 6514?
No. The agreement names no certification body, no assessment body, and no audit of any organisation.
Which edition is current?
Edition 1, promulgated 29 January 2020. The cover states that it supersedes no earlier document.
