What do cybersecurity, sustainability, autonomy, and advanced air mobility have in common? These trends present some of the most significant new challenges and opportunities for avionics manufacturers. Addressing them relies on more—and more sophisticated—software that must continue to meet airworthiness certification requirements to ensure safety and security. Development teams are finding that the cost, time, and effort to meet airworthiness certification goals is rising dramatically.
While reuse of existing software allows development and compliance resources to focus more effort on new functionality, modern avionics systems are harder to develop and harder to get right. This has significantly increased the effort and difficulty of the already-formidable task of certifying next-generation software for airworthiness. At the same time, a growing shortage of software developers means avionics and aerospace leaders are forced to find new efficiencies to meet ongoing product release schedules while still maintaining and updating existing systems.
Typically, decisions around software development and verification tools have been managed within individual development teams. With today’s complex regulatory landscape and short windows of competitive opportunity, however, these choices now have a broader impact. Software development initiatives aimed at reducing the cost, time, and risk of certification have become critical path activities for business leaders. Understanding the business impacts can help executive teams take a more informed role in those decisions.


One of the clearest, proven ways to reduce cost, time, and risk is to identify and address issues as early as possible in the development process. Individual teams may feel comfortable with their existing software tools and processes, but the old ways of working are no longer effective in today’s changing landscape.
The increasing complexity and volume of compliance requirements make verification more challenging. Trying to address them without integrated, automated tools is no longer possible. Disparate groups must be able to work in parallel to reduce development and certification time. Significant advantages can be gained with the use of an integrated development and verification tool chain across groups and product lines.
Software verification typically requires at least as much time, effort, and resources as the entire planning and development processes combined. That makes testing and certification costly activities.
Compliant system development involves audits of development and verification activities both for new systems and for product upgrades. Unfortunately, many project teams put more focus on the outcome of individual audits and milestones than the software development and verification process itself. This short-sighted approach can result in suboptimal software and software failures. Successful development teams take a bigger-picture approach that addresses the entire software development lifecycle to ensure effective communication and knowledge transfer through every stage.
The move to an integrated suite of automated software development and verification tools can have a dramatic impact on these efforts. This can be especially important for remote and geographically dispersed teams who need to aggregate information over the course of development and testing or rework, during which manual processes or disparate tools can introduce inefficiencies along with opportunities for errors and vulnerabilities.
Unlike spreadsheets or stand-alone document-management systems, integrated tools offer full visibility and change-impact analysis across projects and teams, enabling better decision making more quickly. An ideal set of verification tools provides a broad range of capabilities including requirements traceability, change impact analysis, test management, coding standards compliance, code quality review, code coverage analysis, data- and control flow analysis, unit/integration/system testing (including target testing), along with the automated generation of certification evidence.
Such tools lend themselves equally to any software development lifecycle model, including Agile and the V model in DO-178C. They also lend themselves to a continuous integration workflow. Verification tools are an important part of the continuous integration (CI) workflow, allowing teams to use the same tools throughout the development process for rapid, iterative software development and verification. Applying CI, developers can run static analysis and unit testing as part of their front-end verification, to make sure their code is doing what it’s intended even before it’s merged with other code bases.
Cybersecurity in avionics systems has been a moving target with serious implications for safety, making it a significant driver of business risk and uncertainty. The recommended strategy to thwart cyberattack is to design in security so that vulnerabilities are minimized during development. Subsequent testing of the completed software can then help to prove the efficacy of that approach before the product is put into the field. Once there, a strategy to address any newly exposed vulnerabilities quickly and safely becomes important.
To address this challenge, many teams are moving to DevSecOps (development/ security/ operations) to help reduce costs and risk and improve efficiencies. In contrast to the traditional handoff to security teams after software is completed, this “shift left” enables software development and security teams to work efficiently and cost-effectively together, in parallel. Flexible and customizable software tools easily adapt to the level of risk and necessary rigor of mitigation, and requirements traceability tools enable a rapid response for dealing with a compromised vulnerability even for systems that have been unchanged for years.
This requirement to deal with both safety and security illustrates why it is important for verification to be extensible for specific needs. For example, the tools should support the development and verification of software that needs to achieve DO-178C and DO-326B certification in parallel (Figure 2). In this figure, the security process described in DO-326B has been aligned with the aircraft development process described in ARP4754A, showing how developers can follow a hybrid safety and security process to satisfy both standards. Trying to achieve compliance/conformance with multiple standards sequentially increases the time and cost to develop, and it would likely result in unnecessary rework including a costly cycle of regressions and fixes.

Even with the support of comprehensive automation, coming to grips with airworthiness regulation can be a daunting task. Certification and regulatory support are available to provide a helping hand and give confidence that certification costs will be contained. In the US, services must be delivered by a team with experience liaising with FAA Aircraft Certification Offices (ACO). In addition to comprehensive audit support, services may include training, mentoring and the production of compliance artifacts that expedite and enhance life cycle data production.
Software development often begins before the project target hardware is available, and perhaps before it has been completely specified – an issue that is often exacerbated on smaller aircraft developed with the intent for more frequent upgrades. Hardware simulators are usually deployed in such situations, although for critical systems with higher levels of design assurance, verification must ultimately be on the final target. Verification tools must therefore be flexible enough to support both simulation and target testing.
Highly critical software developed in compliance with DO-178C DAL A requires verification that the object code executed by the microprocessor correctly reflects the requirements and the intent of the developer. Using different tool chains for different levels of software criticality can introduce additional delays at certification. A single, flexible tool suite capable of demonstrating source code to object code traceability that can be used at any level of verification allows teams to quickly and efficiently match the level of risk identified without an additional learning curve.
Many technical leaders are incorporating new approaches such as model-based software development and object-oriented analysis and design. These allow for faster development, but new layers of abstraction mean that testing becomes critical to keep errors at bay. Verification tools should enable fast and frequent iterationsof virtual prototyping and testing, either on the host development platforms or on the actual target hardware. This ensures that abstractions don’t result in late discovery of errors that can cause delays at certification.
One final and important consideration is tool qualification. Qualification of software verification tools is required for any certification exceeding DO-178C Level C and involves validating the operation of the tool in a project-specific environment. To reduce the cost associated with this qualification process, tool providers offer tool qualification packages and certification support services for programs requiring the appropriate level of assurance. Aircraft certification services encompass systems, safety, security, and electronic hardware and software.
Successful organizations understand that the future will only become more challenging, and that the time to address concerns and make fundamental changes is now—not during a future critical product launch. A flexible, robust, and scalable development process offers the best chance for successfully addressing challenges and reducing risk and uncertainty.
With a comprehensive verification tool suite providing a consistent user interface for all aspects of verification and validation, teams are well-armed with documentation and shared knowledge throughout the process. Integration of verification tools with associated development tools throughout the product development lifecycle provides a foundation for overcoming the challenges of certifying next-generation flight software.
Author – Steve DiCamillo, Technical Marketing and Business Development Manager at LDRA.
Read the article in Embedded.com at https://www.embedded.com/addressing-the-challenges-of-certifying-next-generation-flight-software
Email: info@ldra.com
EMEA: +44 (0)151 649 9300
USA: +1 (855) 855 5372
INDIA: +91 80 4080 8707