Bring together the testing and verification evidence developed across the programme and examine how similar verification concepts appear across five major safety and quality standards.
This eight-hour module provides a cross-industry standards bridge spanning DO-178C, EN 50128, IEC 61508, ISO 26262 and IEC 60880.
Participants compare terminology, assurance levels and verification expectations across the five standards, reuse artifacts from earlier modules, and assemble a verification plan, evidence dossier and safety-case fragment for a chosen specialisation track.
The module concludes with a cross-industry capstone that integrates verification evidence from the wider programme into a structured, reviewable deliverable.
View the Full Software Testing & Verification Programme
What You Will Learn
Module 12 brings together the programme’s technical verification activities and places them into a broader assurance and standards context.
Participants learn how to:
- Compare assurance concepts across multiple industries
- Map verification evidence into different standards contexts
- Distinguish DAL, SSIL, SIL and ASIL terminology
- Work with IEC 60880 software categorisation
- Identify common verification-backbone elements
- Structure a verification plan
- Organise a verification dossier
- Understand tool-qualification concepts
- Build a simple safety-case fragment
- Use GSN notation
- Prepare technical evidence for a mock audit review
Topics
DO-178C & EN 50128
- DO-178C Design Assurance Levels (DAL) and the MC/DC requirement at DAL A
- DO-178C verification objectives and software lifecycle data
- EN 50128 Software Safety Integrity Levels (SSIL) and independence requirements
- DO-178C vs EN 50128 terminology mapping
IEC 61508 & ISO 26262
- IEC 61508 Safety Integrity Levels (SIL); risk graph and LOPA determination
- ISO 26262 ASIL recap and Part 6 software requirements
- IEC 61508 vs ISO 26262 terminology mapping
- Assurance-level correspondence across DAL, SSIL, SIL and ASIL
IEC 60880 & Five-Standard Mapping
- IEC 60880 software categorisation (Category A/B/C)
- The common verification backbone shared across all five standards
- Building a cross-standard mapping table
- Formal methods pointer: SPARK/Ada at the highest assurance levels
Verification Plan, Audit Readiness & Capstone
- Verification plan structure and verification dossier assembly
- Tool qualification concepts across the five standards
- Safety case structure: claims, arguments, evidence; GSN notation
- Audit readiness, common audit findings, and the capstone track deliverable
Lab 1: Mapping a Test Artifact to DO-178C and EN 50128
Learning Objectives: DAL, SSIL, MC/DC-DAL A link, terminology mapping
Description: Determine the DAL and SSIL for a sample function and map one existing test artifact to each standard’s objectives.
Tasks
- Determine the DAL for a sample avionics-style function from a hazard assessment.
- Determine the SSIL for the same function under a rail-signalling framing.
- Map an MC/DC test set (from Module 4) to DO-178C’s DAL A coverage objective.
- Map a traceability matrix entry (from Module 5) to a DO-178C verification objective.
- Map the same artifact to the equivalent EN 50128 requirement.
- Complete a DO-178C/EN 50128 terminology comparison table.
Extension Tasks
- Identify one independence requirement that differs between the two standards.
- Note one lifecycle data artifact required by DO-178C but not explicitly by EN 50128.
Topics Covered
DAL, SSIL, MC/DC-Standard Link, DO-178C/EN 50128 Mapping
Open Source Recommendation
No tool dependency; this lab is a documentation and mapping exercise using artifacts produced in earlier modules.
Lab 2: Mapping Across IEC 61508 and ISO 26262
Learning Objectives: SIL, ASIL, risk graph/LOPA, assurance-level correspondence
Description: Determine the SIL and ASIL for a sample function and complete a four-standard assurance-level comparison.
Tasks
- Determine the SIL for a sample industrial function using a risk graph.
- Recap the ASIL determination for the Module 10 sample function.
- Map the Module 4 coverage evidence to an IEC 61508 verification requirement.
- Map the same evidence to an ISO 26262 Part 6 software requirement.
- Complete a DAL/SSIL/SIL/ASIL rough correspondence table.
- Identify one pitfall of treating two assurance levels as directly equivalent.
Extension Tasks
- Draft a terminology mapping entry between IEC 61508 and ISO 26262.
- Identify where ISO 26262 adds automotive-specific rigor beyond IEC 61508.
Topics Covered
SIL, ASIL, Assurance-Level Mapping
Open Source Recommendation
No tool dependency; this lab builds directly on artifacts from Modules 4 and 10.
Lab 3: IEC 60880 Categorisation & Five-Standard Mapping
Learning Objectives: IEC 60880 categorisation, common verification backbone, cross-standard mapping table
Description: Categorise a sample nuclear safety function and complete the five-standard mapping table for the running example artifact.
Tasks
- Categorise a sample nuclear safety function (Category A/B/C).
- Map the running traceability/coverage artifact to an IEC 60880 evidence requirement.
- Complete a five-standard comparison table (DO-178C, EN 50128, IEC 61508, ISO 26262, IEC 60880).
- Identify the five common verification-backbone elements shared across all five standards.
- Select which of the five standards would apply to a given hypothetical project.
- Note one formal-methods (SPARK/Ada) use case appropriate at the highest assurance level.
Extension Tasks
- Link one CI/CD pipeline artifact (Module 11) into the mapping table.
- Link one traceability matrix entry (Module 5) into the mapping table.
Topics Covered
IEC 60880, Common Verification Backbone, Cross-Standard Mapping
Open Source Recommendation
No tool dependency; SPARK/Ada (the GNAT Community Edition toolchain) is referenced as an open-source formal-methods pointer only.
Lab 4: Capstone: Verification Plan, Safety Case & Track Deliverable
Learning Objectives: Verification plan structure, safety case (GSN), audit readiness, capstone deliverable
Description: Assemble a verification plan and a safety-case fragment for a chosen specialisation track, and prepare it for a mock audit review.
Tasks
- Select one capstone track (Embedded, AI, Automotive, Networking, or Data).
- Draft a verification plan outline covering scope, standards addressed, tools and roles.
- Assemble a verification dossier index referencing artifacts from Modules 2–11.
- Build a simple GSN safety-case fragment linking one claim to one piece of evidence.
- Link one coverage report to its supporting safety-case claim.
- Run a mock-audit walkthrough of the dossier against a basic audit checklist.
Extension Tasks
- Draft a tool-qualification argument for one open-source tool used in the track.
- Present the completed mapping table and verification plan to the group.
Topics Covered
Verification Plan, Safety Case (GSN), Audit Readiness, Capstone Deliverable
Open Source Recommendation
All tooling referenced across the dossier remains the open-source toolchain used throughout Modules 2–11.
Module 12 Coverage Matrix
| Topic | Lab 1 | Lab 2 | Lab 3 | Lab 4 |
|---|---|---|---|---|
| DAL/SSIL Mapping | ✓ | |||
| SIL/ASIL Mapping | ✓ | |||
| IEC 60880 & Five-Standard Mapping | ✓ | |||
| Verification Plan & Safety Case | ✓ | |||
| Capstone Track Delivery | ✓ |
Module Project: Cross-Industry Capstone
Cross-industry capstone: complete a verification plan, evidence dossier, five-standard mapping table and a safety-case fragment for a chosen specialisation track (Embedded / AI / Automotive / Networking / Data Infrastructure).
The capstone brings together evidence created throughout the programme.
Participants move through:
Existing Verification Artifacts
↓
Applicable Standards Context
↓
Cross-Standard Mapping
↓
Verification Plan
↓
Evidence Dossier
↓
Safety-Case Fragment
↓
Mock Audit Review
↓
Capstone Deliverable
This final module therefore acts as the programme’s integration point rather than simply adding another isolated testing technique.
Connecting Verification Evidence Across Industries
The five standards addressed in Module 12 come from different industry contexts and use different terminology.
The curriculum therefore approaches them through mapping and comparison, not through a claim that they are interchangeable.
Participants compare:
- DAL
- SSIL
- SIL
- ASIL
- IEC 60880 Category A/B/C
and examine common verification-backbone concepts while also identifying important differences.
This distinction is important to preserve throughout the webpage.
DO-178C and EN 50128
The first standards lab compares avionics and rail contexts.
Participants work with:
DO-178C
- Design Assurance Levels
- MC/DC at DAL A
- Verification objectives
- Lifecycle data
EN 50128
- Software Safety Integrity Levels
- Independence requirements
- Terminology mapping
Existing artifacts from Modules 4 and 5 are reused so that standards mapping remains connected to concrete verification evidence.
IEC 61508 and ISO 26262
The second lab compares industrial functional-safety and automotive contexts.
Participants determine or revisit:
- SIL
- ASIL
- Risk graph / LOPA concepts
- ISO 26262 Part 6 software requirements
They then construct a rough correspondence table, while explicitly identifying why assurance levels should not be treated as directly equivalent.
That qualifier should remain visible on the live page.
IEC 60880 and Five-Standard Mapping
The third lab introduces IEC 60880 and nuclear software categorisation.
Participants categorise a sample function as:
- Category A
- Category B
- Category C
and then complete a five-standard comparison table spanning:
DO-178C → EN 50128 → IEC 61508 → ISO 26262 → IEC 60880
The lab also asks participants to identify the common verification backbone shared across the standards.
Reusing Evidence From Earlier Modules
One of Module 12’s strongest features is that it does not treat standards discussion as a purely theoretical exercise.
Participants reuse earlier artifacts including:
- Module 4 MC/DC test sets and coverage evidence
- Module 5 traceability entries
- Module 10 ASIL work
- Module 11 CI/CD pipeline artifacts
This gives us excellent internal-linking opportunities across the entire module cluster.
Verification Plan and Evidence Dossier
The capstone requires participants to draft a verification plan covering:
- Scope
- Standards addressed
- Tools
- Roles
Participants also assemble a verification dossier index referencing artifacts produced throughout Modules 2–11.
This gives the programme a tangible final deliverable rather than ending with standards theory alone.
Safety Case and GSN
Module 12 introduces safety-case structure through:
Claim → Argument → Evidence
and references Goal Structuring Notation (GSN).
The practical capstone asks participants to build a simple GSN safety-case fragment linking one claim to one piece of evidence and to connect a coverage report to its supporting safety-case claim.
Do not market this as a complete safety-case engineering qualification; the source supports an introduction and a simple practical fragment.
Tool Qualification Concepts
The curriculum includes tool qualification concepts across the five standards.
It also includes an extension exercise to draft a tool-qualification argument for one open-source tool used in the chosen capstone track.
Keep the wording at the level of concepts and an argument exercise.
Do not claim that completion qualifies specific tools for regulatory use.
Audit Readiness and Mock Audit Review
The capstone includes:
- Audit readiness
- Common audit findings
- Verification dossier review
- A mock-audit walkthrough
Participants review their assembled evidence against a basic audit checklist before presenting the final capstone artifacts.
Again, use mock audit rather than implying formal external certification or regulatory audit approval.
Capstone Tracks
Participants choose one of five specialisation tracks:
Embedded
Focused around embedded-software verification artifacts.
AI
Focused around AI/ML validation artifacts.
Automotive
Focused around automotive/ADAS verification artifacts.
Networking
Focused around network and integration evidence.
Data
Focused around data/infrastructure verification artifacts.
How Module 12 Connects the Entire Programme
This page should visibly act as the capstone hub for the preceding modules.
Module 4: Structural Code Coverage & MC/DC
MC/DC and coverage evidence are reused in standards-mapping exercises.
Module 5: Requirements-Based Testing & Traceability
Traceability-matrix entries are mapped into standards evidence and the final dossier.
Module 10: Automotive/ADAS Safety-Critical Testing
The ASIL determination is revisited within the ISO 26262 mapping exercise.
Module 11: Test Automation & CI/CD Integration
A CI/CD pipeline artifact may be linked into the five-standard mapping table.
Frequently Asked Questions
Which standards are covered in Module 12?
The module covers DO-178C, EN 50128, IEC 61508, ISO 26262 and IEC 60880.
Does the module compare DAL, SSIL, SIL and ASIL?
Yes. Participants build comparison and terminology mappings across these assurance concepts.
Are the assurance levels treated as directly equivalent?
No. The curriculum explicitly asks participants to identify the pitfalls of treating different assurance levels as directly equivalent.
Does the module cover DO-178C MC/DC?
Yes. Participants map a Module 4 MC/DC test set to the DO-178C DAL A coverage objective.
Does the module cover ISO 26262?
Yes. Participants revisit ASIL determination and map coverage evidence to an ISO 26262 Part 6 software requirement.
Is IEC 60880 included?
Yes. Participants categorise a sample nuclear safety function using Category A/B/C and include IEC 60880 in the five-standard comparison table.
Does the module cover verification planning?
Yes. Participants draft a verification plan outline covering scope, standards addressed, tools and roles.
What is a verification dossier in this module?
Participants assemble an index of verification artifacts from Modules 2–11 as part of the capstone.
Does the module cover safety cases?
Yes. The curriculum introduces claims, arguments and evidence, references GSN notation, and asks participants to build a simple safety-case fragment.
Is tool qualification covered?
Tool qualification concepts are included, and an extension exercise asks participants to draft a tool-qualification argument for one open-source tool.
Does the module include audit preparation?
Yes. Audit readiness and common audit findings are included, and participants perform a mock-audit walkthrough using a basic checklist.
What capstone tracks are available?
Participants select Embedded, AI, Automotive, Networking or Data.
What is the final Module 12 project?
The project is a Cross-Industry Capstone comprising a verification plan, evidence dossier, five-standard mapping table and safety-case fragment for the chosen track.
