Overview: SM 331 Replacement Scenarios in S7-300 Systems
The SIMATIC S7-300 analog input module family (order prefix 6ES7331-) has undergone multiple product revisions since its launch, and field engineers routinely face the situation where a discontinued module must be swapped for a newer or higher-channel variant. The most common replacement path encountered in service work is the migration of the legacy 6ES7 331-7KB01-0AB0 (2-channel, 9/12/14-bit, 20-pin front connector) to the 6ES7 331-1KF01-0AB0 or its successor 6ES7 331-1KF02-0AB0 (8-channel, 13-bit, 40-pin front connector). A parallel question involves the digital input SM 321 family, where a 6ES7 321-1BH02-0AA0 is sometimes swapped for a 6ES7 321-1BH50-0AA0.
This reference documents the physical, electrical, and engineering differences between these modules, explains when the existing field wiring can be reused and when it cannot, and provides the STEP 7 / TIA Portal hardware configuration procedure required to bring the new module online. The information is consolidated from the official SIMATIC S7-300 module data manual and the TIA Portal documentation portal.
Module Identification and Catalog Number Reference
Correctly identifying the existing and replacement modules by their full MLFB (Maschinenlesbare Fabrikatebezeichnung / machine-readable product designation) is the first step. The S7-300 SM 331 catalog number follows the format 6ES7 331-XXXXX-0AB0; the hyphenated suffix (-0AB0) denotes the standard hardware revision.
| Feature | 6ES7 331-7KB01-0AB0 | 6ES7 331-1KF01-0AB0 | 6ES7 331-1KF02-0AB0 |
|---|---|---|---|
| Series | SM 331 (legacy HF) | SM 331 (standard) | SM 331 (successor) |
| Number of inputs | 2 AI | 8 AI | 8 AI |
| Resolution | 9 / 12 / 14 bit | 13 bit | 13 bit |
| Galvanic isolation | Yes (optical) | Yes (optical) | Yes (optical) |
| Signal types | U / I / Thermocouple / Resistance | U / I / Resistance / Pt100 / Ni100 / Ni1000 / LG-Ni1000 | U / I / Resistance / Pt100 / Ni100 / Ni1000 / LG-Ni1000 |
| Thermocouple support | Yes (types J, K, N, R, S, T per firmware) | No | No |
| Update time (module) | 20 ms / channel (configurable) | 66 ms (8 channels) | 66 ms (8 channels) |
| Diagnostic interrupt | Yes | Yes (group) | Yes (group) |
| Hardware interrupt | Yes (channel-level) | No | No |
| Front connector | 20-pin (6ES7392-1AJ00-0AA0) | 40-pin (6ES7392-1AM00-0AA0) | 40-pin (6ES7392-1AM00-0AA0) |
| Width on rail | 40 mm | 40 mm | 40 mm |
| Hot swap (backplane) | Supported | Not supported | Not supported |
Wiring Compatibility Analysis: 7KB01 to 1KF01 / 1KF02
The critical engineering question when replacing the 7KB01 with the 1KF01 or 1KF02 is whether the existing front-connector wiring can be reused. The answer is determined by a single physical constraint: the front connector pin count.
Front Connector and Pinout Differences
The 7KB01 ships with a 20-pin front connector (Siemens part 6ES7392-1AJ00-0AA0), while the 1KF01 and 1KF02 use a 40-pin front connector (Siemens part 6ES7392-1AM00-0AA0). Because the pitch and the pin assignment of the two connectors are entirely different, the existing wired connector block cannot be transferred to the new module. The wiring must be re-terminated on a new 40-pin connector using the new pin assignment.
| Pin | Signal (Channel 0 / Voltage mode example) |
|---|---|
| 1 | Mana (analog ground) |
| 2 | Mana (analog ground) |
| 3 | M+ (sensor supply +24 V, channel 0) |
| 4 | M- (sensor supply 0 V, channel 0) |
| 5 | CH0+ (input +) |
| 6 | CH0- (input -) |
| 11 | CH1+ |
| 12 | CH1- |
| 20 | L+ / M (24 V supply / ground) |
| Pin | Signal |
|---|---|
| 1 | Mana (ch0-1) |
| 2 | Mana (ch2-3) |
| 3 | Mana (ch4-5) |
| 4 | Mana (ch6-7) |
| 5 | CH0+ |
| 6 | CH0- |
| 7 | CH1+ |
| 8 | CH1- |
| 9-12 | CH2+ / CH2- / CH3+ / CH3- |
| 13-16 | CH4+ / CH4- / CH5+ / CH5- |
| 17-20 | CH6+ / CH6- / CH7+ / CH7- |
| 21-28 | Mana (compensation) and Pt100/Ni sense leads |
| 35 | L+ (24 V supply) |
| 40 | M (24 V ground) |
Reuse of Cable Conductors
While the front connector itself cannot be reused, the individual conductors feeding the analog sensors can be re-terminated on the new 40-pin connector if the cable is long enough and the conductor labelling is preserved. Engineers frequently re-use the same multi-core shielded cable and simply re-land the conductors according to the new pinout. Color-coded ferrules marked at both ends with the old channel number (e.g., CH0+) significantly speed up this re-termination.
Sensor Wiring Differences by Signal Type
The 7KB01 accepts thermocouple inputs directly with internal cold-junction compensation. The 1KF01/1KF02 do not support thermocouples - if any of the channels on the 7KB01 are wired with thermocouples (types J, K, N, R, S, T), the new module cannot read those signals. In that case either (a) install a separate thermocouple transmitter and read it as a 4-20 mA loop on the 1KF01, or (b) choose a different SM 331 variant that supports thermocouples such as the 6ES7331-7PF01-0AB0 (8 AI, thermocouple/RTD, 16-bit) or 6ES7331-7PF11-0AB0.
Successor Mapping: 1KF01 to 1KF02
When replacing the 1KF01 with its direct successor 1KF02, the situation is materially different:
-
Front connector: Both use the same 40-pin connector (
6ES7392-1AM00-0AA0). - Pinout: Identical.
- Signal types: Identical (U / I / R / Pt100 / Ni100 / Ni1000 / LG-Ni1000).
- Update time: 66 ms on both.
- Diagnostic behavior: Improved on the 1KF02 (faster diagnostic interrupt latency).
For this swap, the existing wiring can be reused as-is after removing the connector from the old module and re-seating it on the new module. The only software change is to update the hardware catalog entry in STEP 7 / TIA Portal from 1KF01 to 1KF02 and re-download the hardware configuration. No I/O address or user-program change is required.
Replacement Path Decision Matrix
| From | To | Wiring Reuse? | HW Config Change? | Program Change? |
|---|---|---|---|---|
| 7KB01-0AB0 | 1KF01-0AB0 | No (20-pin to 40-pin) | Yes (full) | Yes (channel addresses) |
| 7KB01-0AB0 | 1KF02-0AB0 | No (20-pin to 40-pin) | Yes (full) | Yes (channel addresses) |
| 1KF01-0AB0 | 1KF02-0AB0 | Yes (same 40-pin) | Yes (catalog swap) | No |
| 7KF02-0AB0 | 1KF02-0AB0 | Verify pinout first | Yes | Verify |
| 321-1BH02-0AA0 | 321-1BH50-0AA0 | Yes (same 40-pin) | Yes (catalog swap) | No (verify input filter) |
STEP 7 (Classic) Hardware Configuration Procedure
Prerequisites
- STEP 7 V5.4 SP5 or later, or TIA Portal V13 SP1 or later.
- The S7 project file (.s7p / .ap13) backed up before the change.
- Hardware Support Package (HSP) installed for the 1KF02 if using STEP 7 V5.x.
- New 40-pin front connector (
6ES7392-1AM00-0AA0) and labels. - Wire ferrules, screwdriver (0.4 x 2.5 mm), and crimp tool.
Step-by-Step: 7KB01 to 1KF02 Migration
-
Document the existing configuration. Open the S7 project offline in STEP 7, navigate to HW Config, and double-click the 7KB01 slot. Record the measurement type per channel (U/I/R/Thermo), the measuring range, the integration time, and the assigned input addresses (e.g.,
PIW 256,PIW 258, ...). Export the hardware configuration as a CAx file (Station > Export) for reference. - Power down the S7-300 rack. Place the CPU in STOP. Disconnect the 24 V supply to the rack. Wait 60 s for the analog inputs to discharge to safe levels.
- Remove the 7KB01. Open the front cover, unlock the front connector with a flat screwdriver, and pull the 20-pin connector out of the module. Label each conductor (1-20) with adhesive markers indicating the original channel assignment. Unscrew and remove the module from the rail.
-
Re-terminate on a 40-pin connector. Using the new
6ES7392-1AM00-0AA0connector, land each conductor according to the 1KF02 pinout (Table 3). For a voltage input on channel 0: terminal5= CH0+, terminal6= CH0-, terminal1= Mana (analog ground). Repeat for all active channels. The unused channels (the 1KF02 has 8 inputs, the original only had 2) should be tied Mana to the corresponding input to avoid floating inputs that can produce unstable readings; refer to the module manual for the exact "unused channel" wiring. - Install the 1KF02. Seat the module on the rail in the same slot, tighten the screws, and seat the 40-pin connector. Close the front cover.
-
Update the hardware configuration. In STEP 7 HW Config, right-click the slot that held the 7KB01, choose Replace Object, and select 6ES7 331-1KF02-0AB0. Set the measuring range for each active channel to match the original (e.g.,
±10 V,4-20 mA,Pt100). Configure the unused channels as deactivated to prevent diagnostics. Save and compile (Station > Save and Compile). -
Re-assign I/O addresses if necessary. The 1KF02 occupies 16 bytes of input process image (
PIW 256throughPIW 270), while the 7KB01 occupies only 4 bytes. The first two words (PIW 256,PIW 258) are address-compatible with the original 7KB01, so most user programs continue to work without modification. Verify that the user program does not reference addresses abovePIW 260on the old module - if it does, those addresses are now occupied by the new channels and may need to be moved. - Download the hardware configuration. With the CPU in STOP, download the hardware configuration to the PLC (PLC > Download to Target).
- Run the CPU. Switch the CPU to RUN. The analog input LEDs should settle to a steady state within 66 ms (one module update cycle).
- Verify. See the verification section below.
TIA Portal Configuration Procedure
- Open the TIA Portal project and navigate to Devices & Networks.
- Locate the S7-300 station in the project tree, expand the rack, and identify the slot containing the existing SM 331.
- Right-click the slot and select Change Device. In the catalog, browse to AI > SM 331 > 6ES7 331-1KF02-0AA0. Confirm.
- Open the module properties and configure each channel's measurement type and range to match the original wiring.
- Compile the device configuration (Compile > Hardware (rebuild all)).
- Download to the target device (CPU must be in STOP for hardware reconfiguration).
- Run the CPU and verify per the steps in the next section.
Verification Procedure
After the module replacement and configuration download, perform the following verification checks before returning the system to production:
-
Module diagnostics: In STEP 7 PLC > Module Information (or TIA Portal Online & Diagnostics), confirm that the 1KF02 reports no diagnostic errors. The Module Status should show
OKand the Channel Status should showOKfor all configured channels. -
Process image values: Add the input words (PIW 256, 258, ...) to a VAT (Variable Table) in STEP 7 or to a watch table in TIA Portal. With the sensor disconnected, the value should sit at
0(voltage mode) or0(current mode with 0 mA input). With a known input applied (e.g., 10.00 V from a calibrator), the value should read27648(±10 V full scale, 13-bit signed). - Engineering units scaling: Confirm that the scaled engineering value matches the input. For a 4-20 mA loop with 0-100 °C transmitter: at 4 mA the value should be 0.0 °C, at 20 mA the value should be 100.0 °C, at 12 mA (mid-scale) the value should be 50.0 °C.
- Channel cross-talk check: With one channel at full scale and the adjacent channel at zero, confirm that the adjacent channel reads within ±1 LSB of zero. Excessive cross-talk indicates a Mana (analog ground) wiring fault.
- Diagnostic interrupt test (if used): Disconnect the sensor wire on channel 0. Within 1 s the OB82 diagnostic interrupt OB should be called (visible in the CPU diagnostic buffer). Reconnect the wire; OB82 should be called again with the "fault cleared" status.
- Run time: Allow the CPU to run under load for at least 15 minutes. Monitor the analog values for drift; if any channel drifts more than ±2 LSBs over 15 minutes, suspect a loose terminal or a shared Mana loop that is too long.
Related Case: SM 321 Digital Input Replacement
The same principles apply to SM 321 digital input modules. The question of replacing a 6ES7 321-1BH02-0AA0 with a 6ES7 321-1BH50-0AA0 is straightforward because both use the same 40-pin front connector and the same addressing scheme. Differences to be aware of:
| Parameter | 6ES7 321-1BH02-0AA0 | 6ES7 321-1BH50-0AA0 |
|---|---|---|
| Inputs | 16 DI | 16 DI |
| Voltage | 24 V DC | 24 V DC |
| Input filter (typ.) | 3 ms | 3 ms (1BH50-0AA0) |
| Front connector | 40-pin | 40-pin |
| Galvanic isolation | Yes | Yes |
| Addressing | Byte-aligned (IB x, IB x+1) | Byte-aligned (IB x, IB x+1) |
Because the pinout, address range, and filter timing are compatible, the 1BH02-to-1BH50 swap is a true drop-in replacement after updating the hardware catalog entry.
Common Field Issues and Troubleshooting
| Symptom | Likely Cause | Resolution |
|---|---|---|
| Module not detected in HW Config after replacement | Wrong slot order or HSP not installed (1KF02) | Install HSP or update hardware catalog; verify slot number matches the physical slot |
| Channel reads -32768 (underrange) on all configured channels | Mana (analog ground) not wired or wired to wrong terminal | Re-terminate Mana on the correct pin (1, 2, 3, or 4 depending on channel group) |
| Reading stable but offset by ~1000 LSBs | Thermocouple mode used on 7KB01 swapped to 1KF02 which does not support TC | Replace module with a TC-capable SM 331 (7PF01 / 7PF11) or convert sensor to 4-20 mA |
| CPU goes to SF (System Fault) immediately after replacement | Diagnostic interrupt enabled but channel configured for an unsupported range | Disable diagnostics or correct the channel measurement type |
| Existing user program reads garbage from new module | User program references addresses > PIW 260 (above original 7KB01 range) | Update user program to reference PIW 256-270 in correct channel order, or remap channels in HW Config |
| Module hot-swapped and backplane bus error | 1KF01 / 1KF02 do not support hot swap | Always power down the rack before replacing 1KF01/1KF02 modules |
Safety, Standards, and Compliance Notes
- All replacement work on the S7-300 rack must be performed with the rack de-energized and locked out per IEC 60204-1 / NFPA 70E.
- Analog input cabling for the SM 331 should use shielded twisted pair with the shield grounded at the cabinet entry only (single-point ground) to minimize EMC coupling. Refer to the SIMATIC S7-300 Module Data manual for the maximum cable length and EMC guidelines.
- If the module is being used in a safety-related function (SIL 1 / SIL 2), additional constraints from IEC 61508 / IEC 61511 apply and the module selection must be reviewed against the safety manual; standard SM 331 modules are not safety-rated and cannot be used in a SIL path without additional qualification.
- The 7KB01 hardware interrupt capability (channel-level) cannot be replicated by the 1KF01/1KF02 (group diagnostic only). If the user program relies on hardware interrupts from the analog module, this functionality must be moved into the user-program scan cycle or replaced with a different module.
Frequently Asked Questions
Can I directly reuse the wiring from a 6ES7331-7KB01-0AB0 when replacing it with a 6ES7331-1KF02-0AB0?
No. The 7KB01 uses a 20-pin front connector (6ES7392-1AJ00-0AA0) and the 1KF02 uses a 40-pin front connector (6ES7392-1AM00-0AA0). The connector block and pinout are entirely different, so the existing wiring must be re-terminated on a new 40-pin connector using the 1KF02 pin assignment (channels 0-7 on pins 5-20, Mana returns on pins 1-4).
Can I reuse the wiring when replacing 6ES7331-1KF01-0AB0 with 6ES7331-1KF02-0AB0?
Yes. Both modules use the same 40-pin front connector and identical pinout. The connector block can be removed from the old module and re-seated on the new module without re-termination. Only the STEP 7 / TIA Portal hardware catalog entry needs to be updated from 1KF01 to 1KF02.
The 7KB01 was wired for thermocouples. Will the 1KF02 read thermocouples?
No. The 1KF01 and 1KF02 do not support direct thermocouple input. They accept voltage (U), current (I), resistance (R), Pt100, Ni100, Ni1000, and LG-Ni1000 only. For thermocouple inputs use the SM 331-7PF01-0AB0 or 7PF11-0AB0 instead, or convert each thermocouple to a 4-20 mA loop with an external transmitter.
Will the user program continue to work after replacing the 7KB01 with the 1KF02?
In most cases, yes. The 1KF02 reserves the first two input words (PIW 256 and PIW 258) for channels 0 and 1, which matches the original 7KB01 address space. Any code that references only those two words will continue to operate unchanged. Code that references higher addresses (PIW 260 and above) must be reviewed because those addresses now correspond to channels 2-7 of the 1KF02.
Is it safe to hot-swap the 1KF02 module with the rack powered?
No. The 1KF01 and 1KF02 do not support removal/insertion with the backplane bus active. The CPU must be in STOP and the 24 V rack supply must be disconnected before the module is removed. Always follow the lockout/tagout procedure for your plant.