EFB SERIES · PART 5 OF 8 — Technology, Security & Safety · Series Hub · ← Part 4 · Part 6 → (publishes Sep 9)

TL;DR — How are EFBs certified? EFBs are not certified as products; they are authorized operationally, per operator, by the national aviation authority — via FAA OpSpecs (built on AC 120-76E guidance) or EASA acceptance under AMC 20-25 — with ICAO Doc 10020 harmonizing globally. Only installed/interfaced components (mounts, AIDs, Type C software) enter formal airworthiness certification. And since 2025–2026, EASA’s Part-IS adds mandatory information-security management on top.
There is a question every technically-minded person eventually asks about the EFB: “who approved this thing?” The honest answer reshapes how you see the whole system: nobody certifies the iPad. The regulator never blesses the gadget — it blesses the program an operator builds around the gadget. That single fact explains why two airlines can fly the same tablet with different rules, and why the paperwork that governs your charts weighs (metaphorically) more than the paper charts ever did.
This post maps the rulebook — FAA, EASA, ICAO, plus the 2026 twist that turns EFB security from good practice into legal obligation — and then walks the operational approval process step by step, because that process is where every requirement from Parts 1–4 (redundancy, battery policy, revision control, training) becomes enforceable.
The Regulatory Map: Who Says What
Three systems govern EFBs: FAA operational authorization in the US, EASA acceptance in Europe, and ICAO harmonization for everyone else — each expressing the same concerns in different legal instruments.

Table T5.1 — Regulatory crosswalk
| Concern | FAA (US) | EASA (EU) | ICAO (global) |
|---|---|---|---|
| Foundation | 14 CFR ops rules (incl. PED provisions 91.21 / 121.306) | Reg (EU) 965/2012 (Part-CAT/NCC/NCO) | Annex 6 |
| EFB guidance | AC 120-76E (evaluation/authorization) · AC 91-78A (Part 91 use) | AMC 20-25 (portable/installable EFB) | Doc 10020 (EFB Manual) |
| The permission itself | OpSpec paragraphs (A050-class) [verify current designators] | Ops-manual acceptance + oversight | State-level implementation |
| Installed systems | Type design / STC (CS-ACDS on EASA side [verify status]) | CS-ACDS / certification programme part | — |
| Security (2025→) | Cyber rulemaking track [verify current state] | Part-IS — Regs (EU) 2022/1645 (orgs) + 2023/203 (authorities) | Doc 10020 security guidance |
The FAA column
The FAA’s structure is opspec-driven: the advisory circular (AC 120-76E in its current form) tells operators how to build an approvable EFB program, and the operational specification — the OpSpec paragraph attached to the operator’s certificate — is what legally authorizes EFB use in lieu of paper. The PED rules (14 CFR 91.21, 121.306) supply the historical foundation: they’re why the untethered Class 1 device of Part 2 was always stowage-regulated. Transport Canada’s AC 700-020 plays the equivalent role in the Canadian system and is worth reading as a second opinion on the same ideas.
The EASA column
EASA’s structure is acceptable-means-driven: Regulation (EU) 965/2012 hosts the operational requirements, and AMC 20-25 is the accepted means of compliance showing how to meet them for EFBs — the vocabulary of “portable” and “installable” EFBs that Part 2 introduced lives here. Installed data-system equipment on the airworthiness side falls under certification specifications (CS-ACDS in current EASA practice [verify status]). The 2026 wildcard — Part-IS — gets its own section below.
The ICAO layer
ICAO does not approve anything; it harmonizes. Annex 6 sets the obligation for states to have a framework, and Doc 10020, the EFB Manual, is the reference most national rules are paraphrasing. For pilots and engineers working across borders, Doc 10020 is the closest thing to a lingua franca — and for auditors, the checklist behind the checklists.
The Operational Approval Process, Step by Step
EFB approval is a safety-management exercise: the operator builds a program, assesses its risks, and the authority accepts or rejects the package.

Step 1 — Policy and scope. The operator defines what the EFB will replace (paper charts? manuals? performance data?), on which fleets, with which applications (Type A/B from Part 3), and under what configuration control. Ambiguity here metastasizes into findings later.
Step 2 — Hazard identification and risk register. This is the heart, and it is pure ICAO Doc 9859 safety management: enumerate what can go wrong — device failure, data staleness (Part 4’s missed cycle), battery events (Part 8), human factors (Part 8), and increasingly security scenarios (Parts 6–7) — score each on a severity × likelihood matrix, and document mitigations. The classic 5×5 grid below is the artifact inspectors actually interrogate:

Step 3 — Redundancy and backup policy. Dual independent EFBs, or EFB plus retained paper, with the independence rules (separate power, no shared single points — Part 8 dissects the common-mode trap) written down and trained.
Step 4 — Training and differences. Initial and recurrent training on the applications, the failure procedures, and the discipline changes (cross-check culture for Type B tools — Part 3’s safety case, made enforceable).
Step 5 — Configuration control. The two-axis lock from Part 4: approved application versions validated against data cycles, with change management for both.
Step 6 — Documentation package and submission. Everything above, bound into the EFB program manual, submitted within the operator’s certificate structure.
Step 7 — NAA review and authorization. The authority evaluates — including, where interfaces are involved, coordination with the airworthiness side for the installed bits (mount, AID). Approval issues as an OpSpec/authorization (FAA-style) or acceptance within the oversight system (EASA-style).
Step 8 — Implement, monitor, audit. Living program: update-adoption metrics, discrepancy reports, periodic audits (IOSA-style oversight references EFB program elements for member airlines [verify current ISARP references]). A change to applications or data flow re-enters the loop at Step 2.
Table T5.2 — The approval package checklist
| Element | Evidence | Signed by |
|---|---|---|
| Policy & scope | Program manual section | Director of ops / accountable manager |
| Risk register | Hazard log, 5×5 matrices, mitigations | Safety manager |
| Redundancy/backup policy | Procedures, MEL-style guidance | Flight ops |
| Battery policy | Endurance rules, charging discipline | Flight ops / safety |
| Training | Syllabi, records, differences training | Training department |
| Revision control | Version-control procedures, verification flows | EFB administrator |
| Security controls | Hardening baseline, incident reporting path [Part 7] | Security / IT |
| Configuration control | Approved version matrix | EFB administrator |
FAA vs EASA: Side by Side
The philosophical difference: the FAA authorizes through certificate paragraphs; EASA accepts through compliant means — producing the same artifacts with different paperwork genealogies.
Practically: an FAA operator points to its OpSpec paragraph and the AC-based program behind it; an EASA operator points to its Ops Manual as accepted under AMC 20-25 within the Part-CAT/NCC framework. Divergences worth knowing when aircraft or crews cross systems: differing treatment of portable-vs-installed boundaries (Part 2’s shifting vocabulary), differing Type B acceptance nuances, and mutual-recognition gaps that matter for NAA-registered aircraft operated across regimes. None of these diverge on fundamentals — dual independence, procedural containment of Type B failures, revision control — because all three systems descend from the same ICAO material.
The 2026 Twist: Security Becomes Regulated
EASA’s Part-IS turns information security from best practice into an auditable management obligation — and it lands as this series publishes.
“Part-IS” is the shorthand for two paired acts: Commission Delegated Regulation (EU) 2022/1645 (organization requirements — Part-IS.D.OR) and Commission Implementing Regulation (EU) 2023/203 (authority requirements — Part-IS.AR). Organization obligations became applicable from 16 October 2025 for a broad set of organisations (design, production, CAMO, Part-145, aerodromes, ATM/ANS and more), and 22 February 2026 is the widely referenced milestone for air operators with complex motor-powered aircraft, CAMOs and maintenance organisations — with authority oversight attached to the same date, and a transition framework allowing roughly 18 months to reach full compliance maturity while authorities can already raise findings. Translated into this series’ vocabulary: the attack scenarios of Part 6 are no longer merely research curiosities; an operator must have identified them, assessed them, and be able to show mitigations — the security slice of the D5.3 wheel now has a regulation with teeth behind it.
The FAA side is moving on the same vector through its aviation-cybersecurity rulemaking and policy work [verify current state], and DO-326A/ED-202A (Part 7’s centerpiece) already defines how certified systems demonstrate security. Direction of travel, everywhere: an EFB program without a security annex is heading for a finding.
What Inspectors Actually Check
The audit lens: inspectors verify the program, the evidence, and the match between them. Expect document requests (program manual, risk register, training records), system demonstrations (revision-status verification live on a device), fleet metrics (update adoption, version mix), and scenario questions — “show me what happens when a device misses a cycle,” “walk me through your battery-failure procedure,” “who can push a new application to the fleet, and what stops them pushing the wrong one?” That last question, trivial-looking, is a Part 6/7 question wearing an auditor’s blazer — which is tomorrow’s cue.
Tomorrow, Part 6 turns the rulebook inside out and asks the attacker’s questions instead: what’s the EFB’s attack surface, what has security research already demonstrated, and why does a $100 coin-sized device connected to real 737 avionics belong in this conversation?
Key Takeaways
- EFBs are authorized operationally per operator — no regulator certifies the tablet itself; installed pieces (mount, AID, Type C) carry the airworthiness weight.
- FAA: AC 120-76E guidance + OpSpec authorization. EASA: Reg (EU) 965/2012 + AMC 20-25 acceptance. ICAO Doc 10020 harmonizes both.
- The approval process is SMS-shaped: policy → hazard register (5×5) → redundancy/battery/training → submission → authorization → audit loop.
- FAA vs EASA differ in legal genealogy, converge on fundamentals: independence, procedural containment, revision control.
- Part-IS (Regs (EU) 2022/1645 + 2023/203) makes information-security risk management an auditable obligation in Europe — organization duties from October 2025, the 22 Feb 2026 milestone for air operators, CAMOs and maintenance.
- Inspectors check programs and evidence — including who can push changes to the fleet, which is a security question.
FAQ
Do EFBs need FAA approval?
The device doesn’t; the operator’s program does. Under AC 120-76E-based guidance, a US operator obtains EFB authorization through OpSpec paragraphs after building an approvable program — policy, risk assessment, training, backup procedures, configuration control.
What is OpSpec A050?
An operations specification paragraph under which US operators are authorized to use EFBs in lieu of paper [verify current designator and wording for your certificate]. OpSpecs are the legal instrument; the advisory circulars describe how to earn them.
What is EASA AMC 20-25?
EASA’s Acceptable Means of Compliance for electronic flight bags — the framework under which European operators structure portable and installable EFB programs within Regulation (EU) 965/2012, covering evaluation, redundancy and failure management.
Is EFB approval per operator or per device?
Per operator. The authority authorizes the operator’s program for defined equipment and applications. Individual devices gain meaning only inside that authorization — which is why fleet configuration control is a core approval element.
Are EFBs ICAO-standardized?
ICAO Doc 10020 (EFB Manual) provides the global harmonization reference that national rules implement. It is guidance for states rather than direct law, but most national frameworks are recognizably built on it.
What is EASA Part-IS?
The EU’s information-security rulebook for aviation: Delegated Regulation (EU) 2022/1645 (organization requirements, Part-IS.D.OR) and Implementing Regulation (EU) 2023/203 (authority requirements, Part-IS.AR), applicable from October 2025 and February 2026 respectively — making EFB cyber-risk assessment and mitigation auditable law in Europe.
How long does EFB approval take?
Typically months, not weeks — dominated by the operator’s own program build (risk assessment, training design, procedures) rather than authority review time. Scope creep across fleets and applications is the usual schedule killer.
References
- FAA, Advisory Circular 120-76E — Electronic Flight Bag (faa.gov)
- FAA, Advisory Circular 91-78A — Operational Use of Flight Deck EFBs; 14 CFR 91.21 / 121.306 (PED foundations)
- EASA, AMC 20-25 — Airworthiness and Operational Considerations for Electronic Flight Bags
- Commission Delegated Regulation (EU) 2022/1645 (Part-IS.D.OR) & Commission Implementing Regulation (EU) 2023/203 (Part-IS.AR) — applicable 16 Oct 2025 / 22 Feb 2026; EASA Easy Access Rules for Information Security
- Regulation (EU) No 965/2012 (air operations); EASA CS-ACDS (installed data systems) [verify status]
- ICAO, Doc 10020 — Electronic Flight Bag Manual; Annex 6; Doc 9859 — Safety Management Manual
- Transport Canada, AC 700-020 — Operational Use of EFBs
[← Part 4: EFB Data Pipeline] · [Series Hub] · Part 6: EFB Cybersecurity — Threats → (publishes Sep 9)
Parts publish daily through September 11 — bookmark the series hub for the full run.
Current as of September 2026 · standards verified against the latest revisions.
Educational reference only — always follow your operator’s approved EFB program and your NAA’s current guidance.
Author: hmmnm.com editorial team · hmmnm.com
