suriyavaan Aerospace Quality · Systems Transformation
CMMI · DO-178C · RTCA/DO Software Assurance

Process Maturity That Aerospace Software Auditors Respect Is Not Written in the Week Before Appraisal.

For engineering and embedded-software organisations that are building certifiable airborne software and electronic hardware — evidence that an appraiser or certification authority can actually follow, rather than a process set that has been assembled just a month before the audit. This means CMMI V3.0 deployment, RTCA/DO objective compliance, and the requirements and configuration discipline that makes both of these hold up over time, built by a practitioner who holds Certified CMMI Practitioner status on the current V3.0 model.

Simon Kuntam — Founder & Principal Advisor

Certified CMMI Practitioner (ISACA) on the current V3.0 model. IAQG/Probitas-authenticated AS9100D Lead Auditor since 2020. Every credential on this page is dated, issued, and verifiable — please check it before you book, not after you sign. Full background and credentials.

CMMI V3.0
Certified Practitioner, ISACA 2024
9 Sites · 5,000+
Boeing India AS9100D Scope
25+ Years
Field & Aerospace Audit Experience
Or call +91 97413 70111 · Bangalore, India · on-site workshops across India

15-Min OEM Readiness Diagnostic

Free · online or phone · no pitch, no obligation
  • Where your quality system stands today
  • The most likely blockers to approval
  • Whether Suriyavaan is the right fit for you — an honest, straightforward read
  • A concrete next step, either way
Who should join: the MD/CEO and your Quality Head, together.
Book Free 15-Min Diagnostic Prefer WhatsApp? Message us — reply within one business day.
How To Tell The Difference

Two Consultants May Both Say "Appraisal-Ready." Only One Has Actually Built the Trail As the Work Went Along.

Every CMMI consultant will tell you that your process is appraisal-ready. Before you sign anything, it is worth asking them to actually show you the evidence trail — rather than just a folder that has been assembled last month.

What You'll Hear

"Your documentation is appraisal-ready."

What To Check

Appraisers are specifically trained to detect a process set that has been assembled shortly before the appraisal window. It is worth asking whether the evidence was captured as the work actually happened, or written afterward simply to match a template — this distinction is called institutionalisation, and it is essentially the entire point of the appraisal.

What You'll Hear

"We'll get your requirements traced."

What To Check

Ask to see one requirement traced live — through to code, through to test, and back again — across a baseline that has already survived a change. Traceability that only works on the happy path tends to collapse the very first time an auditor asks about a specific change.

What You'll Hear

"DO-178C is basically a documentation exercise."

What To Check

It is, in fact, an evidence exercise scaled to your Design Assurance Level (DAL). A consultant who speaks about DO-178C only in terms of paperwork has, in all likelihood, never actually built the PSAC-to-verification chain that an authority follows — it is worth asking which DAL, which objectives, and which authority.

What You'll Hear

"We handle CMMI and DO-178C separately, no problem."

What To Check

Running them as two disconnected systems is precisely how a Clause 8.3 audit finds a seam. It is better to ask how they map the same design-development plan across both — rather than simply how they staff two separate teams.

Coverage

What this practice covers.

Two bodies of work that most organisations essentially need together: organisational process maturity, and the airborne-systems objectives that your certification authority will assess.

CMMI V3.0 ML3 to ML5

Practice area definition, institutionalisation and appraisal readiness — deployed as working practice rather than just a document set assembled before the appraisal. V3.0 broadened the model beyond development and services into data management, people management, safety, security and supplier management.

DO-178C airborne software

Objectives, evidence and independence scaled to your Design Assurance Level (DAL), starting from the Plan for Software Aspects of Certification (PSAC) through to the traceability that an authority can actually follow.

DO-254 airborne electronic hardware

The hardware counterpart to the above: planning, requirements capture, validation and verification for complex electronic hardware.

DO-330 tool qualification

Where your toolchain replaces or automates a DO-178C objective, the tool itself needs to be qualified as well. This is commonly discovered late in the process, and it is expensive to retrofit at that stage.

DO-331 / 332 / 333 supplements

Model-based development, object-oriented technology and formal methods — essentially how each of these modifies the base DO-178C objectives.

DO-326A / 356A airworthiness security

Airworthiness security process and security-effectiveness assurance, which is now routinely flowed down alongside the safety objectives.

DO-297 and DO-200B

Integrated Modular Avionics roles and responsibilities, and the handling of aeronautical data, where your product consumes or produces it.

Requirements & configuration management

The discipline underneath everything above: baselines, change control and bidirectional traceability that survives staff turnover.

Agile-at-scale governance (SAFe)

Running certifiable development inside an Agile operating model, without breaking the evidence chain along the way.

DO-160G environmental qualification is addressed where it touches your equipment scope. Which of these actually apply to you — and at what Design Assurance Level — is something we scope during the diagnostic, rather than simply assume.
Architecture Bridge

Where airborne software assurance interfaces with your physical QMS.

If your AS9100D system and your DO-178C / CMMI evidence live in separate worlds, Clause 8.3 audits tend to become the seam that fails first. Here is how they connect, sub-clause by sub-clause.

8.3.2 Design & development planning ↔ CMMI Technical Solution (TS)

AS9100D requires a documented design and development plan with stages, reviews and responsibilities. CMMI ML3 Technical Solution practices supply the structured design-alternative selection and product-architecture rationale that this plan is meant to evidence — essentially one planning artefact, rather than two competing ones.

8.3.3 Design & development inputs ↔ DO-178C requirements capture (PSAC / SRS)

Clause 8.3.3 requires inputs to be complete, unambiguous and traceable to function and performance requirements. DO-178C's Software Requirements Standard (SRS) and Plan for Software Aspects of Certification (PSAC) are that input set for the software item — bidirectional traceability satisfies both simultaneously, provided the tooling is shared.

8.3.4 Design & development controls ↔ CMMI Verification & Peer Reviews + DO-178C verification objectives

AS9100D wants evidence that reviews, verification and validation happened at defined stages. CMMI Verification practices and DO-178C's independence-scaled review and test objectives (by Design Assurance Level) are that evidence — structural coverage analysis and peer review records satisfy the same audit question from both directions.

8.3.5 Design & development outputs ↔ DO-178C software life-cycle data

Clause 8.3.5 requires outputs adequate to verify against inputs and to specify product characteristics for production and use. DO-178C's life-cycle data set (design description, source code, verification results) is essentially the software equivalent — configuration-managed and mapped to the DAL that your authority assigned.

8.3.6 Design & development changes ↔ CMMI Configuration Management + DO-178C change impact analysis

Both regimes require controlled change with impact analysis before implementation. One configuration-management baseline and one change-impact process can feed both the AS9100D design-change record and the DO-178C problem-report / change-analysis trail — run these as two separate processes, and they will drift apart within a year.

The point is not running two management systems in parallel. Rather, it is one engineering process with two audit lenses pointed at it — built once, so that the evidence does not have to be reconstructed twice.
Problems We Fix

What usually goes wrong.

Maturity Risk

Practice that lives in people, rather than in process

Your senior engineers are excellent, and the work gets done. However, none of it is repeatable once they move on, and an appraisal essentially measures the organisation, not the individuals.

Evidence Risk

Traceability reconstructed after the fact

Requirements, code and tests exist, but were never actually linked as they were built. Rebuilding that chain retrospectively tends to cost more than doing it once, correctly, the first time.

Scope Risk

Design Assurance Level assumed, rather than agreed

Work starts before the DAL is actually settled with the integrator or authority. Every objective downstream is then either over-engineered or falls short.

Tooling Risk

An unqualified toolchain

Automation replaces a verification objective, but the tool itself was never qualified under DO-330. This is usually discovered only during the audit.

Governance Risk

Agile methodology that breaks the evidence chain

The team runs sprints; the certification evidence, meanwhile, assumes a plan-driven lifecycle. Neither side is wrong as such — the mapping between the two was simply never built.

Appraisal Risk

Documents written specifically for the appraisal

A process set that has been assembled shortly before the appraisal window. Appraisers test for institutionalisation, and this is exactly the pattern they are trained to detect.

Fit Check

This is for you if…

01You are an engineering or embedded-software organisation supplying aerospace or defence programmes.
02A customer or integrator has flowed down a DO-178C, DO-254 or CMMI maturity requirement to you.
03You hold ISO 9001 or AS9100D, but have no software-specific process maturity to show for it.
04Your engineering practice is genuinely strong but undocumented, and appraisal readiness is essentially the gap.
05You run Agile and need certifiable evidence, without abandoning the way your teams actually work.
06You need requirements and configuration management that can survive an authority audit.
If two or more of these apply to you, the gap is institutionalised evidence — not engineering talent.
Engagement Model

Start small, prove the value, then scale up.

There is no year-long contract to sign before we both actually know your real gaps.

Step 01

15-Min Readiness Diagnostic

Free · covering where you stand today, what blocks approval, and an honest read on fit.

Step 02

Flight Plan Workshop

Half or full-day, conducted on-site · a gap snapshot and dated route map · fixed fee, quoted before booking.

Step 03

Certification Advisory Retainer

Alongside you through readiness, implementation and audit preparation · scoped only after the workshop.

Leadership

Who you would actually be working with.

Simon Kuntam, Founder and Principal Advisor, Suriyavaan Solutions
Simon Kuntam
Founder & Principal Advisor

Former Country Quality Leader, Boeing India (AS9100D scope: 9 sites, 5,000+ engineers). IAQG/Probitas-authenticated AS9100D auditor.

Connect on LinkedIn

Exp / 01
25+ Years

Boeing · Schneider Electric · ABB · safety-critical field engineering

Office / 02
Boeing India

Former Country Quality Leader · AS9100D Management Representative

Scope / 03
9 Sites · 5,000+

AS9100D certification scope — one of the largest Boeing operations outside the continental US

Authority / 04
IAQG · Probitas

Authenticated AS9100D aerospace auditor

NPI / 05
AS9145 APQP & PPAP

Aerospace new product introduction — advanced product quality planning and production part approval

Software / 06
CMMI V3.0 Practitioner

Certified CMMI Practitioner (ISACA) on the current V3.0 model

Faculty / 07
Systems-Led Disciplines

Trainer in Systems Thinking, System Dynamics Modelling, Critical Thinking and Design Thinking

Suriyavaan is an independent advisory led by an auditor-practitioner — not a certification body, and not a template vendor. Full career history, all nine professional certifications and the standards list are available on the main practice page.
The Three Practices

One advisory, three aerospace quality standards.

Manufacturing, maintenance and distribution are each audited against different standards, by the same OEM supplier-quality teams. Please pick the one that actually matches what you do.

FAQ

Questions we're asked first.

Is CMMI still relevant, or has Agile replaced it?

They actually answer different questions. Agile governs how a team works week to week; CMMI describes whether the organisation can repeat that reliably across teams, sites and staff turnover — which is precisely what an OEM's supplier-quality team is assessing. Most aerospace engineering organisations run both together, and Agile-at-scale frameworks such as SAFe map onto CMMI practice areas rather than replacing them.

Do you appraise us, or prepare us for appraisal?

I prepare you, and serve on the team — not appraise you. Appraisals today are conducted against CMMI V3.0, which ISACA released in 2023. I hold Certified CMMI Practitioner status on the current V3.0 model, alongside Certified CMMI V2.0 Professional and CMMI V2.0 Appraisal Team Member credentials — the formal benchmark appraisal itself must be led by a Certified Lead Appraiser. That separation is deliberate, and it protects you: the person who builds your process should not be the same person who certifies it.

What does DO-178C actually require?

Objectives, evidence and independence, scaled to your Design Assurance Level (DAL). A DAL A system carries substantially more objectives than DAL D, and most of the work is actually planning and traceability rather than coding: the PSAC, development and verification plans, requirements traced to code and to tests, configuration management, and quality assurance records that the certification authority can follow. Teams that start writing code before the plans exist almost always end up rebuilding the evidence later.

We supply software to an integrator, not directly to an OEM. Do we still need DO-178C?

Usually yes, in proportion to what you supply. The integrator carries the certification obligation, and they discharge it by flowing the objectives down to you. In practice, you are held to the same evidence standard for your component, without actually controlling the overall approval — which makes early clarity about your scope and DAL more important, not less.

How long does CMMI ML3 take?

The route map gives you actual dates after the workshop, rather than a guess before it. As a rough anchor: organisations with working engineering discipline but undocumented practice typically plan for several months of process definition and institutionalisation before appraisal readiness, and the appraisal window itself is scheduled with your Lead Appraiser. What really drives the timeline is how much of your current practice is real and repeatable, versus simply written down after the fact.

What does this cost?

The diagnostic is free of charge. The Flight Plan Workshop is a fixed fee, quoted before you book. Advisory retainers are scoped only after the workshop — so that you know your actual gaps, and the full cost, before committing to anything long-term. Appraisal and certification-authority fees are separate, and payable directly to those bodies, never to me.

The Practice Behind Every Engagement

Recurring findings keep recurring because the underlying structure produces them.

Four systems-led disciplines are used to find and fix that structure — with AI-assisted analysis where it genuinely improves speed and discipline: mapping audit evidence, spotting process gaps, and structuring corrective-action follow-up.

Discipline 01

Systems Thinking

Understanding why your recurring findings actually recur — and how to make them stop by fixing the structure, rather than blaming operators or tools.

Discipline 02

System Dynamics Modelling

How delays, feedback and incentives drive quality behaviour over time — and where one small change can move the whole system.

Discipline 03

Critical Thinking

Separating the certificate from the actual capability. Testing every assumption an auditor will test — before they get to it.

Discipline 04

Design Thinking

Building the system around your people, culture and behaviour, so that quality survives real production — not just audit day.

These are the disciplines Simon taught as lead faculty for Systems Thinking & System Dynamics at Boeing's Technical Leadership Institute.
Book the Diagnostic

Ready to find out what is actually blocking approval?

Book a free 15-minute diagnostic. You will get an honest read on your readiness, the likely blockers, and the most practical next step — whether or not we end up working together.

Direct Channels
Phone / WhatsApp+91 97413 70111
LinkedInSimon Kuntam
LocationBangalore, India
On-site workshops across India
Call WhatsApp Email Book