Back to Blog
6 min read Safety Engineering

ISO 13849 vs IEC 61508: When to Use Which

ISO 13849 covers machine safety. IEC 61508 covers the full functional safety lifecycle. Here's how to know which standard applies to your system.

Two standards. Both cover functional safety. Both show up in certification requirements. And most engineers encounter both in the first month of a safety project without a clear answer for which one applies to their system.

This is one of the most common questions in functional safety engineering. It deserves a direct answer.

ISO 13849 IEC 61508
Scope Safety-related parts of control systems for machinery Functional safety of any electrical, electronic, or programmable system
Risk metric Performance Level (PLa through PLe) Safety Integrity Level (SIL 1 through SIL 4)
Best fit Machines, workcells, discrete safety functions Autonomous systems, complex programmable architectures
Lifecycle coverage Safety functions in the control system Full lifecycle from concept through decommissioning
CE Marking Directly referenced in the EU Machinery Directive Applied via sector-specific standards or directly

What each standard actually covers

ISO 13849 governs safety-related parts of control systems for machinery. It defines performance levels (PLa through PLe) using a simplified reliability framework. If you’re building a machine, a workcell, or a piece of industrial equipment with a safety control system, ISO 13849 is likely your starting point. It was designed for that scope and works well within it.

IEC 61508 is broader. It’s the foundational international standard for functional safety of electrical, electronic, and programmable electronic systems. It defines Safety Integrity Levels (SIL 1 through SIL 4) and prescribes a full lifecycle model, the V-Model, from concept through decommissioning. It applies to any safety-related system across any industry.

The relationship: ISO 13849 is sector-specific. IEC 61508 is the parent. ISO 13849 was designed for a narrower scope and uses a more accessible methodology. IEC 61508 covers everything ISO 13849 does and significantly more.

The decision framework

When ISO 13849 is sufficient:

  • Your system is a machine or workcell with discrete safety functions
  • The safety functions are relatively straightforward (e-stops, guard interlocking, safe speed monitoring)
  • You’re pursuing CE marking under the EU Machinery Directive
  • Your safety control system uses simple or limited programmable logic
  • The assessor or customer specification references ISO 13849 directly

When you need IEC 61508:

  • Your system has complex programmable electronics
  • You’re building an autonomous mobile robot, vehicle, or device that operates without continuous human supervision
  • Multiple subsystems interact in ways that require system-level safety analysis
  • You need to demonstrate a Safety Integrity Level, not just a Performance Level
  • The sector-specific standards (like ISO 13849 or ISO 26262) don’t fully cover your application
  • Your system’s complexity exceeds what a desktop reliability calculator can meaningfully capture

The short version: ISO 13849 is for machines with safety functions. IEC 61508 is for anything where functional safety applies and the sector-specific standards fall short.

Where teams get stuck

The trouble starts when a system that began as a “machine” becomes something more complex. A collaborative robot that was originally a fixed workcell gets mounted on an AMR. An industrial machine gets connected to a fleet management system. A straightforward safety function now depends on software, sensors, and communication layers that ISO 13849 was never designed to address.

At that point, teams discover they’ve been building against the wrong standard. The performance level calculations they completed don’t map cleanly to the SIL requirements an assessor now expects. The documentation structure is different. The analysis depth is different. The traceability expectations are different.

This isn’t a paperwork problem. It’s a rework problem. And it gets more expensive the later it surfaces.

Can you use both?

Yes. Many teams do, and the standards were designed for this.

A system might have subsystems certified to ISO 13849 (the safety control system for a single machine) while the overall system-level safety case follows IEC 61508. Performance levels can map to SIL levels. PLd roughly corresponds to SIL 2. PLe roughly corresponds to SIL 3. But the mapping isn’t exact, and the methodological differences mean you can’t just relabel a PL calculation as a SIL calculation and call it done.

The key is choosing the right standard for the right scope from the beginning. When your safety infrastructure supports both standards within the same workflow, expanding scope doesn’t mean starting over. You extend the analysis. You don’t rebuild it.

What this means for your project

Two questions before your next certification decision:

  1. Is your system a machine with defined safety functions, or is it a system with programmable electronics operating with limited human supervision?

  2. Will the scope of this system expand in the next 12 to 24 months?

If either answer points toward complexity, start with IEC 61508. You can always scope down to ISO 13849 for specific subsystems. Scoping up after you’ve built your entire safety case on ISO 13849 means significant rework (and the certification delays that come with it).

The standards exist to protect people. Getting the right one from the start also protects your timeline.

FAQ: ISO 13849 vs IEC 61508

What is the main difference between ISO 13849 and IEC 61508? ISO 13849 applies to safety-related parts of control systems in machinery. It uses Performance Levels (PLa through PLe) and was designed for machines with well-defined safety functions. IEC 61508 is the parent standard for functional safety of electrical, electronic, and programmable electronic systems across all industries. It uses Safety Integrity Levels (SIL 1 through SIL 4) and prescribes a full lifecycle from concept through decommissioning.

When does ISO 13849 apply vs IEC 61508 for machine safety? ISO 13849 is sufficient when you’re building a machine with defined safety functions and relatively straightforward programmable logic. Move to IEC 61508 when the system includes complex software, operates without continuous human supervision, or involves subsystems that interact in ways that exceed the scope ISO 13849 was designed to address.

How does Performance Level map to Safety Integrity Level? PLd corresponds roughly to SIL 2. PLe corresponds roughly to SIL 3. But the mapping isn’t direct. Performance Level uses a simplified reliability framework optimized for machinery. SIL requires more rigorous probabilistic analysis. You can’t relabel a PL calculation as a SIL result without redoing the underlying work.

Can you use both ISO 13849 and IEC 61508 on the same system? Yes. Many systems use ISO 13849 for individual machine safety functions while the system-level safety case follows IEC 61508. The standards are designed to work together. What matters is choosing the right scope for each layer from the beginning, not changing standards mid-program when the architecture doesn’t fit.

Which functional safety standard applies to autonomous mobile robots? Most AMR applications require IEC 61508 at the system level because autonomous navigation involves complex programmable electronics operating without continuous human supervision. ISO 3691-4 applies to powered industrial trucks including AMRs, and ISO 13849 may govern specific safety functions within the AMR. But the system-level safety architecture is typically IEC 61508 territory.

This post covers general functional safety engineering principles and is for educational purposes only. It is not engineering advice. Consult a qualified functional safety professional and your applicable standards body before making safety-critical design decisions.


Fennec Engineering’s ASAP platform supports ISO 13849, IEC 61508, and ISO 26262 within a single guided workflow. If you’re working through which standard applies to your system, that’s a conversation worth having.