| ISO |
26262-5 |
Ed. 2 |
Road vehicles – Functional safety – Part 5: Product development at the hardware level |
This document is intended to be applied to safety-related systems that include one or more electrical and/or electronic (E/E) systems and that are installed in series production road vehicles, excluding mopeds. This document does not address unique E/E systems in special vehicles such as E/E systems designed for drivers with disabilities.
NOTE - Other dedicated application-specific safety standards exist and can complement the ISO 26262 series of standards or vice versa.
Systems and their components released for production, or systems and their components already under development prior to the publication date of this document, are exempted from the scope of this edition. This document addresses alterations to existing systems and their components released for production prior to the publication of this document by tailoring the safety lifecycle depending on the alteration. This document addresses integration of existing systems not developed according to this document and systems developed according to this document by tailoring the safety lifecycle.
This document addresses possible hazards caused by malfunctioning behaviour of safety-related E/E systems, including interaction of these systems. It does not address hazards related to electric shock, fire, smoke, heat, radiation, toxicity, flammability, reactivity, corrosion, release of energy and similar hazards, unless directly caused by malfunctioning behaviour of safety-related E/E systems.
This document describes a framework for functional safety to assist the development of safety-related E/E systems. This framework is intended to be used to integrate functional safety activities into a company-specific development framework. Some requirements have a clear technical focus to implement functional safety into a product; others address the development process and can therefore be seen as process requirements in order to demonstrate the capability of an organization with respect to functional safety.
This document does not address the nominal performance of E/E systems.
This document specifies the requirements for product development at the hardware level for automotive applications, including the following:
— general topics for the product development at the hardware level;
— specification of hardware safety requirements;
— hardware design;
— evaluation of the hardware architectural metrics;
— evaluation of safety goal violations due to random hardware failures; and
— hardware integration and verification.
The requirements of this document for hardware elements are applicable to both non-programmable and programmable elements, such as ASIC, FPGA and PLD. Further guidelines can be found in ISO 26262-10:2018 and ISO 26262-11:2018.
|
2018-12-01 |
Published |
Management/ Engineering Standards, Safety |
Link |
| ISO |
26262-6 |
Ed. 2 |
Road vehicles – Functional safety – Part 6: Product development at the software level |
This document is intended to be applied to safety-related systems that include one or more electrical and/or electronic (E/E) systems and that are installed in series production road vehicles, excluding mopeds. This document does not address unique E/E systems in special vehicles such as E/E systems designed for drivers with disabilities.
NOTE - Other dedicated application-specific safety standards exist and can complement the ISO 26262 series of standards or vice versa.
Systems and their components released for production, or systems and their components already under development prior to the publication date of this document, are exempted from the scope of this edition. This document addresses alterations to existing systems and their components released for production prior to the publication of this document by tailoring the safety lifecycle depending on the alteration. This document addresses integration of existing systems not developed according to this document and systems developed according to this document by tailoring the safety lifecycle.
This document addresses possible hazards caused by malfunctioning behaviour of safety-related E/E systems, including interaction of these systems. It does not address hazards related to electric shock, fire, smoke, heat, radiation, toxicity, flammability, reactivity, corrosion, release of energy and similar hazards, unless directly caused by malfunctioning behaviour of safety-related E/E systems.
This document describes a framework for functional safety to assist the development of safety-related E/E systems. This framework is intended to be used to integrate functional safety activities into a company-specific development framework. Some requirements have a clear technical focus to implement functional safety into a product; others address the development process and can therefore be seen as process requirements in order to demonstrate the capability of an organization with respect to functional safety.
This document does not address the nominal performance of E/E systems.
This document specifies the requirements for product development at the software level for automotive applications, including the following:
— general topics for product development at the software level;
— specification of the software safety requirements;
— software architectural design;
— software unit design and implementation;
— software unit verification;
— software integration and verification; and
— testing of the embedded software.
It also specifies requirements associated with the use of configurable software.
|
2018-12-01 |
Published |
Management/ Engineering Standards, Safety |
Link |
| ISO |
26262-7 |
Ed. 2 |
Road vehicles – Functional safety – Part 7: Production, operation, service and decommissioning |
This document is intended to be applied to safety-related systems that include one or more electrical and/or electronic (E/E) systems and that are installed in series production road vehicles, excluding mopeds. This document does not address unique E/E systems in special vehicles such as E/E systems designed for drivers with disabilities.
NOTE - Other dedicated application-specific safety standards exist and can complement the ISO 26262 series of standards or vice versa.
Systems and their components released for production, or systems and their components already under development prior to the publication date of this document, are exempted from the scope of this edition. This document addresses alterations to existing systems and their components released for production prior to the publication of this document by tailoring the safety lifecycle depending on the alteration. This document addresses integration of existing systems not developed according to this document and systems developed according to this document by tailoring the safety lifecycle.
This document addresses possible hazards caused by malfunctioning behaviour of safety-related E/E systems, including interaction of these systems. It does not address hazards related to electric shock, fire, smoke, heat, radiation, toxicity, flammability, reactivity, corrosion, release of energy and similar hazards, unless directly caused by malfunctioning behaviour of safety-related E/E systems.
This document describes a framework for functional safety to assist the development of safety-related E/E systems. This framework is intended to be used to integrate functional safety activities into a company-specific development framework. Some requirements have a clear technical focus to implement functional safety into a product; others address the development process and can therefore be seen as process requirements in order to demonstrate the capability of an organization with respect to functional safety.
This document does not address the nominal performance of E/E systems.
This document specifies the requirements for production, operation, service and decommissioning, including related planning activities.
|
2018-12-01 |
Published |
Management/ Engineering Standards, Safety |
Link |
| ISO |
26262-9 |
Ed. 2 |
Road vehicles – Functional safety – Part 9: Automotive safety integrity level (ASIL) – oriented and safety-oriented analyses |
This document is intended to be applied to safety-related systems that include one or more electrical and/or electronic (E/E) systems and that are installed in series production road vehicles, excluding mopeds. This document does not address unique E/E systems in special vehicles such as E/E systems designed for drivers with disabilities.
NOTE - Other dedicated application-specific safety standards exist and can complement the ISO 26262 series of standards or vice versa.
Systems and their components released for production, or systems and their components already under development prior to the publication date of this document, are exempted from the scope of this edition. This document addresses alterations to existing systems and their components released for production prior to the publication of this document by tailoring the safety lifecycle depending on the alteration. This document addresses integration of existing systems not developed according to this document and systems developed according to this document by tailoring the safety lifecycle.
This document addresses possible hazards caused by malfunctioning behaviour of safety-related E/E systems, including interaction of these systems. It does not address hazards related to electric shock, fire, smoke, heat, radiation, toxicity, flammability, reactivity, corrosion, release of energy and similar hazards, unless directly caused by malfunctioning behaviour of safety-related E/E systems.
This document describes a framework for functional safety to assist the development of safety-related E/E systems. This framework is intended to be used to integrate functional safety activities into a company-specific development framework. Some requirements have a clear technical focus to implement functional safety into a product; others address the development process and can therefore be seen as process requirements in order to demonstrate the capability of an organization with respect to functional safety.
This document does not address the nominal performance of E/E systems.
This document specifies the requirements for Automotive Safety Integrity Level (ASIL)-oriented and safety-oriented analyses, including the following:
— requirements decomposition with respect to ASIL tailoring;
— criteria for coexistence of elements;
— analysis of dependent failures; and
— safety analyses.
|
2018-12-01 |
Published |
Management/ Engineering Standards, Safety |
Link |
| ISO |
TS 20003 |
Ed. 1 |
Road vehicles – HMI specifications for software updates Over the Air (OTA) |
This standard provides human machine interface (HMI) design specifications by Over The Air (OTA) software updates for passenger cars (including sport utility vehicles and light trucks) plus commercial vehicles (including heavy trucks and buses). These HMI specifications include state transitions, timing, HMI locations with respect to the driver, types of information, necessary notifications and warnings, confirmation of successful completion, and how deviations from the intended results will be handled, based on sequences defined in ISO24089. It covers software updates facilitated both while driving and while stationary.
|
2026-02-01 |
Published |
Human Interaction |
Link |
| ISO |
PAS 21448 |
Ed. 1 |
Road vehicles – Safety of the intended functionality |
The absence of unreasonable risk due to hazards resulting from functional insufficiencies of the intended functionality or by reasonably foreseeable misuse by persons is referred to as the Safety Of The Intended Functionality (SOTIF). This document provides guidance on the applicable design, verification and validation measures needed to achieve the SOTIF. This document does not apply to faults covered by the ISO 26262 series or to hazards directly caused by the system technology (e.g. eye damage from a laser sensor).
This document is intended to be applied to intended functionality where proper situational awareness is critical to safety, and where that situational awareness is derived from complex sensors and processing algorithms; especially emergency intervention systems (e.g. emergency braking systems) and Advanced Driver Assistance Systems (ADAS) with levels 1 and 2 on the OICA/SAE standard J3016 automation scales. This edition of the document can be considered for higher levels of automation, however additional measures might be necessary. This document is not intended for functions of existing systems for which well-established and well-trusted design, verification and validation (V&V) measures exist at the time of publication (e.g. Dynamic Stability Control (DSC) systems, airbag, etc.). Some measures described in this document are applicable to innovative functions of such systems, if situational awareness derived from complex sensors and processing algorithms is part of the innovation.
Intended use and reasonably foreseeable misuse are considered in combination with potentially hazardous system behaviour when identifying hazardous events.
Reasonably foreseeable misuse, which could lead directly to potentially hazardous system behaviour, is also considered as a possible event that could directly trigger a SOTIF-related hazardous event.
Intentional alteration to the system operation is considered feature abuse. Feature abuse is not in scope of this document.
|
2019-01-01 |
Withdrawn |
Management/ Engineering Standards, Safety |
Link |
| ISO, SAE |
8475 |
Ed. 1 |
Road vehicles — Cybersecurity Assurance Levels (CAL) and Target Attack Feasibility (TAF) |
This document defines the term Cybersecurity Assurance Level (CAL) and describes the conceptual model, main principles, and relationships between CAL and other concepts.
Definition of a specific approach for assigning a CAL to a cybersecurity goals of an item and/or to a cybersecurity requirement of a component and how a CAL determines the rigour of cybersecurity activities at the relevant stages /phases of the lifecycle.
This document provides guidelines how CAL can be determined and used by organizations integrating or developing out-of-context or off-the-shelf components.
|
|
Under Development |
Cybersecurity |
Link |
| ISO, SAE |
21434 |
Ed. 1 |
Road vehicles — Cybersecurity engineering |
This document specifies engineering requirements for cybersecurity risk management regarding concept, product development, production, operation, maintenance and decommissioning of electrical and electronic (E/E) systems in road vehicles, including their components and interfaces.
A framework is defined that includes requirements for cybersecurity processes and a common language for communicating and managing cybersecurity risk.
This document is applicable to series production road vehicle E/E systems, including their components and interfaces, whose development or modification began after the publication of this document.
This document does not prescribe specific technology or solutions related to cybersecurity.
|
2021-08-01 |
Published |
Cybersecurity, Management/ Engineering Standards |
Link |
| ISO, SAE |
8477 |
Ed. 1 |
Road vehicles — Cybersecurity verification and validation |
|
|
Under Development |
Cybersecurity, Testing, Verification & Validation |
Link |
| ISO |
23150-1 |
Ed. 1 |
Road vehicles — Data communication between sensors and data fusion unit for automated driving functions — Logical interface |
This document is applicable to road vehicles with automated driving functions. The document specifies the logical interface between in-vehicle environmental perception sensors (for example, radar, lidar, camera, ultrasonic) and the fusion unit which generates a surround model and interprets the scene around the vehicle based on the sensor data. The interface is described in a modular and semantic representation and provides information on object level (for example, potentially moving objects, road objects, static objects) as well as information on feature and detection levels based on sensor technology specific information. Further supportive information is available.
This document does not provide electrical and mechanical interface specifications. Raw data interfaces are also excluded.
|
2026-06-01 |
Published |
In-Vehicle Systems, Networks, Data and Interface Definition |
Link |