Functional safety that truly holds when it matters
ASIL/SIL or PL classification, safety functions and redundancy architecture under IEC 61508/61511 or ISO 26262 – we facilitate the analysis and build the capability within your team.
SIL (Safety Integrity Level) = the measure of reliability required of a safety function. IEC 61508 = the cross-industry base standard for functional safety of electrical/electronic/programmable systems, IEC 61511 its derivative for the process industry. ISO 26262 = functional safety in the automotive sector (Automotive Safety Integrity Level), PL (Performance Level) = an older classification approach similar to SIL/ASIL; every classification starts with a hazard and risk analysis (G+R) or, in automotive contexts, HARA (Hazard Analysis and Risk Assessment) – see also our Risk Management page.
Is your safety function still missing traceability?
The classification comes from gut feeling instead of a traceable hazard and risk analysis (or HARA) and recognized calculation methods.
Safety and operational functions run in the same system without clear separation – making the evidence trail unnecessarily complex.
The safety case gets written up right before the audit, instead of growing alongside the project.
Duplicate sensors or actuators exist, but there’s no documentation of why exactly this architecture (1oo2, 2oo3) was chosen.
Based on experience, a safety architecture considered from the start avoids costly retrofits right before certification.
From guesswork to a solid classification
The status quo
With our approach
From hazard to solid certification
Functional safety isn’t created by a certification stamp at the end – it comes from a process that runs consistently from the first hazard analysis through to the finished safety case. Our approach connects four steps: assessing hazards, deriving the required safety level, designing the architecture to match, and building the safety case alongside the project.
The starting point of every safety consideration – builds on our risk management methodology, deepened here for safety: which hazard, how severe, how frequent, how controllable.
Traceable derivation of the required safety level under IEC 61508/61511 or ISO 26262 (ASIL) – documented, not estimated.
A clear separation of safety and operational functions, with a justified choice of redundancy architecture (e.g. 1oo2, 2oo3) matched to the required level.
The safety case grows alongside the project and is fully in place for audit or certification, instead of being improvised at the end.
The same methodology, deepened for safety functions
Functional safety builds on the same HARA methodology that underpins our Risk Management page – deepened here with the specific requirements of IEC 61508, IEC 61511 and ISO 26262. Applied for decades across safety-critical industries: mechanical engineering, process industry, automotive development. This experience helps especially where safety and development teams need a shared language – not just to meet requirements, but to actually understand them.