Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NQA-1 vs ISO 9001 explained

NQA-1 vs ISO 9001: A Clear Guide to the 6 Differences

NQA-1 vs ISO 9001 is the comparison every supplier makes when a nuclear customer first asks for an “Appendix B program”. The two standards share a vocabulary — document control, corrective action, audits, training — and a supplier with a mature ISO 9001 system is a long way toward NQA-1. But the resemblance stops at the point where NQA-1 becomes a regulatory instrument: it exists to satisfy 10 CFR 50 Appendix B, it is written as 18 mandatory requirements rather than a framework of clauses, it is not certifiable, and it reaches into design verification, procurement and special processes in ways ISO 9001 never does. This guide sets the two side by side on six differences that decide whether an ISO 9001 system can be extended or has to be rebuilt.

NQA-1 vs ISO 9001: six differences that decide whether to extend or rebuild
Same family, different jobs: ISO 9001 is a customer-satisfaction management system; NQA-1 is a nuclear safety assurance program.

NQA-1 vs ISO 9001: what each standard is for

ISO 9001:2026, published September 2026 as the sixth edition, is the generic quality management system standard: ten clauses on the harmonized structure, applicable to any organization, certifiable by accredited certification bodies, with a stated purpose of consistently providing products and services that meet customer and regulatory requirements. It replaced ISO 9001:2015, which is now withdrawn; existing certificates transition over the IAF-set period.

ASME NQA-1, Quality Assurance Requirements for Nuclear Facility Applications, currently the 2024 edition, is a consensus standard written so that a nuclear facility licensee — and everyone in its safety-related supply chain — can satisfy the 18 criteria of 10 CFR 50 Appendix B. Its Part I sets 18 requirements that track the Appendix B criteria one for one; Part II adds subpart-level detail for specific activities such as software (Subpart 2.7) and commercial grade dedication (Subpart 2.14); Parts III and IV carry non-mandatory guidance and application notes. The NRC endorses specific editions through Regulatory Guide 1.28 — Revision 6 endorses NQA-1-2017, 2019 and 2022 — so the edition a licensee’s program commits to may not be ASME’s newest. Our guide to NQA-1 and which edition binds you covers that trap.

NQA-1 vs ISO 9001: the six differences

Difference ISO 9001:2026 NQA-1-2024
1. Legal status Voluntary; contractual when a customer requires it Voluntary standard, but the means of meeting 10 CFR 50 Appendix B, which is law for NRC licensees and flows down by contract
2. Certification Certifiable by accredited CBs; certificate valid 3 years Not certifiable. Acceptance is by customer audit (often via NUPIC) and NRC inspection
3. Structure 10 harmonized-structure clauses; risk-based, outcome-oriented 18 mandatory requirements mirroring Appendix B; prescriptive on records, procurement, design
4. Design control Clause 8.3 design and development, applicable if the organization designs Requirement 3: design verification by individuals other than the designer, design interfaces, design changes controlled like the original
5. Procurement and dedication Clause 8.4 control of externally provided processes; supplier evaluation Requirements 4 and 7 plus Part II Subpart 2.14: procurement documents, supplier qualification, source verification, commercial grade dedication
6. Graded application Proportionate by design but not formalized Graded approach: controls scaled to safety significance, documented in the QA program

1. Legal status

ISO 9001 obliges no one until a customer writes it into a contract. NQA-1 is technically also a voluntary consensus standard — but it is the vehicle for 10 CFR 50 Appendix B, which binds NRC licensees and, through their procurement documents, every supplier of safety-related items and services. When a nuclear customer asks for NQA-1, the request carries regulatory weight the supplier cannot negotiate away. Our guide to the 18 criteria of 10 CFR 50 Appendix B explains the parent obligation.

2. Certification

There is no NQA-1 certificate. ASME issues certificates for some nuclear activities under its N-type stamps, but NQA-1 conformance is demonstrated to each customer through audit, and in the US utility supply chain those audits are largely pooled through NUPIC, the Nuclear Procurement Issues Corporation, whose member utilities share audit results. A supplier’s ISO 9001 certificate is useful evidence at an NQA-1 audit but does not shorten it.

3. Structure

ISO 9001’s clauses say what outcomes a system must achieve and leave the method to the organization. NQA-1’s 18 requirements say what the program must contain. Requirement 6, Document Control, and Requirement 17, Quality Assurance Records, are far more specific than ISO 9001 clause 7.5 about review, approval, distribution, retention categories and storage. The practical effect is that an ISO 9001 procedure usually needs additions rather than replacement, but every one of the 18 needs its own visible treatment in the QA program description.

4. Design control

ISO 9001 clause 8.3 requires design review, verification and validation but lets the organization decide who does them. NQA-1 Requirement 3 requires design verification “by individuals or groups other than those who performed the original design”, specifies the acceptable methods — design review, alternate calculations, qualification testing — requires interface control between design organizations, and requires design changes to receive the same controls as the original design. A supplier whose ISO 9001 design process has the designer self-verifying has a structural gap.

5. Procurement and dedication

Clause 8.4 of ISO 9001 asks the organization to evaluate, select and monitor external providers. NQA-1 Requirements 4 (Procurement Document Control) and 7 (Control of Purchased Items and Services) require procurement documents to invoke the applicable QA requirements, supplier evaluation before award, and verification methods including source inspection and receipt inspection. Then Part II Subpart 2.14 adds commercial grade dedication — the process for accepting an item not made under an Appendix B program for safety-related use. Nothing in ISO 9001 corresponds to it. Our guide to commercial grade dedication covers the four acceptance methods.

6. Graded application

ISO 9001 is proportionate in spirit. NQA-1 makes grading a documented decision: the QA program identifies the safety significance of items and activities and applies controls accordingly, and the grading must be defensible to an auditor and an inspector. See the graded approach in NQA-1.

NQA-1 vs ISO 9001: where the two overlap

The NQA-1 vs ISO 9001 overlap is real and worth using. An organization with a working ISO 9001 system already has most of the machinery for NQA-1 Requirements 2 (QA Program, partly), 5 (Instructions, Procedures and Drawings), 6 (Document Control), 15 (Nonconforming Items), 16 (Corrective Action) and 18 (Audits), and much of 17 (Records). Training and qualification under Requirement 2 maps to ISO 9001 clause 7.2 competence with additions for indoctrination and the qualification of inspection, test and audit personnel. Management review, internal audit and corrective action procedures usually survive with amendments.

NQA-1 Part I requirement Nearest ISO 9001:2026 clause Typical gap
1 Organization 5.3 Roles, responsibilities and authorities QA organization’s independence and authority to stop work
2 Quality Assurance Program 4.4, 7.2, 7.3 Indoctrination; qualification of inspection, test and audit personnel; graded approach
3 Design Control 8.3 Independent verification; interface control
4 Procurement Document Control 8.4.3 Invoking QA requirements and right of access in procurement documents
5 Instructions, Procedures and Drawings 7.5, 8.5.1 Acceptance criteria in the documents themselves
6 Document Control 7.5.3 Controlled distribution and review by the original approver
7 Control of Purchased Items and Services 8.4, 8.6 Supplier evaluation records; source verification; CGD
8 Identification and Control of Items 8.5.2 Physical identification maintained through the life of the item
9 Control of Processes 8.5.1 Special process qualification records
10 Inspection 8.6 Inspector independence; hold points
11 Test Control 8.6 Test procedures with prerequisites and acceptance criteria
12 Control of Measuring and Test Equipment 7.1.5 Out-of-tolerance evaluation of previously accepted items
13 Handling, Storage and Shipping 8.5.4 Storage levels and environmental controls
14 Inspection, Test and Operating Status 8.5.2 Status indication on the item itself
15 Control of Nonconforming Items 8.7 Disposition categories; segregation
16 Corrective Action 10.2 Significant conditions adverse to quality reported to management
17 Quality Assurance Records 7.5.3 Lifetime vs nonpermanent records; storage facility requirements
18 Audits 9.2 Auditor qualification; supplier audits

Extend or rebuild?

The NQA-1 vs ISO 9001 decision is really extend-or-rebuild. Extend when the ISO 9001 system is genuinely operating — records exist, audits happen, corrective actions close — and the organization’s nuclear scope is a subset of what it already does. The work is a QA program description that walks all 18 requirements, procedure revisions where NQA-1 is more specific, and new procedures for design verification, procurement, special processes and dedication where nothing exists.

Rebuild when the ISO 9001 certificate is a wall ornament, or when the nuclear scope introduces activities the organization has never controlled — safety-related design, software under Subpart 2.7, or dedication. Grafting NQA-1 onto a system that does not really run produces two systems that do not run. Our guide to the corrective action program covers Requirement 16, the one most often failing on the ISO side too.

Either way, keep ISO 9001; NQA-1 vs ISO 9001 was never an exclusive choice. Nuclear customers do not require it, but most suppliers serve other markets, and the ISO 9001:2026 clauses on culture, risk and opportunity fit comfortably inside an NQA-1 program. The two are complements, not alternatives.

Frequently asked questions

Is NQA-1 certification a thing?
No. NQA-1 is not certifiable. Conformance is demonstrated through customer audits — pooled through NUPIC in the US utility supply chain — and NRC inspection. ISO 9001, by contrast, is certified by accredited bodies.

Does an ISO 9001 certificate satisfy a nuclear customer?
It is useful evidence for several of the 18 requirements but does not satisfy Appendix B. Design verification, procurement document control, special processes, dedication and records retention all need NQA-1-specific treatment.

Which NQA-1 edition should we commit to?
The one your customer’s program commits to, which is often an NRC-endorsed edition under RG 1.28 (Revision 6 endorses 2017, 2019 and 2022) rather than ASME’s current 2024 edition. Ask before writing the QA program.

Is NQA-1 more expensive to run than ISO 9001?
Usually, because of the records burden, independent verification, source inspection and audit obligations. The graded approach limits the cost to the items and activities that are actually safety significant.

Can one management system hold both?
Yes. Most nuclear suppliers run one system with an NQA-1 QA program description mapped to the 18 requirements and an ISO 9001 certificate covering the whole organization.

Where this leaves you

Read NQA-1 vs ISO 9001 as a gap analysis, not a choice. Map your ISO 9001 procedures to the 18 requirements, add what NQA-1 specifies that ISO 9001 leaves open — independent design verification, procurement flow-down, dedication, lifetime records, auditor qualification — and write a QA program description that shows an auditor where each requirement lives. That is the document a NUPIC audit opens first.

References

More on nuclear quality assurance

A QA program description mapped to all 18 requirements, the design verification, procurement and dedication procedures, and the records and audit templates are in the NQA-1 Nuclear Quality Assurance Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.