Skip to main content
ANTARES AGL & Industrial Control

Home / Method & compliance

Safety is not a project phase. It is the project.

A safety case cannot be reconstructed after the fact. It is built continuously, from the first site survey through to regular service verification — and the civil aviation authority is involved from the design stage onwards.

01 · Criticality tiers

Three tiers, three exit gates.

Each tier has its own functional scope, its own level of safety requirement and its own passing condition. Selling tier 3 before tier 1 has been delivered in real operation would be the single biggest risk in the programme — for you as much as for us.

TierScopeNaturePassing condition
P1 Supervision and operations
Read-only on the field side
Not safety-related. Status acquisition, synoptics, alarms, historisation, CMMS, analytics, national console. No write access to controllers or regulators — the link is one-way, physically and logically. Site acceptance, then 6 months of continuous operation with no blocking anomaly.
P2 Control of non-critical circuits Safety-related, limited criticality. Apron lighting, de-icing areas, service road lighting, obstacle lighting. Excludes runway, approach and stop bars. Safety case, risk assessment, changeover trials, authority approval.
P3 Full ALCMS Safety-related, high criticality. Control of runway, taxiways, approach, stop bars, low visibility operations up to CAT III, Follow-the-Greens guidance. Complete safety case, demonstrated software lifecycle, in-service trials, formal approval.

02 · Functional safety

Seven requirements we impose on ourselves.

Ref.CriticalityRequirement
CNF-01MandatoryAn operational risk assessment is produced for each tier: hazardous events, their consequences on operations, and the barriers put in place. Revised at every significant functional change.
CNF-02MandatoryFail-safe principle: any loss of communication, computing or power in the supervision layer leaves the lighting in its current state and reports it explicitly to the operator. No spontaneous extinction.
CNF-03MandatoryPermanent visual distinction between measured state, commanded state and stale data. Any value whose freshness exceeds the configured threshold is flagged invalid, never displayed as valid.
CNF-04MandatoryCritical tier P3 safety interlocks are implemented at controller level, independently of the supervision software. Supervision can neither bypass nor disable them.
CNF-05MandatoryDocumented software lifecycle: traced requirements, design reviews, automated testing, configuration and defect management. The requirement → design → test → result traceability matrix is a contractual deliverable.
CNF-06ImportantFor tier P2 and P3 functions, a recognised software safety assurance approach — EUROCAE ED-153 or equivalent — with the assurance level justified by the risk assessment.
CNF-07ImportantRegister of waivers and operating limitations, kept up to date and issued to the operator with every release.

Applicable framework

ReferenceScope for the product
ICAO, Annex 14, Vol. IBaseline framework: characteristics of visual aids, lighting monitoring requirements, availability thresholds per operating category, secondary power supply and changeover times.
ICAO, Doc 9157 (parts 4 and 5)Aerodrome Design Manual: visual aids and electrical systems. Guides the design of synoptics and of the operating rules implemented.
ICAO, Doc 9476 and 9830SMGCS and A-SMGCS: the framework for surface guidance, stop bars and Follow-the-Greens at tier P3.
FAA AC 150/5345-56BL-890 system specification: minimum ALCMS requirements and monitoring levels. The highest level is the tier P3 target.
EASA CS-ADR-DSNCertification specifications for aerodrome design: the European design framework, used for export.
IEC 61821 · 61822 · 61823Airfield lighting electrical installations: maintenance of series circuits, constant current regulators, isolating transformers. Frames the measurements acquired and the thresholds implemented.
IEC 62305 and 60364Lightning protection and low voltage installations: determines the architecture of substation acquisition enclosures.
ISO/IEC 25010Software quality model: the framework for demonstrating the non-functional requirements.
National regulationAeronautical regulations and directives of the Moroccan civil aviation authority; Law 05-20 on cybersecurity and its national directive; Law 09-08 on the protection of personal data.

03 · Cybersecurity

Zones, conduits, and nothing leaving without your consent.

Airfield lighting is critical national infrastructure: it falls within the scope of Law 05-20 and of the national information systems security directive. The security architecture follows the zones and conduits model of the IEC 62443 series.

Ref.CriticalityRequirement
SEC-01MandatoryDocumented zones and conduits partitioning, with a target security level justified per zone. Strict separation of the operational and office networks, with no direct gateway.
SEC-02MandatoryNo direct internet exposure of any supervision component or below. All outbound traffic passes through a demilitarised zone under the operator's control.
SEC-03MandatoryNamed authentication for all access, two-factor for any role holding control or administration rights. No generic accounts, no default passwords at delivery.
SEC-04MandatoryRole-based access control with separation of privileges: read, operate, control, maintain, administer, audit. No single account ever combines administration and audit.
SEC-05MandatoryTamper-proof audit log of all actions, logins, configuration changes and acknowledgements. Timestamped, exported to an external collector, protected against deletion including by an administrator.
SEC-06MandatoryEncryption of all application traffic, including internal traffic, using TLS with certificates managed by a public key infrastructure. Backups encrypted at rest.
SEC-07MandatoryRemote maintenance permanently disabled: remote access is enabled on request, time-limited, named, logged, recorded, and revocable unilaterally by the operator.
SEC-08MandatoryData hosted on national territory. No operational data, no log and no backup leaves the Kingdom without the operator's written authorisation.
SEC-10ImportantVulnerability management: monitoring of delivered components, patches qualified within 30 days for critical vulnerabilities, documented emergency procedure.
SEC-11MandatoryPenetration testing by an independent third party before every site commissioning, and annually thereafter. Critical and major vulnerabilities block acceptance.
SEC-12ImportantCyber continuity and recovery plan: site isolation procedure, fallback to local control, restoration procedure validated in an annual exercise.

04 · Deployment

Airfield lighting cannot be switched off.

The airports concerned are in operation, several of them around the clock. The whole deployment strategy follows from that: the existing system remains master and operational throughout the connection phase.

  • No operational interruption attributable to the deployment.
  • Substation work planned in low-traffic windows, coordinated with operations and air traffic control.
  • 60 days minimum of parallel running: new system observing, old system master, every discrepancy analysed.
  • Rollback procedure tested before every cutover, executable in under 30 minutes, under a designated cutover manager.
  • One complete pilot site before any wider rollout.

Recommended sequence

STEP 1

Pilot site

A medium-sized airport with a recent, well-documented estate, at tier P1 only. Objective: validate the core, the acquisition drivers and the HMI under real conditions.

STEP 2

Regional rollout

Three to five airports with different profiles, including one with an ageing estate, to put the manufacturer abstraction layer to the test.

STEP 3

National console

Aggregation brought into service as soon as at least three sites are reporting stable data.

STEP 4

Major airports

Connection of the hubs, with reinforced availability and cybersecurity requirements.

STEP 5

Tier P2, then P3

Undertaken site by site, after the safety case and approval. Never as a simultaneous rollout.

05 · Validation and acceptance

Seven stages, each with its own passing criterion.

StageLocationContent and passing criterion
Unit and integration testsContinuous integrationAutomated, run at every release. Coverage of operating rules and availability calculations across 100 % of traced functional requirements.
Factory acceptance testANTARES test benchFull site simulator reproducing regulators, controllers and faults. Replay of operating and failure scenarios. No blocking or major anomaly left open.
System integration testsTest bench + real equipmentVerification of every acquisition driver against the equipment actually present on the target site, including degraded modes and out-of-range values.
Site acceptance testAirportPoint-to-point verification of every acquired state, server failover trials, power and link outage trials, load testing.
Security testingAirportPenetration test by an independent third party, configuration review, verification of zone segregation. Critical and major vulnerabilities are blocking.
Operational trialsAirportScenarios played by real operators: circuit failure during operations, power loss, low visibility operations, loss of the national centre, rollback.
Regular service verificationAirport60 days of parallel running with no blocking anomaly and no unexplained state discrepancy. Condition for final acceptance.

Milestones of a pilot package (tier P1)

MilestonePurposeTimingExit deliverable
J0Kick-offT0Specification frozen, pilot scope agreed, steering committee established.
J1Detailed designT0 + 2 monthsArchitecture dossier, data model, tier P1 risk assessment, HMI mock-up validated by operators.
J2Pilot site surveyT0 + 3 monthsAsset inventory, circuit drawings, data point matrix, acquisition driver specification.
J3Factory acceptanceT0 + 7 monthsFAT report, traceability matrix, automated test report.
J4Connection and site acceptanceT0 + 9 monthsSAT report, penetration test report, as-built documentation.
J5Commissioning in observationT0 + 10 monthsStart of parallel running, operators trained and authorised.
J6Final acceptanceT0 + 12 monthsRegular service verification report, pilot review, rollout decision.

Contractual deliverables

  • Technical architecture dossier and detailed design dossier.
  • Operational risk assessment and register of operating limitations, per tier.
  • Requirement → design → test → result traceability matrix, maintained at every release.
  • Cybersecurity dossier: zones and conduits, reference configuration, penetration test report.
  • Operations, maintenance and administration manuals, in French and Arabic.
  • As-built documentation per site, wiring drawings and delivered configuration.
  • Training material and certificates, skills transfer plan.
  • Software bill of materials, licences and source code escrow terms.

Risks we address head-on

RiskControl measure
Scope creep towards critical control before maturityTiers written into the contract, control layer absent from the P1 delivery, formal safety gate.
Manufacturer interfaces closed or undocumentedInterfaceability survey from milestone J2; fallback to physical acquisition through a controller.
Asset data missing or out of dateSurvey and asset register construction budgeted as a package in their own right.
No work windows availableJoint planning from J1; design allowing connection without taking a circuit out of service.
Authority approval delaysAuthority involved from the design stage; safety case built continuously.
Rejection by operatorsOperators involved in HMI design from J1; usability evaluation blocking for acceptance.

Tenders

Writing an ALCMS specification?

We are happy to share our requirements template — tiers, safety, cybersecurity, acceptance. Even if you consult other suppliers, a well-built specification protects you: it makes bids comparable and stops anyone selling you tier 3 on a slide deck.