Short answer: what is the difference between AQAP 2110 and ISO 9001
AQAP 2110 vs ISO 9001 isn't an either-or choice — it's a question of layers. ISO 9001:2015 is the baseline international quality management system standard that works in any industry, from a coffee shop to a car plant. AQAP 2110 is NATO's defense-specific overlay on top of ISO 9001, adding defense requirements: configuration management, batch traceability, contractor control, evidence base for customer audits.
The core conclusion the Ekontrol team repeats on every first call with a defense manufacturer: AQAP 2110 doesn't replace ISO 9001 — it complements it. All ISO 9001:2015 requirements are incorporated into AQAP 2110 in full, plus defense blocks on top. So the correct question isn't "which one to choose," but "how to build a single system that covers both standards." In practice this saves 20-30% of the implementation budget and 4-6 weeks of calendar time.
Around 70-80% of documents are shared: quality policy, organizational context, objectives, risk management, internal audits, management review. Defense add-ons are a separate layer of modules that overlay the ready ISO 9001 base.
Quick comparison in one sentence
ISO 9001 is the universal quality system foundation for any industry; AQAP 2110 is NATO's defense overlay that adds 8 specific blocks (configuration management, traceability, GQAR oversight, evidence base for customer audits) on top of the same ISO 9001 base. That's why integrated certification of both standards costs 20-30% less than separate ones and takes 4-6 weeks less time.
What each standard is — the foundation for comparison
Before comparing, you need to nail down what you're comparing. In back-to-back calls with defense manufacturers it turns out half the team understands "ISO 9001" as "a piece of paper for tenders" and "AQAP 2110" as "something military." That misunderstanding costs money at later stages.
ISO 9001:2015 is the international quality management system standard issued by ISO (International Organization for Standardization, Geneva) in 2015. According to the ISO Survey, over 1.1 million ISO 9001 certificates have been issued worldwide in 178 countries. The standard is voluntary, but de facto required for serious B2B contracts and government tenders in practically any industry. Its structure follows the 10-clause Annex SL model (HLS, High Level Structure) that ISO uses for all its management system standards. The details and implementation logic are in our complete ISO 9001 guide.
AQAP 2110 Edition D Version 1 is a publication from the NATO Standardization Office (NSO, Brussels), in force since 2016 with no changes as of 2026. AQAP stands for Allied Quality Assurance Publication. Unlike ISO 9001, AQAP 2110 isn't a standalone standard — it's a defense overlay that incorporates all ISO 9001:2015 requirements and adds 8 blocks of specific requirements for NATO defense contracts. It's issued within STANAG 4107, the agreement on mutual recognition of government quality inspections between Alliance countries. For a deeper dive, see the complete AQAP 2110 guide.
The key difference is in the nature of the standards: ISO 9001 is a voluntary general management tool, AQAP 2110 is a contractual defense-sector requirement. You implement ISO 9001 because you've decided to step up your management quality and gain a market edge. You implement AQAP 2110 because without it you won't be admitted to an NSPA tender, a Bundeswehr contract, or a serial DOT contract. That difference shapes priorities, budget, and project tempo.
8 key differences between AQAP 2110 and ISO 9001
Let's go through the eight blocks where AQAP 2110 goes beyond baseline ISO 9001. This isn't an exhaustive list (there are more minor ones), but these eight tend to drive the toughest conversations with auditors and the most painful nonconformities in companies that underestimated the defense specifics.
1. Scope. ISO 9001 is universal — it works for a chocolate maker and a medical device developer alike. AQAP 2110 is defense-only: the standard explicitly assumes the context of a defense contract, regulatory restrictions (ITAR/EAR), and collaboration with a government military customer. AQAP 2110 is pointless in civilian business; ISO 9001 alone is insufficient in defense.
2. Configuration management. This is the most critical and most underestimated difference. ISO 9001:2015 doesn't explicitly require configuration management — the word "configuration" appears only in passing. AQAP 2110 requires a full Configuration Management cycle per the ACMP-2100 model (NATO Configuration Management Policy): configuration identification, change control, status accounting, configuration audit. Every microchip swap, every firmware change is formally recorded and approved by the customer. It's a separate discipline you need to build from scratch if you didn't have it.
3. Product traceability. ISO 9001 clause 8.5.2 says "when traceability is a requirement — the organization shall ensure it." So it's optional, depending on context. AQAP 2110 makes traceability mandatory for defense products: serial numbers, lot tracking, integration with suppliers, ability to trace both ways — from raw material to airframe number and back. For ammunition makers or UAV component manufacturers this means a real ERP or PLM system, not Excel records.
4. Contractor control. ISO 9001 says "evaluate suppliers against defined criteria" — no detail. AQAP 2110 spells it out: criteria must account for defense specifics, critical-component suppliers must themselves have sufficient quality control, evaluations are renewed at set intervals, there's a clear disqualification mechanism. In practice this means broader supplier audits and often cascading AQAP requirements down the supply chain.
5. Evidence base and documentation. ISO 9001 says "the organization shall maintain documented information" — minimally. AQAP 2110 adds an evidence layer for the government customer: records must be ready for GQAR (Government Quality Assurance Representative) inspection, retention periods are longer, version control is stricter, audit trail is mandatory. At a civilian ISO 9001 audit the auditor accepts "we have a process"; at an AQAP audit it's "show me records for the past 12 months."
6. Customer inspections. ISO 9001 doesn't anticipate customer inspections as part of the system. AQAP 2110 is explicitly designed around regular customer audits — from MoD, GQAR, prime contractors. So the system is designed from day one to withstand a third-party inspector: clear control points, ready document packages, assigned owners for each process. Details are in our piece on the MoD customer audit.
7. Certification body. ISO 9001 is issued by any accredited body (CB) within IAF MLA — for Ukraine that means NAAU-accredited bodies or foreign CBs. AQAP 2110 needs a body whose accreditation is recognized by NATO MoDs. Not every Ukrainian CB has that recognition; for defense contracts it's safer to work with Bureau Veritas, TÜV NORD, DNV, BSI, or SGS — their certificates are accepted by NSPA and national MoDs without further questions.
8. Certificate duration and contractual hardness. Formally they're similar — both are issued for 3 years with annual surveillance audits. But the contractual requirement makes AQAP harder in practice: a nonconformity at a surveillance audit can lead to suspension of deliveries under a specific contract, not just an NCR closure in the next cycle. Losing ISO 9001 means losing a piece of paper; losing AQAP 2110 means losing a contract.
A short summary is in the table below.
| Aspect | ISO 9001 | AQAP 2110 | What it means in practice |
|---|---|---|---|
| Scope | Any industry | NATO defense contracts only | For defense ISO 9001 is the minimum, AQAP 2110 is the tender entry ticket |
| Configuration management | Not explicitly required | Mandatory, per ACMP-2100 | Separate discipline — build from scratch, ~2-3 months implementation |
| Product traceability | Optional (8.5.2) | Mandatory, both directions | Needs ERP or PLM, not Excel — investment €5-25k |
| Contractor control | General supplier evaluation | Detailed, with AQAP cascade | Broader supplier audits, sometimes AQAP cascaded down |
| Evidence base | Minimal documentation | Extended evidence for GQAR | Audit trail mandatory, longer retention, stricter versioning |
| Customer inspections | Not anticipated | Built into the system | System designed for future MoD/GQAR inspections from day one |
| Certification body | Any IAF MLA accredited CB | CB with NATO MoD recognition | Not every Ukrainian CB qualifies — need BV/TÜV/DNV/BSI/SGS |
| Contractual weight of certificate | Marketing asset | Contract qualification requirement | Losing AQAP = losing the specific defense contract |
The biggest difference that's often underestimated
Configuration management is the real deal-breaker. Teams implement ISO 9001, then take on AQAP 2110 "as an overlay," think it's a month of work — and end up stuck for 3-4 months because CM (Configuration Management) turns out to be a separate discipline with its own terminology, processes, and tooling requirements. If you don't have a change-control history from 60-90 days of operational cycle before Stage 1, the auditor won't see how your CM actually runs, and that's a guaranteed major nonconformity. Plan CM into the schedule from day one — not two weeks before the certification audit.
What is common: 70% of documents and processes
Now the good news. ISO 9001 and AQAP 2110 are built on the same architecture, and that's what makes integration realistic rather than duplicate work.
Both standards use the Annex SL structure (High Level Structure) — the 10 clauses ISO applies to all its management systems: organizational context, leadership, planning, support, operations, performance evaluation, improvement. That means the process map, stakeholder register, risk register, quality policy, and objectives have a single format and a shared set of documents for both standards.
Both standards rest on the 7 quality management principles of ISO 9000: customer focus, leadership, engagement of people, process approach, improvement, evidence-based decision-making, relationship management. None is replaced or modified in AQAP 2110 — the defense overlay runs on the same principles.
Both require process approach and risk-based thinking. Risk management in AQAP 2110 is stricter (because of defense-contract specifics and penalty clauses), but the tools are the same: risk register, likelihood-impact assessment, mitigation plans. You don't need two separate risk management systems — one, with additional defense risk categories.
Both require internal audit, management review, corrective actions (CAPA). The internal audit program covers both standards; management review looks at data for ISO 9001 and AQAP 2110 simultaneously; the CAPA process is unified, with an additional loop for defense nonconformities.
When Ekontrol consultants do gap analysis before implementing AQAP 2110 at a company with ISO 9001:2015, on average 70-80% of documents turn out to be ready or need cosmetic edits (add defense context to the policy, add GQAR to the stakeholder register, add defense contracts to the risk register). The real new work is the defense blocks from item 8 in our table: configuration, traceability, evidence base.
That's the foundation integration builds on.
How to integrate AQAP 2110 with ISO 9001 into one system
The basic integration strategy is simple: one management system, two documentation layers. The first layer is universal documents that cover both standards at once. The second layer is defense-specific modules that overlay the universal base.
Universal documents (one set for both standards): quality policy with defense context, organizational context with GQAR in the stakeholder register, quality objectives with defense-contract KPIs, risk register with a defense-risks block, process map, quality manual, documented information register, document and records control procedures, internal audit program, management review minutes, CAPA procedure.
Defense-additional modules: configuration management (CM) procedure per ACMP-2100, traceability procedure tied to serial numbers and lot tracking, GQAR and MoD-customer interaction procedure, customer-audit readiness checklists, defense-nonconformity handling procedure with mandatory customer notification, AQAP 2110-specific forms.
The core organizational principle is one quality team, not two. Large companies sometimes try to split: "here's our QA team for civilian contracts, here's our defense QA team." It costs money and creates document collisions. The correct model is a single quality team where part of the people have additional defense competence (AQAP 2110 internal auditors, CM manager), but the system is one. This should be set up at the system design stage, usually carried out within management system implementation.
Before starting the implementation project — a diagnostic audit, always. 3-5 working days, full checklist against ISO 9001:2015 and AQAP 2110 Edition D, gap fixation, realistic budget and timeline. Without this step integration planning is blind, and you'll end up reworking it mid-project.
The IAQG 9137 guidance document (Guidance for the Application of AQAP 2110 within a 9100 QMS) is the single most useful practical material on integration. Although written for AS 9100 (9100 QMS), 90% of the methodology applies to ISO 9001 as well. The quality team should read IAQG 9137 before starting the implementation project.
| Document / module | Shared for both | Additional for AQAP 2110 |
|---|---|---|
| Quality policy | Yes (with defense context) | — |
| Organizational context, stakeholder register | Yes (add GQAR and MoD) | — |
| Risk register | Yes (add defense-risks block) | — |
| Configuration management (CM) | — | Yes — full procedure per ACMP-2100 |
| Product traceability | — | Yes — serial numbers, lot tracking, ERP/PLM |
| Internal audit program | Yes (unified) | Auditors with AQAP competence |
| CAPA, RCA | Yes (unified process) | GQAR notification loop for defense NCRs |
| GQAR and customer interaction | — | Yes — separate procedure and checklists |
Ready to integrate AQAP 2110 with ISO 9001?
Free 30-minute consultation for integration into your existing quality system. Bureau Veritas partner in Ukraine.
Get consultationEconomic benefit of joint AQAP 2110 + ISO 9001 certification
Separate ISO 9001 and AQAP 2110 certifications mean two implementation projects, two auditors, two certification visits, two annual support schedules. Joint certification as a combined audit means one project, one auditor (with dual competence), one visit, a single surveillance cycle. The typical savings numbers look like this:
- Implementation budget drops by 20-30%. The savings come from shared documents, shared internal auditor training, shared system design. Real numbers for a typical UAV manufacturer of 50-100 people: separate ISO 9001 + AQAP 2110 cost roughly X euros, integrated cost 0.7-0.8X. Cost details are in our piece on the cost of AQAP 2110 certification.
- Calendar time shrinks by 4-6 weeks. Stage 1 and Stage 2 run simultaneously for both standards, with no 2-3 month gap between cycles.
- Quality team's time shrinks by roughly a third. Instead of duplication — joint planning, joint internal audits, joint management review.
- Annual support optimizes similarly. Surveillance audit is one visit instead of two; internal audits run as one program; management review is one document per year.
Another economic bonus — most serious certification bodies (Bureau Veritas, TÜV NORD, DNV, BSI, SGS) deliberately incentivize combined audits with pricing. In their price lists a combined audit is cheaper than the arithmetic sum of two separate ones. Ekontrol, as a Bureau Veritas partner in Ukraine, recommends a combined audit from day one for clients who know for sure they need both certificates — it's the most economical and fastest strategy.
Where combined audit doesn't fit: if you need ISO 9001 right away (say, for a transparent tender in 2 months) and AQAP 2110 a year out, then sequential is the way. But if both certificates fall within a 6-12 month horizon, joint certification is the better deal.
How to choose — which standard first?
This depends heavily on your starting point and timeline. Let's outline three typical scenarios that cover 80% of real cases for Ukrainian defense manufacturers.
Scenario A. Manufacturer with no certificates, new defense project, 12+ month horizon. The logic: ISO 9001 first (3-5 months implementation), then AQAP 2110 as an overlay (3-4 months on top). Why not go straight to AQAP 2110? Because the team has no experience operating in a structured quality system, and implementing the base standard and the overlay in parallel overloads people. On the average project that ends in a Stage 2 failure and rework. A staged sequence lets you build operational maturity on ISO 9001 first, then calmly add the defense blocks.
Scenario B. You already have ISO 9001:2015, you need AQAP 2110. This is the most comfortable starting position. The team knows how to live in the system, the documentation works, internal audits run. What's left is adding the defense overlays: configuration management, expanded traceability, evidence base for GQAR, customer interaction procedures, customer-audit checklists. Timeline — 4-6 months to AQAP 2110 Stage 2. Integration into the existing system without duplicate work.
Scenario C. Fast entry into a defense contract, both standards needed at once. If you have no certificates but a clear contract or tender within an 8-12 month horizon that requires both — joint AQAP 2110 + ISO 9001 certification as a combined audit. Timeline — 8-12 months to both certificates. It's a more intense tempo than the sequential strategy, but it lets you hit the tender on time and save 20-30% of budget. Suits companies with a strong quality team or with consulting support.
A separate word on drone startups. If you grew out of Brave1, have your first serial deliveries, and are looking at NATO-export horizons — the recommended sequence is laid out in detail in our piece on drone manufacturer certification. In short: 6-8 months of ISO 9001 (no extra complexity), then 4-6 months of AQAP 2110 as an overlay, in parallel — MoD customer audit preparation. Total horizon — 12-18 months, which matches the real growth tempo of a drone company from pilot series to serial contracts. More on the sector specifics is in the defense industry pillar.
The constraint is almost always configuration management and traceability — defense blocks that need 60-90 days of operational cycle before Stage 1. That's a physical constant you can't compress with nice Gantt charts — build it into the plan from day one.

Need a certification consultation?
Free Consultation
On This Page
- Short answer: what is the difference between AQAP 2110 and ISO 9001
- What each standard is — the foundation for comparison
- 8 key differences between AQAP 2110 and ISO 9001
- What is common: 70% of documents and processes
- How to integrate AQAP 2110 with ISO 9001 into one system
- Economic benefit of joint AQAP 2110 + ISO 9001 certification
- How to choose — which standard first?
- FAQ — Common questions about AQAP 2110 vs ISO 9001
Short answer: what is the difference between AQAP 2110 and ISO 9001
AQAP 2110 vs ISO 9001 isn't an either-or choice — it's a question of layers. ISO 9001:2015 is the baseline international quality management system standard that works in any industry, from a coffee shop to a car plant. AQAP 2110 is NATO's defense-specific overlay on top of ISO 9001, adding defense requirements: configuration management, batch traceability, contractor control, evidence base for customer audits.
The core conclusion the Ekontrol team repeats on every first call with a defense manufacturer: AQAP 2110 doesn't replace ISO 9001 — it complements it. All ISO 9001:2015 requirements are incorporated into AQAP 2110 in full, plus defense blocks on top. So the correct question isn't "which one to choose," but "how to build a single system that covers both standards." In practice this saves 20-30% of the implementation budget and 4-6 weeks of calendar time.
Around 70-80% of documents are shared: quality policy, organizational context, objectives, risk management, internal audits, management review. Defense add-ons are a separate layer of modules that overlay the ready ISO 9001 base.
Quick comparison in one sentence
ISO 9001 is the universal quality system foundation for any industry; AQAP 2110 is NATO's defense overlay that adds 8 specific blocks (configuration management, traceability, GQAR oversight, evidence base for customer audits) on top of the same ISO 9001 base. That's why integrated certification of both standards costs 20-30% less than separate ones and takes 4-6 weeks less time.
What each standard is — the foundation for comparison
Before comparing, you need to nail down what you're comparing. In back-to-back calls with defense manufacturers it turns out half the team understands "ISO 9001" as "a piece of paper for tenders" and "AQAP 2110" as "something military." That misunderstanding costs money at later stages.
ISO 9001:2015 is the international quality management system standard issued by ISO (International Organization for Standardization, Geneva) in 2015. According to the ISO Survey, over 1.1 million ISO 9001 certificates have been issued worldwide in 178 countries. The standard is voluntary, but de facto required for serious B2B contracts and government tenders in practically any industry. Its structure follows the 10-clause Annex SL model (HLS, High Level Structure) that ISO uses for all its management system standards. The details and implementation logic are in our complete ISO 9001 guide.
AQAP 2110 Edition D Version 1 is a publication from the NATO Standardization Office (NSO, Brussels), in force since 2016 with no changes as of 2026. AQAP stands for Allied Quality Assurance Publication. Unlike ISO 9001, AQAP 2110 isn't a standalone standard — it's a defense overlay that incorporates all ISO 9001:2015 requirements and adds 8 blocks of specific requirements for NATO defense contracts. It's issued within STANAG 4107, the agreement on mutual recognition of government quality inspections between Alliance countries. For a deeper dive, see the complete AQAP 2110 guide.
The key difference is in the nature of the standards: ISO 9001 is a voluntary general management tool, AQAP 2110 is a contractual defense-sector requirement. You implement ISO 9001 because you've decided to step up your management quality and gain a market edge. You implement AQAP 2110 because without it you won't be admitted to an NSPA tender, a Bundeswehr contract, or a serial DOT contract. That difference shapes priorities, budget, and project tempo.
8 key differences between AQAP 2110 and ISO 9001
Let's go through the eight blocks where AQAP 2110 goes beyond baseline ISO 9001. This isn't an exhaustive list (there are more minor ones), but these eight tend to drive the toughest conversations with auditors and the most painful nonconformities in companies that underestimated the defense specifics.
1. Scope. ISO 9001 is universal — it works for a chocolate maker and a medical device developer alike. AQAP 2110 is defense-only: the standard explicitly assumes the context of a defense contract, regulatory restrictions (ITAR/EAR), and collaboration with a government military customer. AQAP 2110 is pointless in civilian business; ISO 9001 alone is insufficient in defense.
2. Configuration management. This is the most critical and most underestimated difference. ISO 9001:2015 doesn't explicitly require configuration management — the word "configuration" appears only in passing. AQAP 2110 requires a full Configuration Management cycle per the ACMP-2100 model (NATO Configuration Management Policy): configuration identification, change control, status accounting, configuration audit. Every microchip swap, every firmware change is formally recorded and approved by the customer. It's a separate discipline you need to build from scratch if you didn't have it.
3. Product traceability. ISO 9001 clause 8.5.2 says "when traceability is a requirement — the organization shall ensure it." So it's optional, depending on context. AQAP 2110 makes traceability mandatory for defense products: serial numbers, lot tracking, integration with suppliers, ability to trace both ways — from raw material to airframe number and back. For ammunition makers or UAV component manufacturers this means a real ERP or PLM system, not Excel records.
4. Contractor control. ISO 9001 says "evaluate suppliers against defined criteria" — no detail. AQAP 2110 spells it out: criteria must account for defense specifics, critical-component suppliers must themselves have sufficient quality control, evaluations are renewed at set intervals, there's a clear disqualification mechanism. In practice this means broader supplier audits and often cascading AQAP requirements down the supply chain.
5. Evidence base and documentation. ISO 9001 says "the organization shall maintain documented information" — minimally. AQAP 2110 adds an evidence layer for the government customer: records must be ready for GQAR (Government Quality Assurance Representative) inspection, retention periods are longer, version control is stricter, audit trail is mandatory. At a civilian ISO 9001 audit the auditor accepts "we have a process"; at an AQAP audit it's "show me records for the past 12 months."
6. Customer inspections. ISO 9001 doesn't anticipate customer inspections as part of the system. AQAP 2110 is explicitly designed around regular customer audits — from MoD, GQAR, prime contractors. So the system is designed from day one to withstand a third-party inspector: clear control points, ready document packages, assigned owners for each process. Details are in our piece on the MoD customer audit.
7. Certification body. ISO 9001 is issued by any accredited body (CB) within IAF MLA — for Ukraine that means NAAU-accredited bodies or foreign CBs. AQAP 2110 needs a body whose accreditation is recognized by NATO MoDs. Not every Ukrainian CB has that recognition; for defense contracts it's safer to work with Bureau Veritas, TÜV NORD, DNV, BSI, or SGS — their certificates are accepted by NSPA and national MoDs without further questions.
8. Certificate duration and contractual hardness. Formally they're similar — both are issued for 3 years with annual surveillance audits. But the contractual requirement makes AQAP harder in practice: a nonconformity at a surveillance audit can lead to suspension of deliveries under a specific contract, not just an NCR closure in the next cycle. Losing ISO 9001 means losing a piece of paper; losing AQAP 2110 means losing a contract.
A short summary is in the table below.
| Aspect | ISO 9001 | AQAP 2110 | What it means in practice |
|---|---|---|---|
| Scope | Any industry | NATO defense contracts only | For defense ISO 9001 is the minimum, AQAP 2110 is the tender entry ticket |
| Configuration management | Not explicitly required | Mandatory, per ACMP-2100 | Separate discipline — build from scratch, ~2-3 months implementation |
| Product traceability | Optional (8.5.2) | Mandatory, both directions | Needs ERP or PLM, not Excel — investment €5-25k |
| Contractor control | General supplier evaluation | Detailed, with AQAP cascade | Broader supplier audits, sometimes AQAP cascaded down |
| Evidence base | Minimal documentation | Extended evidence for GQAR | Audit trail mandatory, longer retention, stricter versioning |
| Customer inspections | Not anticipated | Built into the system | System designed for future MoD/GQAR inspections from day one |
| Certification body | Any IAF MLA accredited CB | CB with NATO MoD recognition | Not every Ukrainian CB qualifies — need BV/TÜV/DNV/BSI/SGS |
| Contractual weight of certificate | Marketing asset | Contract qualification requirement | Losing AQAP = losing the specific defense contract |
The biggest difference that's often underestimated
Configuration management is the real deal-breaker. Teams implement ISO 9001, then take on AQAP 2110 "as an overlay," think it's a month of work — and end up stuck for 3-4 months because CM (Configuration Management) turns out to be a separate discipline with its own terminology, processes, and tooling requirements. If you don't have a change-control history from 60-90 days of operational cycle before Stage 1, the auditor won't see how your CM actually runs, and that's a guaranteed major nonconformity. Plan CM into the schedule from day one — not two weeks before the certification audit.
What is common: 70% of documents and processes
Now the good news. ISO 9001 and AQAP 2110 are built on the same architecture, and that's what makes integration realistic rather than duplicate work.
Both standards use the Annex SL structure (High Level Structure) — the 10 clauses ISO applies to all its management systems: organizational context, leadership, planning, support, operations, performance evaluation, improvement. That means the process map, stakeholder register, risk register, quality policy, and objectives have a single format and a shared set of documents for both standards.
Both standards rest on the 7 quality management principles of ISO 9000: customer focus, leadership, engagement of people, process approach, improvement, evidence-based decision-making, relationship management. None is replaced or modified in AQAP 2110 — the defense overlay runs on the same principles.
Both require process approach and risk-based thinking. Risk management in AQAP 2110 is stricter (because of defense-contract specifics and penalty clauses), but the tools are the same: risk register, likelihood-impact assessment, mitigation plans. You don't need two separate risk management systems — one, with additional defense risk categories.
Both require internal audit, management review, corrective actions (CAPA). The internal audit program covers both standards; management review looks at data for ISO 9001 and AQAP 2110 simultaneously; the CAPA process is unified, with an additional loop for defense nonconformities.
When Ekontrol consultants do gap analysis before implementing AQAP 2110 at a company with ISO 9001:2015, on average 70-80% of documents turn out to be ready or need cosmetic edits (add defense context to the policy, add GQAR to the stakeholder register, add defense contracts to the risk register). The real new work is the defense blocks from item 8 in our table: configuration, traceability, evidence base.
That's the foundation integration builds on.
How to integrate AQAP 2110 with ISO 9001 into one system
The basic integration strategy is simple: one management system, two documentation layers. The first layer is universal documents that cover both standards at once. The second layer is defense-specific modules that overlay the universal base.
Universal documents (one set for both standards): quality policy with defense context, organizational context with GQAR in the stakeholder register, quality objectives with defense-contract KPIs, risk register with a defense-risks block, process map, quality manual, documented information register, document and records control procedures, internal audit program, management review minutes, CAPA procedure.
Defense-additional modules: configuration management (CM) procedure per ACMP-2100, traceability procedure tied to serial numbers and lot tracking, GQAR and MoD-customer interaction procedure, customer-audit readiness checklists, defense-nonconformity handling procedure with mandatory customer notification, AQAP 2110-specific forms.
The core organizational principle is one quality team, not two. Large companies sometimes try to split: "here's our QA team for civilian contracts, here's our defense QA team." It costs money and creates document collisions. The correct model is a single quality team where part of the people have additional defense competence (AQAP 2110 internal auditors, CM manager), but the system is one. This should be set up at the system design stage, usually carried out within management system implementation.
Before starting the implementation project — a diagnostic audit, always. 3-5 working days, full checklist against ISO 9001:2015 and AQAP 2110 Edition D, gap fixation, realistic budget and timeline. Without this step integration planning is blind, and you'll end up reworking it mid-project.
The IAQG 9137 guidance document (Guidance for the Application of AQAP 2110 within a 9100 QMS) is the single most useful practical material on integration. Although written for AS 9100 (9100 QMS), 90% of the methodology applies to ISO 9001 as well. The quality team should read IAQG 9137 before starting the implementation project.
| Document / module | Shared for both | Additional for AQAP 2110 |
|---|---|---|
| Quality policy | Yes (with defense context) | — |
| Organizational context, stakeholder register | Yes (add GQAR and MoD) | — |
| Risk register | Yes (add defense-risks block) | — |
| Configuration management (CM) | — | Yes — full procedure per ACMP-2100 |
| Product traceability | — | Yes — serial numbers, lot tracking, ERP/PLM |
| Internal audit program | Yes (unified) | Auditors with AQAP competence |
| CAPA, RCA | Yes (unified process) | GQAR notification loop for defense NCRs |
| GQAR and customer interaction | — | Yes — separate procedure and checklists |
Ready to integrate AQAP 2110 with ISO 9001?
Free 30-minute consultation for integration into your existing quality system. Bureau Veritas partner in Ukraine.
Get consultationEconomic benefit of joint AQAP 2110 + ISO 9001 certification
Separate ISO 9001 and AQAP 2110 certifications mean two implementation projects, two auditors, two certification visits, two annual support schedules. Joint certification as a combined audit means one project, one auditor (with dual competence), one visit, a single surveillance cycle. The typical savings numbers look like this:
- Implementation budget drops by 20-30%. The savings come from shared documents, shared internal auditor training, shared system design. Real numbers for a typical UAV manufacturer of 50-100 people: separate ISO 9001 + AQAP 2110 cost roughly X euros, integrated cost 0.7-0.8X. Cost details are in our piece on the cost of AQAP 2110 certification.
- Calendar time shrinks by 4-6 weeks. Stage 1 and Stage 2 run simultaneously for both standards, with no 2-3 month gap between cycles.
- Quality team's time shrinks by roughly a third. Instead of duplication — joint planning, joint internal audits, joint management review.
- Annual support optimizes similarly. Surveillance audit is one visit instead of two; internal audits run as one program; management review is one document per year.
Another economic bonus — most serious certification bodies (Bureau Veritas, TÜV NORD, DNV, BSI, SGS) deliberately incentivize combined audits with pricing. In their price lists a combined audit is cheaper than the arithmetic sum of two separate ones. Ekontrol, as a Bureau Veritas partner in Ukraine, recommends a combined audit from day one for clients who know for sure they need both certificates — it's the most economical and fastest strategy.
Where combined audit doesn't fit: if you need ISO 9001 right away (say, for a transparent tender in 2 months) and AQAP 2110 a year out, then sequential is the way. But if both certificates fall within a 6-12 month horizon, joint certification is the better deal.
How to choose — which standard first?
This depends heavily on your starting point and timeline. Let's outline three typical scenarios that cover 80% of real cases for Ukrainian defense manufacturers.
Scenario A. Manufacturer with no certificates, new defense project, 12+ month horizon. The logic: ISO 9001 first (3-5 months implementation), then AQAP 2110 as an overlay (3-4 months on top). Why not go straight to AQAP 2110? Because the team has no experience operating in a structured quality system, and implementing the base standard and the overlay in parallel overloads people. On the average project that ends in a Stage 2 failure and rework. A staged sequence lets you build operational maturity on ISO 9001 first, then calmly add the defense blocks.
Scenario B. You already have ISO 9001:2015, you need AQAP 2110. This is the most comfortable starting position. The team knows how to live in the system, the documentation works, internal audits run. What's left is adding the defense overlays: configuration management, expanded traceability, evidence base for GQAR, customer interaction procedures, customer-audit checklists. Timeline — 4-6 months to AQAP 2110 Stage 2. Integration into the existing system without duplicate work.
Scenario C. Fast entry into a defense contract, both standards needed at once. If you have no certificates but a clear contract or tender within an 8-12 month horizon that requires both — joint AQAP 2110 + ISO 9001 certification as a combined audit. Timeline — 8-12 months to both certificates. It's a more intense tempo than the sequential strategy, but it lets you hit the tender on time and save 20-30% of budget. Suits companies with a strong quality team or with consulting support.
A separate word on drone startups. If you grew out of Brave1, have your first serial deliveries, and are looking at NATO-export horizons — the recommended sequence is laid out in detail in our piece on drone manufacturer certification. In short: 6-8 months of ISO 9001 (no extra complexity), then 4-6 months of AQAP 2110 as an overlay, in parallel — MoD customer audit preparation. Total horizon — 12-18 months, which matches the real growth tempo of a drone company from pilot series to serial contracts. More on the sector specifics is in the defense industry pillar.
The constraint is almost always configuration management and traceability — defense blocks that need 60-90 days of operational cycle before Stage 1. That's a physical constant you can't compress with nice Gantt charts — build it into the plan from day one.


