Standards and Certification: How to Read Functional Safety SIL
The most common misunderstanding of functional safety in engineering practice is to treat SIL as a product parameter of the sensor — "this sensor is SIL 2". The accurate statement is: SIL describes the integrity level of a safety function; the object of assessment is the whole safety loop of "sensor — logic unit — actuator". A single component can only declare that it is "suitable for a safety function of a given level" and provide the corresponding reliability data and conditions of use. The trend is that, as equipment export and whole-machine safety assessment spread, purchasers are raising the demand for completeness of certification documents; at the same time another deviation has appeared — substituting a rating label for a system assessment. This article sorts the relationship among the relevant standard systems and how to look at them. No SIL rating is declared for any specific model.
The standards system: how the three main lines relate
| Standard | Role | Rating statement | Typical application |
|---|---|---|---|
| IEC 61508 | Functional-safety foundation standard (generic) | SIL 1–4 | Generic framework for component and system development |
| IEC 62061 | Electrical safety control systems in machinery | SIL 1–3 | Machinery whose systems are mainly electrical / electronic / programmable |
| ISO 13849-1 | Generic part of machinery safety control systems | PL a–e | Mixed systems including pneumatic, hydraulic and mechanical |
The three are not mutually exclusive: IEC 61508 is the foundation; IEC 62061 and ISO 13849-1 are application standards for the machinery sector. A correspondence for reference between the two rating sets is given in the standard documents (for example a higher PL usually corresponds to a higher SIL), but they cannot simply be equated. Specific conversion must follow the standard text and the assessment conclusion. Which main line to choose depends on the technical composition of the safety function and the convention of the target market.
SIL is not a property of a single sensor
The integrity of a safety function (for example "stop immediately when the press ram exceeds a safe position") depends on the joint behaviour of three parts: detection (the displacement sensor), judgement (a safety PLC or safety relay) and actuation (a valve, a brake). Insufficient capability in any one becomes the short board of the whole loop. Assessment therefore looks at loop-level probability of failure, diagnostic coverage, resistance to common-cause failure and systematic capability — not at adding up sensor labels.
This also explains why self-diagnostic capability is not a safety rating: diagnostics raise availability and fault visibility and are one means of achieving high diagnostic coverage, but they only count inside a system-assessment framework. The conceptual distinction is in smart sensors: the trend towards self-awareness through self-diagnostics.
The role of redundancy and dual channels
One conventional engineering means of raising safety integrity is a redundant structure: two independent position-detection channels compare with each other, and a safe state is entered if either channel is abnormal or the two-channel deviation exceeds the limit. It improves two things at once — detectability of a single-point failure, and the ability to keep the safety function when one channel fails. The technical background is in what redundant output is: the story behind dual-channel safety design; on-site comparison and verification are in redundant installation: how to compare two sensors.
Two boundaries must be stressed: first, redundancy does not automatically equal a given SIL rating and must still be assessed to the standard; second, if the two channels share the same supply, the same position magnet or the same mounting structure, common-cause failure will weaken the practical effect of the redundancy, so the architecture should separate them as far as possible. At product level, a dual-output structure can refer to the 16R redundant cylinder-integrated, which provides two independent position outputs in the same rod and is suited to hydraulic machines that need dual-channel comparison.
The difference from explosion-protection certification: do not mix them
| Dimension | Functional safety (SIL/PL) | Explosion-protection certification (Ex) |
|---|---|---|
| Problem addressed | Hazards caused by control-system failure | The equipment becoming an ignition source in an explosive atmosphere |
| Object of assessment | The safety-function loop | The explosion-protection type of the equipment itself |
| Common marking | SIL 1–3 / PL a–e | Ex ia (intrinsic safety), Ex d (flameproof), Ex tD (dust) |
| Can they replace each other? | No. They are independent and may both be required | |
The selection logic of explosion-protection types is in explosion protection basics: intrinsic safety, flameproof and dust protection compared and explosion-protected area selection: which certification applies to Zone 0/1/2. On-site wiring requirements of an intrinsically safe loop are in hazardous-area installation: intrinsically safe wiring and isolating barriers. Intrinsically safe products can refer to the 17EX intrinsically safe type.
What documents to ask for at purchase and review
- Safety-related reliability data and conditions of use: not a sentence that says "supports SIL 2". Conditions of use (diagnostic requirements, comparison period, supply independence) often decide whether the rating can actually be met.
- Scope of the certificate: whether model coverage, range and interface type include the specification purchased.
- The compliance chain of the export market: when a whole machine is exported, safety and EMC certificates must form a system; see equipment for export: how to read CE / ATEX / UL certification.
- EMC basis: insufficient immunity can cause a safety function to operate falsely; see EMC: why strong magnetic fields disturb measurement.
Obtaining certification documents, selection and safety-architecture matching in China are assisted by Shenzhen Yice Electric Co., Ltd. (authorised distributor).
Frequently Asked Questions
Q: Can one say that a given displacement sensor is SIL 2?
The wording is inaccurate. SIL describes the integrity level of a safety function; the object of assessment is the whole safety loop of sensor, logic unit and actuator. A single component can only declare that it is suitable for a safety function of a given level, and provide the corresponding reliability data and conditions of use.
Q: How do SIL and PL relate?
IEC 61508 is the functional-safety foundation standard (SIL 1–4); IEC 62061 addresses machinery whose systems are mainly electrical and electronic (SIL 1–3); ISO 13849-1 addresses mixed systems that include pneumatics and hydraulics (PL a–e). The standard documents give a correspondence for reference between the two rating sets, but they cannot simply be equated; conversion must follow the standard text and the assessment conclusion.
Q: Does using redundant dual channels achieve a given SIL rating?
It is not achieved automatically; a system assessment to the standard is still required. In addition, if the two channels share the same supply, the same position magnet or the same mounting structure, common-cause failure will weaken the practical effect of the redundancy. Architecture design should separate supplies and cable routing as far as possible.
Q: Can functional-safety certification and explosion-protection certification replace each other?
No. They are independent and may both be required. Functional safety addresses hazards caused by control-system failure and is marked SIL/PL; explosion protection addresses the equipment becoming an ignition source in an explosive atmosphere and is marked with types such as Ex ia (intrinsic safety), Ex d (flameproof) and Ex tD (dust).
Q: What documents should be requested at purchase review?
Safety-related reliability data and conditions of use (not a sentence that says it supports SIL 2); the scope of the certificate (whether model, range and interface cover the specification purchased); the compliance-certificate chain of the export target market; and the EMC immunity basis — insufficient immunity can cause a safety function to operate falsely.





