Description
ICS Triplex T8110B Trusted TMR Processor
Product Overview
The ICS Triplex T8110B is the central Trusted TMR Processor for the ICS Triplex Trusted safety-control platform. Rockwell Automation’s Trusted documentation identifies T8110B specifically as the Trusted TMR Processor, while the associated product documentation describes a lock-step Triple Modular Redundant architecture consisting of three processor fault-containment regions. Each processor executes the application and participates in cross-checking and voting functions designed to detect processor and memory faults.
The processor communicates with Trusted I/O through a triple-redundant Inter-Module Bus and handles application execution, I/O scanning, system diagnostics, and fault management. The documented T8110B hardware uses a 100 MHz processor clock, 20–32 VDC supply range, and up to 80 W load. Its documented memory configuration includes 16 MB EDO DRAM, 512 KB EPROM, 2 MB Flash, and 128 KB NVRAM, with a 1,000-event SOE buffer transferred to the communications-interface buffer.
For safety-system maintenance, the T8110B should be treated as a complete controller component rather than a generic CPU replacement. Firmware and Toolset compatibility matter. Rockwell’s Trusted 3.6.1 documentation, for example, explicitly required the T8110B firmware and Toolset Suite to be from the same certified release.
Product Introduction
A failed Trusted processor is not simply a PLC CPU swap. The participates directly in the TMR execution, diagnostic, I/O-scan, and safety architecture, so hardware revision and firmware compatibility have to be established before replacement.
For a Trusted TMR legacy replacement, verify the T8100 chassis, processor hardware issue, software/firmware release, application backup, standby configuration, and serial number. Rockwell has also issued product notices for specific serial-number populations, making nameplate-level identification important during procurement.
Key Technical Specifications
| Parameter | Specification |
|---|---|
| Product Model | |
| Manufacturer | ICS Triplex / Rockwell Automation |
| Product Family | Trusted |
| Product Type | Trusted TMR Processor |
| Architecture | Triple Modular Redundancy, lock-step |
| Fault-Tolerance Architecture | HIFT |
| Compatible Chassis | T8100 |
| Processor Clock | 100 MHz |
| Supply Voltage | 20–32 VDC |
| Maximum Load | 80 W |
| Heat Dissipation | 80 W |
| DRAM | 16 MB EDO, 60 ns |
| EPROM | 512 KB |
| Flash | 2 MB |
| NVRAM | 128 KB |
| Retained Variable Storage | 4 KB |
| I/O Interface | Triple-redundant Inter-Module Bus |
| SOE Buffer | 1,000 events; transferred to 4,000-event CI buffer |
| Operating Temperature | 0°C to +60°C |
| Non-operating Temperature | -25°C to +70°C |
| Relative Humidity | 10–95%, non-condensing |
| Dimensions | 266 × 93 × 303 mm |
| Published Weight | Approx. 2.94 kg |
These values come primarily from the /T8110 reference documentation. Older and newer Trusted documentation can differ in physical and hardware details, so the installed module revision should be checked before using dimensions or memory figures for a retrofit.

T8110B
Major Features / Practical Advantages
Triple Modular Redundant Processing
The defining characteristic of is its TMR architecture. The processor module contains three processor fault-containment regions, each with its own processor and memory resources. The processors operate in lock-step and cross-check one another, while the architecture uses voting to identify discrepancies.
This is fundamentally different from a conventional redundant PLC CPU arrangement. does not simply wait for one CPU to fail and then transfer control to another. The three processing paths participate continuously in the Trusted fault-tolerant architecture.
Trusted Inter-Module Bus
The communicates with Trusted I/O through a triple-redundant Inter-Module Bus. The processor reads input data, executes the application, and updates outputs as part of the cyclic Trusted control process.
For troubleshooting, this means a processor fault, IMB fault, I/O module fault, and application fault should not be treated as the same problem. The Trusted diagnostic architecture provides separate information for identifying the failing section.
100 MHz Processor Architecture
The documented processor clock is 100 MHz. The processor architecture is based on Motorola PowerPC-class processors, with separate memory resources within the three fault-containment regions.
The clock figure should not be confused with application scan time. Actual scan performance depends on the application, number and type of I/O modules, communication loading, scheduled operations, and logic complexity. The Trusted manual provides scan-time calculation methods rather than a single universal scan time.
SOE Event Handling
The processor provides a documented 1,000-event Sequence-of-Events buffer, with events transferred to a communications-interface buffer capable of holding 4,000 events. This is important for safety-system diagnostics because the timing sequence surrounding a trip can be more valuable than a simple alarm indication.
Standby Processor Capability
Trusted systems can be configured with a second TMR processor as a standby processor in the companion slot arrangement. The standby processor performs its own diagnostics and is kept synchronized with the active processor so that it can take over when the active unit requires functional replacement.
That is a system-level feature, not proof that every individual installation is configured for active/standby operation.
Safety-System Application
Rockwell’s Trusted system documentation identifies as a certified Trusted TMR Processor for safety-related configurations and documents use in configurations supporting applications up to SIL 3, subject to the applicable certified architecture and conditions.
The SIL statement should therefore be applied to the complete certified system configuration, not interpreted as an independent safety rating that automatically transfers to any application in which the processor is installed.
Firmware Compatibility Matters
This is one area where procurement shortcuts can cause trouble. Rockwell’s Trusted 3.6.1 release documentation explicitly states that the firmware and Toolset Suite must be from the same release for that certified configuration.
A replacement processor with the correct catalog number but an incompatible firmware/software combination is not automatically a plug-in replacement.
Serial-Number Traceability
Rockwell has published product notices concerning specific serial-number populations. One documented issue involved certain 2017 units shipped with firmware revision 1.3 instead of 1.4; affected serial numbers had to be identified and corrected.
For used or New Surplus procurement, recording the serial number and software/hardware issue markings is therefore worthwhile.
Related Products
- T8100 — Trusted Controller Chassis that houses the processor and associated Trusted modules.
- T8110C — Later Trusted TMR Processor variant with configuration/environmental differences; verify compatibility rather than assuming interchangeability.
- T8151B — Trusted Communications Interface used for communications functions separate from the processing role.
- T8153 — Trusted Communication Interface Adapter associated with the Trusted communications architecture.
- T8160 — Trusted TMR Interface module for system communication/interconnection applications.
- T8403 — Trusted TMR 24 VDC Digital Input module.
- T8431 — Trusted TMR Analog Input module.
- T8451 — Trusted TMR 24 VDC Digital Output module.
- T8311 — Trusted TMR Expander Interface used to connect Trusted controller and expansion architectures.
- T8310 — Trusted TMR Expander Processor used in Trusted expansion systems.
FAQ
What is ICS Triplex ?
The is the Trusted TMR Processor, serving as the main processing component of the Trusted safety-control system. It executes the application, scans I/O, performs diagnostics, and participates in the TMR architecture.
Is an I/O module?
No. It is the processor/controller module. Trusted I/O functions are handled by modules such as T8403, T8431, and T8451.
Can I hot-swap the ?
The Trusted architecture supports online replacement arrangements, including the use of a standby processor in a companion-slot configuration. However, replacement must follow the applicable Trusted maintenance procedure and system configuration. Do not interpret the architecture as permission to remove an active processor without verifying the standby state and maintenance conditions.
Does support SIL 3?
Rockwell’s Trusted system documentation identifies the in IEC 61508 certified configurations supporting safety-critical applications up to SIL 3, subject to the stated system conditions. The SIL capability belongs to the certified system configuration, not simply to an isolated spare module.
What firmware does use?
Firmware depends on the Trusted system release and module revision. Rockwell’s 3.6.1 release documentation specifically requires compatible firmware and Toolset Suite versions. Do not infer the installed firmware from the catalog number alone.
Does have Ethernet?
Do not specify Ethernet as a generic interface. The processor’s primary system communication with Trusted I/O is through the triple-redundant Inter-Module Bus. Dedicated Trusted communications functions are handled by associated communication modules such as T8151B.
Does the retain the application if power is removed?
The module includes NVRAM and retained-variable storage, but application retention and recovery should not be confused with a complete backup strategy. For replacement work, maintain a verified application/toolset backup rather than relying on the spare processor’s memory state.
What should I verify before purchasing a ?
Verify:
- catalog number
- Hardware issue/revision
- Software/firmware issue
- Serial number
- T8100 chassis configuration
- Trusted Toolset/software release
- Active/standby arrangement
- Application backup and configuration records
- Product-notice status for the serial number
- Physical condition and available functional-test evidence
Procurement Note
The is a safety-system CPU, so procurement should be handled more like a controlled system component than a generic PLC spare. The catalog number alone does not establish firmware compatibility, application compatibility, or certification status for a particular installation.
Pay particular attention to the serial number, hardware/software issue markings, and Trusted release. Rockwell has documented -specific firmware anomalies affecting defined serial-number populations, which demonstrates why a nameplate photograph is useful when purchasing New Surplus or refurbished inventory.
For a replacement, the minimum practical matching set is + hardware issue + software/firmware issue + serial number + T8100 system configuration. If those details are available, they provide much stronger evidence of compatibility than a supplier description such as “Trusted CPU” or “SIL 3 processor.”
