Display qualification
Display system software and environmental qualification evidence review
This review reads the qualification evidence a display article rests on, before it is cited in a TSO or STC package. It looks at the DO-178C software life-cycle data at the declared DAL alongside the DO-160G environmental campaign, then checks that the objective closure, the declared categories, and the reports behind each claim match what the certification argument will lean on. A qualification engineer runs it during evidence assembly, so a partially closed objective or an over-declared category is caught before it anchors a compliance claim. You receive a product-specific gap list against the qualification plan, a trace map into the certification basis and means of compliance, and a sequence for closing each open item.
When this review is needed
- A display article's DO-178C data and DO-160G campaign are finishing and both have to be checked before they feed a certification claim.
- A late software build has to be reconciled with the environmental evidence taken on an earlier configuration.
- A qualification test ran with a deviation and the disposition has to hold up when the evidence is cited.
- The declared DAL and objective set have to be confirmed complete before they anchor the compliance argument.
The problem
A display's qualification pulls together two bodies of evidence that move at different speeds: software life-cycle data that has to close a full DO-178C objective set at the declared DAL, and an environmental campaign tied to a specific hardware and software build. Objectives get claimed complete while a verification result is still open, and the DO-160G reports can lag a software build that changed after the article was tested. Read separately they look done; read together the seams show, and by then the campaign is over.
What gets reviewed
- DO-178C objectives at the declared DAL checked for closure against actual life-cycle data items
- Requirements-to-test traceability for the display software verified for unexplained breaks
- Display environmental categories under DO-160G checked against the setups that produced each report
- The software and hardware build the environmental campaign tested reconciled to the build being certified
- Display test deviations and failures traced to a disposition that survives being cited in the package
- The display qualification plan reconciled to the certification basis and the means of compliance it feeds
Scope this review
Tell us the asset, the event, and the evidence in scope, and we will outline a focused first engagement.
Identify what is missing against the means of compliance.
What gets validated
- Each DO-178C objective claimed at the declared DAL is closed by a real life-cycle data item, not a matrix entry alone
- Traceability from requirement to test across the display software holds with no link left unexplained
- Each declared display DO-160G category is backed by a report whose setup genuinely represented that condition
- The build the environmental campaign tested matches the software and hardware being certified
- Every display test deviation carries a disposition that holds when the report is cited in a compliance claim
Evidence normally required
- The display qualification plan with the declared DAL and DO-160G category set
- DO-178C software life-cycle data and the requirements-to-test traceability
- Environmental test reports with their setup and build descriptions
- Deviation and failure logs from the display campaign with their dispositions
- The software and hardware build definition the evidence is meant to support
Common discrepancies
- A DO-178C objective shown satisfied in the matrix that no life-cycle data item actually closes
- Environmental reports taken on a build the software has since moved past
- A display DO-160G category declared broader than the setups actually covered
- A deviation left without a disposition that would survive being cited in a package
What is at stake
A DO-178C objective cited as closed but not satisfied, or an environmental result taken on a superseded build, invites a finding when an authority reads the evidence against the claim. On a display the DAL is usually high and the objective set large, so a gap found after the package is submitted is expensive to close, and a build mismatch can put the whole environmental campaign back in question.
How the work runs
Anchor to the display plan and DAL
Fix the display qualification plan, the declared DAL, and the build the evidence is meant to support.
Close every objective
Confirm each DO-178C objective is closed by a real life-cycle data item and traceability holds.
Reconcile the build
Check that the environmental campaign was run on the build being certified.
Order the display closure work
Sequence objective closure, re-test, and disposition by difficulty against the citing date.
What the buyer receives
- A product-specific gap list against the display qualification plan, ranked by closure difficulty
- A trace map from each display qualification result into the certification basis and means of compliance
- A closure sequence covering objective closure, re-test, and disposition work before the display evidence is cited
Who uses the output
- Qualification and software engineers confirming both bodies of display evidence support the claims they feed
- Certification leads deciding which display objectives and reports are ready to cite and which need rework
- Program managers weighing display re-test and objective-closure cost against the certification schedule
How the work fits into the transaction or program
The review runs at the close of the qualification effort and before the evidence is cited, reading the software and environmental evidence together so a build mismatch or an open objective is caught while rework is still possible. Its gap list drives the closure and re-test work, and its trace map hands the TSO or STC package evidence whose software and hardware builds already agree.
Start with a single asset
Confirm requirements map to substantiating evidence.
Jurisdiction-specific considerations
The FAA and the European system both recognize DO-178C and DO-160G, but the environmental conditions and the objective expectations for a display are not always aligned, and the build configuration control an authority expects can differ. The review notes where a declared objective or category rests on an interpretation the receiving authority treats differently.
Regulatory limits
The review measures the display qualification evidence against the claims it will feed and marks where it holds or overreaches. It witnesses no testing, closes no DO-178C objective, grants no authorization, and makes no airworthiness determination on the article.
What this review does not cover
- Running or re-running display qualification tests or software verification
- Signing off a disposition on a display test failure for the supplier
- Any equipment authorization or airworthiness determination on the display
Specific to this review
- A display's software and environmental evidence are tied to a build, so the review reconciles the build the DO-160G campaign tested to the one the software has reached, which is where late changes most often break the link.
- A compliance matrix entry is a claim, not a closure, so the review reads each DO-178C objective at the declared DAL down to the life-cycle data item that actually satisfies it.
- Because a display's DAL is usually high, an objective that was declared done and never finished stays hidden until an authority reads the data behind the matrix.
Sources
U.S. Government (eCFR). Type certificates, STCs (Subpart E), TSO authorizations (Subpart O), PMA (Subpart K), and export airworthiness approvals (Subpart L).
European Union / EASA. EASA design and production certification, STCs, ETSO authorizations, and EASA Form 1 release.
RTCA. Environmental qualification test categories and procedures referenced by TSO and equipment qualification.
RTCA. Objectives and lifecycle data for airborne software assurance, by design assurance level (DAL A-E).
Frequently asked questions
Why read the software and environmental evidence together instead of separately?
Both bodies of evidence are tied to a build, and a display's software often changes after environmental testing. Reading them together catches a DO-160G report taken on a superseded build or an objective the matrix shows done but the data never closed, before either weakness anchors the certification claim.
Relevant glossary terms
Related pages
Where this fits
Talk to an engineer who has done this work
We will walk through your current state, the records or evidence involved, and a scoped first engagement.
Talk through the aircraft, records, evidence, deadline, and next useful step.