HomeGuide › Determining the performance level (PL) to EN ISO 13849-1

How do I determine the performance level (PL) of a safety function to EN ISO 13849-1?

The performance level is never determined for the machine as a whole but always per safety function. From the risk assessment, the risk graph made up of severity (S), frequency (F) and possibility of avoidance (P) gives the required PLr from a to e. The technical implementation is then considered: sensor, logic and actuator together form the safety chain, whose probabilities of failure (PFHd) are added up. The PL achieved has to be at least equal to the PLr; only validation to EN ISO 13849-2 completes the evidence.

Contents
  1. What is the performance level determined for?
  2. What belongs in the description of a safety function?
  3. How do I get from the hazard to the required PLr?
  4. Which PLr results from which combination?
  5. How does the achieved PL arise from components?
  6. What is documented as evidence?
  7. Which mistakes keep coming up in projects?

What is the performance level determined for?

For each individual safety function.
Not for the machine, not for a component and not for the control system as a whole.

A machine typically has several safety functions: guard door monitoring, emergency stop, muting of a light curtain, safely limited speed in setting mode. Each of these functions gets a required performance level of its own, because each covers a different risk.

That is the most common mistake in projects: a blanket claim that "the installation is PL d". That is not a statement anyone can check. What can be checked is the chain of a specific safety function, its PLr, the circuit implemented and the PL calculated from it.

The list of safety functions therefore does not arise in control system planning; it already falls out of the risk assessment. Whenever a hazard is reduced by a control measure, a safety function comes into being.

What belongs in the description of a safety function?

Triggering eventWhat starts the function? Opening the guard door, operating the emergency stop device, interrupting the light curtain, exceeding a speed.
Safe stateWhat is the goal? Standstill of the hazardous movement, depressurising, isolating the energy supply, limiting speed to a safe value.
Stop categoryStop 0, 1 or 2 to EN 60204-1. The choice determines whether energy is removed immediately or the drive is brought to a controlled stop and then isolated.
Response time and run-downTotal time from triggering to the safe state. It feeds directly into the calculation of safety distances to EN ISO 13855.
Operating modesIn which operating modes the function acts and in which it is deliberately bypassed, for instance in setting mode with an enabling device.
Behaviour on restoration of powerNo automatic restart. Define whether a reset is required and where the reset point is.
Required PLrThe result of the risk assessment for exactly this function, documented with the underlying S, F and P classification.

This description is not a formality: without it neither the PLr can be justified nor the implementation checked. It belongs in the technical documentation and is the basis for later validation.

How do I get from the hazard to the required PLr?

Step 1
Can the hazard lead to an irreversible injury, such as amputation, a broken bone or death?
YesSeverity S2. Go to the next question.
NoSeverity S1 for slight, normally reversible injuries. Go to the next question.
Step 2
Are people in the hazard zone frequently or continuously, or is the area entered more often than about once per hour?
YesFrequency F2. Go to the next question.
NoFrequency F1 for seldom or short exposure. Go to the next question.
Step 3
Is the hazard recognisable and can it be averted through the speed of the process or by moving away?
YesPossibility of avoidance P1. The PLr is thereby fixed.
NoPossibility of avoidance P2, where avoiding it is practically impossible. The PLr is thereby fixed.
Step 4
Is there a type-C standard for the machine type that already specifies the PLr for this function?
YesThen the value stated there applies. Deriving it yourself is only necessary if you depart from it, and that has to be justified.
NoThe derivation via the risk graph stands. The classification of S, F and P is documented traceably.

Which PLr results from which combination?

Severity SFrequency FAvoidance PRequired PLr
S1 slight, reversibleF1 seldomP1 possiblea
S1 slight, reversibleF1 seldomP2 scarcely possibleb
S1 slight, reversibleF2 frequentP1 possibleb
S1 slight, reversibleF2 frequentP2 scarcely possiblec
S2 severe, irreversibleF1 seldomP1 possiblec
S2 severe, irreversibleF1 seldomP2 scarcely possibled
S2 severe, irreversibleF2 frequentP1 possibled
S2 severe, irreversibleF2 frequentP2 scarcely possiblee

The risk graph is a classification tool, not a calculation method. Borderline cases are not rounded away but justified: anyone choosing between F1 and F2 records the reason, otherwise the classification will not hold up in a dispute.

How does the achieved PL arise from components?

A safety function always runs through a chain: sensor detects, logic evaluates, actuator switches off. Each of these three links is a subsystem with its own probability of failure per hour, the PFHd.

The PFHd values of the subsystems are added up. The sum determines which performance level is achieved. From this follows a rule often overlooked in practice: three subsystems each rated PL d do not necessarily add up to PL d, because the probabilities of failure accumulate. The distance to the next boundary therefore has to be checked.

For each subsystem there are two routes. Either the manufacturer supplies a certified value with PFHd and category in the data sheet, in which case that value is used. Or the subsystem is built in-house, in which case category, MTTFd, diagnostic coverage DC and the measures against common cause failures CCF have to be determined and the PFHd derived from them.

The category is not a calculation value but a structural requirement on the architecture: single channel, single channel with test, dual channel, dual channel with monitoring. Category and PFHd together give the achieved PL.

What is documented as evidence?

The calculation alone is not enough. EN ISO 13849-2 requires validation of the actual implementation, that is a comparison between paper and machine. Without documented validation the evidence is incomplete.

Which mistakes keep coming up in projects?

Sources and standards

Editions of standards and their harmonised status change continuously. Check standard numbers and editions against the current list in the Official Journal of the EU before applying them. This article is a technical classification and does not replace legal advice.

Frequently asked questions

What is the difference between PL and SIL?

Both describe the reliability of safety-related parts of control systems but come from different standards: PL a to e from EN ISO 13849-1, SIL 1 to 3 from IEC 62061. For machine controls both routes are permitted; the values can be mapped to each other via the underlying probability of failure. What matters is working consistently within a project and documenting the method chosen.

Do I have to calculate if the manufacturer states the PL of the component?

Yes. The manufacturer's figure applies to the individual subsystem, not to the whole safety function. Only the sum of the PFHd values of sensor, logic and actuator gives the PL achieved by the function. A certified value saves you the calculation of the subsystem, not that of the chain.

What does PFHd mean?

PFHd stands for the average probability of a dangerous failure per hour. The value is the common calculation quantity for all subsystems of a safety function and assigns the result to a performance level.

Is stating "PL d, category 3" enough in the documentation?

As a result line yes, as evidence no. It only becomes traceable with the description of the safety function, the justification of the PLr, the circuit diagram, the component data, the calculation and the validation report.

Does the Machinery Regulation change anything about determining the PL?

The method of the standard remains. The Machinery Regulation requires safe control systems in Annex III and sets additional requirements for software and cybersecurity. Check the edition of the standard and the current listing of harmonised standards in the Official Journal of the EU before applying them.

Heinrich Knutas
Heinrich Knutas
Machinery safety engineer
Founder of Kaidoc.app · CEO of Knutec.de · LinkedIn

Has been guiding CE projects in machinery, plant and special purpose engineering for years. That work led to Kaidoc.app, a software for standards-based CE documentation. Through Knutec.de the same work is available as a personal service.

Still have a question?

Write me a few lines about your project. You get a first assessment back, free of charge and without obligation.

This article was produced with AI assistance and reviewed for technical accuracy before publication. Editorial responsibility within the meaning of Art. 50(4) of the AI Act (EU) 2024/1689 lies with Heinrich Knutas.

Do it yourself or have it done
Instructions for use, risk assessment and EU declaration of conformity under Machinery Regulation (EU) 2023/1230. With Kaidoc.app you create the documents yourself, structured along the standards instead of copied together from past projects. If time is short, Knutec.de takes the project on as a service.
All mandatory chapters in placeStandards and deadlines kept currentWord and PDF, fully editable
Start 30-day free trial

No credit card required. A complete project to try out.

Related articles

How does a risk assessment to EN ISO 12100 work? How do you produce a risk assessment for a machine? Which standards matter for CE marking of a machine?
© 2026 Knutec · GDPR compliant · Servers in Germany Home Guide Contact