Skip to content

Requirements

How to prepare for the defence supply chain

Practical overview of supply-chain structure, qualification and certifications for technology companies aiming to work in the European defence ecosystem.

Market context

The European context indicates stronger defence investment and rising demand for qualified suppliers. For SMEs, opportunities often emerge in critical software, cybersecurity, communications systems and embedded electronics.

How the supply chain works

Primes and Tier-1

Large system integrators with direct contracts with States and Armed Forces, subcontracting specialist suppliers.

Tier-2 suppliers

Companies delivering subsystems, software and components directly to Primes. This is usually the most common entry point for tech SMEs.

Tier-3 suppliers

Suppliers of parts, materials and support services. Even at this level, quality requirements and process evidence remain important.

AVL (Approved Vendor List)

Entry into the chain is typically based on formal qualification and AVL registration. The key is not only the product: it is proving reliable, repeatable and auditable processes with consistent documentation.

Priority certifications and requirements

ISO 9001

Minimum quality baseline
Baseline

It is often the starting point for qualification processes. On its own, it is usually not enough for more demanding defence contexts.

ISO 27001 + NIS2

Priority for software and sensitive data
Very high

Information security management and incident response have become central in critical chains. Even without direct legal scope, these requirements are frequently imposed contractually.

AQAP 2110 / 2210

NATO quality standard
High

Standards used in defence contracts with reinforced requirements for traceability, risk and quality. Relevant for suppliers targeting NATO contracts and direct-chain positioning.

CMMI (Level 3+)

Development process maturity
High

Helps demonstrate delivery predictability in critical software and services, and is valued by international integrators.

ASPICE (Level 2+)

Embedded software in critical systems
High

Especially relevant for contexts with strict traceability and validation requirements across the critical software lifecycle.

Start with the expression of interest

It is the first step to follow the programme and applications.

Cookie preferences

You can manage optional cookies used for measurement and campaigns. Without consent, only essential cookies are used. View cookie policy