Certification plan
Certification plan evidence review for aircraft modifiers
A certification plan evidence review reads the modifier's plan as a set of commitments and checks each one against what the program can actually produce. It is run for aircraft modifiers ahead of a submittal, in response to a project-office finding, or when a change forces the plan to be re-issued. The review confirms the plan names the right certification basis, scopes the affected areas correctly, and does not promise coverage the data package will not contain. You get a gap list, an evidence map from plan commitments to their eventual proof, and a sequence for closing what the plan has over-promised.
When this review is needed
- The plan is about to be submitted and it will set the scope the authority measures the whole program against.
- A finding challenged the plan's stated basis or its list of affected areas.
- A design change has outrun the plan and a revision is needed before the next milestone.
- The plan was drafted early by one team and the program that must deliver against it has since changed.
The problem
A certification plan is written before most of the evidence exists, so it is a set of promises about work not yet done. Teams tend to scope it optimistically: a clean basis, a tidy list of affected areas, a compliance approach that assumes tests will pass on the first attempt. Once the authority accepts the plan it becomes the standard the program is held to, and any place where the plan promised more than the data package will hold turns into a finding later.
What gets reviewed
- The certification basis named in the plan checked against the change being certified and its applicable rules
- The affected-areas list tested for subsystems the change touches but the plan omits
- Each compliance commitment matched to a means the program can realistically deliver
- The plan's proposed level of authority involvement checked against the change's classification
- Cross-references from the plan to the compliance matrix and lower-tier plans confirmed to resolve
- Schedule-linked commitments in the plan flagged where the underlying evidence path is not yet defined
What gets validated
- The basis paragraphs cited in the plan match the rules applicable to this change and its classification
- Every subsystem the change affects appears in the plan's affected-areas discussion
- Each compliance approach in the plan resolves to a means the program has a path to produce
- Lower-tier plan and matrix references named in the plan exist and are the current revisions
- The plan's commitments and the program's actual work breakdown describe the same set of tasks
Evidence normally required
- The current certification plan and any prior accepted revision
- The change description or engineering scope the plan is meant to cover
- The certification basis and any issue papers or special conditions
- The compliance matrix and any subordinate discipline plans the plan references
- The program schedule or milestone list the plan commits against
Common discrepancies
- Affected subsystems touched by the change that the plan's scope does not mention
- Compliance approaches stated in the plan with no defined evidence path behind them
- A basis that predates a change in classification and no longer fits the modification
- References from the plan to a matrix or lower-tier plan revision that has since moved
What is at stake
An over-scoped or mis-based plan quietly commits the program to evidence it will struggle to produce, and the mismatch surfaces at the worst time, during finding response or just before a milestone. Correcting the basis or the affected-area list late means re-issuing the plan and re-opening rows that were thought settled, which pushes the schedule.
Move from findings to resolution
Identify gaps against the means of compliance.
How the work runs
Read the plan as commitments
Extract the basis, affected areas, and compliance approaches the plan promises and treat each as a testable claim.
Test scope against the change
Compare the affected-areas list with the actual reach of the modification and surface omitted subsystems.
Trace commitments to evidence paths
Check that each compliance approach resolves to a means the program can deliver and that references resolve.
Deliver gaps and sequence
Return the over-promised commitments with an evidence map and an order that clears basis and scope first.
What the buyer receives
- A gap list of plan commitments that the data package cannot yet support
- An evidence map linking each plan commitment to the proof intended to satisfy it
- A closure sequence that resolves basis and scope gaps before the dependent commitments
Who uses the output
- STC program managers confirming the plan is safe to submit as the program's yardstick
- Certification engineers answering a finding on basis or affected-area scope
- Engineering leads aligning the work breakdown with what the plan has committed
How the work fits into the transaction or program
The plan sits upstream of the matrix and every discipline report, defining what the program has agreed to prove. Reading it against the deliverable data package early keeps the promise and the proof aligned before the plan becomes the fixed standard the authority applies to everything downstream.
Start with a single asset
Confirm requirements trace through verification.
Jurisdiction-specific considerations
An FAA program frames the plan around the certification project notification and the agreed level of involvement, while an EASA program builds it around the certification programme and its compliance demonstration items. The review checks the plan against the framing the governing authority expects rather than a single house style.
Regulatory limits
This review reads the modifier's own plan. It does not accept the plan, does not agree the basis on the authority's behalf, and makes no airworthiness or compliance determination. Acceptance of the plan and its basis stays with the authority.
What this review does not cover
- Drafting or re-issuing the certification plan for the modifier
- Negotiating the certification basis or level of involvement with the authority
- Producing the compliance evidence the plan commits to
Specific to this review
- A plan's weakest point is usually its affected-areas section, because a change often disturbs an interfacing subsystem that the author did not think to list.
- The plan becomes a liability the moment the authority accepts it, since from then on every gap between promise and proof reads as a shortfall rather than a work item.
- Optimistic scheduling shows up in the plan as commitments with no named evidence path, which are the commitments most likely to slip.
- Re-issuing a plan late is expensive because it can reopen matrix rows and lower-tier plans that were treated as settled.
Sources
U.S. Government (eCFR). Type certificates, STCs (Subpart E), TSO authorizations (Subpart O), PMA (Subpart K), and export airworthiness approvals (Subpart L).
Federal Aviation Administration. FAA type certification process, certification basis establishment, and compliance findings.
Federal Aviation Administration. STC application process, certification basis, and continued airworthiness obligations of an STC holder.
Frequently asked questions
How is a plan review different from a matrix review?
The matrix review checks whether each requirement's evidence exists and is current. The plan review checks the commitments the program made before that evidence existed, catching a mis-scoped basis or an unlisted affected area that a matrix read would take as given.
Relevant glossary terms
Related pages
Where this fits
Talk to an engineer who has done this work
We will walk through your current state, the records or evidence involved, and a scoped first engagement.
Talk through the aircraft, records, evidence, deadline, and next useful step.