SIL (Safety Integrity Level)
SIL (Safety Integrity Level) is the risk classification of IEC 61508 for safety-related electrical, electronic and programmable electronic (E/E/PE) systems. The four levels SIL 1 (lowest) to SIL 4 (highest) define how improbable the dangerous failure of a safety function must be and how rigorously its development must be assured.
How is the SIL determined?
The starting point is the hazard and risk analysis of the application: what risk arises if the safety function fails? Among the aspects assessed, qualitatively or quantitatively, are the possible extent of harm, the time spent in the hazardous zone, the possibility of averting the hazard and the probability of occurrence. IEC 61508-5 describes methods for this, such as the risk graph. The result: each individual safety function — not the system as a whole — is assigned a SIL that expresses the necessary risk reduction.
Target failure measures: PFD and PFH
Each SIL is associated with target values for the failure probability of the safety function — depending on the mode of operation:
| SIL | PFDavg (low demand) | PFH (high demand / continuous) |
|---|---|---|
| 4 | ≥ 10⁻⁵ to < 10⁻⁴ | ≥ 10⁻⁹ to < 10⁻⁸ per hour |
| 3 | ≥ 10⁻⁴ to < 10⁻³ | ≥ 10⁻⁸ to < 10⁻⁷ per hour |
| 2 | ≥ 10⁻³ to < 10⁻² | ≥ 10⁻⁷ to < 10⁻⁶ per hour |
| 1 | ≥ 10⁻² to < 10⁻¹ | ≥ 10⁻⁶ to < 10⁻⁵ per hour |
In low demand mode, the safety function is only rarely demanded — typically, for example, an emergency shutdown in the process industry; what is assessed is the average probability of failure on demand (PFDavg). In high demand or continuous mode, the function operates frequently or constantly; what is assessed is the failure rate per hour (PFH).
Safety integrity is more than statistics
The numerical values apply to random hardware failures. Systematic faults — for example in the specification or in the software — cannot be meaningfully assessed probabilistically. IEC 61508 therefore additionally couples each SIL with requirements for the development process: the higher the level, the stricter the methods for specification, architecture, implementation and verification, the higher the requirements for the fault tolerance of the architecture, and the greater the independence of the reviewing instances. For the highest levels, the method tables highly recommend formal methods. A SIL is therefore never just a failure probability, but always also a measure of the rigour of the entire engineering.
SIL vs. ASIL
In the automotive domain, ISO 26262 uses its own scheme with ASIL A to D. Both scales have four levels but cannot be converted 1:1: the ASIL classification additionally considers the controllability by the driver, and the underlying target values and method requirements differ. Statements such as “ASIL D corresponds to SIL 3” are therefore at best a rough orientation, not evidence.
SIL in practice
In practice, the SIL determines the actual engineering effort: requirements traceability, test depth, analyses and the independence of reviews all scale with the level. Correct attribution matters here: a SIL belongs to a safety function in its concrete application context — a purchased “SIL 3 capable” device does not by itself make an overall function SIL 3 compliant. The evidence only emerges from the end-to-end chain from the risk analysis through the safety requirements to the verification and validation of the entire function.


