Data loader TSO
Data-loading equipment TSO certification support
This review prepares the data a data-loading unit needs to earn a TSO authorization, covering both its DO-178C software assurance and its DO-160G environmental evidence. A certification specialist reads the software life-cycle data, the load integrity and configuration controls, and the environmental reports against the TSO's requirements and its assigned software level. It is used when a supplier is compiling a TSO application for a data loader and wants the true state of the package before filing. You receive a gap list tied to the required software and environmental evidence, a trace from each requirement to its data, and a sequence for closing what is open.
When this review is needed
- A supplier is preparing a TSO application for a data loader and needs to confirm both the DO-178C and environmental evidence are complete.
- The software life-cycle data exists but the traceability from requirements to test to structural coverage has not been checked at the assigned DAL.
- Load integrity and configuration controls are implemented but not substantiated against the standard's integrity requirements.
- A commercial loader is being taken to TSO and its original software evidence was not produced to DO-178C objectives.
The problem
A data loader carries a software burden most equipment does not, because it writes configuration and software into other aircraft systems, and its own DO-178C evidence has to hold at the assigned design assurance level. Suppliers often have working software and passing environmental reports but incomplete life-cycle data: gaps in requirements-to-test traceability, structural coverage that stops short of the DAL's objectives, or load integrity controls implemented in code but not substantiated as meeting the standard. The environmental side can be clean while the software side is where the TSO actually lives.
What gets reviewed
- DO-178C life-cycle data completeness against the objectives for the assigned DAL
- Requirements-to-code-to-test traceability and structural coverage analysis
- Load integrity, error detection, and configuration management controls in the loading function
- Installation interface behavior when the loader writes to a target system
- DO-160G environmental coverage for the equipment's category and use environment
- Requirement-to-evidence trace across the full set of TSO-required software and environmental data
Scope this review
Tell us the asset, the event, and the evidence in scope, and we will outline a focused first engagement.
Identify what is missing against the means of compliance.
What gets validated
- The DO-178C data package includes the objectives required at the assigned DAL, not a lower level's set
- Requirements trace to code and to test, and structural coverage matches the DAL's coverage objective
- Load integrity and error-detection behavior is substantiated, not merely asserted in a description
- Configuration management identifies exactly which software and data standard the evidence covers
- DO-160G reports cover the categories the loader's use environment demands
Evidence normally required
- The applicable TSO, its assigned DAL, and the performance standard it invokes
- The DO-178C plans, including the PSAC, and the resulting life-cycle data
- Requirements, design, code, and verification records with traceability
- Load integrity, error-handling, and configuration management descriptions
- Environmental qualification reports for the loader's DO-160G categories
Common discrepancies
- Structural coverage analysis that stops short of the objective the assigned DAL requires
- Requirements-to-test traceability with orphan tests or requirements that trace nowhere
- Load integrity controls described in the design but never verified against an integrity requirement
- Software evidence originally produced to a commercial process rather than to DO-178C objectives
What is at stake
A data-loader TSO package with soft DO-178C evidence fails during review when the authority traces a software requirement to its test and finds the coverage or the review record missing at the required level. Closing DO-178C gaps late is among the most expensive recoveries in avionics certification, because reconstructing life-cycle data, coverage analysis, and review records after the fact can approach redoing the software assurance from the requirements down.
How the work runs
Confirm the DAL
Pin the assigned design assurance level and the DO-178C objectives it requires before reading the life-cycle data.
Walk the traceability
Trace requirements to code and to test, and check structural coverage against the DAL's objective.
Substantiate load integrity
Confirm the loading function's integrity and error-detection controls are verified, not just described.
Sequence the closures
Order the verification, coverage, and documentation work so dependent objectives clear in the right order.
What the buyer receives
Who uses the output
- Supplier certification engineers compiling the TSO software and environmental package
- Software assurance engineers scoping the verification and coverage work still owed
- Program managers setting a realistic TSO filing date given the DO-178C effort
How the work fits into the transaction or program
The review stands between the data loader's development and its TSO filing. It reads the DO-178C life-cycle data and the environmental reports against the assigned DAL and the invoked standard, so the supplier files a package whose software objectives are already met rather than discovering a coverage or traceability shortfall during review, when DO-178C rework is at its most costly.
Start with a single asset
Confirm requirements map to substantiating evidence.
Jurisdiction-specific considerations
The FAA and EASA both recognize DO-178C, but they can differ on how they assess the DAL assignment and on the transition credit for software originally developed to an earlier revision or a commercial process. The review flags the DAL and credit questions most likely to be read differently between the two authorities.
Regulatory limits
This work assesses whether the software and environmental evidence meets the TSO's requirements. It does not grant the TSO, make an airworthiness finding, approve the software, or serve as the authority's or the applicant's compliance determination.
What this review does not cover
Specific to this review
- A data loader's TSO lives mostly in its software, because it writes into other systems, so DO-178C evidence usually dominates the package over environmental data.
- Structural coverage is an objective set by the assigned DAL, so coverage that satisfied a lower level is a genuine gap at a higher one, not a minor shortfall.
- Load integrity and error detection must be verified against a requirement, and controls that only appear in a design description do not close the finding.
- Reconstructing DO-178C life-cycle data after the fact is among the costliest recoveries in avionics certification, which is why the traceability check comes early.
Sources
U.S. Government (eCFR). Type certificates, STCs (Subpart E), TSO authorizations (Subpart O), PMA (Subpart K), and export airworthiness approvals (Subpart L).
European Union / EASA. EASA design and production certification, STCs, ETSO authorizations, and EASA Form 1 release.
RTCA. Environmental qualification test categories and procedures referenced by TSO and equipment qualification.
RTCA. Objectives and lifecycle data for airborne software assurance, by design assurance level (DAL A-E).
Frequently asked questions
Our data loader works and the environmental tests passed. Why does the TSO hinge on software?
A data loader writes configuration and software into other aircraft systems, so its integrity matters at the level of the systems it touches, and the TSO demands DO-178C life-cycle evidence at the assigned DAL. Working software and clean environmental reports do not close that: the authority looks for requirements-to-test traceability, structural coverage to the DAL's objective, and verified load integrity. The review isolates which DO-178C objectives your evidence already meets and which still need work before the application is credible.
Relevant glossary terms
Related pages
Where this fits
Talk to an engineer who has done this work
We will walk through your current state, the records or evidence involved, and a scoped first engagement.
Talk through the aircraft, records, evidence, deadline, and next useful step.