NFPA compliance software: what the standards actually require of your records
NFPA 25, 72, 10 and 110 each specify what an inspection record must contain and how long it is kept. What that means when choosing compliance software, the record fields the standards name, and why most spreadsheet systems fail at the AHJ visit rather than at the inspection.
By Hovermarks team
Quick answer. The NFPA standards do not mandate a particular software product, but they do specify what records must exist, what those records contain, and how long they are retained: NFPA 25 requires records of every inspection, test and maintenance activity with dates and the person performing them, kept until the next comparable activity plus one year; NFPA 72 requires completion and testing documentation retained per the standard's cycle; NFPA 10 requires monthly inspection records and service tags; NFPA 110 requires records of every EPSS test and inspection. Software that cannot produce these per asset, on demand, is not compliance software.
"NFPA compliance software" is a category invented by vendors, not by NFPA. No product is NFPA-certified. What exists is a set of record obligations inside each standard, and software that either satisfies them or does not.
What each standard asks of the record
NFPA 25 (water-based systems). Records of inspection, testing and maintenance, with the procedure performed, the organisation and person who did it, the results, and the date. Retention runs until the next comparable activity is recorded, plus a year, which for a 5-year internal inspection means holding that record for six years.
NFPA 72 (fire alarm). A record of completion at installation, and inspection and testing records showing the devices tested, the results, and who performed them. The record of completion follows the system for its life, and matters more than owners expect at the point a system is modified.
NFPA 10 (extinguishers). Monthly inspection records, an annual maintenance tag or label, verification-of-service collars for internal examinations, and hydrostatic test records. The tag on the unit is the minimum, and it is also the most fragile: tags leave with the extinguisher when it goes for service.
NFPA 110 (emergency power). Records of the weekly inspection, each monthly load test with run time and loading achieved, annual load bank results where applicable, and the 3-year test for Level 1 systems.
The pattern behind all four
Every one of them attaches the record to the asset, dated, attributed to a named person, with results. That single shape decides whether software works for this job:
- Per-asset, not per-visit. The AHJ asks about a device, not a job.
- Attributed. A record with no named performer is worth little in an incident investigation.
- Retained past the obvious. Multi-year cycles mean multi-year retention, and the 2-year purge policy written for office documents is how good programmes lose the record that mattered.
- Retrievable in minutes. The standards do not say "quickly", but every AHJ visit and insurance claim tests it anyway.
Why spreadsheets fail here, specifically
Not because they cannot hold the fields. Because the frequency logic (six NFPA 25 tiers, four NFPA 10 intervals, four NFPA 110 cycles) has to run per device across a whole estate, and because the photographic and signature evidence lives somewhere else, usually a phone or a shared drive, detached from the row that references it. The spreadsheet says compliant. The evidence does not exist in a form anyone can walk.
What to require of software
- Per-asset record with date, performer, procedure and result
- Frequency scheduling per asset with overdue visibility across sites
- Photo and signature evidence attached to the record itself
- Retention that outlasts the longest cycle in your estate
- Export in an open format so the records survive a change of vendor
- Verification a third party can perform without your involvement
Where Hovermarks fits
Hovermarks holds every inspection against the QR-tagged asset it describes, with the performer, date, result and photo evidence in the same record, an append-only tamper-evident audit log behind it, retention tiers of 90 days, 13 months or 7 years by plan, unlimited storage for the evidence itself, and CSV or JSON export whenever you want it. AuditorPack bundles a compliance period into one signed export with a public verification URL.
See the fire inspection solution, or build a schedule first with the free NFPA ITM schedule builder.