NUCLEAR POWER PLANT I&C SYSTEMS: A COMPREHENSIVE LOOK AT IEC 61513 STANDARD (PART 1)
NUCLEAR POWER PLANT I&C SYSTEMS: A COMPREHENSIVE LOOK AT IEC 61513 STANDARD (PART 1)
While nuclear power plants play a critical role in meeting the world’s energy needs, the safety and operational efficiency of these massive structures depend on the meticulous design and implementation of instrumentation and control (I&C) systems. In this first part of the series exploring the standards that define deterministic design principles and safety classification for nuclear I&C systems, we will focus on the “umbrella standard” IEC 61513.

Control room visualization
IEC 61513 Overview
IEC 61513 standard is an umbrella document that defines the general safety and technical requirements for instrumentation and control (I&C) systems used in nuclear power plants. It is considered the highest-level document in the IEC SC 45A standard series.
Scope of the Standard: It covers the entire life cycle from design to decommissioning. The processes covered by the standard are listed below:
- Determination of requirements;
- System requirements;
- Detailed design and implementation;
- Integration;
- Verification;
- Installation;
- Modifications made to the system design (if any). IEC 61513 refers to many documents, such as the examples given below, to show the main definitions of safety requirements:
- IEC 61226 (Categorization of I&C Systems important for Safety)
- IEC 60880 (Requirements for Category A software)
- IEC 60987 (Hardware requirements in computer-based systems)
- IEC 62138 (Requirements for Category B and C software)
- IEC 61000 series (EMC requirements)
- IAEA NS-R-1 (SSR-2/1) (NPP safety — design)
- IAEA INSAG-10 (Defence in Depth in Nuclear Safety)
- IAEA NS-G-1.3 (SSG-39) (I&C systems important for safety in NPPs)
IEC 61513 and IEC 61508: Understand the Relationship Between Two Safety Standards
IEC 61513 is often confused with IEC 61508 series requirements. However, the two standards are based on significantly different philosophies. IEC 61513 (Ref: IEC 61513 Clause 6.5.2) states that IEC 61508 is considered an umbrella standard. Furthermore, detailed information on the subject can be found in Annex D of IEC 61513. IEC 61513 primarily has a deterministic approach (supported by probabilistic methods). Especially in Class 1 systems, the loss of deterministic behavior is unacceptable. IEC 61508, on the other hand, is more performance-based and relies on probabilistic risk assessment methods. Therefore, IEC 61508 SIL requirements are not a mandatory application for IEC 61513. In IEC 61513, deterministic and probabilistic methods are used together. While a deterministic approach is used in the design of systems, a probabilistic approach is used to optimize appropriate parts of the design and evaluate the overall safety of the system. For example, the probability of severe reactor core damage in the technical safety objectives of the reactor should be less than 10^-4 per year (Ref: IEC 61513 Annex A).

Choosing deterministic design over probabilistic methods in nuclear safety standards
Ensuring Deterministic Behaviour
Deterministic behavior means that the time between a system’s stimulus and response is predictable. IEC 61513 (Ref: Clause 6.2.2.3.3) and IEC 60880 standards recommend the following methods to maintain deterministic behavior:
- Static scheduling
- Limitation of multitasking
- Watchdog timers
- Monitoring CPU and memory usage
- Automatic correction (reset or fail-safe) when deviation is detected
Category and Class: From Safety Function to System Level
The concepts of ‘Category’ and ‘Class’ within IEC 61513 and IEC 61226 are different and often confused:
- Category (A/B/C): Defined according to IEC 61226. It indicates the safety significance of an I&C function. (Will be explained in detail in subsequent articles).
- Class (1/2/3): Defined according to IEC 61513. It determines the safety level of the system performing this function.
────────────────────────────── Nuclear I&C System Classification ──────────────────────────────
IEC 61513: Class 1 👇High Safety Requirement 👉 IEC 61226: Category A 👉 IAEA NS-G-1.3: Safety Systems (Highest Safety Level - Prioritizing Deterministic Behavior)
──────────────────────────────
IEC 61513: Class 2 👇 Important Safety Requirement 👉 IEC 61226: Category B (May also be implemented in Class 1) 👉 IAEA NS-G-1.3: Safety Related Systems (Safety-Related Systems - Medium Criticality)
──────────────────────────────
IEC 61513: Class 3 👇 Supportive / Non-Safety Related 👉 IEC 61226: Category C (May be implemented in Class 1 and 2) / Unclassified 👉 IAEA NS-G-1.3: Non-safety Systems / Supportive Functions (General Purpose Systems - Not Directly Safety Critical) ──────────────────────────────
Example:
Function: Emergency Reactor Shutdown → Category A.
System Performing This Function: EP ESFAS→ Class 1.
This means ‘Category’ determines the safety criticality of the function, while ‘Class’ determines the design quality and safety level of the system performing this function.
As can be understood from the table above, a Class 1 system may include a Category B function. In this case, Category B functions are not subject to Category A requirements. However, since the system is Class 1, the infrastructure (hardware, software, communication channels) is designed in accordance with the highest category requirements. If the most critical function within any system is Category A, that system is directly defined as Class 1.

When Category A really means “absolutely must not fail”
DEFENCE IN DEPTH: The Multi-Layered Shield of Nuclear Safety
IEC 61513 frequently refers to IAEA regulations when defining design requirements. The standard includes the concept of defence in depth, which is one of the I&C concepts in nuclear power plants (Ref: IEC 61513 Annex A4). The concept of defence in depth is detailed in IAEA regulations, and according to the INSAG-10 document, the layers of defence in depth are briefly shown below:

Levels of DiD
As can be understood from the table above, defence in depth consists of 5 levels, where the purpose of the first level is normal operation and prevention of possible accidents, while the final level is to mitigate the effects of possible radioactive releases in the event of an accident. Detailed information regarding these levels will be explained later in the section about the INSAG-10 document.

Because one barrier is never enough.
Principles Used to Ensure High Reliability in Nuclear I&C Systems
There are some fundamental principles for the effective implementation of defence in depth. One of the most important is the principle of independence between layers. The failure of one layer should not affect the performance of another layer (Ref: INSAG-10, Section 2.2). Along with the principle of independence, the following principles are also used:
- Redundancy
- Diversity
- Measures against common cause failures
- Single failure criterion
In this article, we summarized IEC 61513’s deterministic approach, the Category-Class distinction, and defence in depth principles. In the next article, a more detailed explanation of the principles used to ensure high reliability will be provided, and it will be specified in which situations these principles should be used.
What are your thoughts on the role of standards like IEC 61513 in shaping nuclear I&C systems? I’d be interested to hear your perspective.
Connect on LinkedIn: linkedin.com/in/gokhan-kurtkaya
메타데이터
- post_id
- fdca8f3acef6
- slug
- nuclear-power-plant-i-c-systems-a-comprehensive-look-at-iec-61513-standard-part-1-fdca8f3acef6
- url
- https://medium.com/nuclear-i-c-systems-safety/nuclear-power-plant-i-c-systems-a-comprehensive-look-at-iec-61513-standard-part-1-fdca8f3acef6
- canonical_url
- https://medium.com/nuclear-i-c-systems-safety/nuclear-power-plant-i-c-systems-a-comprehensive-look-at-iec-61513-standard-part-1-fdca8f3acef6
- author_url
- https://medium.com/@kurtkayagokhan
- status
- ok
- fetched_at
- 2026-06-27 07:40:21