This training Program includes the requirements of the AQAP-PECAL / AS / ISO-IEC / ENS quality and safety management system specific to the requirements, definitions and additional elements for its implementation and audit, for the aviation, space and defense industry.
It is emphasized that the requirements specified in this regulatory framework are complementary and not alternative to each other, as well as in relation to the Client’s requirements and the applicable legal and regulatory requirements.
This training Program includes the requirements of the AQAP-PECAL / AS / ISO-IEC / ENS quality and safety management system specific to the requirements, definitions and additional elements for its implementation and audit, for the aviation, space and defense industry.
It is emphasized that the requirements specified in this regulatory framework are complementary and not alternative to each other, as well as in relation to the Client’s requirements and the applicable legal and regulatory requirements.
Module I
Reference Management Systems
1. Introduction to the Reference Standards for Quality and Security Assurance AQAP-PECAL / AS /ISO-IEC / ENS.
- 1
1.1. AQAP-2110, Edition D Version 1, 2016: NATO QUALITY ASSURANCE REQUIREMENTS FOR DESIGN, DEVELOPMENT AND PRODUCTION. This standard focuses on establishing, documenting, implementing, maintaining and improving a quality management system (QMS) compliant with NATO requirements, identical to PECAL – 2110 (Edición 4), REQUISITOS OTAN DE ASEGURAMIENTO DE LA CALIDAD PARA EL DISEÑO, EL DESARROLLO Y LA PRODUCCIÓN, Spanish version of AQAP – 2110, in addition to those required by ISO 9001:2015, which is the international standard that establishes theRequirements for a Quality Management System (QMS).
- 2
1.2. AQAP-2210, Edition B Version 1, 2022: NATO SUPPLEMENTARY SOFTWARE QUALITY ASSURANCE REQUIREMENTS TO AQAP-2110 OR AQAP-2310. This standard complements AQAP-2110 and AQAP-2310, focusing on quality management of the software development process, according to NATO requirements, identical to PECAL-2210 (Edición B Versión 1) REQUISITOS OTAN DE ASEGURAMIENTO DE LA CALIDAD DEL SOFTWARE, SUPLEMENTARIOS A LA PECAL-2110 O A LA PECAL-2310.
- 3
1.3. AQAP-2310, Edition B Version 2, 2022: NATO QUALITY ASSURANCE REQUIREMENTS FOR AVIATION, SPACE AND DEFENCE SUPPLIERS. This standard is aimed at suppliers involved in complex projects in these sectors, in addition to those required by AS9100:2016, which is the standard on the Quality Management System for the Aerospace, Defense and Space Industry.
- 4
1.4. ISO/IEC 27001:2022: Information security, cybersecurity and privacy protection—Information security management systems—Requirements. This standard focuses on requirements for the establishment, implementation, maintenance and continuous improvement of an information security management system in the organization, identical to UNE-ISO/IEC 27001:2023 Seguridad de la información, ciberseguridad y protección de la privacidad. Sistemas de gestión de la seguridad de la información. Requisitos.
- 5
1.5. Royal Decree D 311/2022: National Security Scheme, Esquema Nacional de Seguridad (ENS). This is a statutory regulation to strengthening the defense capabilities against cyberthreats among technology and service providers to the public sector, the objective of which is to establish a common security framework to protect information and information systems in the public and private sectors.
2. Implementation of a Quality Management System (QMS) ISO 9001/Quality Assurance System (QAS) AQAP-2110.
- 1
2.1. Principles and benefits of a QMS based on ISO 9001.
- 2
2.2. Integration of AQAP-PECAL quality assurance requirements into the QAS.
- 3
2.3. Documentation and maintenance of the QMS/QAS.
3. Project management for NATO acquisition programs.
- 1
3.1. Project planning and control during the life cycle.
- 2
3.2. Risk identification and risk management based on NATO particularities.
- 3
3.3. Tools and techniques for NATO framework management.
4. Specific requirements for the Aerospace, Defense and Space Industry AS9100/AQAP-2310-PECAL 2310.
- 1
4.1. Sector-specific standards and regulations and NATO quality assurance requirements for aviation, space, and defense suppliers.
- 2
4.2. Quality management in highly complex projects.
- 3
4.3. Continuous quality assessment and improvement for NATO suppliers.
Module I
Reference Management Systems
1. Introduction to the Reference Standards for Quality and Security Assurance AQAP-PECAL / AS /ISO-IEC / ENS.
- 1
1.1. AQAP-2110, Edition D Version 1, 2016: NATO QUALITY ASSURANCE REQUIREMENTS FOR DESIGN, DEVELOPMENT AND PRODUCTION. This standard focuses on establishing, documenting, implementing, maintaining and improving a quality management system (QMS) compliant with NATO requirements, identical to PECAL – 2110 (Edición 4), REQUISITOS OTAN DE ASEGURAMIENTO DE LA CALIDAD PARA EL DISEÑO, EL DESARROLLO Y LA PRODUCCIÓN, Spanish version of AQAP – 2110, in addition to those required by ISO 9001:2015, which is the international standard that establishes theRequirements for a Quality Management System (QMS).
- 2
1.2. AQAP-2210, Edition B Version 1, 2022: NATO SUPPLEMENTARY SOFTWARE QUALITY ASSURANCE REQUIREMENTS TO AQAP-2110 OR AQAP-2310. This standard complements AQAP-2110 and AQAP-2310, focusing on quality management of the software development process, according to NATO requirements, identical to PECAL-2210 (Edición B Versión 1) REQUISITOS OTAN DE ASEGURAMIENTO DE LA CALIDAD DEL SOFTWARE, SUPLEMENTARIOS A LA PECAL-2110 O A LA PECAL-2310.
- 3
1.3. AQAP-2310, Edition B Version 2, 2022: NATO QUALITY ASSURANCE REQUIREMENTS FOR AVIATION, SPACE AND DEFENCE SUPPLIERS. This standard is aimed at suppliers involved in complex projects in these sectors, in addition to those required by AS9100:2016, which is the standard on the Quality Management System for the Aerospace, Defense and Space Industry.
- 4
1.4. ISO/IEC 27001:2022: Information security, cybersecurity and privacy protection—Information security management systems—Requirements. This standard focuses on requirements for the establishment, implementation, maintenance and continuous improvement of an information security management system in the organization, identical to UNE-ISO/IEC 27001:2023 Seguridad de la información, ciberseguridad y protección de la privacidad. Sistemas de gestión de la seguridad de la información. Requisitos.
- 5
1.5. Royal Decree D 311/2022: National Security Scheme, Esquema Nacional de Seguridad (ENS). This is a statutory regulation to strengthening the defense capabilities against cyberthreats among technology and service providers to the public sector, the objective of which is to establish a common security framework to protect information and information systems in the public and private sectors.
2. Implementation of a Quality Management System (QMS) ISO 9001/Quality Assurance System (QAS) AQAP-2110.
- 1
2.1. Principles and benefits of a QMS based on ISO 9001.
- 2
2.2. Integration of AQAP-PECAL quality assurance requirements into the QAS.
- 3
2.3. Documentation and maintenance of the QMS/QAS.
3. Project management for NATO acquisition programs.
- 1
3.1. Project planning and control during the life cycle.
- 2
3.2. Risk identification and risk management based on NATO particularities.
- 3
3.3. Tools and techniques for NATO framework management.
4. Specific requirements for the Aerospace, Defense and Space Industry AS9100/AQAP-2310-PECAL 2310.
- 1
4.1. Sector-specific standards and regulations and NATO quality assurance requirements for aviation, space, and defense suppliers.
- 2
4.2. Quality management in highly complex projects.
- 3
4.3. Continuous quality assessment and improvement for NATO suppliers.
Module II
Software Quality and Information Security
5. NATO supplementary software quality assurance requirements AQAP-2210/PECAL 2210.
- 1
5.1. Requirement’s composition.
- 2
5.2. General software quality control requirements.
- 3
5.3. NATO-specific software requirements.
6. Specific Information Security Requirements ISO/IEC 27001.
- 1
6.1. Specific standards and regulations for information security, cybersecurity and privacy protection.
- 2
6.2. Information security management in reserved projects.
- 3
6.3. Evaluation and continuous improvement of information security, cybersecurity and privacy protection
7. Specific Requirements of the National Security Scheme (ENS).
- 1
7.1. Legal framework of the ENS, Royal Decree D 311/2022 for defense suppliers.
- 2
7.2. Security categorization, requirements and measures in information systems.
- 3
7.3. Protection of classified and critical information for public contracts.
Module II
Software Quality and Information Security
5. NATO supplementary software quality assurance requirements AQAP-2210/PECAL 2210.
- 1
5.1. Requirement’s composition.
- 2
5.2. General software quality control requirements.
- 3
5.3. NATO-specific software requirements.
6. Specific Information Security Requirements ISO/IEC 27001.
- 1
6.1. Specific standards and regulations for information security, cybersecurity and privacy protection.
- 2
6.2. Information security management in reserved projects.
- 3
6.3. Evaluation and continuous improvement of information security, cybersecurity and privacy protection
7. Specific Requirements of the National Security Scheme (ENS).
- 1
7.1. Legal framework of the ENS, Royal Decree D 311/2022 for defense suppliers.
- 2
7.2. Security categorization, requirements and measures in information systems.
- 3
7.3. Protection of classified and critical information for public contracts.
Module III
Audits in the Reference Framework
8. Quality Audits in ISO 9001.
- 1
8.1. Planning and carrying out Quality Audits.
- 2
8.2. Methods and analysis of QMS evidence.
- 3
8.3. Execution of the report and presentation of ISO 9001 audit results.
9. Quality Assurance Audits in AQAP-2110/PECAL-2110.
- 1
9.1. Planning and carrying out Quality Assurance Audits.
- 2
9.2. Methods and analysis of QMS evidence.
- 3
9.3. Execution of the report and presentation of AQAP-2110/PECAL-2210 audit results.
10. Quality Assurance Audits in AQAP-2210/PECAL-2210.
- 1
10.1. Planning and carrying out Software Quality Audits.
- 2
10.2. Software Quality Evidence Analysis and Methods.
- 3
10.3. AQAP-2210 Audit Report Execution and Presentation of Results.
11. AS9100D Aviation, Space, and Defense Quality Audits.
- 1
11.1. Planning and Conducting Aviation, Space, and Defense Quality Audits.
- 2
11.2. Aviation, Space, and Defense Quality Evidence Analysis and Methods.
- 3
11.3. AS9100 Audit Report Execution and Presentation of Results.
12. AQAP-2310/PECAL-2310 Aviation, Space, and Defense Quality Assurance Audits.
- 1
12.1. Planning and Conducting Aviation, Space, and Defense Quality Audits.
- 2
12.2. Aviation, Space, and Defense Quality Evidence Analysis and Methods.
- 3
12.3. Execution of the report and presentation of audit results AQAP-2310/PECAL-2310.
13. Information Security Audits in ISO/IEC 27001.
- 1
13.1. Planning and conducting Information Security audits.
- 2
13.2. Methods and analysis of ISMS evidence.
- 3
13.3. Execution of the report and presentation of ISO/IEC 27001 audit results.
14. Audits in the ENS.
- 1
14.1. Planning and conducting ENS Security audits.
- 2
14.2. Methods and analysis of ENS Security evidence.
- 3
14.3. Execution of the report and presentation of ENS audit results.
Module III
Audits in the Reference Framework
8. Quality Audits in ISO 9001.
- 1
8.1. Planning and carrying out Quality Audits.
- 2
8.2. Methods and analysis of QMS evidence.
- 3
8.3. Execution of the report and presentation of ISO 9001 audit results.
9. Quality Assurance Audits in AQAP-2110/PECAL-2110.
- 1
9.1. Planning and carrying out Quality Assurance Audits.
- 2
9.2. Methods and analysis of QMS evidence.
- 3
9.3. Execution of the report and presentation of AQAP-2110/PECAL-2210 audit results.
10. Quality Assurance Audits in AQAP-2210/PECAL-2210.
- 1
10.1. Planning and carrying out Software Quality Audits.
- 2
10.2. Software Quality Evidence Analysis and Methods.
- 3
10.3. AQAP-2210 Audit Report Execution and Presentation of Results.
11. AS9100D Aviation, Space, and Defense Quality Audits.
- 1
11.1. Planning and Conducting Aviation, Space, and Defense Quality Audits.
- 2
11.2. Aviation, Space, and Defense Quality Evidence Analysis and Methods.
- 3
11.3. AS9100 Audit Report Execution and Presentation of Results.
12. AQAP-2310/PECAL-2310 Aviation, Space, and Defense Quality Assurance Audits.
- 1
12.1. Planning and Conducting Aviation, Space, and Defense Quality Audits.
- 2
12.2. Aviation, Space, and Defense Quality Evidence Analysis and Methods.
- 3
12.3. Execution of the report and presentation of audit results AQAP-2310/PECAL-2310.
13. Information Security Audits in ISO/IEC 27001.
- 1
13.1. Planning and conducting Information Security audits.
- 2
13.2. Methods and analysis of ISMS evidence.
- 3
13.3. Execution of the report and presentation of ISO/IEC 27001 audit results.
14. Audits in the ENS.
- 1
14.1. Planning and conducting ENS Security audits.
- 2
14.2. Methods and analysis of ENS Security evidence.
- 3
14.3. Execution of the report and presentation of ENS audit results.



