中文官网
STANDARDS · 2026-05-20 · ~10-min read

Performance Level (PL) vs SIL — How ISO 13849 and IEC 62061 Actually Decide Your Safety Rating

PL a to PL e. SIL 1 to SIL 3. Two scales, two standards, one underlying question — how reliably does the safety function reduce risk? Here is what the letters mean and where engineers most often get them wrong.

PL e safety standard documentation for an industrial machine safety function
The rating on the box is a component capability — not the rating of your function.

Consider this illustrative question: “The light curtain is rated PL e; does that make the protective-stop function PL e?” No component label answers the complete-function question. For the relationship between risk assessment, reliability and protective-device installation, use the machine-safety standards guide; this article focuses on PL and SIL verification.

This article explains what PL and SIL actually are, what inputs decide them, how the two scales relate, and the handful of mistakes that cause real functions to come in below the level their designers assumed. It is not a substitute for the standards themselves or for a competent safety engineer — but it should let you read a safety calculation without taking anything on faith.

Two standards, one question

A safety function — “when the light curtain is broken, the machine stops” — has to be reliable. Both major machinery standards exist to quantify that reliability so it stops being a matter of opinion.

ISO 13849-1 gives you the Performance Level, written PL a through PL e. PL e is the highest. This is the standard most machine builders reach for first, because its method is approachable and there is good software tooling for it.

IEC 62061 gives you the Safety Integrity Level, written SIL 1 through SIL 3 in the machinery context. It is the machine-sector application of IEC 61508, the broad functional-safety standard that also underpins the process industries. IEC 62061 addresses SIL 1–3; SIL 4 belongs to the broader IEC 61508 framework.

PFHd provides a numerical comparison, not full interchangeability. Both machinery methods use dangerous-failure-rate bands for high/continuous-demand functions, alongside architectural and systematic requirements. A matching band cannot replace the other evidence needed for a PL or SIL claim.

How the two scales line up

Performance Level (ISO 13849-1)SIL (IEC 62061)PFHd — dangerous failures per hour
PL a—≥10⁻⁵ to <10⁻⁴
PL bSIL 1 band≥3×10⁻⁶ to <10⁻⁵
PL cSIL 1 band≥10⁻⁶ to <3×10⁻⁶
PL dSIL 2 band≥10⁻⁷ to <10⁻⁶
PL eSIL 3 band≥10⁻⁸ to <10⁻⁷

The table uses a lower-inclusive, upper-exclusive interval for each band. PL b and PL c subdivide the SIL 1 band, so not every adjacent PL step is a factor of ten. Compare actual PFHd values and integration limits; two labels alone do not show that one particular function is exactly ten times more reliable than another.

What actually determines the Performance Level

Under ISO 13849-1, the PL of a subsystem is not a single number you look up. It is built from several inputs:

The simplified category/MTTFd/DC method has conditions that must be satisfied. Review common-cause measures, software and systematic faults, test assumptions and validation as well as the quantitative result. Use an edition-matched tool; the ISO 13849-1:2023 transition checklist covers review of an existing project.

DAIDISIKE DA31 safety relay module — the logic stage of a safety function
The logic stage — here a safety relay — is one of three subsystems whose ratings combine.

A worked example — and the mistake hiding in it

Take a simple safety function: a light curtain guards a robot cell; when a beam is broken, the robot stops. The chain has three subsystems.

A single unmonitored contactor cannot be assigned a PL merely from that description. Its data and architecture may be inadequate for the required function. Two suitable contactors with correctly implemented feedback can form part of a higher-integrity output design, but reliability, diagnostics, common-cause measures, fault conditions and validation still have to be established. Adding a second contactor is not automatic PL e.

The takeaway: A safety function is rated as a chain — input, logic, output. The achieved PL is limited by the weakest subsystem and by how the subsystem PFHd values sum. Each subsystem must meet the required integration conditions; the complete function still needs verification and validation.

How much PL do you actually need?

The required PL is not a free choice — it comes from the risk assessment. ISO 13849-1 provides a risk graph that takes three parameters: the severity of the potential injury (reversible or irreversible), the frequency and duration of exposure to the hazard, and the possibility of avoiding the hazard once it occurs. Feed those in and the graph returns a required PL — the PLr — for that function.

In the ISO risk-graph method, the relevant severe-injury, frequent-exposure and difficult-avoidance combination can lead to PLr e. Record why each parameter was selected and check the applicable machine-specific standard. A robot cell, press or low-energy label alone does not fix every safety function's target. Select a design that meets the justified requirement and can be maintained and validated.

ISO 13849-1 or IEC 62061 — which one?

ISO 13849-1 is a practical option when the design and component data fit its methods, including designated architectures and manufacturer subsystem data. The choice should be made in the safety requirements specification, with the relevant machine standard and available validation evidence, not simply because a device carries a PL label.

IEC 62061 covers design, integration and validation of machinery safety-related control systems, including non-electrical technologies. The IEC catalogue now lists IEC 62061:2021 with Amendments 1:2024 and 2:2026. It does not itself cover designing complex programmable electronic subsystems. Use the selected edition's rules when integrating PL- or SIL-assessed subsystems; avoid both arbitrary formula mixing and the incorrect claim that cross-standard subsystem integration is always prohibited.

Common mistakes

Reading the component label as the function rating. Covered above, and worth repeating because it is that common. PL e on a curtain box is a capability, not a result.

Skipping the CCF checklist. Two channels that share a power supply, a cable route, or an environmental weakness can fail together. CCF scoring exists to catch that. A calculation that shows Category 3 architecture but never scores CCF is incomplete.

Forgetting the output stage. Engineers lavish attention on the sensor and the logic and then wire the result to a single unmonitored contactor. The output is a full subsystem and needs its own treatment — usually two monitored contactors with EDM feedback. Our light curtain and safety relay wiring guide shows the EDM loop in practice.

Ignoring response time. The PL tells you how reliably the function works; it says nothing about howfast. Those are separate requirements. A perfectly PL e function still injures someone if it is mounted closer than the ISO 13855 safety distance allows. Reliability and timing are both mandatory — see our ISO 13855 safety-distance guide.

Where DAIDISIKE products sit

For a DQA light curtain or DA31 relay, request the exact model's safety manual and reliability data before assigning a subsystem capability. Do not assume DA31 has EDM or a particular reset mode without its manual. The engineering team can help identify product documentation; the integrator remains responsible for the function-level assessment.

The bottom line

Use PL/SIL bands to understand the reliability target, then evaluate the actual safety function under the selected method. Check subsystem integration, quantitative and qualitative measures, response time and validation. A function-level claim requires that evidence; it is not obtained by relabelling a component rating.

Primary references

ISO 13849-1:2023 defines the PL design framework. The current IEC 62061 consolidated edition identifies its machinery scope and amendments. OMRON safety-control guidance explains control reliability concepts and their application limits. Consult the complete applicable standard for a compliance assessment.

Related reading

ISO 13855 Safety Distance — Practical Guide

Reliability is PL; timing is ISO 13855. You need both.

Type 2 vs Type 4 Light Curtains

How ESPE Type and documented PL/SIL capability differ.

Light Curtain & Safety Relay Wiring Guide

Output-stage feedback and safety integration conditions.

Machine Safety on EV Battery Lines

A station-by-station guarding guide where these ratings get applied.

DAIDISIKE DA31 Safety Relay

Verify model-specific safety data, reset and feedback functions in the manual.

DAIDISIKE DQA Series

Model-specific light-curtain documentation for input-subsystem selection.

Content updated:

Frequently asked questions

What is the difference between Performance Level (PL) and SIL?

PL a–e comes from ISO 13849-1; machinery SIL 1–3 comes from IEC 62061. Their high/continuous-demand dangerous-failure-rate bands can be compared, but each method also requires architectural, systematic, software and validation evidence. Similar PFHd bands do not automatically establish conformity to the other standard.

How do PL and SIL map onto each other?

PL b/c lie within the SIL 1 high/continuous-demand PFHd band, PL d within SIL 2 and PL e within SIL 3. PL a has no corresponding IEC 62061 SIL band. This is a numerical comparison, not an automatic conversion of a component certificate or complete safety function. IEC 62061 covers machinery SIL 1–3, not SIL 4.

Which standard should I use, ISO 13849-1 or IEC 62061?

Select the method that fits the safety-function specification, subsystem evidence, technologies and applicable machine standard. IEC 62061 is not limited to electrical technology. A function can incorporate subsystems evaluated using another recognised method where the selected standard's integration rules are satisfied; do not mix formulas or claim equivalence solely from a label.

What inputs determine the Performance Level under ISO 13849-1?

Relevant inputs include architecture, MTTFd, diagnostic coverage, common-cause measures and category-specific test conditions, together with systematic measures, software and validation. The simplified chart is not the complete assessment. A CCF score documents implemented risk-reduction measures; it does not prove that a common cause is impossible.

Does a Type 4 / PL e light curtain make my safety function PL e?

No. A documented PL e input capability is only part of the evidence. Verify the complete input–logic–output function, subsystem limits, PFHd contributions, diagnostics and integration conditions, then validate it. Neither a Type 4 light curtain nor two contactors plus a feedback loop automatically establishes PL e.

What is PFHd and why does it matter?

PFHd expresses the average dangerous-failure probability per hour in the applicable high/continuous-demand assessment. PL e/SIL 3 share the band at least 10⁻⁸ and below 10⁻⁷ per hour; PL d/SIL 2 share at least 10⁻⁷ and below 10⁻⁶. For eligible series-connected subsystems, use the selected standard's combination rules and actual PFHd data. Do not equate these bands with low-demand PFDavg.

About DAIDISIKE: Foshan DAIDISIKE Optoelectronics Technology Co., Ltd. supplies industrial safety and sensing products. Ratings vary by exact model; no family-wide Type 4, PL e or SIL 3 claim is made here. Request documented capabilities through our engineering team or browse the safety light curtain range.

Share this pageEmailWhatsAppLinkedIn

Leave your message