AdaCore Technologies for Airborne Software

Supporting certification and tool qualification for DO-178C:ED-12C

About the Authors

Frédéric Pothon

During his professional career dating back to the 1980s, Frédéric Pothon has been a recognized expert in the area of software aspects of certification (most notably DO ‑ 178/ED ‑ 12, Levels A, B, and C). He was a member of the EUROCAE/RTCA group that produced DO ‑ 248B/ED ‑ 94B, which provides supporting information for the DO ‑ 178B/ED ‑ 12B standard. Mr. Pothon has led projects at Turboméca (now Safran Helicopter Engines) and Airbus, where he was responsible for software methodologies and quality engineering processes. He founded the company ACG-Solutions in 2007 and worked as an independent consulting engineer, providing training, audits, and support, and he was involved in several research projects. Mr. Pothon is an expert in the qualification and utilization of automatic code generation tools for model-based development, and he served as co-chair of the Tool Qualification subgroup during the DO ‑ 178C/ED ‑ 12C project.

Quentin Ochem

Quentin Ochem is the Chief Product and Revenue Officer at AdaCore, where he oversees marketing, sales, and product management while steering the company's strategic initiatives. He joined AdaCore in 2005 to work on the company's Integrated Development Environments and cross-language bindings. With an extensive background in software engineering in high-integrity domains such as avionics and defense, he has served leading roles in technical sales, customer training, and product development. Notably, he has conducted training on the Ada language, AdaCore tools, and the DO ‑ 178B/ED ‑ 12B and DO ‑ 178C/ED ‑ 12C software certification standards. In 2021 he stepped into his current role, directing the company's strategic initiatives.

Foreword

The guidance in the DO ‑ 178C/ED ‑ 12C standard and its associated technology-specific supplements helps achieve confidence that airborne software meets its requirements. Certifying that a system complies with this guidance is a challenging task, especially for the verification activities, but appropriate usage of qualified tools and specialized run-time libraries can significantly simplify the effort. This document explains how a number of technologies offered by AdaCore — tools, libraries, and supplemental services — can help. It covers not only the "core" DO ‑ 178C/ED ‑ 12C standard but also the technology supplements: Object-Oriented Technology and Related Techniques DO ‑ 332/ED ‑ 217, and Formal Methods (DO ‑ 333/ED ‑ 216). The content is based on the authors' many years of practical experience with the certification of airborne software, with the Ada and SPARK programming languages, and with the technologies addressed by the DO ‑ 178C/ED ‑ 12C supplements.

We gratefully acknowledge the assistance of Ben Brosgol (AdaCore) for his review of and contributions to the material presented in this document.

Frédéric Pothon, ACG Solutions
Montpellier, France
March 2017
Quentin Ochem, AdaCore
New York, NY
March 2017

Foreword to V2.1

This revised booklet reflects the evolution of and enhancements to AdaCore's products since the earlier edition. Among other updates, the static analysis tools supplementing the GNAT Pro development environment have been integrated into a cohesive toolset (the GNAT Static Analysis Suite). The dynamic analysis tools have likewise been consolidated, and the resulting GNAT Dynamic Analysis Suite has introduced a fuzzing tool — GNATfuzz — which exercises the software with invalid input and checks for failsafe behavior.

I would like to express my appreciation to Olivier Appere (AdaCore) for his detailed and helpful review of the content for the revised booklet.

Ben Brosgol, AdaCore
Bedford, Massachusetts
July 2025