-
Company
-
Banner Blog
-
Machine Safety Ratings Explained
Machine Safety Ratings: How PL, SIL, and Safety Categories Shape Your Design
Machine safety ratings help engineers translate risk assessment into design requirements for a safety function. Before selecting a safety light curtain, safety switch, emergency stop device, safety relay, or safety controller, the designer needs to understand the hazard being controlled, when a person may be exposed to it, and what the machine must do to reduce the risk.
Performance Level (PL), required Performance Level (PLr), Safety Integrity Level (SIL), and safety categories help define the required performance of safety-related control functions. They influence architecture, device selection, diagnostics, response time, fault behavior, and validation, but do not prove the performance of the complete safety function by themselves.
A product’s rating can indicate that a device is suitable for the required safety performance, but it does not demonstrate that the installed system achieves it. The complete safety function must be designed and validated across the input device, safety logic, output devices, wiring, diagnostics, reset behavior, and fault response.
Table of Contents
- Start with the Safety Function
- Required Performance Level PLr: The Safety Function Target
- Performance Level: The Target Versus the Achieved Result
- How Safety Categories Shape Architecture
- Where Safety Integrity Level Fits in Machine Safety Design
- How Ratings Influence Product Selection and Implementation
- Validate the Installed Safety Function
- What to Do Next
Machine safety design starts with risk assessment. Before choosing devices, engineers identify each task-related hazard and evaluate possible injury severity, exposure frequency, and whether a person can realistically avoid the hazard.
This assessment extends beyond normal production. Setup, cleaning, jam clearing, maintenance, troubleshooting, and material changeovers often create access conditions that do not exist during an automatic cycle.
The next step is to define the safety function. For example, if a person interrupts the light curtain at an infeed opening, hazardous motion must stop within the required time and must not restart until the field is clear and a deliberate reset occurs. These conditions turn a general safety need into a specific function with design and validation requirements. They also prevent the engineer from selecting a light curtain before defining what the complete function must do.
Under ISO 13849-1:2023, required Performance Level, or PLr, is the performance level required of a specific safety function. In practical terms, PLr defines how reliably the safety-related parts of the control system must perform that function when needed. The risk assessment assigns that target on a scale from PL a through PL e, with PL e requiring the highest level of risk reduction.
Required Performance Level (PLr) Scale
| PLr | Average probability of dangerous failure per hour (PFH) |
Required performance |
|---|---|---|
| PL a | 10−5 ≤ PFH < 10−4 | Lowest on the PLr scale |
| PL b | 3 × 10−6 ≤ PFH < 10−5 | Higher required performance |
| PL c | 10−6 ≤ PFH < 3 × 10−6 | Higher required performance |
| PL d | 10−7 ≤ PFH < 10−6 | High required performance |
| PL e | PFH < 10−7 | Highest required performance |
PLr turns the result of the risk assessment into a design requirement. A machine may have multiple safety functions, each with its own PLr. For example:
- stop hazardous motion when a light curtain is interrupted
- prevent operation when an interlocked guard door is opened
- stop the machine when an emergency stop is actuated
Each PLr guides the architecture, device selection, diagnostics, and validation required for that function. It gives the engineer a measurable target for the complete safety function and a basis for selecting the components needed for implementation.
PLr is the target determined by risk assessment. Achieved PL is the level the completed safety function reaches after its architecture, devices, wiring, diagnostics, and fault behavior have been evaluated. Both use the PL a through PL e scale shown above.
The distinction that matters in design is simple:
- PLr is the required target determined by risk assessment.
- Achieved PL is the performance level reached by the completed safety function.
- Achieved PL must meet or exceed PLr.
A PLe-rated light curtain does not automatically make the safety function PLe. Achieved PL depends on the complete function, including:
- input device
- logic device
- output or final switching devices
- architecture
- component reliability and diagnostic coverage
- common-cause failure measures and systematic fault considerations
- wiring, reset behavior, response time, and fault behavior
If a safety input operates correctly but a final switching device fails to remove hazardous energy, the safety function may not achieve its target. The same is true if the architecture cannot detect relevant faults or permits an unsafe restart.
Consider Banner's S4B Safety Light Curtains. Its PLe and SIL3 capability may make it suitable for high-performance safety functions when it is applied within its ratings and integrated into an architecture that achieves the required performance. The light curtain is the input portion of the function. The complete design must also account for the safety relay or configurable safety controller, wiring, output devices, reset behavior, response time, contactor or drive fault behavior, and external device monitoring where required.
Safety categories describe the architecture and fault behavior of the safety-related parts of a control system under ISO 13849-1:2023. They help engineers evaluate whether a safety function will continue to perform as intended when components fail.
Safety Categories
| Category | Design implication |
|---|---|
| B | Uses basic safety principles and appropriately selected components. A fault can lead to loss of the sub-function. |
| 1 | Builds on Category B with well-tried components and well-tried safety principles to improve component reliability. The occurrence of a fault can lead to loss of the sub-function, but with a lower probability of occurrence than Category B. |
| 2 | Builds on Category B using well-tried safety principles and testing at suitable intervals to detect faults. A fault can lead to loss of the sub-function between tests. Loss of the sub-function is detected by the test. |
| 3 | Uses redundancy so a single fault does not lead to loss of the sub-function. Some faults may not be detected, and accumulated undetected faults can lead to loss of the sub-function. |
| 4 | Uses redundancy and high fault detection. A single fault does not lead to loss of the sub-function. Detection of accumulated faults reduces the probability of loss of the sub-function, and faults are detected in time to prevent its loss. |
Note: a Sub-function is a part of the safety function whose failure results in a failure of the safety function
Safety categories are architecture characteristics, not substitutes for achieved PL. Category is one factor in the evaluation. Component reliability, diagnostic coverage, common-cause failures, and other design factors also affect the achieved result.
This matters when choosing and connecting devices. A dual-channel input alone does not establish a Category 3 or Category 4 function. The engineer must evaluate the full path from the safety input to the final switching devices, including the fault behavior of that path.
Safety Integrity Level, or SIL, is used in IEC 62061:2021 to evaluate safety-related control functions. Like PL, SIL 1 through SIL 3 express how reliably a safety function must perform when needed.
PL and SIL use different terminology and evaluation methods. Choose the applicable method early based on relevant machinery standards, customer specifications, project requirements, and jurisdictional expectations.
A product’s SIL claim is not a shortcut for an ISO 13849:2023 PL calculation, and a PL rating is not a substitute for a subsystem evaluation under IEC 62061:2021. Both approaches require the engineer to assess the complete safety function.
Once PLr or SIL is established, machine safety ratings help determine the next engineering decisions. They influence:
- whether a safety light curtain, safety switch, emergency stop device, or another input device is appropriate
- whether the safety logic can be handled by a safety relay or configurable safety controller
- whether outputs need redundancy, monitoring, or external device monitoring
- whether diagnostics are needed to detect faults
- how response time affects safety distance
- how reset and restart behavior must work
- what must be verified after installation
Banner safety light curtains, safety switches, emergency stop devices, safety relays and controllers, and remote safe I/O can provide compatible building blocks for a safety function. Product data, selection resources, application guidance, and configuration software can help engineers move from requirement to implementation.
These resources do not eliminate the need for machine-specific engineering. Ratings do not automatically choose the product, determine the architecture, or validate the final installation.
Once safety-function requirements are defined, the choice between a safety relay and a safety controller depends on the function’s complexity, I/O needs, diagnostic and monitoring requirements, reset and restart behavior, and validation plan.
Validation confirms that the installed system performs the required safety function as intended.
Depending on the application, validation may include reviews of documentation, architecture, component data, configuration, and installation. It may also include stopping-time verification, safety-distance verification, restart testing, fault-behavior testing, and confirmation that achieved PL or SIL meets the target.
Simulation can help engineers review safety logic before implementation. It does not replace commissioning and validation on the installed machine.
The machine safety workflow begins with hazard identification and safety-function definition. From there, engineers establish the required PLr or SIL target, design the architecture to achieve it, and select the input, logic, and output devices used to implement the complete function.
Diagnostics, response time, safety distance, reset behavior, fault response, and validation determine whether the installed system achieves the required performance. Treating PL, PLr, SIL, and safety categories as parts of one safety-function workflow helps engineers select appropriate devices and verify the completed system before the machine returns to operation.