Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ASIL means Automotive Safety Integrity Level. Under ISO 26262, it classifies the risk-reduction rigor required for a safety goal or requirement arising from a hazardous event in a road-vehicle electrical or electronic system. The four levels run from ASIL A, the least stringent, to ASIL D, the most stringent. They are not consumer safety ratings, probabilities of failure or quality scores for an entire vehicle.

What ASIL means in ISO 26262

ISO 26262 is the automotive functional-safety framework for safety-related electrical and electronic (E/E) systems in series-production road vehicles. It addresses hazards caused by malfunctioning behavior of those systems; it does not assess whether a system performs its intended function well under nominal conditions. The framework uses a risk-based process to determine Automotive Safety Integrity Levels and set requirements intended to avoid unreasonable residual risk.

An ASIL belongs to a safety goal or a requirement derived from a hazardous event. It is not automatically assigned to a product, component, vehicle model or manufacturer. A single system can contribute to multiple safety goals, and those goals can have different ASILs depending on the hazards and operating situations involved.

How HARA determines an ASIL

During the concept phase, engineers conduct hazard analysis and risk assessment (HARA). They consider how a safety-related function could malfunction, the operational situation in which that malfunction might occur, and the resulting hazardous event. The event is assessed using three factors: severity, exposure and controllability. These judgments establish the ASIL for the safety goal associated with that event.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Describe the function and malfunctioning behavior. Identify the safety-related function and the ways its behavior could become hazardous through a malfunction.
  2. Set the operational situation. Assess the malfunction in a defined driving or vehicle-use context. The same malfunction can pose different risks in different situations.
  3. Describe the hazardous event. State how the malfunction and situation could combine to create a hazard.
  4. Assess severity, exposure and controllability. These are scenario-specific judgments, not measurements that can be inferred from a component’s name or data sheet.
  5. Assign and document the safety goal’s ASIL. Use the applicable ISO 26262 method and justify the classification for the function and scenario.

The level then informs the rigor of downstream safety requirements, architecture, analyses, verification, validation and confirmation measures. The exact rating cannot be determined from the part alone: a sensor, controller or actuator does not have one universal ASIL independent of how it is used and what safety goal it supports.

What ASIL A, B, C and D mean

The letters are ordered classes of required risk reduction. They are not accident rates, failure probabilities or a ranking of general product quality. As the assigned level rises, the safety measures and evidence expected by the standard become more demanding.

Classification Meaning
QM No ASIL is assigned in some cases; ordinary quality-management processes apply. Consult the applicable ISO 26262 edition for normative terminology and requirements.
ASIL A Lowest of the four ASIL risk-reduction levels.
ASIL B More stringent than ASIL A.
ASIL C More stringent than ASIL B.
ASIL D Highest required risk reduction and the most stringent of the four ASIL levels.

ASIL D does not mean a system is risk-free, nor does ASIL A mean a hazard is harmless. The classification sets the required safety-development rigor for a specific safety goal; it is not a prediction that an accident will or will not occur.

ASIL B versus ASIL D

ASIL D requires greater safety rigor than ASIL B. The distinction affects the development and assurance work for the relevant safety goal and its derived requirements—not just the component chosen to implement them. A sound comparison therefore needs more than the ASIL label on a product brochure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • HARA assumptions: Compare the operational situations and severity, exposure and controllability judgments used to derive the goal.
  • Scope: Check that the same safety goal and requirement boundaries are being compared.
  • Architecture: Review any decomposition argument and whether the required independence between elements is supported.
  • Technical evidence: Examine the hardware and software architecture, analyses and verification evidence against the applicable requirements.
  • Assurance activities: Compare validation, confirmation measures and the work products required by the relevant ISO 26262 parts.

What ISO 26262 Part 9 covers

ISO 26262-9:2018 specifies ASIL-oriented and safety-oriented analyses. Its scope includes requirements decomposition for ASIL tailoring, criteria for coexistence of elements, dependent-failure analysis and safety analyses. These activities help teams analyze and structure safety work; they do not provide a general shortcut for reducing a safety goal’s ASIL.

Decomposition is conditional, not a relabeling tool

ASIL decomposition can distribute a requirement across sufficiently independent elements, but only within the standard’s constraints and with an adequate argument and evidence. A team cannot simply take a high-ASIL function, divide it on paper and claim that each resulting element has a lower ASIL. The independence and failure assumptions behind the decomposition must be addressed under the applicable requirements.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

The ten parts of the 2018 ISO 26262 package

The ISO catalog lists ten parts in the 2018 package. Each addresses a different area of the functional-safety lifecycle and supporting processes.

Part Subject
Part 1 Vocabulary
Part 2 Management of functional safety
Part 3 Concept phase
Part 4 Product development at the system level
Part 5 Product development at the hardware level
Part 6 Product development at the software level
Part 7 Production, operation, service and decommissioning
Part 8 Supporting processes
Part 9 ASIL-oriented and safety-oriented analyses
Part 10 Guidelines on ISO 26262

ISO’s catalog record identifies Part 9 as ISO 26262-9:2018, Edition 2, published in December 2018. The record reports a systematic review in 2023–2024 and a status of “to be revised”; the 2018 edition remains the published edition displayed in that record. Check the ISO catalog for the latest status when edition currency matters.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does ASIL D mean a component is certified?

No. An “ASIL D capable” or similar claim about a component does not, by itself, establish that a vehicle function meets ISO 26262 or that the component is certified for every use. The safety case depends on the specific safety goal, requirements, intended integration, architecture, assumptions, analyses and evidence across the development lifecycle. Evaluate a component claim in that context and against the work products and requirements applicable to the project.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.