WITTENSTEIN high integrity systems Ltd.

Andrew Longhurst, WITTENSTEIN high integrity systems Ltd. | Semi Conductor Review | Top Safety-Critical Real-Time Operating SystemsAndrew Longhurst, Managing Director
The next generation of embedded systems will not be limited by computing performance or software capability. It will be shaped by how confidently those systems can be certified. As autonomous vehicles, industrial equipment, aerospace platforms and medical devices become increasingly software-driven, developers face a growing challenge: proving that complex software can operate safely.

WITTENSTEIN high integrity systems Ltd. has built its expertise around solving this challenge. The company’s SAFERTOS® provides a safety-certified real-time operating system designed to reduce certification complexity by combining reliable software with the engineering evidence, traceability and assurance required for regulated industries.

Foundation for Safety-Critical Systems

Within the semiconductor ecosystem, SAFERTOS® serves as a foundational software layer between processor hardware and application software. When engineers select their embedded development environment, the processor, RTOS and compiler are among the decisions they make. WITTENSTEIN high integrity systems positions SAFERTOS® as the operating environment that enables developers to build applications while simplifying the certification journey.

The company works closely with semiconductor partners to support processor launches and ensure SAFERTOS® is available across hardware platforms. Its architecture separates the operating system into a core layer and a portable layer, allowing the majority of functionality to remain consistent while adapting the smaller hardware-specific portion for chips.

Engineering Confidence through Evidence

For safety-critical developers, the value of SAFERTOS® extends beyond the operating system itself. The company provides design assurance documentation, integration guidance, verification evidence and certification support that help customers demonstrate compliance with industry standards to auditors. Andrew Longhurst, managing director explains, “What our customers are really buying is an easy route to certification. They are getting a highly reliable RTOS, a full design assurance pack with all the certification evidence, and an easier route to certifying SAFERTOS® within their product.”

  • What our customers are really buying is a proven path to certification. They are getting a highly reliable RTOS, a full Design Assurance Pack with all the certification evidence needed to integrate and certify SAFERTOS® within their product.

This approach is built on rigorous engineering practices. SAFERTOS® was developed using systems-based engineering principles, transforming a functional model into a safety-focused platform through hazard analysis, defined requirements and extensive verification. The company validates each implementation against customer-specific processors, compilers and configurations, achieving traceability and comprehensive testing coverage.

Supporting Multiple Industries

Safety and security requirements continue to expand across automotive, aerospace, medical and industrial markets. WITTENSTEIN high integrity systems addresses these needs through a quality framework designed to support multiple standards, allowing engineers to develop a robust platform that can be adapted for certification environments.

The company also provides technical and safety support throughout customer engagements, including onboarding assistance, training and access to development artifacts. By providing source code and verification materials, WITTENSTEIN high integrity systems enables customers to maintain transparency and confidence throughout the product lifecycle.

Preparing for Future Embedded Challenges

As AI, software-defined products and autonomous systems reshape embedded technology, safety remains a concern. WITTENSTEIN high integrity systems sees its role as enabling customers to use advanced capabilities while maintaining controlled and dependable operation. SAFERTOS® can support architectures where safety functions remain isolated from higher-level computing workloads, helping developers introduce innovation without compromising assurance.

Long-term reliability is also central to the company’s strategy. As products such as aircraft and vehicles require decades of operational life, customers seek technology partners with stability and proven expertise. Longhurst notes, “People are designing planes which could last 70 years and cars which could have a lifetime of 30 years. They are looking for RTOS companies that are stable and will be there.”

Through SAFERTOS®, certification expertise and ecosystem partnerships, WITTENSTEIN high integrity systems demonstrates that safety is not simply a compliance obligation. It is an engineering capability that enables the next generation of embedded innovation.

Deep Dive

Reducing Certification Friction in Safety-Critical RTOS Selection

An RTOS decision can become costly long before licensing is signed if certification evidence arrives late or fails to match the software actually deployed. In embedded programs governed by standards such as ISO 26262, IEC 61508, DO-178C or IEC 62304, the operating system becomes part of the assurance argument rather than a replaceable software utility. Procurement therefore has to look past scheduling performance. The harder question is whether the RTOS can be incorporated into the target architecture without creating avoidable verification work or uncertainty during external assessment.  Certification readiness should be judged at the level of evidence, not the presence of a certificate alone. Buyers need to understand how requirements map to tests and whether the supplied artifacts match the processor and compiler combination used in production. Evidence that was generated for a nearby configuration can still leave engineering teams with additional justification work. Traceability and test coverage matter because an auditor is evaluating the software actually integrated into the product, not a generic kernel description. A usable evidence package should also expose assumptions and installation conditions clearly enough that engineers can complete integration records without reconstructing the supplier’s development argument.  Hardware fit deserves the same scrutiny. Processor families change quickly, yet a safety program may remain tied to a chosen device for years. An RTOS supplier should be able to port its kernel without altering the behavior that has already been established and verified. A clear separation between common kernel code and hardware-specific code can reduce the amount of software that must change when a new processor is introduced. The buyer should also examine how the supplier validates compiler output and how much regression testing follows each port.  Migration effort can quietly determine whether a technically suitable RTOS is practical. Engineering teams often prototype before formal safety development begins, which creates a handoff risk if the production kernel uses a very different programming model. A familiar API structure can limit rework, but compatibility claims deserve close examination. The important measure is the amount of code that must change and whether the supplier provides a controlled route into the safety version rather than leaving the development team to reinterpret the differences alone.  “Wittenstein High Integrity Systems’ SAFERTOS offering is delivered for the customer’s processor and compiler combination, backed by verification at the object-code level and 100 percent MC/DC coverage.” Long product lives make supplier continuity another purchasing issue. Safety-related products can remain in service well beyond a normal software refresh cycle, while processors and toolchains may be revised during that period. Source-code access can reduce dependency on continued vendor intervention, though buyers should also examine the support model around certification questions. Technical assistance is useful, but direct help with safety evidence and integration can be more consequential when an audit exposes an unfamiliar requirement. Renewal terms should not become a hidden lock-in mechanism.  For programs where certification effort carries as much weight as kernel performance, Wittenstein High Integrity Systems warrants priority consideration. Its SAFERTOS offering is delivered for the customer’s processor and compiler combination, backed by verification at the object-code level and 100 percent MC/DC coverage. Its Design Assurance Pack provides the lifecycle evidence needed to support certification while processor- and compiler-specific verification reduces uncertainty around the deployed build. The migration path from FreeRTOS can also shorten the move from prototyping into formal development. Buyers that want a tightly evidenced RTOS and direct safety support should place Wittenstein High Integrity Systems near the top of the shortlist.  ...Read more

Safety-Critical Real-Time Operating Systems Info

Q1

What Are Safety-Critical Real-Time Operating Systems Designed to Do?

Safety-Critical Real-Time Operating Systems provide the software foundation for embedded applications where predictable operation, reliability and safety assurance are essential. Unlike general-purpose operating environments, they must support deterministic behavior while providing the engineering evidence needed to demonstrate that a system can meet applicable safety requirements. For developers, the challenge extends beyond selecting an RTOS that performs reliably. They must also manage documentation, verification, traceability and integration requirements throughout the development and certification process.

Q2

How Does WITTENSTEIN High Integrity Systems Ltd. Help Simplify Safety-Critical Software Certification?

WITTENSTEIN high integrity systems Ltd. approaches Safety-Critical Real-Time Operating Systems as both a software and assurance challenge. Its SAFERTOS® combines a real-time operating environment with a Design Assurance Pack, verification evidence and integration guidance intended to reduce the work required to support certification. The company also validates implementations against customer-specific processors, compilers and configurations, helping developers establish traceability and testing coverage within their intended embedded environment.

Q3

What Should Developers Look for When Evaluating a Safety-Critical RTOS?

When evaluating Safety-Critical Real-Time Operating Systems, developers should consider more than functional performance. The availability of design assurance documentation, verification artifacts, integration support and evidence of systematic development can affect how efficiently a product progresses toward certification. Compatibility with the selected processor and development environment also matters, particularly when hardware-specific requirements must be addressed without changing the broader software architecture. A strong evaluation considers both the operating system and the evidence available to support its use in the finished product.

Q4

Why Is Traceability Important in Safety-Critical Embedded Development?

Traceability helps connect system requirements, design decisions, verification activities and resulting evidence. For Safety-Critical Real-Time Operating Systems, that connection can make it easier to demonstrate how software requirements have been addressed and tested. It also provides a more structured basis for reviewing changes, configurations and implementation decisions over the product lifecycle. As embedded applications become more complex, traceability can reduce uncertainty by giving engineering teams and assessors clearer visibility into how the software has been developed and verified.

Q5

How Does WITTENSTEIN High Integrity Systems Ltd. Support Different Embedded Applications?

WITTENSTEIN high integrity systems Ltd. supports Safety-Critical Real-Time Operating Systems across applications in automotive, aerospace, medical and industrial environments. SAFERTOS® uses an architecture that separates the core operating system from a smaller portable layer, allowing the majority of functionality to remain consistent while the hardware-specific portion is adapted for different processors. The company also provides technical and safety support, onboarding assistance, training, source code and development artifacts to support customers throughout implementation and product development.

Q6

How Can Safety and Innovation Coexist in Advanced Embedded Systems?

Safety-Critical Real-Time Operating Systems can help developers introduce increasingly advanced software capabilities while maintaining controlled operation in functions where assurance is essential. This is particularly relevant as AI, autonomous technologies and software-defined products increase the complexity of embedded architectures. Safety functions may need to remain isolated from higher-level workloads, while developers still require a dependable foundation that can support long product lifecycles. The goal is not to limit innovation, but to create a structured environment in which new capabilities can be introduced without weakening safety assurance.

Share this Article:

Company
WITTENSTEIN high integrity systems Ltd.

Management
Andrew Longhurst, Managing Director

Description
WITTENSTEIN high integrity systems Ltd. enables the future of safety-critical embedded systems with SAFERTOS®, providing certification-ready software, engineering assurance, and functional safety expertise. The company helps automotive, aerospace, medical, and industrial developers reduce certification complexity while building reliable, secure, and compliant solutions.