Removing K80 Safe Stop from Siemens Masterdrive VC: Procedure

David Krause15 min read
SiemensTechnical ReferenceVFD / Drives
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview of the K80 Safe Stop Option on Masterdrive VC

The K80 option on the Siemens MASTERDRIVE VC (6SE70 series) implements a hardware-based Safe Stop function, broadly equivalent to category 1 / SS1-style stop behavior in modern IEC 61800-5-2 terminology. It is a factory-fitted option only on the Compact-Plus (6SE702x) variants and cannot be retrofitted in the field. Compact and chassis-format units (6SE703x, 6SE709x) have different retrofit rules and should be treated as a separate engineering exercise.

The option is sometimes colloquially referred to as "Z80" in informal documentation; the correct Siemens ordering code is L80 / K80 in the MLFB (Maschinenlesbare Fabrikate-Bezeichnung, machine-readable product designation) — verify the option code on the drive rating plate before commencing any work. The original equipment in the case described is a 6SE7021-0TP60, which is a Compact-Plus 2.2 kW class unit in the 6SE70 family.

Safety Notice: Safe Stop is a functional-safety feature. Removing or bypassing it has legal, regulatory, and machine-safety implications. The following procedure is documented for decommissioning, replacement, or end-of-life scenarios only. Before proceeding, confirm with the machine's safety file, the risk assessment, and the applicable regional machinery directive (e.g., 2006/42/EC, ANSI B11.0, ISO 13849-1) that safe stop is no longer required. If a replacement drive is being installed in place of a K80-fitted unit, the preferred path is to replace like-for-like with another K80-equipped drive.

Identifying Whether the K80 Option Is Fitted

Before any parameter manipulation, confirm the option status. Three independent indicators must agree:

  1. MLFB / Order Code — the 6SE7021-0TP60-Z suffix (the "-Z" plus option code) appears on the rating plate. K80 will be appended if fitted at the factory.
  2. Physical connector X533 — a 4-pin Phoenix-style connector is present on the top-left of the unit, immediately adjacent to the control terminal block. Drives supplied without K80 do not have this connector populated on the PCB; the footprint may exist but is unpopulated.
  3. Drive parameter r977 / r978 (control word status) — read back the safety-related status indicators from the drive parameter set. The exact parameter index varies with firmware version; consult the parameter list for the firmware load installed (see firmware identification below).

Only proceed with parameter changes once you have confirmed, by physical inspection, whether X533 is populated. If the replacement drive is a spare that has never had K80, there is no safety interlock to release — only the parameter expectations of the upstream controller need to be normalized.

Hardware Architecture: X9, X533, and the Safety Path

The K80 option implements a hardware interlock that breaks the gate-pulse path to the IGBTs (Insulated Gate Bipolar Transistors — the drive's power-switching devices) when the safety input is opened. The relevant terminals are:

Connector Pin Function with K80 Function without K80 Field Action
X9 3 Safe Stop input (return) Not connected Leave open or bridge per drive logic
X9 4 Safe Stop input (24 V) Not connected Leave open or bridge per drive logic
X533 1 Safe Stop loop — n/a (no PCB population) Do not connect
X533 2 Safe Stop loop + n/a (no PCB population) Do not connect
X533 3 Auxiliary contact N.C. n/a Bridge 3↔4 to bypass safety
X533 4 Auxiliary contact N.C. n/a Bridge 3↔4 to bypass safety

Key engineering rule: With K80 fitted, the safety function is enforced by a hardware break in the gate-pulse path. Parameters alone cannot recreate a Safe Stop function. Setting P555/P556/P557 only changes which binectors (binary control flags used internally by the drive firmware) gate the OFF1/OFF2/OFF3 ramps; it does not re-establish a safety-rated hardware interlock. This is the single most important misconception in the field and is the reason multiple sources in the original case study pushed back hard on the proposal.

Parameter Map: P555, P556, P557, P558, P561

The MASTERDRIVE VC parameter model is binector-driven. The following parameters are the ones typically involved in any Safe Stop deactivation. Read the current values and record them (DriveMonitor trace or r parameter readback) before making changes.

Parameter Name (typical) Effect Default Factory When Deactivating K80
P555 Binector input — OFF1 inhibit Source of the OFF1 (controlled ramp stop) release interlock Site-specific (often a Profibus bit or a digital input) Set to 0 (always released) — only after confirming no external safety chain depends on it
P556 Binector input — OFF2 inhibit Source of the coast-to-stop (OFF2) interlock Site-specific Set to 0
P557 Binector input — OFF3 inhibit Source of the fast-stop (OFF3) interlock Site-specific Set to 0
P558 OFF1 command source Selects source of the OFF1 command 0 (control word bit 0) Verify remains consistent with drive control logic
P561 OFF3 (quick stop) source Selects source of the OFF3 (fast ramp) command 0 (control word bit 2) Verify remains consistent with drive control logic
Critical: The default values of P555, P558, and P561 are site-specific. Before touching them, capture the current settings, and the upstream source they point to (Profibus PZD (Process Data, the cyclic I/O words exchanged over Profibus) word, terminal, etc.). If you cannot determine the field report, do not change the parameter — investigate the control logic first.

Firmware Identification and Parameter-Lock Behavior

MASTERDRIVE VC firmware versions in service today range from V1.x through V3.x (the latter shipped with later 6SE70 hardware). Some firmware loads have a parameter-write protection that must be released before P555–P561 can be changed. The procedure is:

  1. Read r001 — drive state (must be in Ready or Run, not Fault or Commissioning lock).
  2. Set P053 = 7 (parameter-access enable for the safety-related subset). Some firmware loads require P052 = 40 first as a master access key.
  3. Read r060 / r061 to confirm the firmware version and the parameter set in use. Cross-reference against the Siemens Industry Online Support (SIOS) portal parameter manual for that version — older loads (V1.x) have different numbering for the safety parameters than V2.x+ loads.

If the drive is password-locked (P052 contains a non-zero user password), obtain the password from the responsible engineer before proceeding. There is no factory backdoor password for production firmware loads.

Procedure: Replacing a K80-Fitted Drive with a Non-K80 Spare

The cleanest case is a planned replacement of a failed unit, where the original was K80-fitted and the spare is not. The objective is to get the non-K80 drive into a state where the upstream controller sees a normal, ready drive without the safety interlock asserting a permanent fault.

Pre-work

  1. Lock out and tag out the drive (LOTO — Lockout/Tagout, the procedure for ensuring equipment is de-energized and cannot be re-energized until maintenance is complete) per site procedure. Wait the discharge time printed on the front of the unit (typically 5 minutes for 400 V class units) before opening covers.
  2. Verify zero energy at the DC bus with a Cat III (CAT III 600 V minimum) meter on the DC-link test points (measured DC bus voltage should be < 5 V DC before proceeding).
  3. Document the existing parameter set via DriveMonitor, STARTER (Siemens' commissioning software, suitable for older 6SE70 units with the correct firmware), or by hand-typed list. Include the safety-related P555–P561 values and their binector sources.

Spare-Drive Preparation

  1. Confirm the spare's MLFB and that it has no K80 option. The spare will not have an X533 connector on the PCB. Do not attempt to wire to a non-existent connector footprint.
  2. Apply power to the spare and read P053, P052, and the safety-related subset. Note the firmware version (r060 / r061).
  3. Upload the parameter set from the original (K80) drive if available. Caveat: if you upload naively, the safety-related parameters will be transferred as set, and the drive will appear to "expect" a K80 input that does not exist. The recommended workflow is to:
  • Upload all non-safety parameters from the original drive (P000–P500, P600–P999).
  • Manually set the safety subset (P555, P556, P557) to a known safe default — typically 0 (always released) for a decommissioned safety function, or to a digital input that mimics the original Profibus bit if the upstream PLC still asserts it.
  • Set P558 and P561 to match the original — typically P558 = 0 (control word bit 0 via Profibus) and P561 = 0 (control word bit 2 via Profibus).

Re-commissioning

  1. Restore the original control wiring (Profibus, terminals, encoder, motor cables). Do not attempt to wire to X533 pins 1/2 or X9 pins 3/4 on the non-K80 drive — the safe-stop hardware path does not exist.
  2. Run a no-load commissioning (motor uncoupled) at low speed (5 Hz) to verify direction, encoder feedback, and the OFF1/OFF2/OFF3 ramps.
  3. Test each stop command source: Profibus control word bits 0 and 2, terminal stops if wired. Confirm the drive ramps down rather than coasting for OFF1, and that OFF3 (fast stop) is still functional via the parameter (not the safety hardware).

Parameter Reference: Common Binector Sources for P555–P561

Binector Value Typical Meaning Use Case
0 Constant 0 (always released) Spare drive, decommissioned safety function
1 Constant 1 (always inhibited) Drive held in stop — generally not desired
DI 0 … DI 7 Digital input on the customer terminal block Standalone cabinet, hard-wired E-stop loop
Profibus bit (e.g., B110, B220) Cyclic bit in the Profibus PZD PLC-controlled line; original K80 machines used a Profibus word for the safety release
USS / Modbus bit Serial-link bit Legacy serial comms

The exact binector numbering depends on the firmware version. Always cross-reference against the Siemens MASTERDRIVE VC parameter list for the specific firmware load in use. Do not guess binector numbers from one firmware to another — they can shift between V1.x and V2.x.

Verification: How to Confirm the Drive Is Operating as Expected

  1. No faults on first power-up: the drive should reach state o007.0 (Ready for Run) within 5 seconds of pre-charge completing. Any F-fault related to "safe stop," "SS1," or "X533 open" indicates either the wrong parameter set is loaded or the wrong spare has been selected.
  2. Control word handshake: with the PLC asserting the standard 047Eh control word (the typical "enable operation" pattern: bit 0 = ON, bit 1 = no OFF2, bit 2 = no OFF3, bit 3 = enable, bit 4 = enable ramp, bit 5 = reserved, bit 6 = enable setpoint), the drive should accept the run command. If the PLC is configured to assert a safety bit, that bit must be re-mapped in the PLC program, not in the drive.
  3. Stop-ramp validation: from 50 Hz, command OFF1 via Profibus — the drive should ramp to zero in the time set by P464 (ramp-down time 1), typically 5–10 s. Then command OFF3 — the drive should ramp to zero in the time set by P466 (ramp-down time 3, the fast-stop time), typically 0.5–3 s.
  4. Loss-of-comms test: physically disconnect the Profibus connector; the drive should execute the comms-failure response defined by P685 (default: OFF2 / coast). If the drive continues to run, the fieldbus watchdog is not configured correctly — this is a separate problem from the K80 removal but is often uncovered during the same commissioning visit.

Safety and Compliance Implications

Read before proceeding.

Removing a Safe Stop function is a functional-safety change, not a parameter edit. The following must be addressed before the drive is returned to service:

  • Risk assessment update: the original safety function (hardware break of the gate-pulse path) contributed to the machine's PL (Performance Level, defined in ISO 13849-1) or SIL (Safety Integrity Level, defined in IEC 61508) rating. Removing it requires a new risk assessment under ISO 12100 and a documented justification.
  • Alternative stop category: if the machine previously relied on K80 for category 1 stop, an equivalent stop must be implemented externally (e.g., a contactor in the motor supply, a certified safety relay monitoring a hard-wired E-stop loop, or a replacement drive with a current-generation safety option such as STO (Safe Torque Off) or SS1).
  • Documentation trail: the parameter changes (P555, P556, P557) must be recorded in the machine's technical file, with the date, the engineer, the firmware version, and a justification. Most regulatory bodies expect this to be a controlled engineering change, not a field tweak.
  • Marking the drive: apply a label on the front of the unit indicating that the original Safe Stop function is no longer present. This prevents a future engineer from assuming the drive is K80-functional based on its appearance alone.

Troubleshooting Matrix

Symptom Likely Cause Action
Drive faults on first run, "Safe Stop open" or F082 X533 jumper not installed on the K80 drive, or the original K80 wiring carried over to a non-K80 spare Confirm drive is non-K80 by physical inspection; ignore X533 references
Drive runs but does not respond to ON command P555/P556/P557 = 1 (inhibited) carried over from K80 parameter set Set to 0; verify with r555/r556/r557 readback if available
Drive runs but will not stop on OFF1 P558 routed to wrong source; OFF1 release bit not asserted by PLC Trace PLC program; confirm control word bit 0 toggles; reset P558 = 0 if necessary
Fast stop (OFF3) is slow or absent P561 routed away from control word bit 2; P466 (ramp time) too long Set P561 = 0; check P466 (typical 1.0 s)
Parameter write rejected with "access denied" P053 ≠ 7, or P052 contains a user password Set P053 = 7; obtain password from responsible engineer
Drive shows firmware version mismatch with spare Original was V2.x, spare is V1.x or vice versa Match firmware, or accept that parameter numbering may differ and re-map manually
Motor runs in wrong direction Encoder phasing or P571/P572 swap Independent of K80; swap encoder channels or set P571 = 1

Alternatives to Removing the K80 Function

Before deciding to remove the K80 function, consider these alternatives, in order of preference:

  1. Source a K80-fitted replacement. Siemens used to offer the K80 as a factory option on the 6SE7021 series. The lead time is the typical constraint, not feasibility. Contact your Siemens drive spares channel with the original MLFB including the -Z option code.
  2. Replace the entire drive with a current-generation SINAMICS platform. The SINAMICS S120, G120, or V90 families offer certified STO and SS1 functions as standard options, with full support for PROFIsafe (the safety communication profile over Profinet/Profibus). The mechanical and electrical retrofit path is well-documented and the safety case is far easier to defend.
  3. Add an external safety contactor upstream of the drive. If the machine's risk assessment allows a category 0 stop (immediate removal of power) as an alternative to category 1, a certified safety contactor in the motor supply lines can provide an equivalent PL/SIL rating. This is the lowest-cost path and is appropriate for non-Servo, non-vertical-axis applications.
  4. Accept the loss and re-rate the safety function. Only valid if the machine's risk assessment permits it. Requires sign-off from a competent safety engineer and a documented change to the technical file.

Field-Proven Caveats

  • The K80 option label can also appear as "L80" on some markets' MLFB encoding; cross-check the order code, not the option suffix, before any work.
  • Some 6SE70 firmware loads (notably V1.4x) treat P555–P557 as a triple — changing one without the others causes an internal consistency check to fail and the drive to refuse to leave the commissioning state. Change all three in the same parameterization session.
  • DriveMonitor v5.x and earlier cannot read the safety subset on firmware V2.20+ without the safety-license dongle. STARTER is unaffected.
  • If the upstream PLC expects a "Safety OK" feedback bit, that bit will never come on a non-K80 drive. Either re-map the PLC logic to ignore the bit, or hard-wire a permanent "OK" signal from a separate source. This is the most common cause of a PLC refusing to enable the run command after the K80 drive is replaced.
  • Masterdrives approaching end-of-life (manufacture date > 20 years) may have dried-out electrolytic capacitors in the safety path. Even if you are keeping the K80 hardware, plan for a full capacitor refresh on the safety PCB before re-commissioning.

Summary Workflow

  1. Confirm the spare drive is not K80 by physical inspection of X533 and the MLFB.
  2. Capture the original K80 drive's full parameter set, with special attention to P555, P556, P557, P558, and P561 — and the binector sources of each.
  3. Power the spare, identify firmware (r060 / r061), unlock P053 = 7.
  4. Set P555 = P556 = P557 = 0 (or to a digital input that mimics the original Profibus bit if the PLC still asserts one).
  5. Set P558 = 0, P561 = 0 to match standard control-word-driven OFF1 / OFF3.
  6. Do not wire anything to X533 pins 1/2 or X9 pins 3/4 on the non-K80 drive.
  7. Re-commission with motor uncoupled: test run, OFF1, OFF3, loss-of-comms.
  8. Update the machine's technical file, apply a "Safe Stop removed" label, and inform the safety engineer.

What is the K80 option on a Siemens Masterdrive VC?

The K80 (sometimes mis-stated as Z80) is a factory-fitted hardware Safe Stop option on the 6SE70 / MASTERDRIVE VC family. It implements a hardware interlock that breaks the IGBT gate-pulse path, providing a category 1 / SS1-style stop. It is identified by an X533 connector on the top-left of the drive and a -Z K80 suffix in the MLFB.

Can I retrofit a K80 option to a non-K80 Masterdrive VC drive in the field?

No. On Compact-Plus (6SE702x) units, K80 is factory-fitted only; the safety PCB is not installed on non-K80 units and Siemens does not authorize field retrofit. Compact and chassis-format units have different rules — refer to the Siemens option catalog for the specific variant.

Will setting P555, P556, and P557 to 0 give me a safe stop?

No. These parameters only control which binectors gate the OFF1, OFF2, and OFF3 ramps. They cannot reproduce the hardware gate-pulse break that defines the K80 safety function. Safe Stop without the K80 hardware is a misconception and must be replaced by an alternative safety measure such as an upstream contactor, a SINAMICS replacement with STO, or a documented re-rate of the machine's safety function.

Why does the drive fault with a Safe-Stop error after replacing a K80 unit with a non-K80 spare?

The PLC or hard-wired safety loop is still asserting the K80 release bit, which the non-K80 drive does not have hardware to acknowledge. The fix is to (a) re-map or remove the safety bit in the upstream PLC, or (b) wire a permanent "Safety OK" signal to the PLC's input. The drive itself is operating correctly for its configuration.

What should I do with the X533 connector on a non-K80 spare?

Leave it disconnected. The non-K80 drive does not have the safety PCB populated, so wiring to X533 pins 1/2 has no function and can create a short or a misleading impression of safety. Document the absence in the commissioning report so that no future engineer attempts to use it.

Back to blog