Abstract
Memory Storage product is evolving as an essential component in the overall automotive systems layout. The integration of Cybersecurity (ISO/SAE 21434) & Functional Safety (ISO 26262) requirements into the existing Automotive Quality Management System compliant to ASPICE 3.1 CL3 differs between the typical OEM or Tier-1 approach.
The objective is to provide an overview of how the approach differs between Component Development and OEM / Tier-1 development for both ISO/SAE 21434 & ISO 26262, including the rationale on those differences.
The journey towards establishing an Integrated Automotive Quality Management System began with an analysis of ISO/SAE 21434 & ISO 26262 requirements against the existing Quality Management System, which is already compliant with ASPICE 3.1 Capability Level 3 & IATF 16949.
A mature QMS with ASPICE 3.1 CL3 provides a strong foundation. A detailed gap analysis of ISO/SAE 21434 & ISO 26262 was conducted to identify additional requirements and overlaps. Internal technical experts were consulted to assess the business need, applicability/relevance, and value creation of cybersecurity engineering and functional safety requirements. The integration exercise focused on how requirements from the Concept phase, Threat Analysis & Risk assessment, HARA, Diagnostic Analysis, Automotive Safety level (ASIL) & safety analysis, Continual Cybersecurity activities, Hardware development, and Operations & Maintenance can be realized for Memory Storage products.
Potential exceptions and alternative compliance approaches were evaluated, and the rationale was validated through consultations with industry experts on ISO/SAE 21434 and ISO 26262. Based on these insights, organizational processes were enhanced & harmonized to establish an integrated Automotive QMS aligned with ISO/SAE 21434, ISO 26262, ASPICE 3.1, ISO 9001 & IATF 16949. This included development of the Hardware Process (HWE.1 to 4) & Requirements Elicitation (SYS.1) process in line with ASPICE 4.
Value
Participants will gain an understanding/ clarity on the below areas
- Clear differentiation of quality and development expectations for component developers, semiconductor firms, and Tier-2 suppliers versus OEMs and Tier-1s.
- How it enables organizations to design a holistic, integrated Automotive QMS aligned with IATF 16949, ASPICE, ISO/SAE 21434, and ISO 26262.
- Positions ASPICE 3.1 as the foundational operating framework to unify quality, functional safety, and cybersecurity practices.
- How the complex safety and cybersecurity concepts translates into practical implementation guidance tailored for semiconductor environments.
- Clarifies how to operationalize critical activities such as TARA, HARA, diagnostic analysis, ASIL determination, and safety analyses within semiconductor product development.
- Demonstrates structured mapping of ISO 26262 and ISO/SAE 21434 requirements into ASPICE 3.1 processes for seamless integration.
- Identifies specific ASPICE 3.1 process areas requiring enhancement to achieve compliance with safety and cybersecurity standards and provides actionable guidance on what enhancements are needed, reducing interpretation gaps and accelerating readiness.
- How bridge the disconnect between system-level automotive requirements and semiconductor-level execution.
- Delivers a practical, adoption-ready model and ways of working tailored to component developers, semiconductor companies, and Tier-2 suppliers.
- Helps organizations reduce compliance risk while improving development maturity and audit preparedness.
- Supports faster alignment with OEM expectations by embedding safety, cybersecurity, and quality into core engineering processes.
