S3NIS LOPA Software Tool Certified Under IEC 61511 and the CCPS LOPA Method
Risknowlogy has certified S3NIS LOPA, the layer of protection analysis software tool developed by Consultoría en Seguridad Funcional (CSF) of Venezuela, against IEC 61511:2016 and the published CCPS layer of protection analysis method — confirming the tool is fit to support the documentation of the allocation of safety functions to protection layers.
What Was Certified
S3NIS LOPA is a Windows desktop application used to document the allocation of safety functions to protection layers for hazardous scenarios. It records each scenario with its deviation, cause and consequence; the initiating events and their frequencies; enabling conditions and conditional modifiers; and the independent protection layers credited to it. It computes the mitigated frequency of each initiating event, the mitigated risk of the scenario, the required risk reduction factor, and the safety integrity level that the required risk reduction implies. The certified version is 2.1.0, build 9552.14499, released on 25 October 2025.
Two limits belong to the certificate rather than to its small print. S3NIS is a suite of applications developed by CSF; only the LOPA module was assessed, and the other applications distributed in the suite carry no certification from this work. And the certification covers the tool itself — not the results of any analysis performed with it, and not the tool’s application on any specific project.
Assessed domains: quality and software development management; software development lifecycle; tool requirements specification; software architecture and design; verification, testing and validation; method and algorithm implementation; configuration management; installation and operating environment; user documentation — nine domains, as listed on the certificate.
Certificate 2259.660.4-1, issued 10 September 2026, valid to 10 September 2029; certification report 2259.660.3 states the conditions and restrictions it is subject to.
How the Tool Was Assessed
Risknowlogy reviewed CSF’s software development management system, the lifecycle records for the certified version, the tool requirements specification, the architecture and design documentation, the verification and validation records, and the configuration management arrangements. The implemented algorithms were checked against the published CCPS method, and the worked example in CSF’s algorithm specification was independently re-calculated: the re-calculation reproduced the tool’s mitigated frequencies, mitigated risk, required risk reduction factor and projected risk to the precision displayed. The certified version was also installed from its installer package on Windows 11, activated, and used to generate reports.
The certificate carries conditions of use. The certified functionality supports low demand mode safety functions only; high demand and continuous mode are not supported. It applies to the operating environment assessed — Windows 10 and later, on laptops and desktop computers — and to the Spanish language build, which is the only build of this version. It is intended for use by hazard and risk analysis engineers competent in the layer of protection analysis method, and does not extend to personnel who are not.
What This Means for Practitioners and Asset Owners
LOPA practitioners get a tool whose calculations have been checked against the method they are required to apply, rather than against a vendor’s description of it. Engineering contractors and integrators specifying a LOPA workflow can point to an assessed development lifecycle and a fixed certified configuration, which narrows what has to be argued during a safety lifecycle audit. Auditors and regulators receive independent evidence that the software used to document the allocation of safety functions was itself subject to assessment. What none of them get is relief from judgement: confirming the true independence of the protection layers credited, assessing each layer’s design, verifying the tool’s outputs and reviewing the draft executive summary remain the user’s work, and the outputs still require independent review under the user’s own functional safety management system.
About Consultoría en Seguridad Funcional
Consultoría en Seguridad Funcional (CSF) is a functional safety consultancy serving the oil, petrochemical and manufacturing industries, and develops software tools supporting the safety lifecycle through an internal department. Submitting one of those tools to independent assessment against IEC 61511 and the published method places its development under external scrutiny.
The full certification basis, the assessed configuration and the restrictions are stated in certificate 2259.660.4-1 and in certification report 2259.660.3; both sit behind the certification page for the tool.
Need independent certification?
Risknowlogy is an independent certification body for functional safety — certifying people, products, subsystems, solutions, and management systems worldwide.