ISO 26262 and Automotive SPICE
Automotive SPICE asks whether your engineering is under control; ISO 26262 asks whether the product is safe. They are not two projects but one engineering flow, sharing a single V-model, a traceability backbone and one set of work products, with safety attributes riding on top.
- Chapters
- 12
- Chapters
- Capability Levels
- 6
- Capability Levels
- Shared V-Model
- 1
- Shared V-Model
- Artifacts Written Twice
- 0
- Artifacts Written Twice
- 01Why Two Frameworks
- 02What ASPICE Actually Is
- 03The Process Landscape
- 04The Capability Dimension
- 05The Two V-Models Are One
Why it pays for itself
Decode a dual-standard statement of work
Read an OEM requirement asking for an ASPICE capability level and ISO 26262 compliance in one sentence, and know which demands are process, which are safety, and where one artifact satisfies both.
Overlay the two V-models node for node
Map SYS.2 to SYS.5 and SWE.1 to SWE.6 onto their Part 4 and Part 6 clauses, so one work-breakdown and one verification plan serve the assessor and the safety auditor alike.
Stop writing artifacts twice
Build one traceability backbone with an ASIL on every safety link and one safety-tagged documentation set, instead of parallel safety and quality specifications that drift apart and get maintained twice.
What you’ll be able to do
Decode an OEM statement of work
Read a dual-standard requirement and know exactly which demands are ASPICE, which are ISO 26262, and where a single artifact satisfies both.
Overlay the two V-models node for node
Map each SYS and SWE process to its Part 4 or Part 6 clause and lay out one work-breakdown and verification plan that serves both.
Build one traceability backbone
Stand up a single trace graph with a safety-relevant flag and an ASIL on every node, so an assessor and a safety auditor walk the same evidence.
Merge work products without duplicating
Keep one safety-tagged documentation set instead of parallel specifications that drift, while holding safety-only artifacts distinct.
Scale rigor by ASIL
Use the Part 6 method tables to dial verification depth from ASIL A to ASIL D on the same shared engineering activity.
Run a joint assessment
Schedule a capability assessment and the confirmation measures against one milestone so evidence is pulled once and each verdict stays honest.
Chapter by chapter
- 01
Why Two Frameworks
Why an OEM statement of work asks for an ASPICE capability level and ISO 26262 compliance in one sentence, and what it costs to run them as two silos instead of one integrated flow.
- Two lenses on the same engineering: is it controlled, is it safe
- The drift and duplication trap of separate safety and quality programs
- Capability level 2 to 3 as the typical contractual target
- 02
What ASPICE Actually Is
Automotive SPICE as a yardstick for how you work: the PRM and PAM, the four-layer anatomy of a process, and the three things it is deliberately not.
- VDA QMC WG13, rooted in ISO/IEC 15504 and the 330xx family
- Purpose, outcomes, base practices and work products (SWE.2 as example)
- Not a lifecycle, not a safety standard, not a simple pass or fail
- 03
The Process Landscape
The process groups ACQ, SPL, SYS, SWE, SUP, MAN and the version 4.0 additions, and the subset an OEM actually puts in scope for an assessment.
- The SYS.1 to SYS.5 and SWE.1 to SWE.6 engineering Vs
- Where Part 4, Part 6 and Part 8 attach to the process map
- Version 3.1 versus 4.0 naming, including the new HWE and MLE groups
- 04
The Capability Dimension
The capability scale from level 0 to 5, the process attributes that unlock each level, and the N/P/L/F rating an assessor applies to real evidence.
- Six levels, each adding a management discipline over the last
- The weakest-link rule: one gap at level 2 caps the process at level 1
- Why OEMs ask for CL 2 (managed) or CL 3 (established)
- 05
The Two V-Models Are One
Lay the ASPICE V over the ISO 26262 V and the same shape appears, with each engineering process mapping to its safety clause node for node.
- SYS.2 to SYS.5 and SWE.1 to SWE.6 mapped to Part 4 and Part 6 clauses
- Where the overlay is close but not identical
- The concept phase (Part 3 HARA and safety goals) has no ASPICE home
- 06
Traceability, the Shared Backbone
Both frameworks demand bidirectional traceability and consistency across the whole chain, so building one trace graph serves an assessor and a safety auditor alike.
- Traceability versus consistency: the link that exists but lies
- One chain, two sets of labels, the ASIL riding down every safety link
- The four gaps both frameworks hunt: orphan, childless, unverified, stale
- 07
Mapping the Work Products
One artifact, two homes: ASPICE information items (04-04, 13-51, 15-51) sitting next to their ISO 26262 work products, with safety attributes added on top rather than duplicated.
- A software requirement read once as 17-00 and as a Part 6-6 safety requirement
- The duplication trap versus a single safety-tagged documentation set
- Safety-only artifacts (safety plan, safety case, HARA) kept distinct
- 08
Where Safety Extends the Process
ASPICE says do it well; ISO 26262 says how strong, by ASIL. The Part 6 method tables tune rigor, and a body of safety-only work has no ASPICE process at all.
- ASIL-scaled method tables, from light reviews to fault injection at ASIL D
- HARA, safety goals, ASIL decomposition and hardware metrics (SPFM, LFM, PMHF)
- Safety analyses, tool confidence and confirmation measures ASPICE never mentions
- 09
Supporting Processes and Joint Assessment
How SUP and MAN processes meet their Part 8 and Part 2 counterparts, and how a combined capability assessment and functional safety audit run on one evidence set.
- SUP.8/SUP.10 configuration and change as the easy win with Part 8
- Two notorious traps: MAN.5 risk is not HARA, SUP.1 QA is not a safety assessment
- One evidence set, two walks: shared interviews, separate verdicts
- 10
Integration Blueprint and Pitfalls
Seven concrete building blocks for one integrated flow, a requirement walked down a worked V, and the myths that most damage a joint program.
- One process architecture, one trace database, one tailoring record
- A worked ASIL D thread from safety goal to vehicle validation
- Myths debunked: level 3 does not mean safe, a trace tool is not compliance
Not just text: the visual toolkit
Braided Frameworks Schematic
Shows the ASPICE and ISO 26262 strands, one asking if the work is under control and the other if the product is safe, braiding into a single engineering flow.
Overlaid V-Model Map
Lays a single V-model annotated with ASPICE process IDs and matching ISO 26262 clauses, with dashed links joining each design activity to the verification that proves it.
Capability Staircase
Climbs the six capability levels, each unlocked by its process attributes, from an incomplete process at level 0 to an innovating one at level 5.
Traceability Backbone Graph
Walks the end-to-end chain from item definition and safety goal down through requirements, design and verification, with the ASIL flowing along every safety-relevant link.
ASIL Method-Rigor Heatmap
Illustrates how the Part 6 method tables strengthen from ASIL A to ASIL D, shifting emphasis from lighter reviews toward structural coverage and fault injection.
Integrated Safety Thread
Follows one E-Gas style ASIL D requirement down the integrated V, with a plausibility monitor in a freedom-from-interference partition validated at vehicle level.
One ASIL D Requirement Down the Integrated V
An E-Gas style safety goal, prevent unintended acceleration, is followed as a single thread through the integrated flow. At every node the same artifact answers an ASPICE process and an ISO 26262 clause, and the ASIL rides all the way down from safety goal to vehicle-level validation.
- Safety goal (Part 3): prevent unintended acceleration, assigned ASIL D
- SYS.2 / Part 4: two independent pedal sensors request torque limitation when implausible
- SWE.1 / Part 6-6: compare sensor A and B every 10 ms, set a fault flag after N deviating cycles
- SWE.2 / Part 6-7: plausibility monitor in an ASIL D partition, free from interference by the QM application
- SWE.4 / Part 6-9: unit tests with boundary and fault-injection cases, structural coverage measured
- SYS.4 / SYS.5 / Part 4: system integration then vehicle validation that unintended acceleration is prevented
Unlock the full node-by-node trace with ASIL, FFI, MISRA and coverage attributes
Who this guide is for
- Suppliers whose OEM contract demands ASPICE CL 2 or CL 3 plus ISO 26262 compliance
- Safety managers merging a separate safety program and quality program into one flow
- Process and quality engineers preparing for a joint capability assessment and safety audit
- Engineers confused about where MAN.5 risk management ends and HARA begins
Frequently Asked Questions
Common questions about ISO 26262 and Automotive SPICE
Start the course today
A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month. The Pro and Expert plans unlock more of the 77-guide library. No credit card required.