Certification plan
Certification plan evidence review for hardware assurance teams
This review checks that a certification plan and the data package underneath it still agree. A certification engineer reads the plan's certification basis, its statement of affected areas, and the compliance and review commitments it makes to the authority, then compares each promise against the evidence the program has actually produced. Hardware assurance teams use it before a stage review, in a finding response, or when scope creep has pulled the plan and the data apart. You receive a gap list of commitments the data does not yet meet, an evidence map, and a closure sequence.
When this review is needed
- A stage review is coming and the plan's commitments have to line up with what the data package holds.
- The authority asked whether the program is delivering the coverage the plan promised.
- Scope grew during development and the plan was never updated to match the work.
- The certification basis shifted and the plan's stated basis may be out of date.
The problem
A certification plan is a set of promises made early, when the design and the basis were less settled than they later become. As the program runs, the affected areas expand, methods get chosen differently than planned, and the basis is refined, but the plan often stays frozen at its initial revision. That leaves it committing the program to coverage the data package is not building, or describing a basis the design has already moved past.
What gets reviewed
- The certification basis stated in the plan against the current, refined basis
- The statement of affected areas against the design the program actually changed
- Compliance methods committed in the plan against the methods the evidence uses
- Review and data-submittal commitments against the program's actual milestones
- Assumptions in the plan that later design decisions may have overtaken
- Consistency between the plan and the compliance matrix built from it
What gets validated
- The certification basis in the plan matches the current basis, with refinements captured
- Affected areas in the plan cover everything the design change actually touches
- Committed compliance methods match the methods the data package employs
- Review and submittal commitments are ones the program's milestones can meet
- The plan and the compliance matrix describe the same scope with no divergence
Evidence normally required
- The certification plan at its current revision
- The current certification basis
- The design change definition and affected-area analysis
- The compliance matrix and the evidence produced to date
- The program milestone schedule
Common discrepancies
- A plan committing to a compliance method the data package no longer uses
- Affected areas in the plan narrower than the design change actually reaches
- A stated certification basis that predates a refinement the program has adopted
- A review commitment the program schedule can no longer meet as written
What is at stake
A plan the data package does not back is a set of commitments the program will miss at the stage review, and the authority reads the plan as the yardstick. A gap between the two forces either a scramble to produce the promised evidence or a plan revision negotiated late, both of which cost schedule at exactly the point where the program has the least of it.
Move from findings to resolution
Identify gaps against the means of compliance.
How the work runs
Re-read the commitments
Extract the plan's basis, affected areas, and compliance and review commitments as testable claims.
Match against the data
Compare each commitment to the evidence and methods the program has actually produced.
Check the schedule
Confirm review and submittal commitments are ones the current milestones can still meet.
Reconcile before the review
List the deltas and sequence whether each closes with evidence or a plan revision.
What the buyer receives
- A gap list of plan commitments the evidence does not yet satisfy
- An evidence map tying each commitment to the data produced against it
- A closure sequence for reconciling the plan and the data package before the stage review
Who uses the output
- Hardware assurance leads confirming the plan and the program are aligned
- Certification leadership answering a finding on a plan commitment
- Engineering leads deciding whether to revise the plan or close the delta with evidence
How the work fits into the transaction or program
The certification plan is the agreement the authority holds the program to, and every other evidence type is scoped by it. Reconciling it with the data package before a stage review keeps the program from arriving with commitments it cannot meet and turns the plan back into a working baseline instead of a stale one.
Start with a single asset
Confirm requirements trace through verification.
Jurisdiction-specific considerations
FAA and EASA both expect a certification plan, but they name and structure it differently and attach their own liaison and involvement expectations to it, and EASA can pin commitments through certification review items the FAA process handles through issue papers. The review flags where a plan written for one authority would need reshaping for the other.
Regulatory limits
This review reads the plan against the evidence for alignment. It does not author or approve the certification plan, agree the basis with the authority, or make a compliance finding. Acceptance of the plan rests with the authority.
What this review does not cover
- Writing or revising the certification plan
- Negotiating the certification basis with the authority
- Any compliance finding on the plan or the program
Specific to this review
- A certification plan is written at the moment of least certainty and then rarely updated, so it drifts from the program more than any other governing document.
- The plan is the yardstick at a stage review, so a promise the data does not back becomes the review's agenda rather than a footnote.
- Scope creep shows up first as a mismatch between the plan's affected areas and the change the design actually made.
Sources
U.S. Government (eCFR). Type certificates, STCs (Subpart E), TSO authorizations (Subpart O), PMA (Subpart K), and export airworthiness approvals (Subpart L).
Federal Aviation Administration. FAA type certification process, certification basis establishment, and compliance findings.
Federal Aviation Administration. STC application process, certification basis, and continued airworthiness obligations of an STC holder.
Frequently asked questions
Should we fix the plan or the data package when they disagree?
That is the decision the review sets up. Some deltas close by producing the promised evidence; others close by revising a commitment the program has good reason to change. The gap list separates the two so leadership decides each on its merits rather than defaulting to a late scramble.
Relevant glossary terms
Related pages
Where this fits
Talk to an engineer who has done this work
We will walk through your current state, the records or evidence involved, and a scoped first engagement.
Talk through the aircraft, records, evidence, deadline, and next useful step.