ISO 26262
Automotive Functional Safety
ISO 26262:2018 at a glance
- Current edition
- ISO 26262:2018 - Road vehicles — Functional safety (Parts 1 to 12)
- Published
- 2018
- Status
- Published
- Type of standard
- Requirements
- Certifiable
- No — used for reference and implementation, not certification
- Previous edition
- ISO 26262:2011
- Official ISO page
- View ISO 26262:2018 on iso.org
- Last verified
Overview
The automotive functional safety standard for electrical and electronic systems in road vehicles. The 2018 second edition is a multi-part series covering the whole safety lifecycle and extends the scope beyond passenger cars to trucks, buses, trailers, semi-trailers and motorcycles.
ISO 26262:2018, Road vehicles — Functional safety, is a multi-part series that adapts the generic functional safety standard IEC 61508 to the specific needs of electrical and electronic (E/E) systems in road vehicles. The 2018 edition is the second edition; it cancels and replaces the ISO 26262:2011 series and has been technically revised. It is not a single document but a set of parts, each covering a distinct phase or aspect of the safety lifecycle.
The series covers vocabulary (Part 1), management of functional safety (Part 2), the concept phase (Part 3), product development at the system level (Part 4), at the hardware level (Part 5) and at the software level (Part 6), production, operation, service and decommissioning (Part 7), supporting processes (Part 8), automotive safety integrity level (ASIL) oriented and safety-oriented analyses (Part 9), a guideline on the series (Part 10), guidelines on application to semiconductors (Part 11) and adaptation for motorcycles (Part 12).
The organising concept is the Automotive Safety Integrity Level (ASIL). A hazard analysis and risk assessment considers vehicle-level hazards arising from malfunctioning behaviour and classifies each hazardous event by severity, probability of exposure and controllability. The resulting classification — ASIL A through ASIL D, or QM where no safety requirement applies — determines the rigour of the process, the analyses required, the hardware architectural metrics, and the level of independence needed for confirmation measures. Safety goals derived from the hazard analysis flow down into functional and technical safety requirements and then into hardware and software requirements.
The 2018 revision broadened the scope significantly. The first edition applied to series production passenger cars up to a stated maximum gross vehicle mass; the second edition extends coverage to trucks, buses, trailers and semi-trailers, and adds Part 12 for motorcycles. Part 11 was added to address the particular problems of applying the series to semiconductor components, including intellectual property blocks, digital and analogue components, memories and multi-core processors — a response to the growing dominance of complex silicon in vehicle safety architectures.
Functional safety under ISO 26262 addresses hazards from malfunctioning behaviour of E/E systems. It does not by itself address hazards arising when a system operates as designed but the design is inadequate for the situation, which is the domain of ISO 21448 (safety of the intended functionality, SOTIF), nor cybersecurity, which is addressed by ISO/SAE 21434. Modern programmes for driver assistance and automated driving typically apply all three together, alongside an IATF 16949 quality management system.
ISO 26262 is not the subject of accredited management system certification. Conformity is demonstrated through the standard's own mechanisms: Part 2 requires confirmation measures — confirmation reviews, functional safety audits and a functional safety assessment — with defined independence depending on ASIL, and the evidence is collected in a safety case. Independent assessment bodies and consultancies do offer voluntary third-party functional safety assessments and attestations of process or product, and customers commonly require them contractually, but these are not equivalent to certification against a management system standard under an IAF-recognised accreditation scheme.
Purpose
To provide an automotive-specific functional safety framework for electrical and electronic systems in road vehicles, addressing hazards caused by malfunctioning behaviour of those systems throughout the safety lifecycle from concept to decommissioning.
Key Benefits
- Provides the accepted automotive framework for managing functional safety of E/E systems
- Gives a defensible, ASIL-based method for setting the rigour of development activities
- Covers the whole lifecycle from concept through production, service and decommissioning
- Establishes a common language between vehicle manufacturers, tier suppliers and semiconductor vendors
- Supports supplier interface agreements through defined distributed development responsibilities
- Part 11 addresses the specific problems of semiconductor components and IP reuse
- Extends to trucks, buses, trailers, semi-trailers and motorcycles as well as passenger cars
- Provides the safety case structure needed to evidence due diligence to customers and authorities
Key Requirements
- Establish functional safety management, including a safety culture, roles and a safety lifecycle (Part 2)
- Perform a hazard analysis and risk assessment and derive safety goals with ASIL classification (Part 3)
- Define the item, its boundary and interfaces, and produce a functional safety concept
- Derive technical safety requirements and allocate them to system architecture (Part 4)
- Develop hardware to the required architectural metrics and evaluate random hardware failures (Part 5)
- Develop software with methods, coding guidelines and verification appropriate to the ASIL (Part 6)
- Perform safety analyses, including ASIL decomposition and dependent failure analysis where used (Part 9)
- Manage production, operation, service and decommissioning safety requirements (Part 7)
- Apply supporting processes: configuration and change management, verification, documentation, tool qualification, qualification of software and hardware components, and proven-in-use argument (Part 8)
- Manage distributed development through development interface agreements with suppliers
- Carry out confirmation measures — confirmation reviews, functional safety audit and functional safety assessment — with the required independence
- Compile and maintain the safety case as the argument and evidence that safety goals are met
Who Needs This Standard?
Vehicle manufacturers and their tier 1 and tier 2 suppliers developing electrical or electronic systems for road vehicles; semiconductor and IP vendors supplying into automotive safety applications; developers of driver assistance, braking, steering, powertrain, battery management and automated driving systems; and functional safety managers, safety engineers, hardware and software engineers, verification teams and assessors working on those programmes.
Where to get ISO 26262
The full text of ISO 26262 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 26262 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.
Get our free implementation resources
Send me the implementation checklist for ISO 26262, plus an alert when this standard is revised, withdrawn or replaced. Free, no account needed.
We'll only email you about this standard. Unsubscribe anytime.
Looking to get certified?
You cannot be certified to ISO 26262 — it is guidance, and no accredited scheme exists for it. The closest standards you can certify against are ISO IATF-16949 (Automotive Quality Management Systems), ISO 21434 (Automotive Cybersecurity Engineering) and ISO 9001 (Quality Management Systems).
If that is the direction you are heading, tell us what stage you are at and we will put you in touch with people who work with them. Free and no obligation.
In a hurry? You can also compare quotes from verified providers on CertBetter (affiliate link — we earn a commission, and it stays free for you).