2026-09-21 · Equipo editorial KeXinMaterials

DO-178C Aseguramiento Diseño Software Aeronáutico Deep Dive + Maletín B2B Guía

RTCA DO-178C / EUROCAE ED-12C "Consideraciones de software para certificación de sistemas aéreos" (2011) es la norma aceptada FAA / EASA. DAL A a E.

DO-178C Scope + DAL Allocation + Software Lifecycle

DO-178C 2011 Edition. Replaces DO-178B 1992. DAL A-E per failure condition. 10 chapters + supplements.

RTCA DO-178C / EUROCAE ED-12C: "Software Considerations in Airborne Systems and Equipment Certification". 2011. Replaces DO-178B 1992. FAA + EASA accepted.

Edition history: DO-178 (1982) + DO-178A (1985) + DO-178B (1992) + DO-178C (2011). Currently active DO-178C. Supplements DO-330/331/332/333 (2011).

Scope: Airborne software + airborne systems + equipment certification. Includes flight control + navigation + display + autopilot + engine control + cabin + entertainment + ground operations + maintenance + mission + military.

DAL (Design Assurance Level) per DO-178C § 2.2: Same as DO-254. DAL A + DAL B + DAL C + DAL D + DAL E. Determined by failure condition per SAE ARP 4761 + SAE ARP 4754A.

Failure condition per SAE ARP 4761: Catastrophic + Hazardous + Major + Minor + No Effect. Maps to DAL A-E.

Software lifecycle per DO-178C Table 1: Planning + Software Requirements + Software Design + Software Implementation + Software Verification + Software Configuration Management + Software Quality Assurance + Software Certification Liaison. 8 processes.

Software Planning per DO-178C § 4: Plan Software Aspects of Certification (PSAC) + Software Development Plan (SDP) + Software Verification Plan (SVCP) + Software Configuration Management Plan (SCMP) + Software Quality Assurance Plan (SQAP).

Software Requirements per DO-178C § 5: Software Requirements Data (SRD) + Software Requirements Standards. High-level requirements + low-level requirements. Traceability.

Software Design per DO-178C § 5.3: Software Design Data (SDD) + Software Design Standards. Software architecture + detailed design. Traceability to SRD.

Software Implementation per DO-178C § 5.5: Source code + object code. Per coding standards. Traceability to design.

Software Verification per DO-178C § 6: Per DAL. Multiple methods: requirements-based testing + review + analysis + test coverage + structural coverage + regression testing.

Software Configuration Management per DO-178C § 7: Problem reporting + change control + archive + retrieval + release control + baselines.

Software Quality Assurance per DO-178C § 8: Compliance review + conformity review + process assurance + Stage of Involvement (SOI) audits.

Software Certification Liaison per DO-178C § 9: Communication with certification authority. SOI audits per DAL. FAA / EASA / TCCA / CAAC / JCAB / CASA.

Geographic adoption: FAA (US) + EASA (Europe) + TCCA (Canada) + CAAC (China) + JCAB (Japan) + CASA (Australia) + DGCA India. Global acceptance per bilateral agreements.

B2B relevance: For B2B protective cases containing avionics software (flight control + autopilot + navigation + display + cabin + engine), DO-178C compliance per DAL is procurement requirement for FAA + EASA + commercial aerospace.

Per-DAL Verification + Structural Coverage + Traceability

Per-DAL verification rigor. Structural coverage C0/C1/MC/DC. Requirements traceability. Independence per DAL.

Per-DAL verification rigor per DO-178C § 6 Table A-1 to A-9: Different verification methods required per DAL.

Per-DAL verification methods: Requirements-based testing + review + analysis + test coverage + structural coverage + regression testing. Higher DAL = more methods + more rigor.

Requirements-based testing per DO-178C § 6.4.4: Tests derived from requirements. Normal range + robustness + error handling. Required per DAL.

Structural coverage per DO-178C § 6.4.4 + Table A-7: Statement coverage (C0) + Branch coverage (C1) + Modified Condition / Decision Coverage (MC/DC).

Structural coverage per DAL: DAL C requires statement coverage (C0). DAL B requires branch coverage (C1). DAL A requires MC/DC.

Statement coverage (C0) per DO-178C: Every executable statement in source code executed at least once during testing.

Branch coverage (C1) per DO-178C: Every branch (if-then-else + switch-case) executed at least once in each direction.

Modified Condition / Decision Coverage (MC/DC) per DO-178C § 6.4.4: Each condition in a decision must be shown to independently affect the decision result. Required for DAL A.

MC/DC requires: Every condition in a decision must take both true + false values + each condition must independently affect decision outcome. TUV Sued Software Tool Qualification + VectorCAST + LDRA + Tessy + Cantata + Coverity.

Requirements traceability per DO-178C § 6.4.2: Bidirectional traceability between system requirements + high-level software requirements + low-level software requirements + source code + test procedures + test results.

Per-DAL independence per DO-178C § 6.2 + Table A-1 to A-9: Per DAL. Higher DAL = more independence for verification activities. DAL A typically requires independent verification (separate person + organization).

Independence levels per DO-178C: Level A (independent verification authority). Level B (independent person within same organization). Level C (no independence required).

Per-DAL independence mapping: DAL A + B typically require Level A or B independence for critical verification activities. DAL C + D + E may use Level C.

Software testing per DO-178C § 6.4.4: Requirements-based test cases + procedures + results + coverage analysis + regression testing.

Common DO-178C mistakes: (1) Missing per-DAL rigor. (2) Missing structural coverage analysis (MC/DC for DAL A). (3) Missing requirements traceability. (4) Missing independence per DAL. (5) Missing SOI audits per DAL.

B2B recommendation: For B2B avionics software case, require DO-178C per DAL + per-DAL verification + structural coverage (MC/DC for DAL A) + requirements traceability + independence per DAL + SOI audits.

DO-330/331/332/333 Supplements + Tool Qualification

DO-330 tool qualification + DO-331 MBSE + DO-332 OOT + DO-333 formal methods. Modern avionics software development practices.

DO-330 (Software Tool Qualification Considerations): Per DO-178C § 12.2. Required for tools used in software development. Five Tool Qualification Levels (TQL-1 to TQL-5).

TQL-1 (most rigorous): Tool could cause undetectable error. Required for compilers + assemblers + linkers + static analyzers + test vector generators.

TQL-2: Tool could cause error detectable by downstream verification.

TQL-3: Tool could cause error not affecting safety directly.

TQL-4: Tool affects only non-safety items.

TQL-5: Tool has no impact. No qualification required.

Compiler qualification per DO-330 TQL-1: GCC + LLVM + IAR + Keil + GreenHills + WindRiver + TASKING + ARM Compiler + clang + Intel Compiler. Required for DAL A + B typically.

DO-331 (Model-Based Development): Per DO-178C Supplement. MBSE (Model-Based Systems Engineering). Tools: Mathworks Simulink + Stateflow + dSPACE TargetLink + SCADE Suite + IBM Rational Rhapsody + No Magic MagicDraw + Cameo Systems Modeler.

MBSE development: High-level model (architecture) + low-level model (detailed design) + auto-generated code + verification at model level + on-target testing.

MBSE verification: Per DO-331 § MB.5. Model coverage + structural coverage + back-to-back testing (model vs code) + requirements traceability + model review.

DO-332 (Object-Oriented Technology): Per DO-178C Supplement. C++ + Java + Ada 95. OOT concerns: inheritance + polymorphism + dynamic binding + memory management + exception handling.

OOT verification: Per DO-332 § OO. Object coverage + inheritance coverage + polymorphism verification + binding coverage + memory coverage.

DO-333 (Formal Methods): Per DO-178C Supplement. Formal verification. Tools: Coq + Isabelle + HOL Light + ACL2 + Frama-C + Polyspace + Astrée + KLEE + CBMC + SpaceEx + NuSMV + UPPAAL.

Formal methods verification: Abstract interpretation + model checking + theorem proving + SAT/SMT solvers + deductive verification. Required for DAL A safety-critical code typically.

Polyspace: Per DO-333 TQL-1. Abstract interpretation for C/C++/Ada code. Detects runtime errors + overflow + divide-by-zero + array bounds + NULL pointer + uninitialized variable + unreachable code + dead code.

Astrée: Per DO-333 TQL-1. Abstract interpretation for C code. Used in Airbus + DO-330 + DO-333 for avionics safety-critical software.

Common B2B mistakes: (1) Missing tool qualification per DO-330. (2) Missing MBSE supplements per DO-331. (3) Missing OOT supplements per DO-332. (4) Missing formal methods per DO-333. (5) Missing SOI audits per DAL.

B2B recommendation: For B2B avionics software case, require DO-178C per DAL + DO-330 tool qualification + DO-331 MBSE + DO-332 OOT (if applicable) + DO-333 formal methods (if DAL A) + per-DAL verification + SOI audits.

B2B Procurement Workflow + Cost + Test Lab + Case Design

DO-178C B2B procurement workflow + cost + test lab + protective case requirements.

B2B procurement workflow: (1) Identify program + aircraft + system + software function. (2) Determine DAL per SAE ARP 4761 + ARP 4754A + system safety per ARP 4761. (3) Specify DO-178C compliance per DAL + DO-330/331/332/333 supplements if applicable. (4) Verify software development plan + verification + configuration management + quality assurance + certification liaison. (5) Verify per-DAL verification + structural coverage + traceability + independence. (6) Verify FAA / EASA SOI audits + certification.

Cost: DO-178C development per DAL EUR 100,000-5,000,000 per software function. DAL A much more expensive than DAL E. Tools (compiler + verifier + analyser) EUR 50,000-500,000 per year. SOI audits EUR 50,000-200,000 per audit. FAA / EASA certification EUR 50,000-200,000 additional. Total EUR 250,000-5,000,000 per DAL function.

Duration: DO-178C development per DAL 12-48 months. Higher DAL = longer. FAA / EASA certification 12-24 months additional. Total 24-72 months.

Common tools: Greenhills INTEGRITY RTOS + VxWorks + LynxOS-178 + PikeOS+RTCA + Deos + AUTOSAR. Required for DAL A + B typically.

Common code generation tools: Mathworks Simulink + Stateflow + dSPACE TargetLink + SCADE Suite + Esterel SCADE + IBM Rational Rhapsody.

Common verification tools: VectorCAST + LDRA + Cantata + Tessy + IBM Rational Test RealTime + LDRA TBvision + Parasoft + Coverity.

Test lab: FAA DER (Designated Engineering Representative) + EASA SSEA + TCCA + CASA + CAAC. Direct certification by FAA / EASA per SOI audits.

Common B2B mistakes: (1) Missing per-DAL rigor. (2) Missing MC/DC for DAL A. (3) Missing tool qualification per DO-330. (4) Missing MBSE supplements. (5) Missing SOI audits per DAL.

Protective case requirements for avionics software: (1) DO-160G environmental. (2) MIL-STD-810 environmental. (3) MIL-STD-461 EMC. (4) IP rating per mission requirements. (5) Vibration per aircraft + UAV. (6) Shock per DO-160G Cat H. (7) Tamper-evident if classified. (8) Shielding for EMC + TEMPEST.

Common avionics software applications: Flight control (FBW + autopilot + primary flight controls) + engine control (FADEC) + navigation (GPS + inertial + radio) + autopilot (autothrottle + autoland) + communication (VHF + HF + SATCOM) + surveillance (TCAS + transponder + weather radar) + display (PFD + ND + EICAS + FMS) + recorder (FDR + CVR + QAR) + cabin (IFE + lighting + temperature).

UAV / drone avionics software: Autopilot (ArduPilot + PX4 + DJI A3 + N3) + flight control + GPS + camera + communication + mission computer + payload + ground control station.

Commercial aerospace vs military: DO-178C for civil (FAA + EASA). MIL-STD-882E + MIL-STD-498 + MIL-HDBK-454 for military. UAV commercial DO-178C + DAL assignment per ASTM F3196 + FAA Part 107.

B2B procurement workflow integration: (1) DO-178C + (2) DO-254 + (3) DO-160G + (4) SAE ARP 4754A + (5) SAE ARP 4761 + (6) DO-330 + (7) DO-331 + (8) DO-332 + (9) DO-333 + (10) CAST papers + (11) FAA AC + (12) EASA ETSO + (13) Supplier quality + (14) AS9100.

B2B recommendation: For B2B avionics software case, require DO-178C per DAL + DO-330 tool qualification + DO-331 MBSE + DO-332 OOT + DO-333 formal methods + per-DAL verification + structural coverage (MC/DC for DAL A) + traceability + independence + SOI audits + FAA / EASA certification.

Puntos clave

  • DO-178C / ED-12C is FAA / EASA accepted avionics software. 2011 Edition. Replaces DO-178B (1992). DAL A (Catastrophic) to E (No Effect).
  • Per-DAL verification rigor. Structural coverage: C0 (Statement) for DAL C + C1 (Branch) for DAL B + MC/DC for DAL A.
  • Requirements traceability per DO-178C § 6.4.2. Bidirectional between system + HLR + LLR + source code + tests.
  • Independence per DAL. Higher DAL = more independence for verification activities. DAL A typically requires independent verification authority.
  • DO-330 Tool Qualification (5 TQL levels) + DO-331 MBSE + DO-332 OOT + DO-333 Formal Methods. Required supplements per DAL.
  • B2B recommendation: For B2B avionics software case, require DO-178C per DAL + DO-330 + DO-331/332/333 + per-DAL verification + MC/DC for DAL A + traceability + independence + SOI audits + FAA / EASA.

Preguntas frecuentes

q

a

q

a

q

a

q

a

q

a

q

a