FUNCTIONAL SAFETY

Safety PLCs, SIL and SIS Explained: Functional Safety for Engineers

What a safety instrumented system is, why SIL belongs to a safety function rather than a plant, how voting and proof testing work, and what changes when you program a safety PLC.

By EDWartens engineering team 18 January 2026 Updated 5 October 2026 6 min
Safety PLCs, SIL and SIS Explained: Functional Safety for Engineers

A safety PLC is a controller certified for safety functions, used as the logic solver in a safety instrumented system (SIS) that takes a process to a safe state when control has failed. SIL, the Safety Integrity Level, sets how reliable each safety function must be. The key standards are IEC 61508 and, for process plants, IEC 61511.

“What is Functional Safety? - IEC 61511 and IEC 61508 Standards” by Instrumentation Tools, 19 min. Played from the creator's own YouTube channel; the video belongs to them.

In this lesson by Instrumentation Tools, functional safety and the two standards are introduced. Watch it, then use the notes below to connect the ideas to the programming and maintenance work a PLC engineer actually does.

Control and safety are separate layers

The basic process control system (BPCS), usually a PLC or a DCS, keeps the plant running: it holds levels, temperatures and pressures at setpoint. Our guide to oil and gas automation shows how DCS, SCADA and safety systems sit side by side on a real site. The safety instrumented system does one job only: when a dangerous condition is detected, it acts to reach a defined safe state, such as closing a valve or stopping a pump. It is kept independent of the control system because a failure that upsets control, a stuck transmitter or a crashed controller, must not also disable the protection.

Each protective action is a safety instrumented function (SIF). A SIF has a sensor or sensors, a logic solver (the safety PLC) and final elements such as shutdown valves. On drawings, SIS instruments and interlocks have their own symbols; how to read a P&ID explains them, and process instrumentation basics covers the transmitters themselves. It is defined by what it detects, its trip point, the safe state it brings about and how fast it must respond. "Close the feed valve within 2 seconds if reactor pressure exceeds 18 bar" is a SIF. "The safety system" is not.

The standards behind safety PLCs, SIL and SIS

  • [IEC 61508](https://webstore.iec.ch/en/publication/5515) is the generic functional safety standard. It is mostly used by manufacturers of sensors, logic solvers and valves to design and certify their products.
  • [IEC 61511](https://webstore.iec.ch/en/publication/24241) applies functional safety to the process industries and is written for the end user: the people who specify, design, install, operate and maintain an SIS.
  • IEC 62061 and ISO 13849-1 cover machinery safety functions, such as emergency stops, guard doors and light curtains. ISO 13849-1 uses Performance Levels a to e rather than SIL. The electrical side of a machine's control panel is covered in our guide to electrical control panel design with IEC 60204-1.

Regulators lean on the same ideas. The UK Health and Safety Executive's technical guidance on control systems for major-hazard sites refers to IEC 61508 and to SILs when it describes what it expects of instrumented protection.

What SIL actually means

A SIL is a target for one safety function, not a grade for a plant or an industry. It comes from a risk assessment. A hazard study, often a HAZOP, identifies what can go wrong. A layer of protection analysis (LOPA) then asks how often the initiating event happens, what other independent layers already reduce the risk (alarms with operator response, relief valves, bunds), and how much risk reduction is still needed. That remaining gap sets the SIL target.

For a function that is demanded rarely, the usual case in process plants, each SIL corresponds to a band of average probability of failure on demand (PFDavg), or equivalently a risk reduction factor:

SIL bands for low-demand safety functions (IEC 61508 / 61511)
SIL bands for low-demand safety functions (IEC 61508 / 61511)

So a SIL 2 function must fail to work on demand less than once in a hundred demands on average, and at least once in a thousand is not good enough for SIL 3. SIL 4 is very rarely used in the process industries; designers usually add other layers instead.

How the design meets the target

Three things have to line up for a SIF to claim a SIL:

  1. Random hardware failures. The PFDavg calculation for the whole loop, sensor, logic solver and final element, must fall inside the band. Final elements usually dominate, which is why valves get so much attention.
  2. Architectural constraints. The standards require a minimum hardware fault tolerance, in effect redundancy, for higher SILs.
  3. Systematic capability. Every device must be suitable for the SIL, and the work must follow the safety lifecycle, because design and programming mistakes are not random.

Voting

Redundant sensors are combined by voting. 1oo2 (one out of two) trips if either sensor sees the condition: safer, but more spurious trips. 2oo2 trips only if both agree: fewer spurious trips, but less safe. 2oo3 is the common compromise: it tolerates one failed sensor either way. Redundancy only helps if the channels do not share a common cause, such as the same impulse line, the same power supply or the same calibration error.

The safety lifecycle

The safety lifecycle, in outline
The safety lifecycle, in outline

The document that holds it together is the safety requirements specification (SRS). It lists every SIF with its trip point, safe state, response time, SIL target, proof test interval, bypass rules and reset behaviour. If something is not in the SRS, the programmer has to guess, and guessing is how safety systems go wrong.

What changes when you program a safety PLC

Safety PLC programming looks familiar but works under stricter rules:

  • Separate safety and standard programs. Safety logic lives in its own protected area, with its own signature or checksum, and changes are tracked.
  • Certified building blocks. You use the vendor's certified safety function blocks for emergency stops, guard monitoring, two-hand control and feedback monitoring rather than writing your own.
  • Limited variability. IEC 61511 expects application programs to be written in a limited variability language, typically ladder or function blocks, with no clever tricks.
  • Safe communication. Safety I/O talks to the CPU over safety protocols such as PROFIsafe or CIP Safety, which detect corrupted, delayed or misrouted messages.
  • Defined safe state. Most process trips are de-energise to trip, so a broken wire or lost power takes the plant safe.
  • Test everything against the SRS. Every function is validated, and every later change goes through management of change and re-validation.

On Siemens this is Safety Integrated with F-CPUs and F-modules in TIA Portal; on Rockwell it is GuardLogix in Studio 5000.

Operation: where safety is kept or lost

A SIS is only as good as its maintenance. Proof testing at the interval in the SRS finds dangerous failures that diagnostics cannot, such as a valve that will not close fully. Bypasses and maintenance override switches must be controlled, recorded and removed. A SIS with a permanent bypass has no SIL at all.

Competence

IEC 61511 requires people working on an SIS to be competent for their role. Many engineers also take vendor-independent functional safety engineer schemes run by certification bodies, which include an exam. A course certificate, ours included, shows study; it is not a functional safety certification.

Learn functional safety free

Safety Instrumented Systems and SIL to IEC 61511 covers SIFs, LOPA, PFDavg, voting, the SRS, validation and proof testing, with no software needed. Siemens Safety Integrated and Allen-Bradley GuardLogix Safety cover the programming side, and Industrial Instrumentation the field devices. Browse all free safety courses. Learning is free in full. The SIS course is an advanced course: if you pass its final assessment, the optional EDWartens Certificate of Completion is a small one-off fee, and checkout shows your price. It is verifiable at edwartens.com/verification and is not a functional safety certification or a vendor qualification.

Take the free course

Questions

What is the difference between a safety PLC and a standard PLC?

A safety PLC is certified for use in safety functions, typically to IEC 61508, with redundant processing, extensive self-diagnostics and a defined safe state on failure. A standard PLC runs control logic and is not relied on for safety.

What does SIL mean?

Safety Integrity Level: a measure of how much risk reduction a safety instrumented function must deliver. SIL 1 to SIL 4 correspond to bands of average probability of failure on demand, with SIL 4 the most demanding.

Is SIL set for a whole plant?

No. SIL is assigned to each safety instrumented function from a risk assessment. One plant can have functions at SIL 1, SIL 2 and SIL 3, and none at all where other layers already reduce the risk enough.

What is the difference between IEC 61508 and IEC 61511?

IEC 61508 is the generic functional safety standard, written largely for people who make safety devices and systems. IEC 61511 applies it to the process industries and is written for the people who specify, build and operate a safety instrumented system.

Which standards apply to machinery safety?

Machinery safety functions are usually designed to IEC 62061, which uses SIL, or ISO 13849-1, which uses Performance Levels a to e. Safety PLCs such as Siemens F-CPUs and GuardLogix are used in both process and machine applications.

Sources

Written by the EDWartens engineering team for general education. Product names are trademarks of their owners; mentioning them does not imply endorsement. Prices and terms of other providers were checked on the date shown and can change.