
The ELISA Project community gathered at Canonical’s London office from June 9–11, 2026, for three days of technical presentations, discussions, and collaboration focused on advancing Linux for safety-critical applications.
The workshop brought together ELISA members, contributors, and industry experts to exchange knowledge across topics including safety certification, cybersecurity compliance, real-time Linux, AI-assisted development, safety cases, testing, requirements, and open source best practices.
In this post-event blog series, we will highlight three sessions each week. This first article covers the opening Ask Me Anything session, a cybersecurity compliance case study from Canonical, and OSADL’s work on long-term latency monitoring with PREEMPT_RT.
Welcome and Introductions – Kate Stewart, Linux Foundation; Philipp Ahmann, ELISA TSC Chair; Teemu Kärkkäinen and Jaume Rafols Borrell, Canonical
The ELISA Workshop London 2026 opened with a welcome from ELISA leadership and co-host Canonical. Teemu Kärkkäinen and Jaume Rafols Borrell introduced Canonical’s mission and its work to bring secure, reliable, and dependable open source software to mission-critical systems. They highlighted security, quality management, and safety as interconnected foundations for dependable software. Philipp Ahmann provided an overview of the workshop and its collaboration guidelines, while Kate Stewart introduced her current work connecting SPDX with software requirements and architecture. Slides here.
Ask Me Anything – Gabriele Paoloni, ELISA Governing Board Chair; Philipp Ahmann, ELISA TSC Chair
This Ask Me Anything session introduced the ELISA Project’s work to enable Linux for use in safety-critical applications. Gabriele Paoloni and Philipp Ahmann discussed how safety standards across industries share common expectations around requirements, documentation, testing, traceability, and system understanding, even when their levels of rigor differ. They explained how ELISA’s horizontal and industry-focused working groups collaborate on processes, tools, system architectures, Linux features, and use cases. The session also clarified that ELISA does not certify Linux or guarantee the safety of a complete product. Instead, it helps identify gaps and develop approaches that organizations can use within their own system and certification contexts. Questions and discussion also addressed AI-based tools, real-time behavior, programmable logic controllers, and the growing complexity of safety-critical systems. Slides here.
Certifying Linux for Safety-Critical Systems: A Cybersecurity Compliance Case Study – Mikel Azkarate-Askatsua, Canonical
Mikel Azkarate-Askatsua presented Canonical’s cybersecurity compliance work as an early step in its broader journey toward dependable Linux for critical automotive and industrial systems. He explained how Canonical used its existing secure software development lifecycle as the foundation for aligning its processes with the ISO/SAE 21434 and IEC 62443-4-1 cybersecurity standards. The session showed how established practices—including threat modeling, security testing, package reviews, vulnerability management, security updates, and disclosure—were mapped to the standards, while identified gaps were used to improve Canonical’s development processes. Examples included Ubuntu’s Main Inclusion Review and vulnerability management processes. Mikel also discussed the challenge of applying traditional supplier-based certification approaches to open source communities, where there may be no conventional supplier. The experience gained through these process certifications now supports Canonical’s continued work on quality management and functional safety. Slides here.
Long term latency monitoring of Linux with PREEMPT_RT – Jan Altenberg, OSADL
Jan Altenberg presented OSADL’s approach to evaluating the real-time behavior of Linux systems using PREEMPT_RT. He explained that the complexity of Linux and modern processor architectures makes execution times difficult to predict, leading OSADL to use empirical testing alongside other evaluation methods. Through the OSADL QA Farm, around 200 systems are continuously monitored under different load conditions, including high CPU load, graphics activity, moderate load, and idle states. The farm uses cyclictest and kernel-internal latency measurements while also recording system health data, hardware information, kernel versions, configurations, and applied patches. Jan demonstrated how latency histograms and timestamps can help identify outliers and investigate possible causes by correlating them with other recorded data. Although these measurements do not provide mathematical proof of timing behavior, long-term monitoring supports reproducibility, comparison, regression testing, and a better understanding of system behavior over time.
These sessions reflected the range of work involved in enabling Linux for safety-critical applications. The community discussion highlighted the importance of shared processes, tools, requirements, testing, traceability, and system understanding. Canonical’s case study showed how existing open source development practices can be mapped to cybersecurity standards and improved where gaps are identified, while OSADL demonstrated how continuous, long-term latency monitoring can support reproducibility, comparison, and regression testing for real-time Linux systems.
Together, the sessions showed how collaboration, practical experience, and measurable evidence can help organizations better understand and address the challenges of using Linux in safety-critical environments. The next blog in this series will highlight three more sessions from the ELISA Workshop London 2026. Stay tuned!