
Link Coverage 100%, ASPICE Assessment Still at Risk.
100% link coverage does not mean ASPICE compliance. How a type check, a consistency check and a consistency score expose semantic inconsistencies with LLMs.
Read Article
Pierre Dammé
7 min readHolistic protection and seamless traceability for cybersecurity, functional safety, and the Cyber Resilience Act
OverviewMethodological excellence and tailored tools for model-based system and software engineering.
OverviewEnterprise software from a single source: AI integration, legacy migration and full-stack development — cost-efficiently and sovereignly hosted.
OverviewExpert knowledge on Compliance Intelligence, Model-Based Engineering and Custom Software Development.
Topic area
Format

100% link coverage does not mean ASPICE compliance. How a type check, a consistency check and a consistency score expose semantic inconsistencies with LLMs.
Read Article
Pierre Dammé
7 min read
Decision guidance from 20 years of project experience: when a custom DSL pays off, when a UML/SysML profile is the better choice, and how to get from domain analysis to a productive tool.
Download Whitepaper
SysML v2 promises cleaner concepts, a textual notation, and a standard API. But does switching pay off? Pros and cons, an ROI perspective across three starting points, and an honest assessment of who should switch and who is better off staying.
Read Article
Benjamin Alders
8 min read
The Item Definition sets the quality ceiling for the whole TARA — what abstraction level is right, why SBOM mapping forces a minimum resolution, and why a living model is the foundation for API and MCP integrations.
Read Article
Jens Bühl
9 min read
Independence is assessed once in a DFA workshop and never revisited. This whitepaper shows how the independence premise in ASIL decompositions can be verified continuously and machine-executed using graph theory.
Download Whitepaper
From risk definition to a living TARA: a 7-part guide to systematic cyber risk assessment, with direct mappings to CRA, ISO/SAE 21434, and IEC 62443.
Download Whitepaper
The CRA doesn't ask for a one-time risk analysis — it demands a permanently demonstrable security engineering process. How a Living TARA and the Security Digital Thread keep your risk picture continuously current and audit-ready.
Read Article
Dirk Leopold
6 min read
Excel template for CRA risk analysis: TARA in line with ISO 21434 and IEC 62443 — how to start methodically, what you can import, and when Excel becomes the bottleneck.
Read Article
Jens Bühl
6 min read
Compare systems, not models. Whether a self-hosted open-weight model holds up is decided by the context you assemble, the tools it can call, the checks it has to pass and the training data your workflow produces on its own. Christoph Hess sets out five engineering levers and the conditions under which each one pays off.
Download Whitepaper
SysML v2 is not v1.8. This guide gives systems engineers a transferable mental model (not a mechanical element mapping) for making the transition with confidence.
Download Whitepaper
System Composer or a SysML tool for your architecture modeling? A comparison across requirements handling, simulation, onboarding, stakeholder views, AI integration, and cost — and why the answer depends on your project.
Read Article
Benjamin Alders
7 min read
Evaluating Your Migration Options — a joint session with itemis and Haulmont on life after Camunda 7's end of life.
Watch Webinar
Combining knowledge graphs and LLM agents for automated process assessment: how to cut ASPICE preparation from 23 weeks to 6.
Download Whitepaper
How the Portalon plugin connects AI coding agents like Claude to the live model of a JetBrains MPS project via MCP — structurally safe edits, validation, and language-engineering skills, on your current MPS version.
Read Article
Dr. Klaus Birken
10 min read
Why dynamic behavior belongs in the interface contract: protocol state machines formally specify the allowed order of events – with Franca IDL as an example and a look at Dezyne, P, and session types.
Read Article
Dr. Klaus Birken
8 min read
A TARA is not a threat catalogue — it is an auditable record of risk decisions: what it involves, how the process works, and when Excel reaches its limits.
Read Article
Jens Bühl
6 min read
CRA Article 14 reporting obligations take effect on 11 September 2026. This article walks through the complete notification process chronologically — from the initial assessment to the final report — and identifies the points where reporting processes break down in practice.
Read Article
Dirk Leopold
12 min read
How to use UML profiles in Enterprise Architect and how to process profiled models with the Eclipse-based EA-Bridge for code generation using Xtend.
Read Article
Dr. Patrick Könemann
6 min read
How to extend Enterprise Architect with add-ins: model assistants, integrity checks, and installer-based rollout — and which tasks are better handled by external tools like the EA-Bridge.
Read Article
Dr. Patrick Könemann
7 min read
How Eclipse with Xtend and the Java-based EA-Bridge provides a proven alternative to EA's built-in code generation — and how the AUTOSAR Consortium uses this approach headlessly at scale.
Read Article
Dr. Patrick Könemann
6 min read
How the Eclipse-based EA-Bridge loads Enterprise Architect models as Eclipse UML models, reports syntactical errors, and enables custom validation rules with quick fixes.
Read Article
Dr. Patrick Könemann
5 min read
An honest, detailed comparison of three leading statechart tools — MathWorks Stateflow, IBM Rhapsody, and itemis CREATE — covering features, pricing, and which tool fits which team.
Read Article
Axel Terfloth
7 min read
How the itemis EA Bridge provides Enterprise Architect models as stable, machine-readable data, enabling custom code generation, validation, and documentation tooling.
Read Article
Dr. Patrick Könemann
10 min read
Best-of-breed or all-in-one suite? A look at the real trade-offs in engineering toolchain strategy — and why tool suitability should always come first.
Read Article
Dr. Alexander Nyßen
5 min read
Collaborative modeling workshops are valuable — but drawing pictures isn't MBSE. If you can't validate, derive, or generate from your models, you're missing the point.
Read Article
Dr. Alexander Nyßen
6 min read
How the itemis EA Bridge turns Enterprise Architect from an isolated modelling tool into a data supplier: validation, code generation, report generation and AI reasoning, performant and platform-independent.
Read Article
Dr. Patrick Könemann
7 min read
How to hand the bulk of software development to AI agents – and still get a result you can trust. A practitioner's look at vertical agents and horizontal skills for enterprise software teams.
Read Article
Arne Deutsch
8 min read
AI can now produce TARAs, traceability matrices, and safety cases that are structurally complete and terminologically correct. That surfaces a question worth asking: what, exactly, is being verified? The problem is not AI-generated documentation. It is compliance processes that optimize for artifacts instead of the properties those artifacts were supposed to encode.
Read Article
Florian Antony
6 min read
An unreachable transition, an unsatisfiable guard, a numeric overflow: these bugs hide in the model long before any test reveals them. A results report from two master's theses on formal error detection for state machines using symbolic execution and SMT solvers.
Read Article
Andreas Mülder
9 min read
How AI assistants reduce TARA creation from weeks to hours — and turn your threat analysis into a real competitive advantage.
Watch Webinar
Jens Bühl
Learn how TARA automation with itemis SECURE (formerly YAKINDU Security Analyst) makes cybersecurity processes in the automotive industry fundamentally more efficient.
Watch Webinar
Jonathan Mohring
Forget high-stress assessments with massive teams and mountains of manual documentation. Discover how to make a leap from five weeks to five hours.
Watch Webinar


itemis ANALYZE moves to the cloud — unlocking a new era of Agentic Engineering where your Knowledge Graph becomes the governance layer for your AI.
Watch Webinar


Your TARA is a compliance document. It should be the operational brain of your CSMS. This whitepaper shows how a Living Digital Thread transforms static security artifacts into a continuous, data-driven lifecycle operation.
Download Whitepaper
How leading OEMs and Tier-1 suppliers unite Functional Safety and Cyber Security enterprise-wide — without disrupting proven engineering environments.
Download Whitepaper
AI-driven development rarely fails because of the code – it fails because of aimlessness. Why technology is only half the battle and what really determines project success.
Read Article
Holger Schill
4 min read
Will your product still be legally sellable in Europe after December 2027? This guide shows manufacturers how to approach CRA compliance in 7 structured steps and secure EU market access.
Read Article
Dirk Leopold
5 min read
itemis SECURE is now available on the web — collaborate on cybersecurity projects simultaneously from any device, just like Google Docs.
Watch Webinar


Camunda 7 CE is reaching end-of-life. Operaton and the OpenBPM Platform offer a powerful open alternative – with minimal migration effort and maximum future-proofing.
Read Article
Karsten Thoms
2 min read
A design FMEA is mandatory under ISO 26262 — and expensive to create and maintain by hand. This whitepaper shows how the algorithmic nature of the FMEA method enables full automation from existing engineering work products.
Download Whitepaper
The biggest barrier to MBSE adoption isn't tooling — it's the SysML learning curve. This whitepaper shows how natural language patterns and model generation turn your existing requirements into formal SysML v2 models, without training your entire engineering team.
Download Whitepaper
Loosely coupling feature models to development artifacts is convenient – but it has hidden risks. This article shows the advantages of tight integration: early error detection, implicit variation points, and automatic consistency checks.
Read Article
Dr. Klaus Birken
6 min read
Transitioning from static diagrams to executable models in requirements engineering enhances precision and testability in system design.
Read Article
Andreas Mülder
6 min read
With software-defined vehicles, the start of production is no longer the end of development — a holistic approach to security is now essential.
Watch Webinar
Dirk Leopold
Lessons learned from migrating itemis CREATE, a 280K LOC Eclipse-based application, to the web and Visual Studio Code over two years.
Read Article
Andreas Mülder
10 min read
Modelix brings domain-specific languages to non-developers as a modern web application — while seamlessly integrating with powerful tools like JetBrains MPS.
Watch Webinar
Leading experts share why Automotive SPICE 4.0 is a cornerstone of automotive development and what the new version means for your projects.
Watch Webinar
Dynamic-TARA by VicOne and itemis automates vulnerability detection and feeds it directly into comprehensive threat analysis and risk assessment.
Watch Webinar
Find out how Artificial Intelligence is transforming the mobility industry – with practical examples from Deutsche Bahn and itemis experts.
Watch Webinar
Christoph Hess
See how andsafe AG leverages the cloud for impressive InsureTech growth and how itemis delivers a methodical approach to migrating legacy systems.
Watch Webinar
Karsten Thoms
UN Regulation No. 155 hits motorcycles on July 1st 2029 — discover how to prepare your organization for the homologation challenge and emerging cyber threats.
Watch Webinar
Dirk Leopold
Discover how AI and model-based systems engineering converge to set new industry standards in transportation.
Watch Webinar
See how itemis CREATE streamlines state machine development and testing in embedded systems — illustrated with a practical Turn Signal Control case study.
Watch Webinar
Axel Terfloth
See how itemis CREATE enables fast statechart development in the cloud, with AI-assisted model generation and seamless Git-based version control.
Watch Webinar


No global visions — just what's feasible today. Our speakers share unique perspectives on AI technologies already integrated into MBSE workflows.
Watch Webinar
Dr. Alexander Nyßen
Understand the present challenges in risk management for OEMs and suppliers and learn how best-of-breed toolchains and knowledge graphs deliver real value.
Watch Webinar
Dirk Leopold
Discover how to map threat intelligence with TARA, enable dynamic risk assessments, and reduce mistakes while saving time and cost.
Watch Webinar
Florian Antony
Learn which strategies finance and insurance companies use to modernize legacy systems and prepare for a digital future.
Watch Webinar
Holger Schill
How threat analyses (TARAs) and secure data exchange protect the EV ecosystem — from charging infrastructure to the vehicle itself.
Watch Webinar
Dirk Leopold
Most SE failures aren't caused by wrong tools — they're caused by wrong practices. Dr. David Akehurst distills years of field experience into ten concrete, actionable improvements that transform how engineering teams specify, model and deliver complex systems.
Download Whitepaper
Learn how model-based TARA tooling combined with knowledge graphs enables CSMS automation for type approvals and gives you the competitive edge.
Watch Webinar
Jonathan Mohring
Learn how to efficiently manage the TARA process, keep your TARAs up-to-date, and apply the 20-50-90 Rule to significantly reduce cybersecurity spend.
Watch Webinar
Dirk Leopold
Part 2 explores domain-specific languages, language workbenches such as Xtext and MPS, and the role of the language engineer in modern software development.
Read Article
Dirk Leopold
9 min read
What are models, abstractions, and meta models? Using LEGO® as an analogy, this article introduces the foundations of modeling and language engineering.
Read Article
Dirk Leopold
6 min read
ISO/SAE 21434 raises the bar for automotive cybersecurity — from company-wide CSMS governance to threat analysis and product-level security controls. This guide, co-authored by itemis and Deloitte, walks you through every clause that matters.
Download Whitepaper
Learn why transitioning from spreadsheet-based TARAs to automated processes is essential and how to harmonize your TARA landscape across OEMs and suppliers.
Watch Webinar
Jens Bühl
For CFOs and auditors, a new family of threats and controls is emerging: cybersecurity controls and audit reports for their companies' connected products.
Watch Webinar
Dirk Leopold
ISO/SAE 21434 and UN Regulation 155 require cybersecurity across the full vehicle lifespan — from development through maintenance to decommissioning. Learn the most important lifecycle aspects and best practices.
Watch Webinar


Get an overview of threat and control catalogs that speed up your ISO/SAE 21434 compliant TARAs throughout the entire vehicle lifespan.
Watch Webinar
Jens Bühl
UN Regulation 155 and ISO/SAE 21434 require the entire automotive industry to ensure security over the entire lifespan of the vehicle.
Watch Webinar


UN Regulation 155 and ISO/SAE 21434 require the entire automotive industry to ensure security over the entire vehicle lifespan — from development through maintenance to decommissioning.
Watch Webinar
Dirk Leopold
Traceability is more than a compliance checkbox. Learn what it means in software and systems engineering, what insights it unlocks, and what challenges come with it.
Read Article
Florian Antony
5 min read
Business logic and technical code in legacy systems mix over the years — with serious consequences. What this means and what you can do about it.
Read Article
Arne Deutsch
4 min read
When does automated modernization of legacy systems make sense? An analysis of the opportunities, limits, and appropriate transformation tools.
Read Article
Karsten Thoms
7 min read
In the automotive domain, security is becoming more and more important – especially for the new generations of connected, (semi-)autonomous vehicles. Learn how to develop a secure system design and which additional security challenges may arise.
Read Article
Dirk Leopold
9 min read
How Franca IDL and itemis CREATE can be integrated to validate embedded software components against interface contracts interactively during development.
Read Article
Dr. Klaus Birken
9 min read
How itemis CREATE adds higher-level modeling, simulation and unit testing on top of the SCXML standard.
Read Article
Andreas Mülder
5 min read
In times of Spectre and Meltdown it's totally clear that security is a big engineering challenge. Learn more about safety and security in this post.
Read Article
Dirk Leopold
8 min read
The increased share of software solutions places high demands on Automotive Security. But what changes are coming for the industry and manufacturers?
Read Article
Dirk Leopold
5 min read
How to apply Test-Driven Development to model-driven software development using SCTUnit, itemis CREATE's unit testing framework for statechart models.
Read Article
Axel Terfloth
6 min readA requirements traceability matrix is not just a bookkeeping tool. Learn the five key questions it answers in day-to-day project work — plus one bonus question.
Read Article
Florian Antony
6 min read
Requirements coverage is demanded by process standards like Automotive SPICE, yet remains poorly defined. Learn what it really means and how to measure it properly.
Read Article
Florian Antony
6 min read
State machines can not only be modeled. In part 5 we present the State Pattern as an implementation variant.
Read Article
Rainer Klute
11 min read
Learn how to program an MSP430 microcontroller with state machines using itemis CREATE, fully integrated in Code Composer Studio – with automatic code generation and a graphical editor.
Read Article
Robin Herrmann
3 min read
A requirements traceability matrix (RTM) is a simple table that establishes bidirectional traceability across your project. Learn what it is and how to build one in four steps.
Read Article
Florian Antony
5 min read
An empirical study with 71 subjects shows that requirements traceability leads to 24% faster task completion and 50% more correct solutions during software maintenance.
Read Article
Florian Antony
4 min read
State machines can be modeled – but how can they actually be implemented? For example with the help of state tables.
Read Article
Rainer Klute
8 min read
How do modeled state machines become program code? For example with the help of a switch statement. We show how the implementation works.
Read Article
Rainer Klute
6 min read
Learn how to ensure traceability for your itemis CREATE statechart models – with tool support that scales beyond manual trace links.
Read Article
Andreas Mülder
5 min read
In part 2 of the series we cover time-controlled triggering of state transitions, orthogonal regions, and composite states with subdiagrams.
Read Article
Rainer Klute
8 min read
How do state machines work and why should you use them? This post illustrates the modeling of a finite state machine using the example of a blind controller.
Read Article
Rainer Klute
6 min read
How to use entry points, exit points, and final states in state machine modeling with itemis CREATE.
Read Article
Axel Terfloth
5 min read