IEC 61508: Functional Safety of E/E/PE Systems
Build the standard from the ground up: the risk gap that sizes a SIL, the lifecycle that attacks systematic failure, the arithmetic that prices random failure, and the honest comparison with ISO 26262.
- Chapters
- 13
- Chapters
- Parts decoded
- 7
- Parts decoded
- Lifecycle phases
- 16
- Lifecycle phases
- SIL levels
- 4
- SIL levels
- 01Why IEC 61508 Exists
- 02Risk, the EUC and the Safety Function
- 03The Safety Lifecycle
- 04SIL: Four Levels, Three Modes
- 05Getting to the Required SIL
Why it pays for itself
Read a SIL claim without being misled
A SIL belongs to a safety function, not to a device. The guide takes apart what a certificate actually asserts, what the safety manual conditions bind you to, and what your loop still owes, which is where most integration money is lost.
Know exactly what crosses into ISO 26262
Chapter 12 works the boundary properly: failure-mode analysis, failure-rate data, diagnostic descriptions and verification records can support an automotive argument after reinterpretation, while the SIL claim and its demand-mode assumptions never transfer.
See where the numbers really come from
Proof test intervals, proof test coverage and the common cause factor move a result more than another redundant channel does. The quantitative chapters make those levers explicit so you can spot an optimistic calculation before an assessor does.
What you’ll be able to do
Derive a SIL Instead of Choosing One
Run the risk gap from EUC risk and a recorded tolerable risk down to a required failure measure, and recognize the backwards determination the moment someone starts from the hardware.
Use the Right Table Every Time
Classify a function by demand profile, apply PFDavg or PFH accordingly, and refuse the comparisons that quietly mix a probability with a rate.
Read Architecture and Arithmetic Together
Treat hardware fault tolerance and safe failure fraction as ceilings on a claim, keep the quantitative analysis as a separate obligation, and apply the weakest link rule across the whole chain.
Separate the Two Failure Species
Know which problems yield to redundancy, diagnostics and proof tests, and which yield only to lifecycle rigor, diversity and systematic capability evidence.
Interrogate a Supplier Certificate
Start from the safety manual conditions, check the route and failure data behind the headline, and list what your installation still owes before any claim holds.
Bridge Into ISO 26262 Honestly
Identify what evidence from a 61508 assessment can support an automotive argument after reinterpretation, and state clearly why the SIL claim itself never transfers.
Chapter by chapter
- 01
Why IEC 61508 Exists
The public accidents that showed careful engineers and reliable components are not enough, what functional safety actually means as a slice of overall safety, an honest guide to the seven parts, and the standard's status as a basic safety publication.
- Accidents and standardisation milestones
- Passive vs active protection
- Which part to read, and when
- 02
Risk, the EUC and the Safety Function
The three roles the standard casts and why the protection is deliberately not the control system, tolerable risk as a recorded decision rather than a physical constant, and the subtraction that turns a risk gap into a required failure measure.
- EUC, control system, safety-related system
- Tolerable risk and the ALARP structure
- The two halves of a safety function
- 03
The Safety Lifecycle
Why systematic failures force a lifecycle rather than a component specification, the sixteen phases as a working reference, the four management instruments an assessor samples first, and documentation as the argument itself.
- Where incidents are really born
- Verification vs validation vs assessment
- Hazard log, requirements spec, safety manual
- 04
SIL: Four Levels, Three Modes
What a SIL claims and what it never claims, the two target tables with their different physical units, the demand mode boundary that decides which table applies, and the three misreadings that produce most SIL nonsense in real projects.
- PFDavg and PFH as different quantities
- Low, high and continuous mode
- Functions have SILs, devices do not
- 05
Getting to the Required SIL
The methods for measuring the risk gap on a real project: the quantitative route and its honesty requirement, the risk graph and why calibration is mandatory before use, layer of protection analysis and the independence discipline that makes it real.
- Quantitative route, risk graph, LOPA
- Credit inflation and independence
- The one determination direction that is always wrong
- 06
The Architectural Constraints
Why a ceiling sits on top of the arithmetic, hardware fault tolerance and what each voting arrangement really buys, the safe failure fraction and its inflation problem, type A and type B elements, and the two routes to an architectural claim.
- HFT and voting trade-offs
- SFF, and how it can rise dishonestly
- Route 1H, Route 2H and the weakest link
- 07
Quantifying Random Hardware Failures
The failure rate splits every later number consumes, the sawtooth that proof testing resets and imperfect test coverage never does, how the architecture formulas rank redundancy, and why the common cause factor usually owns the result.
- Safe, dangerous, detected, undetected
- Proof test interval and coverage
- Where the failure rates come from
- 08
Systematic Failures and Systematic Capability
The failure species with no rate: why identical redundancy multiplies nothing against a shared design error, the two fronts of avoidance and control, what SC 1 to SC 4 claim, and the three routes to earning that claim.
- Random vs systematic, side by side
- Avoidance and control measures
- Proven in use and its evidence bar
- 09
Software Safety: Part 3
Software has no failure rate, so Part 3 replaces probability with process, techniques and evidence scaled by SIL: the software lifecycle and its two-way traceability, how technique recommendations climb, tool classification by failure path, and reused code.
- No lambda for code
- Technique rigor by SIL
- Tool classes and the software safety manual
- 10
The Safety Loop End to End
Reassembling the function, because nothing you can buy carries the claim. Everything in the demand path counts, a real loop walked as hardware rather than blocks, what a certified element gives you and what it leaves entirely to the integrator.
- The loop is the unit of the claim
- Certificate vs safety manual
- De-energize to trip and its price
- 11
Worked Example: High-Pressure Protection
One overpressure protection loop taken through the whole page: a target inherited from the risk analysis, a first attempt that fails for two independent reasons, a redesign that passes, and what stretching the maintenance calendar does to the margin.
- Target first, hardware second
- Where the budget actually goes
- Proof testing as a safety parameter
- 12
Certification and the Standards Family
What a certificate is and is not, the sector standards that reuse the framework and what each one changes, and the ISO 26262 comparison done properly, including exactly what a 61508-certified part transfers into an automotive argument.
- Reading a certificate backwards
- The sector family in one table
- Why ASIL D does not equal SIL 3
- 13
Pitfalls, Myths and a Decision Guide
The recurring mistakes assessors meet every year, the four choices every project has to make deliberately rather than by habit, and the questions that open most functional safety assessments.
- The myth wall
- Four project decisions
- The assessor's first questions
Who this guide is for
- Automotive safety engineers evaluating a 61508-certified MCU, watchdog, power device or software element
- Suppliers who must serve several sectors from one functional safety argument
- Engineers moving between process, machinery, rail or drives work and road vehicles
- Safety managers who need to answer SIL questions from customers and auditors precisely
- Anyone who has been told that ASIL D equals SIL 3 and needs the accurate answer
Frequently Asked Questions
Common questions about IEC 61508: Functional Safety of E/E/PE Systems
Start the course today
A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month. The Pro and Expert plans unlock more of the 77-guide library. No credit card required.