How Can ISO 13849 Safety Circuits Protect Your Pneumatic Systems from Critical Failures?

Apply ISO 13849 to pneumatic safety functions using PLr, Category, MTTFd, DCavg, CCF, SISTEMA, and validation without confusing safety exhaust with LOTO.

Share
David Li, Chief Advisor for Bepto Pneumatic technical review

About the author

David Li

Chief Advisor

Hello, I'm David, a Bepto Pneumatic chief advisor. I help teams review compressed-air safety, system reliability, and practical product decisions before quotation.

Author articlesDavid@bepto.com

ISO 13849 protects a pneumatic machine when its safety-related control system detects a hazardous condition, commands a defined safe response, tolerates the faults required by its architecture, and is verified and validated against a risk-based target. It does not prescribe one universal “ISO 13849 circuit,” and a safety-rated valve alone does not make a machine compliant.

For a pneumatic axis, the required response may be to exhaust pressure, hold a load, prevent unexpected extension, return to a safe position, or combine several measures. The correct choice comes from the hazard analysis. Venting a vertical cylinder, for example, can create rather than remove a falling-load hazard.

Key Takeaways

  • Define each safety function and its safe state before choosing valves or sensors.
  • Determine the required Performance Level, PLr, from the machine risk assessment and any applicable type-C standard.
  • Category, MTTFd, DCavg, CCF, systematic measures, software, and subsystem interfaces all affect the achieved PL.
  • Use manufacturer reliability data for the exact component and operating conditions; do not substitute generic B10D values.
  • SISTEMA supports calculation and documentation, but it does not perform the risk assessment or validate the machine.
  • Safety exhaust, load holding, and lockout/tagout solve different problems.

Field Note from David Li

In our experience reviewing pneumatic safety concepts with integrators, the most common starting error is choosing the valve before defining the safe state. I start with three questions: What movement or stored energy can harm someone? What physical state removes that risk? What test will prove the machine reaches that state after a relevant fault?

I have found that these questions expose missing load-holding, trapped-pressure, and restart requirements before they become installation changes. If the team cannot answer all three, ordering a “PL e valve” is premature. The component label cannot repair an undefined safety function.

What ISO 13849 Applies to in a Pneumatic Machine

ISO 13849-1:2023 provides a methodology for designing and integrating safety-related parts of control systems, or SRP/CS, in high-demand and continuous modes. It is technology-neutral: electrical, hydraulic, pneumatic, mechanical, and software elements can all form part of the same safety function.

The standard does not assign a safety function or PLr to a particular machine. It also does not say every pneumatic application needs Category 3, Category 4, dual valves, diverse sensors, or PL d. Those decisions depend on the risk assessment, the required risk reduction, the chosen architecture, and any machine-specific standard.

The terminology matters because several different concepts are often collapsed into the word “rating.” A safety function is a specified machine response that reduces one identified risk. PLr is the required Performance Level for that function. The achieved PL is the result demonstrated by the complete safety-related control design; it is not copied from one component certificate.

Term What it means What it does not mean
Safety function A defined control-system action that reduces a specific risk A general promise that the machine is safe
PLr The required Performance Level for one safety function The PL already achieved by the design
PL The achieved performance of the complete safety-related control function A label inherited automatically from one component
Category The fault-tolerance and diagnostic behavior of a designated architecture A complete reliability calculation
MTTFd Mean time to dangerous failure used for channels or subsystems Expected service life or proof-test interval
DCavg Average diagnostic coverage for dangerous failures The percentage of every possible fault that will be detected
CCF Measures against common-cause failure in multi-channel systems Proof that two channels are independent under all conditions
SIL A functional-safety integrity measure used by standards such as IEC 62061 Another name for ISO 13849 Category 3 or Category 4

ISO 13849 uses Performance Levels from a through e. IEC 62061 uses SIL values. Some products declare suitability under both standards, but the methods and terminology should not be mixed when documenting the machine.

Step 1: Define the Safety Function and Safe State

ISO 12100:2010 provides the machinery risk-assessment and risk-reduction framework that precedes control-system design. Identify the task, exposed person, hazard, hazardous event, operating mode, severity, exposure, and possibility of avoiding harm. Apply inherently safe design and guards before relying on control-system measures.

A useful safety-function specification is measurable. “Stop the cylinder safely” is too vague. A better specification identifies:

  • Trigger: guard opening, light-curtain interruption, emergency-stop actuation, loss of feedback, or another defined event.
  • Hazard: crushing, shearing, impact, ejection, falling load, trapped pressure, or unexpected restart.
  • Required response: remove drive pressure, prevent extension, stop and hold, move to a safe position, or another defined action.
  • Safe-state criteria: maximum allowed movement, pressure threshold, force, speed, stopping time, or position.
  • Reset behavior: who may reset, where the reset device is located, and whether reset may initiate motion.
  • Operating modes: automatic, setup, cleaning, fault recovery, and maintenance may need different protective measures.
  • PLr: the risk-based target for that individual safety function.

Consider a guarded horizontal rodless-cylinder transfer. One safety function might be: “When the access guard opens during automatic operation, prevent further hazardous carriage movement and prevent automatic restart until the guard is closed and a deliberate reset is completed.” The specification must still define the acceptable travel after the demand and how the output stage achieves it.

The same machine may need a separate emergency-stop function, safe pressure-release function, and prevention-of-unexpected-start function. They can have different boundaries and different PLr values.

Step 2: Determine PLr Without Treating the Risk Graph as a Calculation of PL

The ISO 13849 risk graph considers severity of injury, frequency or duration of exposure, and possibility of avoiding or limiting harm. Its result is the required Performance Level, PLr, for the safety function. It does not calculate the PL achieved by the hardware and software.

Use the graph only after defining the hazard and safety function. Record why each S, F, and P parameter was selected. Check whether an applicable type-C machinery standard specifies the function or performance requirement more directly. Do not assign PL d merely because a pneumatic cylinder is large, and do not assume “most pneumatic machines” require PL c or PL d.

The risk assessment should also state the assumptions that affect avoidance and exposure: actuator speed, access frequency, visibility, escape space, operator training, load, and whether the hazard can arise without warning. If any assumption changes, reassess the PLr.

Step 3: Design the Complete Input–Logic–Output Architecture

Model the whole safety function, not just the pneumatic valve:

ISO 13849 engineering chain from risk assessment and PLr through input, logic, pneumatic output, machine response, and validation.

The calculation covers the safety-related control chain, while validation confirms the installed machine response and fault behavior.

  1. Input: guard switch, light curtain, two-hand control, emergency-stop device, pressure switch, or position sensor.
  2. Logic: safety relay, configurable safety controller, or safety PLC, including the safety-related application software.
  3. Output: contactors, monitored pneumatic valves, braking or holding devices, and any feedback required to confirm their state.
  4. Machine response: pressure, force, speed, position, and residual movement at the actual hazard.

The designated Categories describe how faults affect the safety function:

Category Simplified architectural behavior
B Basic safety principles are applied; a fault can lead to loss of the safety function.
1 Well-tried components and safety principles improve reliability, but a fault can still cause loss.
2 The function is checked at suitable intervals; a fault can remain dangerous between checks.
3 A single fault does not cause loss of the safety function; some faults are detected, but an accumulation of undetected faults can cause loss.
4 A single fault does not cause loss, and fault detection or resistance to fault accumulation maintains the safety function as required by the architecture.

This table is a design orientation, not a category-selection shortcut. Achieving PL requires the quantitative and qualitative conditions associated with the chosen Category. A Category 3 drawing with two similar channels is not automatically PL d.

Choose the Pneumatic Safe State from the Hazard

The final pneumatic elements must produce the state defined in the safety-function specification. Common strategies include:

  • Blocking supply and exhausting a hazardous zone
  • Preventing pressure from reaching the extend port
  • Holding an axis with a validated brake or rod lock
  • Returning an actuator under controlled conditions
  • Isolating one branch while retaining pressure in another safety-relevant circuit
  • Combining pneumatic action with mechanical restraint

There is no universal requirement for a 5/2 or 5/3 safety valve. A monitored redundant 3/2 exhaust valve may suit a safe-exhaust function, while a vertical load may require an independent load-holding measure. Read how to integrate safety exhaust valves into machine guarding for valve placement, pressure-decay testing, and downstream-volume considerations.

If loss of air can release a load, evaluate vertical-cylinder load holding and pneumatic check-valve limitations. A pilot-operated check valve can prevent motion while trapping pressure that remains hazardous during service.

Step 4: Quantify Reliability with Component-Specific Data

For wear-dependent pneumatic and electromechanical components, manufacturers commonly provide a B10D value: the number of cycles at which 10% of a population is expected to have failed dangerously under stated conditions. The annual operation count, n_op, converts cycle data into MTTFd:

Annual operations: n_op = (d_op × h_op × 3,600) / t_cycle

Mean time to dangerous failure: MTTF_d = B10D / (0.1 × n_op)

Here, d_op is operating days per year, h_op is operating hours per day, and t_cycle is the mean time in seconds between successive operations of the component. Use the component’s real safety-function demand or switching profile, not the machine’s fastest theoretical cycle unless that is genuinely the operating case.

Do not copy a generic 10-million- or 20-million-cycle value into the calculation. Obtain data for the exact part number, pressure range, air quality, temperature, switching frequency, load, permitted silencer, and maintenance conditions. If the supplier provides PFHd, subsystem PL, or a SISTEMA library instead, confirm the assumptions and integration constraints before using it.

Collect at least the following evidence:

Data Why it matters Typical evidence
B10D or PFHd Quantifies dangerous failure behavior Manufacturer safety manual or declaration
Operating cycles Converts cycle-based data to time-based reliability PLC count, production study, and foreseeable test demands
Mission time Limits how long the calculation remains valid Safety plan and maintenance records
Category Defines architectural fault behavior Circuit design and subsystem documentation
DCavg Credits effective diagnostics Diagnostic method, detectable failure modes, and test intervals
CCF measures Addresses a single cause defeating multiple channels Design review against the applicable CCF criteria
Environmental limits Keeps reliability assumptions valid Air-quality, temperature, vibration, EMC, and installation records
Systematic measures Controls design, software, integration, and maintenance errors Development and verification records

Diagnostic Coverage Must Match Real Failure Modes

Pressure and position sensing can improve diagnostics, but adding a sensor does not automatically create 90% DC. Define which dangerous valve, sensor, wiring, logic, and pneumatic failures the diagnostic detects; when it detects them; and what the system does next.

Examples include valve-spool or poppet position monitoring, downstream-pressure plausibility, channel discrepancy timing, test pulses, and checking the expected actuator state. A pressure switch mounted upstream of the isolation valve cannot prove that a trapped downstream cavity has exhausted.

CCF Is More Than Physical Separation

Multi-channel systems need measures against failures that can defeat both channels. Channel separation can help, but common supply air, contaminated air, excessive temperature, vibration, incorrect maintenance, shared connectors, software errors, and identical installation damage can still affect both channels.

Use the standard’s CCF evaluation method and document the measures actually implemented. Diverse sensor technologies may be useful in some designs, but diversity is not a universal requirement and does not eliminate the need for systematic design controls.

Step 5: Verify the Achieved PL in SISTEMA

IFA’s SISTEMA software models safety functions using designated architectures and evaluates PL from parameters including Category, MTTFd, DCavg, and CCF. Use SISTEMA 3.x for work based on ISO 13849-1:2023; IFA states that each major SISTEMA version is tied to a specific revision of the standard.

A disciplined project structure follows the safety requirements:

  1. Create one SISTEMA safety function for each defined machine safety function.
  2. Enter its PLr and document the risk-assessment reference.
  3. Divide the function into input, logic, and output subsystems.
  4. Import current manufacturer libraries only after checking their version and use conditions.
  5. Enter the machine-specific switching frequency, diagnostics, and mission time.
  6. Resolve warnings and verify that the achieved PL meets or exceeds PLr.
  7. Export the report and place it under configuration control with the schematics and software revision.

SISTEMA is an evaluation tool, not a certificate generator. A green result cannot detect incorrect plumbing, a blocked exhaust, wrong cycle data, an unmodeled gravity hazard, or software that does not match the calculation.

Step 6: Validate the Installed Safety Function

The currently published validation standard is ISO 13849-2:2012. A replacement is under development as ISO/DIS 13849-2, but a draft should not be cited as if it were the current published edition. Validation uses analysis and testing to show that the safety functions, architecture, fault behavior, and achieved PL meet the specification.

Plan validation before commissioning. An independent or sufficiently independent competent person should be able to trace each test back to a requirement. Record the machine mode, product and load, supply pressure, temperature, software checksum, valve and sensor revisions, measuring equipment, acceptance criteria, actual result, and any deviation.

Validation test What to observe
Demand each input channel Safety outputs switch and the machine reaches the specified safe state
Open or short one channel where applicable The fault is detected and the required fault reaction occurs
Prevent one output valve element from changing state Redundancy and feedback behave as designed
Restrict the permitted exhaust path to the credible limit Pressure and motion remain within validated acceptance criteria
Test minimum and maximum supply pressure Timing and final state remain acceptable
Use worst-case cylinder position and load Travel, stopping time, and load behavior remain within limits
Interrupt and restore power or air No hazardous automatic restart occurs
Create feedback discrepancies The controller inhibits the next hazardous cycle as specified
Operate reset controls Reset clears the safety state but does not itself initiate hazardous movement

Time-correlate the safety demand, logic output, valve feedback, downstream pressure, and hazardous motion. A valve’s catalogue switching time is not the machine stopping time. Tubing volume, valve flow, silencers, flow controls, cylinder load, and mechanical inertia all affect the installed response.

Inspection and functional-test intervals must come from the component instructions, risk assessment, operating environment, use frequency, diagnostic design, and applicable machinery standard. ISO 13849 does not impose a generic “monthly for PL e, annual for PL c” schedule.

Safety Exhaust and Lockout/Tagout Are Different Controls

A pneumatic air-preparation assembly with a red-handled lockable supply valve, filter, regulator, and lubricator.

A lockable manual air-supply valve can support an energy-isolation procedure. Its presence does not establish the PL of an automatic safety function.

OSHA 29 CFR 1910.147 addresses hazardous-energy control during covered servicing and maintenance. It defines pneumatic energy as an energy source and requires isolation, lockout or tagout, control of stored or residual energy, and verification of isolation.

A safety relay de-energizing a solenoid valve is normally a control-system action. It is not automatically an energy-isolating device. For covered service work, the procedure may require a manually operated and lockable supply valve, individual locks, bleeding or restraint of stored energy, verification at the point of work, and continued control of any pressure that can reaccumulate.

Keep the documentation boundaries clear:

Situation Primary protection
Guard opens during production Validated safety-related control function
Emergency-stop demand Defined emergency-stop response and related risk-reduction measures
Fault recovery without entering a hazard zone Mode-specific safety function and restart prevention
Maintenance with exposure to unexpected energization Hazardous-energy control procedure and verified isolation
Work beneath a suspended pneumatic load Isolation plus independent mechanical restraint

What to Request from a Pneumatic Safety-Component Supplier

Do not issue an RFQ that asks only for an “ISO 13849 valve.” State the safety function and request the data needed by the integrator:

  • Exact product and revision covered by the documentation
  • Declared safety function and applicable standards
  • Maximum Category, PL or SIL capability and the required architecture
  • B10D, PFHd, mission time, and permitted switching frequency
  • Diagnostic mechanism, feedback timing, and fault reaction
  • Required safety-controller outputs, pulse-test limits, and reset behavior
  • Pressure, temperature, air-quality, vibration, and EMC limits
  • Exhaust-flow data and approved silencers or accessories
  • Restrictions on series or parallel valve arrangements
  • Safety manual, SISTEMA library, declarations, and third-party certificates where applicable
  • Maintenance, replacement, and proof-test instructions

A product described as “PL e capable” can only contribute that capability when installed within its stated limits and integrated into a complete safety function that meets the same target.

Common ISO 13849 Pneumatic Design Errors

  • Selecting a dual valve before defining the safe state
  • Treating PLr from the risk graph as the achieved PL
  • Using Category as a substitute for the full PL evaluation
  • Copying generic B10D values from unrelated valves or actuators
  • Crediting a sensor without mapping the dangerous failures it detects
  • Ignoring shared air contamination as a common-cause mechanism
  • Measuring pressure at the valve while hazardous pressure remains trapped at the actuator
  • Assuming exhaust always makes vertical or spring-loaded mechanisms safe
  • Using a catalogue switching time as the machine stopping time
  • Letting reset or air restoration initiate hazardous movement
  • Substituting a standard spare part without reassessing the safety function
  • Treating a safety exhaust valve as a replacement for verified lockout/tagout
  • Calling a SISTEMA report “machine certification” without installed validation

FAQs About ISO 13849 Pneumatic Safety Circuits

Does ISO 13849 require every pneumatic safety circuit to use two channels?

No. The risk assessment determines PLr, and the design must use an architecture capable of meeting that target. Some safety functions can use lower Categories; higher fault-tolerance requirements may need multi-channel architecture.

Is Category 3 the same as PL d?

No. Category 3 is an architectural characteristic. The achieved PL also depends on MTTFd, DCavg, CCF measures, systematic requirements, and correct subsystem integration. Category 3 can support certain Performance Levels only when all relevant conditions are satisfied.

Can a valve certified for PL e make the complete machine PL e?

No. The valve is one subsystem. Inputs, logic, output integration, diagnostics, software, interfaces, and the physical machine response must all satisfy the safety-function requirements and be validated.

Must a pneumatic emergency stop always dump all machine air?

No. The risk assessment defines the required safe state. Full exhaust may be appropriate for one zone but dangerous for a suspended load, clamp, vacuum gripper, or spring-loaded mechanism. Emergency stopping also does not replace the energy isolation required for covered maintenance.

Does SISTEMA prove that the pneumatic machine is safe?

No. SISTEMA evaluates the modeled safety-related control architecture. It cannot confirm that the physical installation matches the model or that pressure, motion, restart, and fault responses meet the specification. Those points require validation on the installed machine.

How often should the safety circuit be tested?

There is no universal interval based only on PL. Establish inspection and functional-test intervals from the component safety manuals, risk assessment, operating environment, diagnostic design, usage, maintenance history, and applicable machine-specific standards.

Conclusion

ISO 13849 protects pneumatic machinery through a documented chain of engineering decisions: define the hazard and safety function, determine PLr, select an appropriate architecture, quantify reliability with valid component data, verify the achieved PL, and validate the installed response under normal and fault conditions.

The most important question is not “Which valve is ISO 13849 compliant?” It is “What must this machine do when the safety function is demanded, and what evidence proves it will still do so when a credible fault occurs?” Answer that question first, and valve selection becomes one controlled part of a defensible safety design.

Sources

Related