Creating a safer, more secure future.

Reduce Certification Effort

Certification-ready evidence, guidance and traceability for safety-critical development

Most organisations developing safety-critical systems spend months or years generating certification evidence, preparing for audits, and demonstrating compliance with standards such as IEC 61508, ISO 26262 and FDA 510(k).

WITTENSTEIN high integrity systems (WHIS) provide a different approach.

SAFERTOS® includes a Design Assurance Pack (DAP), or Design History File (DHF) for medical applications, to help development teams:

  • Save years of certification effort
  • Improve audit readiness
  • Lower project risk
  • Accelerate compliance activities
  • Avoid unnecessary re-testing

Rather than starting from scratch, engineering teams can leverage proven certification evidence developed with over more than 20 years of functional safety experience.

Why certification projects get delayed

After supporting safety-critical projects for more than 20 years, WHIS consistently find certification delays are more often caused by missing traceability and verification evidence than software functionality itself. The full list includes:

  • Missing traceability
  • Incomplete verification evidence
  • Configuration mismatches
  • Documentation gaps
  • Audit findings
  • Re-testing effort

As systems become increasingly software-defined, certification can become a barrier to innovation.

The SAFERTOS® DAP addresses these issues by providing certification evidence, guidance and traceability from the outset. From source code to instruction set, every functional safety claim is supported by objective evidence. That’s safety made transparent.

Why development teams use the DAP:

  • Processor/compiler-specific evidence
  • Complete lifecycle traceability
  • Safety manual guidance
  • Full source code visibility

SAFERTOS® helps organisations maintain architectural flexibility while reducing certification effort.

Why trust WITTENSTEIN high integrity systems (WHIS)?

  • SAFERTOS® certified since 2007
  • Over 40 successful TUV SUD certifications
  • More than 20 years of functional safety expertise
  • Proven deployments across automotive, industrial, medical, and rail applications
  • 100% certification success record and no in-field safety incidents

Ask Us a Question

For pricing, licensing, or any other sales or product related questions, please contact us.

Ask us a question

Why safety manuals matter

The safety manual is widely regarded as the most valuable document within the DAP. It defines the assumptions of use required for standards such as ISO 26262 and IEC 61508 and provides the practical guidance that helps organisations leverage certification evidence effectively, reduce unnecessary verification effort, and improve audit readiness.

The safety manual:

  • Describes the assumptions of use/integration requirements
  • Provides implementation guidance
  • Includes certification considerations

Without clear guidance, organisations may need to generate additional evidence or repeat verification activities to fulfil certification requirements. The safety manual helps teams understand how existing evidence can be applied, reducing uncertainty and helping avoid unnecessary re-testing effort.

Design History File (DHF)

For medical applications, SAFERTOS® is supplied with a DHF.

The DHF follows the same principles of transparency, traceability and lifecycle evidence as the DAP while supporting medical device development and regulatory activities, including FDA 510(k) class III device submissions and IEC 62304 class C certifications.

Free Demos & Manuals

Download fully functional, time-limited SAFERTOS® demos, plus manuals, datasheets, and more.

What’s inside a DAP/DHF?

A typical DAP includes around 70 supporting documents, SAFERTOS® source files, demonstration applications, and one or more test harnesses providing full lifecycle visibility.

Getting Started

SAFERTOS® User Manual

Provides an overview of SAFERTOS® and gives a description of the RTOS task, queue and scheduling mechanisms, and provides an API reference.

SAFERTOS® Safety Manual

The safety manual contains a concise list of instructions clearly identifying the installation and integration process your engineers should follow when incorporating the RTOS into your development environment.

Upgrading from the FreeRTOS Kernel to SAFERTOS®

The FreeRTOS kernel and SAFERTOS® share a similar usage model but are not direct drop-in replacements for each other. This document highlights the areas requiring modification when moving an application from the FreeRTOS kernel to SAFERTOS®.

Using the SAFERTOS® Demo

This technical note provides information that is intended to assist in understanding of the RTOS demonstration program for the selected processor. This demonstration program exercises the SAFERTOS® kernel functions in order to show the task creation/scheduling and queue communication within an example application.

Configuration

Software Version Description

Contains an inventory of the materials released, their relating checksums and a record of the changes made to this deliverable over its lifetime.

Planning

Software Development Plan

Defines the IEC 61508 SIL 3 compliant development life cycle used in the development of SAFERTOS®.

Software Configuration Management Plan

Gives an overview of the configuration management tool, identifies the items under configuration control, and the configuration management rules and working procedures used in the development of this RTOS.

Software Test Plan

Defines the objectives for each Verification and Validation (V&V) phase, and the relating test environment. Defines the complete V&V schedule.

Software Safety Management Plan

The objective of the Software Safety Management Plan is to adequately justify that SAFERTOS® meets its high level safety requirements. This SSMP forms the plan for ensuring that safety is considered throughout the RTOS development programme and is appropriately designed into SAFERTOS®.

Requirements

Customer Requirements Specification

This document defines the Customer Requirements Specification for the SAFERTOS® product.

MPU Customer Requirements Specification

This document defines the Customer Requirements specific to MPU or MMU product variants of the SAFERTOS® product.

FPU Customer Requirements Specification

This document defines the Customer Requirements specific to SAFERTOS® product variants that support the use of a hardware Floating Point Unit.

Software Requirements Specification

This document defines the software requirements for the SAFERTOS® product.

MPU Software Requirements Specification

This document contains the additional software requirements for SAFERTOS® product variants using the Memory Protection Unit.

FPU Software Requirements Specification

This document contains the additional software requirements for SAFERTOS® product variants that support the use of a hardware Floating Point Unit.

Design

Architectural Software Design Description

This document describes the architectural software design for the SAFERTOS® product.

Architectural Software Design Description for MPU

This document contains the additional architectural software design for SAFERTOS® product variants that utilise the Memory Protection Unit.

Architectural Software Design Description for FPU

This document contains the additional architectural software design for SAFERTOS® product variants that support the use of a hardware Floating Point Unit.

Detailed Software Design Description

This document describes the software design for the SAFERTOS® product.

Product Specific Software Design Description

This document contains the software design elements that are specific to your Product Variant.

Safety

HAZOPS Report

This document contains the SAFERTOS® Hazard and Operability Study, the hazard assessment, risk reduction methods, the safety related requirements and details any residual risks.

HAZOPS Report for MPU Requirements

This document contains the SAFERTOS® Hazard and Operability Study as it relates to development of products featuring MPU support.

Investigations arising from HAZOPS

This Technical Report documents the investigations called for during the Hazard and Operability Study (HAZOPS) process as they relate to your Product Variant of SAFERTOS®.

API Usage Safety Review

Analyses the functions and macros that constitute the API to determine any actual or potential behaviour of the SAFERTOS® that could lead to unsafe or inappropriate use by a user or other interested person.

MPU API Usage Safety Review

This Technical Report analyses the functions and macros that constitute the MPU API to determine any actual or potential behaviour of the software product that could lead to unsafe or inappropriate use by a user or other interested person.

Evidence Supporting IEC61508-3 SIL3 Claim

The purpose of this document is to collate or reference all evidence that supports the claim that SAFERTOS® requirements have been specified and met and that it has been developed to meet the software development requirements of IEC 61508-3 Safety Integrity Level (SIL) 3.

Test Procedures

Software Code Verification Test Description

This document presents the Software Code Verification test definitions for the common elements of the SAFERTOS® kernel.

Software Integration Verification Test Description

This document presents the Software Integration Verification test definitions for the common elements of the SAFERTOS® kernel.

Software System Verification Test Description

This document presents the Software System Verification test definitions for the common elements of the SAFERTOS® kernel.

Validation Test Description

This document presents the Validation test definitions for the SAFERTOS® kernel.

Product Variant Software Code Verification Test Description

This document relates to the development of the SAFERTOS® Product Variant and presents the Software Code Verification test definitions for the port specific elements of the design.

Product Variant Software Integration Verification Test Description

This document relates to the development of the SAFERTOS® Product Variant and presents the Software Integration Verification test definitions for the port specific elements of the design.

System Verification Test Description

This document relates to the development of the SAFERTOS® Product Variant and presents the Software System Verification test definitions for the port specific elements of the design.

Test Harness Build Procedure

This document provides instructions on building and using the software test harness when performing formal testing of the product variant.

SAFERTOS® Test Harness for your toolchain and compiler

The source code for the software test harness is included in this package.

Test Results

Software Test Report

The Software test report gives an overview of the results from the V&V process, before going into the details of each test case.

Frequently asked questions

Why does processor/compiler-specific evidence matter?

Changes to processors, compilers, optimisation settings, or build environments can affect software behaviour. Certification evidence must therefore be tied to the assessed configuration.

SAFERTOS® provides processor/compiler-specific certification evidence to help reduce verification effort, avoid certification gaps, and support a smoother path to compliance.

How is the DAP different from the DHF?

The DAP supports standards such as IEC 61508 and ISO 26262, while the DHF is structured for medical device compliance. Both provide comprehensive lifecycle evidence and transparency.

The main distinctions are:

  • The DAP includes a compliance matrix mapped to ISO 26262 requirements.
  • The DHF includes an off-the-shelf software report template.

What part of the DAP do auditors value most?

Auditors need confidence that functional safety-related software has been implemented correctly. The safety manual provides the guidance needed to demonstrate this:

  • Correct deployment of the RTOS
  • Compliance with documented assumptions
  • Appropriate integration practices
  • Proper use of certification evidence

Ask Us a Question

For pricing, licensing, or any other sales or product related questions, please contact us.

Ask us a question