SDVs demand a layered testing strategy that treats elements as progressive, mutual stages – not rivals – anchored in clear definitions, credible models and virtual results that translate to the road
Vehicles today are continuously evolving software platforms, which puts new pressure on how testing is structured across the lifecycle. To keep up with frequent releases and OTA updates, the optimal use of SIL, HIL and vehicle integration (VI), also called vehicle-in-the-loop, becomes a strategic element rather than a tooling detail.
In SDVs, functions are updated long after SOP, so relying on late-stage vehicle tests alone is no longer viable for safety or schedule. There is considerable pressure to maintain a rapid, continuous release cadence. Testing must be pushed earlier into development while still providing defensible evidence for safety cases and regulatory expectations over multiple software generations.
A layered approach – SIL, HIL and VI combined with on-road testing – provides a progression from fast, scalable virtual (model) checks to highly realistic, driver-in-the-loop evaluations. When those layers are integrated into a coherent architecture, they enable continuous regression across every release and OTA campaign. From my experience, I place great value on regression testing.
If you have read any of my work, you will know my penchant for a common lexicon. SIL enables feature exploration before production on a virtual ECU (subsystem) or host, connected to simulated components, sensors and communication networks (models). It is optimized for early virtual system integration testing, enabling rapid execution of thousands of scenarios before hardware and full production software are available.
HIL adds realism by connecting real ECUs or domain controllers to real-time components and network models on a test bench – a vehicle in the lab. This enables verification of timing behavior, network load, diagnostics and safety mechanisms under controlled yet representative conditions, well before full vehicles are built. From experience, securing time on the vehicle is not trivial, and we need to have some confidence in the product and system before VI.
VI testing takes place in a real vehicle on a proving ground, with its perception and control systems interacting with a controlled virtual environment. VI bridges the gap between lab rigs and road tests, enabling safe, repeatable execution of complex, hazardous scenarios that would be difficult to stage in the real world, in real time.
SIL, HIL and VI deliver the most value when they are treated as a progression rather than as competing options. SIL is ideal for early, rapid fault discovery, software refactoring and large-scale scenario sweeps during early development, when interfaces are still fluid and hardware is not yet fixed.
Once software stabilizes and hardware is available, HIL becomes the workhorse for ECU and domain-level integration, confirming that real electronics and networks behave as expected under realistic loads, failures and transients. VI and structured on-road campaigns then take over for full system behavior, human-machine interaction and vehicle dynamics in complex traffic, while reusing core scenarios defined earlier in SIL and HIL.
In an optimized SDV strategy, scenarios and requirements are progressively elaborated through learning enabled by SIL, HIL and VI. A lane change with a cut-in vehicle, for example, is first debugged in SIL, then checked for timing and network behavior in HIL, and finally executed in VIL on a controlled track and then on-road tests to confirm full-system performance.
Because SIL and HIL rely on virtual elements, sensors and environments, the credibility of their results depends on model veracity. Model veracity includes fidelity (the extent to which the model details represent the actual system), validity range (the range of applicability) and quantified error relative to physical measurements.
A practical approach is to treat model correlation as a formal activity. Engineering, rig, dyno and track tests are used to calibrate models; error bounds are computed for key outputs, such as forces, temperatures, signal delays and sensor artifacts; and these bounds are documented as part of the test environment definition. This makes it clear which requirements can be verified with confidence in SIL or HIL, and which still require VI or real-world testing due to model limitations.
When SIL, HIL and VI are used as a coherent stack, with clear definitions, effort to obtain strong model veracity and disciplined configuration management, they become an enabler for continuous delivery in SDVs. High-risk, safety-critical scenarios can be re-executed selectively in SIL and HIL for each code change. At the same time, VI and on-road checks provide final confirmation before wide OTA deployment. The result is a test strategy that aligns with the SDV business model: rapid, frequent software evolution, anchored in a reusable body
of trustworthy test evidence spanning virtual benches, real hardware and real vehicles.





