Back to Frameworks

NATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production

International (NATO — 31 member nations)
vEdition E (2016)
8 domains
8 controls

NATO Allied Quality Assurance Publication AQAP 2110 (Edition E, 2016) establishes quality assurance requirements for NATO defence procurement. AQAP 2110 covers design, development, and production and is referenced in NATO contracts. It supplements ISO 9001 with additional defence-specific requirements including configuration management, first article inspection, and government quality assurance. Used by NATO member nations (31 countries) for procurement from defence industry. Complementary publications include AQAP 2210 (software quality), AQAP 2310 (inspection), and AQAP 2131 (production only).

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (8)

Audit and Improvement

1 controls
Controls in the Audit and Improvement domain of NATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production1 controls
CodeTitle
AQAP2110-8Internal Audit, Management Review, Corrective Action, CofC, and Continual Improvement

Configuration Management

1 controls
Controls in the Configuration Management domain of NATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production1 controls
CodeTitle
AQAP2110-4Configuration Management and Change Control

Design and Development

1 controls
Controls in the Design and Development domain of NATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production1 controls
CodeTitle
AQAP2110-3Design and Development Control - NATO plus ISO 13485 Cross-Walk

Government Surveillance

1 controls
Controls in the Government Surveillance domain of NATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production1 controls
CodeTitle
AQAP2110-2Government Quality Assurance Representative (GQAR) Authority and Access

Production and Inspection

1 controls
Controls in the Production and Inspection domain of NATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production1 controls
CodeTitle
AQAP2110-7Production, Special Processes, Inspection, Testing, and Records

Quality Management System

1 controls
Controls in the Quality Management System domain of NATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production1 controls
CodeTitle
AQAP2110-1Quality Management System Aligned to ISO 9001 plus NATO Supplementary Requirements

Risk Management

1 controls
Controls in the Risk Management domain of NATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production1 controls
CodeTitle
AQAP2110-5Risk and Opportunity Management

Supply Chain Control

1 controls
Controls in the Supply Chain Control domain of NATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production1 controls
CodeTitle
AQAP2110-6Subcontractor Supply Chain Control plus Counterfeit Material Prevention

Your Compliance Coverage

If you comply with NATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production, you already cover:

Maps to 65 other frameworks

8 total controls
ICH Q10 - Pharmaceutical Quality System
6 source controls mapped|4 target controls covered
75%
ICAO Annex 17 - Aviation Security (AVSEC)
5 source controls mapped|2 target controls covered
63%
IATF 16949:2016 - Quality Management System for Automotive Production
5 source controls mapped|3 target controls covered
63%
GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6
5 source controls mapped|1 target controls covered
63%
German Supply Chain Due Diligence Act (LkSG)
5 source controls mapped|2 target controls covered
63%
FDA Quality Management System Regulation (QMSR)
5 source controls mapped|3 target controls covered
63%
BRCGS Global Standard for Food Safety Issue 9
5 source controls mapped|3 target controls covered
63%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
5 source controls mapped|5 target controls covered
63%
IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2)
4 source controls mapped|3 target controls covered
50%
OWASP Top 10:2025
4 source controls mapped|2 target controls covered
50%
API 1164
4 source controls mapped|5 target controls covered
50%
IRM Enterprise Risk Management Framework (Institute of Risk Management)
4 source controls mapped|1 target controls covered
50%
IEEE 1686
4 source controls mapped|4 target controls covered
50%
GAMP 5 - Good Automated Manufacturing Practice
4 source controls mapped|2 target controls covered
50%
FedRAMP Rev 5
4 source controls mapped|3 target controls covered
50%
Aged Care Quality Standards (Australia)
3 source controls mapped|4 target controls covered
38%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
3 source controls mapped|1 target controls covered
38%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
3 source controls mapped|1 target controls covered
38%
Authorised Economic Operator (AEO) Programmes - Global Standards
3 source controls mapped|2 target controls covered
38%
38%
ISO/IEC 27011:2024
3 source controls mapped|1 target controls covered
38%
Modern Slavery Act 2018 (Australia)
3 source controls mapped|2 target controls covered
38%
GS1 Global Standards - Supply Chain Traceability and Data Security
3 source controls mapped|2 target controls covered
38%
French Sapin II Law (Law No. 2016-1691)
3 source controls mapped|1 target controls covered
38%
Automotive SPICE (ASPICE) v4.0 - Process Assessment Model
3 source controls mapped|1 target controls covered
38%
ISO/IEC 27010:2015
3 source controls mapped|1 target controls covered
38%
MTCS (Singapore)
3 source controls mapped|1 target controls covered
38%
HKMA Cyber Resilience Assessment Framework (C-RAF)
3 source controls mapped|2 target controls covered
38%
SWIFT CSCF
2 source controls mapped|2 target controls covered
25%
ITAR - International Traffic in Arms Regulations
2 source controls mapped|1 target controls covered
25%
25%
ICH E6(R3) - Good Clinical Practice
2 source controls mapped|2 target controls covered
25%
ISO/IEC 27014:2020
2 source controls mapped|1 target controls covered
25%
Monetary Authority of Singapore Technology Risk Management Guidelines
2 source controls mapped|3 target controls covered
25%
HKMA SPM
2 source controls mapped|2 target controls covered
25%
GLBA
2 source controls mapped|1 target controls covered
25%
FTC GLBA Safeguards Rule (16 CFR Part 314)
2 source controls mapped|2 target controls covered
25%
ISMAP (Japan)
2 source controls mapped|2 target controls covered
25%
Ghana Cybersecurity Act
2 source controls mapped|1 target controls covered
25%
FISMA
2 source controls mapped|2 target controls covered
25%
ISO/IEC 27400:2022
2 source controls mapped|2 target controls covered
25%
Florida Digital Bill of Rights (FDBR)
2 source controls mapped|2 target controls covered
25%
ISO/IEC 38500:2024 - Governance of IT
1 source controls mapped|1 target controls covered
13%
Japan AI Guidelines
1 source controls mapped|1 target controls covered
13%
ITU-T X.805 - Security Architecture for End-to-End Communications
1 source controls mapped|1 target controls covered
13%
India CERT-In Cyber Security Directions 2022
1 source controls mapped|1 target controls covered
13%
IEEE 7000
1 source controls mapped|1 target controls covered
13%
ASIS SPC.1-2009 - Organizational Resilience Standard
1 source controls mapped|3 target controls covered
13%
IEC 62351 - Power Systems Communication Security
1 source controls mapped|2 target controls covered
13%
ISO/IEC 27031:2011
1 source controls mapped|2 target controls covered
13%
ISO/IEC 27007:2020
1 source controls mapped|1 target controls covered
13%
ISO 27002:2022
1 source controls mapped|1 target controls covered
13%
OWASP API Security Top 10 - 2023
1 source controls mapped|1 target controls covered
13%
TEFCA - Trusted Exchange Framework and Common Agreement
1 source controls mapped|2 target controls covered
13%
Regulation on the European Health Data Space (EHDS)
1 source controls mapped|3 target controls covered
13%
NAIC Insurance Data Security Model Law (MDL-668)
1 source controls mapped|1 target controls covered
13%
MDS2 (Medical Device)
1 source controls mapped|3 target controls covered
13%
COSO Internal Control - Integrated Framework (2013)
1 source controls mapped|2 target controls covered
13%
IEC 60601-1 - Medical Electrical Equipment Safety
1 source controls mapped|1 target controls covered
13%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
1 source controls mapped|1 target controls covered
13%
ISO/IEC 27006:2024
1 source controls mapped|1 target controls covered
13%
Japan FSA Cybersecurity Guidelines for Financial Institutions
1 source controls mapped|1 target controls covered
13%

Frequently Asked Questions

What is NATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production?

NATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production is a compliance framework from International (NATO — 31 member nations) with 8 domains and 8 controls. NATO Allied Quality Assurance Publication AQAP 2110 (Edition E, 2016) establishes quality assurance requirements for NATO defence procurement. AQAP 2110 covers design, development, and production and is referenced in NATO contracts. It supplements ISO 9001 with additional defence-specific requirements including configuration management, first article inspection, and government quality assurance. Used by NATO member nations (31 countries) for procurement from defence industry. Complementary publications include AQAP 2210 (software quality), AQAP 2310 (inspection), and AQAP 2131 (production only). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does NATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production have?

NATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production has 8 controls organised across 8 domains. The largest domains are Audit and Improvement (1 controls), Configuration Management (1 controls), Design and Development (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does NATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production map to?

NATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production maps to 65 other compliance frameworks. The top mapping partners are ICH Q10 - Pharmaceutical Quality System (75% coverage), ICAO Annex 17 - Aviation Security (AVSEC) (63% coverage), IATF 16949:2016 - Quality Management System for Automotive Production (63% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with NATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production compliance?

Start your NATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 8 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required