Search the field guide, causes, requirements, and glossary

CIP Safety connection timing

At default settings a CIP Safety input connection faults when no valid packet arrives within 40 ms, four times its 10 ms RPI.

Vendor or body
ODVA (protocol); values as documented by Rockwell Automation
Model or version
CIP Safety on EtherNet/IP; Rockwell Automation Logix safety controllers and safety I/O
Last verified
Oct 5, 2026
Sourced values
13

Values

ParameterValueCondition
Input connection reaction time limitRPI x (TM + NDM)1Input connections. TM is the timeout multiplier; NDM is the network delay multiplier as a ratio, so 200% counts as 2.
Output connection reaction time limitTask x (TM + NDM - 1)1Output connections. The output RPI is locked to the safety task period, so you change this limit by changing the safety task period.
Input RPI10 ms1Default for safety input connections
Timeout multiplier21Default. Rockwell Automation says not to set it lower than 2 on any safety connection.
Network delay multiplier200 %1Default; counts as 2 in the formula
Network delay multiplier range10 to 600 %2Valid range in the Advanced Connection Reaction Time Limit Configuration dialog; default 200
Input connection reaction time limit at defaults40 ms1RPI 10 ms, timeout multiplier 2, network delay multiplier 200%
Output connection reaction time limit at defaults3 x RPI3Timeout multiplier 2 and network delay multiplier 200%. The input limit at the same defaults is 4 x RPI.
Safety RPI range, produced and consumed safety tags1 to 500 ms4Safety controllers. The RPI of a consumed safety tag must match the safety task period of the producing controller.
Safety I/O RPI range2 to 500 ms31756 ControlLogix digital safety I/O modules; other safety I/O families set their own limits
Multipliers on wireless networksMay need to exceed defaults5Rockwell Automation states that wireless networks can require timeout or network delay multipliers above the defaults, and that setting them below the defaults can cause nuisance safety connection losses.
Data age checkTime stamp per packet6Each safety packet carries a time stamp. The consumer computes the data age and applies the data only if it is under the maximum allowed age; otherwise the connection goes to the safety state.
Safety integrity supportedUp to SIL 37Per IEC 61508. ODVA describes CIP Safety as a black channel protocol, so its integrity does not depend on the physical media.

Sources

  1. Connection Reaction Time Limit (1756-RM015). Read Oct 5, 2026.
  2. Advanced Connection Reaction Time Limit Configuration dialog box parameters. Read Oct 5, 2026.
  3. 1756 ControlLogix Digital Safety I/O Modules User Manual (1756-UM013B-EN-P). Read Oct 5, 2026.
  4. Logix 5000 Controllers Produced and Consumed Tags (1756-PM011N-EN-P). Read Oct 5, 2026.
  5. Consume Safety Tag Data (1756-UM900). Read Oct 5, 2026.
  6. The Common Industrial Protocol (CIP) and the Family of CIP Networks (PUB00123R1). Read Oct 5, 2026.
  7. CIP Safety (ODVA). Read Oct 5, 2026.

About this page

Built from 8 sources: 2 protocol owners and alliances and 6 vendor documents. Researched and drafted with AI assistance, then reviewed and approved by Ben Rutter on . How pages are made

First published
Last updated
Change history (1)
  • First published
Cite this page

Plain

Ben Rutter. "CIP Safety connection timing." OT Wireless, published October 5, 2026. https://otwireless.com/requirements/cip-safety/

APA 7

Rutter, B. (2026, October 5). CIP Safety connection timing. OT Wireless. https://otwireless.com/requirements/cip-safety/

BibTeX

@misc{rutter2026cipsafety,
  author = {Rutter, Ben},
  title = {{CIP Safety connection timing}},
  year = {2026},
  howpublished = {\url{https://otwireless.com/requirements/cip-safety/}},
  organization = {OT Wireless},
}