Services · Functional Safety
Safety, and we can prove it.
We develop functionally safe electronics and software from SIL 1 to SIL 3 and from PL a to PL e. From the hazard analysis through circuitry and firmware to certification by the accredited body.
What we stand for
The evidence grows with the product
Safety levels
SIL 1 to SIL 3 under IEC 61508, PL a to PL e under ISO 13849. For medical devices, we support classes I, IIa and IIb under the MDR.
The safety requirements follow from the analysis
First the hazard and risk analysis, then the safety requirements, then the architecture. That way, every requirement can be traced back to its hazard.
Figures from the FMEDA
Safety can be quantified. How much each component contributes to diagnostics and what residual risk remains is expressed in the end as a figure that others can recalculate.
No safety without security
A control that has been tampered with is not a safe control. We build the requirements of IEC 62443 into the same architecture, and in future those of prEN 50742 (draft) on protecting machinery against corruption.
- IEC 61508
- ISO 13849
- IEC 62061
- IEC 60601
- IEC 62304
- IEC 60335
- MDR
What we take on
Hazard and risk analysis
We identify the hazards, assess them and derive the required safety level for each function.
Safety concept and architecture
Where the safety function sits, how it is monitored and what happens in the event of a fault. Plus the architecture question: one channel, two channels or diverse.
Functionally safe hardware
Circuits with the fault tolerance the safety level calls for: shut-off paths, diagnostics, defined safe states.
Functionally safe software
Firmware developed using the methods the standard requires for the safety level: MISRA C++, static analysis, reviews with the required independence.
FMEA, FMEDA and safety figures
For every component, the failure modes and their effect on the safety function. From this, we calculate diagnostic coverage, SFF and PFH. Failure exclusions are justified and documented.
Regulatory approval and certification
We compile the documentation package and support the assessment by the accredited body through to certification.
A safety concept written at the end is a rebuild at best.
Get there faster with our semf <safety> framework
Built for safety-related devices
Bootloader, firmware update, communication and data storage are designed for use in safety-related systems and proven in them.
The same groundwork in every project
What has been assessed and documented once does not need to be re-assessed in every project. So the case you make to the assessment body does not start from zero.
Development starts with your function
The groundwork is in place. The effort goes into the safety function that defines your product.
Your benefits at a glance
Fewer iterations before approval
If you take the assessment body's requirements into account from the start, you face fewer surprises at certification.
One team for analysis, development and evidence
The person calculating the FMEDA sits next to the person who designed the circuit. Questions take minutes.
The evidence holds throughout the service life
A discontinued component can shift the safety figures. We assess the replacement, recalculate the FMEDA and support the re-assessment for as long as the device is on the market.
Safety and security go hand in hand
Both start with analysis: hazard analysis for safety, threat analysis for security. Their requirements feed into the same architecture, are implemented in one development and end up in one evidence package.
From hazard to certificate
On request as a fixed-price contract.
Hazard analysis
What can happen, how often, with what consequence. This determines the required safety level for each function.
Safety concept
The safety functions are defined, with their reaction, safe state and fault tolerance time.
Safety plan
Roles, the required independence and the activities for each lifecycle phase. The plan is in place before development begins.
Development and analyses
Electronics and firmware are developed using the methods the standard prescribes. FMEA and FMEDA run in parallel and supply the figures.
Verification
Every safety requirement gets its evidence. The reports go into the documentation package.
Certificate
We hand the package to the accredited body and support the assessment through to certification.
Transparency from the start
We do not yet know which safety level we need.
That is the normal case and the reason for the hazard analysis. It determines the required level for each safety function. Setting the SIL too high only costs money unnecessarily.
Do you also handle the coordination with the assessment body?
Yes. We compile the documentation package, lead the technical discussion and incorporate the findings. You know your product; we know the technical and normative requirements.
When does ISO 13849 apply and when IEC 62061?
Both apply to machinery controls and lead to comparable results. ISO 13849 calculates in performance levels and is tailored to proven architectures, while IEC 62061 calculates in SIL and suits complex electronics. We establish in the hazard analysis which is the better fit for your product.
Where is the work done?
In Offenburg, and nowhere else. We work with our own people. Whoever designs the safety function sits in the same building as the people who build and test it.
Do you work with AI?
Yes, systematically. Anything a tool contributes goes through the same checks as any other work: review, static analysis, test. We build our AI system ourselves, so we know what it does, and we keep improving it.
Tell us about your next project.
Tell us about your product and your schedule. We will tell you how we would approach the project and whether we see any major risks. The assessment, up to an indicative price, is free of charge.


