AQAP 2210
AQAP 2210 software quality assurance
Defence suppliers whose deliverable contains software, where the contract cites AQAP 2210 on top of AQAP 2110 or AQAP 2310.
AQAP 2210 adds NATO's software-specific quality assurance requirements on top of AQAP 2110 or AQAP 2310. It is never cited on its own: it supplements the quality system those publications require, for the part of the deliverable that is software.
ComplyTrain fully supports this standard
What AQAP 2210 is
AQAP 2210 is the NATO Supplementary Software Quality Assurance Requirements to AQAP 2110 or AQAP 2310. It applies when what you deliver contains software, and it exists because software fails in ways a hardware inspection regime was never designed to catch.
Supplementary is the operative word. AQAP 2210 is not a quality system in its own right and is never cited on its own. The contract names AQAP 2110 or AQAP 2310 for the quality management system, and AQAP 2210 for the software inside the deliverable. The obligations are cumulative, not alternative.
What the standard sets out to achieve
AQAP 2210 addresses both managerial and technical processes across the whole project life cycle. Its stated aims are to:
- Establish visibility of the software development process, so the customer is not asked to take it on trust.
- Detect software quality problems as early as possible in the life cycle, where they are still cheap.
- Provide quality control data in time for corrective action to actually be taken.
- Confirm that quality is engineered in during development rather than inspected in afterwards.
- Provide assurance that the software produced conforms to the contractual requirements.
- Ensure appropriate software support is given to system engineering activities, where the contract requires it.
- Ensure the safety and security conditions of the project are addressed.
What that means in practice
The publication carries requirements for the project quality plan as it applies to software, for software design, and for verification and validation, alongside its definitions. In day-to-day terms that is a plan the customer can hold you to, a design that can be traced to the requirements it satisfies, and evidence that each requirement was actually verified rather than assumed.
The practical difficulty is rarely the engineering. It is that the evidence lives in one place, the requirements in another, and the quality plan in a document nobody has opened since the bid. AQAP 2210 is demonstrated by connecting those three, and by being able to show the connection on the day somebody asks.
How it relates to AQAP 2110 and AQAP 2310
AQAP 2110 contains the requirements of ISO 9001 plus NATO's additions, and is the usual base for a supplier that designs and produces. AQAP 2310 does the same with EN 9100 for complex aviation, space and defence work. AQAP 2210 sits on top of whichever of the two your contract cites, and adds nothing to the parts of the deliverable that are not software.
If you are working out which publications your contract actually invokes, the overview of the AQAP family sets out how 2110, 2131, 2210, 2310 and 2105 relate to each other.
There is no AQAP 2210 certificate
As with every AQAP, conformance is not certified by an accredited certification body the way ISO 9001 is. It is assured through Government Quality Assurance: the customer nation's quality authority verifies your quality system and the specific contract, with a right of access to your premises, your records and your sub-suppliers'. For software that access usually reaches further than suppliers expect, because the evidence a reviewer wants is generated during development, not at the end of it.
How ComplyTrain helps you meet it
Because AQAP 2210 is always applied on top of AQAP 2110 or AQAP 2310, the useful thing is one system holding both sets of obligations rather than a separate tool for the software half:
- The ISO 9001-structured QMS the base publication requires - Quality Management
- The contract's software requirements captured as a tracked set and traced to the evidence that verifies each one - Requirements Management
- The project quality plan and the software procedures under revision control with sign-off, so the plan the customer holds you to is the plan in force - Document Control
- Risk to contract performance, including the safety and security conditions the standard asks you to address, as a living register - Risk Management
- Competence records for the engineers named on the contract - Training Management
ComplyTrain holds no AQAP qualification and does not need one: it is the system you run your own AQAP 2210 obligations in and hold the evidence for. Conformance is between you and your customer's quality authority.
Questions
Is AQAP 2210 used on its own?
No. It is supplementary by design. A contract cites AQAP 2110 or AQAP 2310 for the quality management system and AQAP 2210 for the software in the deliverable. If you have been given AQAP 2210 alone, check the contract again - the base publication will be in there.
What is the difference between AQAP 2110 and AQAP 2210?
AQAP 2110 covers quality assurance for design, development and production generally, and contains the requirements of ISO 9001 plus NATO's additions. AQAP 2210 adds the software-specific requirements on top of it. A supplier delivering software-intensive defence materiel is normally held to both, with 2210 applied over the 2110 quality system.
Does AQAP 2210 supplement AQAP 2310 as well?
Yes. Its full designation is the NATO Supplementary Software Quality Assurance Requirements to AQAP 2110 or AQAP 2310. Which of the two it sits on depends on the base publication your contract cites, not on anything about the software itself.
Can a company be certified to AQAP 2210?
No. There is no AQAP certificate issued by a certification body. Conformance is assured through Government Quality Assurance, where the customer nation's quality authority verifies your quality system and the specific contract. An ISO 9001 certificate normally evidences the management system underneath, and the AQAP additions are demonstrated to the customer.
What does AQAP 2210 actually require day to day?
A project quality plan that covers the software, a design traceable to the requirements it satisfies, and verification and validation evidence showing each requirement was actually checked. The standard is written around visibility: the customer should be able to see the state of the software's quality during development, not only at delivery.
Implementation
Meeting AQAP 2210 alongside the base publication
The software requirements are cumulative on top of AQAP 2110 or AQAP 2310, so the work is to connect them rather than run them separately.
Confirm which base publication applies
AQAP 2210 supplements AQAP 2110 or AQAP 2310. Which one the contract cites determines the quality system underneath, and therefore most of the work.
Write the quality plan so it covers the software
The plan is what the customer holds you to. Keep it under revision control with sign-off, so the version in force is the version they were given.
Trace design and verification to requirements
Each software requirement should point at the design that satisfies it and the verification evidence that checked it. That trace is what a reviewer asks for.
Address safety and security, and keep it current
The standard asks for the project's safety and security conditions to be addressed. A register that is maintained during development answers that; one written for the bid does not.
