Skip to content

DO-326A navigation

DO-326A airworthiness security evidence support for navigation equipment

This support reviews a navigation equipment item's airworthiness security evidence against the DO-326A process, with particular attention to the database update chain that navigation units depend on. It is run by the navigation supplier or the installing modifier before submittal or during a finding. The work reads the security scoping, the threat conditions around loaded navigation databases and position data, the integrity controls on the update path, and the measures argued to counter each threat. You get a standards map to the DO-326A objectives, a ranked evidence gap list, and a sequence for closing each gap.

When this review is needed

  • A navigation unit is being submitted and the database update chain has not been assessed for DO-326A threat conditions.
  • An authority questioned the integrity controls on how navigation databases are validated and loaded.
  • A new update mechanism, such as a wireless or removable-media path, changed the threat picture the security case assumed.
  • The item shares position data with other systems and those interfaces were not covered in the threat model.

The problem

Navigation equipment lives or dies on the database it loads, and the update chain is exactly where a security case gets thin. The unit itself may be well protected, but the path that validates and loads a navigation database can accept a corrupted or substituted file if the integrity checks live only in a procedure and not in the design. When the threat conditions around that path are undercooked, the security measures read as assumptions about how the database will be handled rather than controls the equipment enforces.

What gets reviewed

  • Security scoping of the navigation item against its interfaces and update paths
  • Threat conditions around navigation database validation and loading
  • Integrity controls enforced in the design versus assumed in procedure
  • Position-data output interfaces shared with other consuming systems
  • Security measures and the effectiveness argument for each threat condition
  • Security-derived requirements fed back into the navigation equipment baseline

What gets validated

  • The database loading path has integrity controls enforced by the equipment rather than by procedure alone
  • Every threat condition on the update chain maps to a security measure with an effectiveness argument
  • Shared position-data interfaces appear in the threat model with controls consistent with their risk
  • The scoping decision reflects removable-media and wireless update mechanisms if present
  • Security-derived requirements appear in the equipment baseline and trace to verification

Evidence normally required

  • The DO-326A security plan and scoping rationale for the navigation item
  • The threat condition and security risk assessment for the database and position functions
  • Interface control documents for update paths and position-data outputs
  • Descriptions of the database validation and loading controls in the design
  • The equipment requirements baseline and its security-derived requirements

Common discrepancies

  • Database integrity controls that exist in procedure but are not enforced by the equipment
  • An update path threat condition with no security measure mapped to it
  • A shared position-data output whose consuming interfaces are outside the threat model
  • A new removable-media or wireless update mechanism not reflected in the scoping

What is at stake

A navigation item whose update chain lacks enforced integrity controls carries a threat condition the aircraft-level security case has to absorb. If the authority reads that gap, the response has to either add real controls to the loading path or justify why the procedural ones suffice, and the second argument is hard to win once the design is set. An unassessed shared position-data interface widens the same problem to every system that consumes the output.

Move from findings to resolution

Identify gaps against the means of compliance.

How the work runs

01

Scope the update paths

Confirm the security scope covers every navigation database and position-data interface, including new update mechanisms.

02

Separate design from procedure

Identify which database integrity controls the equipment enforces versus which rely on handling procedure.

03

Map threats to measures

Check each update-chain threat condition maps to a security measure with an effectiveness argument.

04

Sequence the fixes

Rank the gaps and flag where a design control must land before the effectiveness argument holds.

What the buyer receives

  • A standards map to the DO-326A objectives for the navigation item
  • A ranked evidence gap list separating design controls from procedural assumptions
  • A closure sequence noting where design changes precede the effectiveness argument

Who uses the output

  • Certification leads preparing the navigation submittal or finding response
  • Security engineers distinguishing enforced controls from procedural assumptions
  • Compliance managers tracking which update-chain gaps still block the package

How the work fits into the transaction or program

This review ties the navigation item's database and position functions into the aircraft-level security case DO-326A governs. It confirms the update chain carries enforced integrity rather than assumed handling, so the unit enters the compliance matrix without leaving a loading path the authority will flag.

Start with a single asset

Confirm requirements trace through verification.

Jurisdiction-specific considerations

Both the FAA and EASA reach the DO-326A objectives, but they weigh procedural controls on database loading differently, and EASA tends to press harder for controls enforced in the design. The map notes where a procedural argument that one reviewer accepts is likely to draw a request for a design control from the other.

Regulatory limits

This work maps and checks the airworthiness security evidence against DO-326A. It does not test the loading path, validate any navigation database, or make an airworthiness determination. Those responsibilities remain with the applicant and the certifying authority.

What this review does not cover

  • Validating or testing any navigation database
  • Penetration testing of the update path
  • Any determination that the navigation equipment is airworthy or approvable

Specific to this review

  • For navigation equipment the update chain is the primary DO-326A exposure, because the database is loaded data the aircraft trusts.
  • A control that lives only in a loading procedure is weaker evidence than one the equipment enforces, and reviewers increasingly say so.
  • A shared position-data output multiplies the threat because every consuming system inherits whatever the navigation item accepted.

Sources

Frequently asked questions

Isn't a controlled loading procedure enough for the navigation database?

A procedure helps, but a procedural control depends on people following it every time. DO-326A reviewers, EASA especially, increasingly expect the equipment to enforce database integrity in the design. The review separates the controls the unit enforces from the ones that rely on handling, so you know where the exposure is.

Relevant glossary terms

Related pages

Where this fits

Talk to an engineer who has done this work

We will walk through your current state, the records or evidence involved, and a scoped first engagement.

Talk through the aircraft, records, evidence, deadline, and next useful step.