FHA, PSSA and development assurance plans
The safety assessment and planning documents that a system development needs before the design is frozen, produced by our experts with Wingman360 Teammate from your functions, architecture and requirements.
Which rule asks for it
The safety assessment process exists because the airworthiness code requires it: 25.1309 for large aeroplanes, 23.2510 for normal category aeroplanes, and their CS and military equivalents. ARP4761A is the accepted method and ARP4754A the development process it belongs to.
(b) The airplane systems and associated components, evaluated separately and in relation to other systems, must be designed and installed so that they meet all of the following requirements: (1) Each catastrophic failure condition— (i) Must be extremely improbable; and (ii) Must not result from a single failure. (2) Each hazardous failure condition must be extremely remote. (3) Each major failure condition must be remote. (4) Each significant latent failure must be eliminated as far as practical, or, if not practical to eliminate, the latency of the significant latent failure must be minimized. However, the requirements of the previous sentence do not apply if the associated system meets the requirements of paragraphs (b)(1) and (b)(2) of this section, assuming the significant latent failure has occurred. (5) For each catastrophic failure condition that results from two failures, either of which could be latent for more than one flight, the applicant must show that— (i) It is impractical to provide additional fault tolerance; and (ii) Given the occurrence of any single latent failure, the residual average probability of the catastrophic failure condition due to all subsequent active failures is remote; and (iii) The sum of the probabilities of the latent failures that are combined with each active failure does not exceed 1/1000.
What we deliver
- Functional hazard assessment at aircraft or system level: functions, failure conditions, effects, classification, safety objectives, with the hazard log.
- PASA and PSSA: the safety requirements and DAL allocation derived from the FHA, with the fault tree or dependence diagram structure.
- Development assurance plans: the plan for software aspects of certification (PSAC) and the plan for hardware aspects of certification (PHAC), and the system development plan.
- Sources register and citation trail.
How it is produced and checked
Our experts produce the assessment with Wingman360 Teammate on Lavionic's servers from your function list, architecture and requirements. A second expert checks every failure condition classification and every derived requirement. Your design organisation reviews and approves before the document enters the certification programme.
Standards and references
- 14 CFR 25.1309 and 23.2510; CS 25.1309, airworthiness codes
- SAE ARP4754A and ARP4761A, development and safety assessment processes; licensed, referred to, not quoted
- RTCA DO-178C / EUROCAE ED-12C and DO-254 / ED-80, software and hardware assurance; licensed, referred to, not quoted
- AC 25.1309-1B, FAA advisory circular
Questions
- Do you deliver the FHA as a document or as a hazard log?
- Both: the FHA report in your template and the hazard log as a structured table that carries into the PSSA and the compliance matrix.
- Which assurance level conventions do you use?
- ARP4754A development assurance levels A to E, DO-178C software levels and DO-254 hardware design assurance levels, as your certification basis requires.
- Can the assessment be done for a UAS or an eVTOL?
- Yes. The same process applies under SC Light-UAS, SC-VTOL and SORA OSO #5; the failure-condition classification follows the special condition.
- Do you quote ARP4761A text?
- No. SAE and RTCA/EUROCAE documents are licensed; we apply the method and cite the document and section, we do not reproduce their text.
Related
Sources
- 14 CFR Part 25, eCFR, 8 May 2026
- 14 CFR Part 23, eCFR, 8 May 2026