The clearest worked method for getting from ATEX to SIL
EN 50495 gives the concept — a safety device has a classification level (K1/K2/K3) that can be demonstrated as a SIL. TRGS 725 gives the worked method: explicit decision tables that take you from a base ATEX zone, through the required classification level, to a SIL realised per IEC 61511.
It is a German technical rule (legally binding under the German GefStoffV/BetrSichV), but the engineering logic is jurisdiction-neutral and unusually clear — which is why it is worth reading even if you never set foot in a German plant. The current version is dated 5 June 2023.
Two ways an instrumented measure earns ATEX credit
TRGS 725 recognises that an MSR measure can do one of two distinct jobs, and the classification logic differs for each:
- Avoid the hazardous explosive atmosphere → reduce the zone. Ventilation, inertisation, concentration monitoring. Credited via Table 7.
- Avoid an effective ignition source → control the source. Temperature, speed, flow, level monitoring on equipment that could ignite. Credited via Table 8.
Either way, the reliability you must prove is expressed as a classification level, and Table 10 converts that into a SIL.
Table 7 — reducing a zone with a monitored measure
How far you may downgrade a zone depends on the failure behaviour of the Ex device (how often it fails such that the protection is lost):
| Base zone (no measure) | Failure behaviour of the Ex device | Resulting classification | Resulting zone |
|---|
| Zone 0 | very rare | K3 | no zone |
| Zone 0 | rare | K2 | Zone 2 |
| Zone 0 | to be expected | K1 ¹ | Zone 1 |
| Zone 1 | rare | K2 | no zone |
| Zone 1 | to be expected | K1 ¹ | Zone 2 |
| Zone 2 | to be expected | K1 ¹ | no zone |
Remark: the resulting zone is what gets entered on the zone plan.
¹ For monitoring of measures that avoid a hazardous explosive atmosphere, a design in proven technology with the general requirements (incl. regular testing) is sufficient. For non-MSR devices, proven technology incl. regular testing is sufficient — no SIL needed.
The pattern: the deeper the downgrade and the more dangerous the base zone, the higher the classification the measure must reach. Downgrading Zone 0 all the way to “no zone” demands K3; shaving Zone 2 to “no zone” only needs K1.
Table 8 — controlling an ignition source
Here the input is how often the ignition source becomes effective, read against what the zone/category already tolerates. The result is a clean diagonal:
| Zone / Category (2014/34/EU) | Ignition source becomes effective… | Monitoring required? | HFT | Classification |
|---|
| Zone 0/20 — Cat 1G/1D | never | No | – | – |
| Zone 0/20 — Cat 1G/1D | on a rare fault | Yes | 0 | K1 |
| Zone 0/20 — Cat 1G/1D | on an expected fault | Yes | 1 | K2 |
| Zone 1/21 — Cat 2G/2D | on a rare fault | No | – | – |
| Zone 1/21 — Cat 2G/2D | on an expected fault | Yes | 0 | K1 |
| Zone 1/21 — Cat 2G/2D | continuously | Yes | 1 | K2 |
| Zone 2/22 — Cat 3G/3D | on an expected fault | No | – | – |
| Zone 2/22 — Cat 3G/3D | continuously | Yes | 0 | K1 |
The logic is “how many levels of credit do you need?” A one-level gap between the source behaviour and what the zone tolerates → K1 (HFT 0); a two-level gap → K2 (HFT 1). A Zone 2 device whose ignition source is only effective on an expected fault needs no monitoring — category 3 already tolerates that.
Table 10 — turning the classification into a SIL
Once a manufacturer or operator provides a functional-safety assessment (per IEC 61508, IEC 61511, IEC 62061 or EN 50495), the classification level maps one-to-one:
| Classification | Safety Integrity Level | Implementation (Class I protective device) |
|---|
| K1 | SIL 1 (or SIL_CL 1) | MSR safety device — SIF loop per IEC 61511 |
| K2 | SIL 2 (or SIL_CL 2) | MSR safety device — SIF loop per IEC 61511 |
| K3 | SIL 3 (or SIL_CL 3) | Redundant MSR safety device — SIF loop per IEC 61511 |
So K3 is the one that forces redundant instrumentation (1oo2/2oo3 sensing, redundant logic/final elements) — the practical jump in cost and complexity. K1 and K2 are typically a single, well-engineered loop.
Two routes: proven technology vs functional safety
TRGS 725 deliberately leaves a pragmatic door open:
- Proven technology (bewährte Technik) + regular testing. Sufficient for many K1 situations and for non-MSR (mechanical/passive) devices — explicitly per the Table 7 footnote. You document the design rationale and the test regime; you do not build a full SIL dossier.
- Quantified functional safety (SIL). Required when the unit is complex/programmable, or when the classification is K2/K3. You run the IEC 61511 lifecycle and prove the PFD/architecture.
Choosing the right route is itself an engineering decision: over-applying SIL where proven technology is allowed wastes money; under-applying it where K2/K3 is required is a compliance gap.
End-to-end worked example — solvent dryer exhaust
A batch dryer handles a solvent; its exhaust duct is Zone 1 during normal operation. You install forced extraction with a flow monitor that trips the heating and isolates the feed if airflow drops.
- Goal: avoid the hazardous atmosphere in the dryer chamber → zone reduction (Table 7). Target: bring the chamber from Zone 1 toward Zone 2.
- Table 7: Zone 1 → resulting Zone 2 requires the device’s failure to be “to be expected” tolerable at K1; bringing it to “no zone” requires K2. Say you want “no zone” → K2 → HFT 1.
- Table 10: K2 → SIL 2, realised as a Class I MSR safety device — a SIF loop per IEC 61511.
- Design: flow sensor → safety logic → heating contactor + feed valve, single-fault safe (HFT 1), PFDavg in the SIL 2 band. Check the candidate with the PFD ↔ SIL tool.
- Operate: schedule proof tests; the credited “resulting zone” on the zone plan is only valid while the loop is proven and tested. Record it in the Explosion Protection Document.
Pitfalls — where it goes wrong
- The zone plan must show the resulting zone, not the base zone — and only if the measure genuinely achieves its classification. Auditors check the loop and its test records against the claimed downgrade.
- Mixing up the two tables. “Reduce the atmosphere” (Table 7) and “control the ignition source” (Table 8) are different jobs with different grids. Pick the one that matches what your device actually does.
- K3 means redundant — budget for it. Discovering late that a measure needs K3 (e.g. downgrading Zone 0) turns a single loop into a redundant architecture.
- Proven technology still needs testing. The bewährte Technik route is not “fit and forget” — the regular-testing obligation is part of what earns the credit.
- The MSR device is in the zone. It needs its own Ex marking (IEC 60079 / ATEX) for the base zone, independent of its classification level. Reliability ≠ ignition protection.
- Reaction time vs source dynamics. “Die Reaktionszeit der Überwachungseinrichtung muss diese Geschwindigkeit berücksichtigen” — the loop must trip before the source becomes effective; a correct SIL with too slow a response is still unsafe.
- It’s German law, not a global standard. Outside the DACH region the method transfers, but the legal obligation is your local ATEX transposition + EN 50495 + IEC 61511. Use TRGS 725 as the clearest worked recipe, then map it to your jurisdiction.
The K2/K3 → SIL route runs the full IEC 61511 lifecycle — risk-graph, PFD calculation, proof-test scheduling, audit trail — which is exactly what the Functional Safety app on industryhub.cloud is built to manage, with Word reports in DE / EN / FR.