July 22, 2026 · Functional Safety

Safety-Rated Robot Cell Controls: PLd, Category 3, and SIL 2 Explained

Quick answer: A robot cell safety function has to do more than stop the robot. It has to keep working when a component fails. ISO 13849-1 measures that reliability as a Performance Level. A risk assessment sets the required level, usually PLd or PLe for hazardous motion, and the achieved level comes from the architecture Category, the MTTFd, the diagnostic coverage, and the common cause failure score together. PLd maps to SIL 2, PLe to SIL 3.

Ask two integrators what makes a robot cell safe and you get two answers. One points at the light curtain and the interlocks. The other asks what happens the day a contact welds shut or a channel opens. The second engineer is thinking about functional safety, and that is the difference between a cell that looks safe and a cell that stays safe through a component failure.

This is a working guide to safety-rated controls on robot cells, written for the controls and EHS engineers who own that question in West Michigan plants. What a Performance Level actually measures, how you determine the level a given safety function must reach, what separates Category 3 from Category 4, and why good hardware wired into the wrong architecture still fails the target. It is the layer underneath the safeguarding devices we covered in our guide to light curtains and laser scanners.

What a Performance Level Actually Measures

A safety function is the whole chain that carries out one protective action: a sensor detects the demand, logic evaluates it, and an output removes power or motion. On a robot cell that chain might be the perimeter gate interlock, the light curtain at the load station, the enabling device on the teach pendant, or the safe-stop input to the drive. Each of these is a separate safety function, and each one earns its own rating.

ISO 13849-1 rates that chain with a Performance Level, PLa through PLe. The level is a measure of reliability, expressed underneath as a probability of dangerous failure per hour. PLd sits in the range of one dangerous failure per ten million hours down to one per million hours. PLe is an order of magnitude better. The point is not the exact figure. The point is that a Performance Level is a statement about how the function behaves over time and through faults, not just whether it works on the day it was commissioned.

Step One: Determine the Required Level, PLr

You do not pick a Performance Level from habit or from the last cell you built. You derive it from the risk. ISO 13849-1 provides a risk graph that walks three parameters:

Run a typical operator-facing robot cell through the graph, S2, F2, P2, and it lands at a required Performance Level of PLd, sometimes PLe for the highest-exposure or highest-force cells. That required level is the PLr, and it is the number every safety function on the cell has to meet or beat. Document the risk assessment that produced it. An unwritten PLr is the first thing a serious audit asks for, and the same risk-assessment discipline underpins the standards alignment we cover in our ANSI R15.06, ISO 10218, and OSHA 1910.147 guide.

Step Two: Build to a Category

The Category is the architecture of the safety function, and it is the backbone of the achieved Performance Level. ISO 13849-1 defines five: B, 1, 2, 3, and 4. On a hazardous robot cell, only the top two are usually in play.

Category 3 is a dual-channel design in which a single fault does not lead to loss of the safety function. Two independent channels carry the safety signal, and the logic cross-monitors them. If one channel fails, the other still stops the cell. The catch is that not every single fault is necessarily detected, so a fault can go latent until a second one arrives.

Category 4 keeps the single-fault tolerance and adds two requirements: most single faults are detected at or before the next demand on the safety function, and an accumulation of undetected faults still does not cause loss of the function. That detection requirement is why Category 4 needs high diagnostic coverage, and why PLe effectively requires Category 4. In practice, a robot cell at PLd is built to Category 3, and a cell at PLe is built to Category 4.

Step Three: The Numbers Behind the Architecture

Architecture alone does not get you to a Performance Level. Three quantitative inputs feed the calculation, and skipping any of them is how a cell that looks like Category 3 lands below PLd on paper.

You combine the Category, MTTFd, and DCavg to read the achieved Performance Level, then confirm CCF passes, then check that the achieved PL meets or exceeds the required PLr. The free SISTEMA tool from the German IFA is the standard way to document this calculation, and a stamped SISTEMA report is exactly the kind of evidence that turns a claimed PLd into a verified one.

Performance Level to SIL: The Same Target, Two Standards

Two standards live in this space. ISO 13849-1 uses Performance Levels and covers control systems of any technology: electrical, electronic, hydraulic, pneumatic. IEC 62061 uses Safety Integrity Levels and is the machinery-specific standard for electrical, electronic, and programmable controls. Both are harmonized for machinery, and they map cleanly through the underlying failure probability.

ISO 13849-1IEC 62061Typical robot cell use
PLc (Cat 1 or 2)SIL 1Lower-risk auxiliary functions
PLd (Cat 3)SIL 2Most robot cell safeguarding: interlocks, light curtains, safe stop
PLe (Cat 4)SIL 3Highest-exposure or highest-force cells

So when a spec says PLd Category 3 and a drive datasheet says SIL 2, they are describing the same target. A cell built to PLd is a SIL 2 cell. Knowing the mapping keeps you from over-specifying an expensive PLe drive where the risk assessment only called for PLd, and from quietly accepting a SIL 1 component in a PLd safety function.

Where West Michigan Robot Cells Fall Short

The gap we write up most often is not a missing device. It is a safety function that was treated as a sensor instead of a rated chain. The recurring findings:

Each of these is a citable condition under OSHA 1910.147, MIOSHA Part 85, and the robotics consensus standards, and each one is fixable without ripping out the cell. Our robotics safety gap analysis verifies the architecture, recalculates the achieved Performance Level, and delivers a written report against the required PLr.

Functional Safety Is Not Lockout

One line that has to stay clear. Safety-rated controls are a functional safety measure. They protect the operator during normal production by stopping motion on demand, reliably, through faults. They are not energy isolation. When a technician goes inside the cell for service, the answer is still an actual lockout at the disconnect under OSHA 1910.147, not a trust in the safety controller. The two protect different people at different times, and the standards require both. We walk through the isolation side in our robot cell LOTO procedures.

Free Robotics Safety Gap Assessment

We will review the risk assessment behind your cell, verify each safety function's architecture, recalculate the achieved Performance Level against the required PLr, and confirm the control system meets the PL or SIL your cell actually needs.

Request Gap Assessment

Frequently Asked Questions

What Performance Level does a robot cell safety function need?

It comes from the risk assessment, not a default. ISO 13849-1 uses a risk graph based on severity, frequency of exposure, and possibility of avoidance to set the required Performance Level, or PLr. For a robot cell with hazardous motion and workers close to the envelope, the safeguarding safety functions almost always land at PLd or PLe. Lower-risk auxiliary functions can be PLc or below.

What is the difference between Category 3 and Category 4?

Both are dual-channel architectures where a single fault does not cause loss of the safety function. Category 4 goes further: it requires that most single faults are detected at or before the next demand, and that an accumulation of faults still does not cause loss of the function. Category 3 tolerates one fault. Category 4 tolerates one fault and detects it, which is why PLe effectively requires Category 4.

How does Performance Level map to SIL?

ISO 13849-1 uses Performance Levels a through e. IEC 62061 uses Safety Integrity Levels 1 through 3 for machinery. They align through the probability of dangerous failure per hour: PLc maps to SIL 1, PLd maps to SIL 2, and PLe maps to SIL 3. A robot cell specified at PLd Category 3 is equivalently a SIL 2 safety function. The two standards are harmonized for machinery.

What determines the achieved Performance Level of a safety circuit?

Four things, not just the components. The Category, or architecture. The MTTFd, the mean time to dangerous failure of each channel. The average diagnostic coverage, how well the system detects its own faults. And the common cause failure score. You combine these to get the achieved PL, then confirm it meets the required PLr. Good parts wired into a poor architecture still fail the target.

Is a safety PLC required to reach PLd on a robot cell?

Not always a full safety PLC, but you do need a safety-rated logic device. A safety controller or safety relay with dual-channel monitoring, cross-checking, and diagnostic coverage is required to reach PLd Category 3 on a robot cell. A standard control relay with no diagnostics cannot achieve it, no matter how good the light curtain or interlock feeding it is.

Do safety-rated controls replace lockout/tagout on a robot cell?

No. Safety-rated controls protect people during normal production by stopping motion on demand. They are a functional safety measure, not energy isolation. OSHA 1910.147 still requires actual lockout at the disconnect for service and maintenance inside the cell. The safety controller protects the operator running the line; lockout protects the technician working inside the guarded space.

Related reading: Light Curtains and Laser Scanners for Robot Cells, Robot Cell LOTO: Aligning ANSI R15.06, ISO 10218, and OSHA 1910.147, Robotics Safety Gap Analysis.

About Industrial Robot Automation Grand Rapids. West Michigan robotics safety and LOTO compliance. Sister company to ECPL (Equipment Compliance Placards Ltd) under the same parent organization. We provide robot cell LOTO procedures, access control placards, annual LOTO audits, and full robotics safety gap analysis for manufacturers across Grand Rapids, Wyoming, Kentwood, Walker, Grandville, Cascade, Caledonia, Holland, Zeeland, Muskegon, Kalamazoo, and Battle Creek. Our content references OSHA 1910.147, MIOSHA Part 85, ANSI/RIA R15.06-2025, ISO 10218-1:2025, ISO 10218-2:2025, ISO 13849-1, ISO 13849-2, and IEC 62061.