Aerospace-and-defense suppliers increasingly carry two obligations at once: a quality standard (AS9100, soon IA9100) and a cybersecurity mandate (CMMC, built on NIST SP 800-171). Historically these lived in separate binders owned by separate teams. IA9100 changes that by pulling information security directly into the quality management system — so the two frameworks now overlap far more than they diverge.
Track the IA9100 standard as it develops
IA9100 is a moving target — clause content, the timeline, and the rebrand are still being finalized, and revisions will keep posting through 2027. Bookmark SAE’s official IA9100 page and check back often. It is the primary source we watch, and the fastest way to catch changes before they reach your certification cycle.
Track the latest IA9100 developments at SAE → Tip: bookmark this article and the SAE page — we refresh our guidance as the standard evolves.Why they are converging
IA9100’s new digital-and-infrastructure-security clause brings cyber controls into QMS scope and aligns them with CMMC and NIST 800-171. In practice, DFARS and CMMC obligations can be treated as customer-specific requirements inside the QMS and assessed with the same risk-based discipline you already apply to quality.
Where the two frameworks map
Many QMS clauses you already operate are, in substance, the same control a CMMC assessor is looking for:
- Configuration management (QMS 8.1.2) ↔ NIST 3.4 Configuration Management.
- Control of documented information (7.5) ↔ Access Control, Audit & Accountability, Media Protection (3.1 / 3.3 / 3.8).
- Nonconformance & corrective action (8.7 / 10.2) ↔ Incident Response (3.6) and the CMMC Plan of Action & Milestones.
- Control of external providers (8.4) ↔ supply-chain flow-down (3.1.20).
- Risk-based thinking (6.1) ↔ Risk Assessment (3.11).
- Internal audit (9.2) ↔ Security Assessment (3.12).
- Competence & awareness (7.2 / 7.3) ↔ Awareness & Training (3.2).
The practical payoff
When you map the frameworks to each other, you can run one management system instead of two:
- Collect evidence once, use it twice — document control, CAPA, supplier flow-downs, risk register, and training records serve both audits.
- One corrective-action engine — your QMS CAPA process feeds the CMMC POA&M.
- One integrated internal audit — test a control once and report to both programs.
- Aligned calendars — time the CMMC annual affirmation to your IA9100 surveillance audit, and the CMMC triennial to your IA9100 recertification.
One note on timing: as of mid-2026 the Department of Defense paused the CMMC third-party assessment requirement (currently a triennial self-assessment plus annual affirmation). Confirm the exact requirement in your contracts.
New to the aerospace transition? Start with AS9100 to IA9100: what contractors should expect.