The paper will introduce the requirements from the European certification authorities for safety-relevant control devices and systems. It will discuss the different methods allowed to detect single-failures. Detecting single failures causes the actuating devices to transit into safe-state. Single failures include loss of messages, data corruption, delayed reception, etc. Allowed detection methods include crosschecking, running number, application CRC (cyclic redundancy check), etc.

The paper will also discuss the configuration possibilities and restrictions. The object dictionary containing all the communication and application objects accessible via the CANopen network is CRC protected in order to avoid an accidental misconfiguration.