Configuring Failsafe Encoder Inputs on Siemens CPU 315F ET200M

David Krause17 min read
Safety SystemsSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Configuring Failsafe Encoder Inputs on Siemens CPU 315F ET200M

External-axis position verification on industrial robot cells is one of the more demanding safety-integration tasks. When a light curtain or other perimeter guard is broken, the safety controller must evaluate the kinematic state of the moving axis fast enough to determine whether the robot can stop inside the protected field or whether a controlled stop is required. A natural first approach is to read the axis position from a rotary or linear encoder and feed it into a failsafe input module, then let the safety program decide. Engineers new to functional safety frequently try to route that encoder through an analog input on a Siemens SIMATIC CPU 315F with ET 200M distributed I/O because the F-analog module is already in the rack. This article explains why that path is technically wrong, what signal and module families the 315F can actually accept for safety-rated motion monitoring, and how to build an architecture that meets ISO 13849-1 Performance Level d/e and IEC 61508 SIL 2/3 without abandoning the 315F entirely.

Field-proven constraint: An analog F-input has no edge-detection, no quadrature decoding, and no diagnostic coverage for a pulse train. Routing an encoder through it cannot be credited with more than PL a under ISO 13849-1 regardless of the SIL rating of the module itself.

1. The Architectural Problem with Encoders on Analog F-Inputs

An incremental encoder produces two quadrature pulse trains, A and B, with an optional index Z. A single channel carries no direction information; a quadrature pair carries 1, 2, or 4 counts per mechanical increment depending on the decoder configuration. An absolute encoder produces a multi-bit parallel or serial code (typically SSI, BiSS, or EnDat) representing the shaft angle in a single transmission.

None of these signals are analog in the IEC 61131 sense of a continuous +/-10 V or 0/4-20 mA process variable. A 0-10 V analog F-input is filtered, range-checked, and converted to a 16-bit integer at a fixed sample rate. The F-module is designed to verify that the value stays inside configured limits, not to count edges with microsecond resolution. Routing an encoder through a voltage divider or current loop to "look like" an analog signal discards the very information the safety function needs: the position increment between two safety cycles, the direction, and the proof that the encoder hardware is alive.

The failure modes are equally telling. An analog input cannot detect a stuck encoder, a missing index pulse, a quadrature fault, a broken cable shielding, or a severed A/B wire. The diagnostic coverage of such a topology is so low that no recognized functional-safety standard would credit it with anything above PL a. The encoder pulses continue to arrive even when the encoder is mechanically decoupled, so the safety program cannot distinguish a real position from a frozen one.

For these reasons, an encoder must enter a safety system as a digital counting or absolute-position signal on an F-counter or F-SSI module, never as a voltage or current on a generic analog F-input. If the only available slot is analog, the encoder is the wrong transducer for the job; replace the transducer or replace the module.

2. Encoder Signal Types Compatible with F-Controllers

Functional-safety encoder integration follows a small set of well-defined physical and protocol interfaces. Each maps to a specific Siemens F-module family.

Signal Type Wire Count Position Resolution Safety Use Siemens F-Module Match
HTL/TTL quadrature A/B(/Z) 4-6 4 x PPR Speed + position with dual-channel redundancy ET 200S 6ES7138-4DA04-0AB0 (F-DI 24 V counter)
SSI absolute (RS-422) 6 Up to 32 bits per revolution Absolute position with parity/gray-code check SM 338 POS-IN 6ES7338-4BC01-0AB0 (F-CPU reads via F-FB)
Sin/Cos 1 Vpp 4-6 Interpolation dependent High-resolution with plausibility via sin^2 + cos^2 SMx38 modules plus external safety evaluation
PROFIsafe over PROFINET 2 (CAT5e) Vendor-defined Native failsafe position, black-channel principle F-CPU PROFINET interface, no extra module
IO-Link Safety (SIO mode) 3 Vendor-defined Vendor-specific safe I/O ET 200SP CM 4xIO-Link + F-CPU

The PROFIsafe profile is the only interface in the table that pushes the entire safety evaluation into the encoder itself. Encoders such as the SICK AFM60A, Kubler Sendix F5863, and Siemens SIMODRIVE 1FK7 with PROFIsafe return a signed 32-bit position and 16-bit status word through PROFINET. The F-CPU receives the value, applies SIL 2/3 monitoring blocks from the F-library, and the black-channel principle guarantees that the PROFINET cable itself is not part of the safety chain. This is the preferred architecture when the encoder can be replaced with a PROFIsafe-capable unit.

3. Siemens F-CPU Family: 315F vs 319F

Cycle time is the silent killer of motion safety. The F-shutdown time is the sum of the input module's detection time, the F-CPU's safety program execution, the F-output module's response time, and the actuator's stop time. If the robot's hazardous motion is faster than this sum, the safety function fails regardless of the SIL claims on the module.

Parameter CPU 315F-2 PN/DP (6ES7315-2FJ14-0AB0) CPU 319F-3 PN/DP (6ES7318-3FL01-0AB0)
Bit execution time 0.05 us 0.02 us
Word execution time 0.2 us 0.05 us
Typical F-runtime budget for 200 F-ops ~25 ms ~7 ms
PROFINET IRT Yes Yes
Integrated work memory 512 KB code + data 1.4 MB code + data
Recommended for ≤ 3 safety functions, moderate cycle Multi-axis motion, ≤ 10 ms F-cycle

For a single external axis where the F-cycle is set to 32 ms and the safety function is "if axis position outside safe window then trip", the 315F-2 is adequate. When the safety function must compute velocity, acceleration, and position simultaneously across two or more external axes, the 319F-3 is the correct choice; the safety program execution time directly determines the maximum speed at which the axis can still be caught inside the safe window. If a faster response is required, the SIMATIC S7-1500F (CPU 1515F, 1517F, 1518F) with the F-runtime of TIA Portal reduces F-cycle by roughly 4x compared to the 315F-2 for the same logic. Reference the Siemens fail-safe modules manual collection for input-specific timing.

4. ET 200M F-Module Limits

ET 200M is a modular DP slave / IO-Device. The F-modules that fit it are a legacy SM 300 family, and the analog F-module is SM 336F; 6ES7336-1HE00-0AB0 (4AI, 0/4-20 mA, 15-bit + sign) or 6ES7336-1HF00-0AB0 (6AI, 0/4-20 mA, HART). Both modules are listed on the official Siemens SiePortal catalog page for analog fail-safe inputs.

Per the official SiePortal entry, the 4-channel SM 336F is specified for measuring temperature, pressure, flow, and level - the four process variables that map cleanly to a current loop. The module's internal diagnostics compare the two redundant ADCs per channel, monitor the line for wire break (current < 3.6 mA) and over-range (current > 22 mA), and provide discrepancy analysis between channels when configured as a 1oo2 or 2oo2 pair. None of these diagnostics are useful for a pulse train.

The sample time of the SM 336F is the deeper problem. With all four channels enabled and 50 Hz line integration, the per-channel update is approximately 20 ms. At 1,024 PPR, a 1,000 rpm axis generates 17,067 pulses per second, or 341 pulses per 20 ms sample. A single missed or extra pulse - which the analog input cannot count in the first place - represents roughly 1 degree of shaft error that the safety function will never see. The module's own Siemens documentation on ET 200SP F-inputs explicitly separates digital F-inputs, analog F-inputs, and counter modules; mixing the three is not supported and is not safety-credible.

5. ET 200SP F-I/O: A More Capable Modern Alternative

If the cabinet can be re-designed around an ET 200SP head station (IM 155-6 PN, e.g., 6ES7155-6AU00-0BN0 with firmware >= V3.0) wired to the same F-CPU, the F-module family becomes much more useful for motion safety.

ET 200SP F-Module Order Number Function Relevant Spec
F-DI 8x24 V HF 6ES7136-6BA00-0CA0 8 failsafe digital inputs 0.5 ms input filter, 1oo2/2oo2 evaluation
F-AI 4xI 0.5..4 mA HART 6ES7136-6AA00-0CA1 4 failsafe analog current inputs 2.5 ms conversion, SIL 3 / Cat. 4 / PL e
F-AI 4xU 0..10 V HART 6ES7136-6AB00-0CA1 4 failsafe analog voltage inputs 2.5 ms conversion, SIL 3 / Cat. 4 / PL e
TM Timer DIDQ 10x24V 6ES7138-6CG00-0BA0 Timestamped high-speed I/O 1 us timestamp, used for safe counting

For encoder safety monitoring through digital counting, the proper ET 200SP module pairing is the F-DI 8x24 V HF used together with the TM Timer DIDQ 10x24V in the head station. The F-DI handles the safety diagnostic (1oo2 evaluation between two input pins, discrepancy time monitoring), while the TM Timer supplies the position counter with sub-microsecond timestamps. The F-program reads the counter value via the standard F-library block F_COUNT from the F-IO library in TIA Portal. See the official Siemens fail-safe inputs documentation for the step response, sample time, and supported sensor types for both ET 200SP and ET 200MP F-inputs.

6. Allen-Bradley FLEX 5000 Analog Safety I/O for Cross-Reference

For plants standardized on Logix, the Allen-Bradley FLEX 5000 analog safety I/O modules (catalog numbers 5094-IF8IH, 5094-IF8XY, 5094-OF8IH, 5094-OF8XY) provide 8-channel isolated analog safety I/O over EtherNet/IP with CIP Safety. Per the Rockwell Automation product announcement, the modules meet SIL 2 / PL d and SIL 3 / PL e with 2oo3 voting across multiple modules. Like the Siemens F-AI, the 5094-IF8IH is designed for 0/4-20 mA process variables with HART, and is not the correct module for direct encoder pulse counting. The correct Logix module for safe encoder reading is the 5094-HSC high-speed counter, or a third-party safe encoder published on the CIP Safety EDS registry.

7. Dual-Encoder Comparison Pattern

A common suggestion when a single encoder cannot be trusted is to mount two encoders on the same shaft, one at each end, and let the F-program compare their positions. If the discrepancy exceeds a configured threshold, the safety function trips. This is a valid pattern; the implementation details matter.

  1. Use two physically separate encoders with different part numbers where possible, to defeat common-mode failure.
  2. Route each encoder to a different F-input module, ideally in different ET 200 stations, to defeat common-mode electrical failure.
  3. Read each encoder in a separate F-runtime group with its own watchdog, so a single stuck F-task cannot mask both encoders.
  4. Use the F-library block F_2OUT_3 or a custom F-FB to perform a 1oo2 or 2oo2 evaluation of the two positions.
  5. Configure a discrepancy time (typically 50-200 ms) below which the two encoders are allowed to disagree, above which the safety function trips.

For absolute encoders, add a "no movement at standstill" test: if the axis is commanded to be stationary and both encoders report any motion, trip. This catches decoupled shafts that the F-program would otherwise read as a static position. For dynamic motion, also cross-check the F-program's count of pulses per OB35 against an independent speed estimate derived from the F-CPU's wall-clock time to catch a stuck-at-one or stuck-at-zero encoder channel.

8. Common-Cause Failure Mitigation

Functional safety is recursive. If encoder A is the only position source for the safety function, what tells the F-CPU that encoder A is alive? The answer is a second independent source: a second encoder, a second channel on the same encoder evaluated in 1oo2 mode, or a second physical principle (e.g., a tachogenerator that confirms speed).

For the 315F / ET 200M analog input path, the answer is "nothing". A single analog reading of an analog voltage or current derived from a pulse train has no plausibility check. A second analog reading on a different channel improves the diagnostics of the analog module but does not improve the diagnostics of the encoder because both channels share the same pulse train, the same cable, and the same transducer. This is the common-cause failure that safety engineering practice warns against in functional-safety white papers.

The correct mitigation is the dual-encoder approach of Section 7, or a PROFIsafe encoder with internal dual-channel safety (e.g., a dual-redundant optical disk with separate read heads), which the encoder vendor certifies to SIL 2 / PL d or SIL 3 / PL e as a single device. Either way, the safety function must have at least two independent sources of evidence before the F-CPU credits the position value.

9. PILZ PNOZ Multi Alternative

The PNOZ Multi (e.g., PNOZ m B0, 750-101, or 750-103) is a configurable stand-alone safety controller from Pilz that supports analog input monitoring via expansion modules. The PNOZ m B0 with a PNOZ m EF 4AI analog expansion can compare two analog inputs as a safety function with adjustable threshold and discrepancy time, and can be SIL 3 / PL e certified. This is the right tool for "is the analog process variable inside the safe window" - exactly the cell-perimeter case described in the original question.

However, the PNOZ Multi is a poor choice for encoder position tracking. Its analog expansion samples at roughly 10 Hz with 12-bit resolution, and it has no facility for counting quadrature edges or reading SSI data. If the safety function is "if external axis position is outside the safe window", the PNOZ Multi can be used only with an external position-to-analog converter, which loses the safety benefit of digital counting. For the genuine motion-safety case, the F-CPU with the correct F-counter module remains the better architecture.

10. Building a Fail-Safe Analog Output as Reference Pattern

Siemens publishes a detailed application note titled Forming a Fail-safe Analog Output Signal that demonstrates the dual-channel analog pattern. A standard ET 200SP analog output module (e.g., AQ 4xU/I ST) is paired with a fail-safe analog input module (e.g., F-AI 4xI) that reads back the output value. The F-program continuously compares the commanded output (F-CPU process image) to the read-back value (F-input); if the discrepancy exceeds the configured tolerance, the F-output commands the actuator to the safe state. The same architectural pattern - read, monitor, trip on discrepancy - applies to encoder position monitoring when the F-CPU cannot directly read the encoder pulses. Download the Siemens fail-safe analog output application PDF for full TIA Portal V18 configuration details.

11. Step-by-Step Implementation

Use this procedure to replace a failed analog-encoder safety plan with a defensible architecture.

11.1 Prerequisites

  • Completed risk assessment per ISO 12100 and ISO 13849-1, with PL target for the cell-perimeter safety function.
  • Siemens SIMATIC Manager V5.6 SP2 (for 315F) or TIA Portal V18 with F-IO option pack (for 1500F).
  • S7 F-systems library (for SIMATIC Manager) or F-CPU Safety package (for TIA Portal).
  • Selected encoder: PROFIsafe over PROFINET, or dual-channel SSI / HTTL into SM 338 POS-IN, or quadrature into F-counter.

11.2 Hardware Configuration

  1. Mount the encoder with a positive-locking coupling to the external axis. Do not use a friction coupling for safety applications; slip defeats the safety function.
  2. Route the encoder cable separately from power cables, with a minimum 200 mm parallel separation, in a shielded twisted-pair cable with the shield grounded at the cabinet end only.
  3. Connect encoder Channel A and Channel B to a 24 V F-DI module (e.g., ET 200S 6ES7138-4DA04-0AB0), one channel per F-input pin. Configure 1oo2 evaluation in HW Config.
  4. Set the discrepancy time to 50 ms for high-speed motion, 200 ms for low-speed motion, per the F-program timing budget.
  5. Install the F-CPU's safety program with the F-library block F_ESTOP1 for the light-curtain interlock and a custom F-FB for the position-window check.

11.3 Software Configuration

  1. Open TIA Portal (or SIMATIC Manager), open the safety administration editor, and assign a PROFIsafe address to the F-DI module (default F-address is 1 for the first F-module in the rack).
  2. Import the F-library into the project. The F-blocks must live in the safety program (yellow background in TIA Portal), not the standard program.
  3. Configure the F-CPU's safety cycle time. The safety program runs in OB35 by default; for the 315F-2, set OB35 to 32 ms. For the 319F-3, set OB35 to 8 ms.
  4. Pass the encoder counter value from the F-DI into the F-FB. The F-FB implements the position window: if the counter is between Safe_Position_Min and Safe_Position_Max, the F-output Axis_Safe is TRUE; otherwise FALSE.
  5. Compile the safety program and accept the F-collective signature at the end of compilation. Record this signature in the safety acceptance test report.

11.4 Verification

  1. Power up the system and confirm all F-modules report "PASS" status in the diagnostic buffer.
  2. Trigger the light curtain with the axis stationary in the safe window: the F-output must drop to FALSE within the F-cycle time + 1 ms.
  3. Trigger the light curtain with the axis in the unsafe window: the F-output must drop to FALSE within the F-cycle time + 1 ms.
  4. Open the diagnostic buffer (Module Information → Diagnostic Buffer) and confirm no safety diagnostics other than the expected F-trip events.
  5. Test the F-CPU's collective signature against the signed value. Any mismatch indicates a non-credited program change; reset and re-validate.

12. Pitfalls, Alternatives, and Decision Path

12.1 Field-Proven Pitfalls

  • Do not "average" an analog signal to recover quadrature direction. Direction information requires digital edge ordering, not level averaging.
  • Do not run a safety function in OB1. OB1 is not a deterministic cycle; OB35 is. The safety function must run in the safety OB with a fixed cycle.
  • Do not use a 1oo1 (single-channel) F-DI for a PL d/e safety function. Use 1oo2 or 2oo2 evaluation; the F-program must combine two independent channels.
  • Do not share the encoder cable with non-safety signals. Cross-talk can corrupt the position; shield the cable and ground the shield at one end only.
  • Do not "lock" the F-program by setting the CPU to RUN-P without the password. Online changes to the F-program require a re-signed safety acceptance test.

12.2 Cross-Platform Alternatives

If the 315F cannot meet the motion-safety cycle time, the cleanest replacement is the S7-1500F (CPU 1515F-2 PN, 6ES7515-2FM02-0AB0, or CPU 1517F-3 PN/DP, 6ES7517-3FP00-0AB0). The 1500F supports the same F-library blocks, runs the F-program in OB1238 with a minimum cycle of 1 ms, and has F-runtime typically 4x faster than the 315F-2 for equivalent logic. The ET 200SP F-modules work with both 300F and 1500F families, so a controller upgrade does not require new I/O. For greenfield robot cells with high axis count, the SIMATIC S7-1500F with a TM Timer DIDQ 10x24V timestamp module and PROFIsafe encoders delivers sub-millisecond safety cycle times.

12.3 Decision Path

Routing an encoder through an analog F-input on a CPU 315F / ET 200M is a non-credible safety architecture. The correct path is one of the following, in order of preference:

  1. PROFIsafe encoder over PROFINET, evaluated by the 315F/319F or upgraded to 1500F. Single cable, vendor-certified to SIL 2/3, minimal integration effort.
  2. Dual SSI/quadrature encoders on a SM 338 POS-IN or TM Timer DIDQ, with discrepancy analysis in the F-program. Higher wiring cost, no need to replace existing encoders.
  3. Stand-alone safety relay (PNOZ Multi) for a non-encoder analog process variable such as pressure or temperature, NOT for encoder position.
  4. Upgrade controller to S7-1500F and use the ET 200SP F-AI 4xU/I HART modules with PROFIsafe encoders. Highest performance, highest cost.

The 315F is not the wrong controller for this safety function. The wrong choice is the analog input. Replace the input with a counter or PROFIsafe input, and the 315F / ET 200M combination can deliver a SIL 2 / PL d safety function with a 32 ms F-cycle, sufficient for most external-axis light-curtain interlocks.

Can I connect an encoder to the SM 336F analog F-input on ET 200M?

No. The SM 336F (6ES7336-1HE00-0AB0 or -1HF00-0AB0) is a 4-20 mA / HART input designed for temperature, pressure, flow, and level. It samples at ~20 ms per channel, has no edge-detection or quadrature decoding, and provides no plausibility check for a pulse train. Use a counter or SSI F-module instead.

What is the fastest F-cycle the CPU 315F-2 PN/DP can run?

32 ms in OB35 is the practical minimum. The 319F-3 PN/DP can run an equivalent F-program in 8-10 ms. For sub-millisecond cycles, upgrade to an S7-1500F (CPU 1517F-3 PN/DP), which supports 1 ms F-cycles.

Does a PROFIsafe encoder replace the F-CPU's safety logic?

No. The encoder provides a safety-rated position value; the F-CPU still runs the safety program (position-window check, discrepancy check, E-stop output) in the F-runtime. The PROFIsafe profile guarantees that the value is delivered uncorrupted, not that the F-CPU can skip the safety logic.

What is the discrepancy time for dual-encoder comparison?

For motion under 1 m/s, 50 ms is typical. For motion up to 5 m/s, reduce to 20 ms. The discrepancy time must be at least 2x the F-cycle time of the controller, and should be reviewed during the risk assessment for common-cause failure.

Can I use a PILZ PNOZ Multi for encoder safety?

Only if the encoder is first converted to an analog value (e.g., via a position-to-current transmitter), and even then the PNOZ m B0's analog expansion samples at ~10 Hz with 12-bit resolution, which is too slow for most motion-safety cases. Use a Siemens F-CPU with the correct counter or PROFIsafe input instead.

Back to blog