From automotive to off-highway: NX NextMotion integrates diverse safety requirements into a common drive-by-wire-based control layer.
Functional Safety for Drive-by-Wire: Why a Standard Alone Is Not Enough
Pfronstetten-Aichelau, 13.08.2026 (PresseBox) - Autonomous and remotely controlled vehicles place new demands on vehicle architecture. Where steering, braking, and propulsion are electronically controlled, control over vehicle movement must be ensured at all times?even in the event of a fault.
This makes drive-by-wire a safety-critical control layer between the driving command and vehicle motion. Whether the command comes from an autonomous driving system, a teleoperator, or a driver: it is not only crucial that it is reliably executed. The safety of the entire chain of action must be systematically verifiable. This is precisely where functional safety comes into play.
From ?works? to ?verifiably safe?
Testing and validation are indispensable. However, they alone do not answer the crucial question of functional safety: What happens if something fails? What faults can occur? What are their consequences? How are they detected, and how does the system architecture ensure that vehicle movement remains controllable despite the failure?
Standards provide the methodological framework for this?from hazard and risk analysis through safety objectives and technical requirements to verification and validation. For road vehicles, ISO 26262 serves as the central reference framework. However, a drive-by-wire platform?which is used not only in passenger cars or commercial vehicles but also, for example, in agricultural machinery, construction equipment, or intralogistics?encounters multiple sets of standards.
One parent standard, many variants
IEC 61508 is considered the generic base standard for functional safety of electrical, electronic, and programmable electronic systems. Domain-specific standards have emerged from it or are based on it?each tailored to the risk profiles of its specific application area. This is because an autonomous shuttle in urban traffic, a tractor in a field, a wheel loader on a construction site, and a forklift in a warehouse differ fundamentally: in terms of speed and environment, as well as in terms of exposure and a person?s ability to still control a malfunction.
That is why different risk metrics exist:
ISO 26262 for road vehicles with Automotive Safety Integrity Levels (ASIL A through D)
IEC 61508 as a generic basis with Safety Integrity Levels (SIL 1 through 4)
ISO 25119 for agricultural and forestry machinery with Agricultural Performance Levels (AgPL)
ISO 19014 for earth-moving machinery with Machine Performance Levels (MPL)
DIN EN 1175 / ISO 13849 for industrial trucks and machine controls with Performance Levels (PL)
Different scales and operating conditions?but essentially the same task: systematically assessing and managing dangerous failures. For NX NextMotion, ISO 26262 is the guiding standard for development. For the primary functions of steering, braking, and propulsion, ASIL D represents the highest relevant safety level. At the same time, a cross-domain platform must take other standards into account already during its development.
Functional Safety Becomes an Architectural Decision
This is precisely where a challenge lies for OEMs, Tier 1 suppliers, and system integrators: functional safety cannot be ?added on? at the end of the development process. Hazard analyses, safety requirements, architectural decisions, verification, and documentation are established throughout the development process. If a system is initially developed exclusively for one domain and later transferred to another, significant portions of this verification may need to be repeated. Anyone developing a drive-by-wire platform for multiple vehicle domains must therefore embed the standards strategy into the system architecture at an early stage.
Safety-by-Wire®: A Common Requirements Base
Arnold NextG has therefore decided against separate safety concepts for individual markets in NX NextMotion. The requirements of the relevant standards are consolidated into a common set of requirements. Different risk metrics are systematically mapped to one another?in cases of doubt, the most stringent requirement sets the standard. Arnold NextG refers to this strategy as Safety-by-Wire®.
This is explicitly not about equating different standards. Their scopes of application and conformity requirements remain in place. The difference lies in the development approach: requirements from various vehicle domains are taken into account as early as the platform development phase, rather than retroactively adapting the safety architecture for each new application.
Safety does not end with functional safety
For autonomous and teleoperated vehicles, however, functional safety alone is not sufficient. A comprehensive safety case must take additional levels into account. ISO 21448 (SOTIF) addresses hazards that can arise without technical faults, such as those caused by functional limitations. ISO/SAE 21434 addresses cybersecurity. Added to this are homologation requirements?such as UNECE regulations for steering, braking, and EMC, as well as the new international ADS framework with UN R185 and UN GTR No. 26. For a drive-by-wire-based control layer, functional safety, SOTIF, cybersecurity, and homologation must therefore be considered together from the very beginning.
What does this mean for OEMs and integrators?
One key question should be clarified right at the start of the project: What safety certifications does a platform already provide?and which ones still need to be obtained for the specific vehicle project? This applies not only to the relevant standards landscape. Equally relevant is whether, for example, an ASIL or SIL rating applies only to a single component or to an entire safety-critical function, and how the interfaces between functional safety, SOTIF, and cybersecurity are defined.
At NX NextMotion, this consideration was at the forefront of platform development from the very beginning. The consolidated set of requirements thus creates a pre-developed foundation for various applications. The vehicle manufacturer?s responsibility for the safety case of the entire vehicle remains unaffected.
Conclusion: Safety Requires a Strategy
Standards are not bureaucracy. They are the language through which safety is verifiable?to developers, auditors, regulatory agencies, operators, and ultimately the people who trust autonomous and remotely controlled systems. Anyone developing a drive-by-wire-based control layer for different vehicle domains therefore needs not just a standard, but a standards strategy.
NX NextMotion combines these requirements into a unified, multi-redundant, fail-operational architecture. The goal: to make vehicle movement fully electronically controllable?and to maintain control even if a component in the system fails.
WE CONTROL WHAT MOVES
This makes drive-by-wire a safety-critical control layer between the driving command and vehicle motion. Whether the command comes from an autonomous driving system, a teleoperator, or a driver: it is not only crucial that it is reliably executed. The safety of the entire chain of action must be systematically verifiable. This is precisely where functional safety comes into play.
From ?works? to ?verifiably safe?
Testing and validation are indispensable. However, they alone do not answer the crucial question of functional safety: What happens if something fails? What faults can occur? What are their consequences? How are they detected, and how does the system architecture ensure that vehicle movement remains controllable despite the failure?
Standards provide the methodological framework for this?from hazard and risk analysis through safety objectives and technical requirements to verification and validation. For road vehicles, ISO 26262 serves as the central reference framework. However, a drive-by-wire platform?which is used not only in passenger cars or commercial vehicles but also, for example, in agricultural machinery, construction equipment, or intralogistics?encounters multiple sets of standards.
One parent standard, many variants
IEC 61508 is considered the generic base standard for functional safety of electrical, electronic, and programmable electronic systems. Domain-specific standards have emerged from it or are based on it?each tailored to the risk profiles of its specific application area. This is because an autonomous shuttle in urban traffic, a tractor in a field, a wheel loader on a construction site, and a forklift in a warehouse differ fundamentally: in terms of speed and environment, as well as in terms of exposure and a person?s ability to still control a malfunction.
That is why different risk metrics exist:
ISO 26262 for road vehicles with Automotive Safety Integrity Levels (ASIL A through D)
IEC 61508 as a generic basis with Safety Integrity Levels (SIL 1 through 4)
ISO 25119 for agricultural and forestry machinery with Agricultural Performance Levels (AgPL)
ISO 19014 for earth-moving machinery with Machine Performance Levels (MPL)
DIN EN 1175 / ISO 13849 for industrial trucks and machine controls with Performance Levels (PL)
Different scales and operating conditions?but essentially the same task: systematically assessing and managing dangerous failures. For NX NextMotion, ISO 26262 is the guiding standard for development. For the primary functions of steering, braking, and propulsion, ASIL D represents the highest relevant safety level. At the same time, a cross-domain platform must take other standards into account already during its development.
Functional Safety Becomes an Architectural Decision
This is precisely where a challenge lies for OEMs, Tier 1 suppliers, and system integrators: functional safety cannot be ?added on? at the end of the development process. Hazard analyses, safety requirements, architectural decisions, verification, and documentation are established throughout the development process. If a system is initially developed exclusively for one domain and later transferred to another, significant portions of this verification may need to be repeated. Anyone developing a drive-by-wire platform for multiple vehicle domains must therefore embed the standards strategy into the system architecture at an early stage.
Safety-by-Wire®: A Common Requirements Base
Arnold NextG has therefore decided against separate safety concepts for individual markets in NX NextMotion. The requirements of the relevant standards are consolidated into a common set of requirements. Different risk metrics are systematically mapped to one another?in cases of doubt, the most stringent requirement sets the standard. Arnold NextG refers to this strategy as Safety-by-Wire®.
This is explicitly not about equating different standards. Their scopes of application and conformity requirements remain in place. The difference lies in the development approach: requirements from various vehicle domains are taken into account as early as the platform development phase, rather than retroactively adapting the safety architecture for each new application.
Safety does not end with functional safety
For autonomous and teleoperated vehicles, however, functional safety alone is not sufficient. A comprehensive safety case must take additional levels into account. ISO 21448 (SOTIF) addresses hazards that can arise without technical faults, such as those caused by functional limitations. ISO/SAE 21434 addresses cybersecurity. Added to this are homologation requirements?such as UNECE regulations for steering, braking, and EMC, as well as the new international ADS framework with UN R185 and UN GTR No. 26. For a drive-by-wire-based control layer, functional safety, SOTIF, cybersecurity, and homologation must therefore be considered together from the very beginning.
What does this mean for OEMs and integrators?
One key question should be clarified right at the start of the project: What safety certifications does a platform already provide?and which ones still need to be obtained for the specific vehicle project? This applies not only to the relevant standards landscape. Equally relevant is whether, for example, an ASIL or SIL rating applies only to a single component or to an entire safety-critical function, and how the interfaces between functional safety, SOTIF, and cybersecurity are defined.
At NX NextMotion, this consideration was at the forefront of platform development from the very beginning. The consolidated set of requirements thus creates a pre-developed foundation for various applications. The vehicle manufacturer?s responsibility for the safety case of the entire vehicle remains unaffected.
Conclusion: Safety Requires a Strategy
Standards are not bureaucracy. They are the language through which safety is verifiable?to developers, auditors, regulatory agencies, operators, and ultimately the people who trust autonomous and remotely controlled systems. Anyone developing a drive-by-wire-based control layer for different vehicle domains therefore needs not just a standard, but a standards strategy.
NX NextMotion combines these requirements into a unified, multi-redundant, fail-operational architecture. The goal: to make vehicle movement fully electronically controllable?and to maintain control even if a component in the system fails.
WE CONTROL WHAT MOVES
Über "Arnold NextG GmbH":
Über Arnold NextG:
Arnold NextG realisiert die Safety-by-Wire®-Technologie von morgen: das mehrfach redundante Zentralsteuergerät NX NextMotion ermöglicht eine ausfallsichere und individuelle Implementierung, fahrzeugplattform-unabhängig und weltweit einzigartig. Mit dem System können autonome Fahrzeugkonzepte sicher und nach den neuesten Hard- und Software- sowie Sicherheitsstandards umgesetzt werden, ebenso wie Remote-, Teleoperation- oder Platooning- Lösungen Als unabhängiger Vorausentwickler, Inkubator und Systemlieferant übernimmt Arnold NextG die Planung und Umsetzung – von der Vision bis zur Straßenzulassung. Mit der Straßenzulassung von NX NextMotion setzen wir den globalen Drive-by-Wire-Standard. www.arnoldnextg.de
About Arnold NextG:
Arnold NextG realizes the safety-by-wire® technology of tomorrow: The multi-redundant central control unit NX NextMotion enables a fail-safe and individual implementation, independent of the vehicle platform and unique worldwide. The system can be used to safely implement autonomous vehicle concepts in accordance with the latest hardware, software and safety standards, as well as remote control, teleoperation or platooning solutions. As an independent pre-developer, incubator and system supplier, Arnold NextG takes care of planning and implementation - from vision to road approval. With the road approval of NX NextMotion, we are setting the global drive-by-wire standard. www.arnoldnextg.com
Arnold NextG realisiert die Safety-by-Wire®-Technologie von morgen: das mehrfach redundante Zentralsteuergerät NX NextMotion ermöglicht eine ausfallsichere und individuelle Implementierung, fahrzeugplattform-unabhängig und weltweit einzigartig. Mit dem System können autonome Fahrzeugkonzepte sicher und nach den neuesten Hard- und Software- sowie Sicherheitsstandards umgesetzt werden, ebenso wie Remote-, Teleoperation- oder Platooning- Lösungen Als unabhängiger Vorausentwickler, Inkubator und Systemlieferant übernimmt Arnold NextG die Planung und Umsetzung – von der Vision bis zur Straßenzulassung. Mit der Straßenzulassung von NX NextMotion setzen wir den globalen Drive-by-Wire-Standard. www.arnoldnextg.de
About Arnold NextG:
Arnold NextG realizes the safety-by-wire® technology of tomorrow: The multi-redundant central control unit NX NextMotion enables a fail-safe and individual implementation, independent of the vehicle platform and unique worldwide. The system can be used to safely implement autonomous vehicle concepts in accordance with the latest hardware, software and safety standards, as well as remote control, teleoperation or platooning solutions. As an independent pre-developer, incubator and system supplier, Arnold NextG takes care of planning and implementation - from vision to road approval. With the road approval of NX NextMotion, we are setting the global drive-by-wire standard. www.arnoldnextg.com
Suchen