SIL-certified safety systems
SIL-certified safety systems are electronic systems whose safety functions have been designed, documented, and verified to achieve a defined probability of dangerous failure, expressed as a Safety Integrity Level (SIL) in accordance with the IEC 61508 framework and its railway-specific implementations.
Safety Integrity Level is defined in IEC 61508, the generic functional safety standard for electrical, electronic, and programmable electronic systems.
The SIL framework
SIL is a discrete measure of required safety performance, ranging from SIL 1 (least stringent) to SIL 4 (most stringent). The applicable SIL for a given safety function is determined by a hazard and risk analysis: the more severe and frequent the potential harm, and the less effective other risk-reduction measures, the higher the SIL required.
IEC 61508 distinguishes two operating modes. Low demand mode applies to systems activated infrequently in response to a hazardous condition; performance is expressed as probability of failure on demand (PFDavg).
High demand or continuous mode applies to systems that operate continuously or are demanded at high frequency; performance is expressed as probability of dangerous failure per hour (PFH).
The distinction matters for railway applications: most safety-critical onboard functions — traction control, brake management, movement authority — operate in continuous mode and are assessed against PFH values, while some protection systems activated only on fault detection may be assessed in low demand mode.
The specific numerical thresholds for each SIL level and operating mode are defined in IEC 61508-1 tables 2 and 3.
CENELEC has derived three railway-specific standards from IEC 61508. EN 50126 (IEC 62278) covers the RAMS (reliability, availability, maintainability, and safety) lifecycle. EN 50129 (IEC 62425) specifies safety evidence requirements for electronic signalling systems.
EN 50657 (2017) applies to software on board rolling stock. EN 50716:2023 consolidates and updates the software requirements of EN 50128 and EN 50657 into a single standard covering both signalling and rolling stock domains.
Railway applications by SIL level
SIL 4 is the highest level applied in railway contexts. The European Train Control System (ETCS) onboard unit — responsible for movement authority management and emergency brake application — is certified at SIL 4.
Odometry functions that provide the speed and position inputs to the ETCS unit must also achieve SIL 4, because an erroneous position estimate can result in a missed or premature brake command. Interlocking systems at trackside are similarly SIL 4.
SIL 2 applies to systems where failure could cause significant harm but where additional protective layers exist. Automatic door control systems — which must not permit doors to open while a train is in motion and must confirm closure before departure — are typically assessed at SIL 2. Fire suppression activation circuits and some TCMS safety functions also fall at this level.
SIL 1 applies to systems where failure would cause limited harm given existing operational controls, such as warning indicators in the driver’s cab or passenger emergency call systems.
Certification process
SIL certification requires independent safety assessment (ISA) by an accredited body. The process includes hazard and risk analysis to establish the required SIL, a safety plan, and a safety case — a structured argument supported by evidence that the system achieves its required SIL. For software, this includes code review, formal verification where required at higher SIL levels, and test coverage analysis.
EN 50716:2023 introduced consolidated documentation requirements and extended the scope to cover configurable application software and pre-existing software components.

