Understanding Performance Levels in Machine Safety - Flow Control Group

  • Home
  • Understanding Performance Levels in Machine Safety
FCG_Admin October 6, 2026 0 Comments

Machine safety functions must perform reliably when hazardous conditions occur. Under ISO 13849-1, that capability is expressed as a Performance Level (PL), ranging from PLa through PLe.

The required Performance Level is established as part of the machine risk assessment, while the achieved Performance Level depends on how the complete safety-related control function is designed. Factors such as circuit architecture, component reliability, diagnostics, common cause failures, software, and fault behavior all contribute to the result.

What Is a Performance Level?

A Performance Level describes the ability of the safety-related parts of a control system to perform a safety function under foreseeable conditions.

ISO 13849-1 defines five discrete levels:

  • PLa
  • PLb
  • PLc
  • PLd
  • PLe

Higher Performance Levels correspond to a greater capability to reduce risk through the safety-related control system.

Performance Level applies to a complete safety function or safety-related subsystem rather than being determined from a single component characteristic alone. ISO 13849-1 evaluates both quantitative reliability measures and qualitative design considerations when determining the achieved PL.

What Factors Determine Performance Level?

Safety Circuit Architecture

The structure of the safety circuit is one of the fundamental considerations. ISO 13849 uses designated architectures associated with Categories B, 1, 2, 3, and 4.

These categories describe how safety-related components are arranged, the level of redundancy and diagnostics incorporated into the design, and how the system behaves when faults occur.

Architecture alone does not establish the final Performance Level, but it sets an important foundation for what the safety circuit can achieve.

Mean Time to Dangerous Failure

Mean Time to Dangerous Failure (MTTFd) represents the reliability of components or channels with respect to failures that could result in loss of the safety function.

A higher MTTFd indicates a lower expected rate of dangerous failure. When evaluating the complete safety function, the reliability of the components within each channel contributes to the achievable Performance Level.

Diagnostic Coverage

Diagnostic Coverage (DC) describes how effectively the safety system detects dangerous failures.

A system with greater diagnostic capability can identify a larger proportion of failures before they result in loss of the safety function. ISO 13849 therefore considers diagnostic coverage alongside circuit architecture and component reliability when estimating Performance Level.

Common Cause Failures

Redundant safety channels can still fail if a single condition affects both channels simultaneously. These are known as common cause failures (CCF).

For example, two independent components may still be vulnerable to the same environmental condition, installation problem, or other shared cause.

Evaluating and reducing common cause failure risk is therefore an important part of designing redundant safety systems.

Fault Behavior

The way a safety circuit responds when a component fails also affects its safety capability.

For some architectures, particularly Category 2 systems, fault behavior may need to be evaluated using methods such as failure mode and effects analysis (FMEA) or fault tree analysis (FTA).

These analyses help determine whether a fault can prevent the safety function from operating as intended and whether additional measures are needed.

Safety-Related Software

When programmable controls are part of a safety function, the software development process must also address systematic faults.

Safety-related user software should be structured so that it can be understood, tested, verified, and maintained throughout its lifecycle. Software design is therefore part of the overall safety function assessment rather than separate from the hardware evaluation.

Systematic Failures

Not all failures are random component failures. Systematic failures can originate from identifiable causes associated with design, manufacturing, installation, operating procedures, or documentation.

Addressing these failures may require changing the design or the process that created the condition rather than simply selecting a component with a higher reliability rating.

Other Conditions That Can Affect Performance Level

The achieved Performance Level can also depend on conditions surrounding the application, including:

  • Environmental and ambient conditions
  • Frequency of demands on the safety function
  • Materials or substances that may affect components
  • Operating conditions and component usage

These factors reinforce why Performance Level should be evaluated for the complete safety function in its actual application.

Performance Level and Safety Integrity Level Are Related, but Not Interchangeable

Performance Level under ISO 13849 and Safety Integrity Level (SIL) under IEC 62061 are both methods of expressing functional safety capability, but they are established using different standards and assessment methods.

Approximate relationships can be made between the two systems. For example, PLb and PLc generally correspond to SIL 1, PLd to SIL 2, and PLe to SIL 3. However, a SIL value should not simply be converted into a Performance Level without evaluating the requirements of the applicable standard.

Performance Level Depends on the Complete Safety Function

Determining machine safety Performance Level requires more than selecting safety-rated devices. The complete circuit must be evaluated, including its architecture, component reliability, diagnostic capability, resistance to common cause failures, fault behavior, and any safety-related software.

Evaluating these factors together helps confirm whether the safety function achieves the Performance Level established by the machine risk assessment.