EFB series part 5 title card: regulations and certification under FAA AC 120-76E, EASA AMC 20-25 and ICAO Doc 10020.
Regulations and certification under FAA AC 120-76E, EASA AMC 20-25 and ICAO Doc 10020

EFB Regulations & Certification: FAA AC 120-76E, EASA AMC 20-25 & ICAO Doc 10020

  • Post author:
  • Post category:Technology
📋 Key Takeaways
  • The Regulatory Map: Who Says What
  • The Operational Approval Process, Step by Step
  • FAA vs EASA: Side by Side
  • The 2026 Twist: Security Becomes Regulated
  • What Inspectors Actually Check
10 min read · 1,957 words

EFB SERIES · PART 5 OF 8 — Technology, Security & Safety · Series Hub · ← Part 4 · Part 6 → (publishes Sep 9)

hmmnm.com EFB Series hero banner: Part 5 of 8 — EFB Regulations & Certification

TL;DR — How are EFBs certified? EFBs are not certified as products; they are authorized operationally, per operator, by the national aviation authority — via FAA OpSpecs (built on AC 120-76E guidance) or EASA acceptance under AMC 20-25 — with ICAO Doc 10020 harmonizing globally. Only installed/interfaced components (mounts, AIDs, Type C software) enter formal airworthiness certification. And since 2025–2026, EASA’s Part-IS adds mandatory information-security management on top.

There is a question every technically-minded person eventually asks about the EFB: “who approved this thing?” The honest answer reshapes how you see the whole system: nobody certifies the iPad. The regulator never blesses the gadget — it blesses the program an operator builds around the gadget. That single fact explains why two airlines can fly the same tablet with different rules, and why the paperwork that governs your charts weighs (metaphorically) more than the paper charts ever did.

This post maps the rulebook — FAA, EASA, ICAO, plus the 2026 twist that turns EFB security from good practice into legal obligation — and then walks the operational approval process step by step, because that process is where every requirement from Parts 1–4 (redundancy, battery policy, revision control, training) becomes enforceable.

The Regulatory Map: Who Says What

Three systems govern EFBs: FAA operational authorization in the US, EASA acceptance in Europe, and ICAO harmonization for everyone else — each expressing the same concerns in different legal instruments.

Which document answers which concern, per jurisdiction.
Which document answers which concern, per jurisdiction.

Table T5.1 — Regulatory crosswalk

Concern FAA (US) EASA (EU) ICAO (global)
Foundation 14 CFR ops rules (incl. PED provisions 91.21 / 121.306) Reg (EU) 965/2012 (Part-CAT/NCC/NCO) Annex 6
EFB guidance AC 120-76E (evaluation/authorization) · AC 91-78A (Part 91 use) AMC 20-25 (portable/installable EFB) Doc 10020 (EFB Manual)
The permission itself OpSpec paragraphs (A050-class) [verify current designators] Ops-manual acceptance + oversight State-level implementation
Installed systems Type design / STC (CS-ACDS on EASA side [verify status]) CS-ACDS / certification programme part
Security (2025→) Cyber rulemaking track [verify current state] Part-IS — Regs (EU) 2022/1645 (orgs) + 2023/203 (authorities) Doc 10020 security guidance

The FAA column

The FAA’s structure is opspec-driven: the advisory circular (AC 120-76E in its current form) tells operators how to build an approvable EFB program, and the operational specification — the OpSpec paragraph attached to the operator’s certificate — is what legally authorizes EFB use in lieu of paper. The PED rules (14 CFR 91.21, 121.306) supply the historical foundation: they’re why the untethered Class 1 device of Part 2 was always stowage-regulated. Transport Canada’s AC 700-020 plays the equivalent role in the Canadian system and is worth reading as a second opinion on the same ideas.

The EASA column

EASA’s structure is acceptable-means-driven: Regulation (EU) 965/2012 hosts the operational requirements, and AMC 20-25 is the accepted means of compliance showing how to meet them for EFBs — the vocabulary of “portable” and “installable” EFBs that Part 2 introduced lives here. Installed data-system equipment on the airworthiness side falls under certification specifications (CS-ACDS in current EASA practice [verify status]). The 2026 wildcard — Part-IS — gets its own section below.

The ICAO layer

ICAO does not approve anything; it harmonizes. Annex 6 sets the obligation for states to have a framework, and Doc 10020, the EFB Manual, is the reference most national rules are paraphrasing. For pilots and engineers working across borders, Doc 10020 is the closest thing to a lingua franca — and for auditors, the checklist behind the checklists.

The Operational Approval Process, Step by Step

EFB approval is a safety-management exercise: the operator builds a program, assesses its risks, and the authority accepts or rejects the package.

EFB approval is a program approval, not a gadget approval.
EFB approval is a program approval, not a gadget approval.

Step 1 — Policy and scope. The operator defines what the EFB will replace (paper charts? manuals? performance data?), on which fleets, with which applications (Type A/B from Part 3), and under what configuration control. Ambiguity here metastasizes into findings later.

Step 2 — Hazard identification and risk register. This is the heart, and it is pure ICAO Doc 9859 safety management: enumerate what can go wrong — device failure, data staleness (Part 4’s missed cycle), battery events (Part 8), human factors (Part 8), and increasingly security scenarios (Parts 6–7) — score each on a severity × likelihood matrix, and document mitigations. The classic 5×5 grid below is the artifact inspectors actually interrogate:

If your program file can't answer all eight slices, it isn't a program yet.
If your program file can’t answer all eight slices, it isn’t a program yet.

Step 3 — Redundancy and backup policy. Dual independent EFBs, or EFB plus retained paper, with the independence rules (separate power, no shared single points — Part 8 dissects the common-mode trap) written down and trained.

Step 4 — Training and differences. Initial and recurrent training on the applications, the failure procedures, and the discipline changes (cross-check culture for Type B tools — Part 3’s safety case, made enforceable).

Step 5 — Configuration control. The two-axis lock from Part 4: approved application versions validated against data cycles, with change management for both.

Step 6 — Documentation package and submission. Everything above, bound into the EFB program manual, submitted within the operator’s certificate structure.

Step 7 — NAA review and authorization. The authority evaluates — including, where interfaces are involved, coordination with the airworthiness side for the installed bits (mount, AID). Approval issues as an OpSpec/authorization (FAA-style) or acceptance within the oversight system (EASA-style).

Step 8 — Implement, monitor, audit. Living program: update-adoption metrics, discrepancy reports, periodic audits (IOSA-style oversight references EFB program elements for member airlines [verify current ISARP references]). A change to applications or data flow re-enters the loop at Step 2.

Table T5.2 — The approval package checklist

Element Evidence Signed by
Policy & scope Program manual section Director of ops / accountable manager
Risk register Hazard log, 5×5 matrices, mitigations Safety manager
Redundancy/backup policy Procedures, MEL-style guidance Flight ops
Battery policy Endurance rules, charging discipline Flight ops / safety
Training Syllabi, records, differences training Training department
Revision control Version-control procedures, verification flows EFB administrator
Security controls Hardening baseline, incident reporting path [Part 7] Security / IT
Configuration control Approved version matrix EFB administrator

FAA vs EASA: Side by Side

The philosophical difference: the FAA authorizes through certificate paragraphs; EASA accepts through compliant means — producing the same artifacts with different paperwork genealogies.

Practically: an FAA operator points to its OpSpec paragraph and the AC-based program behind it; an EASA operator points to its Ops Manual as accepted under AMC 20-25 within the Part-CAT/NCC framework. Divergences worth knowing when aircraft or crews cross systems: differing treatment of portable-vs-installed boundaries (Part 2’s shifting vocabulary), differing Type B acceptance nuances, and mutual-recognition gaps that matter for NAA-registered aircraft operated across regimes. None of these diverge on fundamentals — dual independence, procedural containment of Type B failures, revision control — because all three systems descend from the same ICAO material.

The 2026 Twist: Security Becomes Regulated

EASA’s Part-IS turns information security from best practice into an auditable management obligation — and it lands as this series publishes.

“Part-IS” is the shorthand for two paired acts: Commission Delegated Regulation (EU) 2022/1645 (organization requirements — Part-IS.D.OR) and Commission Implementing Regulation (EU) 2023/203 (authority requirements — Part-IS.AR). Organization obligations became applicable from 16 October 2025 for a broad set of organisations (design, production, CAMO, Part-145, aerodromes, ATM/ANS and more), and 22 February 2026 is the widely referenced milestone for air operators with complex motor-powered aircraft, CAMOs and maintenance organisations — with authority oversight attached to the same date, and a transition framework allowing roughly 18 months to reach full compliance maturity while authorities can already raise findings. Translated into this series’ vocabulary: the attack scenarios of Part 6 are no longer merely research curiosities; an operator must have identified them, assessed them, and be able to show mitigations — the security slice of the D5.3 wheel now has a regulation with teeth behind it.

The FAA side is moving on the same vector through its aviation-cybersecurity rulemaking and policy work [verify current state], and DO-326A/ED-202A (Part 7’s centerpiece) already defines how certified systems demonstrate security. Direction of travel, everywhere: an EFB program without a security annex is heading for a finding.

What Inspectors Actually Check

The audit lens: inspectors verify the program, the evidence, and the match between them. Expect document requests (program manual, risk register, training records), system demonstrations (revision-status verification live on a device), fleet metrics (update adoption, version mix), and scenario questions — “show me what happens when a device misses a cycle,” “walk me through your battery-failure procedure,” “who can push a new application to the fleet, and what stops them pushing the wrong one?” That last question, trivial-looking, is a Part 6/7 question wearing an auditor’s blazer — which is tomorrow’s cue.

Tomorrow, Part 6 turns the rulebook inside out and asks the attacker’s questions instead: what’s the EFB’s attack surface, what has security research already demonstrated, and why does a $100 coin-sized device connected to real 737 avionics belong in this conversation?

Key Takeaways

  • EFBs are authorized operationally per operator — no regulator certifies the tablet itself; installed pieces (mount, AID, Type C) carry the airworthiness weight.
  • FAA: AC 120-76E guidance + OpSpec authorization. EASA: Reg (EU) 965/2012 + AMC 20-25 acceptance. ICAO Doc 10020 harmonizes both.
  • The approval process is SMS-shaped: policy → hazard register (5×5) → redundancy/battery/training → submission → authorization → audit loop.
  • FAA vs EASA differ in legal genealogy, converge on fundamentals: independence, procedural containment, revision control.
  • Part-IS (Regs (EU) 2022/1645 + 2023/203) makes information-security risk management an auditable obligation in Europe — organization duties from October 2025, the 22 Feb 2026 milestone for air operators, CAMOs and maintenance.
  • Inspectors check programs and evidence — including who can push changes to the fleet, which is a security question.

FAQ

Do EFBs need FAA approval?
The device doesn’t; the operator’s program does. Under AC 120-76E-based guidance, a US operator obtains EFB authorization through OpSpec paragraphs after building an approvable program — policy, risk assessment, training, backup procedures, configuration control.

What is OpSpec A050?
An operations specification paragraph under which US operators are authorized to use EFBs in lieu of paper [verify current designator and wording for your certificate]. OpSpecs are the legal instrument; the advisory circulars describe how to earn them.

What is EASA AMC 20-25?
EASA’s Acceptable Means of Compliance for electronic flight bags — the framework under which European operators structure portable and installable EFB programs within Regulation (EU) 965/2012, covering evaluation, redundancy and failure management.

Is EFB approval per operator or per device?
Per operator. The authority authorizes the operator’s program for defined equipment and applications. Individual devices gain meaning only inside that authorization — which is why fleet configuration control is a core approval element.

Are EFBs ICAO-standardized?
ICAO Doc 10020 (EFB Manual) provides the global harmonization reference that national rules implement. It is guidance for states rather than direct law, but most national frameworks are recognizably built on it.

What is EASA Part-IS?
The EU’s information-security rulebook for aviation: Delegated Regulation (EU) 2022/1645 (organization requirements, Part-IS.D.OR) and Implementing Regulation (EU) 2023/203 (authority requirements, Part-IS.AR), applicable from October 2025 and February 2026 respectively — making EFB cyber-risk assessment and mitigation auditable law in Europe.

How long does EFB approval take?
Typically months, not weeks — dominated by the operator’s own program build (risk assessment, training design, procedures) rather than authority review time. Scope creep across fleets and applications is the usual schedule killer.

References

  1. FAA, Advisory Circular 120-76E — Electronic Flight Bag (faa.gov)
  2. FAA, Advisory Circular 91-78A — Operational Use of Flight Deck EFBs; 14 CFR 91.21 / 121.306 (PED foundations)
  3. EASA, AMC 20-25 — Airworthiness and Operational Considerations for Electronic Flight Bags
  4. Commission Delegated Regulation (EU) 2022/1645 (Part-IS.D.OR) & Commission Implementing Regulation (EU) 2023/203 (Part-IS.AR) — applicable 16 Oct 2025 / 22 Feb 2026; EASA Easy Access Rules for Information Security
  5. Regulation (EU) No 965/2012 (air operations); EASA CS-ACDS (installed data systems) [verify status]
  6. ICAO, Doc 10020 — Electronic Flight Bag Manual; Annex 6; Doc 9859 — Safety Management Manual
  7. Transport Canada, AC 700-020 — Operational Use of EFBs

[← Part 4: EFB Data Pipeline] · [Series Hub] · Part 6: EFB Cybersecurity — Threats → (publishes Sep 9)

Parts publish daily through September 11 — bookmark the series hub for the full run.


Current as of September 2026 · standards verified against the latest revisions.
Educational reference only — always follow your operator’s approved EFB program and your NAA’s current guidance.
Author: hmmnm.com editorial team · hmmnm.com

Hmmnm
Published by Hmmnm

Hands-on cybersecurity tutorials, CVE breakdowns, and guided learning paths — written and lab-tested by the Hmmnm team.

🛡️ Hmmnm also delivers this expertise as a service — security testing, assessment & training.