
Technical standards
EN ISO 13849-1 and Performance Level: safety-related machinery control systems
How to apply EN ISO 13849-1 to safety circuits: PLr, MTTFd, DCavg, CCF, SYSTEM and technical documentation.
The safety of a machine does not only depend on guards, barriers and emergency buttons. A decisive part of compliance concerns the control systems that must intervene when a safety function is required: stop a dangerous movement, prevent unexpected start-up, monitor an interlocked guard, manage a photoelectric barrier or command an STO on a drive.
EN ISO 13849-1 standard provides the method for designing and checking parts of safety-related systems, often referred to as SRP/CS, i.e. safety-related parts of control systems. The final result of the evaluation is the Performance Level, expressed by PL a, b, c, d or e, which represents the ability of the safety function to reduce the risk reliably.
What is EN ISO 13849-1
EN ISO 13849-1 is a reference standard for the design of parts of control systems that perform safety functions on machines. The international ISO 13849-1:2023 is the fourth edition of the standard and covers the general design principles of SRP/CS, including software connected to safety functions.
The standard does not determine which safety functions should be present on a specific machine and does not automatically assign a PLr. These decisions result from risk analysis, machine characteristics, intended use, reasonably foreseeable misuse and any applicable C-type standards.
For a manufacturer, then, applying EN ISO 13849-1 does not simply mean choosing “safety” components. It means showing that each safety function has been identified, designed, calculated, verified, validated and documented in a manner consistent with the risk to be reduced.
When applying to machine control systems
The standard applies when a part of the control system contributes to reducing a risk. Some typical examples are emergency stops, movable guard interlocks, photoelectric barriers, laser scanners, two-hand controls, safe stop functions, reduced speed control, hold-to-run controls and unexpected start-up prevention functions.
The principle is simple: if the malfunction of a circuit can result in the loss of a safety function, that circuit must be evaluated as part of a safety-related control system. In these cases it is not enough to check the schematic from the functional point of view; it is also necessary to evaluate architecture, reliability, diagnostics, systematic failures and behaviour in case of failure.
EN ISO 13849-1 is designed for high-demand or continuous functions, typical of the machine world. For low-demand applications, different methodologies may be relevant, to be evaluated case by case.
From risk to PLr: the role of risk analysis
The starting point is not the component, but the danger. Before calculating a Performance Level it is necessary to draw up the analysis of the machine’s risks, identify the hazardous situations and define which risk reduction measures are necessary.
When risk reduction is entrusted to a controlled safety function, the PLr must be determined, i.e. the required Performance Level. The PLr depends on the severity of possible damage, the frequency or duration of exposure to danger and the possibility of avoiding or limiting damage.
This phase is critical because an underestimated PLr leads to a too weak safety function compared to real risk. On the contrary, an overestimated PLr can generate technically correct but unnecessarily costly, complex and difficult to maintain solutions. The value lies in the balance: designing a proportional, documentable and consistent solution with the actual risk.
How to determine the Performance Level achieved
Once the PLr is defined, the designer must verify the PL achieved by the safety function. The result depends on the combination of different factors: circuit category, components reliability, diagnostic coverage, measures against common cause failures and proper software management, if present.
The evaluation can be carried out with dedicated tools, such as IFA SISTEMA, or with equivalent methods provided that reliable technical data, documented criteria and a clear traceability of the assumptions used are available.
Circuit Category
The category describes the architecture of the safety function and its behaviour in the presence of faults. Architectures can go from simple single-channel solutions to redundant structures with more advanced diagnostics.
The category is not, alone, the Performance Level. Two circuits with the same category can achieve different results if they change components reliability, diagnostics, control logic, frequency of use or measures against common cause failures.
MTTFd, B10d and components reliability
The reliability of the components is one of the main elements of the evaluation. For electronic components, data such as MTTFd or PFHd are normally used by the manufacturer. For electromechanical, pneumatic or hydraulic components it may be necessary to start from B10d data and the number of annual operations (Nop).
This point is often underestimated. If the number of real cycles of the machine is higher than the one suggested in the calculation, the result may no longer represent the reliability of the safety function. For this reason the hypotheses of use must be consistent with the machine cycle, the working environment and the expected useful life.
DCavg media diagnostic cover
Diagnostic coverage indicates how much the system is able to detect dangerous failures. A redundant function, for example, is not automatically reliable if there are no adequate controls on channel consistency, contact status, feedback or control devices.
Diagnosis must be real, consistent with the schema and verifiable. It is not enough to declare the presence of a safety PLC or a safety relay: it is necessary to demonstrate what faults are detected, with which logic and with what effects on the safety function.
CCF Joint Case Gains
In redundant systems it is also necessary to consider common cause failures, i.e. events that can compromise multiple channels simultaneously. Typical examples are wiring errors, heavy environmental conditions, overtensions, contamination, vibrations, design errors or choice of components too similar and not adequately separated.
Redundancy only has value if channels do not fail in the same way and at the same time. For this reason the CCF assessment should not be treated as a formality, but as a concrete verification of the robustness of the project.
safety Software
When the safety function involves software, programmable logic or safety PLC, the evaluation must also consider aspects of development, structure of the program, validation, management of changes and prevention of systematic errors.
The software must be readable, controllable and consistent with the specification of the safety function. An undocumented logic, although apparently working, can become a weak point during testing, maintenance or subsequent modification of the machine.
Verification, validation and documentation
Design in accordance with EN ISO 13849-1 must be followed by verification and validation. Verification uses calculations and technical evidence to demonstrate that the function achieves the required Performance Level. Validation confirms that the safety function has been implemented correctly and is effective for the intended use.
EN ISO 13849 series also includes EN ISO 13849-2, dedicated to validation. In practice, this means that the technical file should contain not only the calculation, but also the specification of the safety function, the relevant electrical schematics or tires, the data of the components, the hypotheses of use, the tests performed and the evidence of testing.
A Performance Level calculation without linking to risk analysis, without updated scheme or without functional validation is an incomplete document. In case of audit, documentary verification or dispute, the traceability of the whole process is essential.
EN ISO 13849-1:2023 and report with Machinery Regulation
2023 version of ISO 13849-1 updates the technical picture with respect to the previous 2015 edition. For those who design machines, the practical point does not change: the method must be integrated into the design process, not added to the end as formal verification.
In the European context, harmonised standards published in the Official Journal of the European Union may provide compliance with the essential requirements covered by the standard. However, the manufacturer must always check the updated list of applicable harmonised standards and the correspondence between relevant standards, machines and requirements. Reference
The Regulation (EU) 2023/1230 will replace Machinery Directive 2006/42/EC from 20 January 2027. This makes it even more important to build today ordered technical files, robust control systems and documentation easily up-to-date.
Be careful. EN ISO 13849-1 is not a shortcut to avoid risk analysis. It is a tool to correctly design and verify safety features after identifying and specifying them.
Frequent errors in the application of EN ISO 13849-1
| Common mistake | Why it is a problem |
|---|---|
| Starting from the component instead of the risk | The PLr must derive from the risk assessment. Selecting a safety relay or safety PLC is not sufficient to demonstrate conformity of the safety function. |
| Using untraceable B10d or MTTFd data | Data must come from reliable technical sources. Where data are unavailable, assumptions must be justified and conservative. |
| Confusing Category and Performance Level | The Category describes the architecture. The PL also depends on reliability, diagnostics, CCF and systematic requirements. |
| Failing to validate the function on the actual machine | The calculation must be supported by tests and functional checks that reflect the machine’s actual use. |
| Failing to update the calculation after modifications | A change to sensors, actuators, software logic, operating frequency or the machine cycle may alter the assessment result. |
| Considering only the emergency stop | Many critical safety functions are not emergency functions: interlocking, muting, enabling devices, reduced speed, prevention of unexpected restart and guard monitoring often have a greater effect on the actual risk. |
How Waves Engineering supports manufacturers
Waves Engineering supports machinery manufacturers, integrators and engineering teams throughout the management of safety functions, from risk assessment to the documentation included in the technical file.
Our support is not limited to the calculation. We verify the consistency between risk, safety function, electrical schema, components used, software logic, validation and instructions for use. This approach enables you to identify design errors before final testing and reduce the risk of non-compliance. Reference
We can intervene on new machines, substantial changes, existing lines, revamping, CE checks, preparation for the Machinery Regulation and adjustment of technical documentation for international markets.
Connected services Waves Engineering
Risk analysis according to EN ISO 12100.
Identification of PLr safety and determination functions.
Performance Level calculation according to EN ISO 13849-1.
Check electrical patterns and safety architectures.
Validation of safety functions according to EN ISO 13849-2.
Support for the drafting of the CE technical file.
instructions for use support instructions, warnings and operating procedures.
Conclusion
EN ISO 13849-1 is one of the most important tools to demonstrate the functional safety of machine control systems. Applying it correctly means connecting risk analysis, design, component selection, calculation, validation and documentation in a single consistent technical process.
For a manufacturer, the value is not having an isolated calculation, but a complete and defenseless demonstration of the safety function. This is where a structured technical approach makes the difference: it reduces errors, simplifies the technical file and makes the conformity of the machine more solid.
Do you need to check the Performance Level of your machine's safety features? Waves Engineering can support you in risk analysis, in calculation according to EN ISO 13849-1, in schematic verification and technical documentation for CE marking. Contact us for a technical evaluation. Reference
FAQ
What is EN ISO 13849-1?
It is a standard for the design and verification of parts of the control systems related to the safety of the machines. It is used to determine the Performance Level of safety functions.
What is the difference between PL and PLr?
The PLr is the level of performance required by risk assessment. The PL is the level actually achieved by the designed safety function. The function is appropriate when the PL reached is at least equal to the PLr.
Is the calculation of the Performance Level mandatory?
When risk reduction depends on a controlled safety function, the manufacturer must demonstrate that the function is adequate. EN ISO 13849-1 is one of the main methods used in the machine industry for this demonstration.
Just use safety certified components?
No. Certified components help, but that's not enough. It is necessary to evaluate the entire safety function: architecture, reliability, diagnostics, common cause failures, software logic, installation and validation.
What is IFA SISTEMA?
It is a software tool used to document and calculate safety functions according to ISO 13849-1. The result depends however on the correctness of input data, circuit diagrams and assumptions.
When should EN ISO 13849-1 evaluation be updated?
It should be updated when changing components, software logic, schematics, machine cycle, frequency of use, intended use or safety measures affecting the safety function being assessed.




