Certification evidence
DO-178C SOI-2 development data evidence review for DO-178C
This review is for avionics suppliers, Engineering teams, Certification teams responsible for DO-178C SOI-2 development data. It is triggered by sOI-2 audit scheduled. EE checks high-level, low-level requirements, design descriptions, plus the governing plan or application, against DO-178C. Discrepancies include missing source records, mismatched configuration, unsupported assumptions, or childless requirements in the trace. Output includes DO-178C SOI-2 development data exception register, Claim to evidence map, Reviewer question list.
When this review is needed
- The team is preparing for sOI-2 audit scheduled.
- Supplier records and applicant records must be reconciled.
- Program leads need to know which findings could block the next gate.
- A proposed means of compliance depends on evidence reuse, analysis, or rationale.
The problem
Reviewers need to reconstruct the path from final claim to source data. For DO-178C SOI-2 development data, weak files usually show childless requirements in the trace, then reveal revision drift or unclosed assumptions.
What gets reviewed
- Review high-level against the configuration, installation, or claim under review.
- Compare low-level requirements against the configuration, installation, or claim under review.
- Trace design descriptions against the configuration, installation, or claim under review.
- Challenge source code samples against the configuration, installation, or claim under review.
- Reconcile bidirectional traceability against the configuration, installation, or claim under review.
- Confirm derived requirements with rationale against the configuration, installation, or claim under review.
What gets validated
- Pass check: high-level must match the released configuration and the claimed means of compliance.
- Configuration check: low-level requirements must match the released configuration and the claimed means of compliance.
- Trace check: design descriptions must match the released configuration and the claimed means of compliance.
- Rationale check: source code samples must match the released configuration and the claimed means of compliance.
- Closure check: bidirectional traceability must match the released configuration and the claimed means of compliance.
Evidence normally required
- Controlled high-level
- Released low-level requirements
- Signed design descriptions
- Current source code samples
- Archived bidirectional traceability
- Supplier derived requirements with rationale
Common discrepancies
- Gap: childless requirements in the trace.
- Mismatch: derived requirements with no rationale.
- Unsupported claim: no record of feedback to the safety process.
- Late issue: code that does not match the design description.
- Configuration break: transition criteria that were declared met without the exit evidence.
What is at stake
An unresolved gap can become a finding, a deferred submittal, or a narrower claim. Missing support for derived requirements with no rationale often affects several records at once.
Move from findings to resolution
Identify gaps against the means of compliance.
How the work runs
Frame 178c Soi
Confirm the exact event, affected file set, buyer role, and decision standard before any high-level is treated as sufficient.
Trace Review Prep
Walk the named evidence from index entry to source artifact and mark where the trail supports, conflicts with, or fails to answer the page-specific question.
Sort Evidence Certification
Group exceptions by closure route: document retrieval, data correction, engineering disposition, authority response, or contractual decision.
Package Design Code
Deliver the exception list, evidence map, and owner sequence in a form that can move directly into remediation, submittal cleanup, or transaction negotiation.
What the buyer receives
Who uses the output
- software lead assign closure actions from the exception register.
- certification liaison use the map to locate source evidence.
- DER decide what can proceed and what must wait.
How the work fits into the transaction or program
Will the development data survive the sample-based SOI-2 audit. The evidence set centers on high-level and low-level requirements, design descriptions, source code samples, bidirectional traceability, and derived requirements with rationale and safety feedback records. The likely weak points are orphan and childless requirements in the trace, derived requirements with no rationale and no record of feedback to the safety process, code that does not match the design description, and transition criteria that were declared met without the exit evidence. The output gives the software lead a cleanup register for DO-178C SOI-2 development data before SOI-2 audit.
Start with a single asset
Confirm requirements trace through verification.
Regulatory limits
This review is not an approval activity. Final findings, acceptance, installation approval, and airworthiness decisions remain with the responsible applicant, authorized representatives, and authorities.
What this review does not cover
- Authority negotiations as decision maker
- Compliance finding approval
- Test execution or article build
- Operator airworthiness release
Specific to this review
- Configuration identity matters because evidence from another baseline may prove a different article, load, or installation.
- A useful trail names the source record, revision, owner, and closure decision for each claim.
- The exception list separates document-control cleanup from gaps that need engineering substantiation.
- The finding pattern for this page is specific: childless requirements in the trace changes the strength of the certification argument.
- The scope uses the 178c Soi Development Review question as the control point, so the review stays tied to SOI-2 audit scheduled and the buyer decision behind it.
- The evidence starts with High-level and follows Prep Data Evidence Certification references until every exception has a source location and a reason code.
- The finding logic separates missing paperwork, conflicting status, stale revision data, and unsupported disposition because each class closes through a different owner.
- The timing matters for software lead: the output is useful only if the unresolved items are visible before acceptance, submittal, handback, or negotiation pressure fixes the sequence.
- The boundary control keeps Requirements Design Code Sampled questions in the records or certification lane and sends technical acceptance issues to the authorized people who own them.
- The handoff value comes from DO-178C SOI-2 development data exception register; it gives the next reviewer a precise map instead of another broad request for a better file.
Sources
RTCA. Objectives and lifecycle data for airborne software assurance, by design assurance level (DAL A-E).
Federal Aviation Administration. FAA type certification process, certification basis establishment, and compliance findings.
Frequently asked questions
What makes this evidence review different from a general file audit?
The scope is tied to 178c soi development review and to the decision named in the request. A general audit can list weak records; this pass ranks the gaps by whether they block soi-2 audit scheduled or can be closed later without changing the decision.
What evidence has to be available before this work starts?
The starting point is high-level, the current status source, and any index or matrix that tells reviewers where the supporting artifact should live. Missing inputs are logged as findings rather than filled with assumptions.
Who decides whether an open item is acceptable?
The review explains what the evidence supports and gives software lead a closure path. Acceptance remains with the buyer, operator, authority, delegated engineer, or authorized person responsible for the underlying airworthiness or certification decision.
Relevant glossary terms
Related pages
Where this fits
Talk to an engineer who has done this work
We will walk through your current state, the records or evidence involved, and a scoped first engagement.
Talk through the aircraft, records, evidence, deadline, and next useful step.