CEN/TS 16501:2013
(Main)Air Traffic Management - Specification for software assurance levels
General Information
- Abstract
This Technical Specification specifies the technical, operational and maintenance requirements for Software Assurance Levels to support the demonstration of compliance with some elements of the Essential Requirements Safety and Principles governing the construction of systems of the Regulation (EC 552/2004) of the European Parliament and of the Council on the interoperability of the European Air Traffic network (the Interoperability regulation).
This Technical Specification on Software Assurance Levels (SWAL) is intended to apply to software that is part of the EATMN, focusing only on its ground segment and providing a reference against which stakeholders can assess their own practices for software specification, design, development, operation, maintenance, evolution and decommissioning.
Requirements in the present document which refer to should statements or recommendations in the normatively referenced material are to be interpreted as fully normative (shall) for the purpose of compliance with the present document.
- Status
- Published
- Publication Date
- 09-Apr-2013
- Technical Committee
- CEN/TC 377 - Project Committee - Air Traffic Management
- Drafting Committee
- CEN/TC 377 - Project Committee - Air Traffic Management
- Current Stage
- 6060 - Definitive text made available (DAV) - Publishing
- Start Date
- 10-Apr-2013
- Due Date
- 11-May-2014
- Completion Date
- 10-Apr-2013
Overview
CEN/TS 16501:2013 - "Air Traffic Management - Specification for software assurance levels" - defines technical, operational and maintenance requirements for Software Assurance Levels (SWAL) applied to software in the European Air Traffic Management Network (EATMN). Focused on the EATMN ground segment, the Technical Specification supports demonstration of compliance with the Essential Requirements (“Safety” and “Principles governing the construction of systems”) of Regulation (EC) 552/2004 (the Interoperability Regulation) and the Single European Sky framework.
Key topics and requirements
- SWAL allocation and grading: Allocation of an appropriate SWAL must follow the methodology in EUROCAE ED‑153, including the grading policy and independence expectations.
- Likelihood assessment & justification: Assessment of the likelihood of effects and the rationale for that assessment are performed per ED‑153 guidance.
- Life‑cycle process objectives: SWAL objectives are specified for primary life‑cycle processes:
- Acquisition, Supply, Development, Operation, Maintenance
- Supporting processes: Documentation, Configuration Management, Quality Assurance, Verification, Joint Review, Audit, Problem/Change Resolution
- Organisational processes: Management, Infrastructure, Improvement, Training
- COTS handling: Specific processes for Commercial Off The Shelf (COTS) software: planning, acquisition, verification, and configuration management (ED‑153, Clause 7).
- Independence and assurance evidence: For certain objectives, independence in performing or checking prevention/verification is required - primarily for higher assurance levels (noted for SWAL 1 and 2).
- Configuration management: For highest-assurance SWAL (SWAL 1), software configuration management is required at the executable level.
- Normative effect of referenced guidance: “Should” recommendations in normatively referenced material (e.g., ED‑153) are to be interpreted as “shall” for compliance with CEN/TS 16501.
Practical applications and users
Who uses this standard:
- Air Navigation Service (ANS) providers and operators
- System integrators, software developers and suppliers for ATM ground systems
- Maintainers, verification and quality assurance teams
- Procurement teams assessing COTS suitability
- Regulatory compliance and safety assessment bodies
Practical uses:
- Assigning and justifying SWAL to software components in ATM ground systems
- Structuring development, verification and maintenance activities to meet regulatory safety principles
- Preparing assurance evidence for interoperability and safety compliance under EC 552/2004
- Performing gap analysis against other assurance frameworks (ED‑109, EN 61508 referenced in bibliography)
Related standards and guidance
- EUROCAE ED‑153 (Guidelines for ANS software safety assurance) - normative reference for allocation, objectives and processes
- ED‑109, EN 61508 and EU Regulations cited in the bibliography for complementary guidance and regulatory context
For implementation, consult CEN/TS 16501 together with ED‑153 to map SWAL objectives onto your project lifecycle, evidence collection and audit strategy.
Relations
- Effective Date
- 28-Jan-2026
- Effective Date
- 28-Jan-2026
- Effective Date
- 28-Jan-2026
Get Certified
Connect with accredited certification bodies for this standard

BSI Group
BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

NYCE
Mexican standards and certification body.
Sponsored listings
Frequently Asked Questions
CEN/TS 16501:2013 is a technical specification published by the European Committee for Standardization (CEN). Its full title is "Air Traffic Management - Specification for software assurance levels". This standard covers: This Technical Specification specifies the technical, operational and maintenance requirements for Software Assurance Levels to support the demonstration of compliance with some elements of the Essential Requirements Safety and Principles governing the construction of systems of the Regulation (EC 552/2004) of the European Parliament and of the Council on the interoperability of the European Air Traffic network (the Interoperability regulation). This Technical Specification on Software Assurance Levels (SWAL) is intended to apply to software that is part of the EATMN, focusing only on its ground segment and providing a reference against which stakeholders can assess their own practices for software specification, design, development, operation, maintenance, evolution and decommissioning. Requirements in the present document which refer to should statements or recommendations in the normatively referenced material are to be interpreted as fully normative (shall) for the purpose of compliance with the present document.
This Technical Specification specifies the technical, operational and maintenance requirements for Software Assurance Levels to support the demonstration of compliance with some elements of the Essential Requirements Safety and Principles governing the construction of systems of the Regulation (EC 552/2004) of the European Parliament and of the Council on the interoperability of the European Air Traffic network (the Interoperability regulation). This Technical Specification on Software Assurance Levels (SWAL) is intended to apply to software that is part of the EATMN, focusing only on its ground segment and providing a reference against which stakeholders can assess their own practices for software specification, design, development, operation, maintenance, evolution and decommissioning. Requirements in the present document which refer to should statements or recommendations in the normatively referenced material are to be interpreted as fully normative (shall) for the purpose of compliance with the present document.
CEN/TS 16501:2013 is classified under the following ICS (International Classification for Standards) categories: 35.240.60 - IT applications in transport. The ICS classification helps identify the subject area and facilitates finding related standards.
CEN/TS 16501:2013 has the following relationships with other standards: It is inter standard links to EN ISO 19901-6:2009, EN ISO 19904-1:2006, EN ISO 19906:2010. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.
CEN/TS 16501:2013 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
SLOVENSKI STANDARD
01-julij-2013
8SUDYOMDQMH]UDþQHJDSURPHWD6SHFLILNDFLMH]DVWRSQMHYDURYDQMDSURJUDPVNH
RSUHPH
Air Traffic Management - Specification for software assurance levels
Flugverkehrsmanagement - Spezifikation für Software-Sicherheitsanforderungsstufen
Gestion du trafic aérien - Spécification des Niveaux d'assurance logicielle
Ta slovenski standard je istoveten z: CEN/TS 16501:2013
ICS:
03.220.50 =UDþQLWUDQVSRUW Air transport
35.240.60 Uporabniške rešitve IT v IT applications in transport
transportu in trgovini and trade
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.
TECHNICAL SPECIFICATION
CEN/TS 16501
SPÉCIFICATION TECHNIQUE
TECHNISCHE SPEZIFIKATION
April 2013
ICS 35.240.60
English Version
Air Traffic Management - Specification for software assurance
levels
Gestion du trafic aérien - Spécification des niveaux Flugverkehrsmanagement - Spezifikation für Software-
d'assurance logicielle Sicherheitsanforderungsstufen
This Technical Specification (CEN/TS) was approved by CEN on 12 February 2013 for provisional application.
The period of validity of this CEN/TS is limited initially to three years. After two years the members of CEN will be requested to submit their
comments, particularly on the question whether the CEN/TS can be converted into a European Standard.
CEN members are required to announce the existence of this CEN/TS in the same way as for an EN and to make the CEN/TS available
promptly at national level in an appropriate form. It is permissible to keep conflicting national standards in force (in parallel to the CEN/TS)
until the final decision about the possible conversion of the CEN/TS into an EN is reached.
CEN members are the national standards bodies of Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia,
Finland, Former Yugoslav Republic of Macedonia, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Lithuania,
Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, Switzerland, Turkey and United
Kingdom.
EUROPEAN COMMITTEE FOR STANDARDIZATION
COMITÉ EUROPÉEN DE NORMALISATION
EUROPÄISCHES KOMITEE FÜR NORMUNG
Management Centre: Avenue Marnix 17, B-1000 Brussels
© 2013 CEN All rights of exploitation in any form and by any means reserved Ref. No. CEN/TS 16501:2013: E
worldwide for CEN national Members.
Contents Page
Foreword .3
Introduction .4
1 Scope .5
2 Normative references .5
3 Terms and definitions .5
4 Software Assurance Levels (SWAL) .6
4.1 General .6
4.2 Allocation .6
4.3 Likelihood assessment .6
4.4 Likelihood justification .6
5 SWAL Objectives per Process .6
5.1 General .6
5.2 Primary Life Cycle Processes .7
5.2.1 The Acquisition Process .7
5.2.2 The Supply Process .7
5.2.3 The Development Process .7
5.2.4 The Operation Process .7
5.2.5 The Maintenance Process .7
5.3 Supporting Life Cycle Processes .7
5.3.1 The Documentation Process .7
5.3.2 The Configuration Management Process .7
5.3.3 The Quality Assurance Process .7
5.3.4 The Verification Process .7
5.3.5 The Joint Review Process .7
5.3.6 The Audit Process .8
5.3.7 The Problem/Change Resolution Process .8
5.4 Organisational Life Cycle Processes.8
5.5 COTS processes .8
5.5.1 COTS planning process .8
5.5.2 COTS acquisition process .8
5.5.3 COTS verification process .8
5.5.4 COTS configuration management process .8
Bibliography .9
Foreword
This document (CEN/TS 16501:2013) has been prepared by Technical Committee CEN/TC 377 “Air Traffic
Management”, the secretariat of which is held by DIN.
Attention is drawn to the possibility that some of the elements of this document may be the subject of patent
rights. CEN [and/or CENELEC] shall not be held responsible for identifying any or all such patent rights.
According to the CEN-CENELEC Internal Regulations, the national standards organisations of the following
countries are bound to announce this Technical Specification: Austria, Belgium, Bulgaria, Croatia, Cyprus,
Czech Republic, Denmark, Estonia, Finland, Former Yugoslav Republic of Macedonia, France, Germany,
Greece, Hungary, Iceland, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland,
Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, Switzerland, Turkey and the United Kingdom.
Introduction
The European Union launched the "Single European Sky" (SES) Legislation in 2002, which was adopted in
2004.
The SES legislation is based on a framework of 4 regulations, which includes the Interoperability Regulation
(EC 552/2004). The objective of the Interoperability Regulation is to ensure interoperability of the European
Air Traffic Management Network (EATMN) consistent with air navigation services.
An increasing proportion of functions of the EATMN are implemented by software and these functions are
becoming more safety-critical. It is therefore necessary to define guidance on how to standardise the
assurances that may be provided for software.
1 Scope
This Technical Specification specifies the technical, operational and maintenance requirements for Software
Assurance Levels to support the demonstration of compliance with some elements of the Essential
Requirements “Safety” and “Principles governing the constr
...



