DO-178C surveillance
DO-178C software compliance support for surveillance equipment
DO-178C compliance support for surveillance equipment maps the software lifecycle evidence for a transponder or ADS-B unit against its assurance objectives, while accounting for the message-integrity, antenna, and installation substantiation the surveillance function depends on. Suppliers and modifiers use it as they build a submittal or respond to a finding. It reviews the plans, requirements trace, verification results, and the transmitted-data integrity assumptions that the surveillance role rests on. You receive a standards map, an evidence gap list, and a closure sequence.
When this review is needed
- A transponder or ADS-B unit is nearing submittal and its software evidence has to meet the assurance objectives and the message-integrity rules.
- A finding asks how the software guarantees the correctness of transmitted position and identity data.
- The antenna or installation substantiation changed and the software assumptions built on it need review.
- The unit reports a surveillance integrity level that the software evidence has to substantiate.
The problem
Surveillance software broadcasts what other aircraft and controllers act on, so the correctness of the transmitted message matters as much as the correctness of the code. A supplier can present tidy DO-178C artifacts and a passing broadcast test, yet leave the link between them implicit: which requirement governs message integrity, and where is it verified. Installation substantiation, antenna placement, transmit power, and interference, sits in the airframe side of the package and is rarely mapped back to the software assumptions that rely on it.
What gets reviewed
- Software plans and standards checked against the objectives for the assurance level
- Message-integrity and data-encoding requirements traced through design to verification
- Transmitted position and identity behavior reconciled with the DO-178C verification
- Antenna, transmit-power, and installation assumptions carried from substantiation into the software evidence
- Environmental qualification for the surveillance unit tied to the verified software configuration
- Open evidence items sequenced by their effect on the submittal
What gets validated
- Each DO-178C objective for the assurance level maps to an identifiable artifact
- Message-integrity requirements trace from specification through design to verification
- Transmitted-data behavior verified in test references the software version under approval
- Installation substantiation for antenna and power aligns with the software's stated assumptions
- Environmental qualification covers the configuration the software actually runs on
Evidence normally required
- The Plan for Software Aspects of Certification and the lifecycle plans
- Software requirements, design data, and code references for the surveillance function
- Verification cases, procedures, and results with structural coverage data
- Installation substantiation covering antenna placement, transmit power, and interference
- DO-160G environmental qualification results for the surveillance unit
Common discrepancies
- Message-integrity behavior verified in broadcast test but not traced to a governing requirement
- Antenna and power substantiation that the software assumptions were never reconciled against
- A DO-178C objective with no evidence artifact identified in the surveillance package
- Transmitted-data test evidence run on a software version earlier than the one submitted
What is at stake
A surveillance unit that transmits without provable message integrity is a safety-of-others problem, and an authority treats a missing objective on that path as blocking. If the software's antenna or timing assumptions were never reconciled to the installation substantiation, an approval on one airframe will not carry to the next, and the gap resurfaces at the following installation approval.
Move from findings to resolution
Identify gaps against the means of compliance.
How the work runs
Fix the objectives and integrity rules
Confirm the assurance level and the message-integrity requirements the surveillance function must meet.
Trace integrity to verification
Follow the message-integrity requirements through design to the verification that exercises them.
Reconcile installation assumptions
Match the software's antenna and power assumptions to the installation substantiation.
Sequence the gaps
List the unsupported objectives and integrity links and order them by submittal impact.
What the buyer receives
- A standards map placing each DO-178C objective against its supporting evidence
- An evidence gap list covering the objectives, integrity traces, and installation links not yet supported
- A closure sequence ordering the gaps by their effect on the submittal
Who uses the output
- Certification leads confirming the surveillance software package will hold under review
- Software engineers closing a message-integrity or installation-assumption trace gap
- Compliance managers answering a finding on transmitted-data correctness
How the work fits into the transaction or program
The support ties the software evidence to the installation substantiation the surveillance function broadcasts from, so the software and airframe sides of the package agree at submittal. Its gap list drives the verification and reconciliation work needed before the unit is submitted, and its map exposes any integrity path left unevidenced.
Start with a single asset
Confirm requirements trace through verification.
Regulatory limits
The support maps DO-178C evidence and its links to installation substantiation, and flags gaps. It does not certify the surveillance integrity level, make a compliance finding, or approve the software or the installation.
What this review does not cover
- Executing the software verification or broadcast integrity testing
- Certifying the surveillance integrity level or acting as a DER
- Any airworthiness determination on the surveillance unit
Specific to this review
- Surveillance software transmits data others act on, so message integrity has to trace to a governing requirement rather than rest on a broadcast test alone.
- Antenna, transmit-power, and interference substantiation lives on the airframe side, so the software's assumptions about it are frequently never reconciled back.
- An integrity path proven on one installation does not automatically carry to the next, because the substantiation the software relies on is installation-specific.
Sources
RTCA. Objectives and lifecycle data for airborne software assurance, by design assurance level (DAL A-E).
SAE International. Development assurance process at aircraft and system level, including requirements capture and validation.
U.S. Government (eCFR). Type certificates, STCs (Subpart E), TSO authorizations (Subpart O), PMA (Subpart K), and export airworthiness approvals (Subpart L).
Frequently asked questions
Why reconcile software evidence with the antenna and installation substantiation?
A surveillance unit's software makes assumptions about transmit power, antenna placement, and interference that only the installation substantiation supports. If those are never reconciled, an approval on one airframe will not carry to another, and the gap reappears at the next installation. Mapping them together closes that exposure before submittal.
Relevant glossary terms
Related pages
Where this fits
Talk to an engineer who has done this work
We will walk through your current state, the records or evidence involved, and a scoped first engagement.
Talk through the aircraft, records, evidence, deadline, and next useful step.