Skip to content

ETSO authorization

Certification plan support for an ETSO authorization

This service reviews the certification plan a supplier writes at the front of an EASA European Technical Standard Order authorization. The plan is the agreement the applicant proposes to the authority: the certification basis, the affected areas of the article, the means of compliance, and the review commitments the program will meet. A certification specialist reads the plan against the invoked ETSO to find where it promises coverage the eventual data package will not contain, or leaves an affected area unaddressed. You receive a gap assessment against the basis, a traceable map of what the plan commits, and a closure plan for the mismatches.

When this review is needed

  • A supplier is drafting the plan and wants an outside read before proposing it to the authority.
  • The article combines hardware, software, and environmental exposure, and the plan must name a means for each discipline.
  • An earlier authorization is being amended and the plan has to describe only the changed areas and their basis.
  • The program is committing to a submittal schedule and the plan's review points drive it.

The problem

The plan is written early, when the design is still moving and the team is optimistic about what it will produce. It commits to a basis, a set of affected areas, and a means for each, but the data package is built months later against a configuration that has shifted. A plan that promised an analysis where the program later chose a test, or omitted an affected area the design grew into, sets up findings that surface only once the authority starts reading.

What gets reviewed

  • The proposed certification basis against the invoked ETSO and any EASA special conditions
  • The affected areas of the article and whether the plan addresses each one
  • The means of compliance the plan declares for every requirement group
  • The review commitments and hold points offered to the authority
  • Alignment between the plan and the compliance matrix that will report against it
  • Software and hardware assurance levels asserted and the standards invoked to reach them

Scope this review

Tell us the asset, the event, and the evidence in scope, and we will outline a focused first engagement.

Identify what is missing against the means of compliance.

What gets validated

  • The declared basis names every applicable ETSO paragraph and any special condition EASA has attached
  • Each affected area the article touches has a stated compliance approach in the plan
  • The means named for a requirement is one the authority accepts for that requirement type
  • Asserted software and hardware assurance levels match the article's failure effects
  • The plan's review points are ones the program can actually meet on the proposed schedule

Evidence normally required

  • The draft or current certification plan and its revision history
  • The invoked ETSO and any EASA special conditions or technical conditions
  • The article's functional description and preliminary failure-effect classification
  • The compliance matrix outline if one has been started
  • The program schedule the plan's review points feed

Common discrepancies

  • Affected areas the plan does not address because the design grew after it was written
  • A means declared for a requirement that the authority does not accept for that type
  • Assurance levels asserted below what the article's failure effects require
  • Review commitments the schedule cannot support once the work is sequenced

What is at stake

A plan that does not match the eventual package forces mid-program renegotiation with the authority, which is slower and costlier than getting the plan right up front. Affected areas discovered late need their own basis and evidence, and each one added after the plan was accepted risks reopening the agreed scope and the schedule built on it.

How the work runs

01

Confirm the basis

Check that the proposed certification basis names every applicable ETSO paragraph and EASA special condition.

02

Test the affected areas

Compare the article's design against the plan's affected-area list and find any area left unaddressed.

03

Vet the means

Confirm each declared means is accepted for its requirement and that asserted assurance levels fit the failure effects.

04

Reconcile the commitments

Deliver a gap assessment and a closure plan for the areas and means the plan leaves open.

What the buyer receives

  • A gap assessment mapping the plan against the invoked ETSO and special conditions
  • A traceable view of every commitment the plan makes and where it is addressed
  • A closure plan for the affected areas and means the plan leaves open

Who uses the output

  • Certification leads finalizing the plan before proposing it to EASA
  • Compliance managers aligning the matrix to the plan's structure
  • Engineering leads sizing the work the plan commits to

How the work fits into the transaction or program

The plan is the promise the whole program is measured against later. Reading it before it goes to the authority means the basis, affected areas, and means are settled while they are still cheap to change, so the data package built later reports against a plan it can actually satisfy rather than one it quietly outgrows.

Start with a single asset

Reduce finding cycles by checking the package first.

Jurisdiction-specific considerations

For an EASA European Technical Standard Order authorization, the plan proposes a certification basis the authority then agrees or amends. The review reads the plan against EASA expectations for that ETSO, including any deviations the applicant intends to request, rather than against an equivalent FAA process, because the accepted basis and the route to agree it differ.

Regulatory limits

The review evaluates the supplier's proposed plan. It does not agree the certification basis on EASA's behalf, grant an authorization, or approve the compliance approach. Agreeing the plan remains a matter between the applicant and the authority.

What this review does not cover

Specific to this review

  • The plan fixes the affected-area scope early, and any area added later needs its own basis, which is why an incomplete affected-area list is the costliest thing to miss.
  • A means the authority will not accept for a given requirement type does not fail loudly at plan stage; it fails later as a rejected finding, so the means is checked against acceptance up front.
  • Assurance levels asserted in the plan cascade into the DO-178C and DO-254 effort, so an understated level in the plan understates the whole software and hardware program built from it.

Sources

Frequently asked questions

Why review the plan before EASA sees it if the authority agrees it anyway?

Because the authority agrees the plan you propose. If it omits an affected area or names a means EASA will not accept, that surfaces as a mid-program change to an agreed document, which is slower and more expensive than settling it before the plan is submitted.

Relevant glossary terms

Related pages

Where this fits

Talk to an engineer who has done this work

We will walk through your current state, the records or evidence involved, and a scoped first engagement.

Talk through the aircraft, records, evidence, deadline, and next useful step.