How to Choose a Safety PLC: 5 Steps From Risk Assessment to a Part Number You Can Order

Jul 17, 2026

Leave a message

Chen Tuo
Chen Tuo
Chen Tuo, Senior Automation Engineer at Shenzhen Chentuo Technology, has 15+ years of hands-on PLC, HMI, and VFD experience with Siemens, ABB, Allen-Bradley, Mitsubishi, Omron, and Schneider, supporting automation projects in 80+ countries.

An engineer holds a bill of materials beside a fail-safe controller and a row of safety relays inside an open control cabinet

 

Safety PLC selection fails in three predictable ways, none of them knowledge gaps. A team picks hardware before the risk assessment produces a required level, then finds at validation that the function doesn't reach PL d. A machine builder stacks a sixth safety relay into a panel with no room for a seventh, and the first field change becomes a rewiring job. Or a line passes FAT and fails the safety audit because the F-module specified eighteen months ago is end-of-life and the certificate names a superseded part number.

 

None of that is a functional safety problem. It's a sequencing problem. This guide fixes the sequence: five steps from risk assessment to a part number you can send out for stock and lead time. For the mechanisms underneath (dual-channel processing, diagnostic coverage, fail-safe state design), our complete safety PLC guide covers those. This one is about deciding.

 

Safety PLC vs Standard PLC: The Two Differences That Change Your Design

Five differences get listed everywhere. Only two change what you buy and how you wire it.

 

Certification, not redundancy. The most repeated claim about safety PLCs is the wrong one. Redundancy is a means, not the essence: plenty of standard PLCs run redundant CPUs, and none are safety PLCs. The real difference is published PFHd and SFF figures backed by a TÜV or UL certificate. That isn't marketing; it's an input: you feed it into SISTEMA or your IEC 62061 calculation, and it lets you prove a performance level to an assessor. A standard PLC, however redundant, publishes no usable PFHd, so there is nothing to enter and nothing to prove. In an audit, "our redundant CPU is very reliable" isn't an argument. It's a gap.

 

Diagnostics, priced in downtime. Every datasheet says "detects its own faults. " What that buys is clearest at 3 a.m., when a light curtain channel drops for 40 milliseconds and someone must decide whether that was an intrusion or a connector vibrating loose. A relay knows one thing: the circuit opened, so your tech walks the whole zone. A safety PLC logs which channel and which discrepancy, and the operator resets in two minutes instead of forty. Over a year of nuisance trips is the largest number in the comparison, and it never appears on the quote.

 

(Certified function blocks are the third, smaller one: pre-validated under the vendor's certificate, so the verification and the liability stay with the vendor. Our complete guide has the full side-by-side table.)

 

The question is no longer whether. It's which level.

 

Step 1: Decide the Level You Actually Need

"Choose by SIL" assumes you already have a SIL. You don't choose one; you derive it.

 

Which standard applies to you

If your project is...

You work under

Rated as

Key metric

Machinery for the EU/UK

ISO 13849-1

Performance Level (PL a to e)

PFHd, Category, MTTFd, DC

Machinery, complex electronic safety

IEC 62061

SIL 1 to 3

PFHd

Oil, gas, chemical, refining

IEC 61511 (on IEC 61508)

SIL

PFDavg

The component certification itself

IEC 61508

SIL

PFHd, SFF

 

Most OEM control engineers are under ISO 13849-1, so this section speaks PL. An ESD or fire-and-gas logic solver puts you in IEC 61511 territory, where the platforms behind our energy industry solutions are on the shortlist.

 

How to determine PL from a risk assessment

ISO 13849-1 gets you to a required PL (PLr) from three parameters, judged per safety function, not per machine:

 

  1. S, severity. S1 = normally reversible. S2 = normally irreversible, including death. Amputation risk is S2; if you're arguing about it, it's S2.
  2. F, frequency and duration of exposure. F1 = seldom and short. F2 = frequent to continuous or long. A door opens once a shift is F1; every cycle, F2.
  3. P, possibility of avoidance. P1 = possible under specific conditions (slow motion, the operator sees it and steps back). P2 = scarcely possible. Faster than human reaction is P2.

 

Read them in order down the risk graph: S2 + F2 + P2 lands on PLr e, and S2 + F1 + P1 on PL c. The output is one line per function: "Guard door, cell 3: S2, F2, P1, therefore PLr d." Without that line you aren't ready for hardware, and any model recommendation, including ours, is a guess.

 

PL, SIL, Category and PFHd: the mapping table

Performance Level (ISO 13849-1)

PFHd (per hour)

Equivalent SIL (IEC 62061 / 61508)

Typical Category

PL a

≥ 10⁻⁵ to < 10⁻⁴

No SIL equivalent

B, 1

PL b

≥ 3×10⁻⁶ to < 10⁻⁵

SIL 1

B, 1, 2, 3

PL c

≥ 10⁻⁶ to < 3×10⁻⁶

SIL 1

1, 2, 3

PL d

≥ 10⁻⁷ to < 10⁻⁶

SIL 2

2, 3

PL e

≥ 10⁻⁸ to < 10⁻⁷

SIL 3

3, 4

 

How to use it. Take the PLr from your risk graph and read across: you now have the two things a datasheet actually states, a SIL equivalent and a PFHd band. Assessment says PL d, so you need SIL 2 equivalence, Category 3 structure, PFHd below 10⁻⁶. Open the Safety Manual and check the controller reaches that in the architecture you're building.

 

One warning that saves projects: this maps levels, not your function. PL belongs to the whole chain, sensor plus logic plus actuator, including Category, MTTFd, DC and CCF. A SIL 3 controller is a ceiling, not a result.

 

The common mistake: specifying SIL 3 when PL d is enough

Over-specification is the expensive error and the one that looks professional in a meeting. PL d to PL e means a higher-tier CPU, roughly double the safety I/O, a Category 4 architecture with the redundant field wiring that implies longer lead times, and a proof-test regime you carry for twenty years. Higher isn't more professional, just more, and an assessor will ask why your risk graph says d and your BOM says e.

 

Step 2: Safety Relay, Safety I/O Module, or Safety PLC?

Four questions decide it: how many safety functions; whether maintenance needs to know which channel tripped; whether safety must be networked or logged; whether the machine will change. Any "yes" past the first pushes you toward a PLC.

 

 

Safety relay

Safety I/O module

Safety PLC

Safety functions

1 to 3

4 to 12, logic lives elsewhere

Dozens, one controller

Wiring

Every function hardwired

Field wiring to a remote station

Safety over the existing network

Panel space

~22.5mm per unit, grows linearly

Compact, distributed

One CPU slot

Diagnostics

Contact open or closed

Per channel

Per channel, logged, on the HMI

Cost of a change

Rewire, retest, redocument

Moderate

Download, revalidate one function

Unit price

Lowest

Middle

Highest hardware, lowest change cost

 

Safety I/O modules are the option people forget: if you already run a compatible CPU, adding certified safety I/O over the existing network is often the shortest path. See what that looks like per brand on our PLC module pages.

 

The crossover point

Somewhere between three and five safety functions, the safety PLC's total cost starts to win. That's a working number from panel builds, not a standard, and it moves: tight panels push it to three, a machine that will never change pushes it past six. Anyone quoting "exactly four" has more confidence than the data supports.

 

modular-1
Not sure which side you fall on?

Send us your safety function list and we'll tell you which way it falls, with a shortlist either way.

Step 3: Architecture: One CPU or Two? One Network or Two?

Integrated vs separate safety controller

Integrated (safety and standard logic on one F-CPU) wins on hardware cost, one engineering environment, and no gateway between safety status and control logic. It costs you at change management: the safety program shares a project with the standard one, so version control and access rights must keep the certified boundary clean.

 

Separate wins on that boundary: the safety system can be assessed, and left alone, independently of the process controller. It costs hardware, a second toolchain, and coordination.

 

Rule of thumb: machine builders and discrete lines go integrated, because safety functions and the machine change together. Process safety (ESD, burner management) goes separate, because independence from the process control system is the point and often the regulator's expectation.

 

The black channel principle

Safety data can share your standard network because the safety layer doesn't trust the network at all. PROFIsafe, CIP Safety and FSoE wrap each telegram in its own sequence number, timeout watchdog and CRC. The switches, cables and standard traffic underneath are an untrusted "black channel": a frame delayed, duplicated, corrupted or lost is detected, and the function goes to its safe state. The network doesn't have to be safe, only observed.

 

The consequence: you don't need a separate safety network. Safety and standard traffic share the same PROFINET or EtherNet/IP infrastructure, which removes a cable tray from your design. What you do need is a correctly calculated safety response time, since worst-case network latency counts against it. Your vendor's tool gives you that number.

 

Protocol, ecosystem, and what you can actually mix

Safety protocol

Runs on

Native ecosystem

Mixing reality

PROFIsafe

PROFINET / PROFIBUS

Siemens, ABB

Certified third-party devices work on a Siemens F-CPU; the F-CPU stays Siemens

CIP Safety

EtherNet/IP

Allen-Bradley, Omron

The most cross-vendor of the four; Omron safety I/O on a GuardLogix is real

FSoE (Safety over EtherCAT)

EtherCAT

Omron, Beckhoff

Open on paper, assumes an EtherCAT backbone you may not have

CC-Link IE Field Safety

CC-Link IE Field / TSN

Mitsubishi

Effectively a Mitsubishi decision; strong in Asian supply chains

 

Safety I/O crosses vendors more easily than safety CPUs do. Choosing the safety protocol is choosing the CPU brand, so make that call consciously rather than inherit it. For how the underlying networks compare, see our PLC communication protocols comparison.

 

Brownfield: adding safety to a line that already runs

Most safety projects aren't greenfield. Three paths: certified safety I/O on the existing controller (cheapest, but only if your CPU family has a fail-safe variant or an F-capable remote station); a standalone safety controller for the new zone (no touch to a running program whose author left in 2019, at the cost of a second toolchain); or migrating the CPU to the F-variant (cleanest, but revalidation needs a shutdown window you can't get before the annual stop). The shutdown window decides this, not the engineering. Plan backwards from it.

 

Step 4: The Six-Brand Model Table

 

Six industrial safety controllers of different sizes arranged in a row on a workbench mat beside a notebook and crimping tool

 

Brand

Safety series

Max PL / SIL

Safety network

Best fit

Stock

Siemens

SIMATIC S7-1500F / S7-1200F, ET 200SP F-CPU and F-modules

PL e / SIL 3

PROFIsafe over PROFINET

TIA Portal plants; the default for European machinery

Siemens PLC

Allen-Bradley

GuardLogix 5580, Compact GuardLogix 5380, Guard I/O

PL e / SIL 3

CIP Safety over EtherNet/IP

North American discrete lines, automotive cells, Rockwell sites

Allen-Bradley PLC

Omron

NX-SL safety CPU units, NX-SI / NX-SO safety I/O

PL e / SIL 3

FSoE, and CIP Safety on EtherNet/IP

High-speed packaging; motion, vision and safety on Sysmac

Omron PLC

Mitsubishi

MELSEC iQ-R Safety CPU (R08 / R16 / R32 / R120SFCPU-SET)

PL e / SIL 3, TÜV Rheinland certified

CC-Link IE Field Safety, CC-Link IE TSN

Motion-dense machinery; Asian lines on GX Works3

Mitsubishi PLC

Schneider

Modicon M580 Safety PAC with BMXS safety I/O

SIL 3

Ethernet-based, black channel over the M580 backbone

Process and hybrid plants, mixed-vendor sites

Schneider PLC

ABB

AC500-S with DI581-S / DX581-S safety modules

PL e / SIL 3

PROFIsafe

Heavy industry and energy sites built on ABB drives

ABB PLC

 

Confirm the exact certificate and firmware for your part number before design freeze; safety series get revised more often than their datasheets suggest. Specialist platforms (Pilz for machine safety, HIMA for process ESD) sit outside our stocked lines and are profiled in the complete safety PLC guide.

 

By scale: 3 to 8 functions on a single machine, S7-1200F or Compact GuardLogix 5380. A mid-size cell at 10 to 30, S7-1500F or GuardLogix 5580. Plant-wide, S7-1500F on distributed ET 200SP F-modules; process, M580 Safety.

 

Pick by ecosystem, not by spec sheet

The best safety CPU on paper is wrong if it fights the rest of your panel. Your HMI has to display safety status, and every gateway to a foreign safety CPU is engineering hours plus a tag map someone maintains. Drives matter more: STO and SS1 over the safety network only work cleanly when the variable frequency drive speaks the same safety protocol as the CPU. Mismatch them and you're back to hardwired STO terminals and a safety relay, the wiring you moved to a PLC to avoid. Ecosystem consistency isn't brand loyalty; it's integration hours you don't spend.

 

What a safety PLC actually costs

Roughly 1.5x to 2.5x the equivalent standard CPU in the same family, and 2x to 3x on safety I/O per point, plus a separate safety license and the engineering and validation hours nobody budgets. Those bands move with volume, region and lead time, which is why nobody serious publishes an absolute number.

 

modular-1
Have a part number?

We'll check genuine stock, current pricing and real lead time across all six brands above.

Step 5: Verify Before You Buy

The four documents to demand from your supplier

Document

What it does

TÜV / UL certificate

Names your exact part number and firmware. Without it the assessor has nothing to accept.

Safety Manual

The conditions under which the rating holds (proof-test interval, permitted architectures). Ignore it and the certificate doesn't apply to your build.

PFHd / SFF datasheet

The number you enter into your calculation. Without it there is no calculation.

SISTEMA library file

Saves a day of manual entry and removes transcription errors from a safety calculation.

 

A supplier who can't produce all four is one you'll discover at validation, the most expensive moment to discover anything.

 

How to spot a gray-market safety controller

For a standard PLC a counterfeit costs you downtime. For a safety controller it costs someone a hand. Check four things: serial and firmware traceable to the manufacturer; a certificate naming your exact part number and firmware, not the family; original seals, printing and date codes (relabeled date codes mean a used unit sold as new); and a sane price, because a safety CPU far below market is the most reliable warning sign there is.

 

The part that ends the argument: a counterfeit's PFHd figure is fiction, and your safety calculation was built on that number. If it's fake, the calculation is void, the certificate is void, and your safety case describes a machine you don't own.

 

Lifecycle and lead time

Safety series go end-of-life on the manufacturer's schedule, not your project's, so check lifecycle status before design freeze: a phase-out part means a redesign, or hunting stock in the same market that sells counterfeits. Search a part number in our Model Library before it reaches your BOM.

 

Lead time is the same kind of risk. Safety-rated parts run longer than their standard equivalents, because volumes are lower and certified variants aren't stocked as deeply through official channels. By the time procurement finds a 14-week lead time on an F-module, the panel drawing is approved. Confirm availability while the BOM is still editable, and prefer a supplier who can tell you what's on a shelf today, which is what we hold.

 

Quick Reference: The 5-Step Checklist

Step

Question to answer

Output

Where to get help

1. Level

What does the risk assessment require, per function?

PLr / SIL per safety function

The mapping table above

2. Form

Relay, safety I/O, or safety PLC?

A form factor decision

Send your function list

3. Architecture

One CPU or two? Shared network or separate?

An architecture and a safety protocol

The protocol table above

4. Model

Which series, in which ecosystem?

A part number

Model Library

5. Verify

Genuine, certified, in lifecycle, in stock?

Certificates, Safety Manual, confirmed lead time

Request a quote

 

Before the line goes live: validate every certified block against its specification, run and record the proof test, check calculated safety response time against measured, and archive certificates, Safety Manual and calculation with the machine file.

 

FAQ

 

 

How to Choose a Safety PLC: 5 Steps From Risk Assessment to a Part Number You Can Order

What's the difference between SIL and PL?

Two scales for the same thing from different standards: PL from ISO 13849-1 (machinery), SIL from IEC 62061 and IEC 61508. They map through the PFHd band, so PL d corresponds to SIL 2 and PL e to SIL 3. Use the mapping table above to turn your level into something a datasheet states.

Is a SIL 3 safety PLC automatically PL e?

No, and this question separates the engineers from the brochures. SIL 3 and PL e share a PFHd band, so a SIL 3 controller can sit in a PL e function. But PL belongs to the complete function, sensor plus logic plus actuator, and depends on Category, MTTFd, diagnostic coverage and common cause failure. The controller's rating is a ceiling; your architecture decides the result.

Can a safety PLC replace all my safety relays?

Technically yes, economically not always. Past roughly three to five functions the PLC wins on total cost. Below that, a relay on a standalone machine with one guard door and an e-stop is the right answer, and a PLC is over-engineering you pay for twice.

Can I run standard and safety logic on the same PLC?

Yes, on a fail-safe CPU like an S7-1500F or GuardLogix. The safety program runs in a certified, protected context alongside the standard one, and safety data shares the network via the black channel principle. The trade-off isn't technical, it's change management: your safety logic now lives in a project that changes for non-safety reasons.

How much more expensive is a safety PLC?

Roughly 1.5x to 2.5x the equivalent standard CPU and 2x to 3x on safety I/O per point, plus the safety license and engineering time. Treat those as orientation and get a quote for your actual BOM.

Can I add a safety PLC to an existing line?

Yes, by one of three paths: certified safety I/O on your current controller, a standalone safety controller for the new zone, or a CPU migration to the fail-safe variant. The shutdown window you can get usually decides it, not the engineering. Tell us the existing CPU and we'll scope the options.

Get the Right Safety PLC, In Stock and Genuine

The path is one-way. Level comes out of the risk assessment, not a preference. Architecture follows the level. The model follows the architecture and your ecosystem. Verification decides whether any of it survives the audit.

 

Chentuo supplies genuine safety series across all six brands above (Siemens, Allen-Bradley, Omron, Mitsubishi, Schneider, ABB) with certificates and Safety Manuals on request, and stock and lead time you can check today.

 

A well-stocked warehouse aisle with shelves of boxed automation controllers and modules ready for shipment..jpg

Send us your safety function list and your required PL/SIL. We'll return a model shortlist with certificates, current stock and real lead time within 24 hours.

 

Send Inquiry