Skip to content

DO-326A communication

DO-326A airworthiness security evidence support for communication equipment

This support reviews a communication equipment item, such as a datalink radio or communication management unit, against the DO-326A airworthiness security process. It is run by the communication supplier or the installing modifier before submittal or during a finding. The work looks at the security scoping, the threat conditions across voice and datalink channels, the integrity and authenticity of the messages the unit handles, and how its connectivity to ground and cabin networks widens the attack surface. You get a standards map to the DO-326A objectives, a ranked evidence gap list, and a closure sequence.

When this review is needed

  • A datalink or communication management unit is being submitted and its connectivity has not been assessed for DO-326A.
  • An authority questioned how the unit authenticates or bounds the messages it accepts.
  • The unit gained a connection to a cabin or ground network that the original security case did not model.
  • A message routing or forwarding function couples formerly separate domains and those paths were never assessed.

The problem

Communication equipment is the most connected avionics an aircraft carries, which makes its DO-326A attack surface the widest and the easiest to underdraw. A communication management unit routes messages between ground, cockpit, and increasingly cabin networks, and each connection is a path an outside actor might reach. When the security case treats the unit as a pipe rather than a gateway, it never asks what a malformed or unauthenticated message does on arrival, and the connectivity that makes the box useful becomes the exposure no one wrote down.

What gets reviewed

  • Security scoping of the communication item across all connected networks
  • Threat conditions for voice and datalink channels the unit handles
  • Message integrity and authenticity controls on accepted traffic
  • Routing and forwarding paths that couple ground, cockpit, and cabin domains
  • Security measures and the effectiveness argument for each threat condition
  • Security-derived requirements fed back into the communication equipment baseline

What gets validated

  • The scoping reflects every network the unit connects to, including cabin and ground paths
  • Accepted messages have integrity or authenticity controls consistent with their threat conditions
  • Routing and forwarding paths that cross domains appear in the threat model with controls
  • Each threat condition maps to a security measure with an effectiveness argument
  • Security-derived requirements appear in the equipment baseline and trace to verification

Evidence normally required

  • The DO-326A security plan and scoping rationale for the communication item
  • The threat condition and security risk assessment for voice and datalink functions
  • Interface and routing documentation for all connected networks
  • Descriptions of message validation, authentication, and forwarding controls
  • The equipment requirements baseline and its security-derived requirements

Common discrepancies

  • A network connection present in the design but missing from the security scoping
  • Accepted datalink messages with no integrity or authenticity control
  • A routing path that crosses domains without a control in the threat model
  • Cabin connectivity treated as out of scope despite a path into the unit

What is at stake

A communication unit whose connectivity is underassessed can become the bridge that carries an outside threat toward systems the security case assumed were isolated. If an authority reads that gap, the response has to trace every network the unit touches and justify the controls on each, which is slow when the routing is already fielded. An unauthenticated message path left unmodeled undermines the isolation arguments other systems depend on.

Move from findings to resolution

Identify gaps against the means of compliance.

How the work runs

01

Map every connection

Enumerate the networks the unit touches, including cabin and ground paths, and confirm each is in scope.

02

Check message controls

Verify accepted traffic has integrity or authenticity controls matched to its threat conditions.

03

Trace cross-domain routing

Identify routing and forwarding paths that cross domains and confirm each carries a control in the threat model.

04

Sequence the closure

Rank the gaps by exposure and identify which network path to control first.

What the buyer receives

  • A standards map to the DO-326A objectives for the communication item
  • A ranked evidence gap list focused on connectivity and message integrity
  • A closure sequence identifying which network path to control first

Who uses the output

  • Certification leads preparing the communication submittal or finding response
  • Security engineers tracing the unit's connectivity across domains
  • Compliance managers tracking which connectivity gaps still block the package

How the work fits into the transaction or program

This review places the communication item's connectivity inside the aircraft-level security case DO-326A governs. It confirms the unit is analyzed as a gateway between networks rather than a passive pipe, so it enters the compliance matrix without leaving a message path that could bridge an outside threat toward isolated systems.

Start with a single asset

Confirm requirements trace through verification.

Jurisdiction-specific considerations

The FAA and EASA both apply DO-326A, but they scrutinize cabin-to-cockpit connectivity with different intensity, and EASA special conditions often press the isolation argument hardest. The map notes where a connectivity argument accepted by one authority is likely to draw a deeper isolation question from the other.

Regulatory limits

This work maps and checks the airworthiness security evidence against DO-326A. It does not test the datalink, attempt any message injection, or make an airworthiness determination. Those responsibilities remain with the applicant and the certifying authority.

What this review does not cover

  • Datalink testing or message-injection trials on the equipment
  • Authoring the threat assessment or security measures from scratch
  • Any determination that the communication equipment is airworthy or approvable

Specific to this review

  • Communication units are the most connected avionics on the aircraft, so their DO-326A attack surface spans more networks than any other equipment type here.
  • A routing or forwarding function can bridge domains the rest of the security case assumed were isolated, which is why cross-domain paths are checked explicitly.
  • Cabin connectivity is the interface most often scoped out by habit even when a real path into the unit exists.

Sources

Frequently asked questions

Why does cabin connectivity keep coming up in a communication security review?

Because a communication unit that routes between cockpit and cabin networks can become the bridge an outside actor uses to reach systems the security case assumed were isolated. If a cabin path into the unit exists, DO-326A wants it in scope, and it is the connection most often left out by habit.

Relevant glossary terms

Related pages

Where this fits

Talk to an engineer who has done this work

We will walk through your current state, the records or evidence involved, and a scoped first engagement.

Talk through the aircraft, records, evidence, deadline, and next useful step.