Safety Protocols SIL3 Certified CiA 304 (SRDO)

CANopen Safety Slave Stack

Contact for Availability

Description

The CANopen Safety slave stack implements the CANopen Safety protocol (CiA 304 / EN 50325-5) on the device side of a safety network. It adds Safety-Related Data Objects (SRDOs) on top of standard CANopen so a device can exchange safe process data with the integrity required for functional safety, on the same CAN bus.

How the CANopen Safety slave stack works

Each SRDO carries the safety data twice — normal and bitwise-inverted — protected by a CRC and monitored with configurable Safeguard Cycle Time (SCT) and validation time (SRVT). If a timeout or a data mismatch occurs, the CANopen Safety slave stack drives the application to a safe state. It also supports the Global Failsafe Command (GFC) and a safety Object Dictionary with the SRDO communication and mapping parameters.

Runs alongside standard CANopen

The CANopen Safety slave stack coexists with the standard CANopen Slave stack on the same node and the same bus, so safe and non-safe data share one network. There is no need for a separate safety bus, which keeps device cost and wiring down while still reaching SIL3 / PLe integrity.

Portable and certification-ready

Delivered as a ready-to-integrate binary with a thin hardware abstraction layer, the CANopen Safety slave stack runs on any MCU, any RTOS or bare metal, with no third-party dependencies. It is assessed to SIL3 / PLe (IEC 61508 / ISO 13849) by an independent certification body and delivered with the safety manual and certification artefacts your own assessment requires.

Applications

The CANopen Safety slave stack suits safe sensors, safe actuators, safe drives and safe I/O modules that need to exchange safety data on a CANopen network. It is used in machinery, robotics, mobile and off-highway equipment, medical and process applications governed by IEC 61508 and ISO 13849, where a device must be both a standard CANopen node and a safety participant.

Standards and conformance

The CANopen Safety slave stack implements CiA 304 (EN 50325-5) for SRDO-based safety and is assessed to SIL3 / PLe under IEC 61508 and ISO 13849 by an independent certification body. Because it runs alongside the standard CANopen stack, you keep one bus and one wiring while adding a certified safety layer. It ships with the safety manual, certificate and test reports, and is supported by the engineers who developed and certified it.

Key Benefits

  • Certified safety on CANopen Adds SIL3 / PLe SRDO safety communication (CiA 304) on top of your existing CANopen network — no separate safety bus required.
  • Certification evidence, not a black box Ships with the safety manual, certificate and test reports your assessment requires — the evidence pack comes with the binary.
  • Portable, any MCU / RTOS A thin hardware abstraction layer keeps it independent of hardware and RTOS, with no third-party dependencies or vendor lock-in.
  • Backed by safety experts Direct access to the engineers who built and certified the stack, with 30+ years of functional-safety experience.

Key Features

  • CANopen Safety (CiA 304 / EN 50325-5) SRDO producer and consumer
  • SIL3 / PLe assessed by certification body
  • Safety data protected by CRC, redundancy and time monitoring
  • Runs alongside the standard CANopen Slave stack on the same bus
  • Configurable safety Object Dictionary with SRDO mapping
  • Any MCU / RTOS, no third-party dependencies

Complete Feature Set

Safety Communication

  • SRDO (Safety-Related Data Object) producer and consumer
  • Two channels with bitwise-inverted redundancy
  • SRDO CRC protection and configurable refresh / validation time
  • Safe-state entry on timeout or data mismatch

Safety Configuration

  • Safety Object Dictionary with SRDO communication / mapping parameters
  • Safety-relevant Object Dictionary CRC (0x13FE / 0x13FF)
  • Configurable SCT (Safeguard Cycle Time) and SRVT (validation time)
  • GFC (Global Failsafe Command) support

Integration

  • Thin hardware abstraction layer for CAN / CAN FD drivers
  • Documented safety API with a sample application
  • Runs on any MCU, RTOS or bare metal

Technical Specifications

Safety

Safety
Parameter Value
Standards CiA 304 · EN 50325-5 · IEC 61508 (SIL3) · ISO 13849 (PLe)
Safety objects SRDO producer / consumer · GFC
Integrity measures Redundant channels · CRC · time monitoring (SCT / SRVT)
Assessment SIL3 / PLe by an independent certification body

Implementation

Implementation
Parameter Value
Base protocol CANopen (CiA 301) — runs with the CANopen Slave stack
CAN support Classic CAN 2.0A/B and CAN FD
Platforms Any MCU / RTOS / bare metal via HAL
Dependencies None (no third-party libraries)

Datasheet

Enter your details to download the CANopen Safety Slave Stack datasheet (PDF).

Frequently Asked Questions

What safety standard does the CANopen Safety Slave implement?

It implements CANopen Safety per CiA 304 / EN 50325-5 using Safety-Related Data Objects (SRDOs), and is assessed to SIL3 / PLe (IEC 61508 / ISO 13849) by an independent certification body.

How does SRDO achieve safety over a standard CAN bus?

Each SRDO sends the safety data twice — normal and bitwise-inverted — protected by a CRC and monitored with configurable cycle and validation times (SCT/SRVT). Any timeout or mismatch drives the application to a safe state.

Can it run together with the standard CANopen stack?

Yes. The safety layer runs alongside the standard CANopen Slave stack on the same node and the same bus, so safe and non-safe data share one network.

Which microcontrollers and RTOS are supported?

It is portable ANSI-C with a thin hardware abstraction layer, so it runs on any MCU, any RTOS or bare metal, with no third-party dependencies.

What is included for certification?

You receive the target binary plus the safety manual and certification artefacts (validation plan, test results, certificate) needed to support your own SIL3 / PLe assessment.

How is it licensed and can I evaluate it?

It is delivered as a target binary under a one-off project/product licence with no per-unit royalties. Use the Request Quote button or contact contact@isit.fr for a quote or an evaluation.

Interested in this product?

Request a customized quote and our team will get back to you.

Request Quote