Automotive Safety & Cybersecurity Template for Polarion — Assessed Against 5 Standards

Introduction

Nextedy developed a preconfigured Polarion project designed to streamline automotive compliance work. The solution addresses five regulatory frameworks: ISO 26262, ISO/SAE 21434, ASPICE, AIAG-VDA FMEA, and ISO 21448. The template achieved 68% “Largely Achieved” across these standards, with a documented path to 80%+ compliance.

A Complete AEB Reference Implementation

The template centers on an Automatic Emergency Braking system containing 3 subsystems and 7 components. It demonstrates the full V-model lifecycle from customer needs through test execution. Each requirement includes ASIL fields and safety relevance flags, with color-coded traceability columns linking customer needs to test cases.

Risk Analysis — Native in Polarion

The solution integrates risk analysis directly into Polarion using Nextedy Risksheet, eliminating manual Excel-based workflows. Nine analysis templates cover:

  • HARA — 18 hazards with automated ASIL calculation and 5 safety goals

  • System FMEA — 37 failure modes with risk propagation

  • Subsystem & Component DFMEA — 234 failure modes including DFA/CCF analysis

  • Process FMEA — manufacturing analysis per AIAG-VDA

  • Control Plans — risk control effectiveness tracking

Risk analysis templates screenshot

Cybersecurity — Fully Integrated

Cybersecurity components are embedded within the core traceability model rather than treated separately:

  • Threat Analysis (TARA) for AEB Controller and V2X Transceiver with CVSS-aligned attack feasibility scoring

  • 7 cybersecurity goals with CAL ratings linked to risk controls

  • Penetration and fuzz testing test cases with actual execution results

  • V&V dashboards displaying verification coverage and traceability gaps

The Cybersecurity Verification Powersheet connects threat records directly to test cases, showing verification status in real time.

Cybersecurity verification Powersheet screenshot

Test Execution — From Specification to Results

Test cases connect to Polarion Test Runs with live execution status displayed in verification PowerSheets, including color-coded pass/fail/blocked indicators, test method and expected result fields, and a sample test run with 16 test records demonstrating the complete chain.

Test execution verification screenshot

Process Governance — Audit-Ready

  • Four-eyes principle enforced at the workflow level

  • Safety roles (Safety Manager, Safety Engineer, Independent Assessor) with reviewer independence tracking

  • Document workflows with e-signatures for Safety Plan, Safety Case, and Risk Specification

  • Change management with safety impact assessment and baseline reference

Measuring Compliance — Not Just Checking Boxes

Rather than generic checklists, the template includes a process assessment framework with ASPICE-style F/L/P/N ratings across Implementation Evidence, Execution Evidence, Implementation Gap, and Execution Gap. The dashboard groups 23 assessment modules across 5 standards: ISO 26262 (7 modules), ISO/SAE 21434 (6 modules), ASPICE Cybersecurity (5 modules), AIAG VDA FMEA (2 modules), and ISO 21448 SOTIF (3 modules).

Compliance dashboard screenshot

Configuration Over Code

The template uses declarative configuration files (XML, YAML, JSON) without Java extensions or custom plugins, providing upgradeability, auditability through SVN version control, transferability for seeding new projects, and customizability without developer involvement.

Conclusion

Nextedy invites users to evaluate the Automotive Safety & Cybersecurity Template in a live Polarion environment, exploring the HARA, traceability models, cybersecurity verification, and process assessments firsthand.