
Safety PLC selection fails in three predictable ways, none of them knowledge gaps. A team picks hardware before the risk assessment produces a required level, then finds at validation that the function doesn't reach PL d. A machine builder stacks a sixth safety relay into a panel with no room for a seventh, and the first field change becomes a rewiring job. Or a line passes FAT and fails the safety audit because the F-module specified eighteen months ago is end-of-life and the certificate names a superseded part number.
None of that is a functional safety problem. It's a sequencing problem. This guide fixes the sequence: five steps from risk assessment to a part number you can send out for stock and lead time. For the mechanisms underneath (dual-channel processing, diagnostic coverage, fail-safe state design), our complete safety PLC guide covers those. This one is about deciding.
Safety PLC vs Standard PLC: The Two Differences That Change Your Design
Five differences get listed everywhere. Only two change what you buy and how you wire it.
Certification, not redundancy. The most repeated claim about safety PLCs is the wrong one. Redundancy is a means, not the essence: plenty of standard PLCs run redundant CPUs, and none are safety PLCs. The real difference is published PFHd and SFF figures backed by a TÜV or UL certificate. That isn't marketing; it's an input: you feed it into SISTEMA or your IEC 62061 calculation, and it lets you prove a performance level to an assessor. A standard PLC, however redundant, publishes no usable PFHd, so there is nothing to enter and nothing to prove. In an audit, "our redundant CPU is very reliable" isn't an argument. It's a gap.
Diagnostics, priced in downtime. Every datasheet says "detects its own faults. " What that buys is clearest at 3 a.m., when a light curtain channel drops for 40 milliseconds and someone must decide whether that was an intrusion or a connector vibrating loose. A relay knows one thing: the circuit opened, so your tech walks the whole zone. A safety PLC logs which channel and which discrepancy, and the operator resets in two minutes instead of forty. Over a year of nuisance trips is the largest number in the comparison, and it never appears on the quote.
(Certified function blocks are the third, smaller one: pre-validated under the vendor's certificate, so the verification and the liability stay with the vendor. Our complete guide has the full side-by-side table.)
The question is no longer whether. It's which level.
Step 1: Decide the Level You Actually Need
"Choose by SIL" assumes you already have a SIL. You don't choose one; you derive it.
Which standard applies to you
|
If your project is... |
You work under |
Rated as |
Key metric |
|
Machinery for the EU/UK |
ISO 13849-1 |
Performance Level (PL a to e) |
PFHd, Category, MTTFd, DC |
|
Machinery, complex electronic safety |
IEC 62061 |
SIL 1 to 3 |
PFHd |
|
Oil, gas, chemical, refining |
IEC 61511 (on IEC 61508) |
SIL |
PFDavg |
|
The component certification itself |
IEC 61508 |
SIL |
PFHd, SFF |
Most OEM control engineers are under ISO 13849-1, so this section speaks PL. An ESD or fire-and-gas logic solver puts you in IEC 61511 territory, where the platforms behind our energy industry solutions are on the shortlist.
How to determine PL from a risk assessment
ISO 13849-1 gets you to a required PL (PLr) from three parameters, judged per safety function, not per machine:
- S, severity. S1 = normally reversible. S2 = normally irreversible, including death. Amputation risk is S2; if you're arguing about it, it's S2.
- F, frequency and duration of exposure. F1 = seldom and short. F2 = frequent to continuous or long. A door opens once a shift is F1; every cycle, F2.
- P, possibility of avoidance. P1 = possible under specific conditions (slow motion, the operator sees it and steps back). P2 = scarcely possible. Faster than human reaction is P2.
Read them in order down the risk graph: S2 + F2 + P2 lands on PLr e, and S2 + F1 + P1 on PL c. The output is one line per function: "Guard door, cell 3: S2, F2, P1, therefore PLr d." Without that line you aren't ready for hardware, and any model recommendation, including ours, is a guess.
PL, SIL, Category and PFHd: the mapping table
|
Performance Level (ISO 13849-1) |
PFHd (per hour) |
Equivalent SIL (IEC 62061 / 61508) |
Typical Category |
|
PL a |
≥ 10⁻⁵ to < 10⁻⁴ |
No SIL equivalent |
B, 1 |
|
PL b |
≥ 3×10⁻⁶ to < 10⁻⁵ |
SIL 1 |
B, 1, 2, 3 |
|
PL c |
≥ 10⁻⁶ to < 3×10⁻⁶ |
SIL 1 |
1, 2, 3 |
|
PL d |
≥ 10⁻⁷ to < 10⁻⁶ |
SIL 2 |
2, 3 |
|
PL e |
≥ 10⁻⁸ to < 10⁻⁷ |
SIL 3 |
3, 4 |
How to use it. Take the PLr from your risk graph and read across: you now have the two things a datasheet actually states, a SIL equivalent and a PFHd band. Assessment says PL d, so you need SIL 2 equivalence, Category 3 structure, PFHd below 10⁻⁶. Open the Safety Manual and check the controller reaches that in the architecture you're building.
One warning that saves projects: this maps levels, not your function. PL belongs to the whole chain, sensor plus logic plus actuator, including Category, MTTFd, DC and CCF. A SIL 3 controller is a ceiling, not a result.
The common mistake: specifying SIL 3 when PL d is enough
Over-specification is the expensive error and the one that looks professional in a meeting. PL d to PL e means a higher-tier CPU, roughly double the safety I/O, a Category 4 architecture with the redundant field wiring that implies longer lead times, and a proof-test regime you carry for twenty years. Higher isn't more professional, just more, and an assessor will ask why your risk graph says d and your BOM says e.
Step 2: Safety Relay, Safety I/O Module, or Safety PLC?
Four questions decide it: how many safety functions; whether maintenance needs to know which channel tripped; whether safety must be networked or logged; whether the machine will change. Any "yes" past the first pushes you toward a PLC.
|
|
Safety relay |
Safety I/O module |
Safety PLC |
|
Safety functions |
1 to 3 |
4 to 12, logic lives elsewhere |
Dozens, one controller |
|
Wiring |
Every function hardwired |
Field wiring to a remote station |
Safety over the existing network |
|
Panel space |
~22.5mm per unit, grows linearly |
Compact, distributed |
One CPU slot |
|
Diagnostics |
Contact open or closed |
Per channel |
Per channel, logged, on the HMI |
|
Cost of a change |
Rewire, retest, redocument |
Moderate |
Download, revalidate one function |
|
Unit price |
Lowest |
Middle |
Highest hardware, lowest change cost |
Safety I/O modules are the option people forget: if you already run a compatible CPU, adding certified safety I/O over the existing network is often the shortest path. See what that looks like per brand on our PLC module pages.
The crossover point
Somewhere between three and five safety functions, the safety PLC's total cost starts to win. That's a working number from panel builds, not a standard, and it moves: tight panels push it to three, a machine that will never change pushes it past six. Anyone quoting "exactly four" has more confidence than the data supports.

Not sure which side you fall on?
Send us your safety function list and we'll tell you which way it falls, with a shortlist either way.
Step 3: Architecture: One CPU or Two? One Network or Two?
Integrated vs separate safety controller
Integrated (safety and standard logic on one F-CPU) wins on hardware cost, one engineering environment, and no gateway between safety status and control logic. It costs you at change management: the safety program shares a project with the standard one, so version control and access rights must keep the certified boundary clean.
Separate wins on that boundary: the safety system can be assessed, and left alone, independently of the process controller. It costs hardware, a second toolchain, and coordination.
Rule of thumb: machine builders and discrete lines go integrated, because safety functions and the machine change together. Process safety (ESD, burner management) goes separate, because independence from the process control system is the point and often the regulator's expectation.
The black channel principle
Safety data can share your standard network because the safety layer doesn't trust the network at all. PROFIsafe, CIP Safety and FSoE wrap each telegram in its own sequence number, timeout watchdog and CRC. The switches, cables and standard traffic underneath are an untrusted "black channel": a frame delayed, duplicated, corrupted or lost is detected, and the function goes to its safe state. The network doesn't have to be safe, only observed.
The consequence: you don't need a separate safety network. Safety and standard traffic share the same PROFINET or EtherNet/IP infrastructure, which removes a cable tray from your design. What you do need is a correctly calculated safety response time, since worst-case network latency counts against it. Your vendor's tool gives you that number.
Protocol, ecosystem, and what you can actually mix
|
Safety protocol |
Runs on |
Native ecosystem |
Mixing reality |
|
PROFIsafe |
PROFINET / PROFIBUS |
Siemens, ABB |
Certified third-party devices work on a Siemens F-CPU; the F-CPU stays Siemens |
|
CIP Safety |
EtherNet/IP |
Allen-Bradley, Omron |
The most cross-vendor of the four; Omron safety I/O on a GuardLogix is real |
|
FSoE (Safety over EtherCAT) |
EtherCAT |
Omron, Beckhoff |
Open on paper, assumes an EtherCAT backbone you may not have |
|
CC-Link IE Field Safety |
CC-Link IE Field / TSN |
Mitsubishi |
Effectively a Mitsubishi decision; strong in Asian supply chains |
Safety I/O crosses vendors more easily than safety CPUs do. Choosing the safety protocol is choosing the CPU brand, so make that call consciously rather than inherit it. For how the underlying networks compare, see our PLC communication protocols comparison.
Brownfield: adding safety to a line that already runs
Most safety projects aren't greenfield. Three paths: certified safety I/O on the existing controller (cheapest, but only if your CPU family has a fail-safe variant or an F-capable remote station); a standalone safety controller for the new zone (no touch to a running program whose author left in 2019, at the cost of a second toolchain); or migrating the CPU to the F-variant (cleanest, but revalidation needs a shutdown window you can't get before the annual stop). The shutdown window decides this, not the engineering. Plan backwards from it.
Step 4: The Six-Brand Model Table

|
Brand |
Safety series |
Max PL / SIL |
Safety network |
Best fit |
Stock |
|
Siemens |
SIMATIC S7-1500F / S7-1200F, ET 200SP F-CPU and F-modules |
PL e / SIL 3 |
PROFIsafe over PROFINET |
TIA Portal plants; the default for European machinery |
|
|
Allen-Bradley |
GuardLogix 5580, Compact GuardLogix 5380, Guard I/O |
PL e / SIL 3 |
CIP Safety over EtherNet/IP |
North American discrete lines, automotive cells, Rockwell sites |
|
|
Omron |
NX-SL safety CPU units, NX-SI / NX-SO safety I/O |
PL e / SIL 3 |
FSoE, and CIP Safety on EtherNet/IP |
High-speed packaging; motion, vision and safety on Sysmac |
|
|
Mitsubishi |
MELSEC iQ-R Safety CPU (R08 / R16 / R32 / R120SFCPU-SET) |
PL e / SIL 3, TÜV Rheinland certified |
CC-Link IE Field Safety, CC-Link IE TSN |
Motion-dense machinery; Asian lines on GX Works3 |
|
|
Schneider |
Modicon M580 Safety PAC with BMXS safety I/O |
SIL 3 |
Ethernet-based, black channel over the M580 backbone |
Process and hybrid plants, mixed-vendor sites |
|
|
ABB |
AC500-S with DI581-S / DX581-S safety modules |
PL e / SIL 3 |
PROFIsafe |
Heavy industry and energy sites built on ABB drives |
Confirm the exact certificate and firmware for your part number before design freeze; safety series get revised more often than their datasheets suggest. Specialist platforms (Pilz for machine safety, HIMA for process ESD) sit outside our stocked lines and are profiled in the complete safety PLC guide.
By scale: 3 to 8 functions on a single machine, S7-1200F or Compact GuardLogix 5380. A mid-size cell at 10 to 30, S7-1500F or GuardLogix 5580. Plant-wide, S7-1500F on distributed ET 200SP F-modules; process, M580 Safety.
Pick by ecosystem, not by spec sheet
The best safety CPU on paper is wrong if it fights the rest of your panel. Your HMI has to display safety status, and every gateway to a foreign safety CPU is engineering hours plus a tag map someone maintains. Drives matter more: STO and SS1 over the safety network only work cleanly when the variable frequency drive speaks the same safety protocol as the CPU. Mismatch them and you're back to hardwired STO terminals and a safety relay, the wiring you moved to a PLC to avoid. Ecosystem consistency isn't brand loyalty; it's integration hours you don't spend.
What a safety PLC actually costs
Roughly 1.5x to 2.5x the equivalent standard CPU in the same family, and 2x to 3x on safety I/O per point, plus a separate safety license and the engineering and validation hours nobody budgets. Those bands move with volume, region and lead time, which is why nobody serious publishes an absolute number.

Have a part number?
We'll check genuine stock, current pricing and real lead time across all six brands above.
Step 5: Verify Before You Buy
The four documents to demand from your supplier
|
Document |
What it does |
|
TÜV / UL certificate |
Names your exact part number and firmware. Without it the assessor has nothing to accept. |
|
Safety Manual |
The conditions under which the rating holds (proof-test interval, permitted architectures). Ignore it and the certificate doesn't apply to your build. |
|
PFHd / SFF datasheet |
The number you enter into your calculation. Without it there is no calculation. |
|
SISTEMA library file |
Saves a day of manual entry and removes transcription errors from a safety calculation. |
A supplier who can't produce all four is one you'll discover at validation, the most expensive moment to discover anything.
How to spot a gray-market safety controller
For a standard PLC a counterfeit costs you downtime. For a safety controller it costs someone a hand. Check four things: serial and firmware traceable to the manufacturer; a certificate naming your exact part number and firmware, not the family; original seals, printing and date codes (relabeled date codes mean a used unit sold as new); and a sane price, because a safety CPU far below market is the most reliable warning sign there is.
The part that ends the argument: a counterfeit's PFHd figure is fiction, and your safety calculation was built on that number. If it's fake, the calculation is void, the certificate is void, and your safety case describes a machine you don't own.
Lifecycle and lead time
Safety series go end-of-life on the manufacturer's schedule, not your project's, so check lifecycle status before design freeze: a phase-out part means a redesign, or hunting stock in the same market that sells counterfeits. Search a part number in our Model Library before it reaches your BOM.
Lead time is the same kind of risk. Safety-rated parts run longer than their standard equivalents, because volumes are lower and certified variants aren't stocked as deeply through official channels. By the time procurement finds a 14-week lead time on an F-module, the panel drawing is approved. Confirm availability while the BOM is still editable, and prefer a supplier who can tell you what's on a shelf today, which is what we hold.
Quick Reference: The 5-Step Checklist
|
Step |
Question to answer |
Output |
Where to get help |
|
1. Level |
What does the risk assessment require, per function? |
PLr / SIL per safety function |
The mapping table above |
|
2. Form |
Relay, safety I/O, or safety PLC? |
A form factor decision |
|
|
3. Architecture |
One CPU or two? Shared network or separate? |
An architecture and a safety protocol |
The protocol table above |
|
4. Model |
Which series, in which ecosystem? |
A part number |
|
|
5. Verify |
Genuine, certified, in lifecycle, in stock? |
Certificates, Safety Manual, confirmed lead time |
Before the line goes live: validate every certified block against its specification, run and record the proof test, check calculated safety response time against measured, and archive certificates, Safety Manual and calculation with the machine file.
FAQ

What's the difference between SIL and PL?
Is a SIL 3 safety PLC automatically PL e?
Can a safety PLC replace all my safety relays?
Can I run standard and safety logic on the same PLC?
How much more expensive is a safety PLC?
Can I add a safety PLC to an existing line?
Get the Right Safety PLC, In Stock and Genuine
The path is one-way. Level comes out of the risk assessment, not a preference. Architecture follows the level. The model follows the architecture and your ecosystem. Verification decides whether any of it survives the audit.
Chentuo supplies genuine safety series across all six brands above (Siemens, Allen-Bradley, Omron, Mitsubishi, Schneider, ABB) with certificates and Safety Manuals on request, and stock and lead time you can check today.

Send us your safety function list and your required PL/SIL. We'll return a model shortlist with certificates, current stock and real lead time within 24 hours.

