← New search

Other meanings of ISO 26262

Automotive engineering

ISO 26262

ISO 26262 is an international standard for functional safety of electrical and/or electronic systems in production road vehicles, titled Road vehicles — Functional safety. It addresses hazards caused by malfunctioning behavior of E/E systems, including hardware and software. The standard is a derivative of the generic functional safety standard IEC 61508 and is tailored to the automotive industry. It defines risk-classification categories known as Automotive Safety Integrity Levels (ASILs), which range from A (lowest) to D (highest).1

2018
Latest edition
Edition
12
Number of parts
Parts
ASIL A–D
Safety integrity levels
ASIL range
1

Overview and scope

ISO 26262 applies to safety-related systems that include one or more electrical or electronic (E/E) components installed in series-production passenger cars, light trucks, and similar vehicles.1 It covers the entire lifecycle of such systems: from concept phase (hazard analysis and risk assessment) through design, implementation, verification, validation, production, and decommissioning. The standard is structured into 12 parts, including a vocabulary, management of functional safety, and specific requirements for hardware and software development. First published in 2011 and revised in 2018, it is legally referenced in some regions for type approval of vehicles.2 The standard does not address nominal performance (e.g., braking distance) or cybersecurity, though later editions incorporate some cybersecurity considerations via cross-references.

2

Technical structure and ASIL determination

At the core of ISO 26262 is the determination of Automotive Safety Integrity Levels (ASILs) through a hazard analysis and risk assessment (HARA).3 Three parameters are evaluated: severity (S), exposure (E), and controllability (C). The combination yields an ASIL rank — A, B, C, or D — with D representing the highest risk and thus the most stringent requirements. For example, an unintended acceleration event with high severity, moderate exposure, and low controllability might result in ASIL D. The standard then prescribes specific measures for each ASIL, such as hardware fault tolerance, software monitoring, and diagnostic coverage. Independent of ASIL, a quality management level (QM) exists for hazards with negligible risk, where no special functional safety measures are required beyond normal quality processes.

3

Application and industry impact

ISO 26262 has become a de facto requirement for automotive suppliers and original equipment manufacturers (OEMs) worldwide.4 Compliance is often demanded by customers (e.g., carmakers) as a condition for sourcing E/E components. The standard influences the entire supply chain, from semiconductor vendors (e.g., for ASIL-rated microcontrollers) to software tool suppliers. It has also driven the adoption of model-based development, safety-oriented software architectures (e.g., AUTOSAR), and formal verification methods. The 2018 edition added part 12, which adapts the standard for motorcycles, and expanded guidance on software safety analysis using techniques such as failure mode and effects analysis (FMEA) and fault tree analysis (FTA).3 Despite its breadth, ISO 26262 does not cover non-E/E hazards (e.g., mechanical failures) or cybersecurity, which is addressed separately by ISO/SAE 21434.

4

Lesser-known aspects

Though ISO 26262 is often associated with active safety systems (e.g., airbags, braking), it also applies to seemingly mundane functions like window lift motors or interior lighting controllers if a malfunction could cause a hazard.5 A lesser-known requirement is the need for a safety case — a structured argument that the system is acceptably safe—which must be maintained throughout the vehicle's lifecycle. The standard also includes provisions for proven in use arguments, allowing reuse of well‑fielded components without full re‑qualification. Another nuance: ASIL decomposition permits splitting a high‑ASIL requirement across multiple independent elements, each with a lower ASIL, provided independence is proven. The standard's influence extends beyond road vehicles; it has been adapted for off‑highway machinery (ISO 19014) and used as a reference for autonomous driving systems.2 Finally, the 2018 edition introduced a new part on software tool qualification, requiring that tools used in safety‑related development be evaluated for confidence level.

Glossary

ASIL
Automotive Safety Integrity Level — a risk classification scheme in ISO 26262 (A, B, C, D) that dictates the required safety measures.
HARA
Hazard Analysis and Risk Assessment — the process used to identify hazards and determine ASIL.
Safety case
A structured argument, supported by evidence, that a system is acceptably safe.
Proven in use
A justification for reusing a component without full re‑qualification based on field experience.
ASIL decomposition
A method to allocate a high‑ASIL safety requirement to multiple independent elements with lower ASILs.

The standard is periodically updated; the 2018 edition is the current version as of the time of writing.