top of page

SIL Certification vs SIL Verification: Why a SIL-Certified Device Does Not Guarantee a SIL-Compliant Safety Function

Writer: Isabella Bergström | Senior Consultant
Isabella Bergström | Senior Consultant
7 hours ago
7 min read

In this article:


In the process and other high-risk industries, terms such as Safety Integrity Level (SIL)-certified and SIL-verified are often used interchangeably. However, they represent two distinct activities that address different aspects of functional safety.

 

This misunderstanding can lead to incorrect assumptions during design and ultimately to a non-compliant Safety Instrumented System (SIS) causing delays to projects or insufficient risk reduction during the operating phase. For example, a pressure transmitter may be certified for SIL 3 applications, but that alone does not demonstrate that the Safety Instrumented Function (SIF) in which it is installed will achieve said target. The component needs to be considered in relation to the SIF into which it is integrated, and the SIS integrator needs to ensure that all requirements specified by the manufacturer to achieve the SIL target are addressed.

 

Understanding the distinction between SIL certification and SIL verification is therefore essential for ensuring compliance with IEC 61508 and IEC 61511. This article explains the difference and how the two concepts should be applied in practice.


What is SIL Certification?

SIL Certification is a product-level assessment typically performed by an independent certification body such as TÜV or Exida. The purpose of certification is to demonstrate that a device has been developed in accordance with IEC 61508 and is suitable for use in safety applications up to a specified SIL capability.

 

A SIL certificate typically confirms:

  • Systematic capability (avoidance of systematic failures)

  • Hardware fault tolerance requirements

  • Safe Failure Fraction (SFF)

  • Failure rate data (usually derived from FMEDA or similar assessments)

  • Functional safety management practices applied by the manufacturer

 

In other words, SIL certification demonstrates that a product is capable of being used within a safety function targeting a specific SIL. However, it is important to note that neither IEC 61508 nor IEC 61511 explicitly requires components to be SIL certified. Nevertheless, SIL certification has become common practice because it provides confidence that failure data, systematic capability claims, proof test assumptions and hardware reliability assessments have been reviewed by an independent third party. Without certification, the SIS integrator or end user must perform their own assessment of the manufacturer's documentation and demonstrate that the requirements of IEC 61508 have been fulfilled. For many projects, this can be time-consuming and require significant functional safety expertise. SIL certification therefore reduces the effort required by the SIS integrator, but it does not remove the responsibility for performing SIL verification or ensure that an appropriate functional safety organisation is in place.


SIL certification does not confirm that the complete SIF achieves the SIL target. The SIL certification process focuses on IEC 61508, which is the master functional safety standard. The figure below shows the relationship between IEC 61511, IEC 62061 and IEC 61513 as standards which serve as applications of IEC 61508 to specific industries. This article focuses on process industry applications and therefore on IEC 61511, although the same main principles apply to all three standards.


Figure 1: IEC 61508 and its sector-specific functional safety standards
Figure 1: IEC 61508 and its sector-specific functional safety standards

Lastly, the SIL certification process may not cover all aspects of IEC 61508. It is therefore important to study the SIL certificate carefully and identify the scope of the certification. For example, the systematic capability assessment may be excluded from the certificate, or the failure rates may apply only when certain diagnostics are used or the component is installed in a specific configuration.


What is SIL Verification?

SIL verification is a system-level assessment performed during the design of a SIF. Its purpose is to demonstrate that the complete SIF meets the target SIL determined during a hazard and risk assessment, such as a Layer of Protection Analysis (LOPA).

 

The verification process includes:

  • Quantitative assessment: calculation of the Probability of Failure on Demand (PFD) for low-demand functions and the average frequency of dangerous failure per hour (PFH) for high-demand functions.

  • Architectural assessment: verification that the hardware architecture satisfies the applicable fault tolerance and architectural constraints specified in IEC 61508 and IEC 61511.

  • Systematic capability assessment: review of the manufacturer's development processes, quality management system, configuration control, verification activities and, where applicable, software development practices in accordance with IEC 61508 in order to avoid or limit systematic failures.

 

How should SIL Certificates be handled when designing a SIS

SIL verification is a key activity when designing a SIS (see SIS lifecycle Phase 4 in IEC 61511). ORS suggests the following workflow when performing a SIL verification assessment:

 

  1. Ensure that an SRS is available explaining the requirements of the safety function, e.g., SIL target, diagnostics, safe state, etc.

  2. Gather information about the SIF components from SIL certificates, Safety Manuals, Safety Analysis Report (SAR), data sheets, etc.:

    1. Make and model.

    2. Systematic capability.

    3. Failure rates.

    4. Proof test coverage.

    5. Mission time.

    6. Diagnostic coverage.

    7. Safe Failure Fraction.

  3. Evaluate the information received and compare with industry data to ensure that the failure data used in the calculations are realistic.

  4. Calculate PFD / PFH, Systematic Capability, Architectural Constraints.

  5. Explain all key assumptions.

 

Step 3 is important and often overlooked. During Functional Safety Assessments (FSAs), it is common to find that SIL certificates have been collected for SIS components, but that the assumptions and limitations stated in the certification documentation have not been adequately evaluated.

 

In some cases, the failure data provided by vendors are significantly lower than data reported in industry sources such as PDS or Offshore and Onshore Reliability Data (OREDA). The failure rates stated in SIL certificates are often based on specific assumptions regarding diagnostics, operating conditions, maintenance practices and proof testing, and are therefore generally more optimistic than industry data. The SIS integrator should take a conservative approach and carefully assess how the failure rates were calculated and whether the assumptions applied in the Failure Mode Effect and Diagnostics Analysis (FMEDA) and certification assessment are fulfilled in the actual installation. If the certified failure rates differ significantly from industry data, particularly by one or more orders of magnitude, the applicability of the certified data should be critically reviewed before being used in SIL related calculations.


Common questions and misunderstandings

This transmitter is SIL certified, does it mean it is safer than another transmitter?

Not necessarily. A SIL certificate demonstrates compliance with functional safety requirements, not that the device is inherently safer than all alternatives. The suitability of a transmitter depends on its application, operating environment, proof testing, maintenance, and how it performs within the complete Safety Instrumented Function (SIF).

 

Can I use a non-certified component in a safety function with SIL requirements?

Yes. IEC 61511 does not require SIL-certified components. However, sufficient evidence must be available to demonstrate that the device is suitable for the intended application, and that systematic capability, failure rates, proof testing assumptions and architectural requirements have been adequately addressed. This can be achieved by:

  • Conducting a prior-use assessment in accordance with IEC 61511-1, Clause 11.5.3.

  • Conducting an assessment of systematic capability in accordance with IEC 61511-1, Clause 11.5.2 and the applicable requirements of IEC 61508.

  • Comparing design, diagnostics and proof test procedures with similar components.

  • Applying conservative assumptions where uncertainty exists, for example by using conservative failure rates, reducing assumed proof test coverage, or applying additional uncertainty factors.

 

Systematic capability is not stated on the SIL Certificate but it states “SIL 2 Capable”, what does this mean?

Systematic Capability shall always be stated ad “SC”, if SC is not stated on the certificate and if the certificate does not explicitly state that Systematic Capability has been assessed, it can not be assumed to be covered. Confirm with the manufacturer if there is any Systematic Capability assessment available.


The SIL certificate states higher failure rates than industry data, what should I use?

As the failure rates from the certificate are more conservative and probably more accurate to the component being used, the certificate data should be used.

 

Is a Declaration of Conformity equivalent to a SIL Certificate?

A SIL Certificate is issued by an independent certification body following an assessment of the product and its documentation. A Declaration of Conformity is issued by the manufacturer and represents a self-declaration of compliance with IEC 61508. Both can support SIL verification, but a Declaration of Conformity generally requires more review by the SIS integrator or end user.


Functional safety management and training

Having a SIL verification report showing that the SIS is compliant with the SIL target does not mean that all requirements of IEC 61508 and IEC 61511 have been fulfilled. The standards require much more than collecting SIL certificates and performing calculations.

 

Functional safety management and training are often forgotten and are in the shadow of SIL certificates and PFD calculations.

 

Functional Safety Management (FSM) is a fundamental requirement of both IEC 61508 and IEC 61511. Even when all devices are SIL certified and the SIF has been successfully verified, the required integrity may not be achieved if competence, procedures and management systems are inadequate.

 

Typical FSM activities include, but are not limited to:

  • Competence management and training.

  • Management of change.

  • FSA.)

  • Verification and validation activities.

  • Documentation control.

  • Proof test management.

  • Incident investigation and corrective actions.

 

In many audits and FSAs, shortcomings in functional safety management represent a larger compliance issue than deficiencies in SIL calculations.

 

Conclusion

SIL certification and SIL verification are not competing concepts; they address different levels of functional safety.

 

A SIL certificate demonstrates that a component has been assessed and may be suitable for use in a safety application. SIL verification demonstrates that the complete SIF achieves the required level of risk reduction in its intended application.

 

However, achieving compliance with IEC 61508 and IEC 61511 requires more than collecting SIL certificates and performing calculations. Functional safety relies on understanding the assumptions behind the data, evaluating uncertainties, applying sound engineering judgement, and ensuring that the entire safety lifecycle is managed effectively. The objective of functional safety is not to achieve a particular SIL rating or collect certificates, but to reduce risk to a tolerable level while ensuring that the assumptions made during design remain valid throughout the SIS lifecycle.

 

When working with functional safety, it is therefore important not to focus solely on SIL certificates, but to consider the broader context of the application and where the real uncertainties and opportunities for risk reduction exist. At ORS, we help clients interpret functional safety documentation, challenge assumptions when necessary, and translate compliance requirements into practical, fit-for-purpose solutions. Our goal is not only to solve the immediate problem, but also to strengthen our clients' understanding of functional safety and support long-term compliance throughout the SIS lifecycle.

Image by Thought Catalog

SUBSCRIBE TO RECEIVE OUR NEWS & INSIGHTS

Thanks for submitting!

© 2022 ORS Consulting. All Rights Reserved.

bottom of page