Nimble ManufacturingGet a Quote →

Home

Resources

Certifications & Compliance

CERTIFICATIONS & COMPLIANCE

AS9100 Rev D — Complete Guide for Aerospace Buyers

If you’re sourcing aerospace components, AS9100 Rev D isn’t optional — it’s the baseline. Understanding what the standard actually requires (and what it doesn’t) separates engineers who get burned by nonconformances from those who don’t.

BY NIMBLE MANUFACTURING
JUNE 18, 2026
7 MIN READ

KEY TAKEAWAYS

AS9100 Rev D supersedes Rev C and adds explicit requirements for risk management, configuration management, and first article inspection that directly affect your supply chain.

Certification alone doesn’t guarantee quality — audit the shop’s internal NCR rates, CAPA closure times, and customer escapes before awarding work.

AS9100 is a superset of ISO 9001:2015, so every AS9100-certified supplier also satisfies ISO 9001 requirements by default.

Flow-down clauses in your purchase orders must reference AS9100 Rev D explicitly — vague quality language won’t protect you on a DCMA audit.

First article inspection (FAI) per AS9102 is a companion requirement to AS9100 — confirm your supplier performs full AS9102 FAI, not a simplified dimensional check.

What AS9100 Rev D Actually Is — and Isn’t

AS9100 Rev D is the aerospace industry’s quality management system (QMS) standard, published by the International Aerospace Quality Group (IAQG) and aligned with ISO 9001:2015 as its foundation. It adds roughly 80 aerospace-specific requirements on top of ISO 9001 covering areas like product safety, configuration management, first article inspection, and risk management. The current revision — Rev D — was released in 2016 and replaced Rev C, which expired in September 2018. Any supplier still operating under Rev C certification is out of compliance. Rev D is not a minor update. The structural shift to risk-based thinking, the formalization of operational planning requirements, and the addition of human factors considerations represent substantive changes to how a shop must run its QMS. For buyers, this matters because a Rev D-certified supplier has demonstrated a documented, audited process for identifying and mitigating risks before they become escapes — not just inspecting parts after the fact. Verification of certification should always include checking the certificate scope, the issuing Certification Body (CB), and the expiration date. IAQG’s OASIS database is the authoritative source.
Always verify AS9100 certificates through the IAQG OASIS database — nimblemfg.co/certifications. A certificate printed on paper can be expired or out of scope without anyone catching it.

Key Rev D Requirements Engineers Need to Understand

Rev D restructured the standard into the ISO high-level structure (HLS), which means clauses now run 4 through 10 — context of the organization, leadership, planning, support, operation, performance evaluation, and improvement. For aerospace buyers, the operational clause (Clause 8) is where most of the substantive requirements live. Clause 8.1.3 requires suppliers to implement a process for managing product and process changes, including notification to customers when changes could affect form, fit, or function. This alone is worth auditing on your suppliers. Clause 8.1.4 addresses prevention of counterfeit parts — a hard requirement, not a recommendation. Suppliers must have documented processes for sourcing, verification, and quarantine of suspect material. Clause 8.3 governs design and development, and if your supplier is responsible for design authority, their design review, verification, and validation records must be accessible to you. Clause 8.7 covers nonconforming outputs — the shop must document every nonconformance, disposition it (scrap, rework, use-as-is, return to supplier), and maintain records. On safety-critical hardware, use-as-is dispositions require customer approval. Understanding these specific clauses lets you ask the right questions during supplier qualification.
Clause 8.1.4 on counterfeit parts is non-negotiable. If a supplier cannot produce their Suspect/Counterfeit Part (SCCP) procedure on request, treat that as a disqualifying finding.

AS9100 vs. ISO 9001 — Understanding the Difference

ISO 9001:2015 is the global baseline quality management standard applicable to virtually any industry. AS9100 Rev D incorporates ISO 9001:2015 in its entirety and then layers aerospace-specific requirements on top. Think of it as ISO 9001 with a specialized overlay. A supplier certified to AS9100 Rev D is automatically compliant with ISO 9001:2015. The reverse is not true. An ISO 9001-certified machine shop has zero obligation to meet AS9100’s requirements for FAI, configuration management, or counterfeit part prevention. This distinction is critical when qualifying suppliers for aerospace programs. Some procurement teams mistakenly accept ISO 9001 certifications for flight hardware suppliers because both standards share the same QMS structure. The aerospace-specific additions in AS9100 exist precisely because commercial quality practices aren’t sufficient for flight-safety applications. When evaluating a supplier’s certification stack, also look for NADCAP accreditations for special processes (heat treat, NDT, coatings, welding) — AS9100 governs the QMS, but NADCAP governs the process itself. Both matter. A shop can be AS9100 certified and still run non-NADCAP heat treat, which may be unacceptable depending on your prime contractor flowdowns.

First Article Inspection (FAI) and AS9102 — The Companion Standard

AS9100 Rev D requires that suppliers perform first article inspection, but the specific requirements for FAI are defined in a separate standard: AS9102 Rev B. These two standards work together. AS9100 tells you that FAI must happen; AS9102 tells you exactly how to document it. A compliant FAI package under AS9102 consists of three primary documents: the Design Characteristic Accountability (Form 1), the Material and Process Accountability (Form 2), and the Functional Test Results Accountability (Form 3). Every dimension, tolerance, material specification, surface finish callout, and applicable note on the drawing must be ballooned and accounted for in Form 1. Partial FAIs — where only a subset of characteristics are inspected — are only permissible under specific conditions such as changes to a subset of features. Full FAI is required for new parts, new suppliers, design changes, and process changes that affect form, fit, or function. When Nimble’s certified partner network delivers production parts, CMM inspection is included — but confirm with your program requirements whether a full AS9102-compliant FAI package is required, because that’s a distinct deliverable from standard dimensional inspection. FAI records must be retained for the life of the program plus a defined period — typically the contract-specified retention period, but not less than what AS9100 Clause 7.5 requires for documented information.
A ‘ballooned drawing’ isn’t optional on an FAI — every characteristic must be individually numbered and traceable to a measurement record. If your supplier’s FAI package doesn’t have this, it’s not AS9102-compliant.

Risk Management Under Rev D — What Changed from Rev C

One of the most significant shifts in Rev D is the formalization of risk-based thinking throughout the QMS. Under Rev C, risk management was implicit — a good shop did it, but the standard didn’t rigorously require documented processes. Rev D changes that. Clause 6.1 requires suppliers to identify risks and opportunities relevant to the QMS context and implement actions proportional to those risks. For aerospace manufacturing specifically, this shows up in operational planning, process controls, and supplier management. A Rev D-compliant shop should be able to show you their risk register for a given part or process — what failure modes were identified, what probability and severity ratings were assigned, and what mitigations are in place. This is not FMEA in the traditional AIAG sense, though suppliers may use FMEA as their risk analysis tool. The key word is documented. Risk that lives in a machinist’s head isn’t compliant. From a buyer’s perspective, this requirement gives you a legitimate audit hook. During supplier qualification, ask to review the risk management process documentation and a sample risk register. A supplier who cannot produce these quickly either doesn’t have them or doesn’t understand the standard — both are red flags. Risk management quality correlates strongly with on-time delivery and escape rates in practice.

Supplier Qualification — What to Look for Beyond the Certificate

Certification is necessary but not sufficient. The audit that generated a supplier’s AS9100 certificate happened at a point in time — your purchase order ships today. The gap between those two moments can hold a lot of quality erosion. Effective supplier qualification for aerospace work goes beyond certificate verification. Request and review the supplier’s most recent surveillance audit report from their Certification Body. Look at the number of findings, the severity classification (major vs. minor), and the CAPA closure status. A major finding that’s still open is a serious concern. Also request the supplier’s internal nonconformance rate and customer escape rate for the prior 12 months. Shops with mature QMS operations track these metrics and report them without hesitation. Shops that don’t know their own escape rate are telling you something important. For machined components, review their inspection capability — CMM brand, calibration records, measurement system analysis (MSA) data for critical dimensions. For castings or forgings, verify NADCAP status for applicable special processes. Configuration management capability matters too: can the supplier demonstrate revision control on traveler documents, work instructions, and tooling records? At Nimble, our certified partner network is pre-qualified against these criteria — buyers don’t have to run qualification audits on individual shops to access AS9100-certified capacity.
A major finding on a surveillance audit isn’t automatically disqualifying — but an open major finding with no CAPA plan is. Ask for the CAPA records, not just the certificate.

Purchase Order Flow-Down Requirements for AS9100 Programs

Your purchase order language is a legal and contractual instrument — and for AS9100 programs, it needs to be written accordingly. Vague quality clauses like ‘supplier shall maintain quality standards’ are worthless in an audit or a dispute. Flow-down requirements must be specific, traceable, and enforceable. At minimum, your PO quality clauses for AS9100 work should reference: the applicable AS9100 revision (Rev D), any prime contractor-specific quality management system requirements (QMSRs), customer notification requirements for process or design changes, right-of-access provisions for you and your customer to audit supplier facilities, record retention requirements (typically 10 years minimum for aerospace hardware, but confirm with your contract), and FAI requirements including the applicable AS9102 revision. If your parts are subject to ITAR, that flow-down must be explicit and separate — ITAR is a legal obligation, not a quality requirement, and it needs to be called out on the PO. For programs with government oversight (DCMA, FAA Production Approval Holder requirements), confirm which additional clauses apply. DCMA-INST 8210.1 and FAA Order 8120.22 both have specific supplier documentation requirements that AS9100 alone doesn’t fully address. Getting flow-down language right at the PO stage prevents nonconformances, disputes, and program delays downstream.
Right-of-access language is frequently omitted from aerospace POs. Without it, you have no contractual basis to audit a supplier’s facility if a quality escape occurs. Include it on every aerospace PO.

Maintaining Compliance Through the Production Lifecycle

AS9100 certification is a surveillance-based system — suppliers undergo annual surveillance audits and a full re-certification audit every three years. But the standard’s requirements don’t pause between audits, and neither should your oversight. Supplier quality engineers (SQEs) who treat certification as a one-time gate check are setting themselves up for escapes. Production lifecycle compliance means monitoring supplier performance metrics continuously: on-time delivery, first-pass yield, nonconformance rates, and CAPA effectiveness. Schedule periodic supplier performance reviews — quarterly for critical sole-source suppliers, annually minimum for standard suppliers. Review any customer notifications of process changes your supplier sends — these are required under Rev D Clause 8.1.3, and if they’re not coming, either nothing is changing (unlikely in a healthy production operation) or the supplier isn’t complying with the notification requirement. Configuration management deserves specific attention over long production runs. Drawing revisions, specification updates, and material substitutions all require documented change control. Request periodic configuration audits to verify that what the supplier is building matches the current released configuration. For high-volume programs, statistical process control (SPC) data is a valuable ongoing compliance tool — a capable supplier running SPC on critical features can demonstrate process stability with data, not just inspection results. Nimble’s sourcing model keeps certified partners accountable through structured performance tracking on every active program.

READY TO SOURCE?

Get a quote from Nimble’s certified partner network.

Upload your drawings and get a detailed quote within 24 hours. Free DFM review included.

Request a Quote →

// NIMBLE MANUFACTURING

Precision parts, quoted in 24 hours.

AS9100 and ISO 9001 certified partner network. CNC machining, sheet metal, injection molding, and more.