CIP Safety connection timing
At default settings a CIP Safety input connection faults when no valid packet arrives within 40 ms, four times its 10 ms RPI.
- Vendor or body
- ODVA (protocol); values as documented by Rockwell Automation
- Model or version
- CIP Safety on EtherNet/IP; Rockwell Automation Logix safety controllers and safety I/O
- Last verified
- Oct 5, 2026
- Sourced values
- 13
Values
| Parameter | Value | Condition |
|---|---|---|
| Input connection reaction time limit | RPI x (TM + NDM)1 | Input connections. TM is the timeout multiplier; NDM is the network delay multiplier as a ratio, so 200% counts as 2. |
| Output connection reaction time limit | Task x (TM + NDM - 1)1 | Output connections. The output RPI is locked to the safety task period, so you change this limit by changing the safety task period. |
| Input RPI | 10 ms1 | Default for safety input connections |
| Timeout multiplier | 21 | Default. Rockwell Automation says not to set it lower than 2 on any safety connection. |
| Network delay multiplier | 200 %1 | Default; counts as 2 in the formula |
| Network delay multiplier range | 10 to 600 %2 | Valid range in the Advanced Connection Reaction Time Limit Configuration dialog; default 200 |
| Input connection reaction time limit at defaults | 40 ms1 | RPI 10 ms, timeout multiplier 2, network delay multiplier 200% |
| Output connection reaction time limit at defaults | 3 x RPI3 | Timeout multiplier 2 and network delay multiplier 200%. The input limit at the same defaults is 4 x RPI. |
| Safety RPI range, produced and consumed safety tags | 1 to 500 ms4 | Safety controllers. The RPI of a consumed safety tag must match the safety task period of the producing controller. |
| Safety I/O RPI range | 2 to 500 ms3 | 1756 ControlLogix digital safety I/O modules; other safety I/O families set their own limits |
| Multipliers on wireless networks | May need to exceed defaults5 | Rockwell Automation states that wireless networks can require timeout or network delay multipliers above the defaults, and that setting them below the defaults can cause nuisance safety connection losses. |
| Data age check | Time stamp per packet6 | Each safety packet carries a time stamp. The consumer computes the data age and applies the data only if it is under the maximum allowed age; otherwise the connection goes to the safety state. |
| Safety integrity supported | Up to SIL 37 | Per IEC 61508. ODVA describes CIP Safety as a black channel protocol, so its integrity does not depend on the physical media. |
Sources
- Connection Reaction Time Limit (1756-RM015). Read Oct 5, 2026.
- Advanced Connection Reaction Time Limit Configuration dialog box parameters. Read Oct 5, 2026.
- 1756 ControlLogix Digital Safety I/O Modules User Manual (1756-UM013B-EN-P). Read Oct 5, 2026.
- Logix 5000 Controllers Produced and Consumed Tags (1756-PM011N-EN-P). Read Oct 5, 2026.
- Consume Safety Tag Data (1756-UM900). Read Oct 5, 2026.
- The Common Industrial Protocol (CIP) and the Family of CIP Networks (PUB00123R1). Read Oct 5, 2026.
- CIP Safety (ODVA). Read Oct 5, 2026.
About this page
Built from 8 sources: 2 protocol owners and alliances and 6 vendor documents. Researched and drafted with AI assistance, then reviewed and approved by Ben Rutter on . How pages are made
- First published
- Last updated
Change history (1)
- First published
Cite this page
Plain
Ben Rutter. "CIP Safety connection timing." OT Wireless, published October 5, 2026. https://otwireless.com/requirements/cip-safety/
APA 7
Rutter, B. (2026, October 5). CIP Safety connection timing. OT Wireless. https://otwireless.com/requirements/cip-safety/
BibTeX
@misc{rutter2026cipsafety,
author = {Rutter, Ben},
title = {{CIP Safety connection timing}},
year = {2026},
howpublished = {\url{https://otwireless.com/requirements/cip-safety/}},
organization = {OT Wireless},
}