This thread has been locked.

If you have a related question, please click the "Ask a related question" button in the top right corner. The newly created question will be automatically linked to this question.

Use of RM46 microcontrollers for a SIL 3 product

Other Parts Discussed in Thread: RM46L830, RM46L852, RM46L850, RM46L430, RM46L450, RM46L440, HALCOGEN, SAFETI-HALCOGEN-CSP
Dear Sirs,
We need to design a product for industrial applications with SIL 3 rating according to IEC 61508.
The system must be composed of the following sections:
  1. An input section, which must be able to read analog and / or digital signals (e.g. by means of Hall-effect sensors).
  2. A processing section, which must use a microcontroller with ARM / Cortex core architecture. The microcontroller must also necessarily be equipped with CAN and Ethernet peripherals.
  3. An output section, which must be able to drive up to 4 relays for NE loads.
For the time being, we have the following questions:
  1. In order to reach SIL 3 Safety level, must we necessarily use a redundant architecture with two microcontrollers, or can we use just one microcontroller (provided that its diagnostic coverage is > 99%)?
  2. Regarding the microcontroller selection, we are oriented to the RM46 series. Can you guide use to the selection of the right model for our needs, also considering availabilty and cost issues? Regarding other components, in order to reach SIL 3, must we necessarily use those listed in the https://www.ti.com/technologies/functional-safety/products.html webpage?  
  3. In the https://www.ti.com/tool/SAFETI_DIAG_LIB webpage, I see that there is some material available, such as diagnostic FW libraries. What kind of design support can you provide, considering that the product SW must be SIL 3 rated according to IEC 61508 and IEC 61511?