Programmable Logic Controllers (PLCs) are widely used to control machines, production lines, packaging equipment, material-handling systems, robots, process equipment, and industrial utilities. Because PLCs can command motors, cylinders, valves, heaters, conveyors, and other moving or energized equipment, safety must be considered from the beginning of the control-system design.
Good programmable logic controllers safety is not achieved simply by adding an emergency-stop button or using a safety PLC. A safe system requires risk assessment, correctly designed safety functions, suitable hardware, reliable wiring, proper machine guarding, controlled software changes, clear maintenance procedures, and compliance with applicable standards.
This guide explains how engineers and maintenance teams can use PLC systems safely and understand the key standards commonly associated with industrial machine control.
- Assess machine risks
- Define safety requirements
- Apply safeguards
- Control energy during maintenance
- Validate safety functions
- Document and control changes
PLC Safety and Compliance Steps
1. Start With a Machine Risk Assessment
PLC safety should begin before programming.
The first step is to identify hazards associated with the machine or process.
Typical hazards may include:
- Moving machinery
- Crushing and trapping points
- Rotating parts
- Pneumatic or hydraulic movement
- Electrical energy
- Hot surfaces
- Unexpected machine restart
- Stored mechanical energy
- Robot movement
- Conveyors and transfer systems
A risk assessment helps determine what safety functions are required and how much risk reduction they need to provide.
Examples of possible safety functions include:
- Emergency stopping
- Guard-door monitoring
- Safe prevention of unexpected startup
- Two-hand control
- Safe speed monitoring
- Light-curtain protection
- Safe torque off for drives
The safety architecture should be based on the identified hazards rather than selecting devices first and deciding their purpose afterward.
2. Understand the Difference Between Standard PLC Control and Safety Control
A standard PLC is normally used for machine sequencing, production logic, alarms, data handling, and process control.
A safety-related control system is designed specifically to perform safety functions with a defined level of reliability.
For example, a standard PLC may control:
- Conveyor start and stop
- Production counters
- Recipe selection
- Valve sequencing
- HMI messages
A safety PLC or other safety-related control equipment may monitor:
- Emergency-stop circuits
- Guard switches
- Light curtains
- Safety mats
- Safe drive functions
Do not assume that a normal PLC input and output automatically provide the reliability required for a safety function.
Standards such as ISO 13849-1 and IEC 62061 provide methodologies for designing and validating safety-related control systems for machinery. ISO 13849-1:2023 covers safety-related parts of control systems, including software, while IEC 62061 addresses functional safety of safety-related control systems for machinery.
3. Use Emergency Stops Correctly
Emergency stops are an important part of machine safety, but they should not be treated as the only protective measure.
An emergency-stop system should be designed so that activating it brings hazardous machine functions to an appropriate safe condition.
The exact behavior depends on the machine and risk assessment.
Important considerations include:
- Emergency-stop device location
- Accessibility
- Reset method
- Prevention of unintended restart
- Safe stopping method
- Integration with drives and actuators
Resetting an emergency stop should not automatically restart hazardous movement unless the complete machine design and applicable safety requirements allow it.
The emergency-stop circuit should be implemented through appropriately designed safety-related hardware and control architecture rather than depending only on ordinary PLC software.
4. Protect Operators With Machine Guarding
PLC logic cannot replace physical guarding where guarding is required.
Machine safeguards may include:
- Fixed guards
- Interlocked doors
- Light curtains
- Safety scanners
- Safety mats
- Two-hand controls
- Perimeter fencing
OSHA guidance on machine guarding emphasizes protection from hazards created by points of operation, rotating parts, nip points, flying material, and similar machine hazards.
An interlocked guard may communicate with a safety control system so that opening the guard removes or controls hazardous energy.
The exact method depends on the risk assessment and required safety performance.
5. Apply ISO 13849-1 Where Appropriate
ISO 13849-1:2023 is an important machinery-safety standard for safety-related parts of control systems.
It provides requirements and guidance for designing and integrating safety-related control systems that perform safety functions.
One important concept is the Performance Level, commonly expressed as:
- PL a
- PL b
- PL c
- PL d
- PL e
The required level depends on the risk associated with the safety function.
Higher-risk safety functions generally require stronger risk-reduction measures and higher reliability.
Engineers should not simply select a Performance Level without performing the appropriate risk assessment and design calculations.
ISO 13849-1 can apply to different technologies, including electrical, pneumatic, hydraulic, and mechanical control elements that form part of a safety-related control function.
6. Understand IEC 62061 for Functional Safety
IEC 62061 is another major machinery functional-safety standard.
IEC 62061:2021 specifies requirements and recommendations for the design, integration, and validation of safety-related control systems used on machinery.
It uses the Safety Integrity Level concept for machinery safety functions.
Commonly encountered machinery safety integrity levels are:
- SIL 1
- SIL 2
- SIL 3
The selected approach should follow the applicable standards, organizational practices, regulatory requirements, and engineering methodology.
ISO 13849-1 and IEC 62061 both deal with machinery safety-related control systems, but their methods and terminology differ.
Companies should use trained functional-safety personnel where required rather than treating the standards as simple checklist documents.
7. Follow IEC 60204-1 for Machine Electrical Equipment
IEC 60204-1 covers general requirements for electrical, electronic, and programmable electronic equipment used on machines.
It addresses areas such as:
- Electrical equipment of machinery
- Protective measures
- Control circuits
- Overcurrent protection
- Wiring practices
- Operator interfaces
- Electrical documentation
- Power drive systems
- Electromagnetic compatibility
The standard applies from the point where the electrical supply connects to the machine's electrical equipment.
For PLC-controlled machines, electrical safety and PLC design are closely connected.
Poor grounding, incorrect protection, bad cable routing, inadequate isolation, or incorrect control-circuit design can create reliability and safety problems even when the PLC program itself is correct.
8. Use PLC Hardware Suitable for the Industrial Environment
PLC hardware must be suitable for the intended environment.
IEC 61131-2 defines functional and electromagnetic-compatibility requirements and verification tests for PLCs and related industrial control equipment.
Important environmental considerations include:
- Temperature
- Humidity
- Vibration
- Electrical noise
- Electromagnetic interference
- Power quality
- Dust
- Moisture
- Enclosure protection
The PLC should be installed within the limits specified by its manufacturer.
Do not install control electronics near excessive heat sources or strong electromagnetic interference without suitable engineering controls.
9. Prevent Unexpected Machine Startup
Unexpected machine movement is a major hazard during troubleshooting and maintenance.
A machine should not restart simply because:
- PLC power returns
- An emergency stop is reset
- Communication is restored
- A fault is cleared
- An operator closes a guard
unless this behavior has been deliberately designed and validated as safe.
PLC startup logic should clearly define machine state after:
- Power failure
- CPU restart
- Communication loss
- Safety-system reset
- Emergency-stop reset
For many applications, operator action is required before production movement resumes.
This prevents stored commands from unexpectedly restarting the machine.
10. Use Lockout/Tagout During Maintenance
PLC commands should never be considered a substitute for energy isolation when maintenance requires hazardous energy to be controlled.
For example, turning an output OFF in software does not necessarily make a machine safe for maintenance.
Hazardous energy can include:
- Electrical energy
- Pneumatic pressure
- Hydraulic pressure
- Gravity
- Springs
- Stored mechanical energy
- Thermal energy
OSHA's lockout/tagout guidance requires appropriate procedures for isolating machinery from hazardous energy during servicing and maintenance under the U.S. regulatory framework.
Sites in other countries should follow their applicable national regulations and internal safety procedures.
Before working inside machinery, technicians should use the approved hazardous-energy control process for their facility.
11. Control PLC Software Changes
Unauthorized software modifications can create serious safety problems.
A technician may be tempted to:
- Bypass a guard condition
- Disable an alarm
- Force an output
- Remove an interlock
- Change a timer
- Override safety-related conditions
Such modifications can introduce hazards if they are not properly reviewed.
PLC software changes should follow a formal process that includes:
- Change request
- Technical review
- Safety impact assessment
- Program modification
- Testing
- Validation
- Documentation
- Updated backup
For safety PLC applications, change management becomes even more important because software can be part of the safety-related control function.
12. Be Careful When Forcing PLC Inputs and Outputs
PLC forcing is useful during commissioning and troubleshooting, but it must be controlled carefully.
Forcing can override normal program behavior.
For example, forcing a valve output ON could move a pneumatic cylinder even if the normal machine sequence would keep it stopped.
Before using a force:
- Understand the affected equipment
- Confirm the area is safe
- Follow site procedures
- Check interlocks
- Inform relevant personnel
- Remove all forces after testing
Many PLC programming platforms provide a force table or indication showing active forces.
Always verify that no unintended forces remain before returning the machine to production.
13. Validate Safety Functions
Installing safety components is not the end of the safety process.
Safety functions should be validated to confirm they perform as intended.
Validation may include checking:
- Emergency-stop operation
- Guard-door monitoring
- Light-curtain response
- Safety relay operation
- Safety PLC logic
- Drive safe functions
- Fault detection
- Reset behavior
- Restart prevention
- Diagnostic coverage
Documentation should show what was tested and the results.
Functional-safety standards such as ISO 13849-1 and IEC 62061 include requirements related to design, verification, and validation.
Key PLC Safety Standards at a Glance
| Standard | Main Relevance |
|---|---|
| ISO 13849-1:2023 | Safety-related parts of machine control systems |
| IEC 62061:2021 | Functional safety of machinery control systems |
| IEC 60204-1:2016 + AMD1:2021 | Electrical equipment of machines |
| IEC 61131-2:2017 | PLC equipment and EMC requirements |
| OSHA 29 CFR 1910.147 | Hazardous-energy control / lockout-tagout in the U.S. |
The standards that apply to a specific machine depend on its design, location, industry, regulatory environment, and intended use.
Practical PLC Safety Checklist
Before operating or commissioning a PLC-controlled machine, check:
- Risk assessment completed
- Safety functions identified
- Emergency stops tested
- Guards and interlocks operational
- Safety devices correctly connected
- PLC hardware installed within specifications
- Electrical panel correctly protected
- Safety reset behavior verified
- Unexpected restart prevented
- Software version documented
- Active forces removed
- Safety validation completed
- Maintenance isolation procedures available
- Final PLC and safety-program backups stored
Common PLC Safety Mistakes
Avoid these mistakes:
- Using standard PLC logic as the only emergency-stop control
- Bypassing safety interlocks for production convenience
- Leaving forced outputs active after commissioning
- Restarting machinery automatically after safety reset without proper design
- Modifying PLC logic without change control
- Ignoring stored pneumatic or hydraulic energy
- Treating software OFF commands as energy isolation
- Installing PLC hardware outside environmental specifications
- Failing to validate safety functions
- Applying standards without understanding the machine risk
Safety must be designed into the complete machine, not added at the end of the project.
Conclusion
Good programmable logic controllers safety requires a combination of engineering design, functional safety, electrical safety, machine guarding, controlled programming, maintenance procedures, and proper validation.
Standards such as ISO 13849-1, IEC 62061, IEC 60204-1, and IEC 61131-2 provide important frameworks for designing reliable industrial control systems.
However, compliance is not simply about referencing a standard in a project document. Engineers must identify the machine's actual hazards, define appropriate safety functions, select suitable hardware, implement those functions correctly, and validate the final system.
A properly designed PLC-controlled machine should behave predictably not only during normal production but also during faults, maintenance, power loss, emergency stops, and recovery.