FUNCTIONAL SAFETY
Safety PLCs, SIL and SIS Explained: Functional Safety for Engineers
What a safety instrumented system is, why SIL belongs to a safety function rather than a plant, how voting and proof testing work, and what changes when you program a safety PLC.

A safety PLC is a controller certified for safety functions, used as the logic solver in a safety instrumented system (SIS) that takes a process to a safe state when control has failed. SIL, the Safety Integrity Level, sets how reliable each safety function must be. The key standards are IEC 61508 and, for process plants, IEC 61511.
In this lesson by Instrumentation Tools, functional safety and the two standards are introduced. Watch it, then use the notes below to connect the ideas to the programming and maintenance work a PLC engineer actually does.
Control and safety are separate layers
The basic process control system (BPCS), usually a PLC or a DCS, keeps the plant running: it holds levels, temperatures and pressures at setpoint. Our guide to oil and gas automation shows how DCS, SCADA and safety systems sit side by side on a real site. The safety instrumented system does one job only: when a dangerous condition is detected, it acts to reach a defined safe state, such as closing a valve or stopping a pump. It is kept independent of the control system because a failure that upsets control, a stuck transmitter or a crashed controller, must not also disable the protection.
Each protective action is a safety instrumented function (SIF). A SIF has a sensor or sensors, a logic solver (the safety PLC) and final elements such as shutdown valves. On drawings, SIS instruments and interlocks have their own symbols; how to read a P&ID explains them, and process instrumentation basics covers the transmitters themselves. It is defined by what it detects, its trip point, the safe state it brings about and how fast it must respond. "Close the feed valve within 2 seconds if reactor pressure exceeds 18 bar" is a SIF. "The safety system" is not.
The standards behind safety PLCs, SIL and SIS
- [IEC 61508](https://webstore.iec.ch/en/publication/5515) is the generic functional safety standard. It is mostly used by manufacturers of sensors, logic solvers and valves to design and certify their products.
- [IEC 61511](https://webstore.iec.ch/en/publication/24241) applies functional safety to the process industries and is written for the end user: the people who specify, design, install, operate and maintain an SIS.
- IEC 62061 and ISO 13849-1 cover machinery safety functions, such as emergency stops, guard doors and light curtains. ISO 13849-1 uses Performance Levels a to e rather than SIL. The electrical side of a machine's control panel is covered in our guide to electrical control panel design with IEC 60204-1.
Regulators lean on the same ideas. The UK Health and Safety Executive's technical guidance on control systems for major-hazard sites refers to IEC 61508 and to SILs when it describes what it expects of instrumented protection.
What SIL actually means
A SIL is a target for one safety function, not a grade for a plant or an industry. It comes from a risk assessment. A hazard study, often a HAZOP, identifies what can go wrong. A layer of protection analysis (LOPA) then asks how often the initiating event happens, what other independent layers already reduce the risk (alarms with operator response, relief valves, bunds), and how much risk reduction is still needed. That remaining gap sets the SIL target.
For a function that is demanded rarely, the usual case in process plants, each SIL corresponds to a band of average probability of failure on demand (PFDavg), or equivalently a risk reduction factor:

So a SIL 2 function must fail to work on demand less than once in a hundred demands on average, and at least once in a thousand is not good enough for SIL 3. SIL 4 is very rarely used in the process industries; designers usually add other layers instead.
How the design meets the target
Three things have to line up for a SIF to claim a SIL:
- Random hardware failures. The PFDavg calculation for the whole loop, sensor, logic solver and final element, must fall inside the band. Final elements usually dominate, which is why valves get so much attention.
- Architectural constraints. The standards require a minimum hardware fault tolerance, in effect redundancy, for higher SILs.
- Systematic capability. Every device must be suitable for the SIL, and the work must follow the safety lifecycle, because design and programming mistakes are not random.
Voting
Redundant sensors are combined by voting. 1oo2 (one out of two) trips if either sensor sees the condition: safer, but more spurious trips. 2oo2 trips only if both agree: fewer spurious trips, but less safe. 2oo3 is the common compromise: it tolerates one failed sensor either way. Redundancy only helps if the channels do not share a common cause, such as the same impulse line, the same power supply or the same calibration error.
The safety lifecycle

The document that holds it together is the safety requirements specification (SRS). It lists every SIF with its trip point, safe state, response time, SIL target, proof test interval, bypass rules and reset behaviour. If something is not in the SRS, the programmer has to guess, and guessing is how safety systems go wrong.
What changes when you program a safety PLC
Safety PLC programming looks familiar but works under stricter rules:
- Separate safety and standard programs. Safety logic lives in its own protected area, with its own signature or checksum, and changes are tracked.
- Certified building blocks. You use the vendor's certified safety function blocks for emergency stops, guard monitoring, two-hand control and feedback monitoring rather than writing your own.
- Limited variability. IEC 61511 expects application programs to be written in a limited variability language, typically ladder or function blocks, with no clever tricks.
- Safe communication. Safety I/O talks to the CPU over safety protocols such as PROFIsafe or CIP Safety, which detect corrupted, delayed or misrouted messages.
- Defined safe state. Most process trips are de-energise to trip, so a broken wire or lost power takes the plant safe.
- Test everything against the SRS. Every function is validated, and every later change goes through management of change and re-validation.
On Siemens this is Safety Integrated with F-CPUs and F-modules in TIA Portal; on Rockwell it is GuardLogix in Studio 5000.
Operation: where safety is kept or lost
A SIS is only as good as its maintenance. Proof testing at the interval in the SRS finds dangerous failures that diagnostics cannot, such as a valve that will not close fully. Bypasses and maintenance override switches must be controlled, recorded and removed. A SIS with a permanent bypass has no SIL at all.
Competence
IEC 61511 requires people working on an SIS to be competent for their role. Many engineers also take vendor-independent functional safety engineer schemes run by certification bodies, which include an exam. A course certificate, ours included, shows study; it is not a functional safety certification.
Learn functional safety free
Safety Instrumented Systems and SIL to IEC 61511 covers SIFs, LOPA, PFDavg, voting, the SRS, validation and proof testing, with no software needed. Siemens Safety Integrated and Allen-Bradley GuardLogix Safety cover the programming side, and Industrial Instrumentation the field devices. Browse all free safety courses. Learning is free in full. The SIS course is an advanced course: if you pass its final assessment, the optional EDWartens Certificate of Completion is a small one-off fee, and checkout shows your price. It is verifiable at edwartens.com/verification and is not a functional safety certification or a vendor qualification.
Take the free course
FreeSafety · Advanced · Free
Safety Instrumented Systems and SIL to IEC 61511
FreeSafety · Intermediate · Free
Siemens Safety Integrated: S7-1500F and S7-1200F in TIA Portal
FreeSafety · Intermediate · Free
Allen-Bradley GuardLogix Safety and CompactLogix 5380
FreeInstrumentation · Beginner · Free
Industrial Instrumentation and Process Control
Questions
What is the difference between a safety PLC and a standard PLC?
A safety PLC is certified for use in safety functions, typically to IEC 61508, with redundant processing, extensive self-diagnostics and a defined safe state on failure. A standard PLC runs control logic and is not relied on for safety.
What does SIL mean?
Safety Integrity Level: a measure of how much risk reduction a safety instrumented function must deliver. SIL 1 to SIL 4 correspond to bands of average probability of failure on demand, with SIL 4 the most demanding.
Is SIL set for a whole plant?
No. SIL is assigned to each safety instrumented function from a risk assessment. One plant can have functions at SIL 1, SIL 2 and SIL 3, and none at all where other layers already reduce the risk enough.
What is the difference between IEC 61508 and IEC 61511?
IEC 61508 is the generic functional safety standard, written largely for people who make safety devices and systems. IEC 61511 applies it to the process industries and is written for the people who specify, build and operate a safety instrumented system.
Which standards apply to machinery safety?
Machinery safety functions are usually designed to IEC 62061, which uses SIL, or ISO 13849-1, which uses Performance Levels a to e. Safety PLCs such as Siemens F-CPUs and GuardLogix are used in both process and machine applications.
Sources
- IEC: IEC 61508-1:2010, Functional safety, Part 1: General requirements
- IEC: IEC 61511-1:2016, Safety instrumented systems for the process industry sector
- HSE: Control systems (COMAH technical guidance)
- ODVA: CIP Safety
Written by the EDWartens engineering team for general education. Product names are trademarks of their owners; mentioning them does not imply endorsement. Prices and terms of other providers were checked on the date shown and can change.

DCS Training: What a Distributed Control System Is and How to Learn One Free

PLC Training in the UK: Apprenticeships, Vendor Courses and What 'Accredited' Means

Water Treatment Automation: How PLC and SCADA Control a Treatment Works

Pharmaceutical Automation: GMP, GAMP 5, 21 CFR Part 11 and ISA-88 for Control Engineers

Food and Beverage Automation: CIP, Batching, PackML and Hygienic Design for PLC Engineers

4-20 mA Current Loop Explained: Wiring, Loop Power and Faults (Video)