A supplier hands you a controller described as “IEC 61508 SIL 3 capable.” Your vehicle safety goal is ASIL D. Can you accept the controller and move on?
No. The label alone is not enough. The IEC 61508 evidence may be useful, but it does not automatically satisfy ISO 26262. The two standards share a functional-safety foundation, yet they classify risk differently, make different assumptions about the operating environment, and expect different lifecycle evidence.
The important question is not whether one standard is better than the other. It is whether the available evidence supports the safety requirements of the vehicle item. This article looks at what carries across, what does not, and how to make that judgment without relying on a convenient but misleading label.
How the standards fit together
IEC 61508 is a generic functional-safety standard for electrical, electronic and programmable electronic (E/E/PE) safety-related systems. ISO 26262 is its automotive adaptation for safety-related E/E systems in series-production road vehicles.
That relationship matters. ISO 26262 did not begin with a blank sheet of paper: it carries forward core ideas such as a managed safety lifecycle, risk-based rigor, the distinction between systematic failures and random hardware failures, and the need to build verifiable safety evidence.

IEC 61508 provides the generic foundation; ISO 26262 adds the automotive context, lifecycle and evidence model.
What ISO 26262 inherits from IEC 61508
- Lifecycle thinking: safety must be managed from concept and development through operation, modification and decommissioning.
- Risk-based rigor: higher risk demands stronger development, verification and assurance measures.
- Two failure dimensions: systematic failures require disciplined processes and techniques, while random hardware failures require architectural and quantitative analysis.
- Independence and confirmation: important safety claims need appropriately independent reviews, assessments and validation.
- Traceable evidence: a safety claim is only as strong as the requirements, analyses, verification results and assumptions supporting it.
The standards clearly share engineering DNA. Even so, ISO 26262 is not simply IEC 61508 with automotive terminology pasted on top. The automotive context changes both the questions being asked and the evidence needed to answer them.
A quick comparison
| Question | IEC 61508 | ISO 26262 |
|---|---|---|
| What is it for? | A generic basis for E/E/PE safety-related systems and sector standards | An automotive framework for safety-related E/E systems in series-production road vehicles |
| How is risk classified? | SIL 1 to SIL 4, based on the required risk reduction and integrity of a safety function | QM or ASIL A to ASIL D, derived from severity, exposure and controllability of hazardous events |
| What is the starting point? | Hazards, risk and the safety functions needed to reduce that risk | An item definition, operational situations, hazardous events, HARA and automotive safety goals |
| What hardware measures stand out? | Safety integrity, architectural constraints and probability-of-failure targets for safety functions | ASIL-oriented architecture plus automotive hardware metrics such as SPFM, LFM and PMHF |
| What environment is assumed? | Defined by the application or sector | Vehicle use, driver controllability, automotive operating conditions and vehicle-level integration |
| Can a certificate transfer directly? | It can provide useful evidence within its certified scope and assumptions | No automatic transfer; automotive suitability and remaining gaps must be demonstrated |
Why SIL and ASIL cannot be converted
A common mistake is to build a lookup table in which, for example, SIL 2 is treated as equivalent to ASIL C. It looks efficient in a presentation, but the comparison does not hold up in an engineering review.
In IEC 61508, a SIL expresses the required integrity of a safety function. Depending on how the function operates, quantitative targets are framed around probability of failure on demand or frequency of dangerous failure, together with systematic capability and architectural constraints.
In ISO 26262, an ASIL is assigned to a hazardous event during the Hazard Analysis and Risk Assessment (HARA). The classification combines:
- Severity: how serious the potential harm could be;
- Exposure: how often the relevant operational situation occurs; and
- Controllability: how likely the driver or other road users are to avoid the harm.

SIL and ASIL are reached through different risk models. Compare the underlying requirements and evidence, not the labels.
ASIL then tailors requirements throughout the automotive safety lifecycle. This includes system, hardware and software development; supporting processes; safety analyses; confirmation measures; and vehicle-level validation.
For that reason, a SIL certificate cannot be used to claim an ASIL, and an ASIL rating cannot be used to claim a SIL. Start with the target application, then show how the available evidence supports its actual requirements.
A worked example: an IEC 61508 component in an ASIL D steering system
Imagine an Electric Power Steering (EPS) team selecting a controller platform with IEC 61508 development evidence and a SIL 3 capability claim. The EPS has an ASIL D safety goal related to unintended steering torque.
The IEC 61508 package could accelerate the project by providing:
- a documented functional-safety management process;
- failure-rate data and diagnostic-coverage assumptions;
- descriptions of safety mechanisms and fault reactions;
- systematic capability evidence for hardware or software;
- verification results, tool information and a safety manual; and
- constraints and assumptions for safe integration.
But the EPS team still has automotive work to do. It must connect that evidence to the item definition, vehicle-level hazardous events, safety goals, Fault Tolerant Time Interval (FTTI), technical safety requirements and the real vehicle architecture.
It also needs to answer questions the certificate cannot settle:
- Are the assumed temperatures, voltages, mission profile and lifetime valid in the target vehicle?
- Do the component's safe state and fault reaction fit the steering concept?
- Are diagnostic tests completed inside the allocated FTTI?
- Can shared clocks, power, communication or development tools create dependent failures?
- Do the failure data and diagnostic assumptions support the ISO 26262 hardware analyses?
- What integration tests, vehicle tests and confirmation measures remain necessary?
In this example, the SIL 3 claim can contribute supporting evidence to the ASIL D development. The distinction matters: it contributes to the safety argument, but it does not replace it.
Putting IEC 61508 evidence to work in an automotive project
The safest approach is to treat cross-standard reuse as an evidence-mapping exercise. In practice, the work usually follows five steps:
- Define the automotive role. State the component's function, allocated safety requirements, target ASIL, interfaces and assumptions in the vehicle item.
- Establish the certified baseline. Record the exact IEC 61508 scope, SIL capability, hardware and software configuration, certificate limitations and referenced safety manual.
- Map evidence requirement by requirement. Link existing analyses and verification results to ISO 26262 objectives. Avoid mapping only document titles or integrity-level labels.
- Identify and close gaps. Add automotive-specific HARA links, environmental evidence, dependent-failure analysis, hardware metrics, interface verification and confirmation activities where needed.
- Validate in context. Demonstrate that the integrated vehicle item achieves its safety goals in representative operating and fault conditions.

Reuse the evidence through a controlled bridge: scope it, map it, close the gaps and validate it in the vehicle context.
A compact evidence checklist
- Certificate, assessment report and exact certified configuration
- Safety manual and all assumptions of use
- Safety architecture, safety mechanisms and diagnostic behavior
- Failure-rate source, mission profile and dependent-failure assumptions
- Systematic capability and development-process evidence
- Tool, software and configuration-management evidence
- Traceability to allocated ISO 26262 safety requirements
- Documented gap analysis and closure plan
- Integration verification and vehicle-level safety validation results
Where IEC 61508 adds real value to automotive work
ISO 26262 should be the primary functional-safety reference for an automotive item in its scope. IEC 61508 is still useful in several situations:
- Cross-industry components: a processor, operating system, power device or platform may arrive with IEC 61508 evidence.
- Shared corporate processes: an organization serving several sectors may use IEC 61508 as a common baseline and tailor it for automotive projects.
- Technique selection: IEC 61508 offers broad guidance on safety techniques that can inform engineering judgment when applied within ISO 26262.
- Architecture discussions: concepts such as independence, diagnostic coverage, redundancy and common-cause control can broaden the team's design vocabulary.
- Supplier conversations: understanding both standards helps teams ask precise questions about what a certificate actually covers.
This is where IEC 61508 adds value: it gives the team a stronger starting point. It should not be treated as an alternative route around automotive requirements.
Where teams commonly get into trouble
- Publishing a SIL-to-ASIL conversion table. Similar levels of rigor do not make the risk models equivalent.
- Accepting the certificate instead of its scope. Always examine the assessed configuration, assumptions, limitations and safety manual.
- Copying an industrial safe state into a vehicle. A shutdown that is safe for a machine may be hazardous for steering, braking or propulsion at speed.
- Stopping at component compliance. Functional safety is achieved by the integrated item in its operational context, not by collecting certified parts.
A useful question for the next design review
Use IEC 61508 to understand the generic foundation and to harvest credible component evidence. Use ISO 26262 to define the automotive risk, safety goals, lifecycle, integration constraints and acceptance argument.
When a certificate or assessment report appears in a design review, bring the discussion back to one question:
What does this evidence prove for our exact vehicle item, configuration and assumptions of use?
That question turns a certificate from a marketing label into useful safety evidence. It also exposes missing assumptions before they become a hidden gap in the safety case.
Abbreviations and key terms
- ASIL: Automotive Safety Integrity Level, ranging from ASIL A to ASIL D.
- E/E/PE: Electrical, electronic and programmable electronic.
- EPS: Electric Power Steering.
- FTTI: Fault Tolerant Time Interval.
- HARA: Hazard Analysis and Risk Assessment.
- LFM: Latent Fault Metric.
- PMHF: Probabilistic Metric for random Hardware Failures.
- SIL: Safety Integrity Level, ranging from SIL 1 to SIL 4.
- SPFM: Single-Point Fault Metric.
Editorial note: This article was reviewed and corrected with ChatGPT (GPT-5).




Comments
Loading comments