For decades, the barrier to entry for the aerospace supply chain has been formidable. Machine shops, job shops, contract manufacturers, and “make-to-print” providers have often found themselves locked out, not because their products lacked quality, but because the administrative burden of AS9100 certification was too heavy for their size. That is about to change with the upcoming release of IA9150.
What is IA9150?
Originally scheduled for release in late 2026, the IA9150 standard is now anticipated for release during mid-2027. It will be a streamlined, certifiable quality management system (QMS) developed by the International Aerospace Quality Group (IAQG). Unlike guidance documents, this is an entry-level certification standard designed specifically for small businesses producing low-to-moderate complexity products, particularly those that are not design-responsible.
While it has been rumored that IA9150 will NOT use ISO 9001:2026 as its foundation, this remains to be seen, as the final text remains under development.
Its primary mission is to lower the entry barrier for entities like machine shops, job shops, and contract manufacturers that play critical roles in the supply chain but cannot justify the cost and complexity of a full IA9100 (formerly AS9100) system.
Key Differences: IA9150 vs. IA9100
While IA9100 is the comprehensive standard for prime contractors and large Tier 1 suppliers, IA9150 offers a targeted alternative:
Reduced Administrative Burden: IA9150 strips away non-essential requirements that often **bog down small businesses**, focusing strictly on what impacts product safety and quality.
Targeted Scope: It is tailored for simpler operations (e.g., machining, standard parts, powder coating), avoiding the complex risk management and configuration control mandates required for high-complexity systems unless necessary.
Certifiable Status: Like its larger counterpart, IA9150 will result in a formal certification, giving small suppliers the recognized credential needed to win contracts.
Why This Matters Now
The aerospace industry is facing a dual pressure: the transition to IA9100 (expected mid-2027) and, for government contractors, the mandatory integration of cybersecurity via CMMC.
For small businesses in the Defense Industrial Base (DIB), managing both simultaneously under the old framework was a formidable challenge. While CMMC is strictly mandatory for DoD contractors and their supply chain (flow-down), it is not a blanket requirement for commercial-only aerospace suppliers. However, the industry trend is toward integrated compliance. IA9150 provides a viable on-ramp. It allows small businesses to demonstrate compliance and reliability without the overhead of a system designed for large corporations.
Large aerospace companies have long demanded certifications that were out of reach for smaller entities like machine shops and powder coating operations, yet they were forced to use these suppliers regardless. IA9150 addresses this disconnect by providing a way for these smaller companies to demonstrate that their QMS is suitable for their customers, allowing them to bid on contracts that are currently cost-prohibitive.
The Bottom Line
If you’re a small business owner in the aerospace sector who has previously hesitated to pursue certification due to cost or complexity, IA9150 is your signal to prepare. While the final text is still in the Work in Progress (WIP) stage as of July 2026, the framework provides a path to the aerospace market, ensuring that capable suppliers are no longer stifled by bureaucracy.
International Aerospace Quality Group (IAQG). “Bridging the Gaps: The Development of the IA9150 Quality Management System.” IAQG Official Website. Available at: iaqg.org. (Accessed July 2026).
Context: Primary source confirming the development of IA9150 as a foundational QMS for smaller organizations and the involvement of the writing team lead from Lockheed Martin.
Quality Magazine. “Driving Change in Aerospace Quality Management.” Quality Magazine, May 13, 2026. Available at: qualitymag.com.
Context: Confirms IA9150 was originally scheduled for late 2026, describes it as a “streamlined, certifiable quality management system” for startups and niche manufacturers, and details the IAQG’s dual-track approach to standards revision.
Quality Magazine. “The Demand for Integrating Cybersecurity into Aerospace Quality.” Quality Magazine, July 2, 2026. Available at: qualitymag.com.
Context: Clarifies the timeline for IA9100 (late 2026) and explicitly notes IA9150 as a developing standard for smaller organizations. Discusses the separation of CMMC requirements for government contractors versus commercial aerospace.
Compliant Ltd. “ISO 9001:2026 and IA9100: Upcoming Quality Management Standards Revisions.” Compliant Ltd, 2026. Available at: compliantltd.com.
Context: Provides the projected release date for ISO 9001:2026 (September 2026) and explains the dependency of IA9100/IA9150 on this foundation, noting the uncertainty of final alignment until publication.
SAE International / Infohost. “Understanding Standards: The WIP Process.” Infohost, June 25, 2026. Available at: infohost.com.sg.
Context: Explains the SAE process where standards begin as a Work in Progress (WIP) before moving to balloting and final publication, supporting the current status of IA9150.
Amtivo. “Aerospace Standard Revision.” Amtivo, March 27, 2026. Available at: amtivo.com.
Context: Details the anticipated release window for revised aerospace standards (late 2026 to early 2027) and the transition periods for certification bodies and clients.
CVG Strategy. “IA9100 Series Standards Due for Release in 2026.” CVG Strategy, February 2, 2026. Available at: cvgstrategy.com.
Context: Outlines the rebranding from AS9100 to IA9100 and the comprehensive revision of the 91XX series, providing context for where IA9150 fits within the broader ecosystem.
You may have noticed that when you sign your 3-year contract with a Certification Body (CB), there is a fee associated with your AS91xx certificate. This fee is primarily to maintain the International Aerospace Quality Group (IAQG) OASIS (Online Aerospace Supplier Information System®) database.
Effective January 1, 2025, the International Aerospace Quality Group (IAQG) increased its certification fee structure.
Here’s an overview of the new certification fees:
Fee Description
Fee
Initial Certificate
$700.00
Re-Certification Certificate
$700.00
Certificate Transfer
$700.00
Certificate modification including adding a new site
We are always monitoring the upcoming changes in the standards that we support. This post is to share the current status of AS9100 (which will be renamed IA9100) and the impact of its changes.
Culture
The proposed IA9100 includes the following language regarding “culture”: § Leadership – Clause 5.1.1.k – (NEW) ensuring goals and objectives intended to build a quality culture are consistent with policies, vision, mission, values, and the context of the organization (See clause 4.).”
AND § Environment for the Operation of Processes – Clause 7.1.4 NOTE: d. – (NEW) culture (e.g., quality, ethical behavior, product and personnel safety, quality of work life).
My thoughts…
While sec. 5.1.1k is a requirement, I see this as nothing more than virtue signaling from IAQG; which will be highly subjective and effectively non-auditable. And the “Note” under sec. 7.1.4d is completely non-auditable.
Conclusion:
No impact.
Ethics
§ Leadership – Clause 5.1.1.l. – (New) promoting an ethical work environment – NOTE: For example, policy, expectations of conduct, periodic training and awareness, reporting channels, investigation, resolution of concerns, and ensuring no punitive action from reporting concerns)
§ Environment for the Operation of Processes – Clause 7.1.4 NOTE: d. – (NEW) culture (e.g., quality, ethical behavior, product and personnel safety, quality of work life).
My thoughts…
I see “5.1.1.l. – promoting an ethical work environment” as just more virtue signaling (and perhaps a weak CYA for the industry). I feel fairly confident in this because the current requirements relating to ethics (shown below) are typically ignored by the AS9100 auditors.
§ Awareness – Clause 7.3 – the importance of ethical behavior
§ Information for External Providers – Clause 8.4.3 m.3. – the importance of ethical behavior.
Conclusion:
No impact.
Information Security and Data Protection (New)
§ 7.5.3.1 – Control of documented information (Enhanced)
When documented information is managed electronically, data protection processes shall be defined implemented, and maintained (e.g., protection from loss, access control, off-site data management, unauthorized changes, unintended alteration, corruption).
AND
§ 7.1.7 – Information Security (New)
The organization shall plan, implement, and control information security to safeguard the QMS to achieve its intended results.
My thoughts…
While some people in the Aerospace community are “losing their minds” that auditors will be mandating CMMC, that is NOT contained in either of these requirements. Also, notice that neither of these additions requires documented information. IMO, these additions are simply clarifications recognizing that we live in the 21st century.
Conclusion:
Minimal impact.
8.1.3 Product Safety (Enhanced)
The organization shall plan, implement, and control the processes needed to assure product safety. These processes include, as appropriate:
a. identification of hazards, including reactive and proactive methods;
b. analysis, assessment, and control of safety risks associated with identified hazards(see 8.1.1);
c. identification and management of changes that may impact product safety;
d. assessment of the effectiveness of safety processes (see 9.1.3 and 10.1);
e. provision of training on product safety responsibilities to relevant personnel (see 7.2 and 7.3);
f. communication and awareness of product safety information, including safety-critical information, safety events, and changes to safety procedures, as applicable (see 7.3 and 7.4);
g. reporting of safety events to the customer, authorities, and type certificate holder in accordance with customer and regulatory requirements.
My thoughts…
I find this addition very interesting considering that I’ve not gotten a consistent interpretation of what “Product Safety” is from any certification body (CB) Auditor. IAQG should have addressed this issue first.
For “Build-to-Print” machine shops, it’s typically interpreted as “protection” of the product from damage (e.g., rust, gouges, scrapes). For “Design-Responsible” manufacturers, it typically involves ensuring that end users are protected from a defective or malfunctioning product.
Ultimately, even though a “Risk Register” is not required, I believe that auditors will effectively “mandate” them in order to have some objective evidence to examine. Also, I suspect that auditors will be examining “Training” records relating to “Product Safety”.
Conclusion:
Moderate impact.
8.1.4 Prevention of Counterfeit Parts (Enhanced)
The organization shall plan, implement, and control processes, appropriate to the organization and the product, for the prevention of counterfeit or suspect counterfeit part use and their inclusion in product(s) delivered to the customer. These processes shall include, as applicable:
a. training of appropriate persons in the awareness and prevention of counterfeit parts (e.g., personnel involved in procurement, receiving inspection, shipping inspection and material control);
b. application of a parts obsolescence monitoring program;
c. controls for acquiring externally provided product from original or authorized manufacturers, authorized distributors, or other approved sources;
d. requirements for assuring traceability of parts and components to their original or authorized manufacturers;
e. verification and test methodologies to detect counterfeit parts;
f. monitoring of counterfeit parts reporting from external sources;
g. segregation, containment and reporting of suspect or detected counterfeit parts.
My thoughts…
Provided that a company is effectively complying with “a”, “c” & “d.” (above), I don’t think that very many of the above requirements will be “applicable” to the vast majority of IA9100 companies.
Conclusion:
Minimal impact.
Sub-tier Control
Clause 8.4.3.k.d. – (New) Determining the level of control of their direct and sub-tier external providers;
My thoughts…
This is simply an expansion of the current requirement in Clause 8.4.1: “The organization shall require that external providers apply appropriate controls to their direct and sub-tier external providers, to ensure that requirements are met.”
Since the AS9100 “Clarifications” document (i.e., official interpretations) has “clarified” that ALL of 8.4.3 must be either flowed down to suppliers OR excluded with justification, this is just one more thing for companies to add to the “Supplier Requirements”.
Conclusion:
Minimal impact.
Operational Planning and Control (Enhanced)
8.1.k. – planning and implementing operations to prevent, detect and mitigate the risk of foreign objects and debris.
My thoughts…
All I can say about this “new” requirement is… what took them so long? Auditors have been looking for FOD control since day 1 of AS9100D. This “new” requirement is merely the formalization of an “implied” requirement. However, while not specifically required, I suspect that IA9100 auditors will “expect” to see risk mitigation actions identified in a “risk register”… and records reflecting that personnel have been trained and deemed competent in control of FOD.
Conclusion:
Minimal impact.
Design and Development of Products and Services – Clause 8.3.2.1 – (Enhanced)
“When appropriate, The organization shall divide the design and development effort into distinct activities defining the tasks, necessary resources, responsibilities, design content, and inputs and outputs for each activity.”
My thoughts…
The biggest change here is the removal of “When Appropriate” AND the inclusion of “for each activity”. In my experience, the vast majority of AS9100 auditors are “generalists” (i.e., NOT Engineers). And typically do a poor job of auditing sec. 8.3. I doubt that very many AS9100 auditors are going to notice this subtle change.