Table of Contents
ToggleA normal controller is built to keep a process running, but a protective controller is built to stop it safely when things go wrong. Certified hardware, deep diagnostics and redundant channels make that difference measurable and trustworthy.
Protective logic in process plants and machines runs on controllers that are certified to detect their own faults and fail toward a safe state. This guide explains the architectures, diagnostics and numbers behind SIL 3 capable controllers.

What Is a Safety PLC?
A safety PLC is a programmable logic solver certified to IEC 61508 for use in safety functions, with built in self diagnostics, redundant processing and a defined safe state on any detected fault. It forms the logic part of a safety instrumented function, between the sensors and the final elements.
A standard PLC can fail with an output stuck on and never notice. A certified safety PLC compares channels, tests its own memory, clocks and outputs, and de energises outputs when something is wrong.

Each function receives a target safety integrity level from hazard analysis. The logic solver must be certified at least up to that SIL, and SIL 3 capability is common for process grade products.
ABB, for example, states that its AC500 S range is certified up to SIL 3 and PL e by TÜV SÜD. Such certificates list the conditions of use, which the designer must follow.
Safety PLC vs Standard PLC
| Feature | Standard PLC | Certified Controller |
|---|---|---|
| Certification | None for safety | IEC 61508 up to SIL 3 |
| Diagnostics | Basic | High coverage, continuous |
| Processors | Single | Dual or triple, compared |
| Outputs | Can fail on | Tested, de energise to trip |
| Programming | Open | Restricted, locked, checksummed |
The protective controller must stay separate from the basic process control system, so a fault in control cannot defeat protection. Read more in SIS and BPCS differences.
6 Essential Safety PLC Features
Diagnostic coverage raises the safe failure fraction, which together with fault tolerance sets the architectural limit of the design. Detected faults are turned into safe actions instead of hidden dangers.
Black channel protocols add counters, time stamps and CRC codes inside the message, so the network itself needs no certification. Corrupted, delayed or repeated frames are rejected by the receiver.
Voting Architectures for SIL 3
Single channel with diagnostics.
Either channel can trip.
Two channels with diagnostics deciding.
Three processors, majority vote.
Triple modular redundancy is the classic approach used in Triconex controllers, explained in 2oo3 voting logic. Dual designs such as the PACSystems safety controller use 1oo2D.
A full comparison of schemes is in voting architectures. The choice balances dangerous failures, spurious trips and cost.
How Rare Should SIL 3 Be?
Control Engineering reports that ISA 84 moved from three SILs in 1996 to include SIL 4 in 2004. The same article notes that SIL 3 needs a minimum hardware fault tolerance of 2 under clause 11.4.1 of the older IEC 61511 edition.
The authors argue that SIL 3 needs should be extremely rare, and that SIL 2 is usually the highest real requirement. A frequent SIL 3 result often points to missing protection layers or an overly cautious analysis.
PFDavg for 1oo1 and 1oo2
PFDavg 1oo2 ≈ (λDU × TI)² ÷ 3
λDU = dangerous undetected failure rate per hour, TI = proof test interval in hours
Example:
λDU = 0.000002 per hour, TI = 8760 h
1oo1: 0.000002 × 8760 ÷ 2 = 0.00876, SIL 2 band
1oo2: 0.01752² ÷ 3 = 0.000102, SIL 3 band
Redundancy improves PFDavg by about 86 times
The 1oo2 formula ignores common cause failures, which in practice dominate and must be added with a beta factor. Final numbers belong in formal SIL verification.
PFDavg Calculator
Remember that the whole loop, including sensors and valves, sets the achieved SIL. The safety PLC is usually the smallest contributor.
- Certified, predictable failure behaviour.
- Deep self diagnostics.
- Flexible logic compared with relays.
- Safety data over standard networks.
- Higher cost than standard controllers.
- Strict change management.
- Certificate conditions must be followed.
- Engineering tools need training.
For small machines with a few inputs, a safety relay can be simpler and cheaper than a safety PLC. A programmable solution wins when logic grows or diagnostics matter.
ABB AC500 S Safety Manual PDF
What Is a Safety PLC Video
Safety PLC FAQ
Related Articles
- What Is SIL
- Voting Architectures in Safety Systems
- What Is 2oo3 Voting Logic
- Features of Triconex PLC
- SIL Verification
External References
- AC500 S Safety User Manual, ABB
- Safety Integrity Level 3, Control Engineering
- Safety Instrumented System, Wikipedia
What We Learn Today
- A safety PLC is certified to IEC 61508 and fails to a safe state.
- 1oo2D and 2oo3 TMR architectures support SIL 3.
- Redundancy cuts PFDavg, but common cause failures must be considered.
