Functional Safety Certification for Hazardous-Environment Robots: IEC 60880 Explained

Date
2027-01-18
Location
Online
Host
Zach L

About this event

A Standards Interpretation Session for Machine Safety Specialists pursuing functional safety certification. A live 30-minute standards interpretation session on IEC 60880 (Nuclear Software) for hazardous-environment robots, built for machine safety specialists pursuing functional safety certification. What We'll Cover: What IEC 60880 (Nuclear Software) requires and how its scope applies to hazardous-environment robots Mapping IEC 60880 clauses to the certification evidence assessors expect System-specific hazards and safety functions typical of hazardous-environment robots Common findings that delay certification, and how to avoid them A practical readiness roadmap for machine safety specialists preparing for assessment Related topics: IEC 60880 · Hazardous-Environment Robots · functional

Topics

Registration

View event page

About IEC 60880 (Nuclear Software)

This event covers the compliance, engineering, and verification requirements defined by IEC 60880.

IEC 60880 specifies software for category A functions in nuclear I&C — the highest class, e.g., reactor protection — with stringent lifecycle, verification, and tool requirements befitting functions whose failure could lead to core damage.

What it regulates

Software requirements through validation for safety-critical nuclear code: formalized specifications, defensive design, exhaustive verification expectations, strict configuration and modification control, and qualification of pre-existing software.

Who must comply

Reactor protection and safety actuation system developers.

Key requirements of IEC 60880

  • Lifecycle with heavy independent verification
  • Design constraints: simplicity, determinism, no interrupts/dynamic features where avoidable
  • Tool qualification and translation validation
  • Pre-developed software qualification route

Key concepts: IEC 60880

Category A software
Software of the reactor protection class — nuclear's DAL-A analog.
Determinism bias
Architectural preference for statically analyzable, time-deterministic designs.
Independent V&V
Organizationally separate verification as a structural requirement.

Frequently asked questions: IEC 60880

Why do nuclear systems often look technologically conservative?

60880's determinism and verification burden favor simple, proven platforms; innovation cost is dominated by qualification, so architectures minimize software complexity (or stay hardwired) for category A.

Standard information based on the published text of IEC 60880 (Nuclear Software). Event content is provided by the host. For authoritative guidance, consult the official standard body.