Aerospace-and-defense suppliers increasingly carry two obligations at once: a quality standard (AS9100, soon IA9100) and a cybersecurity mandate (CMMC, built on NIST SP 800-171). Historically these lived in separate binders owned by separate teams. IA9100 changes that by pulling information security directly into the quality management system — so the two frameworks now overlap far more than they diverge.
Why they are converging
IA9100’s new digital-and-infrastructure-security clause brings cyber controls into QMS scope and aligns them with CMMC and NIST 800-171. In practice, DFARS and CMMC obligations can be treated as customer-specific requirements inside the QMS and assessed with the same risk-based discipline you already apply to quality.
Where the two frameworks map
Many QMS clauses you already operate are, in substance, the same control a CMMC assessor is looking for:
- Configuration management (QMS 8.1.2) ↔ NIST 3.4 Configuration Management.
- Control of documented information (7.5) ↔ Access Control, Audit & Accountability, Media Protection (3.1 / 3.3 / 3.8).
- Nonconformance & corrective action (8.7 / 10.2) ↔ Incident Response (3.6) and the CMMC Plan of Action & Milestones.
- Control of external providers (8.4) ↔ supply-chain flow-down (3.1.20).
- Risk-based thinking (6.1) ↔ Risk Assessment (3.11).
- Internal audit (9.2) ↔ Security Assessment (3.12).
- Competence & awareness (7.2 / 7.3) ↔ Awareness & Training (3.2).
The practical payoff
When you map the frameworks to each other, you can run one management system instead of two:
- Collect evidence once, use it twice — document control, CAPA, supplier flow-downs, risk register, and training records serve both audits.
- One corrective-action engine — your QMS CAPA process feeds the CMMC POA&M.
- One integrated internal audit — test a control once and report to both programs.
- Aligned calendars — time the CMMC annual affirmation to your IA9100 surveillance audit, and the CMMC triennial to your IA9100 recertification.
One note on timing: as of mid-2026 the Department of Defense paused the CMMC third-party assessment requirement (currently a triennial self-assessment plus annual affirmation). Confirm the exact requirement in your contracts.
New to the aerospace transition? Start with AS9100 to IA9100: what contractors should expect.