Skip to main content
Concept guide · ISO 26262 + ASPICE · 12 chapters

ISO 26262 and Automotive SPICE

Automotive SPICE asks whether your engineering is under control; ISO 26262 asks whether the product is safe. They are not two projects but one engineering flow, sharing a single V-model, a traceability backbone and one set of work products, with safety attributes riding on top.

Chapters
12
Chapters
Capability Levels
6
Capability Levels
Shared V-Model
1
Shared V-Model
Artifacts Written Twice
0
Artifacts Written Twice
Included inExpert
The short version

Quick answers

What is Automotive SPICE and how does it relate to ISO 26262?
Automotive SPICE (ASPICE) is a process assessment model maintained by the VDA QMC, rooted in ISO/IEC 15504 and the ISO/IEC 330xx family. It measures whether your engineering processes are under control, rated on a capability scale from level 0 to 5. ISO 26262 asks a different question: whether the product is functionally safe, scaled by ASIL. They are not two projects but two lenses on one engineering flow - both follow the same V-model, both demand bidirectional traceability, and most work products can be shared, with safety attributes such as the ASIL riding on top of the common artifacts.
Does ASPICE capability level 3 mean a product is safe?
No. A capability level measures how well a process is managed and established, not whether the product achieves its safety goals. A team can run SWE.1 through SWE.6 at level 3 and still ship a design that violates a safety goal, because ASPICE never looks at HARA quality, ASIL-scaled method rigor, hardware metrics such as SPFM and LFM, or confirmation measures. ISO 26262 adds exactly those safety-specific demands on top of a controlled process. The two verdicts are separate: a joint assessment can share interviews and evidence, but the capability rating and the safety judgement are issued independently.
Why this course · ISO 26262

Why it pays for itself

Decode a dual-standard statement of work

Read an OEM requirement asking for an ASPICE capability level and ISO 26262 compliance in one sentence, and know which demands are process, which are safety, and where one artifact satisfies both.

Overlay the two V-models node for node

Map SYS.2 to SYS.5 and SWE.1 to SWE.6 onto their Part 4 and Part 6 clauses, so one work-breakdown and one verification plan serve the assessor and the safety auditor alike.

Stop writing artifacts twice

Build one traceability backbone with an ASIL on every safety link and one safety-tagged documentation set, instead of parallel safety and quality specifications that drift apart and get maintained twice.

After the course

What you’ll be able to do

Decode an OEM statement of work

Read a dual-standard requirement and know exactly which demands are ASPICE, which are ISO 26262, and where a single artifact satisfies both.

Overlay the two V-models node for node

Map each SYS and SWE process to its Part 4 or Part 6 clause and lay out one work-breakdown and verification plan that serves both.

Build one traceability backbone

Stand up a single trace graph with a safety-relevant flag and an ASIL on every node, so an assessor and a safety auditor walk the same evidence.

Merge work products without duplicating

Keep one safety-tagged documentation set instead of parallel specifications that drift, while holding safety-only artifacts distinct.

Scale rigor by ASIL

Use the Part 6 method tables to dial verification depth from ASIL A to ASIL D on the same shared engineering activity.

Run a joint assessment

Schedule a capability assessment and the confirmation measures against one milestone so evidence is pulled once and each verdict stays honest.

The curriculum · 10 chapters

Chapter by chapter

  1. 01

    Why Two Frameworks

    Why an OEM statement of work asks for an ASPICE capability level and ISO 26262 compliance in one sentence, and what it costs to run them as two silos instead of one integrated flow.

    • Two lenses on the same engineering: is it controlled, is it safe
    • The drift and duplication trap of separate safety and quality programs
    • Capability level 2 to 3 as the typical contractual target
  2. 02

    What ASPICE Actually Is

    Automotive SPICE as a yardstick for how you work: the PRM and PAM, the four-layer anatomy of a process, and the three things it is deliberately not.

    • VDA QMC WG13, rooted in ISO/IEC 15504 and the 330xx family
    • Purpose, outcomes, base practices and work products (SWE.2 as example)
    • Not a lifecycle, not a safety standard, not a simple pass or fail
  3. 03

    The Process Landscape

    The process groups ACQ, SPL, SYS, SWE, SUP, MAN and the version 4.0 additions, and the subset an OEM actually puts in scope for an assessment.

    • The SYS.1 to SYS.5 and SWE.1 to SWE.6 engineering Vs
    • Where Part 4, Part 6 and Part 8 attach to the process map
    • Version 3.1 versus 4.0 naming, including the new HWE and MLE groups
  4. 04

    The Capability Dimension

    The capability scale from level 0 to 5, the process attributes that unlock each level, and the N/P/L/F rating an assessor applies to real evidence.

    • Six levels, each adding a management discipline over the last
    • The weakest-link rule: one gap at level 2 caps the process at level 1
    • Why OEMs ask for CL 2 (managed) or CL 3 (established)
  5. 05

    The Two V-Models Are One

    Lay the ASPICE V over the ISO 26262 V and the same shape appears, with each engineering process mapping to its safety clause node for node.

    • SYS.2 to SYS.5 and SWE.1 to SWE.6 mapped to Part 4 and Part 6 clauses
    • Where the overlay is close but not identical
    • The concept phase (Part 3 HARA and safety goals) has no ASPICE home
  6. 06

    Traceability, the Shared Backbone

    Both frameworks demand bidirectional traceability and consistency across the whole chain, so building one trace graph serves an assessor and a safety auditor alike.

    • Traceability versus consistency: the link that exists but lies
    • One chain, two sets of labels, the ASIL riding down every safety link
    • The four gaps both frameworks hunt: orphan, childless, unverified, stale
  7. 07

    Mapping the Work Products

    One artifact, two homes: ASPICE information items (04-04, 13-51, 15-51) sitting next to their ISO 26262 work products, with safety attributes added on top rather than duplicated.

    • A software requirement read once as 17-00 and as a Part 6-6 safety requirement
    • The duplication trap versus a single safety-tagged documentation set
    • Safety-only artifacts (safety plan, safety case, HARA) kept distinct
  8. 08

    Where Safety Extends the Process

    ASPICE says do it well; ISO 26262 says how strong, by ASIL. The Part 6 method tables tune rigor, and a body of safety-only work has no ASPICE process at all.

    • ASIL-scaled method tables, from light reviews to fault injection at ASIL D
    • HARA, safety goals, ASIL decomposition and hardware metrics (SPFM, LFM, PMHF)
    • Safety analyses, tool confidence and confirmation measures ASPICE never mentions
  9. 09

    Supporting Processes and Joint Assessment

    How SUP and MAN processes meet their Part 8 and Part 2 counterparts, and how a combined capability assessment and functional safety audit run on one evidence set.

    • SUP.8/SUP.10 configuration and change as the easy win with Part 8
    • Two notorious traps: MAN.5 risk is not HARA, SUP.1 QA is not a safety assessment
    • One evidence set, two walks: shared interviews, separate verdicts
  10. 10

    Integration Blueprint and Pitfalls

    Seven concrete building blocks for one integrated flow, a requirement walked down a worked V, and the myths that most damage a joint program.

    • One process architecture, one trace database, one tailoring record
    • A worked ASIL D thread from safety goal to vehicle validation
    • Myths debunked: level 3 does not mean safe, a trace tool is not compliance
Diagrams & Visuals

Not just text: the visual toolkit

Braided Frameworks Schematic

Shows the ASPICE and ISO 26262 strands, one asking if the work is under control and the other if the product is safe, braiding into a single engineering flow.

Overlaid V-Model Map

Lays a single V-model annotated with ASPICE process IDs and matching ISO 26262 clauses, with dashed links joining each design activity to the verification that proves it.

Capability Staircase

Climbs the six capability levels, each unlocked by its process attributes, from an incomplete process at level 0 to an innovating one at level 5.

Traceability Backbone Graph

Walks the end-to-end chain from item definition and safety goal down through requirements, design and verification, with the ASIL flowing along every safety-relevant link.

ASIL Method-Rigor Heatmap

Illustrates how the Part 6 method tables strengthen from ASIL A to ASIL D, shifting emphasis from lighter reviews toward structural coverage and fault injection.

Integrated Safety Thread

Follows one E-Gas style ASIL D requirement down the integrated V, with a plausibility monitor in a freedom-from-interference partition validated at vehicle level.

Worked Example

One ASIL D Requirement Down the Integrated V

An E-Gas style safety goal, prevent unintended acceleration, is followed as a single thread through the integrated flow. At every node the same artifact answers an ASPICE process and an ISO 26262 clause, and the ASIL rides all the way down from safety goal to vehicle-level validation.

  • Safety goal (Part 3): prevent unintended acceleration, assigned ASIL D
  • SYS.2 / Part 4: two independent pedal sensors request torque limitation when implausible
  • SWE.1 / Part 6-6: compare sensor A and B every 10 ms, set a fault flag after N deviating cycles
  • SWE.2 / Part 6-7: plausibility monitor in an ASIL D partition, free from interference by the QM application
  • SWE.4 / Part 6-9: unit tests with boundary and fault-injection cases, structural coverage measured
  • SYS.4 / SYS.5 / Part 4: system integration then vehicle validation that unintended acceleration is prevented
Integrated V Thread: E-Gas Torque Limitation
SWE.2 architecture (Part 6-7): plausibility monitor, ASIL D partition, FFI attribute set

Unlock the full node-by-node trace with ASIL, FFI, MISRA and coverage attributes

Built for

Who this guide is for

  • Suppliers whose OEM contract demands ASPICE CL 2 or CL 3 plus ISO 26262 compliance
  • Safety managers merging a separate safety program and quality program into one flow
  • Process and quality engineers preparing for a joint capability assessment and safety audit
  • Engineers confused about where MAN.5 risk management ends and HARA begins

Frequently Asked Questions

Common questions about ISO 26262 and Automotive SPICE

The engineering Vs align closely: SYS.2 to SYS.5 map onto ISO 26262-4 system-level clauses, and SWE.1 to SWE.6 map onto the Part 6 software clauses, node for node down one side of the V and up the other. The concept phase is the big exception - HARA and safety goal derivation from Part 3 have no ASPICE home. On the supporting side, SUP.8 and SUP.10 configuration and change management line up with Part 8, while two mappings are notorious traps: MAN.5 risk management is not a HARA, and SUP.1 quality assurance is not a functional safety assessment.
A combined capability assessment and functional safety audit can run on one evidence set - shared document reviews and shared interviews - but they remain two walks with two verdicts. The practical win is preparing evidence once: a single trace database, a single process architecture, and a single tailoring record answer both the assessor and the safety auditor. What must stay distinct are the safety-only artifacts (safety plan, safety case, HARA) and the independence rules for confirmation measures, which ASPICE does not know about.
The guide has 12 chapters covering both frameworks, the six capability levels, the shared V-model, the traceability backbone, the work-product mapping and a joint-assessment walkthrough, and closes with an integration blueprint. A worked ASIL D thread follows an E-Gas style requirement from safety goal to vehicle validation through the integrated flow. A free account starts you off, and the Pro and Expert plans unlock more of the library.

Start the course today

A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month. The Pro and Expert plans unlock more of the 78-guide library. No credit card required.