ETSO authorization
Accomplishment summary support for ETSO authorization
This review checks the accomplishment summary that sits at the top of an ETSO software and hardware assurance package, confirming that its claims of objective coverage are backed by the lifecycle evidence it points to. It is run by or for an equipment or avionics supplier once the DO-178C and DO-254 lifecycle data is complete and the summary is written on top of it. It looks at whether every objective claimed as satisfied has a traceable evidence reference, whether open problem reports and anomalies are disclosed rather than smoothed over, and whether the summary's assurance-level claims match what the lifecycle data actually demonstrates. You get a gap assessment, an evidence map from each claim to its lifecycle source, and a closure plan for the objectives that read as met but are not yet shown.
When this review is needed
- The lifecycle data is complete and the summary claims objective coverage that a reviewer will want to trace to source.
- Unresolved problem reports exist at the assurance level and the summary has to disclose them with their disposition.
- The claimed DAL does not obviously match the depth of the lifecycle evidence assembled behind it.
- The summary was written from a plan rather than from the delivered evidence and may claim more than the data shows.
The problem
An accomplishment summary is often drafted from the assurance plan, describing what was supposed to happen, and then not fully reconciled to what the delivered lifecycle data actually contains. Objectives get marked satisfied because the process called for them, not because the reviewer can point to the review record, the test result, or the analysis that satisfies them. Problem reports still awaiting disposition get summarized as resolved, and the assurance-level claim carries assumptions that the evidence underneath never fully backed.
What gets reviewed
- Each objective claimed satisfied linked to the specific lifecycle artifact that satisfies it
- Open problem reports and anomalies disclosed with their disposition and any deferred rationale
- The claimed design assurance level checked against the depth and independence of the delivered evidence
- Software DO-178C and hardware DO-254 lifecycle references reconciled to the actual data set
- Summary claims about tool qualification and derived requirements traced to their supporting records
- Consistency between the summary, the plans it derives from, and the evidence it points to
Scope this review
Tell us the asset, the event, and the evidence in scope, and we will outline a focused first engagement.
Identify what is missing against the means of compliance.
What gets validated
- Every objective marked satisfied cites a lifecycle artifact a reviewer can retrieve and read
- Problem reports still open appear in the summary with a stated disposition rather than being omitted
- The evidence depth and independence support the design assurance level the summary claims
- DO-254 hardware lifecycle references resolve to actual data, not to plan sections
- Derived requirements and tool qualification claims trace to the records that back them
Evidence normally required
- The draft accomplishment summary and its objective-coverage claims
- The DO-178C software lifecycle data set: plans, reviews, tests, and analyses
- The DO-254 hardware lifecycle data where the article contains complex hardware
- The open and closed problem report log at the assurance level
- Tool qualification and derived-requirement records referenced by the summary
Common discrepancies
- An objective claimed satisfied with no lifecycle artifact behind the claim
- An open problem report summarized as resolved when its disposition is still pending
- A claimed assurance level that the delivered evidence does not support at the required independence
- A DO-254 reference that points to a plan section rather than to delivered hardware data
What is at stake
A summary that claims coverage the lifecycle data cannot show turns the authority's review into a hunt for evidence that may not exist, and every objective that fails to trace becomes a finding against the assurance case. If the claimed DAL outruns the depth of the delivered data, the shortfall is not a paperwork fix: it can mean additional verification activity at the claimed level, which reopens work the supplier considered finished.
How the work runs
Trace each objective
Link every objective the summary claims satisfied to the specific lifecycle artifact that satisfies it.
Surface the open items
Confirm every open problem report and anomaly is disclosed with its true disposition.
Test the assurance level
Check that the delivered evidence supports the claimed DAL at the required depth and independence.
Plan the closures
List the objectives and problem reports the summary overstates and sequence the work to close them.
What the buyer receives
- A gap assessment of objectives claimed satisfied without a traceable lifecycle artifact
- An evidence map from each summary claim to its lifecycle source
- A closure plan for the objectives and problem reports the summary overstates
Who uses the output
- Certification leads confirming the summary will survive the authority's trace to evidence
- Assurance engineers reconciling objective claims against the delivered lifecycle data
- Quality staff verifying that disclosed problem reports carry an honest disposition
How the work fits into the transaction or program
The accomplishment summary is the document a reviewer reads first and uses to decide where to probe, so it functions as the index into the whole assurance case. This review runs after the lifecycle data is complete and before the summary is submitted, so the gap between what the summary claims and what the evidence shows is closed by the supplier rather than exposed by the authority sampling behind a claim.
Start with a single asset
Reduce finding cycles by checking the package first.
Jurisdiction-specific considerations
Under the EASA route, the accomplishment summary supports the applicant's declaration that the assurance objectives are met, and the authority relies on it being an accurate index into evidence it can sample at will. Where the same software and hardware is used toward an FAA TSO, the review notes where a summary written to one authority's expectations for objective phrasing and independence needs adjustment for the other.
Regulatory limits
The review checks that the summary's claims trace to lifecycle evidence and disclose open items honestly. It does not perform the assurance activities, assign or approve a design assurance level, grant the ETSO authorization, or commit the authority to accept the assurance case.
What this review does not cover
Specific to this review
- The summary is frequently written from the assurance plan rather than the delivered data, so it describes intended coverage instead of demonstrated coverage.
- A claimed DAL that outruns the delivered evidence is a substantive gap, because closing it can require added verification at the claimed level rather than a documentation edit.
- Undisclosed open problem reports are the summary's most damaging omission, since the authority tends to find them and then distrusts every other claim in the document.
Sources
European Union / EASA. EASA design and production certification, STCs, ETSO authorizations, and EASA Form 1 release.
RTCA. Environmental qualification test categories and procedures referenced by TSO and equipment qualification.
RTCA. Objectives and lifecycle data for airborne software assurance, by design assurance level (DAL A-E).
RTCA. Design assurance objectives and lifecycle data for airborne electronic hardware (FPGA/ASIC/PLD).
U.S. Government (eCFR). Type certificates, STCs (Subpart E), TSO authorizations (Subpart O), PMA (Subpart K), and export airworthiness approvals (Subpart L).
Frequently asked questions
Does the summary need to list problem reports that are still open?
Yes. Open problem reports are disclosed with their disposition and any deferral rationale, not omitted. A summary that hides open items is more damaging than one that discloses them, because the authority usually finds them and then re-examines every other claim in the document.
Relevant glossary terms
Related pages
Where this fits
Talk to an engineer who has done this work
We will walk through your current state, the records or evidence involved, and a scoped first engagement.
Talk through the aircraft, records, evidence, deadline, and next useful step.