EN 9125:2025
(Main)Aerospace series - Quality management systems - Non-deliverable software requirements
General Information
- Abstract
This document specifies the requirements for the effective control of non-deliverable software. This document can be used during the design, development, test, production, release, use, maintenance, and retirement of non-deliverable software. This can include non-deliverable software procured from external suppliers and utilized in the design, production, evaluation, test, acceptance, or calibration of a deliverable product.
This document focuses solely on the unique requirements of the operational processes that pertain to non-deliverable software as identified below:
This document applies to non-deliverable software (including firmware) that affects a deliverable product or service. Following are several applications and supporting examples of non-deliverable software that is within the scope of this document:
— design and development: modelling, simulation, virtual reality, virtual machine, computer-aided design (CAD), three-dimensional (3D) modelling and analysis tools, software compiler, and code generators;
— manufacturing: additive manufacturing, computer numerical controlled (CNC) programs, robotics, factory automation, tools that load deliverable software, software used in special process (e.g. heat treat, shot peen, sonic wall inspection), and automated manufacturing software (i.e. pick and place);
— verification, validation and maintenance: coordinate measuring machine (CMM) programs, hardware or software qualification, code coverage, test scripts, analysis tools, acceptance test, production acceptance, calibration (inspection, test or calibration), simulator, emulator, and software used in post-delivery service provisions.
The following types of software are not within scope of this document:
— deliverable software (refer to EN 9115);
— manufacturing and measuring equipment embedded software (e.g. operating system, drivers);
— enterprise or office software (e.g. MS Office, word processing or spreadsheet applications, Teams, network software, email, employee management system).
Operational processes not covered in this document are addressed by the respective organization’s quality management system (QMS), based on the EN 9100-series (i.e. EN 9100, EN 9110, EN 9120) and/or ISO 9001 standards.
- Status
- Published
- Publication Date
- 06-May-2025
- Technical Committee
- ASD-STAN - Aerospace
- Drafting Committee
- ASD-STAN/D 6/S 1 - EAQG European Aerospace Quality Group
- Current Stage
- 6060 - Definitive text made available (DAV) - Publishing
- Start Date
- 07-May-2025
- Completion Date
- 07-May-2025
Overview
EN 9125:2025 - Aerospace series - Quality management systems - Non-deliverable software requirements is a CEN standard that defines requirements for the effective control of non-deliverable software (including firmware) used across the aviation, space and defence supply chain. Approved in 2025, EN 9125:2025 standardizes lifecycle controls for software that is not part of the end-user deliverable but affects deliverable products or services (e.g., tools used in design, manufacturing, verification, calibration).
This standard supersedes SAE ARP9005 and is intended to improve product quality, schedule and cost by aligning non-deliverable software practices across organizations.
Key topics and requirements
EN 9125:2025 focuses on operational processes unique to non-deliverable software and requires organizations to address:
- Design & development planning
- Define lifecycle methodology (e.g., Waterfall, Agile)
- Identify applicable standards, tools, and interfaces
- Specify configuration management, security, verification and validation
- Requirements management
- Verifiable, traceable software requirements that map to parent requirements where applicable
- Verification & validation
- Planned verification/acceptance testing, documentation of results, re-validation for new environments
- Configuration management
- Identification, traceability and controlled changes of non-deliverable software artifacts
- Information security
- Protection of software and data, including secure digital transfers and access control
- External provider controls
- Selection, information flow, acceptance and maintenance of externally supplied non-deliverable software
- Release & control
- Release, distribution, access control, handling obsolete software and preservation of software artifacts
- Documented information
- Records demonstrating compliance with the above processes
Examples within scope include CAD, simulation, compilers, CNC programs, additive manufacturing software, CMM programs, test scripts, simulators and emulators. Exclusions: deliverable software (see EN 9115), embedded equipment OS/drivers, and enterprise office software.
Applications and practical value
Who uses EN 9125:2025:
- Aerospace manufacturers, suppliers and subcontractors who rely on non-deliverable software for design, manufacture, test, calibration and maintenance
- Quality, configuration and software assurance teams implementing aerospace quality management systems
- Procurement and supplier management functions controlling externally provided tools and firmware
Practical benefits:
- Reduced risk of defective deliverable products caused by uncontrolled tools
- Clear supplier expectations and auditability for non-deliverable software
- Consistent verification/validation and traceability practices across the supply chain
Related standards
- EN 9100 / EN 9110 / EN 9120 (EN 9100-series) - organizational QMS for aerospace
- EN 9115 - Deliverable software requirements
- ISO 9001 / ISO 9000 - Quality management fundamentals and vocabulary
Keywords: EN 9125:2025, non-deliverable software, aerospace standard, quality management systems, verification, validation, configuration management, information security.
Relations
- Effective Date
- 09-Feb-2026
- Effective Date
- 28-Jan-2026
- Effective Date
- 28-Jan-2026
- Effective Date
- 28-Jan-2026
- Effective Date
- 28-Jan-2026
- Effective Date
- 28-Jan-2026
Get Certified
Connect with accredited certification bodies for this standard

BSI Group
BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

Bureau Veritas
Bureau Veritas is a world leader in laboratory testing, inspection and certification services.

DNV
DNV is an independent assurance and risk management provider.
Sponsored listings
Frequently Asked Questions
EN 9125:2025 is a standard published by the European Committee for Standardization (CEN). Its full title is "Aerospace series - Quality management systems - Non-deliverable software requirements". This standard covers: This document specifies the requirements for the effective control of non-deliverable software. This document can be used during the design, development, test, production, release, use, maintenance, and retirement of non-deliverable software. This can include non-deliverable software procured from external suppliers and utilized in the design, production, evaluation, test, acceptance, or calibration of a deliverable product. This document focuses solely on the unique requirements of the operational processes that pertain to non-deliverable software as identified below: This document applies to non-deliverable software (including firmware) that affects a deliverable product or service. Following are several applications and supporting examples of non-deliverable software that is within the scope of this document: — design and development: modelling, simulation, virtual reality, virtual machine, computer-aided design (CAD), three-dimensional (3D) modelling and analysis tools, software compiler, and code generators; — manufacturing: additive manufacturing, computer numerical controlled (CNC) programs, robotics, factory automation, tools that load deliverable software, software used in special process (e.g. heat treat, shot peen, sonic wall inspection), and automated manufacturing software (i.e. pick and place); — verification, validation and maintenance: coordinate measuring machine (CMM) programs, hardware or software qualification, code coverage, test scripts, analysis tools, acceptance test, production acceptance, calibration (inspection, test or calibration), simulator, emulator, and software used in post-delivery service provisions. The following types of software are not within scope of this document: — deliverable software (refer to EN 9115); — manufacturing and measuring equipment embedded software (e.g. operating system, drivers); — enterprise or office software (e.g. MS Office, word processing or spreadsheet applications, Teams, network software, email, employee management system). Operational processes not covered in this document are addressed by the respective organization’s quality management system (QMS), based on the EN 9100-series (i.e. EN 9100, EN 9110, EN 9120) and/or ISO 9001 standards.
This document specifies the requirements for the effective control of non-deliverable software. This document can be used during the design, development, test, production, release, use, maintenance, and retirement of non-deliverable software. This can include non-deliverable software procured from external suppliers and utilized in the design, production, evaluation, test, acceptance, or calibration of a deliverable product. This document focuses solely on the unique requirements of the operational processes that pertain to non-deliverable software as identified below: This document applies to non-deliverable software (including firmware) that affects a deliverable product or service. Following are several applications and supporting examples of non-deliverable software that is within the scope of this document: — design and development: modelling, simulation, virtual reality, virtual machine, computer-aided design (CAD), three-dimensional (3D) modelling and analysis tools, software compiler, and code generators; — manufacturing: additive manufacturing, computer numerical controlled (CNC) programs, robotics, factory automation, tools that load deliverable software, software used in special process (e.g. heat treat, shot peen, sonic wall inspection), and automated manufacturing software (i.e. pick and place); — verification, validation and maintenance: coordinate measuring machine (CMM) programs, hardware or software qualification, code coverage, test scripts, analysis tools, acceptance test, production acceptance, calibration (inspection, test or calibration), simulator, emulator, and software used in post-delivery service provisions. The following types of software are not within scope of this document: — deliverable software (refer to EN 9115); — manufacturing and measuring equipment embedded software (e.g. operating system, drivers); — enterprise or office software (e.g. MS Office, word processing or spreadsheet applications, Teams, network software, email, employee management system). Operational processes not covered in this document are addressed by the respective organization’s quality management system (QMS), based on the EN 9100-series (i.e. EN 9100, EN 9110, EN 9120) and/or ISO 9001 standards.
EN 9125:2025 is classified under the following ICS (International Classification for Standards) categories: 03.100.70 - Management systems; 03.120.10 - Quality management and quality assurance; 35.080 - Software; 49.020 - Aircraft and space vehicles in general. The ICS classification helps identify the subject area and facilitates finding related standards.
EN 9125:2025 has the following relationships with other standards: It is inter standard links to ISO 9000:2015, EN 868-2:2025, EN 868-4:2025, EN 868-7:2025, EN 868-6:2025, EN 868-3:2025. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.
EN 9125:2025 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
SLOVENSKI STANDARD
01-julij-2025
Aeronavtika - Zahteve za letalske, vesoljske in obrambne organizacije -
Nedobavljiva programska oprema
Aerospace series - Requirements for Aviation, Space, and Defence Organizations - Non-
Deliverable Software
Qualitätsmanagementsysteme - Anforderungen an Organisationen der Luftfahrt,
Raumfahrt und Verteidigung - Nicht Mitgelieferte Software
Systèmes de management de la Qualité - Exigences pour les Organisations de
l'Aéronautique, l'Espace et la Défense - Logiciel non livrable
Ta slovenski standard je istoveten z: EN 9125:2025
ICS:
35.080 Programska oprema Software
49.020 Letala in vesoljska vozila na Aircraft and space vehicles in
splošno general
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.
EN 9125
EUROPEAN STANDARD
NORME EUROPÉENNE
May 2025
EUROPÄISCHE NORM
ICS 49.020
English Version
Aerospace series - Quality management systems - Non-
deliverable software requirements
Série aérospatiale - Systèmes de management de la Luft- und Raumfahrt - Qualitätsmanagementsysteme -
qualité - Exigences relatives aux logiciels non livrables Anforderungen an nicht mitgelieferte Software
This European Standard was approved by CEN on 7 April 2025.
CEN members are bound to comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for giving this
European Standard the status of a national standard without any alteration. Up-to-date lists and bibliographical references
concerning such national standards may be obtained on application to the CEN-CENELEC Management Centre or to any CEN
member.
This European Standard exists in three official versions (English, French, German). A version in any other language made by
translation under the responsibility of a CEN member into its own language and notified to the CEN-CENELEC Management
Centre has the same status as the official versions.
CEN members are the national standards bodies of Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia,
Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway,
Poland, Portugal, Republic of North Macedonia, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and
United Kingdom.
EUROPEAN COMMITTEE FOR STANDARDIZATION
COMITÉ EUROPÉEN DE NORMALISATION
EUROPÄISCHES KOMITEE FÜR NORMUNG
CEN-CENELEC Management Centre: Rue de la Science 23, B-1040 Brussels
© 2025 CEN All rights of exploitation in any form and by any means reserved Ref. No. EN 9125:2025 E
worldwide for CEN national Members.
Contents Page
European foreword . 3
Introduction . 4
1 Scope . 5
2 Normative references . 5
3 Terms and definitions . 6
4 Design and development of non-deliverable software . 6
4.1 General. 6
4.2 Design and development planning . 6
4.3 Design and development inputs . 7
4.4 Verification . 8
4.5 Validation . 8
4.6 Release review and approval . 8
4.7 Design and development outputs . 8
4.8 Configuration management . 9
4.8.1 Identification and traceability . 9
4.8.2 Control of changes . 9
4.9 Information security . 9
5 Externally provided software . 9
5.1 General. 9
5.2 Software selection . 10
5.3 Information for external providers. 10
5.4 Design and development . 10
5.5 Acceptance and maintenance . 10
6 Release and control . 10
6.1 General. 10
6.2 Release and distribution . 10
6.3 Access control. 11
6.4 Obsolete software . 11
6.5 Preservation of software . 11
6.6 Documented information . 12
Annex A (informative) Acronym log . 13
Bibliography . 14
European foreword
This document (EN 9125:2025) has been prepared by ASD-STAN.
After enquiries and votes carried out in accordance with the rules of this Association, this document has
received the approval of the National Associations and the Official Services of the member countries of
ASD-STAN, prior to its presentation to CEN.
This document shall be given the status of a national standard, either by publication of an identical text
or by endorsement, at the latest by November 2025, and conflicting national standards shall be
withdrawn at the latest by November 2025.
Attention is drawn to the possibility that some of the elements of this document may be the subject of
patent rights. CEN shall not be held responsible for identifying any or all such patent rights.
According to the CEN-CENELEC Internal Regulations, the national standards organizations of the
following countries are bound to implement this document: Austria, Belgium, Bulgaria, Croatia, Cyprus,
Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy,
Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of North
Macedonia, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and the
United Kingdom.
Introduction
This document specifies the requirements for the effective control of non-deliverable software utilized
in the design, production, evaluation, test, acceptance, or calibration of a deliverable product. This
document supersedes the aerospace recommended practice, SAE ARP9005, Aerospace Guidance for
Non-Deliverable Software, published in June 2005.
This document standardizes, to the greatest extent possible, the non-deliverable software requirements
for the Aviation, Space, and Defence industry. The establishment of common requirements for use at all
levels of the supply chain by organizations around the world is intended to result in improved quality,
schedule, and cost performance by the reduction or elimination of organization unique requirements
and wider application of good practices.
Applicability of this document should be based on the context of organization, business, operations and
product development. Other standards may be required for higher quality assurance and safety
criticality levels as appropriate. The organization should identify applicable non-deliverable software
based on the impact to the deliverable products and services.
In this document, the following verbal forms are used:
— “shall” indicates a requirement;
— “should” indicates a recommendation;
— “may” indicates a permission;
— “can” indicates a possibility or a capability.
Information marked as “NOTE” is for guidance in understanding or clarifying the associated
requirement, and “e.g.” indicates suggestions given for guidance.
See Annex A for a list of acronyms applicable to this document.
Notes to entry used in definitions, however, are considered normative and will provide additional information
that supplements the terminological data such as statements, instructions, recommendations or requirements
relating to the use of a term.
1 Scope
This document specifies the requirements for the effective control of non-deliverable software.
This document can be used during the design, development, test, production, release, use, maintenance,
and retirement of non-deliverable software. This can include non-deliverable software procured from
external suppliers and utilized in the design, production, evaluation, test, acceptance, or calibration of a
deliverable product.
This document focuses solely on the unique requirements of the operational processes that pertain to
non-deliverable software as identified below.
This document applies to non-deliverable software (including firmware) that affects a deliverable
product or service. Following are several applications and supporting examples of non-deliverable
software that is within the scope of this document:
— design and development: modelling, simulation, virtual reality, virtual machine, computer-aided
design (CAD), three-dimensional (3D) modelling and analysis tools, software compiler, and code
generators;
— manufacturing: additive manufacturing, computer numerical controlled (CNC) programs, robotics,
factory automation, tools that load deliverable software, software used in special process (e.g. heat
treat, shot peen, sonic wall inspection), and automated manufacturing software (i.e. pick and
place);
— verification, validation and maintenance: coordinate measuring machine (CMM) programs,
hardware or software qualification, code coverage, test scripts, analysis tools, acceptance test,
production acceptance, calibration (inspection, test or calibration), simulator, emulator, and
software used in post-delivery service provisions.
The following types of software are not within scope of this document:
— deliverable software (refer to EN 9115);
— manufacturing and measuring equipment embedded software (e.g. operating system, drivers);
— enterprise or office software (e.g. MS Office, word processing or spreadsheet applications, Teams,
network software, email, employee management system).
Operational processes not covered in this document are addressed by the respective organization’s
quality management system (QMS), based on the EN 9100-series (i.e. EN 9100, EN 9110, EN 9120)
and/or ISO 9001 standards.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content
constitutes requirements of this document. For dated references, only the edition cited applies. For
undated references, the latest edition of the referenced document (including any amendments) applies.
ISO 9000, Quality management systems — Fundamentals and vocabulary
3 Terms and definitions
For the purpo
...



