Embedded software plays a critical role in space applications, where reliability, precision, and the ability to function in extreme conditions are paramount. These applications include control and navigation, payload operations, communications, collision avoidance, onboard diagnostics, and a host of other mission critical functionality.
For almost half a century, LDRA has been helping companies adhere to the best practices such as those laid down by the ECSS and NASA standards. Our tools ease the challenges of compliance by automating best practices from requirements traceability through static code analysis, software metrics, and coding standards adherence, to unit testing, integration testing, and structural coverage on host or target.
The European Cooperation for Space Standardization (ECSS) is “an initiative established to develop a coherent, single set of user-friendly standards for use in all European space activities.”
It is a cooperative effort involving the European Space Agency (ESA), Eurospace representing the European space industry, and various space agencies. Its primary goal is to create and uphold a unified, easily accessible set of standards for use across all European space endeavours. This initiative was established in 1993 in response to Eurospace’s appeal for harmonizing space product assurance standards at a European level. On June 23, 1994, the ESA formally embraced it through resolution ESA/C/CXIII/Res.1, supplanting its existing Procedures, Specifications, and Standards (PSS) system.
The ECSS organization and processes document ECSS-D-00B explains how ECSS activities are organized through a number of bodies as defined through ECSS policy. This organization chart of the ECSS bodies is an extract from that document.

ECSS standards cover a wide range of topics related to space activities, including engineering, quality assurance, safety, and more. The ECSS standards are designed to ensure consistency, reliability, and safety in European space missions.
The ECSS standards most pertinent to embedded software are:
NASA, or the National Aeronautics and Space Administration, is the United States government agency responsible for the nation’s civilian space programme and for aeronautics and aerospace research.
NASA guidance documents relating to the development of embedded software fall into two groups – standards and procedural requirements. The two groups are complementary, in that NPRs ensure that the processes and management aspects align with NASA’s goals, while STDs set the technical and engineering standards for achieving those goals.
The NASA standards most pertinent to embedded software are:
The NPRs most pertinent to embedded software are:
While there are similarities in NASA and ESA/ESCC approaches to software development due to the nature of space missions, there are also some differences. Here are some comparisons:
NASA places a strong emphasis on extensive, standardised documentation throughout the software development lifecycle. Their Software Engineering Handbook provides guidelines for documentation.
The ESA Software Engineering Standards also value documentation but offer more flexibility and may be adapted to specific mission needs.
Both NASA and ESA have rigorous verification and validation processes, and both place a strong focus on software safety and reliability. However, there are variations between their specific procedures and criteria – for example, ESA requires evidence of source to object code traceability for the most critical applications, whereas NASA does not.
Both agencies make software assurance a critical part of their standards. NASA’s Software Assurance (SA) process has similar aims to ESA’s Software Product Assurance (SPA) process. Both ensure that software products meet quality and safety standards and include audits, reviews, and independent assessments.
NASA occasionally uses open-source software but tends to rely more on custom-developed software due to its mission-specific requirements. Commercial off-the-shelf (COTS) software is also used when appropriate.
ESA may use a combination of open-source, commercial, and custom software, depending on the mission’s needs and budget constraints. They are typically required to adhere to the same high standards and procedures outlined in ESA’s software engineering standards.
Both ESA and NASA often collaborate with international partners, including each other, on space missions. In such cases, software development standards may need to be harmonized to ensure compatibility and interoperability.
Although current NASA and ECSS standards make some passing reference to cybersecurity, neither offers detailed guidance on best practice. The draft document ECSS-E-ST-40C Rev1 does offer some promise of change in the future. In the meantime, it is generally acknowledged that the products of the industry represent critical infrastructure – for example, that is already acknowledged in the UK, while there are also moves towards the US taking a similar position.
Until more detailed, space-specific guidance is available, identifying appropriate best practices and adhering to them is likely the most pragmatic and prudent approach. The information relating to the Aerospace Security Framework and the generic cybersecurity advice offered by IEC 64443 may be helpful.

White paper: Test tool qualification for functional safety
Technical briefing: Clarifying and fulfilling test tool qualification requirements
Technical briefing: DO-178C demystified: Strategies for efficient certification
Technical white paper: Verification of Airborne Software in Compliance with DO-178C
ECSS Standards : Compliance with ECSS-E-ST-40C and ECSS-Q-ST-80C Rev1
Email: info@ldra.com
EMEA: +44 (0)151 649 9300
USA: +1 (855) 855 5372
INDIA: +91 80 4080 8707