1. Problem Overview
Engineers expanding an existing SIMATIC S7-300 station built around a CPU 314C-2DP (order number 6ES7 314-6CG03-0AB0 or equivalent) frequently attempt to drop an HART-capable analog input module directly into the central rack alongside the CPU. A common example is the spare module 6ES7 331-7FT00-0AB0 (SM 331, AI 8x13Bit, HART). The module is physically labeled "SM 331" and is part of the S7-300 family, so it appears intuitive to install it into an S7-300 baseplate. The reality is more nuanced:
- The 6ES7 331-7FT00-0AB0 is a SIMATIC S7-300 / ET 200M analog input module that can operate either in a central S7-300 rack or as a station in an ET 200M distributed I/O island.
- The first attempt is to find the article in the Step 7 HW catalog under SIMATIC 300 > SM-300. The HART variants are not always listed there in older versions of the HW catalog. They sit under the PROFIBUS-DP > ET 200M subtree because Siemens exposes them primarily as ET 200M modules that can also be slotted into an S7-300.
- Engineers must also verify the exact MLFB / order code on the front panel. A frequent field confusion is the suffix -7TF00- vs. -7FT00- (and earlier non-HART versions -7KF02- or -1KF02-). Only the 6ES7 331-7FT00-0AB0 carries HART.
This article walks through the verification, identification, and Step 7 V5.5 + SP4 configuration of this module behind the integrated DP master of the CPU 314C-2DP.
2. Identifying the Module
The MLFB 6ES7 331-7FT00-0AB0 decodes as follows:
| MLFB digit | Meaning |
|---|---|
| 6ES7 | SIMATIC S7 / ET 200 product family |
| 331 | SM 331 — analog input module class |
| 7 | 13-bit resolution, 8 channels |
| FT | HART support, electrically isolated |
| 00 | Hardware index / variant |
| 0AB0 | Release / packaging code |
Key electrical and functional data for this module:
| Parameter | Value |
|---|---|
| Number of inputs | 8 (4 if HART is enabled on every channel) |
| Resolution | 13 bit + sign (default), 16-bit oversampling optional |
| Measurement ranges | ±10 V, ±5 V, 1..5 V, ±20 mA, 0..20 mA, 4..20 mA, RTD, TC types (with range cards) |
| HART revision | HART 5 / HART 6 / HART 7 compatible |
| HART burst mode | Supported |
| Galvanic isolation | Yes (channel-to-channel via shared ground, group isolation to backplane) |
| Diagnostic interrupts | Yes (wire break, overflow, HART comm errors) |
| Update time (typical, all 8 channels) | ~ 50 ms without HART, ~ 1.5 s with HART enabled (depending on number of HART variables per channel) |
| Power consumption from backplane | ~ 1.0 W (5 V) plus sensor supply |
| Operating temperature | 0 to 60 °C horizontal mounting, 0 to 40 °C vertical |
Compare this to the more common non-HART 6ES7 331-1KF02-0AB0 (AI 8x13Bit, no HART) and the 6ES7 331-7KF02-0AB0 (AI 8x13Bit, HART but only via channel group 0). The 7FT00 offers full HART on all eight channels and supports a wider set of range cards.
3. CPU 314C-2DP PROFIBUS DP Interface Capabilities
The CPU 314C-2DP integrates two interfaces on the front of the unit:
| Interface | Type | Function | Default address / role |
|---|---|---|---|
| X1 (MPI/DP) | RS-485, switchable MPI or PROFIBUS DP master | Configure as DP master for ET 200M / ET 200S / third-party DP slaves | Default DP address 2 |
| X2 (PtP / DP) | Switchable RS-485 point-to-point or DP slave | Typically used as PtP (ASCII / RK512 / Modbus RTU master or slave), can also be a DP slave | Default PtP |
When interface X1 is configured as a DP master, it can support up to 32 DP slaves (per PROFIBUS segment), and the CPU 314C-2DP supports a maximum address space of 1024 bytes I / 1024 bytes Q per distributed station area. The cyclic PROFIBUS update at 1.5 Mbaud (default) is sufficient for the SM 331 HART 8x13Bit module's worst-case update time of ~ 1.5 s when HART is fully enabled.
Relevant CPU 314C-2DP technical data:
- Work memory: 192 KB (code + data) for the standard 6ES7 314-6CG03-0AB0.
- Bit/integer/real operations: 0.06 / 0.09 / 0.12 µs typical.
- PROFIBUS DP master max. slaves: 32, max. address space 244 bytes input + 244 bytes output per slave (DP-V0/V1).
- PROFIBUS DP master protocol: DP-V0, DP-V1 (read/write with acyclic services such as DPV1 class 1/2 read/write and RECORD READ/WRITE for HART passthrough).
- PROFIBUS line length: up to 1,200 m at 9.6 kbaud / 187.5 kbaud; 1,000 m at 1.5 Mbaud; 200 m at 12 Mbaud.
The DP-V1 capability of the integrated interface is what makes acyclic HART communication possible through the SFC 59 / SFB 52 / SFB 53 service set in user program. Without DP-V1, the user is limited to cyclic HART variables only (PV, SV, TV, QV as a four-real-image mapped into the I/O area).
4. Prerequisites for Configuration
Before opening Step 7 HW Config, verify the following:
- Step 7 V5.5 + SP4 (build 5.5.4.x) is installed. The module FW index 2 (or later) requires SP4. Earlier SP levels list only FW index 1.
- The current Hardware Support Package (HSP) for S7-300/ET 200M is installed. Without it, the new FW indices will not be selectable. The latest HSP for Step 7 V5.5 is normally downloaded from the Siemens support portal.
- Your project is using a CPU 314C-2DP with Firmware V3.3 or later (the 6ES7 314-6CG03-0AB0 ships with V3.3 since 2016; older 6ES7 314-6CG03-0AB1 is V3.0 and works as well, but is end-of-life for spare parts).
- ET 200M IM 153-x interface module of the appropriate PROFIBUS-DP-V1 variant (IM 153-1 6ES7 153-1AA03-0XB0 or IM 153-2 6ES7 153-2BA02-0XB0 for hot-swap) is in stock.
- Range cards for the SM 331 (one per channel, normally pre-installed on Siemens-supplied modules, but they may need re-seating if the module was previously configured for voltage).
- For HART field devices: loop resistors (250 Ω typical, min. 230 Ω) and a shielded, twisted-pair cable suitable for HART 1200 Bd FSK modulation.
- PG/PC with PROFIBUS or Ethernet adapter; the project will be downloaded over MPI initially, then over PROFIBUS if desired.
5. Locating the Module in the Step 7 HW Catalog
Open SIMATIC Manager > S7 Project > Station > HW Config. The catalog tree on the right side of HW Config is organized in two independent branches:
- SIMATIC 300 — modules for the central rack and the expansion rack (IM 360/361 chain).
- PROFIBUS-DP > ET 200M — modules for ET 200M distributed I/O stations.
The SM 331 AI 8x13Bit HART (6ES7 331-7FT00-0AB0) appears in the second branch: PROFIBUS-DP > ET 200M > AI-300. The same article can also be dropped into an S7-300 central slot — the catalog tree under SIMATIC 300 sometimes lists only the non-HART AI 8x13Bit module there. If you want to place the HART module into the central rack, drag it from the ET 200M / AI-300 folder into the S7-300 slot. Step 7 will accept the drop because the article is a SIMATIC S7-300 module, but the catalog highlight stays under ET 200M.
Quick path to find the module without browsing:
- Click in the catalog search field (top-right of HW Config).
- Type the order number:
6ES7 331-7FT00-0AB0. - Step 7 will filter the tree to the entry. If nothing appears, your HW catalog is missing the article — see section 6 below.
6. Installing the GSD File (If the Module Still Does Not Appear)
If the HW catalog does not show the module after SP4/SP5 install, the cleanest path is to insert the module into an ET 200M station and provide the ET 200M with a fresh IM 153 GSD. In rare cases the user wants to drop the module directly into the S7-300 central rack and still has no entry; this is normally an HSP problem, not a GSD problem.
Procedure to update the HW catalog from a Siemens HSP archive:
- Close SIMATIC Manager and HW Config.
- Run Siemens Automation License Manager — confirm the Step 7 license is detected.
- Run HW Update from the Windows Start menu (installed by the HSP setup). Point it to the HSP directory. The tool updates the Step 7 catalog and the GSD library.
- Restart SIMATIC Manager. In HW Config, refresh the catalog with Options > Update Catalog (or press F5).
- Re-search for the order number.
Online catalog update from inside HW Config (Options > Install HW Updates > Download from Internet) is a fallback, but Siemens discontinued this service for Step 7 V5.5 in 2020. Always keep a local copy of the HSP.
7. Configuring ET 200M with SM 331 HART in HW Config
The 6ES7 331-7FT00-0AB0 is best deployed as an ET 200M station on PROFIBUS DP. The CPU 314C-2DP's X1 interface acts as the DP master, the IM 153 is the DP slave, and up to 8 S7-300 I/O modules can be slotted in behind the IM 153 (depending on power budget and module width).
Step-by-step procedure:
- Open the project in SIMATIC Manager and double-click Hardware in the S7-300 station.
- Right-click the DP line on the CPU 314C-2DP (X1 interface) and choose Add Master System. A PROFIBUS subnet (typically 1.5 Mbaud, address 2 on the master side) is created.
- From the catalog, navigate to PROFIBUS-DP > ET 200M and select the desired IM 153 (e.g., 6ES7 153-1AA03-0XB0). Drag it onto the PROFIBUS line. The DP slave is given the next free address (default 3).
- Double-click the IM 153 to open its slot table. The IM 153 appears in slot 0 and is followed by up to 8 empty slots for S7-300 modules.
- Drag the SM 331 AI 8x13Bit, HART (6ES7 331-7FT00-0AB0) from PROFIBUS-DP > ET 200M > AI-300 into slot 4 of the IM 153 (slot 4 is the conventional analog section, slots 1–3 reserved for digital modules in some installations but not required).
- Double-click the SM 331 to open the Properties - SM 331 dialog.
- On the Basic Parameters tab, set the diagnostic interrupt enable, hardware interrupt enable, and HART enable per channel group.
- On the Inputs tab, choose the measurement type (e.g., 4-wire RTD, 0..20 mA, 4..20 mA) for each channel. Select the resolution (13 bit or 16 bit) and the integration time.
- On the HART tab, configure the number of HART variables requested per channel (0, 1, 2, 3, or 4). With all four variables requested, only four channels are available for measurement because each HART frame consumes channel bandwidth; with zero variables, the module behaves as a standard AI 8x13Bit.
- On the Addresses tab, note the input start address. With the IM 153 at slot 0 and digital modules in slots 1–3, the SM 331 typically starts at PIW 256 (32 bytes of input process image for 8 channels, 4 bytes per channel, of which the first 4 bytes are PV/QC).
- Save and compile. Step 7 will validate the configuration; if the IM 153 has insufficient diagnostic data, a warning is shown.
8. HART Parameter Assignment
HART is enabled per channel group (0–1, 2–3, 4–5, 6–7). For each group you can set:
| Parameter | Possible values | Default | Effect |
|---|---|---|---|
| HART enable | Disable / Enable | Disable | Enables the 1200 Bd FSK carrier on the channel pair |
| Number of HART variables | 0 / 1 / 2 / 3 / 4 | 0 | 0 = no HART, 1 = PV only, 4 = PV/SV/TV/QV |
| HART retry count | 0–5 | 3 | Number of retries before declaring a HART comm error |
| HART timeout | 0.1–60 s | 1.0 s | Time to wait for slave response |
| Burst mode | Disable / Enable | Disable | Enables the field device to publish continuously without polling |
| Short-circuit detection (current mode) | Enable / Disable | Enable | Triggers a diagnostic interrupt on loop short |
HART variables are mapped to the cyclic I/O image of the SM 331 as four 4-byte REAL values per HART-enabled channel (channel 0 occupies the first 16 bytes of the channel group). A typical HART-enabled channel thus occupies 16 input bytes; a non-HART channel occupies 4 bytes. With 4 HART variables on 4 channels, the module occupies 16 × 4 = 64 input bytes (16 IB starting at PIW 256 means PEB 256..319).
9. I/O Address Mapping
For a single SM 331 (6ES7 331-7FT00-0AB0) at slot 4 inside the ET 200M on PROFIBUS address 3, with the IM 153 at slot 0 and three digital modules in slots 1–3, the addressing is:
| Channel | Process value | Address (PIW) | Bit position |
|---|---|---|---|
| 0 — measured value (AI) | REAL / INT (depending on resolution) | PIW 256 | 0..15 |
| 0 — HART PV (REAL) | REAL | PIW 260..263 | 0..31 |
| 0 — HART SV (REAL) | REAL | PIW 264..267 | 0..31 |
| 0 — HART TV (REAL) | REAL | PIW 268..271 | 0..31 |
| 0 — HART QV (REAL) | REAL | PIW 272..275 | 0..31 |
| 1 — measured value (AI) | REAL / INT | PIW 320 | 0..15 |
| … | … | … | … |
| 7 — measured value (AI) | REAL / INT | PIW 504 | 0..15 |
The exact address offset depends on the modules placed in slots 1–3. The Addresses dialog in HW Config shows the current start address; trust the dialog, not the table above.
10. Downloading and Commissioning
- Save the project and compile (Ctrl+S). The system data (SDB) is built.
- Connect the PG to the CPU 314C-2DP via MPI (or to the IM 153 via PROFIBUS). Set the PG/PC interface in Options > Set PG/PC Interface.
- From HW Config, click PLC > Download to Target. Choose the CPU. Step 7 will warn if the CPU is in RUN; switch to STOP, download, and switch back to RUN.
- Open the online view: PLC > CPU Messages (or the diagnostic buffer of the CPU via PLC > Diagnostic / Setting). The SM 331 reports an OB82 (diagnostic interrupt) on first parameter download. The diagnostic buffer entry should read "Parameter assignment OK" with HART status "no error".
- Use PLC > Monitor/Modify to view the input words. The PV from a healthy HART transmitter should appear within 1–3 s of power-up at the configured PIW address.
- For cyclic HART communication, no extra SFC calls are required — the values are written automatically into the I area.
- For acyclic HART access (e.g., changing the tag or unit of a HART device), use SFC 58 / SFC 59 (read/write record) with the slot index derived from the IM 153 + SM 331 logical address. Example ST snippet:
// SFC 58 WR_REC, SFC 59 RD_REC for HART passthrough on SM 331, slot 4 // LADDR: logical address of IM 153, RECNUM: index = slot 0x8A04 for HART channel 0 // Returns 16 bytes of HART response frame. CALL "RD_REC" ( REQ := TRUE, IOID := B#16#54, LADDR := W#16#100, // IM 153 logical I/O start address (e.g. 256) RECNUM := B#16#8A04, // HART record 0x8Axx where xx = channel number RET_VAL := MW 100, BUSY := M 102.0, RECORD := P#M 110.0 BYTE 16 );
11. Verification and Diagnostics
After download, perform the following checks in order:
- LED inspection: The SF (red) LED on the SM 331 must be off. The BF (red) on the IM 153 must be off. The HART SF LED (if present on your hardware revision) must be off for every channel that has HART enabled.
- Diagnostic buffer: Read the CPU diagnostic buffer with Step 7. Look for "IO 1: SM 331 HART parameter assignment OK" or similar. A "Configuration error" indicates the slot/parameter set is rejected.
- Process image: Monitor the input process image in Monitor/Modify. The PV must be non-zero and the status byte (if status mapping is enabled) must be 0x00.
- HART multidrop poll: Connect a HART handheld (475/375) on a loop. The device must answer the short frame (0x00/0xFE) with its unique address. Then poll address 0 to verify the loop integrity.
- Wire break detection: Disconnect one field wire. Within 1–3 s, the SF LED should light and OB82 should be called. Re-connect; the alarm clears after the configured debounce time (default 2 s).
12. Troubleshooting Matrix
| Symptom | Probable cause | Action |
|---|---|---|
| Module not visible in HW catalog | HW catalog not updated; wrong MLFB typed | Install SP4/SP5, run HSP, refresh catalog. Re-type the order code in the search box (note: 7FT00, not 7TF00 or 7KF02). |
| SF LED on, "Parameter error" in diagnostic buffer | Incompatible range card position; HART enabled on a channel configured for voltage | Power down, re-seat range card for the affected channel, re-download HW Config. |
| HART PV stuck at 0.0 | Missing 250 Ω loop resistor; reversed polarity; HART not enabled on that channel | Measure 250 Ω across the field-device terminals. Enable HART in HW Config > HART tab. Check that the handheld sees the device. |
| IM 153 BF LED on, station not reachable | PROFIBUS address conflict; baud rate mismatch; missing termination | Verify only one terminator per segment (ON at both physical ends). Match baud rate to 1.5 Mbaud default. Confirm IM 153 address via rotary switch. |
| OB85 / OB122 on CPU | Program reads outside the SM 331's actual I/O length | Verify the input length in HW Config > Addresses. Re-check the FC/FB I/O area. Reduce the polled I/O count to the actual channel count. |
| HART communication is intermittent (works for 5 minutes, then SF) | EMC issue; cable too long; missing shield bonding | Use shielded, twisted pair, bonded at both ends with low-impedance clamps. Check that the cable is in a separate conduit from VFD power cables. |
| SFC 59 returns W#16#80A1 (record not found) | Wrong LADDR or RECNUM. The LADDR must be the IM 153 logical I/O start, not the SM 331 start | Re-read the IM 153 logical address from HW Config. Set RECNUM = 0x8A00 + channel number. |
13. Frequently Asked Questions
Can the 6ES7 331-7FT00-0AB0 be placed directly in the central rack of the CPU 314C-2DP?
Yes, physically it is a standard SIMATIC S7-300 module and can occupy any free slot (typically slot 4–11). However, in Step 7 V5.5 HW Config the article lives under PROFIBUS-DP > ET 200M > AI-300; drag it from there into the S7-300 slot tree. The module's HART communication does not depend on ET 200M — it is identical in central or distributed use.
Do I need the IM 153 with DP-V1 or is DP-V0 sufficient for HART?
DP-V0 is sufficient for cyclic HART (PV/SV/TV/QV mapped into the I/O area). DP-V1 is required for acyclic HART (SFC 58/59 / SFB 52/53) such as remote configuration of the field device. Use 6ES7 153-2BA02-0XB0 (IM 153-2) for DP-V1; the 6ES7 153-1AA03-0XB0 (IM 153-1) is V0 only.
How many HART variables can the module read per channel?
Up to four (PV, SV, TV, QV). The PV is mandatory if HART is enabled. Each HART variable adds 4 bytes to the input process image and increases the channel update time to roughly 750 ms per variable per channel.
What is the firmware version requirement for the CPU 314C-2DP to support this module?
Firmware V3.3 or later on 6ES7 314-6CG03-0AB0. The earlier 6ES7 314-6CH04-0AB0 ships with V3.3 as well. Step 7 V5.5 SP4 or later is required to handle the SM 331 FW 2.0.0 / 2.0.1 module indices.
My module is labeled 6ES7 331-7TF00-0AB0 — is that the same?
No. The 7TF00 part number does not exist as a Siemens order code — it is almost always a misread of the front flap where "7FT00" was rendered as "7TF00". A genuine 6ES7 331-7KF02-0AB0 (the older HART 8x module) is sometimes mislabeled too. Always re-read the MLFB on the inside of the front door before ordering a replacement.
Can I mix the HART and non-HART SM 331 modules in the same ET 200M?
Yes. The IM 153 addresses each slot independently, and the cyclic I/O length is the sum of all module lengths. Just keep the total under the CPU 314C-2DP's distributed I/O limit (1024 bytes input + 1024 bytes output).
Why does the HW catalog show the module under PROFIBUS-DP / ET 200M and not under SIMATIC 300 / SM-300?
Siemens lists the HART-capable SM 331 articles under the ET 200M subtree because the HART variants are most commonly used in distributed I/O. They can still be slotted into a central S7-300 rack — the catalog tree location is a presentation choice, not a functional restriction.