On a critical temperature point, a single transmitter and a single sensor are a single point of failure. When the measurement has to stay live — a reactor inlet, a compressor bearing, a reboiler — the question is how to build in redundancy. Two options come up in most specifications: a dual-channel transmitter running hot backup, or two separate single-channel transmitters wired in parallel. This compares them on the terms a project actually gets judged on: hardware cost, installed cost, availability, and what each does during a fault.
What “hot backup” does on a dual-channel transmitter
A dual-channel transmitter such as the NCS-TT306HH takes two sensors into one device. With hot backup enabled, one channel is the primary and the other is the standby. The mechanism is specific, and worth stating exactly because it determines the failover behaviour:
When PV is mapped to sensor 1, sensor 2 is the backup. If sensor 1 fails — open circuit or short circuit — and sensor 2 is healthy, the transmitter switches the PV mapping to sensor 2 automatically. The PV value becomes sensor 2’s value, and the loop current follows sensor 2. The reverse holds when PV is mapped to sensor 2. On recovery, as soon as the primary sensor reads valid again, the mapping switches back to it.
The result at the loop level: the 4–20 mA output stays continuous through a sensor failure. The control system sees one uninterrupted measurement, not a dropout and a re-acquisition. The switch happens inside the transmitter, so there is no host-side voting logic to configure.
The important boundary: this protects against sensor failure. The transmitter electronics, the loop power, and the wiring back to the marshalling cabinet are still shared. Hot backup removes the sensor as a single point of failure. It does not make the transmitter itself redundant.
What two transmitters give you instead
Two single-channel transmitters, each with its own sensor, wired as two loops into the control system, remove a different single point of failure: the transmitter. If one transmitter dies — electronics, not just its sensor — the other loop is unaffected. The trade-off is that the redundancy now lives in the host. The DCS or SIS has to receive two analog inputs and run the selection or voting logic (which value to use, when to switch, how to alarm a discrepancy).
So the two approaches protect against different failures:
| Dual-channel hot backup | Two single-channel transmitters | |
|---|---|---|
| Sensor failure | Covered, automatic in-device switchover | Covered |
| Transmitter electronics failure | Not covered (shared electronics) | Covered |
| Loop power / wiring failure | Not covered (shared) | Covered (two independent loops) |
| Failover logic | Inside the transmitter | In the DCS/SIS host |
| Analog inputs consumed | 1 | 2 |
Cost: hardware and installed
The comparison isn’t just the price of the boxes. Installed cost is where the gap usually opens.
A dual-channel transmitter keeps everything downstream of the sensor terminals single. Two transmitters double most of the line-item list. Counted out per redundant point:
| Cost element | Dual-channel | Two transmitters |
|---|---|---|
| Transmitters | 1 | 2 |
| Connection heads / enclosures | 1 | 2 |
| Cable runs to marshalling | 1 | 2 |
| AI channels consumed | 1 | 2 |
| Tags to commission | 1 | 2 |
| DCS/SIS failover config | Minimal | Required |
| Calibration / proof-test items | 1 | 2 |
| Spares to hold | 1 | 2 |
The hardware can be cheaper per unit on the two-transmitter side, but installed cost — cable, terminations, I/O count, engineering, commissioning, and documentation — is consistently higher, and it carries forward into lifecycle cost as two devices to calibrate, proof-test, and stock. On a brownfield job where spare I/O is scarce, the extra AI channel alone can be the deciding constraint.
Reliability: be precise about what you’re buying
This is where specifications go wrong, so it’s worth being exact.
Dual-channel hot backup improves availability against sensor failure. It keeps the measurement live and reduces spurious trips caused by a single dead sensor. That is a real and often underrated benefit, because nuisance trips from failed sensors are a common cause of unplanned downtime.
Two transmitters improve availability against a broader set of failures — sensor, electronics, and wiring — because the two loops are independent end to end.
Neither arrangement, by itself, sets the functional safety performance of a safety loop. If the point is part of a safety instrumented function, the SIL performance has to be evaluated across the complete function per IEC 61508 / 61511 — sensor, transmitter, logic solver, final element — and the architecture (1oo1, 1oo2, 2oo2, 2oo3) chosen against the SIL target. Redundancy and SIL are related but not the same: redundancy mostly buys availability; SIL is about controlling dangerous, undetected failure. A device being dual-channel does not, on its own, raise the SIL of the loop. (The NCS-TT306H series is separately assessed per IEC 61508: suitable for use in SIL 2 safety functions, and in SIL 3 safety functions in redundant architectures. That assessment, not the channel count, is what a safety-loop calculation uses.)
How to choose
The decision usually resolves on three questions.
What failure are you actually trying to survive? If it’s a failed sensor on a measurement you want to keep live, dual-channel hot backup covers it for the lowest installed cost. If you need to survive a transmitter failure — the electronics, not just the sensor — you need two transmitters, or a higher redundancy architecture evaluated at the loop level.
Where do you want the failover logic? In-device switchover (dual-channel) is simpler to commission and removes host configuration. Host-side voting (two transmitters) is more flexible and lets you do discrepancy alarming and 2oo3-style schemes, at the cost of complexity and I/O.
Is the point in a safety function? If yes, the architecture is driven by the SIL verification, not by convenience, and you size 1oo1 / 1oo2 / 2oo3 against the target using certified failure-rate data.
For most critical measurement availability requirements that aren’t dictated by a specific SIL architecture, dual-channel hot backup is the lower-cost, lower-I/O way to take the sensor out of the single-point-of-failure list. Where the transmitter itself has to be redundant, two devices remain the answer.
What to look for in a dual-channel transmitter
If dual-channel hot backup is the right answer for your point, the features worth checking on any candidate device are:
- Automatic sensor switchover, with defined behaviour on failure and on recovery
- Fault diagnostics and diagnostic coverage (sensor open/short, NE107-style status)
- SIL certification, where the point is in a safety function
- Hazardous-area approvals matching the area classification
- DCS integration files (EDD, FDI, DTM)
The NCS-TT306HH is one example that combines these in a single device. Its product page publishes the SIL 2 functional-safety certificate, the intrinsic-safety Ex certificate, and the CE and EMC certificates, along with the EDD, FDI, and DTM files — which are the documents to pull when you compare it against your own requirement or against another vendor.