DO-160 environmental testing: the bench evidence behind qualification
By Alex Hernandez · · 12 min read


DO-160 testing exposes airborne equipment to standard environmental conditions, from temperature and vibration to power transients and lightning, and checks that it keeps working. The chamber or test lab supplies the environment. The functional checks run before, during and after each exposure supply the proof that the equipment performed, and a qualification package rests on their record.
This essay draws on two public primary sources, RTCA's DO-160 page and the FAA's Advisory Circular 21-16G, whose appendix summarizes what changed between versions. Test levels and full procedures are in the standard itself, sold through RTCA's authorized reseller.
What is DO-160 testing?
RTCA's description: "The original DO-160 standard was published in 1975 to provide standard test methods which would ensure new aviation equipment would function appropriately in the multiple environmental and EMI conditions found on aircraft." Its title is Environmental Conditions and Test Procedures for Airborne Equipment, and Special Committee 135 maintains it.
AC 21-16G, issued June 22, 2011 and listed as active by the FAA, says DO-160 "defines standard environmental test conditions (categories) and applicable test procedures for airborne equipment." It recognizes versions D through G, the last dated December 8, 2010, "as containing acceptable environmental qualifications to show compliance with certain airworthiness requirements," and "strongly encourages the use of RTCA/DO-160G for new articles." Three points in the AC shape a test program:
- It demonstrates performance, not life. The tests are "a laboratory means of demonstrating the performance characteristics of airborne equipment in environmental conditions that may be encountered in operation," not a measure of service life.
- The AC is guidance, not a mandate. It "is not mandatory" and describes "a means, but not the only means," of compliance. Where a Technical Standard Order names a DO-160 version, using another one means requesting a deviation under 14 CFR part 21 subpart O.
- The applicant decides what applies. Its installer guidance notes that waterproofness, sand and dust, or salt fog may not apply given where the equipment sits: "You must determine which sections and categories are applicable to your specific project."
Which revision? RTCA's page, read October 5, 2026, still names DO-160G as current, alongside Change 1 and DO-357, a user guide supplement RTCA describes as "not required" but helpful. The same page says "A revision, DO-160H, is planned for publication in March of 2026." Confirm which revision your TSO, certification basis and test lab cite before writing a functional check, and put it in every run record.
What do the DO-160 sections and categories cover?
Sections 1 to 3 cover purpose, definitions and conditions of tests. Sections 4 to 26 are the tests, and Appendix A covers how the tested categories are declared. Names follow AC 21-16G; the group column is editorial, not part of the standard.
| Section | Test | Group |
|---|---|---|
| 4 | Temperature and altitude | Climatic |
| 5 | Temperature variation | Climatic |
| 6 | Humidity | Climatic |
| 7 | Operational shocks and crash safety | Mechanical |
| 8 | Vibration | Mechanical |
| 9 | Explosion proofness | Atmosphere |
| 10 | Waterproofness | Contaminants |
| 11 | Fluids susceptibility | Contaminants |
| 12 | Sand and dust | Contaminants |
| 13 | Fungus resistance | Contaminants |
| 14 | Salt fog | Contaminants |
| 15 | Magnetic effect | Electromagnetic |
| 16 | Power input | Power |
| 17 | Voltage spike | Power |
| 18 | Audio frequency conducted susceptibility, power inputs | Power |
| 19 | Induced signal susceptibility | Electromagnetic |
| 20 | Radio frequency susceptibility (radiated and conducted) | Electromagnetic |
| 21 | Emission of radio frequency energy | Electromagnetic |
| 22 | Lightning induced transient susceptibility | Lightning |
| 23 | Lightning direct effects | Lightning |
| 24 | Icing | Climatic |
| 25 | Electrostatic discharge | Electromagnetic |
| 26 | Fire, flammability | Fire |
Within a section, categories set the severity for a type of installation. Section 7 has categories for fixed-wing and helicopter installations. Section 14 gained category T in DO-160E for severe salt atmospheres. Near GPS antennas, the FAA recommends section 21 category P in DO-160F, or P or Q in DO-160G, to reduce RF noise in the GPS band.
The chosen categories go on the Environmental Qualification Form, which "provides information regarding which version of DO-160 was used, which environmental tests were conducted and the environmental category of the equipment being tested." DO-160G stopped using nameplate marking to declare the category.
Some sections have cousins on an ordinary bench. Section 21 is the kind of measurement an EMC pre-compliance setup rehearses before a lab visit, and section 16 is the aircraft counterpart to the electrical-load testing automotive electronics get under ISO 16750-2.
What functional checks run before, during and after DO-160 exposure?
DO-160 specifies the environment and how to apply it. What counts as performing comes from the equipment's own specification, and the procedures defer to it with phrases such as "unless otherwise stated in the EUT specification." The bench side of a DO-160 program is a set of functional checks written from that specification and run at fixed points around each exposure.
Before exposure: a baseline on the same unit
Run the full performance test at ambient, on the unit going into the chamber, in its test configuration, with the sequence revision that will run during and after. The baseline shows the unit worked before the environment touched it, so a later failure is attributable to the exposure. It gives drift a reference: a reading inside its limit but well off its own baseline deserves a question. And it proves out the harnesses, loads, instruments and test software.
Record the unit's identity in full: part number, serial, modification status, software and firmware versions, configuration. Per the FAA's change summary, DO-160E clarified the use of multiple test articles, so the record must say which serial saw which exposure. DO-160G requires "operation of equipment in its most susceptible mode for all environmental tests, not just susceptibility tests," and clarifies the use of special-purpose software to put it there. Record that mode and the software version that set it.
During exposure: operating checks where the procedure calls for them
Some procedures require the equipment to operate inside the environment and say when performance counts. From the AC's summary of changes:
- Temperature variation (section 5). DO-160F moved "the performance compliance timing to be in the second, or last cycle." Compliance is judged in that cycle, so readings need timestamps that line up with the chamber profile.
- Operational shock (section 7). DO-160G: "Unless otherwise stated in the EUT specification, the equipment shall be operating, and its temperature stabilized," during three 6 g sawtooth shocks in each orientation.
- Vibration (section 8). DO-160F has "equipment not operating during sinusoidal scans and operating during the robust test portion," unless the equipment specification says otherwise, and cut performance test times "from 30 minutes to a minimum of 10 minutes."
- Power input (section 16). In DO-160F, a manual reset "was explicitly not permitted after single and double power interrupts." The check must show the unit recovered on its own, logged from before the interrupt through recovery.
- Fluids susceptibility (section 11). DO-160G sprays for 8 hours and dries for 16, three times. The unit operates while wet at the end of the third spray segment, and for at least 30 minutes, or until stabilized, at the end of each drying period.
A during-exposure check can be a subset of the baseline: the outputs most likely to move, sampled often enough to catch an interruption, tagged with the profile phase. The tag matters as much as the value. A clean reading from the first temperature cycle proves nothing about the second.
After exposure: the same checks, compared with the baseline
Other procedures judge the equipment afterward. DO-160D removed a waterproofness step that looked for water inside the unit, because "the test is intended to verify performance of unit following exposure to this environment, not to verify the unit's ability to keep out water." Salt fog has allowed the functional test after a 48-hour dry-out since DO-160D, though DO-160G suppresses drying before power-up for category T. The fungus procedure dropped a 48-hour wait before the performance test.
Run the baseline's sequence revision on the same serial and compare value with value, not only verdict with verdict. A reading that passes but has moved is something to explain before the package goes out, not after a reviewer finds it.
| Checkpoint | Purpose | Minimum record |
|---|---|---|
| Before | Baseline; proves unit and setup | Full sequence, unit identity, configuration and mode, instrument identities |
| During | Performance where the procedure names it | Readings timed against the chamber profile, phase tag, interruptions and recovery |
| After | Performance after exposure; drift | Baseline's sequence revision, value-by-value comparison, deviations and disposition |
Why does traceable bench evidence matter for qualification?
A qualification package has two halves. The lab's report documents the environment: profile, levels, durations, the lab's equipment. The functional record documents how the equipment responded. The EQF compresses both into a version, a list of tests and a category for each. When a reviewer, an installer or your own team asks a question the summary cannot answer, the answer is in the functional record or nowhere.
AC 21-16G describes three situations that lean on that record:
- Installers compare the EQF to their installation. If the categories fall short, "you or the equipment manufacturer may need to re-qualify the equipment to meet the appropriate sections and category levels." A re-test compares with the original only if the original checks are known exactly: sequence, limits, mode.
- Similarity. An applicant may ask to reuse an approved article's environmental test data for a new one, but the request "must be fully supported with a detailed similarity assessment." That argument starts from what was measured, not from a table of pass marks.
- Version comparisons. Using a version older than D where the TSO names D or later means comparing "the specific procedure and category changes, section by section," and addressing "the differences between the two test results." That needs results with their conditions.
Then the obvious case: a unit fails mid-profile, is investigated, modified and retested. The record must show what failed, at which point in the profile, what changed on the unit, and that the retest ran the same checks. Keep every run, including failures.
The weak links are on the bench, not in the chamber: a check run from a script edited the night before, readings typed into a spreadsheet afterward, a meter whose serial nobody wrote down, timestamps that cannot be aligned with the chamber log. Hardware test traceability walks that chain link by link, and the DVT test report template lists the fields a reviewer checks in the report built on it.
What should a DO-160 functional test record include?
Per run: DO-160 revision, section, category and profile phase; checkpoint (before, during or after); unit part number, serial, modification status, software and firmware versions, configuration and test mode; sequence revision and its approver; operator, station, lab or chamber reference, and start and end times in UTC.
Per step: the command sent and raw response; the measured value, unit, limits, comparison and verdict; the instrument's model, serial and firmware, so calibration status can be checked against your calibration records; and a timestamp on the chamber log's clock or with a recorded offset.
An illustrative step record, the unit's 5 V output in the second temperature variation cycle:
{
"run_id": "run-0412",
"do160": { "revision": "G", "section": 5, "checkpoint": "during", "cycle": 2 },
"dut_serial": "SN-0142",
"dut_config": { "part": "PSU-28-5", "mod": "B", "firmware": "2.3.1", "mode": "full load" },
"sequence": { "name": "functional-check", "revision": 7, "commit": "4be19d0", "approved_by": "a.reviewer" },
"step": "5V0 output under full load",
"instrument": { "model": "34461A", "serial": "MY54505555", "firmware": "A.03.01" },
"command": "MEAS:VOLT:DC?",
"raw_response": "+5.01234000E+00",
"value": 5.01234,
"unit": "V",
"limits": { "low": 4.9, "high": 5.1, "comparison": "GELE" },
"verdict": "pass",
"operator": "j.doe",
"timestamp": "2026-10-05T14:32:07.412Z"
}Nothing in it is exotic. What makes it evidence is that the test executor writes it as the step runs, against an approved sequence revision, rather than a person assembling it from notes after the chamber run.
How does Galois record DO-160 functional checks?
Galois is agent-driven test engineering for hardware teams: agents generate tests and instrument drivers, run them on real benches through the open-source galois-edge daemon, and turn the results into reports and a shared engineering record.
On a DO-160 program, Galois is the record of the functional checks, not of the qualification. The lab runs the environment and writes its report, the applicant assembles the package, and the certification authority decides. Bench evidence supports that decision; it does not make it. The platform holds the bench half, captured as each step runs:
- Approved sequences. Functional checks are versioned sequences with explicit limits. A draft cannot run until an engineer approves it, and an edited sequence must be approved again, which keeps the before, during and after checks on one approved version.
- A per-step run record. Measured value, limits, raw command and response, instrument ID, operator, DUT serial and timestamp, written by the platform as the step runs.
- Reports from the record. Reports are drafted from live run data, so a reported number traces to a command and a response. Packaged sign-off deliverables are in build (product).
- An audit log of every action with actor, timestamp and resource (security).
The galois-edge daemon drives GPIB, USBTMC, LAN, serial, Modbus and CAN instruments, plus devices with vendor SDKs. Galois ships 573 instrument profiles across 135 manufacturers in its instrument library, including bench multimeters, programmable AC sources and temperature scanners. For a chamber controller or unit interface without a profile, Évariste, the agent in the Galois platform, drafts one from its programming manual for an engineer to review.
Évariste can also draft the functional checks. The approval gate treats its drafts like anyone's, and the checklist for reviewing a generated test plan applies to both.
For the unit in the record above, open Évariste beside the project and state the objective with limits taken from the EUT specification: measure the 5 V output under full load on the 34461A, passing from 4.9 to 5.1 V, with the unit in the mode it will run in the chamber. Évariste drafts the sequence; an engineer reviews and edits it, then approves and production-locks that version for the before, during and after runs. Start each run with the unit's serial; galois-edge executes it on the bench, and Monitor shows the channels live during exposure. Commands sent individually from the conversation, such as enabling a supply output, ask for confirmation when the profile flags them as dangerous. After exposure, ask Évariste to compare the after run with the baseline and find steps that passed close to a limit, then "Generate a test report from the last run"; name the locked version and its approver in the report, as the per-run record above requires. The team maintains no driver class, logging loop or comparison script. Connecting the unit, running the chamber profile, safety and the disposition of any deviation stay with the engineers.
Programs whose test data must stay on site can run the platform as a dedicated single-tenant cloud or fully on-prem and air-gapped (deployment options).
When is the lab's own record enough?
A separate bench record is not always worth the setup. The lab's report can carry the package when:
- The lab runs the functional checks with its own automation and reports the raw readings, procedure revision and instrument identities.
- The check is a go/no-go a technician observes, with no values to compare against a baseline.
- The item is qualified once, will not change, and no similarity or re-qualification argument is planned.
- Your organization already keeps test records in a system that meets its quality requirements. There, the job is feeding it complete records.
For equipment that will be modified, re-qualified or installed in more than one aircraft type, the functional record is the part of the package your team keeps answering questions from. Plan it before the first chamber slot, alongside the rest of design verification; EVT, DVT and PVT testing covers where that falls.
Frequently asked questions
- What is RTCA DO-160?
- DO-160, Environmental Conditions and Test Procedures for Airborne Equipment, is RTCA's standard set of environmental test conditions (categories) and test procedures for airborne equipment. RTCA lists DO-160G, published in 2010, as the current version. FAA Advisory Circular 21-16G recognizes versions D through G as acceptable environmental qualification and recommends G for new articles.
- Is DO-160 testing mandatory?
- Not by itself. The FAA's guidance on it, AC 21-16G, is not mandatory and describes a means, not the only means, of complying with airworthiness requirements. Where a Technical Standard Order names a DO-160 version, using a different version takes a deviation under 14 CFR part 21 subpart O. Where a TSO does not specify environmental qualification, the applicant may choose an appropriate standard, and the FAA recommends DO-160G.
- What is a DO-160 category?
- A category is a severity level within a test section, chosen to match where and how the equipment is installed. Not every section applies to every product: AC 21-16G notes that waterproofness, sand and dust or salt fog may not apply, depending on where the equipment is located. The categories tested are declared on the Environmental Qualification Form.
- What is an Environmental Qualification Form (EQF)?
- It is the summary the equipment manufacturer provides that states which version of DO-160 was used, which environmental tests were conducted and the category the equipment was tested to. Installers compare it against their installation. If the categories do not cover it, the equipment may need to be re-qualified to the relevant sections and categories.
- Does passing DO-160 tests certify equipment?
- No. The tests are a laboratory means of demonstrating performance in environmental conditions the equipment may meet in operation. The results support a showing of compliance that the certification authority accepts or rejects. AC 21-16G also states that DO-160 is not intended as a measure of the equipment's service life.
Bring Galois to your bench.
The daemon is Apache-2.0, free forever. Enterprise runs in your cloud or on-prem.