A defense purchase order often stacks two different jobs on one shop: a quality management requirement (ISO 9001, and sometimes AS9100) and a cybersecurity requirement under the Defense Federal Acquisition Regulation Supplement (DFARS). They are not substitutes. An ISO 9001 certificate does not satisfy DFARS 252.204-7012, and a NIST SP 800-171 system does not satisfy clause 8.4 of ISO 9001.
Six to nine months is typical for a first certification. That planning range is for the quality system — documentation, operating records, internal audit, management review, then Stage 1 and Stage 2 with an accredited certification body. DFARS cybersecurity work runs on its own calendar and its own evidence.
This guide shows how to tell those obligations apart, which ISO 9001:2015 clauses the quality clauses usually land on, and what to get in writing before you bid.
Two obligations on one purchase order
Primes and the government pass requirements down the supply chain. Quality flow-down is how they meet their own ISO 9001 or AS9100 duty to control suppliers. Cyber flow-down is how they meet DFARS rules for covered defense information. A buyer can put both on the same form. Reading them as one "compliance package" is how shops buy the wrong work.
| What the PO names | What it is asking | What does not satisfy it |
|---|---|---|
| ISO 9001:2015 or AS9100 | Conformance to the named quality-management standard; an accredited certificate only when the contract expressly requires one. | A CMMC level, a NIST SP 800-171 self-assessment, or an IT policy binder |
| DFARS 252.204-7012, 7019, 7020, or 7021 | Safeguarding covered defense information; NIST SP 800-171 and, where named, CMMC | An ISO 9001 or AS9100 certificate |
| FAR 52.246-11 or a lettered quality clause | A stated contract quality requirement — often ISO 9001 or AS9100 by revision | A verbal "you need ISO" from purchasing |
ISO 9001 clauses the quality clauses hit
When the quality text names ISO 9001:2015, these are the clauses that usually carry the work. AS9100 reprints ISO 9001 and adds aerospace and defense controls on top; the ISO 9001 clauses below still apply.
Clause 4.2 — interested parties
Clause 4.2 requires you to determine the interested parties that affect your quality system and what those parties require. On defense work that list is not generic. It includes the prime, the end customer, and often DCMA. Write down what each one requires of you — certificate, right of access, record retention, traceability — and keep that list with your scope. If you ignore 4.2, contract quality clauses show up later as surprise "customer requirements" during the audit.
Clause 8.2.2 — determining product requirements
Clause 8.2.2 is where you capture what the customer asked for, including statutory and regulatory requirements. For a defense PO that means reading the quality clauses, the drawing notes, the specification list, and any referenced supplier quality manual — not just the line-item description. If a Q-clause names AS9100 Rev D, clause 8.2.2 is how that fact enters your system before anyone cuts a chip.
Clause 8.4.3 — information for external providers
Clause 8.4.3 is flow-down to your own suppliers. If the prime flowed a quality requirement to you, you communicate the relevant parts to the shops that make your parts, apply finishes, or run special processes. "We are ISO 9001" on your website does not flow anything. Purchase orders to your suppliers should name the applicable specifications, record requirements, and any right-of-access terms you accepted.
Clause 8.5.2 — identification and traceability
Clause 8.5.2 is identification and, where required, traceability. Defense drawings and quality clauses often require heat-lot, serial, or unique-item traceability back through your suppliers. Build that into receiving, in-process identification, and shipping paperwork. Losing the chain is a quality finding under 8.5.2; it is not a DFARS cyber finding.
When the prime names AS9100
AS9100 contains the full text of ISO 9001:2015 plus aerospace and defense additions: product safety, counterfeit-part prevention, configuration management, and stronger flow-down. One AS9100 audit covers both sets of requirements, and certificates are published in OASIS. If the PO names AS9100, ISO 9001 alone is not the requirement. If the PO names ISO 9001, do not spend AS9100 money on speculation.
Confirm the revision in writing. Buyers say "AS9100" the way they say "ISO." The revision on the clause is the one you will be audited against.
What DFARS cybersecurity is asking
DFARS 252.204-7012 requires contractors to provide adequate security for covered defense information and to report cyber incidents. Related clauses (7019, 7020, 7021) point at NIST SP 800-171 assessments and, where the contract says so, CMMC. That work lives in IT controls, incident response, and how you handle CUI — not in your calibration stickers or CAPA log.
- ISO 9001 clause 7.5 controls documented information for the quality system. It does not implement NIST SP 800-171.
- A Stage 1 or Stage 2 quality audit does not assess DFARS cyber clauses.
- A CMMC assessment does not sample your nonconforming-output process under ISO 9001 clause 8.7.
If the PO has both, staff them as two projects. The quality project produces a QMS and, if the contract requires it, a certificate from a body accredited under ISO/IEC 17021-1. The cyber project produces the NIST/CMMC evidence the DFARS clauses name. Mixing the evidence packages confuses both auditors.
Planning the quality work
Six to nine months is typical for a first certification. Documentation can be written in weeks. The certification body evaluates at Stage 1 whether implementation, records, the completed internal audit and management review demonstrate readiness for Stage 2 — a few months of records is the usual expectation, not a fixed rule. Typical records include receiving, identification, nonconforming output (clause 8.7), and supplier control. IAF MD 5 starts audit time from effective personnel and adjusts for complexity, shifts, sites and scope. None of that calendar is a DFARS cyber timeline.
A $500 Readiness Report maps ISO 9001 shall-statements to how your shop runs. The $8,000 Full documentation package is manuals and policies, procedures, work instructions, and forms, sized to how your company runs. No documentation provider issues a certificate; only an accredited certification body does that. The Public-surface scan is a free first look at what your public site already shows.
- Pull the PO quality clauses and any DFARS cyber clauses into two lists.
- Write down the quality standard, revision, and whether a certificate is required.
- Map quality clauses onto 4.2, 8.2.2, 8.4.3, and 8.5.2, then the rest of clauses 4 through 10.
- Send the cyber list to whoever owns IT and CUI handling — not to the quality manual.
Frequently asked questions
Does ISO 9001 satisfy DFARS 252.204-7012?
No. ISO 9001 is a quality management standard. DFARS 252.204-7012 is a cybersecurity clause about safeguarding covered defense information. A quality certificate is not NIST SP 800-171 evidence, and a cyber assessment is not an ISO 9001 audit.
If the prime wants AS9100, is ISO 9001 enough?
Only if the written requirement says ISO 9001. AS9100 includes ISO 9001 plus aerospace and defense additions, and primes that name AS9100 usually check OASIS. Get the standard and revision in an email before you spend.
Which ISO 9001 clauses matter most on a defense PO?
Start with 4.2 (interested parties), 8.2.2 (determining product requirements), 8.4.3 (information for external providers), and 8.5.2 (identification and traceability). Those four are where quality clauses, flow-down, and lot or serial control typically land. The rest of clauses 4 through 10 still apply.
How long does the quality certification path take?
Six to nine months is typical for a first certification. Documentation is the short part. Operating records, an internal audit, a management review, and the registrar's Stage 1 and Stage 2 schedule set the floor.
Can a documentation provider certify us for defense work?
No. A documentation provider can write the QMS. An accredited certification body, audited under ISO/IEC 17021-1, is the only party that issues an ISO 9001 or AS9100 certificate. The conformity decision stays with that body.