SIL Calculation with PFD and PFH for Siemens S7 F-CPU Safety

David Krause14 min read
Safety SystemsSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

SIL Calculation with PFD and PFH for Siemens S7 F-CPU Safety Systems

1. Overview

Safety Integrity Level (SIL) verification of a SIMATIC S7 F-system requires quantitative proof that the average Probability of Failure on Demand (PFDavg) or the average Probability of Failure per Hour (PFHavg) of the Safety Instrumented Function (SIF) falls inside the target band defined by IEC 61508-1 for the demanded SIL. The calculation must combine:

  • The dangerous undetected failure rate (λDU) and dangerous detected failure rate (λDD) of every F-CPU, F-I/O, sensor, and final element that participates in the function.
  • The diagnostic coverage (DC) of each subsystem, as proven in the manufacturer's FMEDA report.
  • The common cause failure (CCF) factor β for the chosen channel architecture.
  • The proof test interval (Tproof) for low-demand mode or the dangerous exposure time for high-demand/continuous mode.

Siemens publishes the SIL/PFD/PFH values for every F-CPU (CPU 315F-2 PN/DP, CPU 317F-2 PN/DP, CPU 319F-3 PN/DP, CPU 416F-2, CPU 416F-3 PN/DP, CPU 417F-4 PN/DP) and for every F-module (ET 200S, ET 200SP, ET 200MP, ET 200pro) in the relevant product manuals and the TÜV-certified SIMATIC Safety – Integrated Safety Application Note. A working source for these values is the Siemens Industry Online Support portal, entry ID 27832836 ("PFD and PFH values for SIMATIC F-modules").

Reference frame: IEC 61508-1 defines SIL 1 to SIL 4 with the target bands in the next section. The S7 F-system is certified by TÜV Süd / TÜV Rheinland up to SIL 3 (PFDavg ≤ 10⁻³ and PFHavg ≤ 10⁻⁷). S7-300F and S7-400F are designed for use in SIL 2 / SIL 3 applications; SIL 4 is not supported in the SIMATIC product line and must be implemented with a different safety controller.

2. SIL Target Bands per IEC 61508-1

Select the appropriate target band based on the demand rate of the SIF. The same SIL can be reached in either PFDavg or PFHavg depending on whether the SIF operates in low-demand (≤ 1 demand/year) or high-demand/continuous mode.

SIL Low-demand PFDavg target High-demand / continuous PFHavg target (1/h)
SIL 1 ≥ 10⁻² to < 10⁻¹ ≥ 10⁻⁶ to < 10⁻⁵
SIL 2 ≥ 10⁻³ to < 10⁻² ≥ 10⁻⁷ to < 10⁻⁶
SIL 3 ≥ 10⁻⁴ to < 10⁻³ ≥ 10⁻⁸ to < 10⁻⁷
SIL 4 ≥ 10⁻⁵ to < 10⁻⁴ ≥ 10⁻⁹ to < 10⁻⁸

If the SIF runs in mixed mode, calculate both metrics and use the stricter of the two as the binding value.

3. PFD / PFH Architecture Formulas

Each voting architecture in IEC 61508-6 gives a closed-form PFD/PFH expression. The most common architectures for S7 F-CPU SIFs are summarized below. Use T = Tproof for low-demand PFD calculations, and assume a Mean Time To Restoration (MTTR) of 8 h for high-demand PFH if a shorter value cannot be justified.

Simplified PFDavg expressions (low-demand mode)
Architecture PFDavg Typical use
1oo1 (λDU × T)/2 Single F-DI/F-DO channel, basic safety functions
1oo2 (1 − β)² × (λDU × T)² / 3 + β × λDU × T / 2 Two channels, trip on first – highest availability
2oo2 2 × (1 − β)² × (λDU × T)² / 3 + β × λDU × T Two channels, trip on second – best for spurious suppression
2oo3 6 × (1 − β)² × (λDU × T)² / 3 + β × λDU × T Triple-modular redundant, fire & gas, burner management

For high-demand mode, the analogous PFH expressions replace (λDU × T)/2 with λDU directly, and the squared terms reduce to (1 − β) × λDU for the cross-failure component. The full tables are in IEC 61508-6, Annex B.

4. Subsystem Combination Rules

Total PFDavg,tot of a SIF is the sum of the PFDavg of the sensor subsystem, the logic subsystem, and the final element subsystem, because the failures are independent (separated by barriers, different physical locations, different power feeds):

PFDavg,tot = PFDavg,Sensor + PFDavg,Logic + PFDavg,FinalElement

The 100-1 rule (IEC 61511-1 §11.5) allocates at least 1 % and at most 35 % of the total PFDavg budget to any single subsystem. When the SIF mixes 1oo1 and 1oo2 sub-channels, compute the per-channel PFD first, then combine with the CCF beta factor for the redundant part.

For an F-CPU logic subsystem, use the manufacturer-published value for the CPU plus the F-DI/F-DO combination:

PFDavg,Logic = PFDCPU + PFDF−DI + PFDF−DO

5. Siemens F-CPU and F-Module Portfolio

Confirm the firmware/F-toolkit version because the SIL-conformant PFD/PFH values are only valid when the F-CPU runs the correct F-library and the F-modules are configured per the certified parameter sets. Match the version pair below.

F-Controller family Typical F-CPU part numbers Certified F-toolkit
S7-300F 6ES7 315-6TH13-0AB0, 6ES7 317-6TH13-0AB0, 6ES7 318-3FL01-0AB0 Distributed Safety V5.4 SP5 / S7 F Systems RT License
S7-400F 6ES7 416-3FR05-0AB0, 6ES7 416-3ES06-0AB0, 6ES7 417-4XT05-0AB0 S7 F Systems V6.2 or V6.4 add-on for STEP 7 V5.6
ET 200SP F 6ES7 136-6BA00-0CA0 (F-DI 8x24V DC HF), 6ES7 136-6BD00-0CA0 (F-DI 16), 6ES7 136-6DC00-0CA0 (F-DO 8x24V DC/2A), 6ES7 136-6PA00-0CA0 (F-AI 4xI 0(4)-20mA HF), 6ES7 136-6TB00-0CA0 (F-AO 2xI 0(4)-20mA HF) S7 F Systems V6.4 in TIA Portal V16 or later
ET 200S F 6ES7 138-4FA00-0AB0, 6ES7 138-4FB00-0AB0, 6ES7 138-4FC00-0AB0 Distributed Safety V5.4 SP5

For each part number, Siemens provides an individual FMEDA-based PFH/PFD value, plus safe failure fraction (SFF) and DC numbers in the product manual. The TÜV certificate number (e.g., Z10 09 03 10089 002 for S7-300F) is printed in the manual cover page and must be referenced in the verification report.

Firmware pairing rule: Mixing a V5.4 Distributed Safety library with a V6.4 S7 F Systems project invalidates the SIL certification. Verify that the F-CPU, the F-library, and the engineering tool (STEP 7 V5.6 vs. TIA Portal V16/17/18) are all on the matching certified versions before drawing PFD/PFH values from the manual.

6. Where to Obtain Manufacturer PFD/PFH Values

Siemens maintains a consolidated list of PFD/PFH values for all certified F-modules in the SIMATIC Safety Application Note, available through Siemens Industry Online Support (search term "PFD PFH SIMATIC Safety"). The same values are also embedded in the Safety Evaluation Tool (SET), which is a TÜV-certified calculation spreadsheet.

Two procedures are accepted in a TÜV report:

  1. Direct quotation from the manufacturer manual: cite the manual edition, the table number, and the page. For S7-400F, the values are in the manual "SIMATIC S7-400F and S7-400FH – Safety Engineering" (entry ID 12405836 in Siemens support).
  2. Calculation with the Safety Evaluation Tool: open the SET project, import the PFD/PFH of each module, and export the calculation as a PDF signed with the TÜV stamp. The exported PDF is treated as primary evidence by certification auditors.

7. Safety Evaluation Tool Workflow

The Safety Evaluation Tool (SET) is the TÜV-certified spreadsheet shipped by Siemens for the verification of safety functions built with SIMATIC F-modules. Recommended sequence:

  1. Open a new SIF project and enter the SIL target (e.g., SIL 2, PFDavg ≤ 10⁻², PFHavg ≤ 10⁻⁶).
  2. Insert the sensor subsystem. Choose the architecture (1oo1, 1oo2, 2oo2, 2oo3). Enter the sensor λDU, DC, and Tproof. For Siemens F-DI modules, the values are auto-filled from the module catalog.
  3. Insert the logic subsystem. Pick the F-CPU from the catalog; pick the F-DI and F-DO modules. The tool automatically sums the PFD/PFH of all logic components.
  4. Insert the final element (valve, contactor, drive). Enter its λDU, β, and Tproof.
  5. Apply the 100-1 rule check. The tool highlights any subsystem that exceeds 35 % of the SIL budget.
  6. Export the calculation as PDF and append the F-configuration printout, the F-signature, and the TIA / STEP 7 hardware configuration.

8. Handling Non-Failsafe Analog Outputs

As of the current SIMATIC portfolio, several F-analog input modules exist (e.g., ET 200SP F-AI 4xI 0(4)-20mA HF, 6ES7 136-6PA00-0CA0), but the catalog of F-analog outputs is more limited. If a SIF must drive a 4–20 mA control valve from an S7 F-CPU, two architectures are accepted by TÜV:

  1. Standard analog output plus downstream safety relay: A standard 6ES7 135-4GB01-0AB0 (SM 332 AO 8) generates the setpoint; a downstream hard-wired safety relay (e.g., 3SK1 SIRIUS or 3RK3 MSS) performs the shutdown. The standard AO is not part of the SIF; only the safety relay and the wiring carry the SIL PFD budget.
  2. F-DO pulse-width + external I/P converter: An F-DO 6ES7 136-6DC00-0CA0 generates a pulse-width signal; a current-to-pressure converter or a positioner with safety certificate handles the SIL function. The F-DO enters the PFD budget; the converter enters as the final element.
Do not include a non-safety analog output (e.g., SM 332, ET 200SP AQ) inside the SIF PFD sum. Doing so voids the TÜV certificate because the FMEDA for that module was not performed for IEC 61508 safety use.

9. Risk Graph and LOPA for Target SIL Determination

Before the PFD/PFH calculation, the required SIL must be derived from a risk assessment. The two methods accepted by IEC 61511 are:

  • Risk graph – A semi-quantitative matrix (consequence severity C, exposure frequency F, possibility of avoidance A, probability of occurrence W) that yields the required SIL directly. The four-parameter variant in IEC 61511-1 §8.2.2 is the most common.
  • Layer of Protection Analysis (LOPA) – A quantitative method that counts independent protection layers (IPLs) against a target tolerable frequency. The remaining gap between process risk and tolerable risk defines the required SIL of the SIF.

For a SIL 2 target with a tolerable event frequency of 10⁻⁶ per year, a process frequency of 10⁻² per year, and two independent IPLs each credited with a 10× reduction, the SIF must deliver a PFDavg between 10⁻³ and 10⁻². The 100-1 rule then splits the 10⁻³ budget between sensor, logic, and final element.

Detailed LOPA and risk-graph worksheets are in the ABB technical paper "SIL methodology – a methodology for SIL verification" (document 9AKK1074920701), which also covers the use of fault-tree analysis for SIL selection. Cross-reference the ABB document when the SIF overlaps both process and machine safety (IEC 61511 + IEC 62061).

10. Worked Example: SIL 2 SIF with S7-300F

Target: SIL 2 in low-demand mode, Tproof = 5 years (43 800 h).

Subsystems:

  • Sensor: 1oo2 pressure transmitter, λDU = 2 × 10⁻⁷ /h, β = 5 %.
  • Logic: CPU 315F-2 PN/DP (6ES7 315-6TH13-0AB0) with SM 326F-DI (6ES7 326-1BK02-0AB0) and SM 326F-DO (6ES7 326-2BF01-0AB0). From the manual, PFDCPU+DI+DO = 6.0 × 10⁻⁵.
  • Final element: 1oo2 solenoid valve, λDU = 5 × 10⁻⁷ /h, β = 5 %, Tproof = 5 years.

Step 1 – Sensor PFDavg (1oo2, T = 43 800 h):

PFDSensor = (1 − 0.05)² × (2×10⁻⁷ × 43 800)² / 3 + 0.05 × (2×10⁻⁷ × 43 800) / 2

≈ 1.36 × 10⁻⁴ + 2.19 × 10⁻³ ≈ 2.32 × 10⁻³

Step 2 – Logic PFDavg (from Siemens manual):

PFDLogic = 6.0 × 10⁻⁵

Step 3 – Final element PFDavg (1oo2):

PFDFE = (1 − 0.05)² × (5×10⁻⁷ × 43 800)² / 3 + 0.05 × (5×10⁻⁷ × 43 800) / 2

≈ 8.5 × 10⁻⁴ + 5.5 × 10⁻³ ≈ 6.35 × 10⁻³

Step 4 – Total:

PFDtot = 2.32×10⁻³ + 6.0×10⁻⁵ + 6.35×10⁻³ = 8.73 × 10⁻³

Step 5 – Compare to SIL 2 band (10⁻³ to 10⁻²): 8.73 × 10⁻³ is inside the band, but the final element is at 73 % of the budget and violates the 100-1 rule. Tighter solutions:

  • Shorten Tproof on the valve to 2 years, which drops PFDFE to ≈ 2.5 × 10⁻³.
  • Switch the sensor from 1oo2 to 2oo2 with annual proof test, dropping PFDSensor below 5 × 10⁻⁴.
  • Add an external safety relay as a fourth IPL (LOPA credit, not SIF credit).

11. Diagnostic Coverage and CCF Considerations

Diagnostic coverage is the fraction of dangerous failures detected by automatic diagnostics. S7 F-CPUs self-diagnose the CPU, the F-bus (PROFIsafe), and the F-module-internal logic; this yields DC ≥ 90 % for most logic faults. Sensor and final element DC must be calculated from the FMEDA, with values of 60 %–90 % typical for solenoid valves and 70 %–95 % for certified pressure transmitters.

Common cause failure β is non-zero for redundant channels. The IEC 61508 default is β = 10 %; Siemens accepts β = 5 % for F-DI/DO on PROFIsafe with diversified routing and TÜV-checked separation. Document the CCF scorecard (separation, diversity, training, environment) in the verification report per IEC 61508-2 Annex E.

12. Verification, Documentation, and Audit

  1. Generate the Safety Evaluation Tool PDF and attach the TÜV certificate number of the F-CPU family.
  2. Cross-check the TIA / STEP 7 hardware configuration: F-CPU part number, F-library version, F-block signature (F_CRASH, F_STOP, F_FDBACK, F_TIME logic block family for ET 200SP F).
  3. Attach the field wiring drawing showing 24 V supply separation, shield grounding at one end, and channel-by-channel labeling per IEC 61508-2.
  4. Capture the F-signature (CSE:CRC over the F-block DB) and archive it for 20 years – the value must match the design-basis number stored in the F-CPU.
  5. Record the proof test interval and schedule the next proof test in the CMMS.
  6. For TÜV submission, also include the FMEDA excerpt and the IEC 62061 "Practical Application" example document (Siemens support entry ID 23996473) where machine safety is involved.
PFH vs. PFD: For SIFs in continuous service (e.g., burner management, robot speed monitoring), the verification MUST be performed with the PFH formulas, not PFD. The IEC 61508 high-demand/continuous band is roughly 1 000× stricter per hour than the low-demand per-year band, and a logic subsystem that passes the PFD check can fail the PFH check because the F-CPU λDU is expressed per hour.

13. Common Pitfalls

Symptom Root cause Correction
PFD calculation passes but TÜV rejects the report F-library version on the CPU does not match the manual cited Recompile the safety program with the certified F-toolkit; document the version in the cover page
Final element PFD > 35 % of budget 100-1 rule violated; single solenoid with Tproof = 10 y Reduce Tproof to 2 y or move to 1oo2 architecture
CCF score too low (auditor flags β = 10 %) Diversity and training not documented Add the IEC 61508-2 Annex E checklist with each score ≥ 5/10
Standard AO inside the SIF sum Misreading the catalog (SM 332 is not failsafe) Route the AO through an external safety relay or 3SK1 safety output
PFDavg marginally out of band Wrong Tproof used; actual valve never tested Align the PFD calculation with the maintenance plan

14. Reference Documents and Standards

  • IEC 61508 (parts 1–7): Functional safety of E/E/PE systems – the basis for SIL bands and architectural constraints.
  • IEC 61511 (parts 1–3): Functional safety – Safety Instrumented Systems for the process industry sector.
  • IEC 62061: Functional safety of safety-related control systems for machinery – used together with EN ISO 13849-1.
  • Siemens Industry Online Support – SIMATIC Safety manuals and entry ID 27832836 (PFD/PFH values) and 23996473 (IEC 62061 example with S7 Distributed Safety).
  • ABB technical paper "SIL methodology – a methodology for SIL verification" (document 9AKK1074920701), covering LOPA, fault tree, and risk graph selection of the required SIL.

How do I find the certified PFD/PFH of a Siemens F-CPU?

Open the SIMATIC Safety application note on Siemens Industry Online Support (entry ID 27832836) and locate the table for your F-CPU part number; the value is given for a Tproof of 10 years and for a Tproof of 20 years. Always cross-check the F-library version printed in the manual cover page with the F-toolkit compiled into the project.

Can a standard analog output of an S7 F-CPU be used inside a SIL 2 SIF?

No. A standard SM 332 or ET 200SP AQ module is not FMEDA-evaluated for IEC 61508 safety use. The accepted architectures are (a) standard AO driving a hard-wired safety relay that performs the shutdown, or (b) F-DO pulse-width output driving a positioner with a safety certificate. In both cases the AO is outside the SIF PFD sum.

Which is stricter, PFDavg or PFHavg, for an S7 F-CPU SIF?

It depends on the demand rate. For low-demand service (≤ 1 demand/year) the IEC 61508-1 low-demand PFD band is the binding value. For high-demand or continuous service (e.g., burner management, robot safe speed) the PFH band is binding and is roughly 1 000× tighter per hour; a CPU with PFDavg = 8 × 10⁻⁴ over 10 years typically corresponds to a PFH near 9 × 10⁻⁸ /h, on the edge of SIL 3.

What is the 100-1 rule and how does it affect a SIL 2 budget?

The 100-1 rule (IEC 61511-1 §11.5) requires that no single sensor, logic, or final element subsystem consumes more than 35 % of the total SIL PFD budget. For a SIL 2 target of 10⁻², each subsystem must stay below 3.5 × 10⁻³. If the valve alone is at 6.3 × 10⁻³, the SIF fails the rule even if the total PFDavg of 8.7 × 10⁻³ is inside the band; shorten the proof test interval or change to 1oo2 to bring the valve back into budget.

Do I have to use the Siemens Safety Evaluation Tool for TÜV submission?

Not strictly – any TÜV-certified calculation (manual formulas per IEC 61508-6, Exida exSILentia, or ABB SetSIL) is acceptable. The Safety Evaluation Tool is preferred because it is shipped with the F-CPU TÜV certificate, the values are auto-filled, and the exported PDF carries the same TÜV stamp. When the SIF also touches machinery, also reference the Siemens entry ID 23996473 (IEC 62061 application example).

Back to blog