What is ISO 19443?
ISO 19443 is the quality management standard for the civil nuclear supply chain. Its full title says exactly what it does: Quality management systems — Specific requirements for the application of ISO 9001:2015 by organizations in the supply chain of the nuclear energy sector supplying products and services important to nuclear safety (ITNS). The current edition is ISO 19443:2018, updated by Amendment 1:2024, which added the climate-change considerations ISO rolled into all of its management-system standards.
Like AS9100 in aerospace and IATF 16949 in automotive, ISO 19443 is a sector standard built on ISO 9001. It keeps the whole ISO 9001 framework and the same ten-clause structure, then layers on what nuclear demands — because in this industry a single undocumented weld, an unqualified inspector, or one counterfeit valve can matter for decades. The result is a substantially heavier standard: well over 400 discrete requirements across clauses 4 to 10.
The concept that organizes all of it is ITNS — important to nuclear safety. Rather than treating every product line the same, ISO 19443 asks you to identify which of your items, services and activities actually bear on nuclear safety, and then apply controls in proportion to that significance. Everything else in the standard flows from getting that determination right.
Who needs ISO 19443?
ISO 19443 is for organizations anywhere in the nuclear supply chain that provide products or services important to nuclear safety — not just the tier-one fabricators, but the smaller shops and specialists beneath them.
It is a fit for:
- Manufacturers of nuclear-grade components — valves, pumps, forgings, castings, heat exchangers, fasteners, piping and vessels
- Electrical, instrumentation and control (I&C) suppliers, including safety-related software and digital systems
- Providers of special processes — welding, heat treatment, coatings, plating, non-destructive testing
- Civil, structural and mechanical contractors working on nuclear sites
- Engineering, design, inspection, calibration and technical-service firms supporting nuclear operators
- Distributors and stockists handling nuclear-grade material
- Established manufacturers in aerospace, defense or heavy industry looking to qualify into nuclear new build, SMRs or plant life extension
As with the other sector standards, certification is normally driven by your customer, not by law. Utilities, reactor vendors and EPC contractors — particularly across Europe, the UK and the UAE, and increasingly on Central European new-build programs — flow ISO 19443 down as a condition of being on the bid list. If your growth plan includes nuclear work outside the United States, this is usually the certificate that gets you through the door.
What ISO 19443 requires
ISO 19443 keeps every ISO 9001 requirement and amplifies them for nuclear. The main additions:
- Nuclear safety culture — a genuine, demonstrable commitment led from the top, where safety outranks schedule and cost pressure. Top management has to show it, and your management review has to assess the state of it.
- ITNS determination and a graded approach — you identify which items and activities are important to nuclear safety, and apply rigor proportional to their safety significance rather than one flat level of control.
- Stronger competence and qualification requirements — personnel performing ITNS work need demonstrated, maintained qualification, including nuclear-specific awareness. Internal auditors must be competent in nuclear safety requirements, not just in auditing.
- CFSI controls — documented processes to prevent, detect and control counterfeit, fraudulent and suspect items entering your supply chain or your product. This is one of the standard's signature requirements.
- Supplier qualification and full flow-down — rigorous evaluation of your own suppliers, with ITNS requirements passed down through every tier beneath you, and evidence that they were.
- Commercial grade dedication (CGD) — a controlled, documented process for accepting commercial off-the-shelf items for ITNS use.
- Traceability and configuration control — traceability of material, process, product and personnel qualification, with the ability to prove what you shipped and to what revision, years later.
- Documented-information integrity — enhanced control over authenticity, integrity and long-term retention of ITNS records.
- Escalation of nonconformities — prompt reporting of nonconformities affecting nuclear safety to management, the customer and, where applicable, the regulator, with real root-cause analysis behind the correction.
- Statement of delivery — documented evidence at handover that required production, inspection and monitoring activities were completed.
ISO 19443 and the US framework — NQA-1, Appendix B and Part 21
This is the part most US manufacturers need explained honestly, so we will be direct about it.
In the United States, nuclear quality assurance runs through a domestic framework. 10 CFR 50 Appendix B is the NRC regulation. ASME NQA-1 is the industry consensus standard describing how to build a QA program that satisfies it, and it is the route the NRC has endorsed for safety-related work. 10 CFR Part 21 adds the obligation to report defects and noncompliances. If you are supplying safety-related items to a US plant, that is the framework your customer will hold you to — and ISO 19443 does not substitute for it.
ISO 19443 is the international counterpart, and it is where the world outside the US has converged. The two overlap heavily in substance — safety culture, graded QA, traceability, supplier control, counterfeit prevention — which is why organizations that hold both do not end up running two fundamentally different programs. But they are not interchangeable, and gaps remain between ISO 19443 and Appendix B.
So the practical question is which market you are selling into:
- Exporting, or supplying non-US nuclear programs — ISO 19443 is very likely what your customer wants.
- Safety-related supply to US plants — you need an Appendix B / NQA-1 program, and ISO 19443 is at best complementary.
- Both — build one integrated system that carries the shared requirements once and handles the deltas explicitly, including Part 21 reporting.
- Balance-of-plant supply — ISO 9001 plus project specifications often covers it, and certifying to ISO 19443 speculatively may not be worth the cost.
That is why we start every nuclear engagement with a scoping conversation about who your buyers actually are and what they require. Chasing the wrong certificate is an expensive mistake, and we would rather tell you that up front than sell you a project.
Why get ISO 19443 certified
The first reason is access. On most nuclear programs outside the US, ISO 19443 is what qualifies you to bid. Nuclear procurement is conservative and relationship-driven, and contracts run for years — getting onto an approved-supplier list is a durable commercial position, not a one-off win.
The second is audit relief. Before ISO 19443 existed, nuclear suppliers absorbed repeated, overlapping customer audits, each utility and vendor assessing the same processes against its own criteria. One recognized third-party certificate replaces a meaningful share of that burden, which is exactly why the sector backed the standard.
The third is that the discipline genuinely reduces risk. Real traceability means you can answer a question about a part you shipped a decade ago. CFSI controls protect you from one of the most damaging failure modes in the industry. A graded approach concentrates your effort where safety significance is highest instead of spreading it thin. And a working safety culture is what stops schedule pressure from quietly eroding quality — which is the failure pattern behind most serious nuclear supply-chain incidents.
There is a timing argument too. Nuclear new build, small modular reactors and plant life extension are all expanding, and demand for qualified suppliers is outpacing supply. Being certified before the inquiry arrives is a different position from scrambling after it.
How QSE gets you certified
We bring 30+ years of building quality systems and a record of 900+ organizations certified with a 100% first-time pass rate. Nuclear is the most documentation-intensive sector we work in, and our 10-Step Approach exists precisely so that weight does not become unmanageable.
We start with scope, because in nuclear that is where projects go wrong: which of your items and activities are genuinely ITNS, what your customers flow down to you, and which framework — ISO 19443, NQA-1, or both — actually fits your market. Get that right and the rest of the program is proportionate. Get it wrong and you either over-build or fail an audit.
From there we build the system with your team rather than handing you a template: the graded approach, safety-culture practices leadership can actually demonstrate, competence and qualification records, CFSI and supplier flow-down controls, traceability, and CGD where you use commercial items for ITNS work. We train your people so they can run and defend the system once we are gone — that is the whole point.
As with every QSE engagement, you get single-level documentation, typically under 200 pages for the entire system. Lean enough that people use it, complete enough to satisfy a nuclear auditor. We run internal audits and management review, close the gaps, then support you through the Stage 1 and Stage 2 certification audits. Most organizations reach certification in about 8 to 12 months, depending on ITNS scope and how mature your current system is.
Common pitfalls we help you avoid
- Pursuing ISO 19443 when your customers actually require NQA-1 / 10 CFR 50 Appendix B — or holding ISO 19443 and assuming it satisfies the NRC framework
- Defining ITNS scope too broadly, which buries the organization in controls it does not need, or too narrowly, which fails at audit
- Treating nuclear safety culture as a poster and a policy statement instead of something leadership demonstrates and management review evaluates
- Applying uniform controls everywhere and calling it a graded approach
- Having no real CFSI program — no prevention, no detection, no response — until an auditor or a customer asks
- Failing to flow ITNS requirements down to lower-tier suppliers, or having no evidence that you did
- Using commercial off-the-shelf items for ITNS work without a controlled commercial grade dedication process
- Traceability and record-retention gaps that only surface when a customer asks about a part shipped years earlier
- Missing the escalation and reporting obligations when a nonconformity touches nuclear safety
- Internal auditors who are competent auditors but have no nuclear safety competence
- Heavy multi-tier manuals nobody reads, so the documented system and the real one drift apart
