IndustryHub
LEARN / STANDARDS / CENELEC

EN 50495

EN 50495

Safety Devices for Ignition Risk (the bridge from ATEX to SIL)

EN 50495 specifies how reliable a safety device must be when it is the measure that keeps Ex equipment within its ignition-protection limits. It defines classification levels K1/K2/K3 and maps them to SIL — the missing link between the ATEX category (IEC 60079 / 2014/34/EU) and functional safety (IEC 61508/61511).

Document structure

EN 50495:2010

Safety devices required for the safe functioning of equipment with respect to ignition risks

The single document. Defines the role of a 'safety device' that keeps an item of equipment inside its rated ignition-protection envelope, the classification levels (K1/K2/K3) with the associated hardware fault tolerance, and the route to demonstrate them via functional safety (SIL). Harmonised under ATEX 2014/34/EU.

Key concepts

Safety device
A device (usually instrumented — sensor + logic + actuator) that detects when equipment is about to leave its safe ignition-protection state and forces it back to a safe condition. Example: a temperature switch that trips a pump before its surface reaches the gas auto-ignition temperature.
Classification level(K1 / K2 / K3)
The reliability grade EN 50495 assigns to a safety device. K1 = lowest, K3 = highest. The required level is derived from the Equipment Protection Level / ATEX category of the equipment AND how often the ignition source would otherwise become effective.
Hardware Fault Tolerance(HFT)
Number of faults the device can tolerate and still perform its safety function. K1 → HFT 0 (single channel, 1oo1). K2 → HFT 1 (single-fault safe, e.g. 1oo2). K3 → HFT 2 (double-fault safe, e.g. 1oo3).
Equipment Protection Level(EPL)
Ga/Gb/Gc (gas), Da/Db/Dc (dust), defined in IEC 60079-0. EPL is the input to EN 50495: it states how rarely the equipment may become an ignition source, which sets how reliable the safety device must be.
SIL / SIL claim limit(SIL / SIL_CL)
EN 50495 lets you demonstrate K1/K2/K3 through functional safety: K1↔SIL 1, K2↔SIL 2, K3↔SIL 3. SIL applies to the whole safety function; SIL_CL (SIL claim limit, IEC 62061) is the maximum SIL a given subsystem architecture may claim.
Control of ignition source 'b'
For non-electrical (mechanical) equipment, EN ISO 80079-37 defines protection type 'b' — control of ignition sources — with levels b1 and b2. EN 50495 supplies the reliability requirements for the instrumented control that 'b' relies on.

Notes & guidance

The standard that tells you how good your safety device has to be

ATEX tells you what protection level equipment needs in a given zone. IEC 60079 tells you which ignition-protection method (Ex d, Ex ia, etc.) delivers it. Neither tells you how reliable a device must be when that device is itself the protection — when a temperature switch, a flow guard or a speed monitor is the thing standing between normal operation and an ignition source.

That gap is exactly what EN 50495 fills. Its title is literal: Safety devices required for the safe functioning of equipment with respect to ignition risks. It is the bridge between explosion protection and functional safety — the document that converts an ATEX/EPL requirement into a measurable reliability target (a classification level), and then lets you demonstrate that target as a SIL.

If you have ever seen a pump nameplate that says “permitted in Zone 1 provided the surface temperature monitoring is active”, EN 50495 is the standard behind that sentence.

The problem it solves

Two situations make a safety device the protection itself:

  1. Zone reduction. You install a monitored measure (e.g. forced ventilation with a flow monitor, or inertisation with an O₂ analyser) so the dangerous atmosphere becomes less likely. If the measure is reliable enough, the resulting zone is lower than the base zone — and you may use cheaper equipment in it.
  2. Control of an ignition source. The equipment itself can become an ignition source (a bearing overheating, a coupling running dry, a fan over-speeding). A monitor detects the precursor and forces a safe state before ignition is possible. For mechanical equipment this is protection type “b” of EN ISO 80079-37, levels b1/b2 — and the instrumented part of “b” is graded by EN 50495.

In both cases the question is the same: how good must the monitoring be? Too weak and you have a paper safeguard; over-specified and you waste money on redundancy you do not need.

Classification levels K1 / K2 / K3

EN 50495 answers with three reliability grades, each tied to a hardware fault tolerance:

LevelHardware Fault ToleranceTypical architectureMeaning
K1HFT 01oo1 (single channel)A single dangerous fault may defeat it. Acceptable where the ignition source is only present after a rare fault, or via proven technology + regular testing.
K2HFT 11oo2 / 2oo3Single-fault safe: one dangerous fault must not defeat the safety function.
K3HFT 21oo3Double-fault safe: two faults in combination must not defeat it. The highest grade.

The required level rises with two inputs: the EPL/ATEX category of the equipment (how rarely it may ignite) and how often the ignition source would otherwise become effective (never / on a rare fault / on an expected fault / continuously). The German rule TRGS 725 turns this into explicit decision tables — see that page for the worked grids.

From classification to SIL

A classification level is a reliability requirement; SIL is how you prove you met it. EN 50495 (and TRGS 725, Table 10) give a one-to-one map:

ClassificationDemonstrate asImplementation
K1SIL 1 (or SIL_CL 1)Safety-related MSR device — a single instrumented safety function (SIF) per IEC 61511.
K2SIL 2 (or SIL_CL 2)Single SIF loop, single-fault safe, per IEC 61511.
K3SIL 3 (or SIL_CL 3)Redundant MSR safety device, SIF loop per IEC 61511.

Two routes are legitimate:

  • Proven technology (bewährte Technik) + documented regular testing. For K1 / simple, non-programmable devices this can be enough — you do not need a full SIL dossier. This is the pragmatic route TRGS 725 explicitly allows for many cases.
  • Quantified functional safety: a SIL demonstration per IEC 61508 (generic), IEC 61511 (process), or IEC 62061 (machinery). Mandatory once the unit is complex/programmable or the required level is high.

Use the PFD ↔ SIL converter and the RRF ↔ SIL tool to check a candidate architecture against the SIL band before committing to the full calculation.

Worked example — a Zone 1 vacuum pump

A liquid-ring vacuum pump is rated for Zone 1 gas, group IIB, temperature class T3 (≤ 200 °C) only while a surface-temperature monitor is active (a common entry in real ATEX manuals).

  1. EPL / category: Zone 1 → category 2G → EPL Gb. The hot surface may become an ignition source on an expected fault (loss of sealing liquid → dry running → rapid heat-up).
  2. Required classification: from the ignition-source grid this lands at K1 → HFT 0 (one level of credit needed). Higher demand profiles push to K2.
  3. Function: “detect body temperature ≥ 90 °C pre-alarm, ≥ 100 °C trip → de-energise the motor (safe torque off) within the process safety time.”
  4. Demonstrate: a single SIF loop (Ex-rated Pt100 → safety logic → motor contactor/STO), proven to SIL 1 per IEC 61511 — or proven technology + regular proof testing if the device qualifies.
  5. Timing: the loop’s response must be faster than the heat-up rate — a SIL number alone does not guarantee this; the process safety time is a separate, mandatory check.

Where engineers get it wrong

  • “Ex-rated” ≠ “SIL-rated”. Ex d / Ex ia (IEC 60079) describes the ignition protection of the device itself — it says nothing about the reliability of its safety function. A SIL 2 transmitter can be the wrong Ex type; an Ex-certified sensor can be SIL-incapable. They are orthogonal axes and you need both.
  • The monitor sits in the zone too. The safety device is usually installed in the hazardous area, so it must also carry suitable Ex marking for that zone — otherwise the protection is itself a potential ignition source.
  • Reaction time is not in the SIL. “Die Reaktionszeit der Überwachungseinrichtung muss diese Geschwindigkeit berücksichtigen” — the loop must act before the ignition source becomes effective. Verify the full process safety time, not just PFD.
  • Grade the whole chain. Sensor + logic + final element all count; the weakest element governs the achievable K/SIL. A SIL 2 sensor behind a 1oo1 relay is a K1 function.
  • You cannot just declare K2/K3. Complex (programmable) units at K2/K3 require an evidenced reliability assessment by the manufacturer or operator — not a self-assigned label.
  • Don’t double-count zone reduction. A measure only earns the lower resulting zone if the monitoring actually achieves the required classification and is tested on schedule. Skip the testing regime and the credit evaporates.

How EN 50495 sits among the other standards

StandardAnswers…
IEC 60079 / ATEX 2014/34/EUWhich ignition protection / category the equipment needs in a zone.
EN ISO 80079-37 (type “b”, b1/b2)How mechanical equipment controls its ignition sources.
EN 50495How reliable the (instrumented) safety device controlling that ignition source must be — and how to grade it (K1/K2/K3).
IEC 61508 / IEC 61511 / IEC 62061How to design, verify and operate that device as a SIL-rated safety function.
TRGS 725The German implementation: explicit decision tables zone → K → SIL.

The Functional Safety app on industryhub.cloud runs the IEC 61511 lifecycle that the K2/K3 → SIL route requires: risk-graph assistant, PFD engine per IEC 61508-6, proof-test scheduling and audit trail — the evidence base EN 50495 expects for a Class I protective device.

Applicable industries

  • Chemical & petrochemical (pumps, compressors, agitators in zones)
  • Oil & Gas (rotating machinery, vacuum systems)
  • Pharmaceutical & fine chemicals (solvent handling, dryers)
  • Food & feed, grain handling (dust zones, mills, mechanical conveyors)
  • Equipment manufacturers needing to certify mechanical Ex equipment
  • Plant operators reducing zones or controlling ignition sources by instrumentation

References & further reading