DO-326A surveillance
DO-326A airworthiness security evidence support for surveillance equipment
This support checks a surveillance equipment item, such as a transponder or ADS-B unit, against the DO-326A airworthiness security process. It is run by the surveillance supplier or the installing modifier before submittal or during a finding. The work examines the security scoping, the threat conditions around the RF and datalink attack surface these units expose, the integrity of the position and identity data they transmit, and the security measures argued for each threat. You get a standards map to the DO-326A objectives, a ranked evidence gap list, and a closure sequence.
When this review is needed
- A transponder or ADS-B unit is being submitted and its RF attack surface has not been assessed for DO-326A.
- An authority questioned how the unit handles malformed or spoofed uplink interrogations.
- A datalink or reception function was added and its threat conditions were never characterized.
- The unit ingests external position or traffic data and those inputs are outside the current threat model.
The problem
Surveillance equipment is unusual under DO-326A because a chunk of its attack surface is over the air. A transponder answers interrogations it did not solicit, an ADS-B receiver ingests traffic reports it cannot authenticate, and the security case has to say what the unit does with malformed, flooded, or spoofed inputs. Many packages treat the RF side as a performance matter governed by the signal-in-space standard and never model it as a security attack surface, so the threat conditions that matter most are the ones that were never written.
What gets reviewed
- Security scoping of the surveillance item including its over-the-air interfaces
- Threat conditions for malformed, flooded, and spoofed RF or datalink inputs
- Integrity of transmitted position and identity data
- Behavior when the unit ingests unauthenticated external traffic or position data
- Security measures and the effectiveness argument for each threat condition
- Security-derived requirements fed back into the surveillance equipment baseline
What gets validated
- Malformed and flooded RF or datalink inputs are analyzed as threat conditions rather than as performance cases alone
- Each identified threat condition maps to a security measure with an effectiveness argument
- The unit's handling of unauthenticated external data appears in the threat model
- The scoping decision reflects reception and datalink functions alongside transmission
- Security-derived requirements appear in the equipment baseline and trace to verification
Evidence normally required
- The DO-326A security plan and scoping rationale for the surveillance item
- The threat condition and security risk assessment for RF and datalink functions
- Interface descriptions for interrogation, broadcast, and reception paths
- Design descriptions of input validation and rate handling
- The equipment requirements baseline and its security-derived requirements
Common discrepancies
- RF input behavior treated only as a performance case, never as a security threat condition
- No analysis of what the unit does with a flooded or malformed interrogation
- Ingested external traffic or position data outside the threat model
- A reception function present in the design but absent from the security scoping
What is at stake
A surveillance unit whose RF and datalink inputs are unassessed leaves the aircraft-level security case blind to the interface most exposed to an outside actor. When an authority reads that gap, the response has to characterize the malformed and spoofed input behavior after the fact, and if the unit ingests external position data, every function that consumes its output inherits the same unassessed exposure.
Move from findings to resolution
Identify gaps against the means of compliance.
How the work runs
Scope the over-the-air interfaces
Confirm the security scope includes interrogation, broadcast, and reception paths alongside the wired interfaces.
Model the RF threats
Characterize malformed, flooded, and spoofed input behavior as threat conditions rather than performance cases.
Map threats to measures
Check each threat condition maps to a security measure with an effectiveness argument.
Sequence the closure
Rank the gaps by exposure and identify which threat condition to characterize first.
What the buyer receives
- A standards map to the DO-326A objectives for the surveillance item
- A ranked evidence gap list focused on the over-the-air attack surface
- A closure sequence identifying which threat condition to characterize first
Who uses the output
- Certification leads preparing the surveillance submittal or finding response
- Security engineers characterizing the RF and datalink attack surface
- Compliance managers tracking which threat-condition gaps still block the package
How the work fits into the transaction or program
This review connects the surveillance item's over-the-air behavior to the aircraft-level security case DO-326A governs. It confirms the RF and datalink inputs are modeled as an attack surface rather than only a performance envelope, so the unit enters the compliance matrix without the most exposed interface left unassessed.
Start with a single asset
Confirm requirements trace through verification.
Jurisdiction-specific considerations
The FAA and EASA both apply the DO-326A objectives, but they differ on how much of the signal-in-space behavior they treat as already covered by the surveillance performance standard versus needing a separate security argument. The map flags where that line falls differently so the RF threat conditions are argued to the right authority.
Regulatory limits
This work maps and checks the airworthiness security evidence against DO-326A. It does not perform RF testing, attempt any spoofing or jamming trials, or make an airworthiness determination. Those responsibilities stay with the applicant and the certifying authority.
What this review does not cover
- RF, jamming, or spoofing testing of the equipment
- Authoring the threat assessment or security measures from scratch
- Any determination that the surveillance equipment is airworthy or approvable
Specific to this review
- Surveillance units carry an over-the-air attack surface, so part of their DO-326A threat model concerns inputs no one on the aircraft controls.
- Teams often cover RF behavior under the performance standard and forget it is also a security interface, which is where the threat conditions go missing.
- An ADS-B receiver ingesting unauthenticated traffic reports passes that exposure to every function that consumes its output.
Sources
RTCA. Airworthiness security process objectives for aircraft systems exposed to intentional unauthorized electronic interaction.
U.S. Government (eCFR). Type certificates, STCs (Subpart E), TSO authorizations (Subpart O), PMA (Subpart K), and export airworthiness approvals (Subpart L).
SAE International. Development assurance process at aircraft and system level, including requirements capture and validation.
Frequently asked questions
Isn't the RF behavior already covered by the ADS-B and transponder performance standards?
Those standards govern how the unit performs, not how it withstands a hostile input. DO-326A asks what the equipment does with a malformed, flooded, or spoofed signal. That is a security question, and it is the part of the surveillance attack surface most often left out of the threat model.
Relevant glossary terms
Related pages
Where this fits
Talk to an engineer who has done this work
We will walk through your current state, the records or evidence involved, and a scoped first engagement.
Talk through the aircraft, records, evidence, deadline, and next useful step.