Aerospace-and-defense suppliers increasingly carry two obligations at once: a quality standard (AS9100, soon IA9100) and a cybersecurity mandate (CMMC, built on NIST SP 800-171). Historically these lived in separate binders owned by separate teams. IA9100 changes that by pulling information security directly into the quality management system — so the two frameworks now overlap far more than they diverge.

Why they are converging

IA9100’s new digital-and-infrastructure-security clause brings cyber controls into QMS scope and aligns them with CMMC and NIST 800-171. In practice, DFARS and CMMC obligations can be treated as customer-specific requirements inside the QMS and assessed with the same risk-based discipline you already apply to quality.

Where the two frameworks map

Many QMS clauses you already operate are, in substance, the same control a CMMC assessor is looking for:

  • Configuration management (QMS 8.1.2) ↔ NIST 3.4 Configuration Management.
  • Control of documented information (7.5) ↔ Access Control, Audit & Accountability, Media Protection (3.1 / 3.3 / 3.8).
  • Nonconformance & corrective action (8.7 / 10.2) ↔ Incident Response (3.6) and the CMMC Plan of Action & Milestones.
  • Control of external providers (8.4) ↔ supply-chain flow-down (3.1.20).
  • Risk-based thinking (6.1) ↔ Risk Assessment (3.11).
  • Internal audit (9.2) ↔ Security Assessment (3.12).
  • Competence & awareness (7.2 / 7.3) ↔ Awareness & Training (3.2).

The practical payoff

When you map the frameworks to each other, you can run one management system instead of two:

  • Collect evidence once, use it twice — document control, CAPA, supplier flow-downs, risk register, and training records serve both audits.
  • One corrective-action engine — your QMS CAPA process feeds the CMMC POA&M.
  • One integrated internal audit — test a control once and report to both programs.
  • Aligned calendars — time the CMMC annual affirmation to your IA9100 surveillance audit, and the CMMC triennial to your IA9100 recertification.
The external certifications stay separate — IA9100 runs under the IAF/ANAB scheme and CMMC under the Cyber-AB/C3PAO scheme. What you unify is the internal program and evidence, which is where most of the audit overhead lives.

One note on timing: as of mid-2026 the Department of Defense paused the CMMC third-party assessment requirement (currently a triennial self-assessment plus annual affirmation). Confirm the exact requirement in your contracts.

New to the aerospace transition? Start with AS9100 to IA9100: what contractors should expect.