What is CIP Safety?

CIP Safety is a functional safety communication protocol, developed and maintained by ODVA, that carries safety data such as emergency stop and light curtain signals over the same network as standard control data, using the Common Industrial Protocol (CIP). It follows the black channel principle: the network itself does not need to be reliable, because the safety end devices detect every transmission error themselves. CIP Safety is certified by TÜV Rheinland for applications up to SIL 3 under IEC 61508 and runs on IP, DeviceNet and Sercos III. Internationally it is standardised as communication profile IEC 61784-3-2.


🕰️ How did CIP Safety come about?

ODVA and its members started work on integrating safety services into the CIP network architecture in 2002. In 2004 a Joint Special Interest Group was formed in which companies including Omron, Rockwell Automation and Sick turned the design into a formal specification.

Year Milestone
2002 ODVA initiative to add safety to CIP networks begins
2004 CIP Safety Joint Special Interest Group formed
2005 First products: CIP Safety on DeviceNet (“DeviceNet Safety”)
2006 CIP Safety on EtherNet/IP added in edition 1.1 of the specification; Sercos International adopts CIP Safety
2008 CIP Safety on Sercos specification published
2024 Concurrent Connections: redundant CIP Safety connections over EtherNet/IP up to SIL 3

🔧 How does CIP Safety work?

CIP Safety adds a safety layer on top of the standard CIP application layer. At its heart is the Safety Validator object. The producing side, such as a safety input module, uses a Safety Validator Client; the consuming side, such as a safety PLC, uses a Safety Validator Server. Everything in between, including network interfaces, switches and routers, performs no safety function and therefore does not need safety certification.

The specification lists nine communication errors that must be detected, among them repetition, loss, insertion, incorrect sequence, corruption and delay of messages. CIP Safety uses five measures to catch them:

  • Time stamp and time expectation — every safety message carries a time stamp. Periodic ping exchanges align the producer’s and consumer’s clocks, so the receiver can calculate the true age of the data. Data older than the configured limit is discarded
  • ID for send and receive — a Production Identifier (PID), derived from the electronic key, the device serial number and the connection serial number, ensures each message reaches the correct consumer
  • Safety CRC — an end-to-end checksum generated by the producer and checked by the consumer; intermediate routers never inspect it
  • Redundancy with cross-checking — in long messages the data is also sent in inverted form and verified against a second CRC; in short messages redundant CRCs are cross-checked
  • Diverse measures — only safety devices implement CIP Safety, so a standard device cannot masquerade as a safety component
Format Safety data Protection
Short format 1–2 bytes Data + time stamp + 24-bit Safety CRC
Long format 3–250 bytes Data + 16-bit CRC + inverted copy + 24-bit CRC

Connections are either unicast (one producer, one consumer) or multicast, where up to fifteen consumers receive the same safety data. A connection is established with the Safety_Open service, an extension of the standard Forward_Open service that IP uses to set up connections, including across intermediate routers.


🏭 Where does CIP Safety sit in the OSI or Purdue model?

CIP Safety is an application layer protocol (OSI layer 7). Underneath it sits one of the supported CIP networks: EtherNet/IP over TCP/UDP/IP, DeviceNet over CAN, or Sercos III. Because safety lives in the end devices, safety messages can be passed between networks through standard routers, without dedicated safety gateways.

In the Purdue model, CIP Safety belongs at levels 0 and 1: communication between field devices such as light curtains, emergency stops, safety I/O and drives, and the safety PLC. Typical components are GuardLogix and Compact GuardLogix controllers, programmed in Studio 5000, and the Allen-Bradley 450L GuardShield, the first light curtain with CIP Safety over EtherNet/IP. Omron, Sick, Pilz, Fanuc and Bosch Rexroth also supply CIP Safety devices.


🔄 What are the alternatives to CIP Safety?

Every major industrial network family has its own safety protocol based on the black channel principle and IEC 61784-3:

Protocol Organisation Standard Underlying network Data age check
CIP Safety ODVA IEC 61784-3-2 EtherNet/IP, DeviceNet, Sercos III Time stamp with clock alignment
PROFIsafe PROFIBUS & PROFINET International IEC 61784-3-3 PROFINET, PROFIBUS Sequence number and watchdog
FSoE (Safety over EtherCAT) EtherCAT Technology Group IEC 61784-3-12 EtherCAT Sequence number and watchdog
openSAFETY EPSG IEC 61784-3-13 Network-independent, originated in POWERLINK Time synchronisation

All four are suitable for applications up to SIL 3. In practice the choice follows the control platform: CIP Safety is the natural fit in a Rockwell or Omron environment, PROFIsafe with Siemens and FSoE with Beckhoff. What sets CIP Safety apart is its time stamp: the receiver knows the actual age of the data, not just the time since the last message arrived.


🛠️ How do you design a CIP Safety connection?

You can design a safety function over CIP Safety in five steps:

  1. Determine the required integrity — derive the required SIL (via IEC 62061) or PL (via ISO 13849) from your risk assessment
  2. Select certified components — the safety PLC, safety I/O and light curtain must each be certified; GuardLogix systems, for example, reach SIL 3 and PL e (Category 4)
  3. Assign the Safety Network Number — the SNN combined with the device address makes every safety device unique in the plant and prevents mix-ups
  4. Set the reaction time — the Connection Reaction Time Limit is RPI × (Timeout Multiplier + Network Delay Multiplier). With an RPI of 10 ms, a timeout multiplier of 2 and the default network delay multiplier of 200%, you get 10 × (2 + 2) = 40 ms
  5. Validate and lock — test the safety function, record the configuration signature and lock the configuration

The connection reaction time feeds into the total response time of the safety function, and therefore into the required safety distance of, say, a light curtain.


🔐 How secure is CIP Safety against cyberattacks?

The distinction between safety and security is crucial here. CIP Safety protects against random faults: interference, failing switches, misrouted messages. It was not designed to withstand an attacker who deliberately forges messages. The CRC is not a cryptographic signature, and configuration is protected only by an optional password, configuration ownership and locking.

For security, ODVA offers a separate extension: CIP Security, part of the CIP specification since 2015. CIP Security uses TLS and DTLS for device authentication, integrity and optionally confidentiality. The two extensions complement each other. Network segmentation and the zones and conduits approach of IEC 62443 remain essential too. The Machinery Regulation (EU) 2023/1230 also explicitly requires, from 20 January 2027, that safety control systems withstand malicious attempts at tampering.


❓ Frequently asked questions

Is CIP Safety the same as CIP Security?

No, CIP Safety and CIP Security are two separate extensions of the Common Industrial Protocol. CIP Safety protects against random communication errors for functional safety, while CIP Security uses TLS and DTLS to protect against deliberate attacks. A plant can use both at the same time.

Do I need a separate network for CIP Safety?

No, CIP Safety shares the same network as standard control data. Thanks to the black channel principle all safety measures live in the end devices, so standard switches, cables and routers are sufficient. The network does need enough availability to avoid nuisance trips.

What SIL or PL level does CIP Safety achieve?

The CIP Safety protocol is certified for applications up to SIL 3 under IEC 61508. Systems built on it, such as GuardLogix with CIP Safety I/O, reach SIL 3 and PL e (Category 4) under ISO 13849-1. The final level depends on the complete safety function, not on the protocol alone.

What is the difference between CIP Safety and PROFIsafe?

CIP Safety and PROFIsafe are both black channel protocols up to SIL 3, but for different network families. CIP Safety runs on EtherNet/IP, DeviceNet and Sercos III and relies on time stamps, while PROFIsafe runs on PROFINET and PROFIBUS and uses sequence numbers and a watchdog. The choice usually follows the brand of the controller.

Can CIP Safety run over wireless networks?

Yes, because CIP Safety treats the network as a black channel, it can also run over Wi-Fi links. ODVA explicitly lists Wi-Fi and fibre optics as possible transport media. The reaction time and availability of the wireless link must, however, suit the safety function.

What is a Safety Network Number in CIP Safety?

A Safety Network Number (SNN) is a unique identifier for each network within a CIP Safety installation. Combined with the device address, the SNN makes every safety device unique, so a replaced or wrongly connected device cannot receive the wrong safety data.


📌 In summary

CIP Safety is ODVA’s black channel safety protocol that uses time stamps, connection identifiers and CRCs to carry safety data up to SIL 3 over EtherNet/IP, DeviceNet and Sercos III. It protects against random faults, not attackers: combine it with CIP Security, segmentation and IEC 62443.