ISO 26262 (Functional Safety for Road Vehicles)
ISO 26262 is the international standard for the functional safety of electrical and electronic (E/E) systems in road vehicles. It is derived from IEC 61508, defines an automotive-specific risk scheme with ASIL A to D and covers the entire safety lifecycle — from the concept phase through development to production, operation and decommissioning.
Structure: twelve parts along the safety lifecycle
The current second edition (2018) is divided into twelve parts:
| Part | Content |
|---|---|
| 1 | Vocabulary |
| 2 | Management of functional safety |
| 3 | Concept phase: item definition, HARA, functional safety concept |
| 4 | Product development at the system level |
| 5 | Product development at the hardware level |
| 6 | Product development at the software level |
| 7 | Production, operation, service and decommissioning |
| 8 | Supporting processes — including verification, configuration management, tool qualification |
| 9 | ASIL-oriented and safety-oriented analyses — including ASIL decomposition |
| 10 | Guidelines on applying the standard |
| 11 | Application to semiconductors |
| 12 | Adaptation for motorcycles |
Parts 11 and 12 were newly added with the second edition. At the same time, the scope was extended: while the first edition (2011) applied to passenger cars, since 2018 the standard has covered series production road vehicles as a whole — including trucks, buses and trailers.
V-model and safety lifecycle
In ISO 26262, product development follows a V-model — at the system level (Part 4) and, below that, in parallel for hardware (Part 5) and software (Part 6). On the left branch, the safety goals determined in the HARA are refined step by step into functional and technical safety requirements and transferred into an architecture; the right branch demonstrates through integration, verification and testing that every requirement is fulfilled. This end-to-end derivation chain from safety goal to test case must be documented traceably — the standard requires traceability between requirements, implementation and verification.
ASIL: graded rigour instead of blanket requirements
At the core of the standard is the risk-based approach: not every vehicle function is treated with the same rigour. The hazard analysis and risk assessment (HARA) according to Part 3 rates each hazard by severity (S), exposure (E) and controllability (C) and derives the classification QM or ASIL A to D from this. The higher the ASIL, the stricter the requirements — for example regarding test coverage, architectural metrics and the independence of verification instances. From ASIL C, the method tables of the standard highly recommend semi-formal methods for specification and software architectural design. Part 9 additionally allows ASIL decomposition: splitting a high safety requirement across redundant, demonstrably independent elements with a lower ASIL.
ISO 26262 in practice
ISO 26262 is not a legal regulation, but it is considered state of the art — OEMs contractually require compliance along the supply chain, and in a liability case a deviation becomes subject to justification. In practice, the biggest hurdles lie less in understanding the standard than in implementing it across tool boundaries: end-to-end traceability from the HARA to the test result, the qualification of the development tools used according to Part 8, and maintaining the work products in the face of late system changes. Anyone who treats the HARA and the safety case as frozen documents ends up working against copies with every change — and loses the consistency the assessor wants to see.


