Skip to content

Connectivity system

Connectivity system TSO authorization evidence support

This support prepares a connectivity system's certification evidence for a TSO authorization, spanning the antenna installation assumptions, the network architecture, the airworthiness security process, and the environmental qualification. A supplier building the system runs it when those four strands each have to reconcile to the declared basis before the authority reviews them. The work reads the delivered evidence, marks where an architecture, security, or environmental claim lacks a supporting artifact, and orders the gaps so blocking items clear first. You receive a system-specific gap list, a requirement-to-evidence trace, and a closure sequence for the authorization.

When this review is needed

  • The supplier is filing for a TSO authorization on a connectivity system and needs the security and architecture evidence checked first.
  • The airworthiness security process is documented but its outputs have not been traced into the compliance matrix.
  • The network architecture changed to add a segregation boundary and the environmental and security evidence has not caught up.
  • The antenna installation assumptions need reconciling with the environmental qualification the basis requires.

The problem

A connectivity system is where an aircraft touches an untrusted network, so its certification basis carries a strand most equipment does not: airworthiness security under DO-326A, which asks the supplier to show the threat environment was assessed and the architecture protects the aircraft from it. That process produces its own artifacts, a threat assessment, a security architecture, and a set of security requirements, and those artifacts have to trace into the same compliance matrix as the antenna, network, and DO-160G evidence. Suppliers often run the security process as a parallel workstream, and by authorization time its outputs sit alongside the rest of the evidence without being wired into it.

What gets reviewed

  • Antenna installation assumptions against the environmental and interference evidence on file
  • Network architecture, segregation boundaries, and data-path definitions
  • Airworthiness security process outputs under DO-326A traced into the compliance matrix
  • DO-160G environmental qualification against the categories the certification basis assigns
  • The compliance matrix mapping each requirement, including security requirements, to a named artifact
  • Traceability from the security and architecture claims to the artifacts that substantiate them

Scope this review

Tell us the asset, the event, and the evidence in scope, and we will outline a focused first engagement.

Identify what is missing against the means of compliance.

What gets validated

  • Each DO-326A security process output traces to the compliance-matrix line it is meant to satisfy
  • The network architecture and segregation boundaries in the evidence match the current design definition
  • Antenna installation assumptions are consistent with the environmental and interference results on file
  • Every DO-160G category the basis assigns has a passing result at the represented configuration
  • No security requirement is recorded without a demonstrated verification or a substantiated closure

Evidence normally required

Common discrepancies

  • Security process outputs held as standalone documents with no trace into the compliance matrix
  • A segregation boundary added in design but not reflected in the environmental or security evidence
  • A security requirement recorded without a verification result or a substantiated rationale for closure
  • Antenna installation assumptions that conflict with the interference results on file

What is at stake

A security process whose outputs never trace into the compliance matrix reads as a set of documents the authority cannot connect to the requirements they are meant to satisfy, and airworthiness security is not a strand a reviewer lets pass on trust. Filing without that trace draws a finding that reopens the security argument late, and because the architecture, the security requirements, and the environmental evidence are coupled, unwinding one often disturbs the others under schedule pressure.

How the work runs

01

Anchor the basis

Confirm the TSO certification basis and the security, architecture, and environmental requirements the system is held to.

02

Wire the security outputs

Trace each DO-326A output to the compliance-matrix line it satisfies and mark any left standalone.

03

Reconcile the coupled strands

Check that architecture, security, and environmental evidence agree on the current segregation and configuration.

04

Order the closure

Sequence open items so coupled security and architecture work is cleared in the right order, and hand back the plan.

What the buyer receives

  • A system-specific gap list ordered by what blocks the authorization first
  • A trace map linking each requirement, including DO-326A security requirements, to its artifact
  • A closure sequence that keeps the coupled security, architecture, and environmental items in order

Who uses the output

  • Certification engineers assembling the TSO submission for the connectivity system
  • Security engineers wiring DO-326A outputs into the compliance matrix
  • Program leads managing the coupling between security, architecture, and environmental closure

How the work fits into the transaction or program

The review runs after the security, architecture, and environmental workstreams have produced their evidence but before the TSO filing is set. It confirms the security outputs are traced into the same matrix as the rest and that the coupled strands agree, so the filing presents one connected argument rather than parallel bodies of evidence the authority has to reconcile.

Start with a single asset

Confirm requirements map to substantiating evidence.

Jurisdiction-specific considerations

The FAA and EASA both treat airworthiness security seriously but can differ in how they expect the DO-326A argument documented and referenced, and a system pursued for both has to satisfy the stricter expectation without ambiguity. The review flags where a security or architecture claim reads cleanly for one authority but leaves the other with an open question.

Regulatory limits

This work checks readiness of the supplier's evidence, including the security argument. It grants no TSO authorization, makes no airworthiness or security finding, and does not act for the authority. Only the FAA authorizes the system, and only after reviewing the submitted data.

What this review does not cover

  • Performing the DO-326A threat assessment or developing the security architecture
  • Conducting the antenna, interference, or DO-160G environmental testing
  • Filing the TSO application or corresponding with the authority for the supplier

Specific to this review

  • Connectivity systems carry an airworthiness security strand under DO-326A that most equipment evidence does not, and its outputs must trace into the same matrix as everything else.
  • The security process usually runs as a parallel workstream, so its artifacts often arrive at authorization unwired from the requirements they satisfy.
  • Security, architecture, and environmental evidence are coupled, so a late change to a segregation boundary disturbs all three at once.
  • A security requirement without a verification result or a substantiated closure is a gap the review will not let pass on the strength of the document alone.

Sources

Frequently asked questions

Why does the DO-326A security work need to trace into the same matrix as the environmental evidence?

Airworthiness security is part of the certification basis, so its requirements sit in the same compliance matrix as antenna, network, and DO-160G requirements. If the threat assessment and security architecture stay as standalone documents, the authority cannot connect them to the requirements they close. The review wires the security outputs into the matrix so the whole argument reads as one connected package.

Relevant glossary terms

Related pages

Where this fits

Talk to an engineer who has done this work

We will walk through your current state, the records or evidence involved, and a scoped first engagement.

Talk through the aircraft, records, evidence, deadline, and next useful step.