SIL-certified safety systems
SIL-certified safety systems are electronic systems whose safety functions are designed, documented and verified to achieve a defined probability of dangerous failure - a Safety Integrity Level under IEC 61508.
The framework applies wherever electronics carry a safety function in fire safety and noise control and beyond: fire detection, suppression activation, doors, braking, movement authority.
The level required is not chosen; it is derived from hazard and risk analysis.
The SIL framework
Safety Integrity Level is defined in IEC 61508, the generic functional safety standard for electrical, electronic and programmable electronic systems. SIL is a discrete measure of required safety performance, ranging from SIL 1 (least stringent) to SIL 4 (most stringent).
The applicable SIL for a given safety function follows from the hazard and risk analysis: the more severe and frequent the potential harm, and the less effective other risk-reduction measures, the higher the SIL required.
IEC 61508 distinguishes two operating modes. Low demand mode covers systems activated infrequently in response to a hazardous condition, with performance expressed as probability of failure on demand (PFDavg); high demand or continuous mode covers systems operating continuously or demanded at high frequency, expressed as probability of dangerous failure per hour (PFH).
The distinction matters on rail: most safety-critical onboard functions — traction control, brake management, movement authority — operate in continuous mode and are assessed against PFH values, while some protection systems activated only on fault detection may be assessed in low demand mode. The specific numerical thresholds for each SIL level and operating mode are defined in IEC 61508-1 tables 2 and 3.
The CENELEC railway standards
CENELEC has derived railway-specific standards from IEC 61508. EN 50126 (IEC 62278) covers the RAMS lifecycle — reliability, availability, maintainability and safety.
EN 50129 (IEC 62425) specifies safety evidence requirements for electronic signalling systems.
EN 50716:2023 consolidates and updates the software requirements of the earlier EN 50128 (signalling) and EN 50657 (rolling stock) standards into a single standard covering both domains; both predecessors were withdrawn in November 2023.
Railway applications by SIL level
SIL 4 is the highest level applied in railway contexts. The European Train Control System (ETCS) onboard unit — responsible for movement authority management and emergency brake application — is certified at SIL 4.
Odometry functions providing the speed and position inputs to the ETCS unit must also achieve SIL 4, because an erroneous position estimate can result in a missed or premature brake command. Interlocking systems at trackside are similarly SIL 4.
SIL 2 applies where failure could cause significant harm but additional protective layers exist. Automatic door control systems — which must not permit doors to open while a train is in motion and must confirm closure before departure — are typically assessed at SIL 2, as are fire suppression activation circuits and some train control and monitoring system (TCMS) safety functions.
SIL 1 applies to systems where failure would cause limited harm given existing operational controls, such as warning indicators in the driver’s cab or passenger emergency call systems.
Certification process
SIL certification requires independent safety assessment (ISA) by an accredited body. The process includes hazard and risk analysis to establish the required SIL, a safety plan, and a safety case — a structured argument supported by evidence that the system achieves its required SIL.
For software, this includes code review, formal verification where required at higher SIL levels, and test coverage analysis.
EN 50716:2023 introduced consolidated documentation requirements and extended the scope to cover configurable application software and pre-existing software components.

