Automated engineering tools are now part of many avionics software programs. Teams use model-based design, code generation, automated testing, requirements management, and workflow systems to move faster and reduce manual effort. In certification projects, however, automation creates an important question: can the certification activity rely on the tool output? 

That is where
DO-330 matters. DO-330 is the DO-178C supplement focused on software tool qualification. It helps teams decide when a tool must be qualified, what level of qualification is needed, and what evidence is required before certification activities can depend on automated tool behavior. 

For organizations using IBM Engineering Lifecycle Management (
ELM), IBM DOORS Next, IBM Engineering Test Management, IBM Engineering Workflow Management, and IBM Rhapsody, the practical challenge is not only understanding DO-330. The larger challenge is keeping tool requirements, verification cases, results, baselines, approvals, problem reports, and impact analysis connected in one auditable lifecycle.

Table of Contents

What Is DO-330?

DO-330, Software Tool Qualification Considerations, defines guidance for qualifying software tools used in airborne software development and verification. It does not replace DO-178C. Instead, it supports DO-178C by explaining how to control risks introduced when tools automate activities that otherwise require human review or verification. 

In simple terms, DO-330 asks: if a tool makes, checks, transforms, or verifies certification-relevant information, what evidence proves that the tool can be trusted for its intended use?

When Is Tool Qualification Needed?

Tool qualification becomes relevant when a project relies on a tool in a way that could affect certification evidence. 

Qualification is usually considered when a tool automates a certification activity that would otherwise be performed manually or when the project uses tool output without independent manual verification. It is also relevant when the tool could introduce an error into airborne software or lifecycle data, fail to detect an error that should be found during verification, or become part of a model-based testing, code generation, or analysis workflow that supports the certification argument.

How Tool Qualification Levels Work

DO-330 uses Tool Qualification Levels, usually referenced as TQL-1 through TQL-5, to scale the qualification effort to the risk. The level depends on the software assurance level of the airborne system and the role the tool plays in creating or verifying certification-relevant outputs. 

A tool that can introduce errors into high-criticality software usually requires a stronger qualification argument than a tool that only supports a lower-risk verification activity with independent review. This is why early classification of tool use is essential. The same commercial tool can have different qualification implications depending on how it is used in the project.

1.) Qualification levels

What Evidence Does a DO-330 Qualification Effort Need?

A qualification effort normally needs objective evidence that the tool performs its intended functions correctly and consistently in the defined project environment. 

The evidence package should begin with Tool Operational Requirements (TOR), which describe what the tool must do in the qualified use case. It should also include a Tool Qualification Plan (TQP) that defines the scope, approach, responsibilities, activities, and evidence expected for the qualification effort. 

The project then needs verification cases, expected results, executed test records, and review evidence that show the tool behaves as intended. To keep the qualification argument stable over time, teams should also control the tool configuration, version, environment, and baseline information, while maintaining problem reports, change impact analysis records, and any usage restrictions or limitations that users must follow.

How IBM ELM Supports DO-330 Governance

IBM Engineering Lifecycle Management can help teams manage the qualification lifecycle as a connected digital thread. Instead of storing qualification artifacts across disconnected spreadsheets, documents, and test folders, teams can link tool requirements, tests, results, approvals, defects, and baselines across the lifecycle. 

IBM DOORS Next can manage Tool Operational Requirements and connect them to verification artifacts. IBM Engineering Test Management can manage qualification test cases, execution records, and results. IBM Engineering Workflow Management can support change control, task ownership, approval workflows, and problem reporting. Together, these tools can help create a structured evidence trail for certification review. 

The key benefit is traceability. When a tool requirement changes, when a qualification test fails, or when a tool version is updated, the team needs to know which evidence is affected. A well-configured IBM ELM environment helps make that impact visible.

2.) DO-330 Lifecycle Showcase

Best match for traceability coverage and checking whether tool requirements are linked to verification artifacts.

Check traceability coverage before certification review.

IBM Rhapsody and Model-Based Qualification Scenarios

IBM Rhapsody is relevant for model-based systems and software engineering, including design, simulation, and verification workflows. In DO-178C programs, model-based development may also involve DO-331 considerations. When Rhapsody-related tooling is used for verification activities, model execution, testing, or code generation, teams must evaluate whether that use creates a DO-330 qualification need. 

IBM provides Rhapsody Kit for DO-178B/C material and TestConductor Add-On Qualification Kit material. These resources are designed to help teams understand and document the qualification approach for Rhapsody-related tooling. They do not automatically certify a project. The applicant still needs to show that the tool is used correctly in the project-specific environment and certification context.

Where Softacus can help

Softacus helps aerospace and safety-critical engineering teams set up IBM ELM so DO-330 tool qualification evidence is easier to manage, trace, and review.

In IBM DOORS Next, Softacus can help structure Tool Operational Requirements, connect them to qualification tests, and keep requirement changes visible through traceability and impact analysis. In IBM Engineering Test Management, this can include organizing qualification test cases, execution records, expected results, actual results, and supporting evidence. In IBM Engineering Workflow Management, Softacus can help define approval flows, change-control steps, baselines, version records, and problem-reporting workflows that support the tool qualification argument.

The goal is not to make a project automatically compliant. No vendor or tool can credibly promise that. The real value is reducing uncertainty before certification review. Softacus helps teams move tool qualification data out of scattered documents, spreadsheets, and disconnected records into a more controlled IBM ELM lifecycle.

This gives teams a clearer view of which tool requirements have been verified, which evidence supports each requirement, which tool version was used, which approvals are still open, and what may be affected when a tool or requirement changes.

Softacus can also help create dashboards and reporting views for qualification status, traceability coverage, open issues, approval progress, baseline readiness, and evidence completeness. For organizations using IBM ELM, IBM Rhapsody, or Rhapsody TestConductor in DO-178C environments, this support can be combined with advisory services and training so engineering, quality, and certification teams work from the same controlled process instead of maintaining separate evidence silos.

Need help setting up IBM ELM for DO-330 tool qualification?
Softacus can help you structure requirements, tests, workflows, baselines, approvals, and reporting views so your qualification evidence stays traceable and easier to review.

Conclusion

DO-330 tool qualification is not only a documentation exercise. It is a lifecycle governance problem. Teams need to know what the tool is used for, what risk it introduces, what evidence supports its use, and how changes affect the qualification record. 

IBM ELM can support that work by connecting requirements, verification, workflow, baselines, and reporting into a traceable engineering lifecycle. For aerospace and other regulated teams, this makes the qualification argument easier to manage and easier to explain. Primary CTA: Talk to Softacus about IBM ELM for DO-330 tool qualification. Secondary CTA: Download the DO-330 Tool Qualification Checklist for IBM ELM projects.

Frequently asked questions

DO-330 is the DO-178C supplement that provides guidance for qualifying software tools used in airborne software development and verification.

Sign up to our newsletter

Please fill the required field.

Our Services

Our Extensions

Latest blog articles

Contact Us!

Softacus Services

Check out services!

We, in Softacus, are experts when it comes to consulting and service delivery of IBM software products and solutions in your business. We help our clients to improve visibility and transparency when licensing and managing commercial software, providing measurable value while increasing efficiency and accountability and we are providing services in different areas (see Softacus Services).
IBM ELM extensions developed by Softacus are free of charge for the customers who ordered IBM ELM licenses via Softacus or for the customers who ordered any of our services. If you are interested in any of our IBM ELM extensions, you found a bug or you have any enhancement request, please let us know at info@softacus.com.

Related Articles