Functional Safety per EN ISO 13849-1

As soon as a protective function is implemented via the control system, a light curtain, an interlocked guard door, a safely monitored stop, the Machinery Directive requires proof that this safety function is reliable enough. This guide explains how the performance level proof per EN ISO 13849-1 is structured and how the functional safety module of CE-Copilot documents it, with a clear division of labour with SISTEMA.

What does functional safety require in the CE process?

The legal anchor is Annex I No 1.2.1 of the Machinery Directive 2006/42/EC (continued in substance in the Machinery Regulation (EU) 2023/1230): control systems must be designed so that a fault does not lead to hazardous situations. The harmonised standard for this is EN ISO 13849-1 (safety-related parts of control systems); for purely electrical, electronic and programmable systems, EN IEC 62061 with its safety integrity levels (SIL) exists in parallel.

The proof consists of two parts. First: for every safety function the required performance level (PLr) is determined, from a (low) to e (high). This is done with the risk graph of the standard from three questions: how severe would the injury be (S)? How often and for how long is a person exposed to the hazard (F)? Can the hazard be avoided in an emergency (P)? Second: for the control solution actually built, the achieved performance level (PL) is calculated, from the control category (B to 4), the mean time to dangerous failure (MTTFd), the average diagnostic coverage (DCavg) and the measures against common cause failures (CCF). Verification compares the two: PL must reach at least PLr.

The proof of functional safety has two parts. You derive the required performance level (PLr) from the risk assessment; in the functional safety module you record it per safety function using the risk graph of EN ISO 13849-1. The calculation of the PL actually ACHIEVED from category, MTTFd, DCavg and CCF, together with the manufacturers' component data (libraries per VDMA 66413), belongs in SISTEMA, the free tool of the IFA of the DGUV. CE-Copilot does not replace SISTEMA: you then record the SISTEMA result in the module, the software checks PL against PLr for plausibility, and the SISTEMA report belongs in the technical file as evidence, in the section on drawings and calculations.

The functional safety module in CE-Copilot

The module is included from the Starter plan and sits in the project workflow directly after the risk assessment, because the PLr is derived from its hazards. Below are the central functions, each with its concrete advantage and the benefit for your daily work.

Feature

Risk graph of EN ISO 13849-1 for the required performance level (PLr)

Advantage

For each safety function you select the severity of injury (S1/S2), the frequency or duration of exposure to the hazard (F1/F2) and the possibility of avoiding the hazard (P1/P2); the PLr from a to e is determined deterministically according to the risk graph of the standard, with an explanation of every parameter. Alternatively you enter a manually specified PLr. For orientation, the corresponding SIL per EN 62061 is shown for information.

Your benefit

The required performance level is documented in your file in a traceable way and justified in line with the standard, instead of as an unsupported number in an Excel cell.

Feature

Linking the safety functions to the hazards of the risk assessment

Advantage

You link every safety function to one or more hazards from your risk assessment per EN ISO 12100. This documents which risk the protective function reduces and why it exists.

Your benefit

The risk assessment and the proof of functional safety remain one coherent, auditable chain of reasoning instead of two separate documents.

Feature

SISTEMA handover list, result capture and verification PL ≥ PLr

Advantage

A CSV handover list bundles your safety functions with their PLr for entry into SISTEMA. You then record the result calculated there (achieved PL, category, PFHd, optionally MTTFd, DCavg and CCF points) in the module; the software checks PL against PLr and flags contradictions with the characteristic values of the standard, for example if the stated PL does not match the category per Figure 5 or the PFHd value does not match Table 3.

Your benefit

You see at a glance which safety function reaches its required performance level and where action is still needed, with a plausibility check instead of blind transcription.

Feature

Evidence in the complete CE documentation

Advantage

Recorded safety functions appear with their hazard link, PLr including its origin, SISTEMA result and verification status as a separate chapter in the project's complete export (PDF and Word) and in the structured project export.

Your benefit

The proof of functional safety sits where market surveillance and auditors expect it: in the technical file, without a separate file store.

What the module deliberately does not do

CE-Copilot does not calculate the achieved performance level and does not maintain component libraries. This safety-critical calculation belongs in SISTEMA, the free reference tool of the IFA of the DGUV, with the component characteristic values maintained by the manufacturers (VDMA 66413). Nor does the module replace validation per EN ISO 13849-2 or engineering judgement: S, F and P are deliberately separate inputs and are not derived from the risk score of the risk assessment. The responsibility for CE marking remains with the manufacturer.

Document your performance level proof in a structured way now

Set the PLr per safety function traceably, document the SISTEMA result and verify PL ≥ PLr, as part of your complete CE documentation. From the Starter plan, cancellable monthly.

More articles