The objective of the MODSAFE project was to evaluate and develop methods based on formal model checking and apply them in the safety analysis of NPP safety automation (I&C). The purpose was to develop and find a group of methods and tools that support utilities, regulators, vendors and support organizations in their practical safety evaluation efforts. The main tasks of the first two project years were to review the state of the art of employing formal methods and models for safety evaluation of industrial and nuclear safety systems, to develop basic methodology for applying model checking to safety evaluation, and to study the feasibility of the approach. The third and fourth project years concentrated on developing the approach more flexible and suitable for analysing larger and more complex models. The research was conducted by utilizing several industrial example systems which enabled developing the methodology suitable for realistic problems and testing it with various types of systems. The results of the project show that by using model checking techniques it is possible to verify whether a design model of a moderate size safety system satisfies its key safety requirements or not, even when system failures must be taken into account.