IAR C-STAT
Code Quality and Compliance is Included in IAR's Platform
IAR C-STAT is a static analysis tool that analyzes your source code to find error and vulnerabilities.
Key Benefits
IAR C-STAT enhances code quality and compliance with powerful features for efficient analysis, reporting, and automation.
Coding Assistance
Even if identified issues are known, C-STAT provides detailed documentation explaining potential problems like memory leaks and crashes. Each check includes descriptions and code examples showing both failing and passing cases to support better coding decisions
Detailed and Insightful Reports
C-STAT not only reports rule deviations but also assesses severity and confidence levels. Not all flagged issues indicate real problems, helping developers prioritize fixes effectively and avoid unnecessary changes to well-functioning code
Safety Compliance
C-STAT supports compliance with MISRA C, CWE, CERT C/C++, selected SANS Top 25 checks, OWASP, and MISRA C++. TÜV SÜD-certified versions are available in selected IAR Embedded Workbench functional safety editions, providing industry-required verification for safety-critical applications
Automation-Friendly
C-STAT integrates into CI systems and automated build workflows, making static analysis a seamless, recurring process. Regular automated checks enhance code quality while maintaining development efficiency, ensuring early detection of potential issues in the pipeline
Features
IAR C-STAT provides static analysis, automation support, and compliance checks, integrating seamlessly into development environments and CI/CD workflows.
Integrated in IAR Embedded Workbench
C-STAT is built into IAR Embedded Workbench IDE and IAR Build Tools, enabling static analysis within the development environment. SARIF diagnostics enhance reporting, integration, and structured issue tracking for quality assurance
Comprehensive Code Analysis
Performs source code checks for coding rule deviations in C/C++ files and link-time checks for global and static object usage. Supports MISRA C, MISRA C++, CERT C/C++, CWE, and other standards to improve code quality and security.
Regression Testing
Works with IAR Command Line Build Utility (iarbuild.exe) for automated regression testing. Detects deviations early, reduces debugging effort, and ensures continuous code quality verification for compliance
Command-Line Support
Use C-STAT from the command line for CMake-based projects and CI/CD automation. It integrates into automated pipelines without complex setup, enabling continuous static analysis in modern development workflows
Functional Safety Certification
Integrated into IAR Embedded Workbench and IAR Build Tools, IAR C-STAT is certified by TÜV SÜD to meet multiple functional safety standards. Each new platform release undergoes certification, ensuring consistently high-quality development processes and software.

IAR Supported Architectures
| ARM | RISC-V | Renesas RL78 | Renesas RH850 | Renesas RX | AVR | AVR32 | MSP430 | 8051 | STM8 | Renesas V850 | CR16C | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| IAR Embedded Workbench | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| FuSa Certified | Yes | Yes | Yes | No | No | No | No | No | No | No | No | No |
Supported Standards

Compliance With Coding Standards
C-STAT supports MISRA C/C++:2023 (Arm, RISC-V, RX and RL78 toolchains), MISRA C:2012, MISRA C++:2008, MISRA C:2004, CERT C/C++, CWE, selected SANS Top 25 checks, and OWASP for compliance and security, ensuring high code quality and adherence to industry standards

SARIF Diagnostics Dupport
C-STAT supports SARIF (SARIF (Static Analysis Results Interchange Format), enabling structured issue tracking, seamless toolchain integration, and improved reporting for compliance, security, and development workflows