The first decision in an IO-Link Safety implementation is not the master model. It is which hazards each light curtain, safety gate, emergency stop and drive stop function controls, and whether the changed machine will still meet its required safety performance and stopping behaviour. Receiving a safety signal does not, by itself, validate the complete machine safety function.
A Thai factory often cannot replace every installed machine at once. Procurement should therefore distinguish machines that retain their OSSD devices, machines that migrate to IO-Link Safety devices, and machines that only add standard IO-Link for diagnostics. This guide connects the site survey, RFP, factory acceptance test (FAT), site acceptance test (SAT) and lifecycle plan. Qualified personnel must design and validate each safety function against the machine risk assessment and the exact product safety manuals.
Procure a testable safety function, not merely a communication interface
Standard IO-Link provides point-to-point communication with sensors and actuators. IO-Link Safety adds a safety-related communication layer using IO-Link as a black channel. The IO-Link Community technology page describes FS-Masters and FS-Devices, simultaneous safety and standard data, and possible OSSD-capable ports for migration. IEC 61139-2:2022 specifies functional safety extensions to IEC 61131-9 SDCI, including an OSSDe interface, safety communication and configuration mechanisms. It explicitly excludes integration into higher-level fieldbuses and functional safety communication profiles (FSCPs) from its scope.
An “IO-Link Safety capable” line in a quotation does not explain the complete route to the safety PLC, final switching element or machine stop. Draw the chain from sensing device, port, safety master and upper-level safety protocol to safety PLC, contactor or drive and hazardous motion. For each element, document what it monitors, which faults it detects and which safe state follows a fault.
Do not copy a product brochure’s maximum performance rating to the completed machine. ISO 13849-1:2023 addresses the design and integration of safety-related control systems. ISO 13849-2:2012 addresses validation of specified functions and achieved category and performance level through analysis and testing. The required level follows the machine-specific risk assessment. A protocol capability is not an acceptance certificate for an assembled safety function.
Separate specification certification from product certification
The IO-Link Community news page reports TÜV SÜD certification of specification V1.1.4 and the start of testing of masters and devices. That announcement does not certify every part number, firmware release or master/device combination. Request a certificate number, covered models and versions, applicable standards, restrictions, safety manual and certification scope for each item. Check supply and support in the purchasing country and the exact upper-level safety interface separately.
The Community download page lists Safety Systems Extensions V1.1.5 and Safety Test Specification V1.1.5 in its released 2025 package. Its 2026 package is marked REVIEW. Freeze the referenced edition in the RFP; do not treat a review draft as a released compliance requirement. Recheck its status and the editions covered by product certificates before placing an order.
Build a safety-function register before selecting hardware
A drawing labelled “safety door” or “light curtain” may not reveal which motion it stops, how it resets, or whether years of modifications have changed the actual installation. Create a register by machine and hazard zone:
| Register field | Site question | Acceptance evidence |
|---|---|---|
| Hazard and access | Who enters for setup, cleaning, jam removal and production? | Approved risk-assessment revision |
| Detection | Device model, location, circuit and fault monitoring? | Wiring drawing, manual and inspection |
| Logic | Safety PLC/relay version, assignments, reset, muting? | Program revision and change history |
| Final element | Which contactor, STO or valve removes the hazard? | Circuit drawing and stop test |
| Required performance | Basis for PL/SIL, response time and stopping distance? | Calculation and measured validation |
| Restart | Who resets after a door closes or power returns? | Scenario test record |
Record nameplates, installed wiring and actual stopping action, not only old drawings. Resolve discrepancies before proposing a new connection. An unsafe workaround used by operators is a risk-reduction issue; it cannot be hidden inside a “communications upgrade.”
Separate a desire for better fault messages from a need to change a protective function. If diagnostics alone are required, keeping a validated OSSD circuit while reading a manufacturer-approved status output may be the better option. Our standard IO-Link sensor integration guide covers IODDs and ordinary data collection. This article addresses changes to the protective path and their validation.
Three migration architectures
A. Retain the existing safety circuit; add diagnostics separately
Keep the installed OSSD device, safety relay or safety PLC input, and stop output. Read diagnostic information from an approved independent output or monitoring point. This can suit a short shutdown window where no sensor replacement is needed. Never tap a safety output casually: an added load, changed test pulse, shared supply or wiring fault may change the safety behaviour. The manufacturer manual and the safety designer must approve the connection. “Monitoring only” does not automatically mean “no safety impact.”
B. Mix existing OSSD and new IO-Link Safety devices on a suitable master
Convert selected devices while connecting remaining OSSD devices to ports that explicitly support them. This is product-specific. The Community says an FS-Master can offer OSSD-capable ports; it does not say every port on every master does. Pilz’s PDP67 announcement is one example describing IO-Link Safety ports, configurable safe I/O and conventional OSSD sensors. Check the exact model’s port class, quantity, direction, current rating, test-pulse behaviour and short-circuit detection.
A mixed estate contains OSSD, IO-Link Safety, standard IO-Link and an upper safety network at the same time. Do not manage it by connector colour alone. Map machine, port, safety-function ID, allowed device model and version, configuration checksum, PLC variable and acceptance test case one-to-one. This register is especially valuable during maintenance replacement.
C. Replace devices and master as a verified system
Replace selected light curtains or gate devices with IO-Link Safety-capable products and redesign the segment to the safety master. Pilz lists PDP67 IOLS, PSENopt II Advanced IOLS and PITgatebox IOLS as a product-family example. Obtain compatibility documents for the proposed combination, actual certificates, safety manuals, dedicated tools, country availability and lead times. A public product page is not a promise of immediate availability in Thailand.
A full replacement may simplify wiring and diagnostics, but can also change stopping distance, muting, gate unlocking and reset position. Complete the updated risk assessment and validation plan before setting an installation date. Remove legacy hardware only after as-built drawings and maintenance training are complete.
Worked register example: a packaging conveyor
Suppose a light curtain detects a hand entering the hazardous conveyor area and initiates a drive stop. The register must say more than “beam blocked, motor stops.” Record the hazard zone, approach direction, normal passage of product, setup mode and cleaning method. Trace both installed OSSD channels through their terminals to the safety PLC and from its output to the drive STO or contactor. Confirm whether the reset button gives a clear view of the whole area and that clearing the beam does not restart motion.
For a replacement proposal, add the exact IO-Link Safety curtain/master combination, upper safety link and tool revisions. Map every open-circuit, cross-short and device fault detected by the old circuit to a detection method in the new design. Break the stop-time budget down from sensing through mechanical stopping. If product passage requires muting, test its enabling conditions, timing, wrong sequence and recovery after power loss separately. A more detailed fault screen is not a substitute for this validation. FAT covers blocked beam, removed device, upper-link failure and wrong parameters; SAT measures real stopping and reset. Deliver the register, certificates, backup and test records under one safety-function ID so future replacement has a clear approval and retest path.

Specify the joint between the Safety Master and upper safety PLC
The point-to-point segment is only one part of the plant. The master’s communication method to the safety controller, and the existing PLC’s support for that method and version, can determine cost and downtime. Because IEC 61139-2 does not cover upper fieldbus/FSCP integration, verify that joint using the exact master/gateway documentation and safety manuals.
Give bidders the installed safety PLC make, model and firmware; safety network and protocol; I/O count; cycle and watchdog requirements; engineering-tool version; licences; and change-control limits. Require each bidder to identify the implemented route, compatibility evidence, certification scope, safe state on failure, diagnostic code meaning and recovery procedure. If the installed PLC cannot directly integrate, compare a certified appropriate gateway, controller replacement and architecture A. A gateway that only translates ordinary data must never be assumed suitable for a safety path.
Separate safety decisions from ordinary diagnostics even when both travel on one cable. The safety PLC implements the protective action inside its validated architecture; a MES or cloud dashboard supports maintenance and analysis. Delayed events in an IT system cannot replace a protective stop. For general PLC data interfaces and network boundaries, see our PLC data collection guide.
Check the real cable route before claiming savings
A field master near the machine may reduce individual cables to the cabinet, but it needs power, safety network cabling, suitable connectors, protection and maintenance access. Compare current and proposed routes on an installation drawing. Check motion, washing, welding noise, temperature, oil and vibration against the device’s protection and cable specifications. A statement that standard cable is possible applies only within the product safety manual’s allowed lengths and installation conditions.
The installation specification should address connector identification, bending radius, sealing and spare parts. A successful data link does not prove that a technician cannot restore the wrong safety configuration later.
Six differences to examine when migrating from OSSD
- Fault detection. Record how the old circuit uses redundant outputs, test pulses and cross-short detection. Convert each expected detection into a test for the proposed port or its alternative diagnostic mechanism.
- Reset and restart. After the field clears, a gate closes or power returns, prove that hazardous motion cannot restart unexpectedly. Never accept a configuration-tool default as a substitute for the required behaviour.
- Response and stopping distance. Account for sensor detection, IO-Link Safety segment, master, upper network, safety PLC, output and mechanical stopping time. A catalogued communication cycle is not the complete response time. Define limits before installation and measure on site.
- Muting, blanking and bypass. Document who can enable each exception, under which mode and conditions, and what happens on a fault. Recheck the hazard and operating mode rather than transferring settings without review.
- Parameters and replacement. The Community describes a Dedicated Device Tool in addition to the IODD for safety-function parameters. Define approved configuration versions and checksums, access rights and tests after replacement. Plugging in a spare is not proof of identical protection.
- Failure and recovery messages. Distinguish intrusion, device fault, communication loss, master power loss and configuration mismatch. Better diagnostics can support maintenance, but cannot stand in for the required safety performance or controlled restart.
Give every bidder the same RFP response sheet
| Topic | Plant input | Bidder evidence |
|---|---|---|
| Scope | Machine list, zones and modification limits | Included/excluded scope and survey assumptions |
| Safety requirement | Risk assessment and required performance | Function architecture, calculations and responsible validator |
| Devices | Existing OSSD, relay and PLC models | Exact proposed models, certificates and manuals |
| Ports | Current wiring and capacity | Count and restrictions for Safety/OSSD/standard modes |
| Upper link | PLC, protocol and software | Safety-protocol compatibility, added equipment and licences |
| Configuration | Access and approval process | Tool, version control, backup and recovery |
| Acceptance | Shutdown window and zone restrictions | FAT/SAT cases, measurement method and criteria |
| Operations | Spare and local technician needs | Warranty, supply, training and change support |
Break cost into hardware, electrical work, cabling, network, safety PLC changes, software and licences, survey, risk-assessment update, FAT, SAT, shutdown support, training, spares and maintenance. State quantities and conditions for variations. Replace advertised “wiring savings” or “commissioning savings” with a site work breakdown and test evidence. Assess dependence on a single product family and realistic replacement supply.
Procurement alone should not approve a change to a safety function. Production, maintenance, electrical engineering, EHS, IT/OT and the machine builder need assigned review and sign-off roles. Contract deliverables should include configuration files, safety calculations, certificates, drawings, results and training records.
FAT: test failures before installation
FAT must go beyond a normal-operation demonstration. For each safety-function ID, vary the input and follow the logic, output state, diagnostics and reset condition. Mechanical stopping distance still needs SAT, but FAT can find wiring, configuration, protocol and logic defects first.
| FAT case | Injected condition | Evidence |
|---|---|---|
| Protective actuation | Curtain blocked, gate opened, E-stop operated | Required safe output and manual reset |
| Port fault | Device unplugged, power lost, communication interrupted | Fault recognition, safe state and distinct message |
| Wrong connection | Unapproved device or port | Rejection, alarm and protective action |
| Upper link failure | Safety network cut or PLC restarted | Behaviour within designed monitoring time; controlled return |
| Unauthorized setting | Wrong parameter or version | Detection, rights, log and restoration |
| Exceptional mode | Permitted muting or bypass | No activation outside conditions; safe exit |
Derive numerical pass limits from the risk assessment, device manuals and design calculation, not a universal number in an article. Record date, machine and function ID, configuration revision, calibrated instrument, measured result, verdict, witnesses and open issues. A failed case remains open until its correction and repeat test are documented.

SAT: prove the installed stop and the maintenance procedure
SAT is not a photocopy of FAT. Cable lengths, electrical noise, network load, power restoration, machine inertia, operator location and line of sight must be checked in the plant. Before testing, define access restrictions, energy isolation, test leader, emergency contact and recovery sequence. Conduct tests without exposing people to hazardous motion.
Compare the as-built drawing with the actual connections and map every port to its function ID. Measure stopping time or distance under the design conditions. Test alternative actuation positions and concurrent inputs. Exercise upper-network interruption, master power loss, device replacement, approved configuration restoration and restart prevention. Verify the human procedure for confirming that no one remains in a hazard zone before returning to production.
A local technician should identify an approved spare, connect it to the correct port, confirm its settings and perform the required safety tests. Procedures and authority must be understandable in the local working language. The contractually accountable person approves the completed safety validation and any conformity statement based on the full evidence set.
Stage the rollout with clear gates
Survey: Gather asset lists, incident history, drawings, modifications and nameplates. Trace each function from sensor to final element. Existing standard IO-Link investments do not certify safety use. Select a representative pilot with real OSSD/PLC and downtime constraints, not simply the newest machine.
Design: Compare retained circuit, mixed system and replacement against shutdown time, safety change, validation effort, spares and maintenance capability. Include risk-assessment revisions and retesting in the estimate. State which benefits a partial deployment can deliver while awaiting other components.
Acceptance: Put design review, certificate check, FAT, installation inspection, SAT, training and final drawings behind named approval gates. Decide before work begins which safety defects are hard stops. Keep cosmetic diagnostic requests separate from permission to operate.
Operations: Treat firmware, tool, PLC-program and upper-protocol changes as controlled changes. Check whether the certificate and tested combination still cover replacements. Rehearse backup restoration and maintain the mapping from displayed faults to actual safe states.

Additional procurement conditions for Thai factories
Plant staff, a machine builder, overseas vendor and headquarters engineers may use different languages. Tie the Thai operating procedure, English or Japanese design package and signed test results to the same safety-function IDs. Keep “stop request,” “safe state,” “isolation” and “permission to reset” distinct in a controlled glossary. Confirm the applicable Thai installation, import and customer-audit requirements for the particular project; this article cannot certify local legal compliance.
Assign which party updates the machine documentation, which integrates and tests the interface, and which owns operation and maintenance. Require configuration backups and evidence to remain accessible to the plant if a contractor changes. For remote support, separate diagnostic viewing from safety-setting changes; define approval windows, logs and emergency disconnection. Cybersecurity controls and machine safety validation both need review.
Frequently asked questions
Can we remove OSSD devices as soon as an IO-Link Safety Master is installed?
No. Check whether the exact master ports support them, how existing fault detection and stopping behaviour are preserved, and what risk-assessment update and tests each function requires. Retaining OSSD may be the correct staged option.
Can an ordinary IO-Link sensor perform a safety function?
Ordinary IO-Link compatibility is insufficient. The Community’s Safety System Description states that adding safety communication does not automatically make a non-safety device suitable for safety use. Product safety design and certification, plus validation in the machine, are necessary.
Is specification certification the same as product certification?
No. Obtain evidence for the exact purchased models and versions, restrictions and upper link, then validate the complete machine function. Recheck local supply and current certificates when ordering.
Does FAT approval eliminate SAT?
No. FAT tests combinations and faults before installation. Actual stopping performance, cable route, positions and maintenance behaviour require on-site evidence.
Can the 2026 review package be mandatory in our RFP?
The Community currently labels it REVIEW. Base contractual requirements on a released edition and the purchased product’s certified scope. Reassess when an official release appears.
Will diagnostics reduce downtime?
They may speed fault isolation, but any saving is site-dependent. In a pilot, measure whether technicians can distinguish intrusion, communication loss, device faults and wrong settings, and whether replacement retains the required safety tests. Diagnostics are separate from proof of safety performance.
Conclusion: freeze safety functions and acceptance evidence before selecting a master
For each machine, decide whether to retain its existing safety circuit, mix OSSD and IO-Link Safety, or replace devices as a verified combination. Make upper safety-PLC integration, settings, product certificates, stopping performance and fault behaviour comparable in the RFP. FAT proves logic and fault responses; SAT proves installed stopping and recovery. Specification certification, individual product certification and validation of the machine function are three different evidence sets. Check the released specification edition and exact product versions again before purchase.
If your Thai plant is deciding where to retain OSSD and where to introduce IO-Link Safety, contact TOMAS TECH with an initial machine drawing and safety-function register. We can help scope the comparison, RFP and FAT/SAT evidence before procurement. The equipment owner and qualified safety specialists remain responsible for final design and approval.