Safety Standards

The automotive and off-highway safety landscape. Click any expandable standard to explore its specification tree.

IEC 61508 is the umbrella - most domain-specific safety standards derive from it.

IEC 61508 IEC
Generic E/E/PES functional safety (umbrella, SIL 1-4)
->
ISO 26262 ISO
Road vehicles functional safety (ASIL A-D)
->
ISO 25119 ISO
Ag and forestry functional safety (AgPL a-e)
->
ISO 21448 ISO
SOTIF - safety of the intended functionality
->
ISO/SAE 21434 ISO/SAE
Road vehicle cybersecurity engineering
->
ISO 11898 ISO
CAN / CAN FD physical and data link
->
Automotive SPICE VDA
Process assessment for SW/SYS development
->
AUTOSAR AUTOSAR
Classic + Adaptive platform architecture
->
MISRA C / C++ MISRA
Coding guidelines for safety-critical C/C++
->
UNECE R155 / R156 UNECE
CSMS / SUMS type-approval regulations
->

Coding Standards & MISRA C

Zephyr enforces MISRA-C 2012 as a mandatory coding standard across the kernel and safety-relevant subsystems. All new code must comply.

MISRA-C 2012 in Zephyr

  • 147 rules + 5 project-specific - all marked Required, not advisory. No optional rules.
  • No dynamic memory allocation - Dir 4.12: malloc, free, realloc prohibited in safety-relevant code.
  • No undefined behavior - Rule 1.3: all code paths must have defined behavior per the C standard.
  • Restricted standard library - Only minimal libc functions permitted in the kernel. No stdio.h in safety paths.
  • CERT C complementary - CERT C secure coding recommendations applied alongside MISRA.

Linumiz Quality Practices

  • Static analysis on every commit - Automated MISRA-C checks in CI pipeline before merge.
  • Hardware-in-the-loop verification - Every driver tested on physical silicon, not simulators. 98.76% CI pass rate 8,886 of 8,998 test cases passing.
  • SEooC safety artifacts - 16 work products per component: safety requirements, architecture, traceability, test evidence. Developed to ISO 26262 ASIL D process.
  • Implementation findings - 31 code-level findings identified and severity-classified. 4 HIGH severity requiring code changes before certification.
  • Upstream-first development - All code submitted to mainline Zephyr, reviewed by Architecture WG. Community review adds an independent quality gate.
152
MISRA-C rules enforced
100%
Required (none advisory)
98.76%
CI pass rate on hardware
0
Dynamic allocations in safety paths

Safety Roadmap

Full roadmap ->

Zephyr Community (Kernel)

IEC 61508 SIL 3 | Kernel only | No drivers, no BSP

2019Safety certification announced
2021Process foundation, tooling integration
2023Architecture & methodology defined
2025Requirements writing in progress
2027+"May not happen before 2027 or later"

Linumiz (Drivers & Platform)

Targeting ISO 26262 ASIL D | Drivers, arch, BSP | 16 work products per SEooC

Sep 25Project kickoff (post OSS Europe)
Nov 25MPU Subsystem SEooC - done
Jan 26Fault Handling SEooC - done
Mar 26QSPI Driver SEooC - done
May 26CAN/MCMCAN Driver SEooC - done
Jun 267 arch components - in progress
202720 SEooCs x 16 = 320 deliverables
The gap: Community certifies the kernel. Linumiz certifies the body - drivers, BSP, platform.

Safety Process

Full details ->

Zephyr Kernel (community-developed)

  • - Threads & Scheduler
  • - Semaphores, Mutexes, Queues
  • - Memory Protection (abstract)
  • - Interrupts & Timers
IEC 61508 SIL 3
INTEGRATES
Customer receives
Complete Safety Stack

Linumiz Platform (SEooC)

  • - Drivers: CAN, SPI, I2C, UART, ADC
  • - Arch: MPU, fault/trap, CSA, IR
  • - BSP: Initial platform: Infineon AURIX (extensible to any Zephyr-supported target)
  • - CI/CD: Labwire (Part 8)
Targeting ISO 26262 ASIL D

Safety Team

Full team ->
3 Safety Experts
15+ years automotive FuSa
Tier-1 background
2 Technical Leads
Zephyr RTOS & automotive MCUs
End-to-end expertise
OEM Integration
Customer safety team
System integrator
External Assessor
Independent review planned
IEC 61508 / ISO 26262