ASPICE · SUP.1 · Quality Assurance

ASPICE SUP.1 Quality Assurance

Independent, objective assurance that work products and processes comply with plans — with non-conformances recorded, tracked, escalated and resolved.

In short

ASPICE SUP.1 Quality Assurance provides independent and objective assurance that work products and process activities comply with the applicable plans and provisions, that non-conformances are identified, recorded, tracked and resolved, and that unresolved non-conformances can be escalated to appropriate management with assured independence.

SUP.1 is the referee. Its independence is the point — QA that reports into the project it audits is theatre. The tooling job is a controlled non-conformance loop.

Purpose & process outcomes

Purpose (per the ASPICE PAM): provide assurance that work products and processes comply with predefined provisions and plans and that non-conformances are resolved and further prevented.

The process is achieved when these outcomes hold:

Base practices

SUP.1.BP1

Develop a project QA strategy

Define what/when/how QA evaluates.

SUP.1.BP2

Assure quality of work products

Evaluate work products against criteria.

SUP.1.BP3

Assure quality of process activities

Evaluate activities against the defined process.

SUP.1.BP4

Summarize and communicate QA results

Report QA activities and findings.

SUP.1.BP5

Ensure resolution of non-conformances

Track findings to closure.

SUP.1.BP6

Implement an escalation mechanism

Escalate unresolved findings independently.

Work products

The output work products SUP.1 asks for (named per the standard):

Map it to your tools

This is where the standard meets reality. Each work product and outcome has a concrete home — an issue type, work-item type, or model element — in the tools you already run. Types are configurable, so treat this as the typical ASPICE setup:

Work product / outcomeJiraPolarionCodebeamerDOORS NextEnterprise ArchitectConfluence
WP: QA plan / strategyQA plan LiveDocQA plan itemQA plan page
WP: QA audit record / reportQA-audit issue + checklistQA work item / reportQA tracker itemaudit report page + template
WP: non-conformance (finding)'QA Finding' / Non-conformance issue typeNon-conformance work item + workflowQA/NC tracker itemfindings log
Outcome: finding tracked to closureworkflow status + due date + dashboardworkflow state + LiveReportworkflow + reportstatus page
Outcome: escalation recordescalation link / priority + watcher = mgmtescalation field / linked itemescalation fieldescalation page

The trap isn't the tools — it's that the links between them are maintained by hand and decay the moment a requirement changes. (See best ASPICE tools.)

It only matures on one configuration-management data model

Here is the part almost everyone misses. SUP.1 can never reach a mature capability level (CL2+) on its own — it can only be as mature as the configuration-management data model underneath it. SUP.8 Configuration Management is the secret enabling layer: the shared data model of items, versions, baselines and links that is the basis on which every other process group becomes provable. Scatter that data model across a Jira project, a Polarion space, a DOORS module, an EA model and a Confluence tree, and the model is fragmented by construction — the traceability that SUP.1 depends on decays the moment anything changes, and no amount of process ceremony fixes it.

What actually unlocks maturity is a headless ALM — an API-first, tool-agnostic configuration-management data model that is the single source of truth for every work product and every link, readable and writable by both humans and agents — plus an agent/human workflow definition, coordination and traceability platform on top of it, so every change is planned, assigned (to a human or an agent), executed and traced against that one model. That is the layer that lets SUP.1 be mature instead of theatrical.

Where teams fail SUP.1

This is part of The Blueprint — our free template QMS

ASPICE deliberately gives you no blueprint. So we wrote one. This SUP.1 guide is part of The Blueprint — our free, open template QMS for ASPICE: every VDA-scope process area, its outcomes and work products, mapped to concrete artifacts in your tools and grounded in one configuration-management data model. Take it, use it, no cost.

Agents continuously evaluate work products and traceability against the plan and raise structured, tracked non-conformances — so QA has real-time, objective evidence instead of a pre-audit scramble. And we offer to implement The Blueprint for you: our agentic solutions (Vera generates SUP.1's work products and traceability as a byproduct of the build, each with a confidence score and audit trail) running on a partner headless ALM — the API-first configuration-management data model that makes the whole thing provable.

Frequently asked questions

What is SUP.1 in ASPICE?

SUP.1 Quality Assurance provides independent, objective assurance that work products and processes comply with plans, with non-conformances recorded, tracked, escalated and resolved, and QA independence assured.

What are the SUP.1 work products?

A QA plan/strategy, QA records/audit reports, non-conformance (finding) records, and escalation records.

How is SUP.1 different from SUP.9?

SUP.1 is about assuring compliance (QA findings/non-conformances); SUP.9 Problem Resolution manages problems in the product/project to closure. A QA finding may raise a problem or a change request.

How do you track QA non-conformances in Jira?

As a dedicated 'QA Finding'/Non-conformance issue type with a workflow to closure, a due date, and management as watchers for escalation — reported via a dashboard.

Part of the ASPICE explainer series

Grounded in the standard, honest about the theater: All VDA-scope process areas · SUP.9 Problem Resolution · MAN.3 Project Management · SUP.8 CM

Get The Blueprint. Have us implement it.

The Blueprint is our free template QMS for ASPICE. We implement it with our agentic solutions on a partner headless ALM — SUP.1's work products and traceability generated in your tools, with a confidence score and audit trail on every artifact.or book a compliance teardown →

See Vera →