Functional Safety and Safety PLCs: ISO 13849 Explained
How Performance Level and architecture categories under ISO 13849 determine whether a safety function actually holds up.
How Performance Level and architecture categories under ISO 13849 determine whether a safety function actually holds up.
Collaborative robot standards like ISO 10218 and
ISO/TS 15066 answer a specific question: how close can a cobot work
to a person. Functional safety and ISO 13849 answer a broader one:
when a safety function is triggered — a light curtain, an
e-stop, a safety PLC — how reliably does it actually work.

ISO 13849 rates safety functions on a Performance Level scale from
PL a (lowest) to PL e (highest), based on factors like the
probability of a dangerous failure, diagnostic coverage, and
architecture category. A required PL is determined by risk
assessment — how severe an injury could be, how often someone
is exposed to the hazard, and how possible it is to avoid it once
something goes wrong.
| Category | Basic behavior |
|---|---|
| Category B / 1 | Single channel — a fault can lead to loss of the safety function |
| Category 2 | Periodically tested — a fault is detected at the next test cycle |
| Category 3 / 4 | Redundant channels — a single fault doesn’t lose the safety function |
A safety PLC rated for a high Performance Level doesn’t
automatically deliver that rating in an installation — wiring,
input devices, and the overall architecture all factor into the
achieved Performance Level of the complete safety function, not just
the controller’s own rating.

A safety-rated PLC executes independently of the standard process
controller, often on a separate program with certified logic blocks
for functions like safe torque off or safety-rated speed monitoring.
Mixing safety and standard logic in a single non-rated controller is
a common design mistake that undermines the entire safety case.

A calculated Performance Level on paper still has to be verified
against how the machine actually behaves — measuring stop
time, confirming the safety function actually removes power or
motion as designed, and documenting the result. Skipping validation
leaves a gap between the design intent and what the machine actually
does when the safety function triggers.

Functional safety and safety PLCs fit alongside the automation
fundamentals covered in SCMEP’s
Automation and Robotics training catalog, and complement our
related guide on
cobot safety standards for collaborative applications
specifically. As a NIST Manufacturing Extension
Partnership affiliate serving South Carolina manufacturers since
1989, our focus is making sure a calculated Performance Level
matches what the installed system actually does.
If your team is specifying or validating a safety function on new
or existing equipment, you can
browse the Automation and Robotics
training catalog or email the training team.
A rating from PL a to PL e based on the probability of dangerous failure, diagnostic coverage, and architecture category, determined by a risk assessment of injury severity, exposure frequency, and avoidability.
How a safety function behaves when a fault occurs — single-channel designs (Category B/1) can lose the function on a fault, while redundant designs (Category 3/4) maintain it even with a single fault.
A safety-rated PLC needs to execute independently, often with certified logic blocks for functions like safe torque off. Mixing safety and standard logic in a non-rated controller undermines the entire safety case.
A calculated rating on paper has to be confirmed against how the machine actually behaves — measuring stop time and confirming the safety function performs as designed once installed.