Logo

About Us

Careers

Pricing

AS9100 to IA9100 Changes: What’s Changing in 2026 and How Your ERP Must Adapt

NL

Nana Luz

12 mins
Blog Cover

The AS9100 to IA9100 changes center on tighter integration between quality risk, cyber risk, supplier oversight, and audit evidence. For an AS9100D-certified aerospace supplier, that means your ERP and QMS stack has to do more than track parts and inspections. It has to show a defensible, retrievable control trail across work orders, suppliers, risk plans, and incident response.

Take Softype’s 15-minute NetSuite Readiness Assessment for a fast view of where your current operating stack may fall short before IA9100 transition work starts in earnest.

AS9100 to IA9100 changes are about proof, not branding

The phrase as9100 to ia9100 changes sounds like a naming update, but that undersells what quality leaders should be preparing for. The International Aerospace Quality Group has already moved to the IA naming convention for globally harmonized aerospace standards, and the broader 9100-series revision is being synchronized with the ISO 9001 revision cycle now targeted for 2026. The next release is increasingly discussed as a standards update that sharpens how organizations demonstrate risk control, documented information control, supplier governance, and operational evidence.

For a QA Director, Quality Manager, or COO at a US aerospace parts supplier, the practical issue is not whether the certificate title changes from AS9100D to IA9100. It is whether your quality system, ERP workflows, and supporting cyber controls can show a clean chain of evidence when an auditor asks how risk is identified, documented, flowed into operations, and closed out.

This is why the as9100 revision 2026 conversation is increasingly tied to wider compliance language such as DFARS 252.204-7012, NIST SP 800-171 Rev. 2, and CMMC 2.0. These frameworks are not the same as IA9100, but they shape how many aerospace suppliers think about access control, incident response, and evidence integrity. That makes them relevant context for the transition rather than direct substitutes for the standard itself.

What is changing from AS9100D to IA9100?

The clearest way to think about IA9100 is as an update that is expected to keep the familiar clause backbone while tightening how aerospace organizations manage higher-risk operating conditions. Current industry discussion around ia9100 2026 points toward stronger treatment of information security, risk-based auditing, supplier visibility, measurement evidence, product safety, and culture. Because the final text is still not published, quality leaders should distinguish between confirmed source material and widely discussed direction-of-travel themes.

One of the most important anticipated shifts is a tighter connection between cyber risk and the quality risk plan itself. If a ransomware event, access-control weakness, supplier breach, or file-integrity issue can affect product conformity, traceability, or release decisions, then many quality leaders will need to treat it as a quality-system issue, not just an IT issue.

AS9100D vs IA9100: what changes quality teams should expect

Area

AS9100D baseline

IA9100 direction of change

Standard identity

Regional naming under AS9100, EN9100, JIS Q 9100

Global IA prefix to align publication and change control across regions

Quality risk planning

Risk-based thinking is required, but many teams keep cyber risk outside the quality plan

Tighter expectation that cyber risk affecting conformity, records, or delivery is evaluated inside the operating risk model

Documented information

Control is required, but many sites still rely on mixed manual and shared-folder governance

Greater emphasis on access control, integrity, retention, approval history, and electronic evidence

Supplier oversight

Approved supplier control often centers on direct suppliers

More scrutiny on sub-tier visibility, counterfeit exposure, distributor chain, and supplier risk signals

Audit evidence

Evidence can be spread across ERP, spreadsheets, folders, and emails

Higher expectation for fast, consistent retrieval of linked operational evidence

Cyber-control alignment

Often handled in a separate IT or contract-compliance stream

Stronger conceptual link to DFARS 7012, NIST 800-171, and CMMC-style control discipline where cyber events affect quality execution

Why cyber risk is the most important IA9100 story for aerospace operations

Illustration of cyber risk controls connected to aerospace quality records, supplier data, and manufacturing systems

The most consequential shift for many certified suppliers is not a new form or a renamed certificate. It is the way ia9100 cyber risk requirements are likely to pull information security into day-to-day quality management. A compromised drawing, altered work instruction, inaccessible traveler, or corrupted inspection history can create a quality failure just as surely as a bad lot or an unapproved supplier can.

That is why aerospace quality teams should start treating cyber risk as an operational-quality input, not as a separate IT appendix. Under DFARS 252.204-7012, covered defense information and cyber incident reporting already sit inside many aerospace contract environments. NIST SP 800-171, while superseded by a newer revision for official publication purposes, remains deeply embedded in how defense suppliers talk about safeguarding controlled information and system access. CMMC 2.0 then raises the bar on how consistently those controls are assessed.

In practical terms, your quality risk plan should be able to answer questions like these:

  • Which cyber events could compromise revision-controlled production data?

  • Which roles can alter inspection, nonconformance, or release records?

  • How is supplier cyber exposure considered when that supplier handles sensitive drawings, test data, or customer requirements?

  • What is the escalation path if system integrity affects product disposition or delivery?

For the standards side, teams should monitor IAQG for 9100-series governance updates, the ISO 9001 revision timeline for the current 2026 schedule, and NIST guidance for the cyber-control context. That source trail matters because it helps separate confirmed publication updates from industry interpretation.

What the ERP has to do differently under the IA9100 transition

An aerospace quality management erp setup that was acceptable under AS9100D may still process transactions well, but that does not mean it will satisfy the evidence burden quality teams are moving toward. The transition question is no longer “Do we have ERP?” It is “Can our system show how risk, quality, supplier control, and cyber exposure connect at the transaction level?”

The IA9100 readiness work usually breaks into four concrete workflow changes. The question is less about buying a new platform immediately and more about whether your current ERP plus QMS stack can expose risk, approvals, supplier controls, and audit evidence at the record level.

1. Add a cyber-risk-tagged nonconformance workflow

Most nonconformance processes classify issues by material, dimensional, supplier, process, or documentation cause. Under the next wave of aerospace controls, quality teams should also be able to tag events where the trigger or impact is cyber-related. That includes unauthorized document changes, access violations affecting inspection records, corrupted work instructions, unavailable systems blocking release checks, or supplier incidents that compromise required data.

The goal is not to turn every quality team into a security team. It is to create a visible branch in the workflow that distinguishes ordinary production defects from control-integrity events with cyber-risk implications. In a better-configured operating stack, that classification becomes searchable, reportable, and auditable instead of living in free-text notes.

2. Link the risk-plan document to work orders and change activity

A credible quality plan aerospace 2026 approach cannot leave the risk plan in a static document repository disconnected from operations. If the risk plan says a process, part family, or customer program has elevated exposure, the ERP and quality workflow should make that visible where work is planned and executed.

At minimum, teams should be able to connect risk classification to work orders, inspection checkpoints, engineering changes, release approvals, and affected supplier records. If an auditor asks how a known risk changed the operating process, the answer should live in the execution record, not in a meeting note or email thread.

3. Add supplier cyber-risk scoring to the vendor record

AS9100D supplier control often focuses on approvals, certifications, delivery performance, and part quality. IA9100 pressure is likely to push that further. Aerospace suppliers increasingly need a structured view of whether a vendor introduces risk through weak information handling, poor access discipline, unmanaged subcontracting, or uncontrolled external sharing of technical data.

That does not mean every vendor needs a full cyber audit. It does mean your supplier record should support a practical risk tier, review date, evidence reference, and escalation path. If a supplier touches controlled information or critical process knowledge, their cyber posture can influence your quality exposure.

See how manufacturing teams in Detroit structure operational controls or compare the Boston manufacturing workflow view for regional examples of how more mature manufacturing stacks connect operations and governance.

4. Build an auditor-ready evidence trail

Illustration of an audit-ready aerospace evidence trail linking work orders, approvals, supplier records, and quality events

This is where many mixed-tool environments fail. The ERP may hold part, lot, routing, and purchasing history. The quality tool may hold CAPAs and nonconformances. The finance system may still be separate. Shared folders may hold risk plans and customer flow-downs. Email may hold approvals that never made it back into the operating record.

That architecture works until the question becomes time-bound and evidence-specific. Then quality teams spend days reconstructing what should have been traceable in minutes. The IA9100 direction favors systems that can retrieve one coherent story: the part, the revision, the supplier, the risk rating, the nonconformance, the approval sequence, and the final disposition.

NetSuite Advanced Manufacturing plus Softype configuration vs a quality-tool-plus-QuickBooks stack

Your reader is not shopping for ERP from scratch, so this comparison stays narrow. The question is not “Which platform is best?” It is “Which architecture is more likely to support the AS9100 to IA9100 changes without forcing manual evidence assembly?”

Operating area

NetSuite Advanced Manufacturing + Softype configuration

Quality tool + QuickBooks stack

Work-order-linked risk controls

Connects work orders, routing steps, approvals, item records, and custom risk fields in one operating flow

Often split between a finance tool, spreadsheets, and a standalone quality layer with weaker operational context

Cyber-risk-tagged nonconformance

Configured with structured classifications, escalation logic, and linked operational evidence

Often managed as a separate ticket or note outside the main transaction trail

Supplier cyber-risk scoring

Lives on the supplier record with review dates, tiers, and downstream reporting

Often tracked in a side spreadsheet or document folder, disconnected from receiving and purchasing history

Audit retrieval speed

Stronger potential for one-path retrieval when configuration is disciplined

Higher dependence on manual evidence gathering across disconnected tools

Change governance

Better fit for role-based approvals and linked record history

More likely to rely on informal workarounds outside the main operating system

The important nuance is this: software alone is not the answer. Configuration discipline is the answer. The real comparison is not just ERP versus accounting software. It is unified operating evidence versus stitched-together evidence. For teams assessing whether their current architecture can support the transition, Softype’s comparison of NetSuite vs QuickBooks Enterprise and its guide to when businesses outgrow QuickBooks provide useful background.

What to do in the next 90 days

The smartest response to the transition is not a large software project on day one. It is a focused 90-day readiness sprint that exposes where your current control model breaks.

Step 1: map where risk, quality, and cyber records live

Document where the risk plan, supplier reviews, nonconformances, engineering changes, inspection evidence, access approvals, and customer flow-downs are actually stored today. Do not document the intended process. Document the real one.

Step 2: identify where the quality plan ignores cyber-triggered failure modes

Review the existing risk plan and ask whether it accounts for data integrity, access compromise, document tampering, system outage, or supplier cyber incidents that could affect conformity or on-time delivery. If not, the risk model is already behind the operating reality.

Step 3: add structured fields before you redesign the whole stack

Before launching a bigger system project, add the minimum fields needed to make risk visible now: cyber-risk classification on nonconformances, supplier cyber tier, review date, linked risk-plan reference, and a flag that ties elevated-risk jobs to approval controls.

Step 4: test one end-to-end audit scenario

Pick one job, one supplier, one engineering change, and one elevated-risk event. Then see how quickly your team can produce the complete story. If the answer depends on asking three departments and searching inboxes, the evidence model is not strong enough yet.

Step 5: align the quality roadmap with contract-compliance reality

If your customers already invoke DFARS 7012 or expect NIST 800-171 and CMMC maturity, your quality transition plan should not be built in isolation. The cyber-control conversation and the quality-evidence conversation are converging whether the org chart reflects that or not.

Download the Assembly Manufacturing ERP Checklist for a practical starting point on identifying workflow gaps while a dedicated IA9100 checklist is still being built.

External references quality leaders should monitor

  • IAQG for official 9100-series governance and publication updates

  • ISO 9001 revision updates for current 2026 timing and development status

  • NIST SP 800-171 Rev. 2 as the established defense-supplier reference point many teams still map against, while noting that NIST has since issued a newer revision

  • DFARS 252.204-7012 for contract language that shapes how many defense suppliers frame cyber controls and incident response

These sources do not remove every uncertainty around the final IA9100 release language, but they do make the direction clear enough to start remediation planning now. Method note: this article separates confirmed source material, such as IAQG governance pages, ISO revision updates, DFARS text, and NIST publications, from anticipated implementation themes that are still being discussed ahead of final release.

FAQ

When does IA9100 become mandatory?

The exact mandatory date still depends on final publication timing and transition rules, which have shifted. Most aerospace teams should expect a formal transition window after release rather than an immediate cutover, but planning should start before the final deadline is announced.

Does IA9100 replace AS9100 or supplement it?

IA9100 is expected to replace the current regional naming approach rather than sit beside AS9100 as a separate parallel standard. Certified organizations should expect a transition from AS9100D-era certification to the new IA-labeled standard once transition rules are published.

How does IA9100 change my ERP setup?

The biggest change is that ERP must support stronger evidence linkage across risk plans, suppliers, approvals, nonconformances, and document control. A system that only processes jobs and purchasing transactions is unlikely to be enough on its own.

Do I need a new quality-risk plan?

You may not need an entirely new plan, but many organizations will need to expand the current one. If cyber events, supplier information exposure, or document-integrity failures could affect conformity, those risks should be visible in the active quality-risk model.

How does IA9100 connect to CMMC 2.0?

IA9100 and CMMC 2.0 are different frameworks, but they increasingly touch the same operating reality. If cyber controls affect access, data integrity, supplier trust, or audit evidence, the quality team and the compliance team can no longer work in separate lanes.

Will my current AS9100D certificate still be valid?

Current certificates should remain valid until formal transition rules take effect, but organizations will eventually need to migrate within the defined transition period. The safest assumption is that waiting until the last minute will create unnecessary audit pressure.

Do I need to replace QuickBooks immediately to prepare for IA9100?

No, not immediately. But if your evidence trail depends on a finance tool, a separate quality app, spreadsheets, and shared folders with no clean operational linkage, expect more friction as the standard raises the proof burden.

What should I do first if I am not ready to re-platform yet?

Start with a control-gap review. Map where your risk plan, supplier review process, approval records, and nonconformance evidence live today, then identify the highest-risk breaks in traceability and retrieval.

The bottom line for aerospace suppliers

The as9100 to ia9100 changes matter because they move the conversation from “Do we have procedures?” to “Can we prove how risk is controlled inside real operations?” For aerospace suppliers already certified to AS9100D, the most important work is tightening how quality risk, cyber risk, supplier governance, and operational evidence connect in the live system.

If your current stack still depends on a quality tool plus QuickBooks plus manual reconciliation, the next revision cycle is the right moment to expose those gaps before an auditor does. If your team is already on NetSuite, the question becomes how to configure manufacturing and quality workflows so the evidence trail is visible, role-controlled, and retrievable.

Book a 30-minute IA9100 readiness call for a focused review of where your current operating model is likely to break under the next 9100-series transition.

Profile photo of Nana Luz

Nana Luz

Nana co-founded Softype in Palo Alto more than 25 years ago and has since helped shape ERP programs for 500+ companies across North America, Southeast Asia, South Asia, and Sub-Sah…
Softype Logo

Helping businesses thrive with integrated ERP solutions.

NetSuite

NetSuite ERP

NetSuite Planning &

Budgeting

NetSuite Analytics

Warehouse

NetSuite SuiteSuccess

Oracle NetSuite Pricing

SuiteWorld 2024 Highlights

Service

ERP Implementation

ERP Support &

Managed Services

ERP Rescue &

Reimplementation

Company

Blogs

About Us

Careers

Case Studies

History

Contact Us

USA: +1 650 422 9088
India: +91 22 4616 3839
Kenya: +254 720 940 174
Philippines: +63 917 558 1513
Philippines: +63 917 188 8113

Mexico: +52 221 120 6441

info@softype.com

Copyright © 2026

Terms & Conditions

Privacy Policy

Disclaimer

iconicon