Services · Functional Safety

Safety, and we can prove it.

We develop functionally safe electronics and software from SIL 1 to SIL 3 and from PL a to PL e. From the hazard analysis through circuitry and firmware to certification by the accredited body.

What we stand for

The evidence grows with the product

  • Safety levels

    SIL 1 to SIL 3 under IEC 61508, PL a to PL e under ISO 13849. For medical devices, we support classes I, IIa and IIb under the MDR.

  • The safety requirements follow from the analysis

    First the hazard and risk analysis, then the safety requirements, then the architecture. That way, every requirement can be traced back to its hazard.

  • Figures from the FMEDA

    Safety can be quantified. How much each component contributes to diagnostics and what residual risk remains is expressed in the end as a figure that others can recalculate.

  • No safety without security

    A control that has been tampered with is not a safe control. We build the requirements of IEC 62443 into the same architecture, and in future those of prEN 50742 (draft) on protecting machinery against corruption.

  • IEC 61508
  • ISO 13849
  • IEC 62061
  • IEC 60601
  • IEC 62304
  • IEC 60335
  • MDR

What we take on

  • Hazard and risk analysis

    We identify the hazards, assess them and derive the required safety level for each function.

  • Safety concept and architecture

    Where the safety function sits, how it is monitored and what happens in the event of a fault. Plus the architecture question: one channel, two channels or diverse.

  • Functionally safe hardware

    Circuits with the fault tolerance the safety level calls for: shut-off paths, diagnostics, defined safe states.

  • Functionally safe software

    Firmware developed using the methods the standard requires for the safety level: MISRA C++, static analysis, reviews with the required independence.

  • FMEA, FMEDA and safety figures

    For every component, the failure modes and their effect on the safety function. From this, we calculate diagnostic coverage, SFF and PFH. Failure exclusions are justified and documented.

  • Regulatory approval and certification

    We compile the documentation package and support the assessment by the accredited body through to certification.

A safety concept written at the end is a rebuild at best.

Get there faster with our semf <safety> framework

  • Built for safety-related devices

    Bootloader, firmware update, communication and data storage are designed for use in safety-related systems and proven in them.

  • The same groundwork in every project

    What has been assessed and documented once does not need to be re-assessed in every project. So the case you make to the assessment body does not start from zero.

  • Development starts with your function

    The groundwork is in place. The effort goes into the safety function that defines your product.

View semf on GitHub
Logo semf Safety Library

Your benefits at a glance

  • Fewer iterations before approval

    If you take the assessment body's requirements into account from the start, you face fewer surprises at certification.

  • One team for analysis, development and evidence

    The person calculating the FMEDA sits next to the person who designed the circuit. Questions take minutes.

  • The evidence holds throughout the service life

    A discontinued component can shift the safety figures. We assess the replacement, recalculate the FMEDA and support the re-assessment for as long as the device is on the market.

  • Safety and security go hand in hand

    Both start with analysis: hazard analysis for safety, threat analysis for security. Their requirements feed into the same architecture, are implemented in one development and end up in one evidence package.

From hazard to certificate

On request as a fixed-price contract.

  1. Hazard analysis

    What can happen, how often, with what consequence. This determines the required safety level for each function.

  2. Safety concept

    The safety functions are defined, with their reaction, safe state and fault tolerance time.

  3. Safety plan

    Roles, the required independence and the activities for each lifecycle phase. The plan is in place before development begins.

  4. Development and analyses

    Electronics and firmware are developed using the methods the standard prescribes. FMEA and FMEDA run in parallel and supply the figures.

  5. Verification

    Every safety requirement gets its evidence. The reports go into the documentation package.

  6. Certificate

    We hand the package to the accredited body and support the assessment through to certification.

Transparency from the start

We do not yet know which safety level we need.

That is the normal case and the reason for the hazard analysis. It determines the required level for each safety function. Setting the SIL too high only costs money unnecessarily.

Do you also handle the coordination with the assessment body?

Yes. We compile the documentation package, lead the technical discussion and incorporate the findings. You know your product; we know the technical and normative requirements.

When does ISO 13849 apply and when IEC 62061?

Both apply to machinery controls and lead to comparable results. ISO 13849 calculates in performance levels and is tailored to proven architectures, while IEC 62061 calculates in SIL and suits complex electronics. We establish in the hazard analysis which is the better fit for your product.

Where is the work done?

In Offenburg, and nowhere else. We work with our own people. Whoever designs the safety function sits in the same building as the people who build and test it.

Do you work with AI?

Yes, systematically. Anything a tool contributes goes through the same checks as any other work: review, static analysis, test. We build our AI system ourselves, so we know what it does, and we keep improving it.

Tell us about your next project.

Tell us about your product and your schedule. We will tell you how we would approach the project and whether we see any major risks. The assessment, up to an indicative price, is free of charge.

Florian Seibold

Managing Director

info@querdenkerengineering.de

+49 7807 890 80 10