What airworthiness certification requirements apply to new avionics?

Lead Author

Dr. Aris Aero

Published

Sep 14, 2026

Views:

New avionics may look like a contained engineering upgrade—a display, a navigation receiver, a flight-control computer, a connectivity gateway, or a new software load. In a certified aircraft, however, no avionics change is isolated. It can alter pilot workload, electrical loading, failure behavior, electromagnetic compatibility, maintenance practice, cybersecurity exposure, and the aircraft’s approved operating limitations.

That is why airworthiness certification requirements for new avionics extend well beyond proving that a unit performs its intended function on a bench. Technical evaluators need to establish whether the equipment is eligible for approval, whether the proposed installation is safe in its aircraft context, and whether the applicant can sustain the configuration throughout the product’s service life.

For FAA and EASA programs, the exact route depends on the aircraft category, the nature of the change, the intended function, and the authority’s agreed certification basis. The central question remains consistent: can the applicant provide objective evidence that the avionics system performs its intended function without introducing unacceptable risk?

Start with the approval route, not the test plan

A common early mistake is to select qualification tests before defining the approval strategy. That can produce evidence that is technically impressive but poorly aligned with the certification project. Before reviewing software maturity, environmental test chambers, or supplier declarations, determine what is actually being approved.

For a newly designed aircraft, avionics are normally evaluated as part of the aircraft type-certification program under the applicable FAA or EASA airworthiness standards. Depending on the platform, this may involve transport-category aeroplanes, normal-category aeroplanes, rotorcraft, powered-lift aircraft, or a special class of aircraft. The avionics equipment, its installation, and its interaction with the overall aircraft safety assessment are reviewed together.

For an existing aircraft, the work may be pursued through a supplemental type certificate (STC), an amended type certificate, or another approved change process. A minor change may require less authority involvement than a major change, but the classification cannot be assumed merely because the physical installation appears simple. A software-enabled navigation function, an autopilot interface, or an electronic flight bag connectivity feature may have significant operational and safety implications.

Equipment approval can also be relevant. In the United States, a Technical Standard Order (TSO) authorization can demonstrate that an article meets a defined minimum performance standard. In Europe, the equivalent route is generally an ETSO authorization. Yet a TSO or ETSO approval is not, by itself, approval to install the equipment in every aircraft. The installer must still show that the particular installation complies with the applicable aircraft-level requirements.

This distinction matters in procurement reviews. “TSO-approved” does not answer questions about antenna placement, display legibility, cooling, circuit protection, latent failure interactions, operational procedures, or compatibility with legacy systems. It is a meaningful piece of evidence—not the end of the airworthiness case.

The certification basis defines what “acceptable” means

The certification basis is the set of regulations, special conditions, exemptions, and agreed means of compliance that govern the project. For FAA programs, this commonly connects to regulations such as 14 CFR Part 21 for certification procedures and the applicable airworthiness standards in Parts 23, 25, 27, 29, or other product-specific rules. EASA projects follow the corresponding certification procedures and Certification Specifications, such as CS-23, CS-25, CS-27, and CS-29.

Modern avionics often raise issues that were not fully anticipated when a base aircraft was originally certified. Advanced autonomy, artificial-intelligence-enabled functions, high-integrity wireless links, complex integrated modular avionics, and cloud-connected maintenance tools may require special conditions, issue papers, certification review items, or early authority engagement. This is particularly relevant in eVTOL and urban air mobility development, where distributed propulsion, novel flight-control architectures, and highly integrated vehicle management systems shift familiar boundaries between avionics, propulsion, and aircraft control.

A strong evaluator asks for a certification plan that maps each requirement to a means of compliance: analysis, inspection, ground test, flight test, similarity, or a combination. The plan should identify who owns each compliance item, which assumptions must remain valid, and where authority concurrence is required.

Safety assessment drives the development assurance level

Airworthiness is fundamentally about controlling the consequences of failure. An avionics function must be assessed not only for normal operation but also for erroneous output, loss of function, intermittent behavior, misleading information, common-cause failures, and adverse interactions with other systems.

System safety processes are commonly structured around ARP4754A for aircraft and system development and ARP4761/ARP4761A concepts for safety assessment. These documents are widely used industry guidance rather than universal regulations in themselves, but they provide a disciplined framework that certification authorities recognize in many programs.

The process begins by defining the function and its failure conditions. What happens if a traffic display freezes? If a flight-control computer transmits a valid-looking but incorrect command? If a navigation source is unavailable during an approach? If an integrated cockpit display presents conflicting alerts? The severity of each failure condition—often categorized from no safety effect through minor, major, hazardous, and catastrophic—helps establish the required integrity of the design.

That classification then informs the Development Assurance Level (DAL). Higher-consequence functions need more rigorous development, verification, independence, configuration control, and evidence. The DAL is not a label that can be assigned by marketing preference or inherited automatically from a predecessor product. It must be supported by the aircraft-level safety assessment and the allocated system architecture.

What airworthiness certification requirements apply to new avionics?

Software, airborne electronic hardware, and configuration evidence

Most new avionics contain software, and the certification burden often rises sharply when that software supports flight-critical or safety-significant functions. RTCA DO-178C and the related EUROCAE ED-12C are the principal guidance documents used for airborne software development assurance. They address planning, requirements, design, coding, verification, configuration management, quality assurance, and lifecycle data.

DO-178C does not certify software as a standalone consumer product. Instead, it supports a finding that the software was developed with an assurance process appropriate to its assigned DAL and intended aircraft use. Evidence typically includes plans, standards, requirements traceability, test results, coverage analysis where applicable, problem reports, configuration indices, and quality-assurance records.

If the avionics include custom complex electronic hardware—such as an FPGA, ASIC, or programmable logic device—DO-254/ED-80 is commonly applied. Evaluators should be alert to the boundary between software and hardware. Moving a function into programmable logic does not remove the need for development assurance; it changes the evidence expected.

Configuration control deserves special attention. A certified configuration is more than a part number on a purchase order. It includes hardware revisions, firmware versions, loadable software parts, databases, build tools where relevant, approved options, and compatibility constraints. A system that is safe in one configuration may not remain safe after an apparently small interface, database, or operating-system change.

Environmental qualification must match the installation reality

Avionics are often qualified using RTCA DO-160 or EUROCAE ED-14 environmental test methods. These may cover temperature, altitude, vibration, shock, humidity, fluids, power input, radio-frequency susceptibility, emissions, lightning-related effects, electrostatic discharge, and other environmental stresses.

Reviewing a DO-160 report is essential, but it should not become a box-checking exercise. The relevant test categories must correspond to the actual installation zone and aircraft environment. A unit installed in a pressurized, temperature-managed avionics bay does not face the same exposure as one located near a rotorcraft transmission, within an unpressurized equipment compartment, or adjacent to high-voltage electrical equipment.

Installation-specific issues also remain outside a generic equipment qualification report. These include wire routing, grounding and bonding, cooling airflow, mounting stiffness, circuit-breaker coordination, antenna performance, lightning protection, and electromagnetic interference with existing aircraft systems. For electrically propelled aircraft and high-power hybrid platforms, high-voltage transients and electromagnetic effects can demand especially careful integration analysis.

Installation approval is where hidden integration risk emerges

An avionics supplier can provide a well-qualified unit and still leave the aircraft integrator with substantial certification work. The installation must show compliance with requirements for system operation, human factors, electrical power, equipment design, fire protection where applicable, and continued safe flight and landing following failures.

Flight-deck changes deserve a human-factors review as much as an electrical review. A new display can affect alert prioritization, color conventions, control reach, data-entry error probability, crew procedures, and workload during high-demand phases of flight. This is not cosmetic. A correct message that arrives at the wrong time, in the wrong place, or with an ambiguous annunciation can become a safety issue.

Interfaces should be treated as certification items in their own right. ARINC buses, Ethernet networks, AFDX architectures, serial links, wireless channels, and discrete I/O all introduce potential failure propagation paths. The evaluation should address data freshness, integrity, partitioning, timing, loss-of-communication behavior, initialization states, and protection against invalid or out-of-range data. Where one system relies on another system’s output, the assumptions at that interface need explicit verification.

Cybersecurity is now part of the airworthiness conversation

Connectivity has made aircraft more capable, but it has also made the traditional line between operational technology and information technology less clear. If an avionics system can receive data from maintenance devices, airport networks, satellite links, passenger networks, or ground-based operational systems, its security architecture may affect airworthiness.

FAA and EASA expectations continue to evolve, but industry guidance such as DO-326A/ED-202A, DO-355/ED-204, and DO-356A/ED-203A provides a structured approach to airworthiness security. The aim is not simply to prove that a device has encryption. Evaluators should examine security risk assessment, attack paths, trust boundaries, access control, secure loading, vulnerability management, logging, recovery behavior, and the safety impact of a compromised function.

Security and safety teams should work from a shared architecture. A late cybersecurity review often exposes assumptions that are expensive to reverse, such as an unrestricted maintenance port, a shared network segment, or a software update mechanism without adequate authenticity and rollback controls.

Continued airworthiness is part of the approval, not an afterthought

A certification package must support safe operation after entry into service. Instructions for Continued Airworthiness (ICA) may need to address scheduled inspections, functional checks, software loading procedures, database update controls, fault isolation, repair limitations, wiring maintenance, and component life or environmental constraints.

For avionics with frequent updates, the change-management model should be defined early. Which updates are approved changes? Which can be managed within an established configuration-control process? How will operators confirm installed versions? What happens when a new software release affects interoperability with other approved equipment? These questions are increasingly important for connected aircraft, satellite infrastructure, autonomous rail control, and high-speed mobility systems, where digital configuration can change faster than physical hardware.

A practical evidence review for technical evaluators

When screening a new avionics proposal, request evidence in a sequence that exposes certification risk early:

  • Intended function, operating environment, aircraft applicability, and proposed approval route.
  • Certification basis, compliance checklist, and authority engagement plan.
  • Aircraft and system safety assessments, including DAL allocation and interface assumptions.
  • Software and hardware development-assurance artifacts appropriate to the assigned level.
  • Environmental qualification reports with categories justified by the intended installation.
  • Installation drawings, wiring data, power and thermal analyses, antenna or RF assessments, and electromagnetic compatibility evidence.
  • Cybersecurity assessment and secure configuration or update procedures where connectivity exists.
  • Flight-test, ground-test, and conformity plans, plus draft ICA and operational documentation.

The most useful review question is rarely “Do we have a report for this?” It is “Does the report prove the claim being made for this aircraft, this configuration, and this operating context?” That discipline prevents a collection of supplier documents from being mistaken for an integrated airworthiness case.

What usually delays approval

Schedule pressure often reveals the same weaknesses: safety requirements that changed after detailed design, incomplete traceability from aircraft hazards to equipment requirements, unverified assumptions about legacy interfaces, environmental categories copied from another platform, and software baselines that drifted during testing. Another recurring issue is treating flight test as a substitute for disciplined ground verification. Flight testing is vital, but it cannot efficiently uncover every requirement, corner case, or configuration anomaly.

For globally deployed programs, it is also prudent to assess FAA and EASA expectations together from the beginning. Their frameworks are substantially aligned in many technical areas, yet project-specific interpretations, administrative processes, and acceptable means of compliance can differ. A dual-authority strategy reduces the risk of building evidence for one market while discovering late gaps for another.

Certification-ready avionics begin with traceable decisions

New avionics enter service only when their function, failure behavior, development process, installation, and maintenance model form a coherent, auditable argument. The relevant airworthiness certification requirements are therefore not a single checklist. They are a connected body of evidence showing that the right requirements were selected, the design meets them, the aircraft integration preserves them, and the approved configuration can be maintained in service.

For technical assessment teams working across next-generation aviation, space-connected systems, eVTOL platforms, and other advanced transportation environments, the most reliable approach is to bring certification thinking into architecture decisions—not after the prototype is already flying. Early clarity on approval pathways and evidence expectations protects both program credibility and the safety case that ultimately allows innovation to operate in the real world.

Recent Articles