When an application has to move safety-related data — an emergency stop, a safe torque-off, a safe position — you need more than a fast network. You need a safety protocol whose behaviour is proven and documented to a recognised standard. Two common choices are CANopen Safety and FSoE (Fail-Safe over EtherCAT).
CANopen Safety
Built on the familiar CAN bus and the CiA 304 profile, CANopen Safety adds Safety-Relevant Data Objects (SRDO) with the redundancy and monitoring needed for SIL3. It is a strong fit where CAN is already present, node counts are moderate, and cost and robustness matter more than raw bandwidth.
FSoE (Fail-Safe over EtherCAT)
FSoE (IEC 61784-3) carries safety frames over EtherCAT using a black-channel approach: the standard EtherCAT transport is treated as untrusted, and the FSoE layer detects any corruption, loss or delay. It suits high-performance machines, motion control and systems that already run EtherCAT, where you want safety and standard I/O on one wire.
How to decide
- Existing network: already on CAN → CANopen Safety; already on EtherCAT → FSoE.
- Performance: high node counts, fast cycle times and synchronisation favour FSoE.
- Cost & simplicity: CAN hardware is inexpensive and rugged; CANopen Safety keeps the bill of materials down.
- Certification: both reach SIL3 / PLe — the deciding factor is often the quality of the safety documentation you receive.
ISIT-Neperis provides both CANopen Safety and FSoE stacks, SIL3 / PLe assessed by Bureau Veritas and delivered with the evidence your own assessment requires.
Not sure which fits your device? Ask our safety engineers.
See the full side-by-side comparison : CANopen Safety vs FSoE — Choosing a SIL3 Safety Protocol