1. Overview: The IM 153-2 HF in PROFIsafe Architectures
The SIMATIC ET 200M distributed I/O system is one of the most widely deployed remote I/O platforms in process and factory automation. The interface module IM 153-2 HF (Siemens order number 6ES7153-2BA02-0XB0) is the High-Featured PROFIBUS-DP interface that connects an ET 200M station to a higher-level DP master such as an S7-300, S7-400, ET 200S, or S7-1500 CPU.
Engineers building Safety Integrity Level (SIL) 3 or Performance Level (PL e) systems frequently ask whether the IM itself must carry a TÜV certificate. The short, authoritative answer is no, and it is by design. The IM 153-2 HF is intentionally excluded from the safety function evaluation because the safety protocol (PROFIsafe) treats every non-safety element on the transmission path as a so-called black channel. This reference document explains:
- How the PROFIsafe black channel principle works under IEC 61784-3-3.
- Why the IM 153-2 HF carries no TÜV, BGIA, or BIA certificate of its own.
- Which certificates and declarations of conformity do apply to the module.
- The correct engineering workflow for SIL 3 with ET 200M and F-modules.
- Verification, proof test, and audit trails expected by TÜV assessors.
2. The PROFIsafe Black Channel Principle
PROFIsafe (PROFIBUS and PROFINET Safety) is the open, vendor-independent safety bus profile defined in IEC 61784-3-3. Its defining architectural property is the black channel approach: all components that simply move bits between the safety host (F-CPU) and the safety device (F-module) are excluded from the safety evaluation, provided the transmission channel meets a small set of well-defined error assumptions.
In a typical ET 200M safety station the black channel includes:
- PROFIBUS-DP cable, connectors, repeaters, and OLMs.
- The DP master interface inside the F-CPU (e.g. CP 343-5, integrated PROFIBUS port of CPU 315F-2 PN/DP).
- The IM 153-2 HF (or IM 153-4 PN HF for PROFINET).
- The ET 200M backplane and power modules (PS 307).
Safety is delivered by an additional payload in the PROFIsafe telegram: a 24-bit CRC, a consecutive number (VRC – Virtual Receipt Counter), a watchdog timer (F_WD_Time / F_WD_Time_2), and a status/control byte. The receiving F-module checks every telegram for:
- Correct CRC over the safety payload.
- Monotonic increment of the consecutive number within a configurable window.
- Receipt within the watchdog time.
- Valid relationship between the host F-CPU source address and the F-module destination address (F_Dest_Add).
If any check fails, the F-module enters the safe state, de-energises its outputs, and signals the fault to the F-CPU via the standard PROFIBUS diagnostics channel. The IM 153-2 HF is fully passive with respect to this safety payload; it cannot modify, drop, or interpret it. That is precisely why the safety assessor can treat it as interference-free.
3. IEC 61784-3-3 and the PROFIsafe Safety Layer
The PROFIsafe profile is published as the international standard IEC 61784-3-3:2021 ("Industrial communication networks – Profiles – Part 3-3: Functional safety fieldbuses – Additional specifications for CPF 3"). The profile is certified by TÜV SÜD and TÜV Rheinland and is the document that actually carries the TÜV certificate for the safety protocol. The certificate covers:
- The PROFIsafe state machine.
- The CRC polynomial and seed values for the two consecutive-number channels (VRC0 / VRC1).
- The F-Parameter set: F_Source_Add, F_Dest_Add, F_WD_Time, F_WD_Time_2, F_Check_SeqNr, F_Check_iPar, F_ParVersion, F_SIL, F_CRC_Length, F_Block_ID.
- The conformance test specification that every F-device vendor must pass.
The PROFIsafe conformance certificate issued by PROFIBUS Nutzerorganisation e.V. (PNO) is the upstream proof of safety. Device-specific TÜV certificates (for example for a SM 326F digital input module) build on top of the PROFIsafe certificate by demonstrating that the F-module correctly implements the profile in its specific firmware/hardware.
4. Why the IM 153-2 HF Has No TÜV Certificate
Siemens publishes the IM 153-2 HF product information and the corresponding SIMATIC ET 200M manuals without a TÜV certificate for the module itself. The reasons are architectural and are documented by Siemens as follows:
- No safety state of its own. The IM does not hold, evaluate, or output a safe state. It only forwards standard PROFIBUS telegrams, which are themselves non-safety.
- PROFIsafe safety payload is opaque. The IM cannot interpret the PROFIsafe CRC or consecutive number; corruption is detected by the F-module and the F-CPU, not by the IM.
- Black channel requirement already proven. PROFIBUS-DP physical layer conformance (IEC 61158) plus the PROFIsafe error assumptions (residual error probability < 10⁻⁹ per hour) eliminate the IM from the safety chain.
- Failure modes are bounded. IM faults (loss of power, watchdog, address conflict) are signalled via standard PROFIBUS diagnostics and lead to the F-CPU switching the F-modules to passivation.
Issuing a TÜV certificate for the IM would create duplicated audit effort and would falsely imply that the IM is a safety device. Instead, the TÜV certificate is held by:
- The PROFIsafe profile (IEC 61784-3-3).
- Each F-CPU family (e.g. S7-300F, S7-400F, S7-1500F).
- Each F-module (e.g. SM 326F DI/DO, SM 336F AI, SM 326F DO relay).
5. Certifications and Declarations That DO Exist
The IM 153-2 HF ships with the following compliance documents. Engineers should keep all of them in the safety dossier because TÜV / IEC 61511 audits will request them.
| Document | Issuing Body | Scope | Typical File Name on Siemens Support |
|---|---|---|---|
| EU Declaration of Conformity (CE) | Siemens AG | EMC Directive 2014/30/EU, Low-Voltage Directive 2014/35/EU, RoHS 2011/65/EU | DoC_6ES7153-2BA02-0XB0 |
| ATEX Certificate (2014/34/EU) | DEKRA / TÜV | Zone 2 / Zone 22 installation of the ET 200M station | ATEX_6ES7153-2BA02 |
| UL / cUL Listing (E203119) | Underwriters Laboratories | Class I Div 2, hazardous locations | UL_E203119_ET200M |
| FM Approval | FM Approvals | Class I Div 2, Class II/III Div 2 | FM_ET200M |
| RCM (Australia / New Zealand) | Siemens AG | ACMA EMC compliance | RCM_6ES7153-2BA02 |
| Marine Type Approvals | DNV, ABS, LR, BV, CCS, RINA, KR | Shipboard / offshore installation | Marine_ET200M |
| Manufacturer's Declaration – PROFIsafe Black Channel | Siemens AG | Confirms interference-free role of IM under IEC 61784-3-3 | MD_Profisafe_BlackChannel |
These documents are accessible via Siemens Industry Online Support under product article number 6ES7153-2BA02-0XB0. For TÜV-driven functional safety audits the only documents that bear on the safety claim are the PROFIsafe certificate, the F-CPU certificate, the F-module certificates, and the Manufacturer's Declaration. Conventional product safety (CE, UL, ATEX) is necessary but not sufficient for the safety argument.
6. Engineering Workflow for SIL 3 with ET 200M
The following procedure is the de-facto standard workflow when designing a SIL 3 / PL e application on ET 200M with PROFIsafe. It is consistent with the requirements of IEC 61511-1:2016 clause 11.5 and IEC 62061:2021.
6.1 Prerequisites
- Siemens STEP 7 V5.5 + S7 Distributed Safety (S7 F Configuration Pack) or TIA Portal V18 or later with F-Configuration Pack for the chosen F-CPU family.
- Approved F-CPU (e.g. CPU 315F-2 PN/DP, CPU 317F-3 PN/DP, CPU 1516F-3 PN/DP) with current firmware listed in the Siemens Functional Safety manual.
- IM 153-2 HF (6ES7153-2BA02-0XB0) firmware version V8.x or later; cross-check the version against the S7 F Configuration Pack release notes.
- Approved F-modules: SM 326F DI 24×24 VDC (6ES7326-1BK02-0AB0), SM 326F DO 10×24 VDC/2A (6ES7326-2BF10-0AB0), SM 336F AI 6×13 bit (6ES7336-1HE00-0AB0), SM 326F DO 8×230 VAC/2A relay (6ES7326-2BF41-0AB0) – order numbers and firmware versions to be confirmed against the current F-library.
- Functional Safety Manual for the specific F-CPU and F-modules, in printed or PDF form, stored in the safety dossier.
6.2 Step-by-Step Engineering
- Define the safety function. Document the Safety Instrumented Function (SIF) per IEC 61511: input, logic solver, final element, target SIL, demand rate, and Proof Test Interval (PTTI).
- Select the F-CPU and F-modules. Cross-reference the safety manuals to confirm the SIL claim (SIL 2 or SIL 3) and the permitted architectures (1oo1, 1oo2, 2oo2, 2oo3).
- Configure the ET 200M station in HW Config / TIA Portal. Insert the IM 153-2 HF, the PS 307 power module, and the F-modules in the correct slots. The IM occupies slot 0 of the active backplane; the PS 307 occupies slot 0 of the passive backplane when redundant.
- Assign the PROFIsafe address. Set the F-module F_Dest_Add via the DIL switch on the module or via PROFIsafe address assignment (recommended for hot-swap). F_Dest_Add range for PROFIBUS is 1..1023 and must be unique network-wide.
- Enable safety mode in the F-CPU. Activate the "Safety Mode" checkbox in the CPU properties; this forces the F-runtime group to execute with the certified F-library.
- Download the safety program. Use the F-Configuration Pack password-protected download sequence: compile → check consistency → generate F-block container → download with F-password. Record the F-checksum (F_CRC) of the entire safety program for the audit trail.
- Perform the PROFIsafe acceptance test. See section 8 for the full procedure.
7. Compatible F-Modules and Configuration
Only F-modules are permitted in a SIL-rated ET 200M slot. The standard SIMATIC S7-300 modules (SM 321, SM 322, SM 331, SM 332) are not safety-rated and must never be wired to the safety I/O of an F-CPU. The most common F-module families are:
| F-Module | Order Number | Channels | Achievable SIL | Notes |
|---|---|---|---|---|
| SM 326F DI 24×DC24V | 6ES7326-1BK02-0AB0 | 24 digital inputs | SIL 2 / SIL 3 (1oo2) | Readback via 1002 cross-monitoring |
| SM 326F DO 10×DC24V/2A | 6ES7326-2BF10-0AB0 | 10 digital outputs | SIL 2 / SIL 3 (1oo2) | P-, M-switching, 2A per channel |
| SM 326F DO 8×AC230V relay | 6ES7326-2BF41-0AB0 | 8 relay outputs | SIL 2 / SIL 3 | Forcibly-guided contacts |
| SM 336F AI 6×13 bit | 6ES7336-1HE00-0AB0 | 6 analogue inputs | SIL 2 / SIL 3 | 4..20 mA HART transparent |
| SM 336F AO 6×13 bit | 6ES7336-5GE00-0AB0 | 6 analogue outputs | SIL 2 | Requires F-CPU 416F or higher |
Each F-module ships with its own TÜV certificate (e.g. Z10 12 12345 XXX for SM 326F). The certificate lists the permissible sensor/actuator architectures (1oo1, 1oo2, 2oo2, 2oo3), the proof test interval, and the SIL claim. The IM 153-2 HF must be on the certified "permitted bus interface" list of the F-module; this is automatic for all current IM 153-2 HF firmware versions.
8. Verification, Acceptance Test, and Proof Test
8.1 PROFIsafe Acceptance Test
The acceptance test confirms that the black channel is intact and the safety communication is working under all required fault conditions. The test must be executed once at commissioning and re-executed after any change to the PROFIsafe parameter set, the F-module, or the F-CPU.
- Power up the F-CPU and the ET 200M station. Verify that the IM 153-2 HF goes to RUN (green "SF" off, green "BF" off, green "ON" solid).
- Check the F-CPU diagnostic buffer:
SFevents must be zero,PROFIsafe communication errormust be zero. - Force a PROFIsafe CRC error. Disconnect the PROFIBUS connector and re-connect within 1 second. The F-module must enter the safe state (outputs de-energised) within F_WD_Time.
- Force a consecutive-number error. Block a single telegram by briefly disconnecting a repeater. The F-module must enter the safe state within F_WD_Time_2.
- Force an address error. Temporarily change the F_Dest_Add of an F-module and verify the F-CPU signals a "PROFIsafe address mismatch" fault and passivates the channel.
- For each safety input, simulate the process value and verify the F-CPU executes the expected safety reaction.
- For each safety output, command the F-CPU to drive the output and verify the actuator responds within the response time budget.
- Record the F-block container checksum and archive the test report.
8.2 Proof Test Interval
IEC 61511 requires a proof test at the interval stated in the F-module certificate, typically 1 to 10 years. The proof test re-executes the acceptance test on every SIF and records the result. Failure to perform the proof test voids the SIL claim, regardless of the certifications held by the IM 153-2 HF or the F-CPU.
9. Common Engineering Pitfalls
| Pitfall | Symptom | Resolution |
|---|---|---|
| Treating the IM as a safety device in the safety case | Auditor rejects the safety case; functional safety assessment fails | Reference the Manufacturer's Declaration and IEC 61784-3-3; document the black channel explicitly in the SRS |
| Mixing standard SM 321/322 modules with F-modules in the same ET 200M rack | F-CPU refuses to enter safety mode; SF LED lit | Remove standard modules from the safety rack; route standard I/O to a non-safety ET 200M station |
| Using the wrong IM variant (e.g. IM 153-1 instead of IM 153-2 HF) | PROFIsafe telegrams time out; BF LED flashes | Replace with 6ES7153-2BA02-0XB0; confirm order number against the F-module manual |
| Firmware mismatch between IM and F-Configuration Pack | Compilation error "F-Parameter set not released" | Update F-Configuration Pack to the latest revision; flash IM firmware to the matching version |
| Exceeding the maximum F-module count (max 8 F-modules per IM 153-2 HF for PROFIsafe V2.4) | Safety program cannot be compiled; F-runtime group fails to start | Split the station; use multiple ET 200M stations on the same PROFIBUS subnet |
| Not documenting the PROFIsafe address assignment | Field service cannot replace a faulty F-module; address conflict causes SF | Maintain a PROFIsafe address plan; use the DIL switch on the F-module, or use PROFIsafe address assignment (F_Address) |
| Adding a non-PROFIsafe device on the same PROFIBUS subnet as the safety I/O | Bus faults cause nuisance trips | Segment the safety bus with a repeater; keep non-safety DP slaves on a separate segment |
10. Summary and Action Items
The IM 153-2 HF (6ES7153-2BA02-0XB0) does not require and is not issued a TÜV certificate because PROFIsafe (IEC 61784-3-3) implements a black channel that excludes the bus interface from the safety evaluation. The safety certificate chain runs from the PROFIsafe profile, through the F-CPU, to each F-module. The IM is documented as "interference-free" by Siemens via a Manufacturer's Declaration, which is the document to file in the safety dossier for the TÜV Functional Safety Assessment.
Action items for a SIL 3 / PL e project on ET 200M:
- Confirm the IM 153-2 HF order number and firmware version are on the released list in the F-CPU safety manual.
- Request the Manufacturer's Declaration for PROFIsafe Black Channel from Siemens Industry Online Support and file it with the safety case.
- Configure the F-modules with unique F_Dest_Add values and record them in the PROFIsafe address plan.
- Execute the PROFIsafe acceptance test at commissioning and re-execute after any change to the F-parameter set.
- Schedule the proof test at the interval stated in the F-module certificate; keep signed test reports in the safety dossier for the entire operational life of the SIF.
FAQ
Does the IM 153-2 HF (6ES7153-2BA02-0XB0) carry a TÜV certificate for SIL 3?
No. The IM 153-2 HF does not carry a TÜV certificate because PROFIsafe treats it as a black channel under IEC 61784-3-3. The TÜV certificates are held by the PROFIsafe profile, the F-CPU, and each F-module. Request a Manufacturer's Declaration from Siemens for the safety dossier.
Why is the IM 153-2 HF called "interference free" for PROFIsafe?
The IM cannot read, modify, or interpret the PROFIsafe CRC, consecutive number, or watchdog. It forwards PROFIBUS telegrams transparently. Corruption is detected by the F-CPU and the F-module, which then passivate the channel. This is the black channel principle of IEC 61784-3-3.
What is the difference between IM 153-2 HF and IM 153-2 for safety projects?
The IM 153-2 HF (6ES7153-2BA02-0XB0) supports up to 12 modules, F-modules, and the F-configuration required by PROFIsafe V2.4. The basic IM 153-2 (e.g. 6ES7153-2BA00 or 2BA01) supports fewer modules and is not approved for F-module operation in current F-CPU safety manuals. Always cross-check the IM order number against the F-module manual before commissioning.
Which Siemens F-modules are approved for SIL 3 with the IM 153-2 HF?
Commonly approved F-modules include SM 326F DI 24×DC24V (6ES7326-1BK02-0AB0), SM 326F DO 10×DC24V/2A (6ES7326-2BF10-0AB0), SM 326F DO 8×AC230V relay (6ES7326-2BF41-0AB0), and SM 336F AI 6×13 bit (6ES7336-1HE00-0AB0). Each module ships with its own TÜV certificate; verify the certificate and firmware against the F-CPU safety manual before deployment.
How do I prove the IM 153-2 HF is part of a SIL 3 system to a TÜV assessor?
File the following documents in the safety dossier: the Siemens Manufacturer's Declaration for PROFIsafe Black Channel, the PROFIsafe conformance certificate (IEC 61784-3-3), the F-CPU Functional Safety Manual, each F-module TÜV certificate, the F-parameter set dump, the F-block container checksum, and the signed acceptance and proof test reports. The IM 153-2 HF is referenced as a black channel element, not as a safety device.