Requirements for the external safety controller

Without safe communication, it may be necessary to use a safety controller or safety relay to fulfill the safety function of the machine/system. The following requirements apply analogously.

    • The safety controller and all other safety-related subsystems must be approved for at least the safety class required in the overall system for the respective application-related safety function.

The following table shows an example of the required safety class of the safety controller:

Application

Requirement for safety controller

Performance level d according to EN ISO 13849-1, SIL 2 according to EN 62061

Performance level d according to EN ISO 13849‑1
SIL 2 according to EN 61508

  • The wiring of the safety controller must be suitable for the endeavored safety class (see manufacturer's documentation). The safe digital input of the device can be 2-pole switched (sourcing output).
  • The values specified for the safety controller must be strictly adhered to when designing the circuit.
  • Only safeguards with presence detection may be used at the safe digital input of the device if safe communication is not used. The safeguards without presence detection must be connected via a safety relay or a safety controller.
  • To stop the drive in case of an emergency in accordance with EN 60204-1, emergency stop control devices must be connected to the safe digital input of the device as follows:
    • via a safety relay
    • via a safety controller
  • To ensure protection against an unexpected restart in accordance with EN ISO 14118, the safe control system must be designed and connected in such a way that resetting the command device alone does not lead to a restart. This means that a restart may only be carried out after a manual reset of the safety circuit.
  • If no fault exclusion is used for the safe digital input in accordance with EN ISO 13849-2 or EN 61800-5-2, the external safety device must detect the following errors in the wiring within 20 s depending on the connection type:
    • Short circuit of 24 V at F-DI00_A or F-DI00_B (Stuck-at 1)
    • Crossfault between F-DI00_A and F-DI00_B