// defence and regulated procurement

A QA supplier NATO can order from without running a new tender

BetterQA holds a Basic Ordering Agreement with the NATO Communications and Information Agency, under NCAGE code 1JGAL. Vendor registration is complete and commercial terms are already agreed, so NCIA can place an order without going back out to the market first. For a programme working to a delivery date, that is weeks removed from the front of the schedule.

1JGALNCAGE code
0New tenders needed to order
ISO 27001Certified, 2022 revision
// what a BOA is

The agreement is a purchasing route, not a badge

A Basic Ordering Agreement registers a supplier with the agency and fixes the commercial terms in advance. Once it is in place, an order can be raised against those terms instead of starting a procurement from scratch. That is the entire value of it, and it is a real one.

It is not a certification. It is not an approval of our testing methods. It is not a security clearance, and there is no NATO scheme that certifies a supplier. The agreement says so in terms on its first page: it obligates neither party to order or to supply anything.

We are spelling that out because plenty of suppliers do not. If a vendor tells you they are NATO certified, NATO approved or NATO cleared, none of those exist, and a procurement officer will know it before you do.

// what it removes

What the agreement takes off your schedule

Vendor registration

Already done. The NCAGE code exists, the entity is on file, and nobody has to sponsor us through registration before work can begin.

Commercial terms

Already agreed. The clauses that normally take a legal review cycle are settled and sitting in the signed agreement.

The tender itself

Not required for an order placed under the agreement. This is the step that costs weeks, and it is the reason a BOA is worth holding.

Information security evidence

Our ISO 27001:2022 certificate covers the management system behind how we handle client data, credentials and test environments. Read the scope note on our certifications page before you rely on it for a specific engagement.

// the honest boundary

What we can take on, and what we cannot

The second column is the more useful one. A supplier who will not tell you where their limits are will find those limits during your project instead.

We can

  • Be engaged through NATO procurement frameworks under the Basic Ordering Agreement.
  • Take defence and government work that does not involve classified material.
  • Work inside client-controlled environments, so test data stays on approved networks.
  • Bring functional, automation, performance and security testing, with the information security controls our ISO 27001 certification requires.
  • Support medical device programmes under ISO 13485:2016, which is unusual for a QA supplier.

We cannot

  • Handle classified information. That needs a government security clearance and we hold none.
  • Staff work that requires cleared personnel, for the same reason.
  • Offer a NATO certification, approval or endorsement of any kind. No such scheme exists.
  • Produce a SOC 2 report. We have no audit and there is no self-certification path to one. Our control documentation against the SOC 2 Trust Services Criteria is available under NDA.
  • Claim a NIS2 certification. There is no scheme to be certified under, although we did build NIS2 Manager.
// why this matters for testing specifically

How a supplier describes itself predicts how it will describe your defects

You are buying an opinion about whether software is ready to ship. The whole service is a claim about evidence, so the supplier's own relationship with evidence is the thing you are actually procuring.

A vendor that writes NATO certified on a page, where no such certification exists, has told you what happens when a release date is close and a test result is inconvenient. We would rather show you the boundary than the badge.

Read the agreement's own limits

The case study walks through what the Basic Ordering Agreement covers, how we got it, and the four things it explicitly does not give us. Read the NATO NCIA case study.

Bring us your procurement requirements

Send the supplier questionnaire. We will answer it line by line and mark clearly where the answer is no.

Need help with software testing?

BetterQA provides independent QA services across manual testing, automation, security audits, and performance testing. ISO 27001, 9001, 14001 and 13485 certified.

Explore our services Get in touch