Skip to content

Certification evidence

Previously developed software reuse evidence review for DO-178C

This review is for avionics suppliers, equipment suppliers, Certification teams responsible for previously developed software reuse. It is triggered by reuse of legacy software on a new program. EE checks original approval evidence, its retrievability, change impact analysis covering processor, plus the governing plan or application, against DO-178C. Discrepancies include missing source records, mismatched configuration, unsupported assumptions, or baseline evidence that no one can actually produce anymore. Output includes Previously developed software reuse exception register, Claim to evidence map, Reviewer question list.

When this review is needed

  • The plan names previously developed software reuse as a required deliverable.
  • The review notes that evidence was carried forward from another configuration or installation.
  • The authority or authorized representative is expected to sample the records.
  • Open questions need to be separated from editorial cleanup.

The problem

File volume does not settle the question. The package must show why the evidence proves can previously developed software carry its certification credit into a new installation, changed environment, or higher DAL, especially where baseline evidence that no one can actually produce anymore.

What gets reviewed

  • Review original approval evidence against the configuration, installation, or claim under review.
  • Compare its retrievability against the configuration, installation, or claim under review.
  • Trace change impact analysis covering processor against the configuration, installation, or claim under review.
  • Challenge interfacing system changes against the configuration, installation, or claim under review.
  • Reconcile gap analysis of original evidence against the new required level against the configuration, installation, or claim under review.
  • Confirm service experience record being cited. against the configuration, installation, or claim under review.

What gets validated

  • Pass check: original approval evidence must match the released configuration and the claimed means of compliance.
  • Configuration check: its retrievability must match the released configuration and the claimed means of compliance.
  • Trace check: change impact analysis covering processor must match the released configuration and the claimed means of compliance.
  • Rationale check: interfacing system changes must match the released configuration and the claimed means of compliance.
  • Closure check: gap analysis of original evidence against the new required level must match the released configuration and the claimed means of compliance.

Evidence normally required

  • Controlled original approval evidence
  • Released its retrievability
  • Signed change impact analysis covering processor
  • Current interfacing system changes
  • Archived gap analysis of original evidence against the new required level
  • Supplier service experience record being cited.

Common discrepancies

  • Gap: baseline evidence that no one can actually produce anymore.
  • Mismatch: unchanged-software claim invalidated by a new compiler or target.
  • Unsupported claim: dAL upgrades attempted by testing alone when development data does not exist at the new level.

What is at stake

The cost is rework during authority-facing activity. Teams lose time when unchanged-software claim invalidated by a new compiler or target, because closure may touch configuration control and engineering rationale.

Move from findings to resolution

Identify gaps against the means of compliance.

How the work runs

01

Frame Previously Developed

Confirm the exact event, affected file set, buyer role, and decision standard before any original approval evidence is treated as sufficient.

02

Trace Reuse Review

Walk the named evidence from index entry to source artifact and mark where the trail supports, conflicts with, or fails to answer the page-specific question.

03

Sort 178c Certification

Group exceptions by closure route: document retrieval, data correction, engineering disposition, authority response, or contractual decision.

04

Package Change Impact

Deliver the exception list, evidence map, and owner sequence in a form that can move directly into remediation, submittal cleanup, or transaction negotiation.

What the buyer receives

  • Previously developed software reuse exception register
  • Claim to evidence map
  • Reviewer question list
  • Closure action plan

Who uses the output

  • software lead assign closure actions from the exception register.
  • certification manager use the map to locate source evidence.
  • program manager decide what can proceed and what must wait.

How the work fits into the transaction or program

Can previously developed software carry its certification credit into a new installation, changed environment, or higher DAL. The evidence set centers on the original approval evidence and its retrievability, change impact analysis covering processor, compiler, and interfacing system changes, gap analysis of original evidence against the new required level, and the service experience record being cited. The likely weak points are baseline evidence that no one can actually produce anymore, an unchanged-software claim invalidated by a new compiler or target, and DAL upgrades attempted by testing alone when development data does not exist at the new level. The output gives the software lead a cleanup register for Previously developed software reuse before reuse of legacy software on a new program.

Start with a single asset

Confirm requirements trace through verification.

Regulatory limits

EE provides an evidence-quality assessment only. The work does not certify an article, sign a finding, approve a plan, or decide regulatory acceptance.

What this review does not cover

Specific to this review

  • Configuration identity matters because evidence from another baseline may prove a different article, load, or installation.
  • A useful trail names the source record, revision, owner, and closure decision for each claim.
  • The exception list separates document-control cleanup from gaps that need engineering substantiation.
  • The finding pattern for this page is specific: baseline evidence that no one can actually produce anymore changes the strength of the certification argument.
  • The scope uses the Previously Developed Software Reuse question as the control point, so the review stays tied to Reuse of legacy software on a new program and the buyer decision behind it.
  • The evidence starts with Original approval evidence and follows Review Evidence 178c Certification references until every exception has a source location and a reason code.
  • The finding logic separates missing paperwork, conflicting status, stale revision data, and unsupported disposition because each class closes through a different owner.
  • The timing matters for software lead: the output is useful only if the unresolved items are visible before acceptance, submittal, handback, or negotiation pressure fixes the sequence.
  • The boundary control keeps Pds Change Impact Dal questions in the records or certification lane and sends technical acceptance issues to the authorized people who own them.
  • The handoff value comes from Previously developed software reuse exception register; it gives the next reviewer a precise map instead of another broad request for a better file.

Sources

Frequently asked questions

What makes this evidence review different from a general file audit?

The scope is tied to previously developed software reuse and to the decision named in the request. A general audit can list weak records; this pass ranks the gaps by whether they block reuse of legacy software on a new program or can be closed later without changing the decision.

What evidence has to be available before this work starts?

The starting point is original approval evidence, the current status source, and any index or matrix that tells reviewers where the supporting artifact should live. Missing inputs are logged as findings rather than filled with assumptions.

Who decides whether an open item is acceptable?

The review explains what the evidence supports and gives software lead a closure path. Acceptance remains with the buyer, operator, authority, delegated engineer, or authorized person responsible for the underlying airworthiness or certification decision.

Relevant glossary terms

Related pages

Where this fits

Talk to an engineer who has done this work

We will walk through your current state, the records or evidence involved, and a scoped first engagement.

Talk through the aircraft, records, evidence, deadline, and next useful step.