S3NIS LOPA Software Tool Certified Under IEC 61511 and the CCPS LOPA Method

13 September 2026 · Elena Fisher

Risknowlogy has certified S3NIS LOPA, the layer of protection analysis software tool developed by Consultoría en Seguridad Funcional (CSF) of Venezuela, against IEC 61511:2016 and the published CCPS layer of protection analysis method — confirming the tool is fit to support the documentation of the allocation of safety functions to protection layers.

What Was Certified

S3NIS LOPA is a Windows desktop application used to document the allocation of safety functions to protection layers for hazardous scenarios. It records each scenario with its deviation, cause and consequence; the initiating events and their frequencies; enabling conditions and conditional modifiers; and the independent protection layers credited to it. It computes the mitigated frequency of each initiating event, the mitigated risk of the scenario, the required risk reduction factor, and the safety integrity level that the required risk reduction implies. The certified version is 2.1.0, build 9552.14499, released on 25 October 2025.

Two limits belong to the certificate rather than to its small print. S3NIS is a suite of applications developed by CSF; only the LOPA module was assessed, and the other applications distributed in the suite carry no certification from this work. And the certification covers the tool itself — not the results of any analysis performed with it, and not the tool’s application on any specific project.

Assessed domains: quality and software development management; software development lifecycle; tool requirements specification; software architecture and design; verification, testing and validation; method and algorithm implementation; configuration management; installation and operating environment; user documentation — nine domains, as listed on the certificate.

Certificate 2259.660.4-1, issued 10 September 2026, valid to 10 September 2029; certification report 2259.660.3 states the conditions and restrictions it is subject to.

How the Tool Was Assessed

Risknowlogy reviewed CSF’s software development management system, the lifecycle records for the certified version, the tool requirements specification, the architecture and design documentation, the verification and validation records, and the configuration management arrangements. The implemented algorithms were checked against the published CCPS method, and the worked example in CSF’s algorithm specification was independently re-calculated: the re-calculation reproduced the tool’s mitigated frequencies, mitigated risk, required risk reduction factor and projected risk to the precision displayed. The certified version was also installed from its installer package on Windows 11, activated, and used to generate reports.

The certificate carries conditions of use. The certified functionality supports low demand mode safety functions only; high demand and continuous mode are not supported. It applies to the operating environment assessed — Windows 10 and later, on laptops and desktop computers — and to the Spanish language build, which is the only build of this version. It is intended for use by hazard and risk analysis engineers competent in the layer of protection analysis method, and does not extend to personnel who are not.

What This Means for Practitioners and Asset Owners

LOPA practitioners get a tool whose calculations have been checked against the method they are required to apply, rather than against a vendor’s description of it. Engineering contractors and integrators specifying a LOPA workflow can point to an assessed development lifecycle and a fixed certified configuration, which narrows what has to be argued during a safety lifecycle audit. Auditors and regulators receive independent evidence that the software used to document the allocation of safety functions was itself subject to assessment. What none of them get is relief from judgement: confirming the true independence of the protection layers credited, assessing each layer’s design, verifying the tool’s outputs and reviewing the draft executive summary remain the user’s work, and the outputs still require independent review under the user’s own functional safety management system.

A tool certificate confirms that the tool implements the method correctly and was built under control — it does not confirm the judgement of the engineer using it, and it does not certify the study produced with it.

About Consultoría en Seguridad Funcional

Consultoría en Seguridad Funcional (CSF) is a functional safety consultancy serving the oil, petrochemical and manufacturing industries, and develops software tools supporting the safety lifecycle through an internal department. Submitting one of those tools to independent assessment against IEC 61511 and the published method places its development under external scrutiny.

The full certification basis, the assessed configuration and the restrictions are stated in certificate 2259.660.4-1 and in certification report 2259.660.3; both sit behind the certification page for the tool.


Need independent certification?

Risknowlogy is an independent certification body for functional safety — certifying people, products, subsystems, solutions, and management systems worldwide.

We use cookies
Cookie preferences
Below you may find information about the purposes for which we and our partners use cookies and process data. You can exercise your preferences for processing, and/or see details on our partners' websites.
Analytical cookies Disable all
Functional cookies
Other cookies
We use cookies to personalize content and ads, to provide social media features and to analyze our traffic. Learn more about our cookie policy.
Accept all Decline all Change preferences
Cookies