Safeguard
Industry Analysis

Aviation Software Security: Why DO-326A Certification Looks Nothing Like Conventional Patching

Certified avionics software operates under airworthiness rules that treat any change as a potential re-certification event — a fundamentally different risk model than continuous patching.

Safeguard Research Team
4 min read

Aviation software security operates under a constraint almost no other industry shares: the software running on an aircraft — flight management systems, avionics, increasingly connected cabin and maintenance systems — is subject to airworthiness certification requirements that treat security as inseparable from safety, formalized specifically through standards like DO-326A and its European counterpart ED-202A, which require aircraft systems to demonstrate resilience against intentional unauthorized electronic interaction as part of the certification process itself.

Why aviation security certification looks nothing like conventional software security practice

Most software security guidance assumes a continuous patching and update cycle: find a vulnerability, ship a fix, deploy it. Certified aviation software operates under the opposite assumption by design — any change to certified avionics software potentially requires re-certification, a process that can take substantially longer than a typical software patch cycle and involves regulatory bodies (the FAA in the United States, EASA in Europe) rather than a vendor's internal release process alone. That means the aviation sector's security posture depends far more heavily on getting the design right before certification than on rapid post-deployment patching — a fundamentally different risk model than almost any other software category, including other safety-critical industrial sectors that at least retain the ability to patch operational technology on a shorter cycle than aircraft certification allows.

The expanding connectivity surface certification frameworks are still catching up to

Modern aircraft increasingly carry connected systems well beyond the certified flight-critical avionics: in-flight entertainment and connectivity systems, electronic flight bags, maintenance data links, and ground-based systems that exchange data with the aircraft during turnaround. These systems don't always carry the same certification burden as flight-critical avionics specifically because they're architected — at least in intent — to be isolated from flight-critical systems, but the isolation itself is precisely what security assessments under frameworks like DO-326A/ED-202A are meant to verify rather than assume, given how much value connectivity has added to airline operations and how much incentive exists to expand it further.

What to look for in a security approach for this sector

Software supply chain visibility that extends to ground-based and maintenance systems, not only flight-critical avionics. The certified avionics stack is only part of the aviation software attack surface; ground operations, maintenance data systems, and airline back-office systems that interact with aircraft data carry real risk of their own and are rarely subject to the same certification rigor.

Documented evidence of the isolation between flight-critical and non-flight-critical connected systems, given that this boundary — not any single system's own hardening — is what airworthiness security assessments are increasingly designed to verify, and what an operator should be able to demonstrate rather than merely assert.

Vendor and supplier software provenance for avionics and connected cabin systems alike, since aircraft systems integrate software from a deep, multi-tier supplier base, and a certification process focused on the integrated system's behavior doesn't automatically substitute for visibility into every supplier's own development and update practices.

Long-lifecycle software management practices, recognizing that aircraft remain in service for decades and the software running on them is patched and updated on a fundamentally slower cycle than almost any other industry — making accurate, current inventory of what's actually deployed across an aging fleet a persistent rather than one-time exercise.

Why airline back-office systems deserve as much attention as onboard systems

Much of the software an airline actually operates day to day — crew scheduling, maintenance tracking, reservations, and ground operations coordination — sits entirely outside the certified avionics boundary, yet a compromise or outage in any of these systems can ground flights just as effectively as a technical fault in the aircraft itself, as several widely reported airline IT outages over the years have demonstrated at a scale that dwarfed the operational impact of any single aircraft-level incident. Certification-focused security attention on avionics can inadvertently leave these equally consequential back-office systems comparatively under-scrutinized.

A note on the supplier certification chain

Aircraft OEMs certify the integrated system, but individual suppliers producing avionics subcomponents carry their own security obligations up that chain — worth verifying independently rather than assuming the prime contractor's certification alone accounts for every supplier's practices.

How Safeguard helps

Safeguard's continuous inventory and software supply chain visibility extend to the ground-based, maintenance, and connected systems surrounding certified avionics, giving aviation operators and their suppliers the documented software provenance picture that complements — without replacing — the certification-driven assurance already required of flight-critical systems themselves.

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.