Functional Safety Standards Explained: IEC 61508, IEC 61511, ISO 13849 and IEC 62061
Four standards dominate functional safety, and applying the wrong one is a more common and more expensive mistake than most organizations realize. The short answer is this: IEC 61508 is the parent standard, IEC 61511 governs the process industries, and ISO 13849 and IEC 62061 govern machinery. Which one applies to you is determined by what your equipment does, not by what your team is already familiar with.
That distinction matters commercially. A machine builder who applies IEC 61511 will produce documentation that a machinery notified body does not recognize. A process operator who applies ISO 13849 will find the SIL claims unsupportable at assessment. This guide sets out which standard governs which equipment, how they relate, and what each one requires you to produce. If you already know which applies and need it delivered, our functional safety services cover the full lifecycle.
The Four Standards at a Glance
|
Standard |
Applies To |
Measures Safety As |
Typical Users |
|
IEC 61508 |
All electrical, electronic and programmable electronic safety systems |
SIL 1 to SIL 4 |
Device manufacturers, sector standard writers |
|
IEC 61511 |
Process industries: oil and gas, chemical, pharmaceutical, power |
SIL 1 to SIL 4 |
Refineries, chemical plants, upstream operators |
|
ISO 13849 |
Machinery safety-related control systems |
Performance Level a to e |
Machine builders, OEMs, integrators |
|
IEC 62061 |
Machinery safety-related electrical control systems |
SIL 1 to SIL 3 |
Machine builders using complex electronic control |
IEC 61508: The Parent Standard
IEC 61508 is the generic standard from which the others derive. It defines the safety lifecycle, the concept of Safety Integrity Levels, and the requirements for hardware and software in safety-related systems. Most operators never apply it directly, because a sector-specific standard covers them. It matters to you mainly when procuring equipment, since an IEC 61508 certified device carries independently verified failure data that your SIL calculations depend on. Our guide to IEC 61508 certification covers what the certificate actually proves.
IEC 61511: The Process Industry Standard
If you operate a refinery, chemical plant, pharmaceutical facility, or upstream oil and gas asset, IEC 61511 is your standard. It applies the IEC 61508 framework to process safety instrumented systems and defines the full lifecycle: hazard and risk assessment, SIL allocation, safety requirements specification, design, installation, validation, operation, and modification.
The lifecycle begins with a hazard study, which is why a HAZOP is required before any SIL work can proceed. It ends with proof testing and periodic functional safety assessment at defined gates. Clause 8.2.4 also requires a cybersecurity risk assessment, which is why IEC 61511 and IEC 62443 must be applied together.
ISO 13849 and IEC 62061: The Machinery Standards
Machine builders work to a different pair. ISO 13849 measures safety function capability in Performance Levels from PL a to PL e, and suits most machinery applications including hydraulic, pneumatic and mechanical elements. IEC 62061 uses SIL 1 to SIL 3 and suits complex programmable electronic control. Both are recognized routes to demonstrating conformity for machinery placed on the EU market.
The distinction becomes urgent in 2026 because the EU Machinery Regulation replaces the Machinery Directive on 20 January 2027, and it adds explicit cybersecurity and machine learning provisions. Our guide to functional safety in manufacturing covers what machine builders need in place before that date.
|
The most common and most costly mistake Process operators occasionally apply machinery standards to plant safety systems because a contractor was more familiar with them, and machine builders occasionally apply IEC 61511 because a process engineer led the project. Both produce documentation that fails at assessment. The determining question is what the equipment does: a machine placed on the market follows ISO 13849 or IEC 62061, a process plant safety instrumented system follows IEC 61511. |
How SIL and Performance Level Relate
SIL and PL both express how reliably a safety function performs, but they are not interchangeable and they are not the same scale. ISO 13849 provides a mapping between them, roughly aligning PL c with SIL 1, PL d with SIL 2, and PL e with SIL 3. The mapping is approximate and exists for practical conversion rather than equivalence. If a specification requires SIL and your evidence is expressed in PL, the conversion needs to be documented rather than assumed.
SIL is also frequently confused with Security Level from IEC 62443, which uses the identical numbering from 1 to 4 for a completely unrelated concept. SIL measures reliability of a safety function; Security Level measures resistance to a class of attacker. A SIL 3 safety instrumented system with no security controls is entirely possible, and a common finding.
What Each Standard Requires You to Produce
- Hazard and risk assessment, normally a HAZOP for process plant or an ISO 12100 risk assessment for machinery.
- SIL or PL determination, typically via LOPA in process industries. See our SIL assessment and determination guide.
- Safety requirements specification, defining what each safety function must do and to what integrity. Covered by our SRS service.
- Design and verification evidence, showing the implemented system meets the specified target.
- Validation records, proving the installed system performs the safety function correctly.
- Proof test procedures and intervals, maintaining the integrity claim through operation.
Why Choose Arista Cyber
Arista Cyber delivers the full functional safety lifecycle under IEC 61508 and IEC 61511, led by TUV Rheinland certified practitioners. Three things distinguish how we work.
We scope against the standard that actually governs your equipment rather than the one we are most comfortable with, which prevents the documentation rework that costs projects months. We deliver every lifecycle stage from hazard study through validation and verification, so evidence traces cleanly from scenario to SIL claim. And because we work across both IEC 61511 and IEC 62443, the cybersecurity risk assessment that Clause 8.2.4 requires is part of the engagement rather than a separate procurement.
Next Steps
If you are unsure which standard governs your equipment, that question is worth resolving before any technical work begins. Explore our functional safety services, read about what happens during a functional safety assessment, or contact the Arista Cyber team.
Common Questions
Is IEC 61511 a replacement for IEC 61508?
No. IEC 61508 is the parent standard covering all electrical, electronic and programmable safety systems. IEC 61511 applies that framework specifically to process industry safety instrumented systems. Process operators work to IEC 61511, and rely on IEC 61508 certified devices to supply the failure data their calculations need.
Can I use SIL and Performance Level interchangeably?
No. They are different scales measuring the same underlying concept. ISO 13849 provides an approximate mapping, but a specification requiring SIL cannot be satisfied by PL evidence without a documented conversion. Establish which scale your specification uses before design begins.
Which standard applies if my process plant contains packaged machinery?
Both, at different boundaries. The packaged machine follows machinery standards for its own safety functions and CE marking. The plant safety instrumented system that interfaces with it follows IEC 61511. The interface between them needs explicit definition, and it is a frequent source of assessment findings.
|
Not sure which standard applies to your equipment? Arista Cyber can confirm the governing standard and scope the lifecycle work in a short consultation. TUV Rheinland certified practitioners across IEC 61508, IEC 61511 and machinery standards. |