NQA-1 vs ISO 9001 is the comparison every supplier makes when a nuclear customer first asks for an “Appendix B program”. The two standards share a vocabulary — document control, corrective action, audits, training — and a supplier with a mature ISO 9001 system is a long way toward NQA-1. But the resemblance stops at the point where NQA-1 becomes a regulatory instrument: it exists to satisfy 10 CFR 50 Appendix B, it is written as 18 mandatory requirements rather than a framework of clauses, it is not certifiable, and it reaches into design verification, procurement and special processes in ways ISO 9001 never does. This guide sets the two side by side on six differences that decide whether an ISO 9001 system can be extended or has to be rebuilt.

NQA-1 vs ISO 9001: what each standard is for
ISO 9001:2026, published September 2026 as the sixth edition, is the generic quality management system standard: ten clauses on the harmonized structure, applicable to any organization, certifiable by accredited certification bodies, with a stated purpose of consistently providing products and services that meet customer and regulatory requirements. It replaced ISO 9001:2015, which is now withdrawn; existing certificates transition over the IAF-set period.
ASME NQA-1, Quality Assurance Requirements for Nuclear Facility Applications, currently the 2024 edition, is a consensus standard written so that a nuclear facility licensee — and everyone in its safety-related supply chain — can satisfy the 18 criteria of 10 CFR 50 Appendix B. Its Part I sets 18 requirements that track the Appendix B criteria one for one; Part II adds subpart-level detail for specific activities such as software (Subpart 2.7) and commercial grade dedication (Subpart 2.14); Parts III and IV carry non-mandatory guidance and application notes. The NRC endorses specific editions through Regulatory Guide 1.28 — Revision 6 endorses NQA-1-2017, 2019 and 2022 — so the edition a licensee’s program commits to may not be ASME’s newest. Our guide to NQA-1 and which edition binds you covers that trap.
NQA-1 vs ISO 9001: the six differences
| Difference | ISO 9001:2026 | NQA-1-2024 |
|---|---|---|
| 1. Legal status | Voluntary; contractual when a customer requires it | Voluntary standard, but the means of meeting 10 CFR 50 Appendix B, which is law for NRC licensees and flows down by contract |
| 2. Certification | Certifiable by accredited CBs; certificate valid 3 years | Not certifiable. Acceptance is by customer audit (often via NUPIC) and NRC inspection |
| 3. Structure | 10 harmonized-structure clauses; risk-based, outcome-oriented | 18 mandatory requirements mirroring Appendix B; prescriptive on records, procurement, design |
| 4. Design control | Clause 8.3 design and development, applicable if the organization designs | Requirement 3: design verification by individuals other than the designer, design interfaces, design changes controlled like the original |
| 5. Procurement and dedication | Clause 8.4 control of externally provided processes; supplier evaluation | Requirements 4 and 7 plus Part II Subpart 2.14: procurement documents, supplier qualification, source verification, commercial grade dedication |
| 6. Graded application | Proportionate by design but not formalized | Graded approach: controls scaled to safety significance, documented in the QA program |
1. Legal status
ISO 9001 obliges no one until a customer writes it into a contract. NQA-1 is technically also a voluntary consensus standard — but it is the vehicle for 10 CFR 50 Appendix B, which binds NRC licensees and, through their procurement documents, every supplier of safety-related items and services. When a nuclear customer asks for NQA-1, the request carries regulatory weight the supplier cannot negotiate away. Our guide to the 18 criteria of 10 CFR 50 Appendix B explains the parent obligation.
2. Certification
There is no NQA-1 certificate. ASME issues certificates for some nuclear activities under its N-type stamps, but NQA-1 conformance is demonstrated to each customer through audit, and in the US utility supply chain those audits are largely pooled through NUPIC, the Nuclear Procurement Issues Corporation, whose member utilities share audit results. A supplier’s ISO 9001 certificate is useful evidence at an NQA-1 audit but does not shorten it.
3. Structure
ISO 9001’s clauses say what outcomes a system must achieve and leave the method to the organization. NQA-1’s 18 requirements say what the program must contain. Requirement 6, Document Control, and Requirement 17, Quality Assurance Records, are far more specific than ISO 9001 clause 7.5 about review, approval, distribution, retention categories and storage. The practical effect is that an ISO 9001 procedure usually needs additions rather than replacement, but every one of the 18 needs its own visible treatment in the QA program description.
4. Design control
ISO 9001 clause 8.3 requires design review, verification and validation but lets the organization decide who does them. NQA-1 Requirement 3 requires design verification “by individuals or groups other than those who performed the original design”, specifies the acceptable methods — design review, alternate calculations, qualification testing — requires interface control between design organizations, and requires design changes to receive the same controls as the original design. A supplier whose ISO 9001 design process has the designer self-verifying has a structural gap.
5. Procurement and dedication
Clause 8.4 of ISO 9001 asks the organization to evaluate, select and monitor external providers. NQA-1 Requirements 4 (Procurement Document Control) and 7 (Control of Purchased Items and Services) require procurement documents to invoke the applicable QA requirements, supplier evaluation before award, and verification methods including source inspection and receipt inspection. Then Part II Subpart 2.14 adds commercial grade dedication — the process for accepting an item not made under an Appendix B program for safety-related use. Nothing in ISO 9001 corresponds to it. Our guide to commercial grade dedication covers the four acceptance methods.
6. Graded application
ISO 9001 is proportionate in spirit. NQA-1 makes grading a documented decision: the QA program identifies the safety significance of items and activities and applies controls accordingly, and the grading must be defensible to an auditor and an inspector. See the graded approach in NQA-1.
NQA-1 vs ISO 9001: where the two overlap
The NQA-1 vs ISO 9001 overlap is real and worth using. An organization with a working ISO 9001 system already has most of the machinery for NQA-1 Requirements 2 (QA Program, partly), 5 (Instructions, Procedures and Drawings), 6 (Document Control), 15 (Nonconforming Items), 16 (Corrective Action) and 18 (Audits), and much of 17 (Records). Training and qualification under Requirement 2 maps to ISO 9001 clause 7.2 competence with additions for indoctrination and the qualification of inspection, test and audit personnel. Management review, internal audit and corrective action procedures usually survive with amendments.
| NQA-1 Part I requirement | Nearest ISO 9001:2026 clause | Typical gap |
|---|---|---|
| 1 Organization | 5.3 Roles, responsibilities and authorities | QA organization’s independence and authority to stop work |
| 2 Quality Assurance Program | 4.4, 7.2, 7.3 | Indoctrination; qualification of inspection, test and audit personnel; graded approach |
| 3 Design Control | 8.3 | Independent verification; interface control |
| 4 Procurement Document Control | 8.4.3 | Invoking QA requirements and right of access in procurement documents |
| 5 Instructions, Procedures and Drawings | 7.5, 8.5.1 | Acceptance criteria in the documents themselves |
| 6 Document Control | 7.5.3 | Controlled distribution and review by the original approver |
| 7 Control of Purchased Items and Services | 8.4, 8.6 | Supplier evaluation records; source verification; CGD |
| 8 Identification and Control of Items | 8.5.2 | Physical identification maintained through the life of the item |
| 9 Control of Processes | 8.5.1 | Special process qualification records |
| 10 Inspection | 8.6 | Inspector independence; hold points |
| 11 Test Control | 8.6 | Test procedures with prerequisites and acceptance criteria |
| 12 Control of Measuring and Test Equipment | 7.1.5 | Out-of-tolerance evaluation of previously accepted items |
| 13 Handling, Storage and Shipping | 8.5.4 | Storage levels and environmental controls |
| 14 Inspection, Test and Operating Status | 8.5.2 | Status indication on the item itself |
| 15 Control of Nonconforming Items | 8.7 | Disposition categories; segregation |
| 16 Corrective Action | 10.2 | Significant conditions adverse to quality reported to management |
| 17 Quality Assurance Records | 7.5.3 | Lifetime vs nonpermanent records; storage facility requirements |
| 18 Audits | 9.2 | Auditor qualification; supplier audits |
Extend or rebuild?
The NQA-1 vs ISO 9001 decision is really extend-or-rebuild. Extend when the ISO 9001 system is genuinely operating — records exist, audits happen, corrective actions close — and the organization’s nuclear scope is a subset of what it already does. The work is a QA program description that walks all 18 requirements, procedure revisions where NQA-1 is more specific, and new procedures for design verification, procurement, special processes and dedication where nothing exists.
Rebuild when the ISO 9001 certificate is a wall ornament, or when the nuclear scope introduces activities the organization has never controlled — safety-related design, software under Subpart 2.7, or dedication. Grafting NQA-1 onto a system that does not really run produces two systems that do not run. Our guide to the corrective action program covers Requirement 16, the one most often failing on the ISO side too.
Either way, keep ISO 9001; NQA-1 vs ISO 9001 was never an exclusive choice. Nuclear customers do not require it, but most suppliers serve other markets, and the ISO 9001:2026 clauses on culture, risk and opportunity fit comfortably inside an NQA-1 program. The two are complements, not alternatives.
Frequently asked questions
Is NQA-1 certification a thing?
No. NQA-1 is not certifiable. Conformance is demonstrated through customer audits — pooled through NUPIC in the US utility supply chain — and NRC inspection. ISO 9001, by contrast, is certified by accredited bodies.
Does an ISO 9001 certificate satisfy a nuclear customer?
It is useful evidence for several of the 18 requirements but does not satisfy Appendix B. Design verification, procurement document control, special processes, dedication and records retention all need NQA-1-specific treatment.
Which NQA-1 edition should we commit to?
The one your customer’s program commits to, which is often an NRC-endorsed edition under RG 1.28 (Revision 6 endorses 2017, 2019 and 2022) rather than ASME’s current 2024 edition. Ask before writing the QA program.
Is NQA-1 more expensive to run than ISO 9001?
Usually, because of the records burden, independent verification, source inspection and audit obligations. The graded approach limits the cost to the items and activities that are actually safety significant.
Can one management system hold both?
Yes. Most nuclear suppliers run one system with an NQA-1 QA program description mapped to the 18 requirements and an ISO 9001 certificate covering the whole organization.
Where this leaves you
Read NQA-1 vs ISO 9001 as a gap analysis, not a choice. Map your ISO 9001 procedures to the 18 requirements, add what NQA-1 specifies that ISO 9001 leaves open — independent design verification, procurement flow-down, dedication, lifetime records, auditor qualification — and write a QA program description that shows an auditor where each requirement lives. That is the document a NUPIC audit opens first.
References
- ASME NQA-1 Quality Assurance Requirements for Nuclear Facility Applications — ASME’s catalogue page for the current edition.
- 10 CFR 50 Appendix B — The 18 criteria on the eCFR.
- ISO 9001:2026 — The sixth edition of ISO 9001, published September 2026.
More on nuclear quality assurance
- NQA-1 vs ISO 9001 — you are here
- NQA-1 and which edition binds you
- 10 CFR 50 Appendix B: the 18 criteria
- Commercial grade dedication: four methods
- The graded approach in NQA-1
- The corrective action program
A QA program description mapped to all 18 requirements, the design verification, procurement and dedication procedures, and the records and audit templates are in the NQA-1 Nuclear Quality Assurance Toolkit, or start with the free templates.