Major change program
Airborne electronic hardware lifecycle data review for a change
This review checks the DO-254 airborne electronic hardware lifecycle data supporting a major change, confirming that the hardware plans, design data, verification, and configuration records support the assigned design assurance level. A certification specialist reads the hardware data against the DAL it carries, finding the verification depth and design-assurance activities the level requires but the data does not show. The output separates data that supports the assigned DAL from data built to a lower one. You receive a gap assessment, a DAL-coverage map, and a closure plan before the hardware data supports the compliance claim.
When this review is needed
- The change raised the DAL on a complex electronic hardware item built to a lower one.
- A programmable device is being modified and its design-assurance data has not been rechecked against the level.
- Hardware plans, design data, and verification exist but their sufficiency for the DAL is unconfirmed.
- Configuration records for the hardware have to demonstrate control at the assigned level.
The problem
DO-254 design assurance is scaled to the DAL, and a major change can push a complex hardware item to a higher level than its lifecycle data was built for. Design data, verification, and the design-assurance activities appropriate to a lower level carry forward, and at the new level they no longer show the depth the level expects, particularly for elemental analysis, verification independence, and configuration control. The data set is real and organized; it is organized around a level the change has left behind.
What gets reviewed
- The assigned DAL confirmed and the design-assurance depth it requires established
- Hardware plans checked for alignment to the assigned level, not a lower prior one
- Design data and derived requirements read against the level's expectations
- Verification records checked for the coverage and independence the DAL demands
- Configuration management records confirmed to demonstrate control at the level
- Reused hardware data screened for whether its assurance depth suits the new DAL
Scope this review
Tell us the asset, the event, and the evidence in scope, and we will outline a focused first engagement.
Identify what is missing against the means of compliance.
What gets validated
- The hardware plans reflect the design-assurance objectives of the assigned DAL
- Verification coverage and independence meet what the level requires
- Derived requirements and their justification are captured to the level's depth
- Configuration records demonstrate control adequate for the assigned DAL
- Reused hardware data meets the new DAL rather than its original level
Evidence normally required
- The DO-254 hardware plans, design data, and verification records
- The assigned DAL and the safety assessment that set it
- The hardware accomplishment summary or equivalent
- The configuration management records for the hardware item
- The origin and level of any reused hardware data
Common discrepancies
What is at stake
Hardware lifecycle data that falls short of the assigned DAL leaves the design-assurance argument incomplete, which an authority surfaces by testing the verification depth against the level and which can force additional analysis, independent verification, or configuration rework late in a program. On a complex programmable device, reconstructing that depth after the fact is among the most schedule-hostile work a change can carry.
How the work runs
Fix the DAL and its depth
Confirm the assigned DAL from the safety assessment and establish the design-assurance depth it requires.
Read the data to the level
Check plans, design data, and verification against the assigned DAL, not the item's prior one.
Check configuration control
Confirm the configuration records demonstrate control adequate for the assigned level.
Close to the level
List the shortfalls in coverage, independence, and control and sequence the work to close them.
What the buyer receives
Who uses the output
- Certification leadership confirming the hardware data supports the assigned DAL
- Engineering leadership sourcing the additional design assurance the level requires
- Compliance managers tracking the DAL shortfalls still open
How the work fits into the transaction or program
The hardware data review runs once the DAL is fixed by the safety assessment and the lifecycle artifacts exist, because design-assurance sufficiency is only meaningful against a settled level. A gap caught here is closed with planned analysis or independent verification; the same gap at review is a DAL finding on hardware the program considered complete.
Start with a single asset
Reduce finding cycles by checking the package first.
Regulatory limits
The review confirms the hardware lifecycle data is complete and consistent for the assigned DAL. It does not assign the DAL, approve the hardware, or make any compliance or airworthiness finding.
What this review does not cover
- Producing the additional verification or analysis the DAL requires
- Assigning or changing the design assurance level
- Any compliance or airworthiness determination on the hardware
Specific to this review
- DO-254 design assurance is scaled to the DAL, so hardware data built for a lower level is structurally short the moment the change raises it.
- Verification independence and elemental analysis are the activities most often missing when data is carried up from a lower DAL.
- Reconstructing design-assurance depth on a complex programmable device after the fact is among the most schedule-hostile work a change can carry.
Sources
U.S. Government (eCFR). Type certificates, STCs (Subpart E), TSO authorizations (Subpart O), PMA (Subpart K), and export airworthiness approvals (Subpart L).
Federal Aviation Administration. FAA type certification process, certification basis establishment, and compliance findings.
European Union / EASA. EASA design and production certification, STCs, ETSO authorizations, and EASA Form 1 release.
RTCA. Design assurance objectives and lifecycle data for airborne electronic hardware (FPGA/ASIC/PLD).
SAE International. Development assurance process at aircraft and system level, including requirements capture and validation.
Frequently asked questions
The hardware has a full DO-254 data package already. Why review it for the change?
A DO-254 package is sufficient relative to a DAL. If the change raised the level, the design-assurance depth that was adequate before now falls short, especially in verification independence and configuration control. The review maps the hardware data to the DAL the change actually assigned.
Relevant glossary terms
Related pages
Where this fits
Talk to an engineer who has done this work
We will walk through your current state, the records or evidence involved, and a scoped first engagement.
Talk through the aircraft, records, evidence, deadline, and next useful step.