IEC 61508 and IEC 61511 are the twin pillars of functional safety. Understanding the relationship between them — and which applies to your work — is the starting point for any safety instrumented system project. Confusing the two is common and leads to misapplied requirements, incorrect SIL claims, and expensive rework.
IEC 61508: The Parent Standard
IEC 61508 is the generic functional safety standard for Electrical/Electronic/Programmable Electronic (E/E/PE) safety-related systems. It was published by the IEC (International Electrotechnical Commission) and applies to any industry and any application type — from automotive airbag controllers to railway signalling systems to nuclear plant protection systems.
IEC 61508 defines the foundational concepts used by all downstream functional safety standards:
- Safety Integrity Levels (SIL 1 through SIL 4) and their quantitative targets (PFDavg for demand mode, PFH for continuous mode)
- The generic safety lifecycle (concept, overall scope definition, hazard and risk analysis, safety requirements allocation, design, implementation, installation and commissioning, validation, operation and maintenance, decommissioning)
- Requirements for developing safety-related E/E/PE systems, including software development processes
- Hardware architectural constraints (hardware fault tolerance, safe failure fraction)
IEC 61508 is primarily used by equipment manufacturers who need to assess and certify the SIL capability of their products — sensors, logic solvers (safety PLCs), final elements. When a vendor provides a TUV-certified SIL certificate for a transmitter, that certificate was granted based on a design assessment conducted to IEC 61508.
IEC 61511: The Process Industry Standard
IEC 61511 is the sector-specific standard derived from IEC 61508 for the process industry (oil and gas, chemical, pharmaceutical, pulp and paper, power generation). It was developed by the ISA (International Society of Automation) and is also published as ISA-84 in North America.
IEC 61511 is used by end users and engineering contractors to design, implement, and maintain Safety Instrumented Systems (SIS) in process facilities. It uses the SIL concepts from IEC 61508 but adds process-specific guidance for:
- Conducting HAZOP and Layer of Protection Analysis (LOPA) to determine required risk reduction
- Writing a Safety Requirements Specification (SRS) for each Safety Instrumented Function (SIF)
- SIL verification calculations using failure data from 61508-certified components
- Proof testing procedures and intervals to maintain the SIF at its required SIL
- Management of Functional Safety throughout the lifecycle
- Competency requirements for personnel involved in safety lifecycle activities
The Relationship Between the Two Standards
Think of IEC 61508 as the rulebook that governs how safety equipment is designed and certified, and IEC 61511 as the rulebook that governs how that certified equipment is applied in a process plant SIS.
The critical distinction is that IEC 61511 Clause 11 (see “prior use” exemption) allows end users to use components that have demonstrated “prior use” in similar applications, even if those components do not have a formal IEC 61508 SIL certificate. This is important for legacy equipment and components from vendors who have not pursued formal certification.
IEC 61508 does not have a prior use provision. It requires systematic assessment to demonstrate SIL capability.
SIL Levels: What They Mean in Practice
SIL is a measure of the required reliability of a safety function. For demand-mode SIFs (the most common type in process plants):
- SIL 1: PFDavg between 0.1 and 0.01 (RRF 10 to 100). Applies to functions where the consequence of failure is significant but the hazardous event frequency is low or other layers of protection exist.
- SIL 2: PFDavg between 0.01 and 0.001 (RRF 100 to 1,000). Common for functions protecting against severe injury, fatality, or major environmental release.
- SIL 3: PFDavg between 0.001 and 0.0001 (RRF 1,000 to 10,000). Required for functions protecting against catastrophic multi-fatality events or major community impact. Significantly harder to achieve — typically requires redundant sensors, logic solver, and final elements.
- SIL 4: Only defined in IEC 61508 for non-process industries (nuclear, railway). IEC 61511 does not define SIL 4 applications in the process industry.
Who Uses Each Standard
In a typical SIS project, multiple parties use these standards simultaneously:
- Equipment supplier (sensor manufacturer, safety PLC vendor, valve positioner supplier): Designs to IEC 61508. Provides SIL certificates with lambda_D, lambda_DU, SFF, DC, and HFT data.
- End user / owner-operator: Designs and operates the SIS to IEC 61511. Uses LOPA to determine SIL targets. Uses the supplier SIL certificates as inputs to SIL verification calculations.
- EPC contractor: Typically applies IEC 61511 on behalf of the owner, following the owner’s functional safety management system.
- TUV assessor (independent third party): Audits the functional safety management system and validates that the SIS meets its safety requirements, referencing both IEC 61508 and IEC 61511 as applicable.
Common Misconceptions
- “A SIL 2 certified transmitter makes a SIL 2 SIF”: False. A SIL 2-capable transmitter means the transmitter alone can contribute to a SIL 2 SIF in an appropriate architecture. The complete SIF PFDavg must be verified using the IEC 61511 SIL verification calculation, which combines sensor, logic solver, and final element failure rates.
- “IEC 61508 applies to my SIS design project”: If you are the owner-operator or EPC contractor designing an SIS for a process plant, IEC 61511 applies to you. You use 61508-certified components in your design, but your design process follows 61511.
- “We are using TUV-certified components, so we do not need to do SIL verification”: Component certification (61508) and system SIL verification (61511) are separate activities. Certification tells you the component’s SIL capability. Verification tells you whether your complete SIF architecture meets the required SIL target.
Competency Requirements
Both IEC 61508 and IEC 61511 include clauses requiring that persons performing functional safety activities have appropriate education, training, and experience. The TUV Functional Safety Engineer (FSEng) certification is the most recognised credential in the process industry, covering both standards. CFSE (Certified Functional Safety Expert) through ISA is the North American equivalent. Engineers responsible for SIL verification, safety requirements specification writing, or SIS proof test procedure development should have formal functional safety training.


