Home / Method & compliance
Safety is not a project phase. It is the project.
A safety case cannot be reconstructed after the fact. It is built continuously, from the first site survey through to regular service verification — and the civil aviation authority is involved from the design stage onwards.
01 · Criticality tiers
Three tiers, three exit gates.
Each tier has its own functional scope, its own level of safety requirement and its own passing condition. Selling tier 3 before tier 1 has been delivered in real operation would be the single biggest risk in the programme — for you as much as for us.
| Tier | Scope | Nature | Passing condition |
|---|---|---|---|
| P1 | Supervision and operations Read-only on the field side |
Not safety-related. Status acquisition, synoptics, alarms, historisation, CMMS, analytics, national console. No write access to controllers or regulators — the link is one-way, physically and logically. | Site acceptance, then 6 months of continuous operation with no blocking anomaly. |
| P2 | Control of non-critical circuits | Safety-related, limited criticality. Apron lighting, de-icing areas, service road lighting, obstacle lighting. Excludes runway, approach and stop bars. | Safety case, risk assessment, changeover trials, authority approval. |
| P3 | Full ALCMS | Safety-related, high criticality. Control of runway, taxiways, approach, stop bars, low visibility operations up to CAT III, Follow-the-Greens guidance. | Complete safety case, demonstrated software lifecycle, in-service trials, formal approval. |
02 · Functional safety
Seven requirements we impose on ourselves.
| Ref. | Criticality | Requirement |
|---|---|---|
| CNF-01 | Mandatory | An operational risk assessment is produced for each tier: hazardous events, their consequences on operations, and the barriers put in place. Revised at every significant functional change. |
| CNF-02 | Mandatory | Fail-safe principle: any loss of communication, computing or power in the supervision layer leaves the lighting in its current state and reports it explicitly to the operator. No spontaneous extinction. |
| CNF-03 | Mandatory | Permanent visual distinction between measured state, commanded state and stale data. Any value whose freshness exceeds the configured threshold is flagged invalid, never displayed as valid. |
| CNF-04 | Mandatory | Critical tier P3 safety interlocks are implemented at controller level, independently of the supervision software. Supervision can neither bypass nor disable them. |
| CNF-05 | Mandatory | Documented software lifecycle: traced requirements, design reviews, automated testing, configuration and defect management. The requirement → design → test → result traceability matrix is a contractual deliverable. |
| CNF-06 | Important | For tier P2 and P3 functions, a recognised software safety assurance approach — EUROCAE ED-153 or equivalent — with the assurance level justified by the risk assessment. |
| CNF-07 | Important | Register of waivers and operating limitations, kept up to date and issued to the operator with every release. |
Applicable framework
| Reference | Scope for the product |
|---|---|
| ICAO, Annex 14, Vol. I | Baseline framework: characteristics of visual aids, lighting monitoring requirements, availability thresholds per operating category, secondary power supply and changeover times. |
| ICAO, Doc 9157 (parts 4 and 5) | Aerodrome Design Manual: visual aids and electrical systems. Guides the design of synoptics and of the operating rules implemented. |
| ICAO, Doc 9476 and 9830 | SMGCS and A-SMGCS: the framework for surface guidance, stop bars and Follow-the-Greens at tier P3. |
| FAA AC 150/5345-56B | L-890 system specification: minimum ALCMS requirements and monitoring levels. The highest level is the tier P3 target. |
| EASA CS-ADR-DSN | Certification specifications for aerodrome design: the European design framework, used for export. |
| IEC 61821 · 61822 · 61823 | Airfield lighting electrical installations: maintenance of series circuits, constant current regulators, isolating transformers. Frames the measurements acquired and the thresholds implemented. |
| IEC 62305 and 60364 | Lightning protection and low voltage installations: determines the architecture of substation acquisition enclosures. |
| ISO/IEC 25010 | Software quality model: the framework for demonstrating the non-functional requirements. |
| National regulation | Aeronautical regulations and directives of the Moroccan civil aviation authority; Law 05-20 on cybersecurity and its national directive; Law 09-08 on the protection of personal data. |
03 · Cybersecurity
Zones, conduits, and nothing leaving without your consent.
Airfield lighting is critical national infrastructure: it falls within the scope of Law 05-20 and of the national information systems security directive. The security architecture follows the zones and conduits model of the IEC 62443 series.
| Ref. | Criticality | Requirement |
|---|---|---|
| SEC-01 | Mandatory | Documented zones and conduits partitioning, with a target security level justified per zone. Strict separation of the operational and office networks, with no direct gateway. |
| SEC-02 | Mandatory | No direct internet exposure of any supervision component or below. All outbound traffic passes through a demilitarised zone under the operator's control. |
| SEC-03 | Mandatory | Named authentication for all access, two-factor for any role holding control or administration rights. No generic accounts, no default passwords at delivery. |
| SEC-04 | Mandatory | Role-based access control with separation of privileges: read, operate, control, maintain, administer, audit. No single account ever combines administration and audit. |
| SEC-05 | Mandatory | Tamper-proof audit log of all actions, logins, configuration changes and acknowledgements. Timestamped, exported to an external collector, protected against deletion including by an administrator. |
| SEC-06 | Mandatory | Encryption of all application traffic, including internal traffic, using TLS with certificates managed by a public key infrastructure. Backups encrypted at rest. |
| SEC-07 | Mandatory | Remote maintenance permanently disabled: remote access is enabled on request, time-limited, named, logged, recorded, and revocable unilaterally by the operator. |
| SEC-08 | Mandatory | Data hosted on national territory. No operational data, no log and no backup leaves the Kingdom without the operator's written authorisation. |
| SEC-10 | Important | Vulnerability management: monitoring of delivered components, patches qualified within 30 days for critical vulnerabilities, documented emergency procedure. |
| SEC-11 | Mandatory | Penetration testing by an independent third party before every site commissioning, and annually thereafter. Critical and major vulnerabilities block acceptance. |
| SEC-12 | Important | Cyber continuity and recovery plan: site isolation procedure, fallback to local control, restoration procedure validated in an annual exercise. |
04 · Deployment
Airfield lighting cannot be switched off.
The airports concerned are in operation, several of them around the clock. The whole deployment strategy follows from that: the existing system remains master and operational throughout the connection phase.
- No operational interruption attributable to the deployment.
- Substation work planned in low-traffic windows, coordinated with operations and air traffic control.
- 60 days minimum of parallel running: new system observing, old system master, every discrepancy analysed.
- Rollback procedure tested before every cutover, executable in under 30 minutes, under a designated cutover manager.
- One complete pilot site before any wider rollout.
Recommended sequence
Pilot site
A medium-sized airport with a recent, well-documented estate, at tier P1 only. Objective: validate the core, the acquisition drivers and the HMI under real conditions.
Regional rollout
Three to five airports with different profiles, including one with an ageing estate, to put the manufacturer abstraction layer to the test.
National console
Aggregation brought into service as soon as at least three sites are reporting stable data.
Major airports
Connection of the hubs, with reinforced availability and cybersecurity requirements.
Tier P2, then P3
Undertaken site by site, after the safety case and approval. Never as a simultaneous rollout.
05 · Validation and acceptance
Seven stages, each with its own passing criterion.
| Stage | Location | Content and passing criterion |
|---|---|---|
| Unit and integration tests | Continuous integration | Automated, run at every release. Coverage of operating rules and availability calculations across 100 % of traced functional requirements. |
| Factory acceptance test | ANTARES test bench | Full site simulator reproducing regulators, controllers and faults. Replay of operating and failure scenarios. No blocking or major anomaly left open. |
| System integration tests | Test bench + real equipment | Verification of every acquisition driver against the equipment actually present on the target site, including degraded modes and out-of-range values. |
| Site acceptance test | Airport | Point-to-point verification of every acquired state, server failover trials, power and link outage trials, load testing. |
| Security testing | Airport | Penetration test by an independent third party, configuration review, verification of zone segregation. Critical and major vulnerabilities are blocking. |
| Operational trials | Airport | Scenarios played by real operators: circuit failure during operations, power loss, low visibility operations, loss of the national centre, rollback. |
| Regular service verification | Airport | 60 days of parallel running with no blocking anomaly and no unexplained state discrepancy. Condition for final acceptance. |
Milestones of a pilot package (tier P1)
| Milestone | Purpose | Timing | Exit deliverable |
|---|---|---|---|
| J0 | Kick-off | T0 | Specification frozen, pilot scope agreed, steering committee established. |
| J1 | Detailed design | T0 + 2 months | Architecture dossier, data model, tier P1 risk assessment, HMI mock-up validated by operators. |
| J2 | Pilot site survey | T0 + 3 months | Asset inventory, circuit drawings, data point matrix, acquisition driver specification. |
| J3 | Factory acceptance | T0 + 7 months | FAT report, traceability matrix, automated test report. |
| J4 | Connection and site acceptance | T0 + 9 months | SAT report, penetration test report, as-built documentation. |
| J5 | Commissioning in observation | T0 + 10 months | Start of parallel running, operators trained and authorised. |
| J6 | Final acceptance | T0 + 12 months | Regular service verification report, pilot review, rollout decision. |
Contractual deliverables
- Technical architecture dossier and detailed design dossier.
- Operational risk assessment and register of operating limitations, per tier.
- Requirement → design → test → result traceability matrix, maintained at every release.
- Cybersecurity dossier: zones and conduits, reference configuration, penetration test report.
- Operations, maintenance and administration manuals, in French and Arabic.
- As-built documentation per site, wiring drawings and delivered configuration.
- Training material and certificates, skills transfer plan.
- Software bill of materials, licences and source code escrow terms.
Risks we address head-on
| Risk | Control measure |
|---|---|
| Scope creep towards critical control before maturity | Tiers written into the contract, control layer absent from the P1 delivery, formal safety gate. |
| Manufacturer interfaces closed or undocumented | Interfaceability survey from milestone J2; fallback to physical acquisition through a controller. |
| Asset data missing or out of date | Survey and asset register construction budgeted as a package in their own right. |
| No work windows available | Joint planning from J1; design allowing connection without taking a circuit out of service. |
| Authority approval delays | Authority involved from the design stage; safety case built continuously. |
| Rejection by operators | Operators involved in HMI design from J1; usability evaluation blocking for acceptance. |
Tenders
Writing an ALCMS specification?
We are happy to share our requirements template — tiers, safety, cybersecurity, acceptance. Even if you consult other suppliers, a well-built specification protects you: it makes bids comparable and stops anyone selling you tier 3 on a slide deck.