
Automotive & embedded engineering consultancy
From Code to
Compliance
25 years of hands-on experience in automotive and embedded
engineering, in the topics that decide whether a product ships:
quality, functional safety and cybersecurity.
Automotive SPICE · ISO 26262 · IEC 61508 · UNECE R155 · ISO/SAE 21434 · CRA · ISO 5230
Services
Four disciplines, one engineering thread
Most compliance work fails in the same place — the gap between what a standard asks for and what a development team actually does. We work inside that gap, with your engineers, on your artefacts.
Software Quality
Automotive SPICE 4.0
Process assessments, gap analyses and coaching that hold up in a customer audit — not a folder of templates.
Functional Safety
ISO 26262 · IEC 61508
Safety concepts, work products and audit preparation for road vehicles and industrial E/E systems.
Cybersecurity
UNECE R155 · ISO/SAE 21434 · CRA
CSMS build-up, TARA facilitation and type-approval evidence, now extended to the Cyber Resilience Act.
Software Compliance
ISO/IEC 5230
Open-source licence compliance and SBOM practice that survives supplier hand-off and due diligence.
Standards & regulations
What we are asked for
Assessments, concepts and evidence for the frameworks that govern safety- and security-critical software in Europe.
| Framework | Scope | Typical engagement |
|---|---|---|
| Automotive SPICE 4.0 | Process capability, VDA scope | Assessment preparation, gap analysis, assessor support |
| ISO 26262:2018 | Functional safety, road vehicles | Safety plan and concept, work products, confirmation reviews |
| IEC 61508 | Functional safety, industrial E/E | SIL determination, safety case, supplier qualification |
| UNECE R155 / R156 | Type approval — CSMS and SUMS | Process build-up, evidence structure, audit readiness |
| ISO/SAE 21434 | Automotive cybersecurity engineering | TARA facilitation, cybersecurity case, interface to safety |
| Regulation (EU) 2024/2847 — CRA | Products with digital elements | Scope and class analysis, Annex I gap analysis, conformity route |
| ISO/IEC 5230 (OpenChain) | Open-source licence compliance | Programme setup, SBOM tooling, supplier requirements |

How we work
Practical engineering. Not theory.
Safionyx is an independent engineering practice for safety- and security-critical software. We are brought in when a standard has to become a working process — before an assessment, during a type-approval programme, or when a customer audit has already found something.
No template libraries handed over at the door. We sit with the team, review real work products, and leave behind a process the engineers can defend themselves. Engagements run from a two-day gap analysis to long-term accompaniment of a programme.
25 yrs
Hands-on automotive and embedded engineering
4
Disciplines covered end to end, safety through compliance
2027
CRA obligations apply in full — the reporting duties start 2026
Memberships & involvement
Part of the professional community
Standards take shape where practitioners argue about them. We take part in the bodies and networks that shape assessment and engineering practice in Europe.
intacs
Working group participation
Alexander Much is a certified INTACS Principal Assessor for Automotive SPICE with Security Extension.
EuroSPI
Programme committee
Programme committee member of the European conference on software process improvement.
ASQF
Member
The German-language professional association for software quality and testing.
Trainings & workshops
Teams learn faster on their own artefacts
Every training can be run on your project material instead of generic examples — the exercises then produce work products you keep.
1 day · on-site or remote
Automotive SPICE 4.0 essentials
What changed with 4.0, what an assessor actually looks for, and how to read a rating without over-preparing.
For project leads, QA, process owners
2 days · on-site
ISO 26262 for software teams
Requirements, architecture and verification seen from the software side — worked through on your own safety element.
For software engineers and architects
Half day · remote
CRA in practice: scope to conformity
Determine whether the regulation applies to your product, which class it falls in, and what the technical documentation must contain.
For product owners, QM, security leads
Resources
Guides & downloads
PDF · 6 pages
CRA scope decision tree
Walk from “product with digital elements” to default, important or critical class in a dozen questions.
Checklist
ISO 26262 software work products
The artefacts a confirmation review will ask for, phase by phase, with the common findings noted.
Template set
SBOM starter kit
A minimal SPDX-based SBOM practice and the supplier clauses that make it enforceable.
Contact
Tell us where you stand
A short call is usually enough to tell whether you need an assessment, a gap analysis, or simply a second opinion. No sales deck.
Automotive SPICE® is a registered trademark of the Verband der Automobilindustrie e. V. (VDA).
