Overview
This technical reference documents the methodology used to evaluate whether a Siemens SIMATIC MP377 multi-panel (catalog number 6AV6644-0AA01-2AX0) can be credited as part of a Safety-Related Part of a Control System (SRP/CS) requiring Performance Level b (PL b) per ISO 13849-1. The application context is an enabling device (deadman handle) used during maintenance on a machine covered by EN 1010-1:2005+A1:2010, where the machine builder must demonstrate that the safety-related parts of the control system providing the restricted-movement function meet at least PL b. The MP377 is a configurable HMI, so the central question is: can a programmable HMI deliver PL b, and what supporting data and calculation are required to justify the claim?
ISO 13849-1 is the successor to EN 954-1 and expresses the achieved safety performance in terms of Performance Level (PL) rather than the older Category-only approach, as explained in the Analog Devices introduction to ISO 13849 and the Keyence PL parameter reference.
The short answer: yes, the MP377 can be credited at PL b, but only as a Category B SRP/CS, because per ISO 13849-1 a programmable device cannot be Category 1. The justification requires (1) the MTBF value published by Siemens for the specific catalog number, (2) conversion to MTTFd, (3) a statement of zero diagnostic coverage, and (4) calculation of PFHd using a tool such as SISTEMA or PAScal. The output for the cited article number is PFHd ≈ 8.78 × 10−6 1/h, which places the subsystem in PL b for a Category B, single-channel, no-diagnostic structure.
The MP377 in a Safety-Related Application Context
The MP377 is a 12-inch widescreen multi-panel HMI from the SIMATIC MP 377 range, used for operator control and visualization on printing, packaging, and converting machinery. Catalog 6AV6644-0AA01-2AX0 identifies a specific configuration with touch screen, WinCC flexible runtime, and the standard set of PROFINET and PROFIBUS interfaces. The MP377 supports a maintenance login (operator plus password) with restricted functions that include selection of the part of the machinery to be moved under an external enabling device. Because the HMI selects the safety-relevant mode of operation, the safety engineer must consider whether the HMI's mode-selection logic contributes to the safety function defined in the machine's risk assessment.
Per EN 1010-1:2005+A1:2010, clause 5.2.6.3.4, when adjustment or setting is performed with guards open and movement is restricted via a hold-to-run control device, an enabling device, or two-hand control, the interlock and safety-related parts of the control system that provide this function shall comply with at least PL b per EN ISO 13849-1:2008, or SIL 1 per EN 62061:2005. The MP377 is therefore a candidate SRP/CS, and its contribution to the safety function must be quantified even though the HMI itself is a general-purpose automation component, not a safety-typed device.
ISO 13849-1 PL Determination Methodology
ISO 13849-1 expresses the achieved safety performance in five Performance Levels (PL a through PL e). PL is determined by independent parameters evaluated for each SRP/CS (subsystem) per the standard's Table 4, then aggregated for the full safety function:
- Category (B, 1, 2, 3, or 4) — describes the structural architecture and resistance to faults
- MTTFd of each channel — classified as Low (3 yr ≤ MTTFd < 10 yr), Medium (10 yr ≤ MTTFd < 30 yr), or High (30 yr ≤ MTTFd ≤ 100 yr); capped at 100 years per channel
- Diagnostic Coverage (DCavg) — classified as None (0%), Low (≥ 60%), Medium (≥ 90%), or High (≥ 99%) per Table 5
- Common Cause Failure (CCF) — checklist against Annex F; score ≥ 65 required for multi-channel Category 2, 3, 4 structures
The graphical PL determination in ISO 13849-1 Figure 5 (the "bar chart") maps Category plus MTTFd band plus DCavg band to a PL. For a Category B, single-channel, MTTFd = Medium, DCavg = None, the achievable PL is b. This is the starting point for the MP377 analysis. The supporting reference for the methodology is the Siemens technical document "Help on the Application of ISO 13849-1", which clarifies the 100-year MTTFd cap per channel and provides worked examples.
PL versus PFHd range per Table 3 of ISO 13849-1:
| PL | PFHd (1/h) | Average probability of dangerous failure per hour |
|---|---|---|
| a | ≥ 10−5 to < 10−4 | Lowest |
| b | ≥ 10−6 to < 10−5 | Low |
| c | ≥ 10−6 to < 10−5 (with Category 1 or 2 structure) | Low / Medium |
| d | ≥ 10−7 to < 10−6 | Medium |
| e | ≥ 10−8 to < 10−7 | High |
PL b sits in the 10−6 to 10−5 1/h PFHd band. The MP377 evaluation must produce a PFHd in that range to claim PL b.
Category Selection for a Programmable HMI
ISO 13849-1 Annex C and Table 4 are explicit: a programmable electronic subsystem cannot claim Category 1 because Category 1 requires the use of "well-tried components with proven safety principles" as the basis for safety, and a programmable device does not satisfy that definition in the strict reading used by certification bodies. The MP377 is a programmable device, so the maximum category that can be credited at the channel level is Category B. Category B requires the SRP/CS to use safety principles that are well-tried at the design level (separation, overcurrent protection, environmental compatibility) but does not require special fault-tolerance.
Category B is the baseline: single-channel, no redundancy, no diagnostic test. The PL achievable from Category B is therefore limited to a, b, or c, depending on MTTFd and any single-fault tolerance that the application environment happens to provide. In practice, Category B with MTTFd in the Medium band and no diagnostic lands on PL b, which is exactly what the maintenance-function application requires.
Key table reference for the five categories:
| Category | Description | PL Range Achievable | Diagnostic Required |
|---|---|---|---|
| B | Basic; well-tried safety principles; single channel; no diagnostic | a, b, c | No |
| 1 | Single channel, well-tried components and principles | c, d (depends) | No |
| 2 | Single channel with diagnostic test; diagnostic must detect dangerous faults | b, c, d | Yes (low/medium) |
| 3 | Dual channel, single-fault tolerant | c, d, e | Yes (low) |
| 4 | Dual channel, single-fault tolerant, fault accumulation considered; high DC required | d, e | Yes (high) |
MTTFd Calculation from Siemens MTBF Data
Siemens publishes MTBF values for many of its automation products in a support entry titled "MTBF values for Siemens automation products." The value for the MP377 article 6AV6644-0AA01-2AX0 is MTBF = 7.1 years. This figure is derived from Siemens-internal reliability prediction per IEC/TR 62380 or SN 29500 and is the standard value used in factory-acceptance MTTF data sheets.
Conversion of MTBF to MTTFd requires two steps:
- Compute the dangerous failure fraction. If the manufacturer publishes separate λs (safe) and λd (dangerous) failure rates, apply those directly. If only MTBF is given, assume 50% of failures are dangerous (a conservative engineering assumption when no failure-mode distribution is published). A 60% dangerous fraction is also commonly used for control panels with mostly output-driven failure modes.
- Compute MTTFd = 1 / λd. A common shorthand when only MTBF is given is MTTF = 2 × MTBF, which yields 2 × 7.1 = 14.2 years for the MP377. This convention treats the device as repairable with MTTR comparable to MTTF, and the dangerous-failure share at 50%.
Per ISO 13849-1, the MTTFd of each channel is limited to 100 years maximum. The 14.2-year figure sits in the Medium band (10 yr ≤ MTTFd < 30 yr). Some tools, including SISTEMA, apply a normalization to the channel MTTFd contribution in the PFHd formula and report the effective MTTFd used in the calculation. In the MP377 evaluation, the tool reported MTTFd limited to 13 years, which is the rounded equivalent of the dangerous-failure rate used in the PFHd figure below.
Worked calculation with the 50% dangerous-failure assumption:
MTBF = 7.1 yr = 7.1 × 8760 h = 62,196 h
λ_total = 1 / MTBF = 1.607 × 10−5 1/h
λd = 0.5 × λ_total = 8.04 × 10−6 1/h
MTTFd = 1 / λd = 1.244 × 10^5 h ≈ 14.2 yr
PFHd (Category B, single channel, no diagnostic) ≈ λd = 8.04 × 10−6 1/h
Worked calculation with the 60% dangerous-failure assumption:
λd = 0.6 × 1.607 × 10−5 = 9.64 × 10−6 1/h
MTTFd = 1 / 9.64 × 10−6 = 1.037 × 10^5 h ≈ 11.8 yr
PFHd ≈ 9.64 × 10−6 1/h
The SISTEMA/PAScal result reported by the original evaluator (PFHd = 8.78 × 10−6 1/h) corresponds to MTTFd ≈ 13 years and confirms the MTTF = 2 × MTBF convention used in the calculation. Engineers reproducing the calculation should verify the failure-mode distribution assumed in their tool of choice and report the assumption explicitly in the safety file.
For comparison, the same evaluation against EN 62061 SIL is also possible. EN 62061 uses PFHd directly, so the same figure (8.78 × 10−6 1/h) maps to SIL 1 per the EN 62061 Table 3 boundary (10−6 ≤ PFHd < 10−5). Both PL b and SIL 1 are satisfied for the maintenance function, which is the dual-citation outcome EN 1010-1 clause 5.2.6.3.4 accepts.
Diagnostic Coverage (DC) and Common Cause Failure (CCF)
The MP377 in the cited configuration has no self-test of the mode-selection logic; therefore, diagnostic coverage is None (0%). The standard requires DCavg to be classified as None, Low (≥ 60%), Medium (≥ 90%), or High (≥ 99%) per Table 5 of ISO 13849-1. With DC = None, the only structure that yields a defensible PL b is Category B with MTTFd in the Medium band.
Engineers can improve DC only by adding external diagnostics — typically a watchdog relay that cycles an MP377 output and verifies the response. The MP377 itself does not support an integrated safety diagnostic suitable for credit. If the application needs DCavg > None, the only practical options are (a) add an external diagnostic test device, or (b) move the safety function to a separate safety relay or safety PLC.
CCF is scored against Annex F of ISO 13849-1 using a checklist of measures (separation, diversity, protection against over-voltage, common supplies, training of designers, etc.). A score of 65 or higher is required for multi-channel structures. For the single-channel MP377, CCF is not required for the PL b claim, but engineers integrating the MP377 into a larger safety function that includes additional channels (e.g., a safety relay in series with the HMI-controlled output) must still score CCF for the multi-channel portion.
CCF checklist summary per ISO 13849-1 Annex F (informative):
| Group | Measure | Points (max) |
|---|---|---|
| Separation / Segregation | Physical separation of channels; routing; shielding | 15 |
| Diversity | Different technology; different components | 20 |
| Design / Experience | Protection against over-voltage, over-temperature, over-current | 15 |
| Competence / Training | Designer competence; training records; safety culture | 10 |
| Environmental | EMC, temperature, humidity, vibration, contamination control | 15 |
| Supply / Power | Independent power supplies; over-voltage protection | 10 |
| Other (Analysis, Testing) | FMEA, fault simulation, field experience | 15 |
| Total required | 65 minimum |
CCF is only applicable to multi-channel architectures. The MP377 standalone PL b evaluation does not require a CCF score, but the safety function that uses the MP377 may require it depending on the other elements in the chain.
PFHd and PL Calculation for MP377 (6AV6644-0AA01-2AX0)
Final subsystem parameters for the MP377 as a standalone SRP/CS in the maintenance-mode-select function:
| Parameter | Value | Source / Note |
|---|---|---|
| Catalog number | 6AV6644-0AA01-2AX0 | Siemens MP377 12" multi-panel |
| MTBF (per Siemens) | 7.1 years | Siemens MTBF support entry, IEC/TR 62380 basis |
| MTTFd (calculated) | 14.2 years (Medium band) | MTTF = 2 × MTBF assumption, 50% dangerous fraction |
| MTTFd (limited, per tool) | 13 years | SISTEMA / PAScal effective value |
| DCavg | None (0%) | No self-test of mode logic |
| Category | B | Programmable device limit per ISO 13849-1 |
| CCF | N/A | Single-channel structure |
| PFHd | 8.78 × 10−6 1/h | SISTEMA / PAScal calculation |
| PL (subsystem) | b | Within PL b PFHd band (10−6 to 10−5 1/h) |
| Required PL (application) | b | EN 1010-1:2005+A1:2010, clause 5.2.6.3.4 |
PL b is achieved. The required PL b for the deadman-handle maintenance function is met. The conclusion is valid for a subsystem where the MP377 alone implements the mode-selection restriction. If the safety function includes other elements (enabling device, contactors, safety relay, output contacts), the PFHd values for those elements must be summed and the overall PL re-evaluated for the full safety function. The supporting reference for the PL-b boundary and the 100-year MTTFd cap is the Siemens "Help on the Application of ISO 13849-1" guide.
SISTEMA and PAScal Tool Workflow
Two tools are widely used in European machine safety to capture the ISO 13849-1 PL calculation: the IFA's SISTEMA (Windows) and the SICK PAScal (web-based). The workflow for capturing the MP377 evaluation in either tool:
- Open the SISTEMA library (or PAScal project). Both tools accept a subsystem block with Category, MTTFd, DCavg, and CCF inputs.
- Set the SRP/CS to Category B.
- Enter the MTTFd value: 14.2 years (or 13 years if the tool's dangerous-failure rate is entered directly).
- Set DCavg to None.
- Skip CCF (single channel).
- Compute. Verify PFHd ≈ 8.78 × 10−6 1/h and PL = b.
- Export the SISTEMA project or PAScal report. Attach the report to the machine's technical file.
Documentation discipline: the SISTEMA/PAScal report, the Siemens MTBF reference, the catalog number, and the version of the standard used (EN ISO 13849-1:2008 or its successor) must be retained as part of the safety-related evidence package required by the Machinery Directive 2006/42/EC. SICK's "Use of standard components for safety functions" white paper provides additional context on MTTF interpretation for non-safety-typed components.
Standards Compliance: EN 1010-1 and EN ISO 13849-1
EN 1010-1:2005+A1:2010 is the safety standard for printing and paper-converting machines. Clause 5.2.6.3.4 is the specific requirement for restricted-movement access via hold-to-run, enabling device, or two-hand control. It explicitly accepts either PL b per EN ISO 13849-1:2008 or SIL 1 per EN 62061:2005 as equivalent. The PL b claim derived above meets the first option; the SIL 1 claim derived from the same PFHd value meets the second option. The machine builder can therefore cite either or both in the technical file.
EN ISO 13849-1:2008 (and its 2015 update) defines the methodology used. For new designs, the 2015 revision is preferred; the methodology is unchanged for the parameters used here (Category, MTTFd, DCavg, PL). Engineers should also reference the official Siemens "Help on the Application of ISO 13849-1" document, which provides worked examples and clarifies the 100-year MTTFd cap per channel.
Verification and Field Validation
After the calculation, verify the result by:
- Cross-checking the MTBF value with the Siemens support entry for the exact catalog number, including any hardware version suffix.
- Confirming the MTTF-to-MTTFd conversion factor and the dangerous-failure fraction assumed for the specific tool.
- Re-running the calculation in a second tool (e.g., SISTEMA plus PAScal) to detect tool-specific normalization artifacts.
- Confirming the standard version used in the report (EN ISO 13849-1:2008 vs 2015).
- Validating that the maintenance-mode login and mode-selection logic are implemented exactly as documented in the safety-related specification, and that any firmware update to the MP377 triggers a re-evaluation of the MTTF data.
- Reviewing the safety function end-to-end: enabling device input → MP377 mode authorization → downstream safety relay → contactors. The PFHd of the full chain must satisfy the PL b target.
- Verifying that the SIL 1 boundary per EN 62061 is also met (PFHd between 10−6 and 10−5 1/h), which is the alternative citation in EN 1010-1.
Limitations and Alternative Approaches
The MP377-as-SRP/CS analysis is constrained by the structural limits of a programmable HMI. If the machine's risk assessment demands PL d or PL e for the maintenance function, the MP377 cannot be the primary safety element. The alternatives are:
- Use a dedicated, certified safety HMI (e.g., SIMATIC HMI KTP Mobile F, F-CPU panels, or third-party safety HMIs) that publishes safety-relevant data and supports PROFIsafe. The safety HMI is then treated as a Category 3 or 4 structure with two channels and a published PFHd in the PL d/e range.
- Restrict the MP377 to a non-safety role (operator interface only) and place the safety function on a separate SRP/CS such as a safety relay, safety PLC, or hardwired enabling circuit. The MP377 then contributes to the function but is not in the safety chain. The hardwired circuit achieves Category 1 or 3 with MTTFd in the High band.
- Add an external diagnostic test that exercises the MP377 output contacts at a defined rate, increasing DCavg from None to Low or Medium, but this requires additional wiring and does not change the Category ceiling for a programmable device.
None of these alternatives is required for the cited EN 1010-1 PL b application; the MP377 standalone is sufficient. The alternatives become necessary when the risk assessment requires PL d or higher, or when the safety function is required to continue to operate safely in the presence of a single hardware fault in the HMI (which a Category B single-channel subsystem cannot guarantee).
Commissioning Checklist for the MP377 Maintenance Function
- Confirm the catalog number on the installed panel matches the one used in the calculation: 6AV6644-0AA01-2AX0. A different catalog number invalidates the MTBF input.
- Record the firmware version of the MP377 in the safety file. Pin the version in the project so that any update is intentional and triggers re-evaluation.
- Verify the maintenance login: confirm the password policy, the operator-rights matrix, and the audit log for login events.
- Verify the mode-selection logic: each selectable part of the machinery must be explicitly authorized, and an unselected part must not move under the enabling device. Functional test every selectable part.
- Verify the downstream interface: confirm the MP377 output that releases the maintenance function to the safety relay is wired through a safety-rated output, not a standard output. If the interface is a standard output, the safety function ends at the MP377 and the downstream elements are not safety-rated.
- Run the deadman-handle functional test: with the maintenance login active, the selected part must move only while the enabling device is held in the active position. Release of the enabling device must stop the motion within the stop time required by the risk assessment.
- Document the SISTEMA/PAScal report and attach it to the technical file along with the EN 1010-1 risk-assessment worksheet.
- Train the operators on the maintenance login procedure and the limit of the maintenance function. Maintain training records as part of the safety evidence package.
FAQ
Can a Siemens MP377 meet PL b per ISO 13849-1 in a maintenance-mode function?
Yes. Using the Siemens-published MTBF of 7.1 years for catalog 6AV6644-0AA01-2AX0, the calculated MTTFd is approximately 14.2 years. With Category B, DCavg = None, and a single-channel structure, the PFHd is approximately 8.78 × 10−6 1/h, which places the subsystem at PL b. The MP377 cannot exceed PL b on its own because a programmable device cannot claim Category 1 per ISO 13849-1.
Why is the MTTF reported as twice the MTBF for the MP377?
The convention MTTF = 2 × MTBF treats the MP377 as a non-redundant electronic device with MTTR comparable to MTTF, and assumes a 50% dangerous-failure fraction when only MTBF is published. The result (14.2 years) sits in the Medium MTTFd band (10–30 years) per ISO 13849-1 Table 4. If Siemens publishes a separate λd, use that figure directly instead of the 2× conversion.
Does CCF scoring apply to the MP377 as a single-channel SRP/CS?
No. Common Cause Failure (CCF) scoring against Annex F of ISO 13849-1 applies to multi-channel structures (Category 2, 3, 4). A single-channel Category B subsystem is exempt, and the 65-point threshold is not evaluated for the MP377 alone. CCF must still be scored for any multi-channel portion of the full safety function that includes the MP377.
What is the difference between MTTF, MTBF, and MTTFd?
MTTF (Mean Time To Failure) applies to non-repairable components. MTBF (Mean Time Between Failures) applies to repairable systems and equals MTTF + MTTR. MTTFd is the mean time to dangerous failure per channel; it is the safety-relevant subset of the total failure rate and is the figure used in ISO 13849-1 PL determination. All three are limited to 100 years per channel in ISO 13849-1. The Siemens "Help on the Application of ISO 13849-1" guide clarifies the conversion.
Can a firmware update to the MP377 change the PL claim?
Yes. Any firmware change that alters the mode-selection logic, the diagnostic behavior, or the failure mode distribution invalidates the MTTF data and requires a re-evaluation. Document the firmware version in the safety file and re-run the SISTEMA or PAScal calculation when the MP377 firmware is updated. The same applies to a hardware revision change of the MP377 itself.