Other meanings of Future Airborne Capability Environment
MILITARY AVIONICS
Future Airborne Capability Environment (FACE) is an open avionics software standard for military airborne systems. It defines a portable, modular approach for integrating software components across aircraft, mission computers, and embedded platforms, reducing dependence on a single vendor or processor family. The standard is maintained through the FACE Consortium under The Open Group and is intended to support reuse, interoperability, competition, and more manageable modernization cycles.1
FACE separates airborne software into portable components and the platform services that host them. The standard defines interfaces and conformance requirements for software components, operating-system services, input and output, and transport mechanisms rather than prescribing one aircraft computer or one programming language. Its central architectural idea is a partition between a portable components segment and a platform-specific services segment. A component can therefore be developed against standardized interfaces while lower-level details—such as processors, device drivers, buses, and real-time operating systems—remain with the platform integrator.
FACE is closely associated with modular open systems approach practices in defense acquisition. The objective is not simply to make software publicly available, but to establish controlled interfaces that let separately supplied modules be integrated and replaced without redesigning an entire avionics suite.
FACE conformance is established through a technical standard, an editorial and governance process, and verification of products against defined requirements. The Open Group publishes the standard and supports a certification program intended to provide evidence that a product conforms to the applicable FACE requirements. Certification does not mean that a component is automatically suitable for every aircraft: system safety, security, timing, assurance, configuration, and platform-integration obligations remain the responsibility of the program.
The standard uses concepts familiar from POSIX, including portable operating-system interfaces, while adding aviation-oriented architectural and data-exchange requirements.2 A conformant product may be a software component, an operating-system environment, or another element defined by the relevant FACE segment and conformance category. This distinction prevents “open” from being treated as a single binary property.
FACE is intended to shorten the path from software development to deployment by allowing qualified components to be reused across platforms with less bespoke integration. Typical targets include mission applications, communications functions, navigation and sensor processing, stores management, and other airborne mission-computing capabilities. A program can procure a component separately from the aircraft platform, provided its interfaces, performance, assurance evidence, and cybersecurity properties meet the system’s needs.
The practical benefit is greatest when a program establishes interface requirements early and maintains them across the life cycle. FACE can support competition and technology insertion, but it cannot eliminate integration work: differences in timing, memory, sensor semantics, safety levels, security domains, and hardware acceleration can still require adaptation. U.S. defense acquisition policy increasingly treats modularity and defined interfaces as tools for avoiding vendor lock-in and enabling incremental upgrades.
FACE is an ecosystem and governance framework as much as a software interface specification. Its less visible work includes conformance units, verification evidence, supplier coordination, terminology, and the boundaries between portable code and platform-specific services.1 This matters because portability is conditional: a component may be portable at the source or binary-interface level yet still need testing on the target aircraft.
Another subtle feature is the standard’s accommodation of different assurance and performance needs. A safety-critical flight-control function and a less critical mission-planning application do not necessarily share the same certification path, operating environment, or timing demands. FACE therefore provides architectural categories rather than a universal runtime. Its long-term significance lies in making these boundaries explicit, allowing aircraft programs to combine legacy systems with newer software while preserving a defensible integration and assurance process.
FACE requirements and certification criteria can change between standard editions; procurement documents should identify the applicable edition, conformance category, and assurance obligations.
Help improve the encyclopedia. Reports go straight to the site manager.