2026-09-21 · KeXinMaterials Redaktionsteam
IEC 61511 Prozess-SIL + ISO 26262 ASIL + ISO 13849 PL Funktionale Sicherheitsfamilie B2B-Leitfaden
IEC 61511 (Prozess-SIS), ISO 26262 (Automotive-ASIL) und ISO 13849-1 (Maschinen-PL) sind die drei primären sektorspezifischen Funktionale-Sicherheit-Standards. Alle leiten sich vom generischen IEC 61508 SIL-Rahmen ab.
Functional Safety Family + IEC 61508 Common Base
IEC 61508 is generic. Sector standards derive SIL/ASIL/PL from common base. Three primary sectors: process (61511), automotive (26262), machinery (13849).
IEC 61508 "Functional safety of electrical and electronic safety-related systems" is the common generic base. Published 2010 (Edition 2). 7 parts.
Sector functional safety standards: Process industry IEC 61511 (also ANSI/ISA 84.00.01 in US). Automotive ISO 26262 (replaces IEC 61508 in automotive). Machinery ISO 13849-1 (PLa-PLe) + IEC 62061 (SIL).
Other sector standards: Railway EN 50126/50128/50129 (SIL). Nuclear IEC 61513. Medical IEC 62304 (software) + IEC 60601-1 (basic safety). Aerospace DO-178C (software) + DO-254 (hardware). Off-road ISO 19014 (earth-moving machinery).
Functional safety lifecycle: Concept phase + system design + hardware design + software design + production + operation + maintenance + decommissioning.
Risk reduction: Per IEC 61508 + sector standards. Inherent safe design + protective measures + information for safety.
Risk graph / matrix: Sector-specific. Process IEC 61511 has detailed risk graph. Automotive ISO 26262 has ASIL determination (severity x exposure x controllability). Machinery ISO 13849-1 has S (severity) x F (frequency) x P (possibility of avoidance) x C (probability of occurrence).
Cross-sector comparison: SIL (process) 1-4. ASIL (automotive) A-D. PL (machinery) a-e. Mapping is approximate: SIL 1 = PL b / ASIL A. SIL 2 = PL c / ASIL B. SIL 3 = PL d / ASIL C/D. SIL 4 = PL e / (no ASIL).
Geographic adoption: IEC 61511 globally (incl. EU EN 61511, US ANSI/ISA 84.00.01). ISO 26262 globally (incl. EU, US, Japan, Korea, China GB/T 34590). ISO 13849-1 globally (incl. EU EN ISO 13849-1, US, Japan JIS B 9705-1).
B2B relevance: For B2B protective cases containing safety-related control equipment in process (oil + gas + chemicals + pharma + power) / automotive (ADAS + EV + autonomous) / machinery (industrial robots + presses + lifts + packaging), sector-specific functional safety certification is procurement requirement.
IEC 61511 Process Industry SIS
IEC 61511 "Functional safety - Safety instrumented systems for the process industry sector" - process-specific application of IEC 61508. Current Edition 2 (2016).
IEC 61511:2016: "Functional safety - Safety instrumented systems for the process industry sector". Replaces IEC 61511:2003 Edition 1. Currently active Edition 2.
Scope: Safety instrumented systems (SIS) for process industry. Sensors + logic solvers + final control elements for safety instrumented functions (SIF).
Industry scope: Oil + gas + chemicals + petrochemical + power generation + pharmaceuticals + water + waste + pulp + paper + food + beverage.
Safety lifecycle: Per IEC 61511. (1) Process hazard analysis (PHA / HAZOP / LOPA). (2) Allocation of safety functions to protection layers. (3) SIS safety requirement specification (SRS). (4) SIS design + engineering. (5) Installation + commissioning + validation. (6) Operation. (7) Maintenance. (8) Modification. (9) Decommissioning.
LOPA (Layer of Protection Analysis): Per IEC 61511. Semi-quantitative method for assessing risk reduction. Layers: process design + basic process control + alarm + operator + safety instrumented function + physical protection + emergency response.
SIL determination: Per IEC 61511. Target SIL per SIF based on tolerable risk + existing protection layers. SIL 1-4 same as IEC 61508.
Safety integrity: Hardware SIL + systematic capability SC + architectural constraints + SFF + HFT. Same as IEC 61508.
Proof test: Per IEC 61511. Required for low-demand mode SIL 1-4. Proof test coverage (PTC) > 90% for SIL 3-4.
Bypass + maintenance bypass: Per IEC 61511 § 5.2.6.1. Administrative control + automatic means to detect bypass state.
IEC 61511 vs IEC 61508: IEC 61511 is process-specific. IEC 61508 is generic. IEC 61511 provides more detailed requirements for SIS lifecycle, PHA, LOPA, allocation, proof testing.
Common B2B mistakes: (1) Confusing IEC 61511 SIS scope with IEC 61508 generic. (2) Missing proof test schedule. (3) Missing bypass management. (4) Insufficient LOPA documentation. (5) Mixing SIL levels in same SIF.
B2B recommendation: For process industry cases containing SIS equipment, require IEC 61511:2016 Edition 2 compliance + LOPA documentation + proof test schedule + IEC 61511-1 lifecycle + competent Functional Safety Engineer.
ISO 26262 Automotive ASIL A-D
ISO 26262 "Road vehicles - Functional safety" - automotive-specific ASIL A-D levels. Replaces IEC 61508 in automotive. Current Edition 2 (2018).
ISO 26262:2018: "Road vehicles - Functional safety". Edition 2. Replaces Edition 1 (2011). Currently active Edition 2.
Scope: Road vehicles (passenger cars + light commercial + heavy trucks + buses + motorcycles + trailers). Excludes special-purpose vehicles + agricultural + rail.
ASIL (Automotive Safety Integrity Level): Discrete levels A, B, C, D. Higher level = stricter requirements. ASIL D is highest. QM (Quality Management) for non-safety functions.
ASIL determination: Per ISO 26262-3:2018. Severity (S0-S3) x Exposure (E0-E4) x Controllability (C0-C3). ASIL assignment table per ISO 26262-3.
ASIL A: Lowest. Severity S1 + Exposure E1 + Controllability C1 typically. Equivalent to SIL 1 loosely.
ASIL B: Low-medium. Severity S2 + Exposure E2 + Controllability C2 typically. SIL 2 equivalent.
ASIL C: Medium-high. Severity S3 + Exposure E3 + Controllability C2 typically. SIL 3 equivalent.
ASIL D: Highest. Severity S3 + Exposure E4 + Controllability C3 typically. SIL 3-4 equivalent.
ASIL decomposition: Per ISO 26262-9:2018. Decompose ASIL D into two ASIL B(C) requirements. Reduces redundancy burden.
Item definition: Per ISO 26262-3. Defined system + functions under scope. Boundary + interfaces + operating modes.
Hazard analysis + risk assessment (HARA): Per ISO 26262-3. Identify hazards + hazardous events + ASIL per event.
Functional safety concept: Per ISO 26262-4. Functional safety requirements (FSR) + allocation to system architecture.
Technical safety concept: Per ISO 26262-4. Hardware + software requirements from FSR allocation.
Hardware metrics: Per ISO 26262-5. SPFM (Single Point Fault Metric) + LFM (Latent Fault Metric) + PMHF (Probabilistic Metric for random Hardware Failures). ASIL D: SPFM >= 99% + LFM >= 90% + PMHF < 10 FIT.
Software metrics: Per ISO 26262-6. Software architectural metrics + software unit metrics. ASIL D: structural coverage (modified condition / decision coverage MC/DC).
ISO 26262 vs IEC 61508: ISO 26262 is automotive-specific. Replaces IEC 61508 in automotive. Different ASIL vs SIL mapping. No QM equivalent in IEC 61508.
B2B recommendation: For automotive cases containing ADAS / EV / autonomous driving / safety-related control equipment, require ISO 26262:2018 ASIL C/D typically + ASIL decomposition + HARA + hardware + software metrics + FMEA per AIAG-VDA.
ISO 13849-1 Machinery PL a-e + IEC 62061
ISO 13849-1 "Safety of machinery - Safety-related parts of control systems" - machinery-specific PL a-e levels. Companion IEC 62061 (machinery SIL).
ISO 13849-1:2023: "Safety of machinery - Safety-related parts of control systems". Edition 4. Replaces ISO 13849-1:2015.
Scope: Safety-related parts of control systems (SRP/CS) on machinery. Includes mechanical + pneumatic + hydraulic + electrical + electronic + programmable electronic.
PL (Performance Level): Discrete levels a, b, c, d, e. Higher level = lower probability of dangerous failure per hour. PL e highest.
PL determination: Per ISO 13849-1. Severity (S1/S2) x Frequency of exposure (F1/F2) x Possibility of avoidance (P1/P2). Result: PL a-e.
PL a: Lowest. Probability of dangerous failure per hour (PFHd) >= 10^-5 to < 10^-4. Equivalent to SIL 1.
PL b: Low. PFHd >= 3 x 10^-6 to < 10^-5. SIL 1-2.
PL c: Medium. PFHd >= 10^-6 to < 3 x 10^-6. SIL 2.
PL d: Medium-high. PFHd >= 10^-7 to < 10^-6. SIL 2-3.
PL e: Highest. PFHd >= 10^-8 to < 10^-7. SIL 3.
Categories B / 1 / 2 / 3 / 4: Per ISO 13849-1. Structural categories. B basic / 1 redundant / 2 tested / 3 dual channel / 4 dual channel + monitoring.
Diagnostic coverage (DC): Per ISO 13849-1 Table F.1. DCavg low / medium / high. Affects achievable PL.
Common cause failure (CCF): Per ISO 13849-1 Annex F. Mitigation: separation, diversity, CCF score 65+ for PL d/e.
Mission time / T10D: Per ISO 13849-1. Service life for non-repairable components. T10D typically 20 years for machinery.
IEC 62061:2022: "Safety of machinery - Functional safety of safety-related electrical, electronic and programmable electronic control systems". SIL-based (vs PL-based). Companion to ISO 13849-1.
IEC 62061 vs ISO 13849-1: IEC 62061 is SIL-based (extends IEC 61508). ISO 13849-1 is PL-based. Either can be used for machinery EU Machinery Directive 2006/42/EC compliance.
EU Machinery Directive 2006/42/EC + Machinery Regulation (EU) 2023/1230: EU regulatory framework. Compliance per EN ISO 13849-1 or EN IEC 62061.
B2B recommendation: For machinery cases containing industrial robots + presses + lifts + packaging + CNC + conveyors, require ISO 13849-1 PL d/e or IEC 62061 SIL 2/3 + EU Machinery Regulation compliance + T10D documentation + DC + CCF scoring.
B2B Cross-Sector Procurement Workflow
Functional safety family procurement per sector. Identify sector + risk class + required SIL/ASIL/PL + supplier competency + case design.
Functional Safety Engineer (FSE / FSC): Person certified for functional safety work. TUV FSE / CFSE / FS Engineer (IEC 61508) / AFSE (Automotive Functional Safety Engineer per ISO 26262).
Certifying bodies: TUV SUD / TUV NORD / TUV Rheinland / DEKRA / UL / SGS / Intertek / SGS-TUV Saar / Bureau Veritas.
Cost: IEC 61511 SIS certification EUR 30-100K. ISO 26262 ASIL C/D EUR 100-500K. ISO 13849-1 PL d/e EUR 30-100K. Duration 6-24 months depending on complexity.
Common procurement mistakes: (1) Missing sector-specific functional safety expert. (2) Confusing SIL with product safety standard (CE / UL). (3) Missing proof test schedule (process). (4) Missing HARA (automotive). (5) Missing T10D documentation (machinery).
Cross-sector mapping table: IEC 61508 SIL 1 = ISO 26262 ASIL A / ISO 13849-1 PL b / IEC 62061 SIL 1. SIL 2 = ASIL B / PL c / SIL 2. SIL 3 = ASIL C/D / PL d / SIL 3. SIL 4 = (no ASIL) / PL e / (SIL 4 rare in machinery).
B2B procurement workflow: (1) Identify sector (process / automotive / machinery). (2) Risk assessment per sector standard. (3) Determine required SIL/ASIL/PL. (4) Specify sector standard + IEC 61508 base. (5) Verify supplier functional safety competency. (6) Verify hardware + software + systematic capability. (7) Functional safety audit by accredited body. (8) Maintenance + proof test + monitoring.
Functional safety case: Required documentation. Claims + arguments + evidence. Goal is to demonstrate SIL/ASIL/PL achieved per requirements.
B2B recommendation: For B2B protective cases containing safety-related equipment, identify sector + apply sector-specific functional safety standard + IEC 61508 common base + Functional Safety Engineer + accredited body certification.
Wesentliche Erkenntnisse
- Functional safety family = IEC 61508 generic + sector-specific: IEC 61511 (process) + ISO 26262 (automotive) + ISO 13849-1 (machinery) + EN 50126/50128/50129 (railway) + IEC 61513 (nuclear) + IEC 62304 (medical) + DO-178C/DO-254 (aerospace).
- IEC 61511:2016 Edition 2: process industry SIS. LOPA + safety lifecycle + proof test + bypass management. SIL 1-4 same as IEC 61508.
- ISO 26262:2018 Edition 2: automotive ASIL A-D. Determined by S x E x C. ASIL D requires SPFM 99% + LFM 90% + PMHF < 10 FIT + MC/DC. ASIL decomposition reduces redundancy burden.
- ISO 13849-1:2023 Edition 4: machinery PL a-e. Categories B/1/2/3/4 structural. T10D mission time 20 years. PFHd ranges PL a 10^-5 to PL e 10^-8. Companion IEC 62061 SIL-based.
- B2B cost: IEC 61511 EUR 30-100K. ISO 26262 ASIL C/D EUR 100-500K. ISO 13849-1 PL d/e EUR 30-100K. Duration 6-24 months.
- B2B recommendation: For B2B functional safety cases, identify sector + apply sector-specific standard + IEC 61508 base + Functional Safety Engineer + accredited body + Functional Safety Case documentation.
FAQ
q
a
q
a
q
a
q
a
q
a
q
a