Menu
ISO 13849 Performance Levels: A Practical Guide for Maintenance

ISO 13849 Performance Levels: A Practical Guide for Maintenance

What PL a to PL e actually rate, how PLr falls out of the risk graph, what the categories and MTTFd really buy, and the maintenance moves that void a performance level with no warning light.
ISO 13849 Performance Levels: A Practical Guide for Maintenance

Key takeaways

  • A performance level (PL a to e) rates a complete safety function, the whole chain from sensor through logic to actuator. It never belongs to a single component on a datasheet.
  • The required performance level PLr comes from a risk graph with three plain questions: how bad is the injury, how often is someone exposed, and can they get out of the way.
  • Delivering a PL takes four things together: a designated architecture (category B to 4), reliable components (MTTFd), diagnostics that see dangerous failures (DC), and protection against common cause failures.
  • Maintenance can destroy a PL without anyone noticing: a non-identical spare, a bridged function during troubleshooting, or a component run past its mission time, commonly 20 years.
  • Per-function records (function id, PLr, components, test dates, findings) are the only proof the function still exists.

What a safety function is

ISO 13849 does not rate parts. It rates safety functions: complete chains in which something detects, something decides, and something acts. Guard open leads to hazardous movement stopping is one safety function: the interlock switch detects, the safety relay decides, the contactors drop out. The e-stop is another; two-hand control on a press a third. One machine commonly carries a dozen or more.

The performance level, PL a (lowest) to PL e (highest), expresses how reliably that whole chain performs on demand, and it dies with the weakest link. A component sold as "PL e" is only capable of serving in a PL e function; the level itself belongs to the function.

The guards themselves are covered in our guide to machine guarding, and the interlock devices fitted to them in machine guard interlocks. This article is about the reliability rating those devices work inside.

PLr: how much reliability the risk demands

Before anyone picks hardware, the machinery risk assessment answers three questions per hazard, walking down a risk graph to the required performance level, PLr:

  • S, severity: S1, slight injury that normally heals; S2, serious irreversible injury or death.
  • F, frequency or duration of exposure: F1, seldom or briefly; F2, frequently or for long periods.
  • P, possibility of avoidance: P1, avoidance is possible under specific conditions (slow movement, good visibility, room to step back); P2, scarcely possible.

The worst combination, S2 F2 P2, lands on PLr e. S2 F2 P1 and S2 F1 P2 land on PLr d. The S1 branch ends between a and c.

On a bought machine this work is the manufacturer's, and PLr per function should be in the documentation. The duty split is the one our piece on the EU Machinery Regulation 2023/1230 describes: the builder designs and validates the functions, the user keeps them effective. That second half is where maintenance lives.

What actually delivers a PL

Four ingredients combine to produce the achieved PL. In plain words:

  • Category B: a single channel built from standard components used within spec; a single fault can lose the safety function.
  • Category 1: still a single channel, but built from well-tried components and principles, so failure is less likely; a single fault can still lose the function.
  • Category 2: a single channel plus a test channel that checks the safety function at suitable intervals, so some faults are caught.
  • Category 3: two channels, so a single fault does not lose the safety function, and most single faults are detected.
  • Category 4: two channels with diagnostics strong enough that even an accumulation of undetected faults does not lose the function.

Around the architecture sit three more numbers. MTTFd, the mean time to dangerous failure of each channel, banded low, medium and high. DC, diagnostic coverage, the share of dangerous failures the monitoring can actually see. And CCF, common cause failure protection, scored against a checklist in the standard (separation, diversity, over-dimensioning), because two channels that die together from one cause are one channel.

The same category with poorer component reliability or weaker diagnostics lands a lower PL: it is a matrix, not a menu, which is why swapping parts changes the answer.

PL and SIL: a rough correspondence

Machinery safety speaks PL; process safety speaks SIL. As a rough correspondence, PL c sits near SIL 1, PL d near SIL 2, and PL e near SIL 3. Treat it as orientation only: the governing standards decide, and nobody should relabel a system from one to the other by nameplate. If your plant also runs process units under IEC 61511, that is a different regime with its own testing discipline, covered in our article on safety instrumented systems.

What maintenance must know

The achieved PL is a property of the exact hardware installed today. Four rules keep it alive:

  • The like-for-like law. The architecture lives in part numbers. Replace a safety relay with a general-purpose relay, a contactor that has mirror contacts with one that does not, or a coded interlock with a cheaper uncoded spare, and the machine will usually still stop. The category quietly changes, the PL is gone, and no light comes on. Replacement means the identical part or a manufacturer-confirmed equivalent, recorded against the function.
  • Never bridge or force a safety function to troubleshoot. A jumpered interlock or a forced output turns a PL d function into no function. Diagnose with the function intact, or under a controlled, signed, time-limited procedure.
  • Mission time. ISO 13849 calculations assume a limited service life, commonly 20 years: at the end of it, safety components are replaced even if they still work, because the reliability numbers behind the PL no longer hold. Electromechanical parts on high-cycle duty can consume their life much sooner; the manufacturer's data decides.
  • Test on the stated schedule, and record per function. The manual and the machine's validation set the functional test interval. Each record needs the function id, its PLr, the components in the chain, the test date, the result and any findings. Those records belong in the same preventive maintenance plan as the rest of the asset, not in a binder that leaves with a retiring technician.

In Fabrico, each safety function's test runs as a recurring PM task with a checklist, results are stored against the asset, a failed check can trigger a follow-up task, and the per-function history is ready when an auditor asks what was tested and when. To see that on your own machine list, book a short demo.

A worked example with real numbers

A case packer has a hinged guard door over the loading area. The risk graph: a crush injury from the pusher is irreversible, S2. The operator opens the guard several times per shift to clear jams, F2. The movement is slow and visible enough that avoidance is judged possible under specific conditions, P1. Result: PLr d.

The builder delivers it as category 3: a type 4 RFID interlock on the door, a safety relay, and two contactors in series with mirror contacts wired into the relay's feedback loop, so a welded contactor is detected at the next cycle.

The maintenance reality in year one: the line carries 14 safety functions, and the validation calls for a monthly functional test of each, spread across shifts. That is 168 tests a year at roughly 10 minutes each including the record: about 28 hours of technician time a year.

In March, a night-shift breakdown killed one contactor, and a commercial spare of the right rating went in. The machine stopped perfectly every time the guard opened, so to the operator nothing had changed. But the spare had no mirror contacts: the safety relay's feedback loop could no longer see a welded contact. The machine would still have stopped on one failed contactor, so nothing looked wrong; what was lost is detection. A weld would now sit there undiscovered until the second contactor failed too, and it is precisely that detection of dangerous faults which category 3 requires. The April functional test caught it, because the checklist includes verifying the feedback monitoring, not just "does it stop".

The fix was a corrective work order to fit the correct contactor, plus the boring change that prevents the repeat: the spares list for that machine was corrected so stores can only issue the exact mirror-contact part against it. The function appeared to work for five weeks while the PL did not exist.

Common mistakes

  • Treating PL as a component rating. A "PL e" logo on a datasheet describes capability, not your installation. The level belongs to the function, and the weakest link sets it.
  • Mixing SIL and PL paperwork on one machine. Pick the regime the machine was validated under and keep the records in its language.
  • Bridging a function to keep production running. Every hour it runs bridged, the machine operates with a hazard the risk assessment says needs PL d protection, and none is present.
  • Non-identical spares. The cheapest way to void a safety design is a well-meant substitution at 3 a.m. Lock the spares list to the validated part numbers.
  • Ignoring mission time. A 20-year-old safety relay that still clicks is not evidence; the statistics behind its PL expired with its mission time.
  • No per-function test records. If nobody can produce the test history for function 7, then as far as an incident investigation is concerned, function 7 was never tested.

Frequently asked questions

What is a performance level in ISO 13849?

A performance level, PL a to PL e, expresses how reliably a complete safety function (sensor, logic, actuator) performs on demand. It is determined by the architecture category, component reliability (MTTFd), diagnostic coverage and common cause failure protection.

What is the difference between PL and SIL?

PL comes from ISO 13849 for machinery safety functions; SIL from IEC 61508 and IEC 61511, typically in process plants. As a rough correspondence PL c sits near SIL 1, PL d near SIL 2 and PL e near SIL 3, but the standards decide and there is no relabelling by nameplate.

How do I know what PL a machine needs?

The required level, PLr, comes from the risk assessment via the risk graph: severity of injury (S1/S2), frequency or duration of exposure (F1/F2) and possibility of avoidance (P1/P2). On a bought machine the manufacturer should state the PLr per safety function in the documentation; if it is missing, ask for it.

Can maintenance replace parts in a safety circuit?

Yes, with the identical part or a manufacturer-confirmed equivalent, recorded against the function. A substitution that changes the component's safety characteristics (a contactor without mirror contacts, a general-purpose relay, an uncoded interlock) silently changes the architecture and voids the PL, even when the machine still appears to stop.

How often must safety functions be tested?

At the interval the manufacturer's manual and the machine's validation define; monthly to annually per function is common in practice. The test must exercise the whole function, including the monitoring, and every test must leave a per-function record with the finding.

Latest from our blog

Define Your Reliability Roadmap
Validate Your Potential ROI: Book a Live Demo
Define Your Reliability Roadmap
By clicking the Accept button, you are giving your consent to the use of cookies when accessing this website and utilizing our services. To learn more about how cookies are used and managed, please refer to our Privacy Policy and Cookies Declaration