What is NQA-1?

ASME NQA-1Quality Assurance Requirements for Nuclear Facility Applications — is the US consensus standard for nuclear quality assurance. The current edition is NQA-1:2024.

To understand why it matters, you need the regulatory picture. 10 CFR 50 Appendix B is the NRC regulation setting out 18 criteria a quality assurance program must meet for safety-related work at a nuclear facility. Appendix B says what is required but not how — and NQA-1 is the industry standard that answers the how. Critically, it is the route the NRC has endorsed as satisfying Appendix B.

Alongside it sits 10 CFR Part 21, which obliges suppliers of basic components to evaluate deviations and report defects that could create a substantial safety hazard. Part 21 is a separate duty from your QA program, and it carries personal as well as corporate consequences.

NQA-1 is structured in parts. Part I contains the basic requirements and supplements mapped to the Appendix B criteria. Part II adds subparts for specific activities — software, computer programs, installation, inspection, packaging and shipping. Parts III and IV provide non-mandatory guidance. In practice, scoping which parts and subparts apply to you is the first real decision in the project.

Who needs NQA-1?

NQA-1 applies to organizations providing safety-related items and services to US nuclear facilities. Your customer — a utility, a reactor vendor, or an EPC contractor — will flow the requirement down to you contractually, and they will audit you against it.

It is a fit for:

  • Manufacturers of safety-related components — valves, pumps, forgings, fasteners, piping, vessels, heat exchangers
  • Electrical and instrumentation & control suppliers, including safety-related digital systems and software
  • Providers of special processes — welding, heat treatment, non-destructive testing, coatings, calibration
  • Engineering, design and analysis firms supporting nuclear licensees
  • Testing laboratories and inspection organizations serving nuclear clients
  • Distributors performing commercial grade dedication to upgrade commercial items for safety-related use
  • Suppliers to SMR and advanced reactor programs, where the demand for qualified suppliers currently outstrips supply

The most common way organizations arrive here is opportunity-driven: an established manufacturer in aerospace, defense or heavy industry is invited to quote nuclear work and discovers the QA program is the gate.

What NQA-1 requires

NQA-1 Part I is organized around the eighteen Appendix B criteria. The requirements that most often surprise organizations coming from ISO 9001:

  • Organization and QA program — documented, with quality assurance holding genuine independence and the authority to stop work
  • Design control — including independent design verification by someone other than the designer, and rigorous control of design inputs, outputs and changes
  • Procurement document control and supplier evaluation — full requirement flow-down to every lower tier, with evidence
  • Commercial grade dedication (CGD) — a formal, documented process for accepting commercial items for safety-related use by identifying and verifying critical characteristics. This is one of the most heavily scrutinized areas in any NQA-1 audit.
  • Identification and control of items — traceability to material heat lots and individual serial numbers
  • Control of special processes and qualification of the personnel performing them
  • Inspection and test control, with qualified inspection personnel and calibrated measuring equipment
  • Control of nonconforming items, plus corrective action with real root-cause analysis
  • Quality assurance records — authenticated, protected against loss, and often retained for the life of the plant
  • Audits — internal and supplier audits performed by qualified, certified lead auditors
  • Counterfeit, fraudulent and suspect item (CFSI) controls

Two themes run through all of it: independence — the person checking cannot be the person doing — and documented objective evidence. If it is not recorded, in an NQA-1 audit it did not happen.

NQA-1 or ISO 19443? Getting this right first

These two standards cover similar ground and are not interchangeable. Choosing wrong is the most expensive mistake available to you at the start of a nuclear program, so we settle it before anything else.

  • Supplying safety-related items to US nuclear plants — you need NQA-1. It is the NRC-endorsed route to Appendix B, and it is what your US utility and reactor-vendor customers will require and audit.
  • Supplying non-US nuclear programs — European, UK, UAE or Central European new build — your customer almost certainly wants ISO 19443.
  • Both markets — build one integrated program carrying the shared substance (safety culture, graded QA, traceability, supplier control, CFSI) once, and handle the deltas explicitly. The two are similar enough in substance that this works; they are different enough on paper that it has to be deliberate.
  • Balance-of-plant, non-safety-related supply — ISO 9001 plus project specifications is often the right answer, and a full NQA-1 program would be a costly over-build.

Note also that ISO 19443 is not an NRC-endorsed route to Appendix B. If a certifier or consultant implies otherwise, be careful. There is separately an NEI guidance path (NEI 22-04) for using ISO 9001 with additional controls to meet Appendix B, which can be relevant for some advanced-reactor supply chains — we will tell you if it fits your situation.

How QSE gets you there

We bring 30+ years of building quality systems, 900+ organizations certified, and a 100% first-time pass rate. NQA-1 is the most evidence-hungry program we implement, and our 10-Step Approach is what keeps that from turning into an unmanageable paper mountain.

An important distinction up front: NQA-1 is not a certification you hang on the wall. There is no accredited registrar issuing an NQA-1 certificate the way there is for ISO 9001. Your program is accepted by your customers, through their supplier audits, and by NRC oversight of the licensee above you. That changes the goal: the deliverable is a program that survives a utility audit team, not a certificate.

We start with scope — which items and services are safety-related, which NQA-1 parts and subparts apply, what your customers flow down, and whether NQA-1, ISO 19443 or both is the right target. Then we build the program with your team: the QA manual and procedures, design verification, procurement and flow-down, CGD where you use commercial items, special-process and personnel qualification, records with life-of-plant retention, and a qualified internal audit capability. We train your people — including getting your auditors properly qualified — so you can defend the program yourselves.

You get single-level documentation, typically under 200 pages, and then we run a mock customer audit against you, harder than the real one. Most organizations are audit-ready in about 8 to 12 months.

Common pitfalls we help you avoid

  • Assuming an ISO 9001 certificate substantially covers NQA-1 — the gaps around independent design verification, CGD, records retention and auditor qualification are large
  • Assuming ISO 19443 satisfies Appendix B — it is not an NRC-endorsed route
  • Weak or absent commercial grade dedication, the single most commonly failed area in supplier audits
  • No genuine independence for QA, or no real authority to stop work
  • Design verification performed by the original designer, or checked without documented evidence
  • Failing to flow requirements down to lower-tier suppliers, or having no evidence you did
  • Records that do not meet life-of-plant retention, or that cannot be authenticated
  • Overlooking 10 CFR Part 21 obligations entirely — a separate duty from your QA program, with personal liability attached
  • Internal auditors who are not qualified and certified to NQA-1 requirements
  • Scoping the whole company as safety-related when only one product line is, and drowning in controls you never needed