A Layperson's Guide to DO-326A/ED-202A. Part 1 of 10. A Coracademy Insights weekly series.
Jargon Buster
Dotted terms carry explainers, hover or tap to read them.

What this series is

DO-326A/ED-202A is the standard that governs how aircraft are protected from unauthorised electronic interaction, meaning any deliberate interference with the aircraft's systems by someone with no business touching them, whether or not they intend harm. If you design, modify or certify aircraft systems, it is part of your world whether you have read it or not, and most people have not, because standards documents are written for compliance rather than for reading.

One naming note before we start. The standard's most recent revision is DO-326B, and everything in this series applies to it. We use the DO-326A name throughout because it's still the name most of the industry reaches for.

We teach the full framework as a two-day course made up of nine sessions. Over the coming weeks we will be going through each session, for free, one post at a time, starting with this introduction. Each post takes one important idea from its session and explains it properly. If you would rather have the terminology than the translation, there is a switch at the top of every post that swaps this article for a version written in the language of the standard itself.

Why does this standard exist?

For as long as aircraft have been certified, the safety rules were built around one assumption. Things fail by accident. Components wear out, software has bugs, lightning strikes. The certification system that grew from that assumption is among the most successful safety regimes ever built, and it was designed from top to bottom to catch random failure.

An attacker is a different kind of problem. An attacker picks the weakest point, at the worst possible time, on purpose. As aircraft became connected machines that send maintenance data to the ground, receive software updates and carry passenger wi-fi, deliberate interference became possible in a way the accident-based rules were never designed to catch.

Regulators decided against waiting for the first cyber-caused accident. DO-326A is the result. It sets out a required process for finding the ways into an aircraft's systems, working out what an attacker could do through each one, and proving to the authority that enough protection is in place. It became the recognised route to compliance in the United States and Europe in 2019, and the UK carried the same position across after leaving the European system. The UK's military aviation world moved even earlier, writing the framework into its aircraft design requirements back in 2015, and its regulator formalised the position for airworthiness in 2023. Aviation's cyber safety record remains perfect, and this standard is a large part of the reason. Its job is to keep things that way. Our plain-English guide to DO-326A covers the standard's history and its companion documents in more depth.

Does it apply to you?

You design new aircraft systems. Yes. Cyber security is now a standard part of getting a modern aircraft or system certified in Europe, the UK and the US. Without security evidence there is no approval.

You modify existing aircraft. Yes, and this is the group most often taken by surprise. Changing or adding equipment on an aircraft that already flies triggers the same security questions. What has this change connected, and what does that connection make possible? Far more organisations modify aircraft than design them, which is why modifications get a whole post of their own later in this series.

You operate or upgrade older aircraft. Increasingly, yes. An aircraft certified before these requirements existed was approved against the rules of its day, and predating the rules is not a compliance failure. The point of change is where the new questions arrive. Because any change to an in-service aircraft has to be assessed under today's rules, modifications that involve connectivity now invoke the cyber requirements. A large part of the flying fleet will meet this standard for the first time through an upgrade rather than a new design, and on the UK military side the regulator's cyber requirements already reach aircraft that are in service now.

You supply parts or software to any of the above. Very likely yes, indirectly. Your customer cannot complete their security case without evidence about what they bought from you, which makes your cyber competency part of what they are buying. Suppliers who can answer these questions well become easier to choose and easier to keep, and the questions are arriving in contracts now, if they have not already.

You manage or assure any of the above. Yes. You will never write the security documents yourself, but your programme has to deliver them, and programmes that discover this late pay significantly for the discovery in redesign and delay.

Get the next session in your inbox

One post a week, for the length of the series. Nothing else.

What ignoring it costs

Nothing, for a while, and that is the trap. When the cost does arrive, it tends to arrive in three forms.

Aircraft safety. This framework exists to protect what matters most, the safety of the aircraft, the people who fly in it and the people it flies over. Every shortcut taken against the standard is a small erosion of the protection that has kept aviation's cyber safety record perfect.

Financial. Programmes that discover the requirements late pay significantly for the discovery. Late redesign, certification delay and retrofitting evidence onto a finished design are the most expensive ways to do any of this, and every month spent arguing with an authority is a month the product is earning nothing.

Reputation. Relationships with the authority and customers are built over years. Demonstrating competence in this area, to your regulator and to the people who buy from you, is one of the surest ways to build the kind of trust that makes every future approval and every future contract go more smoothly.

The obligation also continues after the aircraft is certified. Protection has to be maintained for as long as the aircraft is in service, through the same kind of ongoing care that keeps any aircraft airworthy. We cover that side of the framework near the end of this series.

In this series

  1. Why DO-326A exists, and whether it applies to you (this post)

Parts 2 to 10 follow weekly, one course session at a time.

What this series is

DO-326A/ED-202A is the AMCAcceptable Means of Compliance. A method the regulator has formally recognised as satisfying a rule. DO-326A is the RTCA publication, used in the US ecosystem and cited by the UK MAA. ED-202A is the technically identical EUROCAE twin, cited by EASA through AMC 20-42. In practice the two are written as a pair. for airworthiness security across EASAEuropean Union Aviation Safety Agency. The EU's civil aviation regulator., the UK CAA and, in effect, the FAA. If your programme touches type certification or the modification of connected aircraft systems, it sits inside your certification basis whether or not anyone on the team has read it. The standard now sits at revision DO-326B/ED-202B. This series keeps the better-known DO-326A name, and everything in it applies to the current revision.

We deliver the framework as a two-day course of nine sessions. Over the coming weeks we will be going through each session, for free, one post at a time, starting with this introduction. Each post takes a single load-bearing concept from its session and keeps the standard's terminology throughout. The switch above swaps to plain English.

Why does this standard exist?

The certification stack that came before it, DO-178CSoftware Considerations in Airborne Systems and Equipment Certification. The development assurance standard for airborne software. for software and ARP4754AGuidelines for Development of Civil Aircraft and Systems. The system-level development process that DO-178C hangs off. at system level, was built on a random-failure model. Failure conditions are identified, classified by severity, and design assurance is applied in proportion. The model is probabilistic, and it has been extraordinarily successful.

An adversary breaks the model's core assumption. Attacks are directed, correlated and adaptive, which means an attacker selects the path of least resistance and can defeat redundancy that random failure never would. Growing connectivity through datalinks, field-loadable software, maintenance interfaces and passenger networks made IUEIIntentional Unauthorised Electronic Interaction. The standard's defined term for a deliberate electronic act with the potential to affect the aircraft. The definition, its principles and examples are the subject of the next post in this series. a credible contributor to failure conditions, and the safety process had no mechanism for seeing it.

DO-326A closes that gap with a security process that runs alongside the safety process. The applicant establishes the security scope, performs the SRASecurity Risk Assessment. The structured assessment of threat conditions, threat scenarios, security measures and level of threat, covered across the middle of this series., decides risk acceptability, develops and verifies the security measures, and communicates the evidence for certification. It became the recognised means of compliance for cyber airworthiness in the US and Europe in 2019. The UK CAA carried the same position across on leaving the EASA system. The MAAMilitary Aviation Authority. The UK's military airworthiness regulator. moved earlier still, bringing the framework into Def Stan 00-970 in late 2015/early 2016, before formalising the airworthiness security position through RA 5890Regulatory Article 5890, Cyber Security for Airworthiness and Air Safety. Published in 2023, it recognises DO-326A/ED-202A and DO-356A/ED-203A as the acceptable means of compliance for UK military air systems.. Our DO-326A guide covers the document history and the wider family.

Does it apply to you?

Type certificate applicants and design organisations. Yes. EASA embeds airworthiness security in the certification specifications for large and normal-category aeroplanes, rotorcraft, engines and propellers, with AMC 20-42AMC 20-42. EASA's general AMC on airworthiness security, which points at DO-326A/ED-202A and its companion documents as the method. naming this framework as the method. The UK CAA mirrors that position, and the FAA treats the framework as an effective requirement for new and changed type designs.

Modifiers and STCSupplemental Type Certificate. The approval route for modifying an already-certified aircraft type. holders. Yes, and most often caught unprepared. A modification re-opens the security questions for everything it touches, from changed interconnectivity to installed or replaced equipment and the knock-on impact on the existing security case. The standard defines a dedicated pathway for modifications, which we cover later in this series.

In-service and legacy platforms. An aircraft certified before these requirements existed was approved against the rules of its day, and predating the requirements is not a finding. The point of change is what brings a legacy platform into scope. Because any change to an in-service aircraft is assessed against the current certification basis, modifications that touch connectivity now invoke the airworthiness security requirements. On the military side, RA 5890 applies to UK military air systems in service as well as in development. A large part of the flying fleet will meet this framework for the first time through its next upgrade rather than through a new design.

Suppliers. Indirectly but unavoidably. Your customer's assessment and assurance case depend on evidence about your item, from its interfaces to its development assurance and its security-relevant behaviour. That makes demonstrable airworthiness security competency part of what your customer is buying, and expect flow-down requirements in contracts to reflect it.

Programme, quality and safety roles. Yes. You will never author the artefact set yourself, but your programme has to deliver it, and programmes that discover this framework late pay significantly for the discovery in redesign and delay.

Get the next session in your inbox

One post a week, for the length of the series. Nothing else.

What ignoring it costs

The failure mode is always the same. Security gets treated as a document-writing exercise at the end of the programme, and the cost of that arrives in three forms.

Aircraft safety. The framework exists to protect what matters most, the aircraft, its occupants and the people it flies over. A security risk assessment performed as paperwork rather than analysis erodes exactly the protection the certification basis assumes is there.

Financial. The evidence the authority expects is the trail of a risk-management process that ran during development, with the scope agreed early, the assessment informing the design and the measures verified as they were built. Reconstructing that trail after design freeze means significant cost in late redesign and certification delay, and in the worst case an approval that stalls due to a lack of evidence.

Reputation. Relationships with the authority and with customers are built over years of programmes and bids. Demonstrated airworthiness security competence builds credibility with both, and credibility is what makes scrutiny quicker, findings rarer and the next selection easier.

Nor does the process end at certification. The security case has to be maintained while the aircraft is in service, through continuing airworthiness security activity that we cover near the end of this series.

In this series

  1. Why DO-326A exists, and whether it applies to you (this post)

Parts 2 to 10 follow weekly, one course session at a time.