The performance level is never determined for the machine as a whole but always per safety function. From the risk assessment, the risk graph made up of severity (S), frequency (F) and possibility of avoidance (P) gives the required PLr from a to e. The technical implementation is then considered: sensor, logic and actuator together form the safety chain, whose probabilities of failure (PFHd) are added up. The PL achieved has to be at least equal to the PLr; only validation to EN ISO 13849-2 completes the evidence.
A machine typically has several safety functions: guard door monitoring, emergency stop, muting of a light curtain, safely limited speed in setting mode. Each of these functions gets a required performance level of its own, because each covers a different risk.
That is the most common mistake in projects: a blanket claim that "the installation is PL d". That is not a statement anyone can check. What can be checked is the chain of a specific safety function, its PLr, the circuit implemented and the PL calculated from it.
The list of safety functions therefore does not arise in control system planning; it already falls out of the risk assessment. Whenever a hazard is reduced by a control measure, a safety function comes into being.
This description is not a formality: without it neither the PLr can be justified nor the implementation checked. It belongs in the technical documentation and is the basis for later validation.
| Severity S | Frequency F | Avoidance P | Required PLr |
|---|---|---|---|
| S1 slight, reversible | F1 seldom | P1 possible | a |
| S1 slight, reversible | F1 seldom | P2 scarcely possible | b |
| S1 slight, reversible | F2 frequent | P1 possible | b |
| S1 slight, reversible | F2 frequent | P2 scarcely possible | c |
| S2 severe, irreversible | F1 seldom | P1 possible | c |
| S2 severe, irreversible | F1 seldom | P2 scarcely possible | d |
| S2 severe, irreversible | F2 frequent | P1 possible | d |
| S2 severe, irreversible | F2 frequent | P2 scarcely possible | e |
The risk graph is a classification tool, not a calculation method. Borderline cases are not rounded away but justified: anyone choosing between F1 and F2 records the reason, otherwise the classification will not hold up in a dispute.
A safety function always runs through a chain: sensor detects, logic evaluates, actuator switches off. Each of these three links is a subsystem with its own probability of failure per hour, the PFHd.
The PFHd values of the subsystems are added up. The sum determines which performance level is achieved. From this follows a rule often overlooked in practice: three subsystems each rated PL d do not necessarily add up to PL d, because the probabilities of failure accumulate. The distance to the next boundary therefore has to be checked.
For each subsystem there are two routes. Either the manufacturer supplies a certified value with PFHd and category in the data sheet, in which case that value is used. Or the subsystem is built in-house, in which case category, MTTFd, diagnostic coverage DC and the measures against common cause failures CCF have to be determined and the PFHd derived from them.
The category is not a calculation value but a structural requirement on the architecture: single channel, single channel with test, dual channel, dual channel with monitoring. Category and PFHd together give the achieved PL.
The calculation alone is not enough. EN ISO 13849-2 requires validation of the actual implementation, that is a comparison between paper and machine. Without documented validation the evidence is incomplete.
Editions of standards and their harmonised status change continuously. Check standard numbers and editions against the current list in the Official Journal of the EU before applying them. This article is a technical classification and does not replace legal advice.
Both describe the reliability of safety-related parts of control systems but come from different standards: PL a to e from EN ISO 13849-1, SIL 1 to 3 from IEC 62061. For machine controls both routes are permitted; the values can be mapped to each other via the underlying probability of failure. What matters is working consistently within a project and documenting the method chosen.
Yes. The manufacturer's figure applies to the individual subsystem, not to the whole safety function. Only the sum of the PFHd values of sensor, logic and actuator gives the PL achieved by the function. A certified value saves you the calculation of the subsystem, not that of the chain.
PFHd stands for the average probability of a dangerous failure per hour. The value is the common calculation quantity for all subsystems of a safety function and assigns the result to a performance level.
As a result line yes, as evidence no. It only becomes traceable with the description of the safety function, the justification of the PLr, the circuit diagram, the component data, the calculation and the validation report.
The method of the standard remains. The Machinery Regulation requires safe control systems in Annex III and sets additional requirements for software and cybersecurity. Check the edition of the standard and the current listing of harmonised standards in the Official Journal of the EU before applying them.
Has been guiding CE projects in machinery, plant and special purpose engineering for years. That work led to Kaidoc.app, a software for standards-based CE documentation. Through Knutec.de the same work is available as a personal service.
Write me a few lines about your project. You get a first assessment back, free of charge and without obligation.
This article was produced with AI assistance and reviewed for technical accuracy before publication. Editorial responsibility within the meaning of Art. 50(4) of the AI Act (EU) 2024/1689 lies with Heinrich Knutas.
No credit card required. A complete project to try out.