· 12 minAirworthinessBlockchainEASACAMOTraceability

Airworthiness Review Reports: Choosing Your Proof Tool

Timestamping, integrity, auditability: what M.A.903(h) requires since 7 August 2026 is exactly what a distributed ledger can guarantee

Maintenance logbook and tablet in a hangar, with a cyan holographic chain of blocks symbolizing a blockchain ledger

EASA mandates no technology for the airworthiness review report: since 7 August 2026, Regulation (EU) 2026/100 requires a written, probative report retained for five years, without prescribing any tool — a shared PDF, a document management system or a distributed ledger all remain open options. The choice is yours, and the criterion for making it fits in one question: five years from now, facing an authority or a buyer who doubts, do you want to assert your report's date and integrity, or demonstrate them?

That criterion changes everything. If the answer is "demonstrate", neither one more PDF in a shared folder nor a tightened internal procedure will do: you need a proof layer that a third party can verify — and that is precisely what a tamper-proof ledger can deliver. Let's start with what the regulation actually requires.

What M.A.903(h) changes

We covered the full regulatory package in our article on Regulation (EU) 2026/100. The point that matters here is the new M.A.903(h), introduced by Commission Implementing Regulation (EU) 2026/100: "the details and the outcome of an airworthiness review shall be recorded in an airworthiness review report". Part-ML carries the same requirement in point ML.A.903(h). Points CAMO.A.220(a)(3) and CAO.A.090(a)(4) then require this report to be retained together with the ARC or the recommendation, and points CAMO.A.220(a)(7) and CAO.A.090(c) set a five-year retention period where the issuing organisation is not the one managing continuing airworthiness — a case that has become common now that the review may be entrusted to an independent organisation. The AMC and GM detailing the expected content were adopted on 6 July 2026 by EASA ED Decision 2026/005/R.

What was good practice therefore becomes a regulated record: a controlled template, a defined minimum content, an identified owner, a place in the record-keeping system, an enforceable retention period. And because the review may be performed by a third party, this report circulates between organisations — the continuing airworthiness manager, the review organisation, the competent authority, sometimes the aircraft's buyer. Every transfer raises the same question: how does the recipient know the document has not changed since it was signed?

What an auditor expects from a regulatory record

A regulatory record is only as good as three properties, all of them checkable in an audit:

  • Dated existence: being able to demonstrate that the report existed, in this form, on a precise date — not merely claiming it.
  • Integrity: being able to demonstrate that no line was altered after signature, including by someone with access to the server.
  • Long-term auditability: being able to produce the document and its proof five years later, before an authority or a buyer, without depending on the goodwill of a single internal system.

A PDF dropped into a shared folder offers none of these three guarantees in a demonstrable way. A file's modification date can be changed, a document can be rewritten, a server can be migrated: these systems were never designed to produce enforceable proof — precisely the gap the new requirement brings to light.

The decision to make: three options, one criterion

Faced with M.A.903(h), three postures are possible. The first is to produce the report like any internal document: compliant on the day it is signed, indefensible three years later. The second strengthens internal procedure — locked folders, access rights, in-house logging — which improves discipline without producing proof verifiable by a third party. The third adds an external proof layer: a fingerprint of the report, timestamped in a ledger no one can rewrite. The selection criterion fits in one question: five years from now, facing an authority or a buyer who doubts, do you want to assert or to demonstrate? If the answer is "demonstrate", only the third option goes the distance.

What a blockchain brings, without the jargon

A blockchain is a ledger of entries that no one — not even its operator — can alter or erase after the fact, and in which every entry is dated in a tamper-proof way. Applied to the review report, the method fits in one sentence: you do not publish the report on the blockchain, you record its fingerprint.

Concretely, when the report is signed, the system computes a cryptographic fingerprint of the file — a short string of characters that changes as soon as a single byte of the document changes — and writes it into the ledger with a timestamp. The document stays in the usual record-keeping system, under access control. Three practical consequences:

  • Proof of existence: the timestamped fingerprint demonstrates that this exact document existed on that date. It becomes impossible to "create" a report retroactively during an audit.
  • Proof of integrity: anyone holding the file can recompute its fingerprint and compare it with the one in the ledger. If they match, the document is unchanged; if any detail was touched up, the comparison fails.
  • Independent verification: the competent authority, the buyer or the customer can verify without depending on the software vendor or on access to the organisation's internal system. And since only the fingerprint is recorded, the report's content remains confidential.

Every new version of the report gets a new anchoring: the version history becomes a chain of proofs, which naturally answers the requirement of full traceability of a review process — from the documented review of records to the physical survey of the aircraft, which M.A.903 requires to be as close together in time as possible (M.A.903(e)).

1Review report signedrequired by point M.A.903(h)2Cryptographic fingerprint computedchanges as soon as one byte changes3Timestamped fingerprint in the ledgerthe document stays in the record-keeping system4Independent third-party verificationrecompute and compare the fingerprint

Anchoring a review report: the fingerprint goes to the ledger, the document stays in the record-keeping system.

The tool: the requirement ↔ ledger-property grid

Here is the full mapping, ready to use for scoping a specification or answering an audit question.

What the regulatory framework requiresBasisWhat a tamper-proof ledger demonstrates
Record the details and outcome of every review in a written reportM.A.903(h), ML.A.903(h)The fingerprint of the signed report is recorded at signature: the report exists, in this exact form
Retain the report with the ARC or the recommendationCAMO.A.220(a)(3), CAO.A.090(a)(4)The timestamped anchoring survives server migrations and vendor changes
Retain for five years when the issuer is not the managerCAMO.A.220(a)(7), CAO.A.090(c)The proof remains verifiable five years later, without depending on the issuer's internal system
Circulate the report between organisations (manager, reviewer, authority, buyer)M.A.901(c), M.A.901(e), M.A.901(i)Each recipient verifies integrity on its own, without access to the issuer's system
Trace the versions of the review process, from records review to physical surveyM.A.903, including M.A.903(e)Each anchored version forms a time-ordered chain of proofs
Protect the confidentiality of the contentContractual practiceOnly the fingerprint is published: the report's content never leaves the record-keeping system

Two rows of this grid are worth stressing. Proof of existence is the only solid answer to the scenario of a report "reconstructed" on the eve of an audit: without a dated anchoring, nothing distinguishes a report signed on the review day from one written three years later. And independent verification changes the dynamics of any transfer: the recipient no longer has to trust the issuer — it checks.

Bounded case: an ARC challenged three years after issuance

Take the most unfavourable — and most realistic — scenario. In 2026, an independent CAMO issues the ARC of a business jet after review, as point M.A.901(c) now allows, and records the report required by M.A.903(h). Three years later, in 2029, the aircraft is sold. During due diligence, the buyer raises a challenge: it suspects the review report was padded afterwards to hide a late-cleared finding, and demands proof that the document presented is indeed the one that existed on the ARC's date.

Without anchoring. The CAMO produces the PDF and its internal metadata. The buyer replies that a file date can be changed, that a server can be reinstalled, that the document system's event log is administered by the CAMO itself — an interested party. The dispute is settled on credibility, not facts: price negotiation, a warranty clause in the sale agreement, sometimes a new airworthiness review at the seller's expense. The CAMO, even acting in good faith, cannot demonstrate what it asserts.

With anchoring. The CAMO produces the report and the anchoring attestation: the document's fingerprint, recorded in the ledger on the day the ARC was signed, in 2026. The buyer — or its adviser — recomputes the fingerprint of the file it was handed and compares it with the one in the ledger. It matches: the document is unchanged since 2026, and the debate over anteriority is closed in minutes. Had the report been touched up, even by a single line, the comparison would fail and the discrepancy would be visible. The same demonstration works before the competent authority if it opens an inquiry into the ARC: the organisation produces the document and its proof, without having to persuade.

2026: ARC issued, review report recorded2029: the buyer challenges the reportWithout anchoring— Proof: PDF and internal metadata, challengeable— Dispute settled on credibility, not facts— Weeks of negotiation, warranty or new reviewWith anchoring— Fingerprint recomputed, compared to the ledger— Document unchanged since 2026: demonstrated— Anteriority debate closed in minutes

The same dispute, with and without anchoring: weeks of negotiation versus minutes of verification.

This case illustrates the central point: the value of the review report is not settled on the day it is signed, but on the day someone challenges it. That is the day the difference between a PDF and an anchored record is measured — in weeks of negotiation, or in minutes of verification.

The same trust problem, on the parts side

This need for tamper-proof records is not new in aviation: it has simply moved to the foreground. The AOG Technics case, revealed in 2023, showed it spectacularly: parts for CFM56 engines had been distributed with falsified certificates, and dozens of aircraft had to be grounded while histories were verified. The value of a part — like that of a review report — rests entirely on the credibility of its records. That is the lesson the industry is now drawing: GA Telesis, one of the world's leading MRO providers, unveiled in 2026 WILBUR, a blockchain-based registry designed to give every part, engine and airframe a single, verifiable lifecycle record, whose large-scale trials began in summer 2026. The airworthiness review report required by M.A.903(h) belongs to exactly the same movement: turning compliance documents into probative records.

What blockchain does not solve

The natural answer is not the magic answer. Four limits must be stated plainly, because they condition the real-world success of such a setup.

  • Bad input at the source. A tamper-proof ledger proves that a document has not changed since anchoring — it does not prove its content is accurate. A report recording a misread value, a miscopied serial number or a missed finding will be perfectly intact... and perfectly wrong. Anchoring shifts the stakes toward the quality of the review process itself: cross-checks before signature, staff competence, supervision. Cryptographic proof never substitutes for the reviewer's rigour.
  • Ledger governance. Who operates the ledger, who can write to it, what happens if the operator disappears? A closed proprietary registry, verifiable only through the vendor, recreates exactly the dependency it claimed to remove. Probative value depends on governance choices — open registry or consortium, public fingerprint standards, an exportable verification procedure — which are architecture decisions, not automatic properties of the technology.
  • Third-party adoption. The proof only has value if the authority, the buyer or the insurer agrees to verify it — and to accept it. Regulation (EU) 2026/100 is technology-neutral: it neither mandates nor mentions blockchain, and no authority is bound to recognise an anchoring. In practice, the demonstration is simple enough to be accepted in good faith, but it would be wrong to present the setup as regulatory recognition.
  • The cost-to-need ratio. For an organisation issuing three ARCs a year for its own aircraft, a rigorous internal procedure may suffice. The proof layer pays off when the report circulates — review decoupled from management, multi-customer fleets, aircraft transactions — that is, precisely in the configurations Regulation 2026/100 has just generalised.

Where to start

No need for a pharaonic project. A pragmatic implementation comes down to five points:

  1. Keep the report where it is: the existing record-keeping system remains the source of the document; the blockchain is only a proof layer.
  2. Anchor at signature: computing and recording the fingerprint must be part of the report's signature workflow, not a manual step afterwards.
  3. Anchor every version: any change results in a new signed and anchored version, never in a silent rewrite.
  4. Plan for third-party verification: a simple exportable fingerprint file lets an authority or a buyer verify on their side.
  5. Stay format-neutral: fingerprints to an open standard, a documented verification procedure — the proof must survive a change of software vendor.

Kepler's take: documentary proof becomes airworthiness infrastructure

Kepler's take: our conviction is that Regulation (EU) 2026/100 marks the moment when documentary proof stops being a matter of good internal housekeeping and becomes airworthiness infrastructure, on a par with the aircraft's technical records. As soon as the review report circulates between organisations and must hold for five years, the question "how do we prove" can no longer be left to each CAMO's improvisation: it calls for shared rails — standardised anchoring, independent verification, open formats. Organisations that lay these rails now will turn a regulatory constraint into a selling point: a demonstrable airworthiness history is worth money when an aircraft is resold.

Kepler Aviation builds this proof layer for airworthiness records within the Kepler Digitals ecosystem, which applies blockchain to aviation. To discuss securing your review reports, contact us.

Frequently asked questions

Is the airworthiness review report really mandatory?

Yes. Since 7 August 2026, points M.A.903(h) and ML.A.903(h) of Regulation (EU) No 1321/2014, as amended by Regulation (EU) 2026/100, require the details and the outcome of every airworthiness review to be recorded in a written report, retained together with the ARC or the recommendation.

How long must the review report be retained?

The report is retained together with the ARC or the recommendation. Where the organisation issuing the ARC or the recommendation is not the one managing the aircraft's continuing airworthiness, points CAMO.A.220(a)(7) and CAO.A.090(c) impose a five-year retention period.

Does EASA require the use of a blockchain?

No. The regulation is technology-neutral: it requires a reliable, retained and auditable record, without prescribing any tool. Blockchain is a means of demonstrating the report's timestamp and integrity, not a regulatory obligation.

Does the report itself need to be published on a blockchain?

No. What is written into the ledger is a cryptographic fingerprint of the signed document, together with a timestamp. The report stays in the organisation's record-keeping system; the fingerprint lets any holder of the document prove that it existed, unchanged, at a given date.

Does blockchain guarantee that the report's content is accurate?

No. It proves that a document existed at a given date and has not been modified since. It cannot detect an error or a falsification committed before anchoring: the quality of the source data remains the responsibility of the organisation and its review staff.

What is the link between airworthiness and parts traceability?

It is the same need: a history that can be proven not to have been falsified. The AOG Technics case (CFM56 parts distributed with falsified documents, 2023) and GA Telesis's WILBUR blockchain registry illustrate this need on the spare-parts side.

PB

Pierre Beunardeau

Founder of Kepler Aviation

A project, a regulatory question?

Kepler Aviation supports aviation stakeholders on AI, blockchain and document compliance. Let's talk about your needs.

Contact us