Sensor hardware
DO-254 hardware assurance evidence support for sensor systems
This support reads the DO-254 evidence for a sensor system's airborne electronic hardware and confirms it demonstrates the assurance the plan commits to, from the acquisition front end through the processing logic. It fits air data, inertial, and other measurement units whose accuracy claims rest on hardware behavior. A specialist checks that requirements, design, calibration, and verification data connect and match the DAL the safety assessment carries into ARP4754B allocation. The output is a standards map by objective, a gap list ordered for closure, and a route to clear each finding before submittal.
When this review is needed
- A sensor unit is entering authorization and its hardware assurance data needs checking against the plan.
- A finding on the sensor front-end hardware has to be traced to the DO-254 objective it belongs to.
- Accuracy requirements were allocated to hardware and their verification coverage is uncertain.
- A processing device on the sensor board changed and the verification must be current for the build.
The problem
Sensor hardware carries requirements that are numeric and unforgiving: accuracy, resolution, and drift bounds that the hardware has to hold across its environmental range. DO-254 wants those requirements captured and verified like any other, but on a sensor they entangle with calibration and with the ARP4754B allocation from the aircraft level. When the accuracy requirement lives in a calibration report and never appears as a captured hardware requirement, the DO-254 trace has a hole exactly where the unit's value sits.
What gets reviewed
- Accuracy, resolution, and drift requirements captured as verifiable hardware requirements
- Design and verification data for the sensor hardware against the assigned DAL
- Calibration evidence linked to the requirements it is meant to support
- The ARP4754B allocation that hands requirements to the sensor hardware
- Configuration records fixing verification to the current sensor build
- Derived hardware requirements returned to the safety assessment
What gets validated
- Each accuracy and drift requirement exists as a captured hardware requirement, not only in a calibration report
- Verification results demonstrate the numeric bounds across the required conditions
- The DAL applied to the sensor hardware agrees with the ARP4754B allocation and safety assessment
- Calibration evidence ties to the specific requirements it substantiates
- Verification records correspond to the processing device build in the configuration baseline
Evidence normally required
- The hardware plans and verification plan for the sensor unit
- Requirements, design, and verification data for the airborne electronic hardware
- Calibration and characterization reports for the sensor
- The ARP4754B allocation and safety assessment setting the sensor DAL
- The certification basis and any prior findings on the hardware
Common discrepancies
- An accuracy requirement present in calibration data but never captured as a hardware requirement
- Verification that covers nominal conditions but not the full required range
- A processing device build in the configuration that the verification does not match
- Derived requirements from the sensor logic that never reached the safety assessment
What is at stake
A missing trace on an accuracy requirement is a finding that questions the sensor's core claim, and answering it late can mean rerunning characterization. Because sensor outputs feed downstream systems through the ARP4754B allocation, a weak DO-254 substantiation on the sensor propagates doubt upward. Confirming the accuracy requirements were captured and verified before submittal keeps the finding from reaching the aircraft-level argument.
Move from findings to resolution
Identify gaps against the means of compliance.
How the work runs
Trace the allocation
Confirm how ARP4754B hands accuracy and integrity requirements down to the sensor hardware and the DAL that follows.
Find the numeric requirements
Check that accuracy, resolution, and drift bounds exist as captured hardware requirements, not only in calibration.
Test the coverage
Confirm verification demonstrates each bound across the full required conditions and matches the current build.
Order the closure
Rank open objectives by effort so any recharacterization is scheduled before submittal.
What the buyer receives
- A standards map covering each DO-254 objective for the sensor hardware
- A gap list ordered by closure effort, with accuracy-trace items called out
- A closure sequence from each open finding to its supporting evidence
Who uses the output
- Certification leads judging whether the sensor package is ready to submit
- Hardware engineers closing the trace on accuracy and calibration requirements
- Compliance managers tracking open objectives against the sensor's authorization date
How the work fits into the transaction or program
The mapping runs after sensor verification is nominally done and before the package reaches the authority, sitting where the DO-254 hardware evidence meets the ARP4754B allocation above it. It checks that the numeric requirements the sensor is sold on were actually captured and verified, so the accuracy claim rests on a closed trace rather than a calibration report standing alone.
Start with a single asset
Confirm requirements trace through verification.
Jurisdiction-specific considerations
FAA and EASA both accept DO-254 for sensor hardware and both look at how accuracy requirements flow down through the ARP4754B allocation. The mapping notes where the allocation and its verification satisfy one authority's expectation but would need supplement for the other under the applicable certification basis.
Regulatory limits
This work maps sensor hardware evidence to the DO-254 objectives and checks the allocation feeding it. It does not approve the sensor design, issue a TSO or STC, determine airworthiness, or take the place of the authority accepting the package.
What this review does not cover
- Producing the requirements, design, calibration, or verification data
- Running the sensor characterization or verification tests
- Issuing an approval or compliance finding on the authority's behalf
Specific to this review
- On a sensor the DO-254 trace most often breaks at the accuracy requirement, because it lives in a calibration report and was never captured as a verifiable hardware requirement.
- Nominal-condition verification is a common shortfall: the numeric bound has to hold across the required range, not just at room conditions.
- Because the sensor feeds downstream systems through the ARP4754B allocation, a weak hardware trace does not stay local; it reaches the aircraft-level safety argument.
Sources
RTCA. Design assurance objectives and lifecycle data for airborne electronic hardware (FPGA/ASIC/PLD).
SAE International. Development assurance process at aircraft and system level, including requirements capture and validation.
U.S. Government (eCFR). Type certificates, STCs (Subpart E), TSO authorizations (Subpart O), PMA (Subpart K), and export airworthiness approvals (Subpart L).
Frequently asked questions
Our accuracy is proven in the calibration report. Isn't that enough for DO-254?
Not by itself. DO-254 expects the accuracy target to exist as a captured hardware requirement that verification demonstrably closes. A calibration report can support that requirement, but it does not substitute for having the requirement in the trace.
Relevant glossary terms
Related pages
Where this fits
Talk to an engineer who has done this work
We will walk through your current state, the records or evidence involved, and a scoped first engagement.
Talk through the aircraft, records, evidence, deadline, and next useful step.