IEC 61511 Phase 6–12 — architecture, FMEDA-graded components, FAT/SAT, Safety Manual, and cybersecurity
SIS design translates the Safety Requirements Specification (SRS) into an as-built protection system that achieves and sustains the allocated SIL across the lifecycle. The discipline integrates sensor selection (transmitter type, redundancy, partial proof-test coverage), logic-solver architecture (TÜV / exida-certified safety PLCs — Triconex, HIMA, ABB AC800M HI, Yokogawa ProSafe-RS, Siemens S7-410F), final-element specification (block valve actuation, fail-safe direction, partial-stroke testing capability, fugitive-emission tightness per ISO 15848), and the cabling, networking, power supply, and HMI architecture that surrounds them. The 2016 revision of IEC 61511 Ed.2 tightened design requirements significantly — explicit cybersecurity treatment per Cl.8.2.4 (now mandating IEC 62443 alignment), restricted BPCS-SIS sharing of sensors, formalised prior-use justification for non-certified devices, and required Safety Manual generation per Cl.16. Common audit findings now cluster on sensor common-cause separation (transmitter mounting, impulse-line geometry, calibration drift), final-element diagnostic coverage and partial-stroke testing realism, beta-factor scoring honesty, and the cybersecurity dimension that 1990s-era SIS programmes rarely addressed.

Review approved SRS for completeness; establish SIS design basis with architecture targets, redundancy strategy, and cybersecurity zone definition; align with IEC 61511 Phase 6 design and engineering requirements.
Select TÜV-certified safety logic solver (Triconex, HIMA, ABB AC800M HI, AB GuardLogix); justify prior-use per IEC 61511 Cl.11.5.3; specify platform certification (SIL 2 / SIL 3 / SIL 4 capable); align with IEC 62443 cybersecurity requirements.
Specify sensors with FMEDA data — pressure (Rosemount 3051SIS / E+H Cerabar), temperature (RTD/TC with safety transmitter), level (radar/DP), flow (vortex/coriolis); specify final elements — ESD valves (Mokveld, Velan) with API 6FA fire-safe, partial-stroke capable for SIL ≥2.
Design voting architecture (1oo1D, 1oo2, 2oo3) per SIL target, MTTFS (spurious trip), and CCF mitigation; specify diverse sensors / separated cabinets / independent power for high-CCF risk; align with IEC 61508 Route 1H or 2H per design tolerance.
Implement IEC 62443 zone-and-conduit architecture — SIS zone isolated from BPCS via uni-directional data diode or firewall; specify access control, audit log, USB lockdown; align with NIST SP 800-82 OT security guidance.
Develop FAT procedure exercising every SIF cause-and-effect; SAT with end-to-end loop testing; produce Safety Manual per IEC 61511 Cl.16 covering operating, proof-testing, bypass, MOC procedures; align with FSA Stage 2 / 3 examination.

Complete SIS Detailed Design & Lifecycle Verification scope — every calculation, drawing, specification, and construction support activity.
Speak with our team to scope an engagement tailored to your facility, regulatory context, and lifecycle stage.