Formal verification sign-off as a service | LUBIS EDA
Formal Verification Sign-Off

Predictable formal verification sign-off for critical digital IP and SoCs

We help RTL teams reduce schedule uncertainty and uncover simulation-resistant corner cases through a systemized delivery model refined across 325+ formal verification projects.

  • Predictable milestones and clear sign-off criteria
  • Corner-case bugs that are hard to reach in simulation
  • A dedicated team 100% focused on formal verification

What our clients value

900+

Design Bugs Uncovered (post UVM)

Critical issues identified and reported through formal verification

On-Time Delivery

Consistent performance over rolling 12 months

LUBIS EDA in numbers

325+
Projects Delivered
Proven track record
50+
Full-time
Deep specialization, all in Germany
6+
Years
Company Record
15+
Repeat Customers
Long-term partnerships
3
BIG EDA Tool knowledge
Cadence, Synopsys, Siemens
5
Fortune25 clients
Trusted by world's largest players

Who this formal verification sign-off service is for?

Typical situations

  • A block is on the critical path and tape-out dates can't slip.
  • Complexity is rising faster than your ability to hire deep formal expertise.
  • You simulate heavily, but you still worry about rare corner cases.
  • Formal exists, but bandwidth, structure, or convergence is the bottleneck.

What are your high-risk blocks?


The problem

The problem: verification is now the schedule bottleneck

As designs get more complex and schedules get tighter, the hardest bugs show up late, often in scenarios that testbenches don't reach.

Formal verification can close that gap, but it only becomes predictable when it's executed with the right structure: clear sign-off targets, sound assumptions, strong abstractions, and disciplined convergence.

The solution

What we do: Formal Verification Sign-Off

Outcome

a verified IP block / subsystem with agreed sign-off criteria and the transparency to defend sign-off internally.

What you receive

  1. 01Formal sign-off plan and scope definition
  2. 02Property plan + assumptions/constraints approach
  3. 03Coverage & convergence tracking
  4. 04Results documentation / sign-off report
  5. 05Reusable verification artifacts (as agreed)

How it works: Discover → Plan → Prep → Execute → Sign-off

Our delivery model is designed to make formal work predictable and visible — without hero-based consulting:

1Discover

Every successful verification project begins with understanding. During discovery, our engineering team develops a comprehensive grasp of the design under verification by reviewing the available documentation, specifications, architecture, interfaces, and design intent. Whether we will be verifying a cache, floating-point unit, controller, or another subsystem, the objective is to establish a shared understanding of what is being verified, what information is available, and, especially, what the customer's broader engineering objectives are.

This shared understanding establishes the foundation upon which all subsequent planning and verification decisions are made. The process is designed to require minimal effort from the customer: once the available design materials have been provided, LUBIS independently reviews and synthesizes the documentation to develop the technical context needed for the engagement. Customer input can then focus on clarifying specific questions and confirming broader engineering objectives, rather than guiding the discovery process itself. The result is an informed foundation for planning that establishes alignment and trust without placing an additional burden on the customer's engineering team.

2Plan

Planning transforms understanding into execution strategy. Based on the knowledge gained during discovery, the verification team defines verification objectives, identifies technical risks, determines the appropriate verification approach which includes abstraction techniques, end-to-end vs. whitebox checks, as well as assumptions on the convergence of the proofs and coverage, allocates responsibilities, establishes milestones, and defines the evidence required to support sign-off confidence.

3Prepare

Thorough preparation ensures that the project will not only get off to a smooth start, but also proceed efficiently and consistently. Verification environments are configured, required assets assembled, assumptions reviewed, constraints developed, workflows established, and engineering teams aligned before execution begins.

4Execute

Execution is where formal verification produces engineering evidence. Engineers develop and run properties, analyze results, debug failing assertions, investigate failures, refine abstractions, improve coverage, and continuously adapt the verification strategy as new information emerges. Where appropriate, automation and AI can accelerate many individual activities—but engineering judgment remains central to thoughtfully applying these efficiencies, interpreting results, and determining appropriate next steps.

5Sign off

Sign-off is not simply the conclusion of execution: it is the disciplined evaluation of whether sufficient evidence exists to demonstrate that all verification objectives have been achieved. Engineers review properties, constraints, coverage, cover pass, remaining risks, and outstanding issues before determining that the design is ready to proceed. LUBIS also supports customers in integrating formal verification results into their regression flows, helping preserve the value of the verification effort as the design continues to evolve.

The output of this stage is a formal sign-off package: a structured, reviewable body of evidence covering scope, assumptions and their validation, per-property proof status, the coverage and completeness argument, documented abstractions, residual risk, and an explicit register of known gaps. It is what allows a sign-off decision to be reviewed and trusted by people who did not perform the verification themselves.


Why LUBIS EDA?

Specialist at scale

A layered team of verification specialists across every depth of expertise.

We sign-off important IP

Sign-off quality for the IP that protects and differentiates your product.

Our sign-off maturity flow

A proven, repeatable flow that drives predictable quality and coverage.

Engagement models

Fixed(scope-based)

Turn-key formal sign-off for a mature design.

Subscription(time-based)

Allocate a certain number of LCIs per month.
Guaranteed capacity for long-term projects.

Objections you might have about a formal verification sign-off

“We can do it ourselves.”

Many teams can. The question is whether it will be fast enough on the highest-risk blocks without pulling experts from everything else.

“We already simulate a lot.”

Simulation is essential. Formal systematically explores scenarios that are unrealistic to cover with testbenches alone.

“Formal is too hard / doesn't scale.”

Formal scales with the right structure — abstractions, constraints, and a clear sign-off methodology.

Questions we hear most about formal verification sign-off

What is formal verification sign-off, and why does it matter for tape-out?

Formal verification sign-off is a structured, exhaustive process that proves or disproves defined behaviors in your RTL design, without relying on test stimulus. Unlike simulation, which checks behavior under expected conditions, formal verification systematically explores every reachable scenario within defined proof bounds. Sign-off is complete when all checkers are proven, all intended behaviors are confirmed reachable, and results are documented with full traceability. It gives you the confidence to tape out a critical IP block with a defensible, reproducible record of what was verified and what was not.

Why use formal verification sign-off instead of simulation?

Simulation verifies that your design behaves correctly under the scenarios you thought to test. Formal verification proves that certain behaviors cannot occur, regardless of input sequence. Simulation-resistant corner-case bugs (race conditions, protocol violations, and multi-cycle state-machine anomalies) live in scenarios that no testbench will ever reach. Across 325+ formal verification sign-off projects, our engineers have found 900+ real bugs that simulation missed, including critical findings just weeks before tape-out.

How do you know when formal verification sign-off is actually complete?

A passing proof run is not sign-off. Our formal verification sign-off process checks five conditions before declaring done: all checkers are proven within agreed bounds or failing for a confirmed design bug; all intended behaviors are reachable and confirmed by cover points; all constraints and assumptions are reviewed and justified; non-converging proofs are addressed through bound analysis; and a formal sign-off report is delivered. This gives you a traceable record you can defend internally and reproduce if the RTL is revisited later

Do you actually find bugs, or just confirm that things work?

We find real bugs. Across 325+ formal verification sign-off projects, our team has uncovered 900+ confirmed design bugs: incorrect exception handling, protocol violations, and corner-case data corruption that had been present in production-bound RTL for months. Formal verification sign-off is not a quality certificate; it is an active, systematic bug-finding process with documented proof of what was covered.

What does a formal verification sign-off project look like from start to finish?

Every formal verification sign-off project follows a five-phase delivery model. In the Discover phase, we review the design documentation, specifications, and design intent to build a shared understanding of the block and your engineering objectives. In the Plan phase, we align on scope, sign-off targets, and milestones. In the Prep phase, we build the formal environment: constraints, abstractions, and a property set. In the Execute phase, we drive convergence, deliver on-the-spot bug reports, and provide weekly progress updates. In the Sign-off phase, we deliver the final report, all developed SystemVerilog assertions, and reusable verification artifacts. Typical project durations range from 10 days for standard blocks to 50 days for complex compute cores.

What do we need to provide to get started with formal verification sign-off?

To start a formal verification sign-off engagement, we need the RTL of the target block, the design specification, and a few sessions with the responsible designer to clarify intent and known risks. You do not need in-house formal verification expertise, and you do not need your own formal tool licenses. We handle the full flow: verification strategy, property development, tool environment, convergence, and reporting. We deliver everything you need to defend sign-off.

Need us to sign-off your design?

Bring one critical IP block and we'll outline a formal verification sign-off plan for you.

Make an appointment

Training Topics

  1. Abstraction vectors (time, functionality)
  2. AIP for protocols
  3. AIP orchestration
  4. BMC & IPG, invariants
  5. Codestyle
  6. Completeness
  7. Liveness property, safety property
  8. Non-determinism (abstraction technique)
  9. Response generation (abstraction technique)
  10. Scoreboard (abstraction technique)
  11. Signal cutting, blackboxing
  12. State space explosion and mitigation techniques
  13. SVA fundamentals
  14. Whitebox checking, blackbox checking, greybox checking
  15. Witness, vacuity, reachability

Become a leader in formal verification