Safety PLC or safety relay: how to pick, and the catalog traps that cost you money
I priced a safety upgrade last year for a two-cell palletizing line where the customer had already made up his mind. GuardLogix, because the integrator on the previous job put one in. The line had four E-stops, two gate switches, and a light curtain, and every one of them did exactly the same thing: kill everything. That is one zone. A pair of Guardmaster relays covered it for a fraction of the money and about a day less commissioning.
The reason this question keeps coming back is that most of the answers online argue the wrong point. They compare a safety PLC to a standard PLC, which nobody was confused about, or they line up feature bullets that make the PLC look like the grown-up choice. So here is the version I would give you across a bench, including the part-number traps that bite hardest when you are buying either one used.
Both of them reach PLe. Start there.
The Guardmaster 440R family is rated up to PLe and Category 4 per EN ISO 13849-1, and SIL CL3 per IEC 61508 and IEC 62061. That covers the DI, DIS, SI, CI, EM, and EMD units. GuardLogix tops out at the same place. There is no safety ceiling you unlock by moving from a relay to a controller.

The 440R-D22R2 dual-input Guardmaster relay. Rated up to PLe, Category 4, SIL CL3, the same ceiling a GuardLogix controller reaches.
Rockwell qualifies that rating with "depending on architecture and application characteristics," and that qualifier is doing real work. The number on the datasheet is what the device can support. What your machine achieves comes out of the subsystem calculation, and the logic device is usually not the weak link in it.
The weak link is more often the button. Rockwell's own E-stop application example spells out why: you are not allowed to exclude the fault of a single actuator failing to switch both channels properly, so a single electromechanical device caps out at PLd. Redundant switches get you to PLe. There is an exception, and it matters: if the device meets the maximum number of operations in IEC 60947-5-5, EN ISO 13849-2 Annex D, Table D8 permits that fault exclusion, and a single properly applied device can reach PLe after all.
So the machine that "needs a safety PLC to hit PLe" often needs a second look at the input device instead.
Count zones, not devices
Rockwell's guidance in Machinery Safebook 5 puts it plainly enough: single-function safety relays are the economical answer on smaller machines that just need a dedicated logic device, while modular and configurable monitoring relays make sense once you have a large and varied set of safeguarding devices and minimal zone control.
That last phrase is the one to hold onto. Minimal zone control. The moment different areas of the machine have to stop independently, you are building a logic matrix, and building a matrix out of hardwired relay contacts is where the wheels come off.
Say you have a cell with a gate, an E-stop, and a light curtain, and any of them drops the whole cell. One zone, three devices, no sequencing. A 440R-D22R2 has two dual-channel inputs and a rotary switch that ANDs or ORs them, and when you run out of terminals the single-wire safety connection cascades to a second unit without giving up SIL 3 or PLe. That is a solved problem and it costs a few hundred dollars.

One zone or three. This is the question that decides the device, not the safety rating.
Now split the cell. Infeed conveyor keeps running when the robot gate opens, the palletizer drops only if the E-stop by the operator station goes, maintenance needs reduced speed at the gate instead of a full stop. Three different stop behaviors from overlapping inputs. Wire that in relay logic and you will be drawing it for a week and troubleshooting it for a year.
Diagnostics is the other half, and it is a maintenance argument rather than a safety one. Ten devices in series on a relay tells you something opened. Ten inputs on safety I/O tells you which one, and puts it on the HMI. Nobody has ever thanked me for the relay version of that at two in the morning.
What is actually inside the controller
A safety PLC runs what Rockwell calls a 1oo2D architecture: two microprocessors, either one able to carry the safety function, with watchdog and compare circuits making sure both stay in sync. Each input circuit gets tested internally many times a second. The outputs get the same treatment, and if one of the three output circuits fails, the other two turn the output off and the internal monitoring reports the fault.

The 1oo2D architecture behind a safety controller. Either processor can carry the safety function, and the compare circuit makes sure they agree.
The line from Safebook that stuck with me: you might press that E-stop once a month, but the circuit behind it has been tested continuously the whole time.
For mechanical contact devices, the controller can pulse test the inputs to catch cross faults. That is the same job the S11 and S21 test outputs do on a 440R, just done in software across whichever terminals you happened to use.
Wiring is where the practical difference shows up first. On a relay, IN1 lands on S12 and S22, IN2 on S32 and S42, feedback on S34, and that is that. On safety I/O you land devices on any safety input terminal and sort out the assignment in the configuration. On a retrofit into a crowded panel, that flexibility buys you more than it sounds like.
Change management runs the other direction. A safety PLC generates a signature built from the program, the I/O configuration, and a time stamp. Record it as part of validation. Touch the safety logic later and you revalidate and record a new one, and you can password lock the program against edits. Real traceability, real overhead. The relay equivalent is a rotary switch position and a white rectangle on the front of the unit where somebody was supposed to write the setting down. I have opened a lot of panels where nobody did.
The part numbers that look interchangeable and are not
This is where surplus buying goes wrong, and it matters more than the philosophical relay-versus-PLC debate.
Not every 440R is PLe
DI, DIS, SI, CI, EM, and EMD all carry the PLe, Category 4, SIL CL3 rating. The GLP, the guardlocking unit that watches two proximity sensors and releases the gate at safe speed, does not. It is rated up to PLd, Category 3, SIL CL2. Same red housing, same DIN rail, same product family, lower ceiling.
Inside the PLe group the units are not swaps for each other either. The DI takes two dual-channel inputs; the SI and CI take one. The CI (440R-S13R2) gives you three N.O. safety outputs and an N.C. auxiliary, laid out to drop into older relay footprints, while the SI (440R-S12R2) gives two N.O. and a solid-state auxiliary. Functional safety data differs too. The 2012 selection guide lists MTTFd at 262 years for the SI against 164 for the CI, with PFHD of 3.98e-9 for the SI and 4.26e-9 for the CI. Those numbers are old enough that I would pull current values before they go into a SISTEMA project, but the point stands: the letters in the middle of the part number are not cosmetic.

The 440R-S13R2, the CI variant. Single dual-channel input, three N.O. safety outputs, and an N.C. auxiliary instead of the solid-state one on the SI.
Response times split the same way. The DI clears its safety outputs in 35 ms, the DIS in 25 ms, and adding a safety mat input pushes the DI to 40 ms. If you are backing into a safety distance, that difference is millimeters on the floor.
Whether a GuardLogix needs a safety partner depends on which one it is
The chassis-based controllers are a two-module system, and the pairing is fixed:
· 1756-L61S, L62S, L63S pair with the 1756-LSP
· 1756-L71S, L72S, L73S pair with the 1756-L7SP
· 1756-L81ES through L84ES pair with the 1756-L8SP

A 1756-LSP safety partner. This one pairs only with a 1756-L61S, L62S, or L63S primary, and it has to sit in the slot immediately to its right.
The partner installs in the slot immediately to the right of the primary controller, and it is not optional at the top rating. A GuardLogix 5580 comes up at SIL 2, PLd by default. You set the safety level on the Safety tab of the module properties, and SIL 3 / PLe requires the partner sitting next to it.
The Compact controllers do not follow the same rule. A 5370, meaning the 1769-L3xERMS units, achieves SIL 3 and PLe / Category 4 on its own with no partner module at all. Move up to the 5380 and it splits down the middle: 5069-L3xxERS2 and ERMS2 are SIL 2, ERMS3 is SIL 3. One character.
Picture the failure mode. Somebody sources "a GuardLogix" for a SIL 3 cell, gets a 1756-L82ES at a good price, and finds out at commissioning that it will not leave PLd until a 1756-L8SP shows up and an adjacent slot frees up. Or they find an LSP cheap and discover it will not pair with their L7xS.
1791DS and 1791ES ride different networks
Guard I/O splits by protocol. The 1791DS blocks are CIP Safety over DeviceNet. The 1791ES blocks are CIP Safety over EtherNet/IP. Two characters apart in the catalog number, and they will not join the same network.

Guard I/O in both flavors. The 1791DS on DeviceNet, the 1791ES on EtherNet/IP. They look like relatives because they are, but they do not share a network.
Worth knowing when you are pricing a retrofit: DeviceNet Guard I/O turns up on the used market at prices EtherNet/IP hardware does not, for the obvious reason. If the existing machine is already DeviceNet, that is a bargain. If you are planning to move the cell to EtherNet/IP in two years, it is not.
Pick the stop category before you pick the device
IEC 60204-1 and NFPA 79 define three stop categories, and they are not the same thing as the ISO 13849 categories, which trips people up constantly:
· Category 0 removes power to the actuators immediately. Uncontrolled, so a motor is free to coast. Takes priority over the other two.
· Category 1 keeps power available long enough to brake, then removes it.
· Category 2 is a controlled stop with power left on. A normal production stop.
An emergency stop has to be Category 0 or Category 1, and which one comes out of the risk assessment.

Category 0 against Category 1. The first cuts power and lets the load coast; the second brakes first and cuts power once it has stopped.
If you land on Category 1, you need a delay somewhere. On the relay side that is the EMD expansion module, with off-delay ranges of 0.1 to 1 s, 0.3 to 3 s, 3 to 30 s, and 30 to 300 s. A controller does it with an SS1 instruction watching a monitored decel ramp, which is the better tool once the load is anything but trivial, because it verifies the deceleration instead of waiting out a timer.
Either way, that delay goes into your stopping time calculation. Safebook flags this specifically for safety distance work, and it is easy to forget when the delay lives in a separate expansion module.
Response time is not a footnote
Rockwell's light curtain application example works the arithmetic all the way through, and it is the clearest illustration I have seen of why this matters.
Light curtain delay 14 ms. Estimated system reaction time 123 ms. Contactor response 50 ms. Actual machine stopping time, assumed at 300 ms. Total 0.487 s. Run that through the ISO 13855 formula at K = 1600 mm/s and the curtain has to sit 780 mm off the hazard.
The controller's share of that is small: safety task watchdog of 10 ms plus a safety task period of 20 ms gives 30 ms. The machine itself dominates.

Where the 780 mm comes from, and what it becomes when the machine takes longer to stop.
Here is the part that should change how you treat a swap. If that machine took 500 ms to stop instead of 300, the safety distance goes to 1100 mm. An extra 0.2 seconds moves the light curtain 320 mm farther from the hazard. Change a contactor, change a logic device with a different response time, let the brakes wear, and the distance you calculated three years ago is no longer the distance you need.
What I check on used safety hardware
Match the full catalog number, not the family.
On a 440R, remember the functional safety data assumes a 20-year mission time and proof test interval, plus a functional test at least once every six months. Used hardware arrives with an unknown history. I start mission time at install and put the six-month functional test on the maintenance schedule in writing, because nobody can tell me what the first owner did.
Reconfigure the rotary switch from scratch rather than trusting how it arrived. Power off, rotary to 0, power up and wait for the PWR LED to flash red, set the position, cycle power to store it. On a DI or DIS that switch picks one of eight combinations of AND/OR logic and reset mode; the single-input units use a simpler selector. Then write the setting on the label area, which is what it is there for.
Budget for the power-on delay during commissioning. The 440R base units take 5.5 s before they will do anything. The GLP takes 11 s. I have watched people start pulling wires at second seven.
On the controller side, sort out software versions before the hardware ships. Compact 5000 safety I/O needs Logix Designer version 32 or later, and the controller and I/O revisions have to line up. Surplus dealers sell hardware, not firmware licenses, so the firmware path is on you.
Common questions
What is a safety PLC?
A controller certified for safety functions, built on a redundant architecture (Rockwell's is 1oo2D) with continuous internal diagnostics, running certified safety instructions in a protected task. It runs standard control in the same project alongside the safety task.
When is a safety PLC required?
Never, strictly speaking. No standard names the device. The risk assessment gives you a required Performance Level, and either a relay or a controller can meet it. In practice the crossover comes somewhere around the second or third independent stop zone, and it comes sooner than that if the machine needs speed monitoring or safety over a network.
Is a safety PLC safer than a safety relay?
Not by rating. Both reach PLe and SIL 3 in the Allen-Bradley lineup. Where the controller genuinely lowers risk is in implementation: a wiring mistake on a relay is invisible until somebody tests it, while a controller flags a miswired input at commissioning. That is a real argument, and a good one, but it is not the same as a higher rating.
Can a safety PLC be used in an E-stop circuit?
Yes. Changes to IEC 60204-1 and NFPA 79 opened emergency stop circuits to safety PLCs and other electronic logic meeting IEC 61508. Hardwired electromechanical components used to be the only option.
Most of the arguments I hear about relay versus controller are really arguments about zones and diagnostics wearing a costume. Count the zones first. If the answer is one, buy a relay and spend the difference on the input devices, because that is where your Performance Level is actually getting capped.
We keep GuardLogix and Compact GuardLogix controllers, 1756 safety partners, Guard I/O in both DeviceNet and EtherNet/IP flavors, and 440R Guardmaster relays in stock at IQElectro, with a two-year warranty on all of it. If you are matching a partner to a primary controller or trying to work out which 440R variant a panel actually needs, the part number is the place to start, and we can check it against what is on the shelf.