Machine Safety

Functional safety design for machines and industrial equipment — risk assessment, Performance Level, safety relays, light curtains, e-stops, and the standards that govern them.

Important: Machine safety is a safety-critical discipline. The content on this page is for reference and educational purposes only. Safety system design must be performed by, or reviewed by, a qualified functional safety engineer (TÜV FS Engineer or equivalent). Always verify your design against the current editions of the applicable standards.

What this section covers

  • Risk assessment: hazard identification, severity, probability, and required Performance Level
  • ISO 13849-1: Category, MTTFd, DC, CCF, and how they combine to give Performance Level
  • IEC 62061: SIL determination for machinery safety-instrumented functions
  • Safety relay modules: dual-channel monitoring, cross-fault detection, output contacts
  • Light curtain wiring and installation: muting, blanking, and safety distance calculation
  • E-stop requirements to ISO 13850: stop categories, self-latching, and manual reset

Articles in this section

Featured Products

The functional safety standards for machinery

Two main international standards govern the functional safety of machinery control systems:

  • ISO 13849-1 (Safety of Machinery — Safety-Related Parts of Control Systems) covers the design of safety-related parts of control systems (SRP/CS) using a Performance Level (PL) approach. It applies to all types of technology (electrical, pneumatic, hydraulic, mechanical) and is the most widely used standard in the machinery sector.
  • IEC 62061 (Safety of Machinery — Functional Safety of Electrical, Electronic and Programmable Electronic Control Systems) covers electrical and programmable electronic safety systems using a Safety Integrity Level (SIL) approach aligned with IEC 61508. It applies to complex programmable safety systems (safety PLCs) and complex subsystems.

ISO 13849 and IEC 62061 are harmonised under the European Machinery Directive and are broadly equivalent for most applications up to SIL 2 / PLd. For most machine builders, ISO 13849 is the primary standard; IEC 62061 is used when a safety PLC is involved.

Severity S1 / S2 Frequency F1 / F2 Avoidance P1 / P2 Risk Graph ISO 13849-1 S1+F1+P1 → PLa S1+F1+P2 → PLb S2+F1+P1 → PLc S2+F2+P1 → PLd S2+F2+P2 → PLe Annex A Required PLr PLa → PLe Achieved PL Category (B→4) + MTTFd + DC + CCF score PL ≥ PLr ✓
ISO 13849-1 risk graph process. Severity (S), Frequency (F), and Avoidance possibility (P) combine to give the required Performance Level (PLr). Design must achieve PL ≥ PLr.

Risk assessment and required Performance Level

Functional safety design begins with a risk assessment (ISO 12100). The purpose is to identify hazards, estimate the risk for each hazard, and determine the required Performance Level (PLr) of any safety function needed to reduce that risk to an acceptable level.

ISO 13849-1 Annex A provides a risk graph with three parameters:

  • Severity (S): S1 (slight reversible injury) or S2 (severe irreversible injury or death).
  • Frequency of exposure (F): F1 (seldom to less often) or F2 (frequent to continuous).
  • Possibility of avoidance (P): P1 (possible under certain conditions) or P2 (scarcely possible).

The risk graph produces a required PLr from PLa (lowest) to PLe (highest). This PLr is the minimum PL the safety function must achieve.

ISO 13849-1: achieving the required Performance Level

The achieved PL of a safety function is determined by four factors:

  • Category (B, 1, 2, 3, 4): The structural design principle. Category 4 uses two redundant channels with cross-monitoring and can tolerate a single fault. Lower categories have less redundancy.
  • MTTFd (Mean Time To Dangerous Failure): The average time before a dangerous hardware failure occurs. Manufacturers publish MTTFd values; three bands are defined: Low (<10 years), Medium (10–30 years), High (>30 years).
  • DC (Diagnostic Coverage): The fraction of dangerous faults detected by diagnostics. Bands: None (<60%), Low (60–90%), Medium (90–99%), High (≥99%).
  • CCF (Common Cause Failure): Measures taken to prevent a single cause failing both channels simultaneously. Checked via a CCF scoring checklist (separation, diversity, protection from EMI, etc.).

ISO 13849-1 Table K.1 maps Category + MTTFd + DC to an achievable PL. A Category 4 architecture with High MTTFd and High DC achieves PLe.

Safety relay modules

For simple safety functions (single e-stop loop, single door interlock), a dedicated safety relay module is the most cost-effective implementation. Safety relay modules monitor dual-channel safety inputs (normally-closed contacts), check for cross-faults (one channel going high when the other is low), and provide force-guided relay output contacts to the machine's control circuit.

Most safety relay modules achieve Category 3 or 4 / PLd or PLe with appropriate input device selection. Key wiring requirements for dual-channel safety relay inputs:

  • Each channel must be wired on a separate cable to minimise common-cause cable damage failures.
  • The module's test pulse outputs must be used to detect short-circuits between channels (cross-faults).
  • The manual reset button must be wired to a separate input from the safety function — automatic restart on safety function reset is not permitted for most applications.

E-stop requirements (ISO 13850)

ISO 13850 (Safety of Machinery — Emergency Stop Function — Design Principles) defines requirements for emergency stop devices. Key requirements:

  • Actuator: Red palm or mushroom-head button on a yellow background. Must be directly accessible. Must be clearly labelled "EMERGENCY STOP" or marked with ISO 7010 symbol E002.
  • Direct-opening action: The contacts must open by a positive mechanical action (not spring-only) to ensure they open even if a contact spring fails. This is the "direct-opening action" requirement of IEC 60947-5-1 Annex K.
  • Self-latching: The actuator must latch in the actuated (stopped) position and require a deliberate manual action (rotate, pull, or key) to release. It must not automatically reset.
  • Stop category: ISO 13850 requires a Category 0 or 1 stop per IEC 60204-1 Annex D. Category 0 is immediate removal of power; Category 1 is controlled deceleration followed by removal of power. Category 2 (controlled stop, power retained) is explicitly prohibited for e-stop functions.
  • Wiring: E-stop circuits must be wired in series (normally-closed contacts) and designed so that a single wire break, earth fault, or device failure causes a safe state.

Safety light curtains

Safety light curtains (also called AOPDs — Active Opto-electronic Protective Devices) provide presence-sensing safeguarding at access points to hazardous areas. A Type 4 light curtain (the most common industrial type) achieves PLe / SIL 3 when correctly installed.

The minimum safety distance between the light curtain and the hazard is calculated per ISO 13855. The formula accounts for the approach speed of a hand (2,000 mm/s in the European standard), the stopping time of the machine, the response time of the light curtain, and the resolution of the curtain (the minimum object detection size).

Light curtains are connected to safety relay modules or safety PLCs via dual-channel OSSD (Output Signal Switching Device) outputs. The safety controller monitors both OSSD channels and detects shorts between channels using test pulses.