Standards Comparison

    AS9110C

    Mandatory
    2016

    Aerospace QMS standard for aviation maintenance organizations

    VS

    ISO 28000

    Voluntary
    2022

    International standard for supply chain security management systems

    Quick Verdict

    AS9110C delivers quality management for aviation maintenance with safety and traceability focus, while ISO 28000 establishes security management across supply chains. Organizations adopt AS9110C for aerospace compliance and ISO 28000 for resilient logistics.

    Quality Management

    AS9110C

    AS9110C:2016 Quality Management Systems for Aviation Maintenance

    Cost
    €€€€
    Complexity
    High
    Implementation Time
    6-12 months

    Key Features

    • Rigorous configuration management for maintenance processes
    • Counterfeit and suspect parts prevention controls
    • Risk-based thinking in operational planning
    • Traceability and preservation of aviation parts
    • Human factors in root cause analysis
    Supply Chain Security

    ISO 28000

    ISO 28000:2022 Security management systems Requirements

    Cost
    €€€
    Complexity
    High
    Implementation Time
    12-18 months

    Key Features

    • Risk-based PDCA cycle for supply chain security
    • Leadership commitment and top management accountability
    • Supplier and external process controls integration
    • Security plans with response and recovery procedures
    • Alignment with ISO 31000 and ISO 22301 standards

    Detailed Analysis

    A comprehensive look at the specific requirements, scope, and impact of each standard.

    AS9110C Details

    What It Is

    AS9110C:2016 is an international certification standard for quality management systems (QMS) in aviation maintenance organizations (MROs). It builds on ISO 9001:2015 Annex SL structure, adding maintenance-specific requirements for continuing airworthiness, using risk-based thinking and PDCA cycles.

    Key Components

    • Clauses 4-10 cover context, leadership, planning, support, operation, evaluation, improvement.
    • Aviation additions: configuration management, counterfeit parts prevention, product safety, traceability, human factors.
    • No fixed control count; focuses on documented information and process approach.
    • Certification via IAQG OASIS after audits.

    Why Organizations Use It

    • Ensures regulatory compliance (FAA/EASA) and customer contracts.
    • Mitigates safety risks, enhances traceability.
    • Boosts market access, customer satisfaction, on-time delivery.
    • Builds stakeholder trust through auditable evidence.

    Implementation Overview

    • Phased: gap analysis, process design, training, audits (6-12 months).
    • Applies to MROs of all sizes globally.
    • Requires internal audits, management reviews before Stage 1/2 certification.

    ISO 28000 Details

    What It Is

    ISO 28000:2022 is an international certification standard specifying requirements for a security management system (SMS) focused on supply chain security. It adopts a risk-based, PDCA (Plan-Do-Check-Act) approach to manage threats like theft, sabotage, and disruptions across organizational operations and supply chains.

    Key Components

    • Clauses 4-10 cover context, leadership, planning, support, operation, evaluation, and improvement.
    • Emphasizes risk assessment (aligned with ISO 31000), operational controls, security plans, and supplier interdependencies.
    • Built on harmonized ISO structure for integration with standards like ISO 22301 and ISO 27001.
    • Optional third-party certification via ISO 28003 guidelines.

    Why Organizations Use It

    • Reduces security incidents, ensures compliance, and meets partner requirements.
    • Enhances resilience, lowers insurance costs, and provides market access.
    • Builds stakeholder trust through auditable governance.

    Implementation Overview

    • Phased: gap analysis, risk assessment, controls deployment, training, audits.
    • Scalable for all sizes/industries; 9-18 months typical.
    • Involves supply chain mapping and continual improvement.

    Key Differences

    Scope

    AS9110C
    Aerospace maintenance QMS with safety, traceability
    ISO 28000
    Supply chain security management system

    Industry

    AS9110C
    Aviation MRO organizations worldwide
    ISO 28000
    All supply chain sectors globally

    Nature

    AS9110C
    Voluntary QMS certification standard
    ISO 28000
    Voluntary security management certification

    Testing

    AS9110C
    Internal audits, management reviews, certification
    ISO 28000
    Internal audits, risk assessments, certification audits

    Penalties

    AS9110C
    Loss of certification, market exclusion
    ISO 28000
    Loss of certification, no legal penalties

    Frequently Asked Questions

    Common questions about AS9110C and ISO 28000

    AS9110C FAQ

    ISO 28000 FAQ

    You Might also be Interested in These Articles...

    Run Maturity Assessments with GRADUM

    Transform your compliance journey with our AI-powered assessment platform

    Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.

    100+ Standards & Regulations
    AI-Powered Insights
    Collaborative Assessments
    Actionable Recommendations

    Check out these other Gradum.io Standards Comparison Pages