Display TSO
Display system certification evidence for TSO authorization
This support prepares the certification evidence for a display article so it holds up to a TSO authorization. It reads the DO-178C software life-cycle data at the declared DAL, the human-factors assumptions the design leans on, and the DO-160G environmental qualification, then ties each claim to a document that exists. An engineer who has built display packages runs it during evidence assembly, before the application goes in. You receive a product-specific evidence gap list, a trace map into the certification basis and means of compliance, and a closure sequence that clears the article for authorization.
When this review is needed
- A display article is heading toward a TSO authorization and the software and human-factors evidence needs a read before filing.
- A software change moved the display to a new build and the DO-178C data has to be reconciled to the declared DAL.
- The human-factors assumptions the design rests on have never been checked against the evidence that supports them.
- An earlier display authorization is being extended to a new part number and the reused life-cycle data has to be tested for currency.
The problem
A display article's certification rests heavily on software life-cycle evidence, and DO-178C data is easy to leave partially closed. Objectives for a given DAL can be claimed complete while a verification result or a traceability link is still open, the human-factors assumptions the display's function depends on can sit in a design note nobody tied to evidence, and the environmental qualification can lag a late software build. The team that owns the package often cannot see which objective is genuinely satisfied and which was declared and forgotten.
What gets reviewed
- DO-178C software life-cycle data at the declared DAL mapped to the objectives the display function requires
- Verification results and traceability from requirements through code to test for the display software
- Human-factors assumptions the display design depends on checked against the evidence that supports them
- Environmental categories under DO-160G declared for the display checked against the qualification reports
- The certification basis and its means of compliance confirmed so the software, human-factors, and environmental evidence read together
- The authorized software build reconciled to the life-cycle data and reports that support it
Scope this review
Tell us the asset, the event, and the evidence in scope, and we will outline a focused first engagement.
Identify what is missing against the means of compliance.
What gets validated
- Each DO-178C objective claimed for the declared DAL is closed by an actual life-cycle data item, not an assertion
- Requirements-to-test traceability across the display software holds with no link left unexplained
- Human-factors assumptions cited in the design are supported by evaluation evidence rather than left as notes
- Declared DO-160G categories match the environmental conditions the display is being authorized for
- The software build the evidence supports matches the part number and configuration being authorized
Evidence normally required
- The display's TSO authorization application draft with the certification basis it declares
- DO-178C software life-cycle data and the declared DAL for the display function
- Verification results and the requirements-to-test traceability data
- Human-factors assumptions and any supporting evaluation evidence
- DO-160G reports covering the display's declared environmental categories
Common discrepancies
- A DO-178C objective marked complete at the declared DAL that no life-cycle data item actually closes
- A traceability break between a display requirement and the test that was supposed to verify it
- A human-factors assumption embedded in the design with no evaluation evidence behind it
- Environmental qualification that lags the latest software build the authorization names
What is at stake
An unsatisfied DO-178C objective cited as complete draws a finding, and on a display the DAL is usually high enough that the objective set is large and the finding is expensive to answer late. A human-factors assumption with no supporting evidence can reopen the display's suitability for its intended function, which is the kind of question that stalls an authorization well past the software desk.
How the work runs
Anchor to the display's TSO
Fix the TSO the display is being authorized against, the declared DAL, and the objective set it invokes.
Close each objective
Confirm every claimed DO-178C objective is closed by an actual life-cycle data item.
Support the assumptions
Tie each human-factors assumption to evaluation evidence rather than a design note.
Order the display gaps
Sequence the open items by closure difficulty against the display's filing date.
What the buyer receives
- A product-specific gap list on the display evidence, ranked by how hard each item is to close before filing
- A trace map linking each display claim to the certification basis, means of compliance, and its data item
- A closure sequence that orders the software and human-factors work against the authorization timeline
Who uses the output
- Certification engineers assembling the TSO authorization application for the display article
- Software leads deciding which DO-178C objectives still need life-cycle data to close
- Program managers holding the display's authorization date against the evidence still open
How the work fits into the transaction or program
The review sits between software verification and the authorization application, taking the life-cycle data, the human-factors work, and the environmental results and testing whether they present as one defensible package. Its gap list drives the objective closure the display needs, and its trace map becomes the reference later finding responses point back to.
Start with a single asset
Confirm requirements map to substantiating evidence.
Jurisdiction-specific considerations
The FAA and the European system both recognize DO-178C, but the human-factors expectations and the referenced guidance for a display function are not always aligned, so an article authorized under a TSO can face a different expectation when the same evidence is presented for European acceptance. The review flags where a human-factors claim rests on guidance the other authority applies differently.
Regulatory limits
The review reads the evidence and shows where it is complete or thin. It does not grant a TSO authorization, approve the software or the article, or make an airworthiness determination on the display function or its installation.
What this review does not cover
- Generating the missing software life-cycle data or human-factors evaluation evidence
- Preparing and filing the display's TSO authorization application for the supplier
- Any installation approval or airworthiness determination on the display once fitted
Specific to this review
- A display's DAL is usually high enough that the DO-178C objective set is large, so an objective declared complete but not closed hides easily until an authority reads the data behind it.
- Human-factors assumptions drive whether the display suits its function, yet they often live in design notes rather than evidence, which is where the trace most often finds them unsupported.
- Environmental qualification and software builds move on different schedules, so a late build can leave the display authorized against DO-160G evidence taken on an earlier configuration.
Sources
U.S. Government (eCFR). Type certificates, STCs (Subpart E), TSO authorizations (Subpart O), PMA (Subpart K), and export airworthiness approvals (Subpart L).
European Union / EASA. EASA design and production certification, STCs, ETSO authorizations, and EASA Form 1 release.
RTCA. Environmental qualification test categories and procedures referenced by TSO and equipment qualification.
RTCA. Objectives and lifecycle data for airborne software assurance, by design assurance level (DAL A-E).
Frequently asked questions
Our DO-178C compliance matrix already shows every objective satisfied. Why re-check it?
A matrix records what was claimed, not always what closed. The review confirms each objective at the declared DAL is backed by an actual life-cycle data item and that traceability holds from requirement to test, so the authorization does not inherit an objective that was marked done but never finished.
Relevant glossary terms
Related pages
Where this fits
Talk to an engineer who has done this work
We will walk through your current state, the records or evidence involved, and a scoped first engagement.
Talk through the aircraft, records, evidence, deadline, and next useful step.