Safety PLC Explained: 6 Essential Features for Solid SIL 3

Share:
Safety Systems
Safety PLC Explained: 6 Essential Features for Solid SIL 3

A normal controller is built to keep a process running, but a protective controller is built to stop it safely when things go wrong. Certified hardware, deep diagnostics and redundant channels make that difference measurable and trustworthy.

IEC 61508 1oo2D 2oo3 TMR PROFIsafe

Protective logic in process plants and machines runs on controllers that are certified to detect their own faults and fail toward a safe state. This guide explains the architectures, diagnostics and numbers behind SIL 3 capable controllers.

Hello everyone, today we are going to learn what a safety PLC is, how it differs from a standard controller, which architectures reach SIL 3 and how to estimate its PFDavg.
safety PLC

What Is a Safety PLC?

A safety PLC is a programmable logic solver certified to IEC 61508 for use in safety functions, with built in self diagnostics, redundant processing and a defined safe state on any detected fault. It forms the logic part of a safety instrumented function, between the sensors and the final elements.

A standard PLC can fail with an output stuck on and never notice. A certified safety PLC compares channels, tests its own memory, clocks and outputs, and de energises outputs when something is wrong.

Hardware fault tolerance architecture diagram for safety controllers
Image credit: Amikong

Each function receives a target safety integrity level from hazard analysis. The logic solver must be certified at least up to that SIL, and SIL 3 capability is common for process grade products.

ABB, for example, states that its AC500 S range is certified up to SIL 3 and PL e by TÜV SÜD. Such certificates list the conditions of use, which the designer must follow.

Safety PLC vs Standard PLC

FeatureStandard PLCCertified Controller
CertificationNone for safetyIEC 61508 up to SIL 3
DiagnosticsBasicHigh coverage, continuous
ProcessorsSingleDual or triple, compared
OutputsCan fail onTested, de energise to trip
ProgrammingOpenRestricted, locked, checksummed

The protective controller must stay separate from the basic process control system, so a fault in control cannot defeat protection. Read more in SIS and BPCS differences.

6 Essential Safety PLC Features

1
IEC 61508 Certificate
Independent assessment of hardware, firmware and tools.
2
High Diagnostic Coverage
Self tests catch most dangerous faults quickly.
3
Redundant Channels
1oo2D or 2oo3 processing with comparison.
4
Defined Safe State
Outputs de energise on any serious fault.
5
Black Channel Protocols
PROFIsafe or CIP Safety over normal networks.
6
Controlled Programming
Password levels, version checks and signatures.

Diagnostic coverage raises the safe failure fraction, which together with fault tolerance sets the architectural limit of the design. Detected faults are turned into safe actions instead of hidden dangers.

Black channel protocols add counters, time stamps and CRC codes inside the message, so the network itself needs no certification. Corrupted, delayed or repeated frames are rejected by the receiver.

Voting Architectures for SIL 3

1oo1

Single channel with diagnostics.

Best for: low SIL or simple duty
Basic
1oo2

Either channel can trip.

Best for: high safety, more spurious trips
Safe
1oo2D

Two channels with diagnostics deciding.

Best for: SIL 3 with good availability
Balanced
2oo3 TMR

Three processors, majority vote.

Best for: SIL 3 with high availability
Available

Triple modular redundancy is the classic approach used in Triconex controllers, explained in 2oo3 voting logic. Dual designs such as the PACSystems safety controller use 1oo2D.

A full comparison of schemes is in voting architectures. The choice balances dangerous failures, spurious trips and cost.

How Rare Should SIL 3 Be?

Control Engineering reports that ISA 84 moved from three SILs in 1996 to include SIL 4 in 2004. The same article notes that SIL 3 needs a minimum hardware fault tolerance of 2 under clause 11.4.1 of the older IEC 61511 edition.

The authors argue that SIL 3 needs should be extremely rare, and that SIL 2 is usually the highest real requirement. A frequent SIL 3 result often points to missing protection layers or an overly cautious analysis.

PFDavg for 1oo1 and 1oo2

PFDavg 1oo1 ≈ λDU × TI ÷ 2
PFDavg 1oo2 ≈ (λDU × TI)² ÷ 3

λDU = dangerous undetected failure rate per hour, TI = proof test interval in hours

Example:
λDU = 0.000002 per hour, TI = 8760 h
1oo1: 0.000002 × 8760 ÷ 2 = 0.00876, SIL 2 band
1oo2: 0.01752² ÷ 3 = 0.000102, SIL 3 band
Redundancy improves PFDavg by about 86 times

The 1oo2 formula ignores common cause failures, which in practice dominate and must be added with a beta factor. Final numbers belong in formal SIL verification.

PFDavg Calculator

1oo1 vs 1oo2 PFDavg
Result
1oo1 PFDavg 0.00876, SIL 2 band; 1oo2 PFDavg 0.000102, SIL 3 band

Remember that the whole loop, including sensors and valves, sets the achieved SIL. The safety PLC is usually the smallest contributor.

Advantages
  • Certified, predictable failure behaviour.
  • Deep self diagnostics.
  • Flexible logic compared with relays.
  • Safety data over standard networks.
Limitations
  • Higher cost than standard controllers.
  • Strict change management.
  • Certificate conditions must be followed.
  • Engineering tools need training.

For small machines with a few inputs, a safety relay can be simpler and cheaper than a safety PLC. A programmable solution wins when logic grows or diagnostics matter.

ABB AC500 S Safety Manual PDF

PDF
AC500 S Safety User Manual
ABB manual for a controller certified up to SIL 3 and PL e

What Is a Safety PLC Video

Safety PLC FAQ

What is a safety PLC?
It is a logic solver certified to IEC 61508 with self diagnostics and a defined safe state. It runs protective functions separately from normal process control.
Can a standard PLC be used for SIL functions?
Generally not, because it lacks certified diagnostics and fault behaviour. Prior use arguments exist but are hard to justify at higher SIL targets.
What does 1oo2D mean?
It means two channels where either can trip, with diagnostics deciding which channel to trust. It gives high safety with fewer nuisance trips than plain 1oo2.
What is TMR?
Triple modular redundancy uses three processors and a majority vote. A single failed processor is outvoted, so the system keeps running safely.
What is a black channel protocol?
It is a safety layer such as PROFIsafe or CIP Safety carried over a normal network. The end devices detect corrupted, late or repeated messages.
Is SIL 3 common in process plants?
Control Engineering suggests SIL 3 needs should be extremely rare in practice. SIL 2 is usually the highest target after a sound hazard analysis.
Does the controller alone set the SIL?
No, the sensors, logic and final elements together determine the achieved SIL. Valves and transmitters usually contribute most of the PFDavg.

Related Articles

External References

What We Learn Today

  • A safety PLC is certified to IEC 61508 and fails to a safe state.
  • 1oo2D and 2oo3 TMR architectures support SIL 3.
  • Redundancy cuts PFDavg, but common cause failures must be considered.
I hope you like above blog. There is no cost associated in sharing the article in your social media. Thanks for reading!! Happy Learning!!

Leave a Reply

Your email address will not be published. Required fields are marked *