Skip to content

Certification evidence

Field-loadable software evidence evidence review for DO-178C

This review is for avionics suppliers, operators, Engineering teams responsible for field-loadable software evidence. It is triggered by first field-loadable release to the fleet. EE checks load integrity mechanisms, their verification, target compatibility data across the hardware part numbers in service, plus the governing plan or application, against DO-178C. Discrepancies include missing source records, mismatched configuration, unsupported assumptions, or corrupted-load protection asserted but never tested against interrupted transfers. Output includes Field-loadable software evidence exception register, Claim to evidence map, Reviewer question list.

When this review is needed

  • A new article, software load, or installation is moving into certification review.
  • Quality control needs a repeatable list of ready and open records.
  • Internal teams need a supplier request list tied to evidence gaps.
  • The buyer wants a defensible package before committing the claim.

The problem

Certification risk sits in the gap between the claimed basis and the records in the folder. With field-loadable software evidence, corrupted-load protection asserted but never tested against interrupted transfers can stay hidden until the exact source record is requested.

What gets reviewed

  • Review load integrity mechanisms against the configuration, installation, or claim under review.
  • Compare their verification against the configuration, installation, or claim under review.
  • Trace target compatibility data across the hardware part numbers in service against the configuration, installation, or claim under review.
  • Challenge protection against partial or interrupted loads against the configuration, installation, or claim under review.
  • Reconcile configuration records that track which aircraft carries which load. against the configuration, installation, or claim under review.

What gets validated

  • Pass check: load integrity mechanisms must match the released configuration and the claimed means of compliance.
  • Configuration check: their verification must match the released configuration and the claimed means of compliance.
  • Trace check: target compatibility data across the hardware part numbers in service must match the released configuration and the claimed means of compliance.
  • Rationale check: protection against partial or interrupted loads must match the released configuration and the claimed means of compliance.
  • Closure check: configuration records that track which aircraft carries which load. must match the released configuration and the claimed means of compliance.

Evidence normally required

  • Controlled load integrity mechanisms
  • Released their verification
  • Signed target compatibility data across the hardware part numbers in service
  • Current protection against partial or interrupted loads
  • Archived configuration records that track which aircraft carries which load.
  • Supplier plan revision

Common discrepancies

  • Gap: corrupted-load protection asserted but never tested against interrupted transfers.
  • Mismatch: compatibility matrices missing hardware dash numbers in the fleet.
  • Unsupported claim: no defined record of loaded configuration so continued airworthiness tracking breaks at the operator.

What is at stake

A weak package can convert a planned review into a long question log. If compatibility matrices missing hardware dash numbers in the fleet, the program may need new evidence before the claim can proceed.

Move from findings to resolution

Identify gaps against the means of compliance.

How the work runs

01

Frame Field Loadable

Confirm the exact event, affected file set, buyer role, and decision standard before any load integrity mechanisms is treated as sufficient.

02

Trace Evidence Review

Walk the named evidence from index entry to source artifact and mark where the trail supports, conflicts with, or fails to answer the page-specific question.

03

Sort Certification Load

Group exceptions by closure route: document retrieval, data correction, engineering disposition, authority response, or contractual decision.

04

Package Bench Fleet

Deliver the exception list, evidence map, and owner sequence in a form that can move directly into remediation, submittal cleanup, or transaction negotiation.

What the buyer receives

  • Field-loadable software evidence exception register
  • Claim to evidence map
  • Reviewer question list
  • Closure action plan

Who uses the output

  • software lead assign closure actions from the exception register.
  • avionics engineer use the map to locate source evidence.
  • continued airworthiness engineer decide what can proceed and what must wait.

How the work fits into the transaction or program

Does the field-loadable software evidence prove that only the approved load, complete and uncorrupted, can end up in the target. The evidence set centers on load integrity mechanisms (part number checks, CRCs) and their verification, target compatibility data across the hardware part numbers in service, protection against partial or interrupted loads, and the configuration records that track which aircraft carries which load. The likely weak points are corrupted-load protection asserted but never tested against interrupted transfers, compatibility matrices missing hardware dash numbers in the fleet, and no defined record of loaded configuration so continued airworthiness tracking breaks at the operator. The output gives the software lead a cleanup register for Field-loadable software evidence before first field-loadable release to the fleet.

Start with a single asset

Confirm requirements trace through verification.

Regulatory limits

The output supports applicant decision making and authority discussions. It does not replace required approvals, designee findings, conformity activity, or airworthiness determinations.

What this review does not cover

Specific to this review

  • Configuration identity matters because evidence from another baseline may prove a different article, load, or installation.
  • A useful trail names the source record, revision, owner, and closure decision for each claim.
  • The exception list separates document-control cleanup from gaps that need engineering substantiation.
  • The finding pattern for this page is specific: corrupted-load protection asserted but never tested against interrupted transfers changes the strength of the certification argument.
  • The scope uses the Field Loadable Software Evidence question as the control point, so the review stays tied to First field-loadable release to the fleet and the buyer decision behind it.
  • The evidence starts with Load integrity mechanisms and follows Review 178c Certification Load references until every exception has a source location and a reason code.
  • The finding logic separates missing paperwork, conflicting status, stale revision data, and unsupported disposition because each class closes through a different owner.
  • The timing matters for software lead: the output is useful only if the unresolved items are visible before acceptance, submittal, handback, or negotiation pressure fixes the sequence.
  • The boundary control keeps Integrity Bench Fleet Fls questions in the records or certification lane and sends technical acceptance issues to the authorized people who own them.
  • The handoff value comes from Field-loadable software evidence exception register; it gives the next reviewer a precise map instead of another broad request for a better file.

Sources

Frequently asked questions

What makes this evidence review different from a general file audit?

The scope is tied to field loadable software evidence and to the decision named in the request. A general audit can list weak records; this pass ranks the gaps by whether they block first field-loadable release to the fleet or can be closed later without changing the decision.

What evidence has to be available before this work starts?

The starting point is load integrity mechanisms, the current status source, and any index or matrix that tells reviewers where the supporting artifact should live. Missing inputs are logged as findings rather than filled with assumptions.

Who decides whether an open item is acceptable?

The review explains what the evidence supports and gives software lead a closure path. Acceptance remains with the buyer, operator, authority, delegated engineer, or authorized person responsible for the underlying airworthiness or certification decision.

Relevant glossary terms

Related pages

Where this fits

Talk to an engineer who has done this work

We will walk through your current state, the records or evidence involved, and a scoped first engagement.

Talk through the aircraft, records, evidence, deadline, and next useful step.