What is ISO 26262 Functional Safety?

ISO 26262 functional safety is the international standard for the safety of electrical and electronic (E/E) systems in road vehicles. Published by ISO (International Organization for Standardization), it defines a systematic, risk-based approach to identifying hazards caused by malfunctioning E/E systems, assigning Automotive Safety Integrity Levels (ASIL), and demonstrating that safety requirements have been met throughout the development lifecycle.

ISO 26262 functional safety applies to all vehicle types with production volumes greater than one per year, covering the complete development lifecycle from concept through production, operation, and decommissioning.

ASIL Classification: The Core of ISO 26262 Functional Safety

ASIL classification is the process of determining the required safety integrity level for a safety goal, based on a systematic hazard analysis and risk assessment (HARA). ISO 26262 defines four ASIL levels:

  • ASIL A: Lowest integrity level — single-point failures with low probability of causing severe harm. Example: exterior lighting failure.
  • ASIL B: Moderate integrity — failures that could cause injury. Example: windscreen wiper failure in rain.
  • ASIL C: High integrity — failures causing serious injury. Example: power steering failure at speed.
  • ASIL D: Highest integrity — failures potentially causing fatalities. Example: brake-by-wire failure, airbag deployment system failure.

ASIL classification is determined by three factors from HARA: severity (S0–S3), exposure (E0–E4), and controllability (C0–C3). The combination maps to an ASIL level or QM (Quality Management — not safety-critical).

ASIL decomposition allows a single ASIL D requirement to be split into two independent ASIL B subsystems, each developed separately with redundancy, making high-ASIL system development more practical.

The ISO 26262 Automotive Safety Lifecycle

The automotive safety lifecycle defined by ISO 26262 covers five main phases:

  1. Concept Phase: Item definition, HARA, and derivation of safety goals with ASIL ratings.
  2. System Level: Functional Safety Concept (FSC) — allocating safety requirements to system elements, designing safety mechanisms (redundancy, monitoring, fail-safe states).
  3. Hardware Level: Hardware safety analysis (FMEA, FTA), ASIL-specific hardware architectural metrics (SPFM, LFM, PMHF targets).
  4. Software Level: Software Safety Requirements, ASIL-appropriate software design (coding guidelines, static analysis, coverage targets).
  5. Safety Validation and Confirmation: Verification, testing, and generation of the Safety Case demonstrating that all safety goals are met.

ISO 26262 is structured as a V-model: requirements flow down from concept through hardware and software design, and verification activities confirm compliance at each level on the way back up. Our Product Engineering Services support the development of safety-critical automotive products through robust design, engineering, validation, and lifecycle management.

Key ISO 26262 Work Products

ISO 26262 functional safety requires specific documentation artefacts as evidence of compliance:

  • Item Definition (Part 3)
  • Hazard Analysis and Risk Assessment (HARA)
  • Functional Safety Concept (FSC) and Technical Safety Concept (TSC)
  • Hardware Design Specification and Safety Analysis (FMEA, FTA)
  • Software Architecture Specification and Unit Test Reports
  • Safety Case (the complete argument that safety goals are met)
  • Dependent Failure Analysis (DFA)

ISO 26262 Functional Safety in Practice: Common Challenges

Achieving ISO 26262 functional safety compliance presents several engineering and organisational challenges:

TCS Control Loop​
  • ASIL decomposition strategy: Choosing where to decompose high-ASIL requirements to manage development cost while maintaining independence between elements.
  • Freedom from Interference (FFI): Demonstrating that software partitions do not interfere — critical for mixed-ASIL software on the same processor or OS.
  • Legacy code integration: Bringing existing software into an ASIL-appropriate development process retroactively.
  • Tool qualification: Software development tools used for ASIL B and above require qualification under ISO 26262 Part 8 to demonstrate they do not introduce undetected errors.

Embien's ISO 26262 Functional Safety Services

Embien Technologies provides ISO 26262 functional safety engineering services for automotive OEMs and Tier-1 suppliers. Our expertise spans the complete automotive safety lifecycle: HARA, safety concept definition, hardware safety analysis, ASIL-D software development, and safety case compilation.

We have delivered ISO 26262 compliant ECU software for body control, ADAS, instrument cluster, and telematics domains, working with AUTOSAR Classic and Adaptive platforms on NXP S32K, Renesas RH850, and Qualcomm SA8xxx silicon. Our automotive embedded software development team is experienced in ASIL decomposition, FFI analysis, and tool qualification for safety-critical development.

« AUTOSAR CLASSIC VS ADAPTIVE: ARCHITECTURE, USE CASES AND SELECTION GUIDE

Related Content

Cross-Domain Embedded Services
insight image

Functional safety expertise supporting automotive and other safety-critical domains where reliable embedded systems are essential for safe operation.

Read More


Cybersecurity Services
insight image

Cybersecurity solutions that complement functional safety by protecting automotive and embedded systems against threats, unauthorized access, and security vulnerabilities.

Read More


Secure Bootloader for Ardupilot STM32H7 Drone Platform with Indian Cybersecurity Compliance
insight image

A case study on developing a secure bootloader for an ArduPilot-based drone using STM32H7, enabling authenticated firmware updates and secure system operation.

Read More


Subscribe to our Insights