IndustryHub
LEARN / STANDARDS / BAuA (AGS)

TRGS 725

TRGS 725

Instrumented Explosion Protection: zone reduction, ignition-source control and SIL

TRGS 725 is the German technical rule that operationalises the ATEX → SIL bridge with explicit decision tables: how reliable an instrumented measure (MSR) must be to reduce a zone or control an ignition source (classification K1/K2/K3), and how that classification maps to a SIL realised per IEC 61511. The clearest worked method even outside Germany.

Document structure

TRGS 725

Gefährliche explosionsfähige Atmosphäre — Messen, Steuern, Regeln im Rahmen von Explosionsschutzmaßnahmen

Part of the German explosion-protection TRGS family (720–727). Specifies how measuring, control and regulating (MSR) equipment is used as an explosion-protection measure: when monitoring is required, which classification level (K1/K2/K3) it must reach, and how to realise it as a functional-safety loop. Legally anchored in the German GefStoffV / BetrSichV.

Key concepts

Ex-Vorrichtung / Ex-Einrichtung
The device that implements an explosion-protection measure — e.g. the ventilation+flow-monitor that reduces a zone, or the temperature monitor that controls an ignition source. May be MSR (instrumented) or non-MSR (mechanical/passive).
MSR-Schutzeinrichtung
An instrumented (Messen-Steuern-Regeln) protective device. When it is safety-related, it is realised as a SIF loop per IEC 61511 — sensor → safety logic → final element.
Klassifizierungsstufe(K1 / K2 / K3)
The reliability grade of the Ex device (same scale as EN 50495). Derived from the base zone and the failure behaviour of the device / how often the ignition source becomes effective. K1 = HFT 0, K2 = HFT 1, K3 = HFT 2.
Resulting zone (resultierende Zone)
The zone that remains AFTER a reliable monitored measure is credited. A Zone 1 with a sufficiently reliable measure can become Zone 2 or 'no zone' — and is what must be entered on the zone plan.
Proven technology (bewährte Technik)
A pragmatic execution route: for many K1 cases and for non-MSR devices, a design in proven technology plus regular testing is sufficient — no full SIL demonstration required.
Protective device Class I (Schutzeinrichtung Klasse I)
The safety-related execution of an MSR protective device: a SIF loop per IEC 61511. For SIL 3 it must be redundant. This is the class that carries an explicit SIL.

Notes & guidance

The clearest worked method for getting from ATEX to SIL

EN 50495 gives the concept — a safety device has a classification level (K1/K2/K3) that can be demonstrated as a SIL. TRGS 725 gives the worked method: explicit decision tables that take you from a base ATEX zone, through the required classification level, to a SIL realised per IEC 61511.

It is a German technical rule (legally binding under the German GefStoffV/BetrSichV), but the engineering logic is jurisdiction-neutral and unusually clear — which is why it is worth reading even if you never set foot in a German plant. The current version is dated 5 June 2023.

Two ways an instrumented measure earns ATEX credit

TRGS 725 recognises that an MSR measure can do one of two distinct jobs, and the classification logic differs for each:

  1. Avoid the hazardous explosive atmospherereduce the zone. Ventilation, inertisation, concentration monitoring. Credited via Table 7.
  2. Avoid an effective ignition sourcecontrol the source. Temperature, speed, flow, level monitoring on equipment that could ignite. Credited via Table 8.

Either way, the reliability you must prove is expressed as a classification level, and Table 10 converts that into a SIL.

Table 7 — reducing a zone with a monitored measure

How far you may downgrade a zone depends on the failure behaviour of the Ex device (how often it fails such that the protection is lost):

Base zone (no measure)Failure behaviour of the Ex deviceResulting classificationResulting zone
Zone 0very rareK3no zone
Zone 0rareK2Zone 2
Zone 0to be expectedK1 ¹Zone 1
Zone 1rareK2no zone
Zone 1to be expectedK1 ¹Zone 2
Zone 2to be expectedK1 ¹no zone

Remark: the resulting zone is what gets entered on the zone plan.

¹ For monitoring of measures that avoid a hazardous explosive atmosphere, a design in proven technology with the general requirements (incl. regular testing) is sufficient. For non-MSR devices, proven technology incl. regular testing is sufficient — no SIL needed.

The pattern: the deeper the downgrade and the more dangerous the base zone, the higher the classification the measure must reach. Downgrading Zone 0 all the way to “no zone” demands K3; shaving Zone 2 to “no zone” only needs K1.

Table 8 — controlling an ignition source

Here the input is how often the ignition source becomes effective, read against what the zone/category already tolerates. The result is a clean diagonal:

Zone / Category (2014/34/EU)Ignition source becomes effective…Monitoring required?HFTClassification
Zone 0/20 — Cat 1G/1DneverNo
Zone 0/20 — Cat 1G/1Don a rare faultYes0K1
Zone 0/20 — Cat 1G/1Don an expected faultYes1K2
Zone 1/21 — Cat 2G/2Don a rare faultNo
Zone 1/21 — Cat 2G/2Don an expected faultYes0K1
Zone 1/21 — Cat 2G/2DcontinuouslyYes1K2
Zone 2/22 — Cat 3G/3Don an expected faultNo
Zone 2/22 — Cat 3G/3DcontinuouslyYes0K1

The logic is “how many levels of credit do you need?” A one-level gap between the source behaviour and what the zone tolerates → K1 (HFT 0); a two-level gapK2 (HFT 1). A Zone 2 device whose ignition source is only effective on an expected fault needs no monitoring — category 3 already tolerates that.

Table 10 — turning the classification into a SIL

Once a manufacturer or operator provides a functional-safety assessment (per IEC 61508, IEC 61511, IEC 62061 or EN 50495), the classification level maps one-to-one:

ClassificationSafety Integrity LevelImplementation (Class I protective device)
K1SIL 1 (or SIL_CL 1)MSR safety device — SIF loop per IEC 61511
K2SIL 2 (or SIL_CL 2)MSR safety device — SIF loop per IEC 61511
K3SIL 3 (or SIL_CL 3)Redundant MSR safety device — SIF loop per IEC 61511

So K3 is the one that forces redundant instrumentation (1oo2/2oo3 sensing, redundant logic/final elements) — the practical jump in cost and complexity. K1 and K2 are typically a single, well-engineered loop.

Two routes: proven technology vs functional safety

TRGS 725 deliberately leaves a pragmatic door open:

  • Proven technology (bewährte Technik) + regular testing. Sufficient for many K1 situations and for non-MSR (mechanical/passive) devices — explicitly per the Table 7 footnote. You document the design rationale and the test regime; you do not build a full SIL dossier.
  • Quantified functional safety (SIL). Required when the unit is complex/programmable, or when the classification is K2/K3. You run the IEC 61511 lifecycle and prove the PFD/architecture.

Choosing the right route is itself an engineering decision: over-applying SIL where proven technology is allowed wastes money; under-applying it where K2/K3 is required is a compliance gap.

End-to-end worked example — solvent dryer exhaust

A batch dryer handles a solvent; its exhaust duct is Zone 1 during normal operation. You install forced extraction with a flow monitor that trips the heating and isolates the feed if airflow drops.

  1. Goal: avoid the hazardous atmosphere in the dryer chamber → zone reduction (Table 7). Target: bring the chamber from Zone 1 toward Zone 2.
  2. Table 7: Zone 1 → resulting Zone 2 requires the device’s failure to be “to be expected” tolerable at K1; bringing it to “no zone” requires K2. Say you want “no zone” → K2 → HFT 1.
  3. Table 10: K2 → SIL 2, realised as a Class I MSR safety device — a SIF loop per IEC 61511.
  4. Design: flow sensor → safety logic → heating contactor + feed valve, single-fault safe (HFT 1), PFDavg in the SIL 2 band. Check the candidate with the PFD ↔ SIL tool.
  5. Operate: schedule proof tests; the credited “resulting zone” on the zone plan is only valid while the loop is proven and tested. Record it in the Explosion Protection Document.

Pitfalls — where it goes wrong

  • The zone plan must show the resulting zone, not the base zone — and only if the measure genuinely achieves its classification. Auditors check the loop and its test records against the claimed downgrade.
  • Mixing up the two tables. “Reduce the atmosphere” (Table 7) and “control the ignition source” (Table 8) are different jobs with different grids. Pick the one that matches what your device actually does.
  • K3 means redundant — budget for it. Discovering late that a measure needs K3 (e.g. downgrading Zone 0) turns a single loop into a redundant architecture.
  • Proven technology still needs testing. The bewährte Technik route is not “fit and forget” — the regular-testing obligation is part of what earns the credit.
  • The MSR device is in the zone. It needs its own Ex marking (IEC 60079 / ATEX) for the base zone, independent of its classification level. Reliability ≠ ignition protection.
  • Reaction time vs source dynamics. “Die Reaktionszeit der Überwachungseinrichtung muss diese Geschwindigkeit berücksichtigen” — the loop must trip before the source becomes effective; a correct SIL with too slow a response is still unsafe.
  • It’s German law, not a global standard. Outside the DACH region the method transfers, but the legal obligation is your local ATEX transposition + EN 50495 + IEC 61511. Use TRGS 725 as the clearest worked recipe, then map it to your jurisdiction.

The K2/K3 → SIL route runs the full IEC 61511 lifecycle — risk-graph, PFD calculation, proof-test scheduling, audit trail — which is exactly what the Functional Safety app on industryhub.cloud is built to manage, with Word reports in DE / EN / FR.

Applicable industries

  • Chemical & petrochemical (German and DACH plants especially)
  • Pharmaceutical & fine chemicals
  • Food, feed and grain handling (dust)
  • Solvent-based coatings and printing
  • Any operator in Germany/DACH using ventilation, inertisation or monitoring as an explosion-protection measure
  • EPC and safety engineers writing the Explosion Protection Document

References & further reading