Skip to main content

SIL (Safety Integrity Level)

SIL (Safety Integrity Level) is the risk classification of IEC 61508 for safety-related electrical, electronic and programmable electronic (E/E/PE) systems. The four levels SIL 1 (lowest) to SIL 4 (highest) define how improbable the dangerous failure of a safety function must be and how rigorously its development must be assured.

How is the SIL determined?

The starting point is the hazard and risk analysis of the application: what risk arises if the safety function fails? Among the aspects assessed, qualitatively or quantitatively, are the possible extent of harm, the time spent in the hazardous zone, the possibility of averting the hazard and the probability of occurrence. IEC 61508-5 describes methods for this, such as the risk graph. The result: each individual safety function — not the system as a whole — is assigned a SIL that expresses the necessary risk reduction.

Target failure measures: PFD and PFH

Each SIL is associated with target values for the failure probability of the safety function — depending on the mode of operation:

SILPFDavg (low demand)PFH (high demand / continuous)
4≥ 10⁻⁵ to < 10⁻⁴≥ 10⁻⁹ to < 10⁻⁸ per hour
3≥ 10⁻⁴ to < 10⁻³≥ 10⁻⁸ to < 10⁻⁷ per hour
2≥ 10⁻³ to < 10⁻²≥ 10⁻⁷ to < 10⁻⁶ per hour
1≥ 10⁻² to < 10⁻¹≥ 10⁻⁶ to < 10⁻⁵ per hour

In low demand mode, the safety function is only rarely demanded — typically, for example, an emergency shutdown in the process industry; what is assessed is the average probability of failure on demand (PFDavg). In high demand or continuous mode, the function operates frequently or constantly; what is assessed is the failure rate per hour (PFH).

Safety integrity is more than statistics

The numerical values apply to random hardware failures. Systematic faults — for example in the specification or in the software — cannot be meaningfully assessed probabilistically. IEC 61508 therefore additionally couples each SIL with requirements for the development process: the higher the level, the stricter the methods for specification, architecture, implementation and verification, the higher the requirements for the fault tolerance of the architecture, and the greater the independence of the reviewing instances. For the highest levels, the method tables highly recommend formal methods. A SIL is therefore never just a failure probability, but always also a measure of the rigour of the entire engineering.

SIL vs. ASIL

In the automotive domain, ISO 26262 uses its own scheme with ASIL A to D. Both scales have four levels but cannot be converted 1:1: the ASIL classification additionally considers the controllability by the driver, and the underlying target values and method requirements differ. Statements such as “ASIL D corresponds to SIL 3” are therefore at best a rough orientation, not evidence.

SIL in practice

In practice, the SIL determines the actual engineering effort: requirements traceability, test depth, analyses and the independence of reviews all scale with the level. Correct attribution matters here: a SIL belongs to a safety function in its concrete application context — a purchased “SIL 3 capable” device does not by itself make an overall function SIL 3 compliant. The evidence only emerges from the end-to-end chain from the risk analysis through the safety requirements to the verification and validation of the entire function.

Frequently asked questions

What is the difference between SIL and ASIL?
SIL (IEC 61508) is the industry-neutral risk classification, ASIL (ISO 26262) the automotive-specific derivation. The scales cannot be converted 1:1: ASIL additionally considers the controllability by the driver, and the underlying target values and methods differ.
What do low demand and high demand mean?
Modes of operation of the safety function: in low demand mode, the function is rarely demanded (e.g., an emergency shutdown) — assessed via the average probability of failure on demand (PFD). In high demand or continuous mode, it operates frequently or constantly — assessed via the failure rate per hour (PFH).
Can a single device be “SIL 3”?
Strictly speaking, a SIL refers to a safety function, not to a device. Manufacturer claims such as “SIL 3 capable” mean that a device is suitable for use in a safety function up to SIL 3 — the classification of the overall function only results from the interplay of all elements involved.

Related terms

Reviewed by Dr. Alexander Nyßen, Executive Vice President Digital Engineering on July 20, 2026