Does this temperature point require a transmitter for a SIL safety function, or is a standard temperature transmitter sufficient?
Two things people run together
The word “SIL” gets thrown around loosely, and the looseness is expensive. There are really two separate ideas underneath it.
The first is that a safety function has an SIL target. SIL runs from 1 to 4, and it describes a function, something like “close the feed valve if this temperature goes above X.” It is not a property of any single box. The target falls out of a risk assessment, usually a LOPA or a HAZOP follow-up, and it gets written into the safety requirements specification. To hit that target, the whole chain has to perform together: sensor, transmitter, logic solver, final element.
The second idea is that a device can be suitable for use inside such a loop. Strictly speaking there is no “SIL-rated transmitter” in IEC 61508 terms. What a device can have is a certificate stating it has been assessed for use in SIL safety functions, together with the evidence behind it: failure-rate data such as SFF and PFD figures, a safety manual setting out the conditions of use, and a way of failing that is predictable and announced rather than silent.
So you’re never really asking “is this transmitter SIL.” You’re asking whether the loop carries a safety function with an SIL target, and if so, whether this transmitter has been assessed and certified for use in it, with the documentation to prove it.
How to tell if your loop is in scope
Most of the time you don’t work this out yourself. It’s decided upstream and handed down, and your job is to read the signals correctly in the documents you already have. A few things to look for:
The P&ID or the cause-and-effect matrix shows the temperature point driving a trip or an interlock, not just an indication or a control action. The safety requirements specification lists that point with an SIL target next to it. The datasheet has a “safety function” field filled in, or cites IEC 61508 or 61511. The point is wired to the SIS or ESD marshalling cabinet rather than to the DCS.
If a temperature point only indicates, trends, or sits in an ordinary regulatory control loop, it is almost certainly not in SIL scope, and a standard transmitter is usually sufficient. One caveat worth knowing: some EPCs and end users impose a blanket requirement for IEC 61508-certified devices across a project, even on points that carry no SIL target of their own. So before you rule it out, check the project-wide instrument specification, not just the individual point.
What a safety-capable transmitter has to provide
If the point is in scope, the device you buy has to clear a higher bar than “it works.” Regardless of brand, a transmitter intended for a safety function should provide:
- A defined safe state it drives to on a detected fault
- A configuration lock, so the safety parameters can’t be changed silently once commissioned
- Fault diagnostics that detect the device’s own failures and signal them on the loop
- A safety manual stating the conditions of use, proof-test interval, and any constraints
- Failure-rate data (SFF, PFD, and similar) for the loop calculation
- A certificate of assessment against IEC 61508 for the relevant SIL level
The reason these matter is worth being clear about. The dangerous failure in a safety loop is the quiet one, where a transmitter dies but keeps feeding the logic solver a plausible number. The diagnostics, the safe state, and the predictable fault current are what stop that from happening. On a safety point, those count for more than another decimal place of measurement accuracy.
The administrative side gets heavier too. Configuration changes become controlled events, the SIL configuration has to be recorded, and proof tests get scheduled at intervals. None of this is hard, but it belongs in the project plan and the maintenance handover, not just on the purchase order.
A quick way to decide
Run down this list and stop at the first answer that puts the point in scope.
Does the temperature point drive a trip, an interlock, or an ESD action? If not, a standard transmitter is usually sufficient, subject to any project-wide certification requirement. Does the safety requirements spec give it an SIL target? If not, go standard, but confirm it with your safety lead first. If either answer is yes, then specify a transmitter assessed for SIL use, with fault diagnostics and a safety manual, and budget for the extra change control and proof testing that come with it.
One more check that catches people out. Is the same point also in a hazardous area? If it is, the SIL requirement sits on top of the Ex requirement, and they don’t substitute for each other. A device can be intrinsically safe and still not be assessed for a safety function, or the other way round. Confirm each one separately, on the exact model code you’re ordering.
Don’t swing the other way
The overcorrection is just as common as under-specifying, so it’s worth being blunt about it. Most temperature points in a plant are not in SIL scope. Indication, trending, and normal regulatory control don’t call for a safety-capable device, and ordering one for every point burns budget and makes the maintenance regime more complicated than it needs to be. Match the device to the point. Use a SIL-assessed device where the safety function genuinely calls for it, and a plain transmitter everywhere else.
If you’re working through the points that aren’t safety-related, our guide on how to select a HART temperature transmitter covers the ordinary criteria, sensor type, accuracy, wiring, topology, without the safety overhead.
An example: the NCS-TT306H
To make the requirements above concrete, it helps to look at how one device implements them. The NCS-TT306H Series HART Temperature Transmitter provides a dedicated SIL mode that maps onto the checklist. You enter the mode with an access code; the device runs a checksum check and a self-diagnostic, and only enters the mode if both pass. Once it’s in, the configuration locks and the diagnostic alarm levels switch to a fixed preset set, which is the configuration-lock and defined-behaviour the safety review is looking for. A SIL configuration timestamp is recorded for the audit trail.

The series also offers dual-channel hot backup. It’s worth being precise about what that does and doesn’t do: redundancy improves availability, keeping the measurement live so that one failed sensor doesn’t trip the plant when it didn’t have to. It is not the same thing as SIL performance. Availability addresses spurious trips; functional safety addresses dangerous failures, and the SIL performance of the loop must still be evaluated across the complete safety function, not inferred from the presence of a backup channel.
The device carries HART, SIL, Ex, and CE marking, so on a point that is both safety-related and in a hazardous area, the two requirements can be addressed from one model line, though as noted above you still confirm each independently against the model code.
Before you finalise the specification
If you’re evaluating a safety-related temperature loop, request the applicable safety manual, IEC 61508 certificate, and failure-rate data before finalising the specification, and check that the certified SIL level and conditions of use match what your safety function requires. Contact Microcyber for documentation specific to your selected model code.
