DO-178C (Software Considerations in Airborne Systems and Equipment Certification) is the primary international standard governing the development and certification of airborne software, published by RTCA in 2011 as the successor to DO-178B. It defines five software levels (A through E) based on failure severity, each requiring progressively more rigorous development assurance activities including requirements traceability, structural coverage testing, and independence in reviews. Compliance with DO-178C is required by aviation regulatory authorities (FAA, EASA) for software installed in certified aircraft.
Content
- Aviation software certification requirements originated with the FAA’s Advisory Circulars in the 1970s, evolving through DO-178 (1982) and DO-178A (1985) before DO-178B (1992) became the global standard for two decades. The 2011 release of DO-178C introduced technology supplements for object-oriented and related technologies (DO-332), formal methods (DO-333), and model-based development (DO-331), acknowledging that modern software development practices required explicit guidance beyond what DO-178B addressed.
- The standard defines five design assurance levels (DALs): Level A covers software whose failure could cause catastrophic aircraft loss; Level B covers hazardous failures; Level C covers major failures; Level D covers minor failures; Level E is non-safety-relevant. Each level prescribes objectives across planning, development, verification, and configuration management processes. Level A requires MC/DC structural coverage—every condition in a decision must independently affect the decision’s outcome—a criterion that drives test case generation and is computationally demanding to satisfy on complex avionics software.
- DO-178C compliance requires formal lifecycle documentation including Plans for Software Aspects of Certification (PSAC), Software Development Plans, Software Verification Plans, and Software Configuration Management Plans. Tool qualification (DO-330) is required when a software tool’s output is not manually verified—compilers, static analysers, and code generators used in the development chain must themselves be qualified. This creates significant overhead compared to non-aviation software development, but provides the evidence base that airworthiness authorities require to grant type certification.
- By 2024–2025 DO-178C faces challenges from AI integration in avionics: neural networks trained through gradient descent cannot satisfy traditional requirements traceability and structural coverage criteria. EASA’s AI Roadmap and RTCA’s SC-216 special committee are developing guidance (tentatively DO-178D or a supplement) for machine learning in airborne systems. Autonomous flight systems, advanced air mobility (eVTOL), and AI-assisted flight management are creating urgency for adapted assurance frameworks that retain the rigour of DO-178C while accommodating data-driven components.