Appendix - Safety-related applications (SIL 2)
en Version 04 PHOENIX CONTACT A-1
Appendix
A1 Safety-related applications (SIL 2)
Valid hardware and firmware versions
SIL regulations apply to the following modules:
The safety-related temperature transducers listed above
from the MACX MCR(-EX)-T-... series have been evaluated
by exida Certification S.A. via a Full Assessment in accor-
dance with IEC 61508 Ed.1.0 to SIL 2.
Certificate number: Phoenix Contact 100134C P0019
C001.
A1.1 Safety function and safety requirements
The safety-related measuring transducers are used for the
acquisition of a sensor signal (RTD, TC sensors, resistance-
type sensors, mV sources), that is converted into a scaled
signal and from which a standardized “life zero” current sig-
nal is generated. The entire conversion is continuously mon-
itored to a maximum transmission error of 5%. In the event
of greater deviations, the device switches to the safe state.
The safe state is an output signal of either < 3.6 mA or > 21
mA.
With the REL versions, an additional signal is generated,
which is compared with up to two specified switching thresh-
olds. When the first threshold is reached, the safety relay is
switched on without confirmation contact and when the sec-
ond threshold is reached, it is switched off. Depending on
the application, the safety for the switching output is imple-
mented by either the series or parallel connection of relays
2 and 3, a fuse connected in series, and by monitoring the
calculated switching value. In the event of deviations of
more than 5%, the device switches to the safe state. The
safe state in this case is an uncontrolled relay.
The hardware is also continuously monitored. If an internal
failure is detected, the measuring transducer also switches
to the safe state (current output < 3.6 mA or > 21 mA or un-
controlled relay).
The transition to the safe state always takes place within the
internal failure detection time of 50 s.
The measuring transducer is released (restarted) by switch-
ing off the supply voltage and switching it back on again, by
resetting the transducer via the serial interface, or by activat-
ing the “Restart” option during configuration. The integrated
startup tests are then performed. If the error is still present,
it will be detected during these tests. If it is still present, the
measuring transducer switches back to the safe state.
In addition to the safety functions, there are also monitoring
functions for the input and the current output.
Evaluation
Failures which are detected in the measuring transducer
and to which the transducer responds by switching to the
safe state are safe failures (λs).
Failures where the measuring transducer does not follow a
change of input signal or generates an output signal that de-
viates from the intended value by more than ±5%, are eval-
uated as dangerous failures (λd).
Both safe (λs) and dangerous (λd) failures can be detected
by diagnostic measures. Detected dangerous failures (λdd)
are handled in the same way as safe failures.
The monitoring functions refer to events whose cause is
detected and reported outside of the device.
NOTE: Only those devices with SIL designa-
tion and device firmware with revision 0.92 or
higher are certified for SIL 2.
Designation Order No.
Standard configuration
MACX MCR-T-UI-UP 28 11 394
MACX MCR-T-UI-UP-SP 28 11 860
MACX MCR-T-UIREL-UP 28 11 378
MACX MCR-T-UIREL-UP-SP 28 11 828
MACX MCR-EX-T-UI-UP 28 65 654
MACX MCR-EX-T-UI-UP-SP 29 24 689
MACX MCR-EX-T-UIREL-UP 28 65 751
MACX MCR-EX-T-UIREL-UP-SP 29 24 799
Order configuration
MACX MCR-T-UI-UP-C 28 11 873
MACX MCR-T-UI-UP-SP-C 28 11 970
MACX MCR-T-UIREL-UP-C 28 11 514
MACX MCR-T-UIREL-UP-SP-C 28 11 831
MACX MCR-EX-T-UI-UP-C 28 11 763
MACX MCR-EX-T-UI-UP-SP-C 29 24 692
MACX MCR-EX-T-UIREL-UP-C 28 65 722
MACX MCR-EX-T-UIREL-UP-SP-C 29 24 809
NOTE: The evaluation unit following the measur-
ing transducer (e.g., safety-related PLC) must
recognize these states and correspondingly con-
trol the actuator as the final link in the safety chain.