From Code to Compliance

From Code to
Compliance

Automotive SPICE   ·   ISO 26262   ·   IEC 61508   ·   UNECE R155   ·   ISO/SAE 21434   ·   CRA   ·   ISO 5230

Services

Four disciplines, one engineering thread

Most compliance work fails in the same place — the gap between what a standard asks for and what a development team actually does. We work inside that gap, with your engineers, on your artefacts.

Software Quality

Automotive SPICE 4.0

Process assessments, gap analyses and coaching that hold up in a customer audit — not a folder of templates.

Learn more →

Functional Safety

ISO 26262 · IEC 61508

Safety concepts, work products and audit preparation for road vehicles and industrial E/E systems.

Learn more →

Cybersecurity

UNECE R155 · ISO/SAE 21434 · CRA

CSMS build-up, TARA facilitation and type-approval evidence, now extended to the Cyber Resilience Act.

Learn more →

Software Compliance

ISO/IEC 5230

Open-source licence compliance and SBOM practice that survives supplier hand-off and due diligence.

Learn more →

Standards & regulations

What we are asked for

Assessments, concepts and evidence for the frameworks that govern safety- and security-critical software in Europe.

FrameworkScopeTypical engagement
Automotive SPICE 4.0Process capability, VDA scopeAssessment preparation, gap analysis, assessor support
ISO 26262:2018Functional safety, road vehiclesSafety plan and concept, work products, confirmation reviews
IEC 61508Functional safety, industrial E/ESIL determination, safety case, supplier qualification
UNECE R155 / R156Type approval — CSMS and SUMSProcess build-up, evidence structure, audit readiness
ISO/SAE 21434Automotive cybersecurity engineeringTARA facilitation, cybersecurity case, interface to safety
Regulation (EU) 2024/2847 — CRAProducts with digital elementsScope and class analysis, Annex I gap analysis, conformity route
ISO/IEC 5230 (OpenChain)Open-source licence complianceProgramme setup, SBOM tooling, supplier requirements
Portrait

How we work

Practical engineering. Not theory.

Safionyx is an independent engineering practice for safety- and security-critical software. We are brought in when a standard has to become a working process — before an assessment, during a type-approval programme, or when a customer audit has already found something.

No template libraries handed over at the door. We sit with the team, review real work products, and leave behind a process the engineers can defend themselves. Engagements run from a two-day gap analysis to long-term accompaniment of a programme.

25 yrs

Hands-on automotive and embedded engineering

4

Disciplines covered end to end, safety through compliance

2027

CRA obligations apply in full — the reporting duties start 2026

Memberships & involvement

Part of the professional community

Standards take shape where practitioners argue about them. We take part in the bodies and networks that shape assessment and engineering practice in Europe.

intacs

Working group participation

Alexander Much is a certified INTACS Principal Assessor for Automotive SPICE with Security Extension.

intacs.info →

EuroSPI

Programme committee

Programme committee member of the European conference on software process improvement.

eurospi.net →

ASQF

Member

The German-language professional association for software quality and testing.

asqf.de →

CyberForum

Member

High-tech business network of the Karlsruhe technology region.

cyberforum.de →

Trainings & workshops

Teams learn faster on their own artefacts

Every training can be run on your project material instead of generic examples — the exercises then produce work products you keep.

1 day · on-site or remote

Automotive SPICE 4.0 essentials

What changed with 4.0, what an assessor actually looks for, and how to read a rating without over-preparing.

For project leads, QA, process owners

2 days · on-site

ISO 26262 for software teams

Requirements, architecture and verification seen from the software side — worked through on your own safety element.

For software engineers and architects

Half day · remote

CRA in practice: scope to conformity

Determine whether the regulation applies to your product, which class it falls in, and what the technical documentation must contain.

For product owners, QM, security leads

Resources

Guides & downloads

PDF · 6 pages

CRA scope decision tree

Walk from “product with digital elements” to default, important or critical class in a dozen questions.

Download ↓

Checklist

ISO 26262 software work products

The artefacts a confirmation review will ask for, phase by phase, with the common findings noted.

Download ↓

Template set

SBOM starter kit

A minimal SPDX-based SBOM practice and the supplier clauses that make it enforceable.

Download ↓

Contact

Tell us where you stand

A short call is usually enough to tell whether you need an assessment, a gap analysis, or simply a second opinion. No sales deck.

info@safionyx.com

linkedin.com/company/safionyx

Automotive SPICE® is a registered trademark of the Verband der Automobilindustrie e. V. (VDA).

Scroll to Top