ETSO authorization
Instructions for continued airworthiness support for ETSO authorization
This review readies the Instructions for Continued Airworthiness that ship with an ETSO article, checking that the maintenance tasks, limitations, and part data match the configuration the supplier is authorizing. It is run by or for an equipment or avionics supplier as the ICA is drafted alongside the rest of the authorization package. It looks at whether every maintainable item has an instruction, whether the limitations line up with the qualification basis, and whether the part numbers and life data in the ICA reflect the released configuration rather than an earlier build. You get a gap assessment, an evidence map linking each instruction to its design source, and a closure plan to bring the ICA into step with the authorized article.
When this review is needed
- The ICA is being drafted and has to cover every maintainable item in the article without listing tasks the design does not need.
- The article configuration changed late in the program and the ICA still names superseded parts or intervals.
- A limitation in the ICA has to be traced back to the qualification result or safety assessment that set it.
- An installer or integrator needs the ICA to slot cleanly into the installation-level maintenance data at the next level up.
The problem
The ICA is usually the last document written and the first to fall behind the design, because it is drafted from a snapshot of the configuration while engineering is still closing changes. A part renumbered in a late revision, a limitation that moved when a test result came back, or a task written against a component that was deleted all leave the ICA describing an article that no longer exists. The mismatch is invisible in the supplier's own files and only shows up when the authority or an installer reads the ICA against the released configuration.
What gets reviewed
- Coverage of every maintainable and life-limited item in the authorized article by a maintenance or inspection task
- Limitations and airworthiness restrictions traced to the qualification result or safety assessment that set them
- Part numbers, effectivity, and life data in the ICA reconciled to the released configuration
- Software and field-loadable data maintenance provisions consistent with the DO-178C baseline
- Tasks that reference removed or superseded components identified and reconciled
- The ICA structured so it integrates into installation-level continued-airworthiness data
Scope this review
Tell us the asset, the event, and the evidence in scope, and we will outline a focused first engagement.
Identify what is missing against the means of compliance.
What gets validated
- Each maintainable item in the released configuration has a corresponding task or a documented reason it needs none
- Every limitation in the ICA traces to a qualification result, analysis, or safety-assessment output
- Part numbers and life limits in the ICA match the current released drawing set, not an earlier revision
- Software maintenance and reload provisions agree with the approved DO-178C load configuration
- No task references a component that the released configuration has deleted or renumbered
Evidence normally required
- The draft ICA and any parts, limitations, and maintenance sections it contains
- The released configuration or drawing set for the authorized article
- Qualification results and the safety assessment that establish the limitations
- Life-limited and time-controlled item data for the article
- Any installation-level maintenance data the ICA has to integrate with
Common discrepancies
- A maintainable item in the released configuration with no task written for it in the ICA
- A limitation stated in the ICA with no traceable qualification or analysis behind it
- Part numbers in the ICA that a late configuration revision has already superseded
- A task referencing a component the design deleted before release
What is at stake
An ICA that lags the authorized configuration cannot be accepted as the continued-airworthiness basis for the article, so the authorization stalls until it is reconciled. Downstream, an installer who builds installation maintenance data on a stale ICA propagates the error into the aircraft-level program, where it is far more expensive to unwind than it would have been to fix at the article level.
How the work runs
Map the maintainable items
List every maintainable and life-limited item in the released configuration and check the ICA covers each.
Trace the limitations
Tie each ICA limitation back to the qualification result or safety assessment that established it.
Reconcile parts and loads
Confirm part numbers, life data, and software provisions match the current released configuration.
Plan the revisions
Sequence the ICA corrections needed to bring the document into step before submission.
What the buyer receives
Who uses the output
- Certification leads confirming the ICA is ready to go into the authorization package
- Engineers reconciling ICA tasks and limitations against the released design
- Integrators who need the article ICA to fit their installation maintenance data
How the work fits into the transaction or program
The ICA is the continued-airworthiness half of an ETSO authorization: qualification and conformity prove the article meets the standard, and the ICA defines how it stays that way in service. This review runs while the ICA is still in draft, catching the lag between the document and the released configuration before it reaches the authority or gets built into installation-level data at the next level up.
Start with a single asset
Reduce finding cycles by checking the package first.
Jurisdiction-specific considerations
EASA expects the ICA supplied with an ETSO article to support the continued-airworthiness obligations that Part 21 places on the eventual installation, so limitations and tasks have to be stated in terms an installer's CAMO can carry into an approved maintenance programme. Where the article will also carry an FAA TSO, the review notes where ICA content acceptable under one system needs restating to satisfy the other's continued-airworthiness expectations.
Regulatory limits
The review checks that the ICA matches the authorized configuration and traces to its design basis. It does not approve the ICA, set airworthiness limitations on the authority's behalf, grant the ETSO authorization, or accept the article onto any installation's maintenance programme.
What this review does not cover
- Authoring the article's maintenance limitations or life limits from scratch
- Producing the installation-level continued-airworthiness data
- Any approval or acceptance of the ICA by an authority
Specific to this review
- The ICA is typically the last document to catch up to the design, so a late part renumber is the most common source of an ICA-to-configuration mismatch.
- A limitation without a traceable qualification or analysis basis is a coverage gap even when the number looks reasonable, because the authority cannot confirm where it came from.
- An article-level ICA error propagates upward into installation maintenance data, where correcting it costs far more than a revision at the supplier level.
Sources
European Union / EASA. EASA design and production certification, STCs, ETSO authorizations, and EASA Form 1 release.
RTCA. Environmental qualification test categories and procedures referenced by TSO and equipment qualification.
RTCA. Objectives and lifecycle data for airborne software assurance, by design assurance level (DAL A-E).
U.S. Government (eCFR). Type certificates, STCs (Subpart E), TSO authorizations (Subpart O), PMA (Subpart K), and export airworthiness approvals (Subpart L).
Federal Aviation Administration. STC application process, certification basis, and continued airworthiness obligations of an STC holder.
Frequently asked questions
Why review the ICA before the rest of the package is final?
Because the ICA is written from a configuration snapshot while engineering is still closing changes, it drifts from the design faster than any other document in the package. Reviewing it while it is in draft catches the lag before the authority reads it and before an installer builds installation data on top of it.
Relevant glossary terms
Related pages
Where this fits
Talk to an engineer who has done this work
We will walk through your current state, the records or evidence involved, and a scoped first engagement.
Talk through the aircraft, records, evidence, deadline, and next useful step.