CODESYS · Functional safety

CODESYS Safety

Certified Safety Software for Supported CODESYS Architectures
CODESYS Safety is a portfolio of certified software solutions for functional-safety applications. A safety claim applies only to the specific CODESYS safety product, controller or virtual-control architecture, safe communication and safe I/O covered by the relevant certification and project design.

Certified productsSafe I/OSafe communicationDefined target scopeValidation obligations
CODESYS Safe Control official product image
BasisIEC 61508
IntegritySIL2 / SIL3 by product
Safe communicationProduct-specific
ClaimCertified scope only
Product role

Select a certified safety architecture—not a generic safety feature

CODESYS Safety is a portfolio of certified software solutions for functional-safety applications. A safety claim applies only to the specific CODESYS safety product, controller or virtual-control architecture, safe communication and safe I/O covered by the relevant certification and project design.

Separates standard and safety control claimsStandard PLC logic does not become safety logic solely because it is developed in CODESYS; a certified safety product and architecture are required.
Supports multiple certified routesSafety can be implemented through supported hardware-integrated CODESYS safety products, EtherCAT safety architectures or Virtual Safe Control SL depending on the project.
Keeps machine validation explicitThe machine builder or integrator remains responsible for risk assessment, safety requirements, response-time calculation, verification and validation.
Architecture role

From risk assessment to validated safety function

Define the interfaces and ownership boundaries first; version, licence and target selection should follow the architecture rather than lead it.

01Risk assessment
02Certified CODESYS safety route
03Safe communication
04Safe I/O / drives
05Safety function
Confirm the exact target, product version, device package, protocol role, licence and—where applicable—certified safety scope before release to production.
Engineering scope

Certified safety routes and project boundaries

These capabilities define what the CODESYS component contributes to the architecture and what must still be provided by the controller, host platform, network or machine design.

01

Separates standard and safety control claims

Standard PLC logic does not become safety logic solely because it is developed in CODESYS; a certified safety product and architecture are required.

02

Supports multiple certified routes

Safety can be implemented through supported hardware-integrated CODESYS safety products, EtherCAT safety architectures or Virtual Safe Control SL depending on the project.

03

Keeps machine validation explicit

The machine builder or integrator remains responsible for risk assessment, safety requirements, response-time calculation, verification and validation.

Technical selection

Certification, safety manual and machine-validation requirements

Use this table as a requirement-capture guide. The final implementation should be checked against current CODESYS product documentation, Store data, target documentation and—where relevant—certificates and safety manuals.

Current CODESYS safety routesCODESYS Safety for EtherCAT Safety Module SL, CODESYS Virtual Safe Control SL, and safety-capable devices from manufacturers that have integrated qualified CODESYS safety products.
Integrity levelSIL2 or SIL3 applicability depends on the exact product, architecture and certification; it is not a generic CODESYS platform rating.
Safe communicationSupported safe protocols are product-specific. CODESYS safety products include architectures using EtherCAT Safety (FSoE) and Virtual Safe Control SL supports PROFIsafe and FSoE.
Engineering environmentSafety engineering uses the corresponding CODESYS safety extensions and certified workflow for the selected product.
Machine obligationsRisk assessment, safety requirements specification, PL/SIL determination, stop-time/response-time calculation, verification, validation and change control remain project responsibilities.
Publication ruleUse the current certificate, safety manual and product documentation—not a generic web-page statement—as the final basis for a safety-related design.
Project workflow

Safety architecture, engineering and validation workflow

Move from architecture qualification to engineering, commissioning and lifecycle evidence in a controlled sequence.

01

Specify the safety functions

Complete the risk assessment and state the required safety behaviour, integrity level and response times.

02

Select a certified route

Match target, runtime, safety product, safe I/O and safe communication to a documented approved scope.

03

Engineer under change control

Develop the safety application within the required project, review and change-control process.

04

Verify and validate

Test each operating mode, diagnostic response, stop, reset and restart against the safety requirements.

Documentation & requirement capture

Official CODESYS documentation and project inputs

Use the official product page for current product information, then provide the project-specific details below so the architecture can be reviewed against the actual machine or system.

Application scopeMachine/process functions, operating modes, cycle-time expectations and whether the project is new design, retrofit or migration.
Target & software baselineController/IPC, CPU architecture, operating system, CODESYS runtime, device package, compiler profile and existing project version.
I/O & communicationLocal/remote I/O, fieldbuses, Industrial Ethernet, OPC UA, MQTT, controller-to-controller links and required protocol roles.
HMI & user accessDisplay hardware, browser clients, independent HMI requirements, alarms, trends, recipes, user roles and remote-service policy.
Motion & functional safetyAxis count, drives, kinematics, CNC/robotics requirements, safe I/O, safe communication and required PL/SIL where relevant.
Deployment & lifecycleController quantity, sites, licensing, backups, certificates, update process, rollback expectations and maintenance ownership.