IEC 62061 is an international standard published by the International Electrotechnical Commission that specifies requirements for the design, integration, and validation of safety-related electrical, electronic, and programmable electronic control systems (SRECS) for machinery. It defines a risk-based framework for achieving Safety Integrity Levels (SIL 1–3) in machinery safety applications, covering the entire safety lifecycle from hazard identification through to decommissioning. The standard is sector-specific machinery application of the generic IEC 61508 functional safety framework, harmonised under the EU Machinery Directive and its successor the EU Machinery Regulation. It provides quantitative methods for calculating Probability of Dangerous Failure per Hour (PFH) and Diagnostic Coverage (DC) for hardware and software subsystems.

Overview

  • IEC 62061 was first published in 2005 and has been revised (edition 2, 2021) to align with IEC 61508 edition 2 and with the convergence effort alongside ISO 13849.
  • The standard applies specifically to machinery control systems combining electrical, electronic, and programmable electronic technologies, addressing both hardware and software aspects.
  • It is applicable throughout a machine’s operational life, covering design, commissioning, operation, maintenance, and decommissioning phases.
  • The 2021 edition introduced clarified guidance on Diagnostic Coverage calculation, updated Hardware Fault Tolerance requirements, and better alignment with the parallel route standard ISO 13849.
  • Compliance with IEC 62061 provides a presumption of conformity to the Essential Health and Safety Requirements of the EU Machinery Directive for the electrical control system aspects.
  • The standard is mandatory in practical terms for machinery sold into the European Economic Area that contains complex programmable safety logic.
  • It is adopted by national standards bodies including BSI (BS EN IEC 62061), DIN, and ANSI/UL, making it globally applicable.

Key Components

  • Safety Lifecycle
    • IEC 62061 mandates a structured Safety Lifecycle encompassing: scope definition, Hazard and Risk Assessment, safety requirements allocation, design and realisation, and verification/validation.
    • The lifecycle is iterative — changes at any stage trigger re-assessment of dependent phases.
  • Safety Integrity Level (SIL)
    • The standard defines three SIL levels (SIL 1, SIL 2, SIL 3) for machinery, each corresponding to a target range of Probability of Failure on Demand (PFHd) for the overall Safety Function.
    • SIL determination is driven by Risk Assessment using parameters: severity of harm, frequency of exposure, probability of avoiding harm, and probability of occurrence.
  • SRECS Architecture
    • A Safety-Related Control System under IEC 62061 is decomposed into subsystems, each characterised by:
      • PFHd (Probability of Dangerous Failure per Hour) for continuous demand mode.
      • Hardware Fault Tolerance (HFT) — the number of faults a subsystem can tolerate while maintaining the safety function.
      • Diagnostic Coverage (DC) — the fraction of dangerous failures detected by on-board diagnostics.
      • Safe Failure Fraction (SFF) — proportion of failures that are either safe or detected dangerous failures.
  • Hardware Assessment
    • IEC 62061 uses a quantitative approach: aggregate PFHd values from individual subsystem PFHd values to derive the total Safety Function PFHd.
    • Annex K provides a simplified approach for subsystems with well-characterised failure rate data.
    • Common Cause Failure (CCF) must be evaluated and mitigated, particularly in redundant architectures.
  • Software Requirements
    • Software in the SRECS must comply with additional software safety requirements defined in IEC 62061 Part 1 and related IEC 61508-3 guidance.
    • Software Safety Integrity Levels (SSIL) are assigned based on the SIL of the safety function the software supports.
    • Requirements include: formal specification, structured design, Verification and Validation, configuration management, and use of appropriate programming languages and tools.
  • Verification and Validation
  • Documentation
    • A Safety Requirements Specification (SRS) is a mandatory output, documenting all Safety Functions, their SIL, and the allocated subsystem requirements.
    • The overall safety manual for each subsystem (from component suppliers) is a required input to the system-level assessment.

Applications and Use Cases

  • Industrial Robots and Collaborative Robots
    • Industrial Robot cells frequently contain SRECS governed by IEC 62061, particularly safety-rated monitored stop, speed and separation monitoring, and power and force limiting functions in Collaborative Robot (cobot) applications.
  • Press and Stamping Machinery
    • Safety functions for guard interlocking, two-hand control, and light curtain interfaces on metal-working presses are typically designed to IEC 62061 SIL 2 or SIL 3 due to high-severity injury potential.
  • Packaging and Food Processing Machinery
  • Automated Guided Vehicles (AGVs) and Mobile Platforms
    • Increasingly, Autonomous Mobile Robot platforms used in warehouses apply IEC 62061 for the safety-related navigation and collision avoidance subsystems where the machinery regulation applies.
  • Wind Turbines and Energy Machinery
    • Wind Turbine control systems use IEC 62061 alongside IEC 61400 for the safety-critical pitch control and emergency shutdown functions.
  • Construction and Earthmoving Machinery
    • OEMs apply IEC 62061 to electronic control systems governing stability monitoring, overload protection, and operator presence sensing.
  • Machine Tool Industry
    • CNC machining centres rely on SIL 2 Safety-Related Control Systems per IEC 62061 for spindle safe-stop, door interlock monitoring, and axis safe-speed functions.

Standards and Context

  • Parent Standard: IEC 61508
    • IEC 62061 is a sector-specific application standard derived from IEC 61508, which provides the generic framework for Functional Safety of electrical/electronic/programmable electronic safety-related systems. IEC 62061 inherits the SIL concept and safety lifecycle structure from IEC 61508.
  • Parallel Standard: ISO 13849
    • ISO 13849 (Safety of Machinery — Safety-Related Parts of Control Systems) provides an alternative route using Performance Level (PL a–e) and Category (B, 1–4) concepts, derived from reliability block diagrams. Engineers may choose either standard (or a combination) to demonstrate compliance with the Machinery Directive. IEC 62061 is preferred for complex programmable electronic systems, while ISO 13849 is often preferred for simpler electromechanical systems.
  • Process Industry Analogue: IEC 61511
    • IEC 61511 applies the same SIL framework to Safety Instrumented Systems in the process industries (oil, gas, chemical). It shares the SIL structure with IEC 62061 but addresses a different sector and different architectural constraints.
  • Cybersecurity Intersection: IEC 62443
    • IEC 62443 addresses Industrial Cybersecurity for industrial automation and control systems. As programmable safety systems become networked, the intersection of IEC 62061 safety requirements and IEC 62443 security requirements is an active area of standards development, particularly regarding the impact of cybersecurity threats on Safety Integrity Level achievement.
  • Risk Assessment Basis: ISO 12100
    • ISO 12100 (Safety of Machinery — General Principles for Design) provides the overarching Risk Assessment methodology that feeds into IEC 62061’s SIL determination process. It defines the iterative risk reduction process that IEC 62061 implements for the control system layer.
  • Regulatory Alignment
    • In the European Union, IEC 62061 (adopted as EN IEC 62061) is a harmonised standard under the Machinery Directive 2006/42/EC and its successor the Machinery Regulation (EU) 2023/1230, effective from 2027. Compliance provides presumption of conformity for the relevant Essential Health and Safety Requirements.
    • In the UK post-Brexit, the equivalent BS EN IEC 62061 remains the applicable standard under the UK Machinery Directive (retained EU law).
    • In North America, UL and CSA have adopted aligned standards, and IEC 62061 is increasingly accepted by OSHA and by machine builders for North American market machinery.
  • Certification and Assessment Bodies
    • TÜV Rheinland, TÜV SÜD, Pilz, and Bureau Veritas are major third-party certification bodies providing Functional Safety assessments against IEC 62061.
    • Many component and subsystem suppliers (e.g. safety relay manufacturers, safety PLC vendors) provide SIL-certified subsystems with validated PFHd data sheets, simplifying the system integrator’s IEC 62061 assessment.

Provenance