Safety Protocols SIL3 Certified CiA 304 (SRDO)

CANopen Safety Master Stack

Contact for Availability

Description

The CANopen Safety master stack brings the CANopen Safety protocol (CiA 304 / EN 50325-5) to the controlling side of a safety network. It produces and consumes Safety-Related Data Objects (SRDOs) to exchange safe process data with one or more CANopen Safety slaves — over the very same CAN bus that already carries your standard CANopen traffic.

How the CANopen Safety master stack works

Toward every safety slave, the CANopen Safety master stack supervises SRDOs using the CiA 304 data model: dual-channel, bitwise-inverted and CRC-protected, with a configurable Safeguard Cycle Time (SCT) and Safety-Related Validation Time (SRVT). Should a telegram time out or its two channels disagree, the stack drives the application to a safe state, and the Global Failsafe Command (GFC) is available to trigger a network-wide safe reaction.

Runs alongside standard CANopen

Because the CANopen Safety master stack sits next to the standard CANopen Master stack on the same controller and the same bus, safe and non-safe data travel together on one network. That lets you layer certified safety control onto an existing CANopen controller — no second, dedicated safety bus required.

Portable and certification-ready

Shipped as a ready-to-integrate binary behind a thin hardware abstraction layer, the CANopen Safety master stack runs on any MCU, any RTOS or bare metal, free of third-party dependencies. It is assessed to SIL3 / PLe (IEC 61508 / ISO 13849) by an independent certification body and arrives with the safety manual and certification artefacts your own assessment will call for.

Where the CANopen Safety master stack is used

Safety controllers, safety PLCs and machine controllers turn to the CANopen Safety master stack whenever they have to supervise safe devices across a CANopen network. Typical deployments span machinery and robotics, mobile and off-highway equipment, and process and medical systems governed by IEC 61508 and ISO 13849 — anywhere a controller has to coordinate safe and standard data on a single CAN bus.

Standards and conformance

The CANopen Safety master stack implements CiA 304 (EN 50325-5) with SRDO producers and consumers, and is assessed to SIL3 / PLe under IEC 61508 and ISO 13849 by an independent certification body. Working side by side with the standard CANopen master, it adds certified safety supervision without a second bus. It ships with the safety manual, certificate and test reports, and is supported directly by the engineers who built and certified it.

Key Benefits

  • Certified safety control on CANopen Adds SIL3 / PLe SRDO safety communication (CiA 304) to your CANopen controller — supervise safe slaves on the existing network, with no separate safety bus.
  • Certification evidence, not a black box Ships with the safety manual, certificate and test reports your assessment requires — the evidence pack comes with the binary.
  • Portable, any MCU / RTOS A thin hardware abstraction layer keeps it independent of hardware and RTOS, with no third-party dependencies or vendor lock-in.
  • Backed by safety experts Direct access to the engineers who built and certified the stack, with 30+ years of functional-safety experience.

Key Features

  • CANopen Safety (CiA 304 / EN 50325-5) master with SRDO producer/consumer
  • SIL3 / PLe assessed by certification body
  • Supervises multiple CANopen Safety slaves
  • Safety data protected by CRC, redundancy and time monitoring
  • Runs alongside the standard CANopen Master stack on the same bus
  • Runs on any MCU / RTOS with no third-party dependencies; delivered as target binary

Complete Feature Set

Safety Communication

  • SRDO producer and consumer toward multiple safety slaves
  • Two channels with bitwise-inverted redundancy
  • SRDO CRC protection and configurable refresh / validation time
  • Safe-state entry on timeout or data mismatch

Safety Configuration

  • Safety Object Dictionary with SRDO communication / mapping parameters
  • Safety-relevant Object Dictionary CRC (0x13FE / 0x13FF)
  • Configurable SCT (Safeguard Cycle Time) and SRVT (validation time)
  • GFC (Global Failsafe Command) handling

Integration

  • Coexists with the standard CANopen Master stack on the same controller
  • Thin hardware abstraction layer for CAN / CAN FD drivers
  • Documented safety API with a sample application
  • Runs on any MCU, RTOS or bare metal

Certification

  • SIL3 / PLe assessed by certification body
  • Delivered with safety manual and certification artefacts
  • Documented binary — no black boxes
  • Backed by engineers with 30+ years in functional safety

Technical Specifications

Safety

Safety
Parameter Value
Standards CiA 304 · EN 50325-5 · IEC 61508 (SIL3) · ISO 13849 (PLe)
Role CANopen Safety master (SRDO producer / consumer)
Integrity measures Redundant channels · CRC · time monitoring (SCT / SRVT)
Assessment SIL3 / PLe by an independent certification body

Implementation

Implementation
Parameter Value
Language ANSI-C (portable)
Base protocol CANopen (CiA 301) — runs with the CANopen Master stack
CAN support Classic CAN 2.0A/B and CAN FD
Platforms Any MCU / RTOS / bare metal via HAL
Dependencies None (no third-party libraries)

Datasheet

Enter your details to download the CANopen Safety Master Stack datasheet (PDF).

Frequently Asked Questions

What does the CANopen Safety Master do?

It is the controller side of CANopen Safety per CiA 304 / EN 50325-5: it produces and consumes SRDOs to exchange safe data with CANopen Safety slaves, assessed to SIL3 / PLe by an independent certification body.

How does SRDO achieve safety over a standard CAN bus?

Each SRDO sends the safety data twice — normal and bitwise-inverted — protected by a CRC and monitored with configurable cycle and validation times (SCT/SRVT). Any timeout or mismatch drives the application to a safe state.

Can it run together with the standard CANopen Master stack?

Yes. The safety layer runs alongside the standard CANopen Master stack on the same controller and bus, so safe and non-safe data share one network.

Which microcontrollers and RTOS are supported?

It is portable ANSI-C with a thin hardware abstraction layer, so it runs on any MCU, any RTOS or bare metal, with no third-party dependencies.

What is included for certification?

You receive the target binary plus the safety manual and certification artefacts (validation plan, test results, certificate) needed to support your own SIL3 / PLe assessment.

How is it licensed and can I evaluate it?

It is delivered as a target binary under a one-off project/product licence with no per-unit royalties. Use the Request Quote button or contact contact@isit.fr for a quote or an evaluation.

Interested in this product?

Request a customized quote and our team will get back to you.

Request Quote