Resolving the SINAMICS "Shutdown Paths Require Testing" Warning on Power-On
When commissioning or maintaining a machine driven by Siemens SINAMICS S120 drives configured under Safety Integrated (SI) with a SINUMERIK controller, the alarm "Shutdown paths require testing" (yellow/info-level message, F-CPU/SI-coded) can appear after a power-on cycle. This article provides the field-engineering depth required to identify the root cause, apply a reset, and isolate the intermittent hardware condition behind it.
1. Problem Statement
After a controlled or uncontrolled power-off / power-on of a multi-axis machine (e.g., a two-arm feeder with 8 axes – 4 per arm), one or more axes show the SI warning text:
"Shutdown paths require testing"
The symptom is characteristically intermittent:
- It may not appear on every boot.
- It may appear only on certain axes (in field reports, typically only one arm of a dual-arm configuration).
- It may appear on multiple identical machines built with the same configuration (5 machines in one field report).
- The remaining time displayed in
P9659can drop to0at the moment of power-on, even though it was non-zero before the previous power-off.
2. Affected Configurations
| Item | Typical Value in Field Reports |
|---|---|
| Controller | SINUMERIK ONE or 840D sl |
| Drive | SINAMICS S120 (CU320-2 / CU320-2 PN) |
| Motor Modules | Single or double-axis modules |
| Safety Functions | STO, SS1, SS2, SOS, SLS, SDI, SLP (Extended) |
| Number of Axes Tested in Block | Up to 6 (per Siemens Support ID 109974210) |
| Relevant Parameters |
P9659, r9773, r9774, r9780, r9782
|
| Diagnostic Bit |
r9773.31 = 1 → "Shutdown paths must be tested" |
3. Root Cause Analysis
The "Shutdown paths require testing" warning is raised by the Forced Checking Procedure (FCP), also called the Dynamic Test, of the SINAMICS Safety Integrated functions. The FCP exists because the safety shutdown paths (typically STO via the Safe Torque Off hardware channel) are otherwise dormant for long periods. The standard requires them to be exercised at least once within a configured interval to prove that the wiring, the safe inputs, and the drive's safe shutdown path are still functional.
SI tracks two time variables:
-
P9659– SI FCP remaining time in hours (e.g.,9000.00= 9000 hours remaining before mandatory test). -
r9780/r9782– Counter of how many times the FCP has been executed successfully versus faulted.
Setting bit r9773.31 = 1 indicates that the FCP must be executed. Siemens' standard remediation is the forced check using the test stop sequence (see Siemens Application Note – Testing shutdown paths). However, in production environments the most common reset is to cycle the STO via the wired E-Stop chain.
3.1 Why the warning may show at power-on even when P9659 > 0
The key behavior reported in the field is that P9659 shows hours remaining (e.g., 9000 h) before power-off, but on the very next power-on the FCP flag r9773.31 is already set and P9659 reads 0. There are three engineering-explainable causes:
-
Non-volatile counter drift on abrupt power removal. The remaining-time value is mirrored between the Control Unit and the Motor Module. If the CU is powered down before the save cycle (typically after SI power-up complete state, ~30 s), the CU's mirror can be reset to
0on next boot, while the Motor Module still holds a non-zero value. The drive then declares the FCP required. -
STO pulse was effectively not retracted. If the E-Stop line is wired such that a power-on occurs with the STO inputs in an undefined or noisy state for a few ms, the drive registers this as a self-test trigger and sets
r9773.31. - One specific hardware channel is intermittently failing the FCP. A corroded contact, marginal 24 V supply, or noisy shielded cable on the safe input path of a single axis can cause the internal self-test to fail the verification and flag the FCP as required.
The fact that 5 identical machines exhibit the same fault localized to the same physical arm strongly points to cause (3): a hardware item (cable, terminal, encoder, or Motor Module) is failing the internal self-test intermittently and only on those axes that share a cable run or terminal strip.
4. Diagnostic Procedure
4.1 Read the SI Status Word
Go online with the SINUMERIK HMI or Starter / Startdrive / TIA Portal and navigate:
Drive unit → Drives → [Axis name] → Functions → Safety Integrated
Inspect the following:
| Parameter | Meaning | Expected vs. Fault |
|---|---|---|
r9773.0 |
SI commissioning mode active | 0 = commissioned (OK) |
r9773.1 |
SI parameters need to be acknowledged | 0 = OK |
r9773.31 |
Shutdown path test required | 1 = FAULT STATE (this article) |
P9659 |
SI FCP remaining time (h) | Field report: 9000 h expected; reads 0 → out-of-sync |
r9780 |
FCP counter – successful | Should increment on each test |
r9782 |
FCP counter – faulted | If incrementing, hardware issue is present |
4.2 Capture Drive Buffers
Before any reset, download the safety message buffer for each axis (r9771 array) and the regular fault buffer. Look for F01611 or F30611 series messages that indicate the FCP failed due to a hardware defect.
4.3 E-Stop Wiring Continuity
With the machine de-energized, measure the resistance of the dual-channel E-Stop chain per axis:
- Channel 1 path (e.g., F-DI 0): expected < 1 Ω end-to-end.
- Channel 2 path (e.g., F-DI 1): expected < 1 Ω end-to-end.
- Cross-talk between channels: > 1 MΩ @ 500 V.
5. Standard Reset Procedure
The Siemens-recommended way to clear r9773.31 after confirming the safety circuit is intact is to perform the Forced Checking Procedure:
- Ensure machine is in a safe state, all personnel clear, drives ready but not enabled.
- Press the E-Stop pushbutton (engage STO).
- Verify STO active for the affected axes via
r9773and the drive LED indicators (yellow flashing on SINAMICS). - Hold E-Stop for at least the configured debounce + test window (typical minimum 500 ms; check
P9650/P9651). - Release E-Stop.
- Acknowledge the safety messages via the configured ack mechanism (e.g.,
DB31.DBX7.7– SI acknowledge). - Power-cycle or run the test stop sequence via the PLC FB (
FB11/ safety FB per Siemens library).
Per Siemens Support ID 109974210, the shutdown paths of up to 6 axes can be tested sequentially using the dedicated block; verify the assignment in the FC block so that the FCP is forced on each axis in turn, not only on the ones whose r9773.31 was set.
6. Isolating the Intermittent Hardware Fault
Because the field report shows that the same warning reappears on power-on in roughly the same axes, the E-Stop reset is masking a real hardware issue. Use this matrix to localize it:
| Test | Method | Pass/Fail Indicator |
|---|---|---|
| Swap motor cable (right ↔ left arm) | Reassign axis to opposite motor module temporarily | If warning follows the cable → cable fault |
| Swap Motor Module | Exchange two Motor Modules of the same rating | If warning follows the MM → MM electronics fault |
| Swap encoder cable (DRIVE-CLiQ) | Exchange DRIVE-CLiQ paths | If warning follows encoder → encoder or SMC/SME module |
| Replace terminal block on E-Stop chain | Pull and reseat Phoenix/Spring terminals | If warning disappears → oxidized contact |
| Measure 24 V under load | Scope the F-DI supply at the drive terminal | If sags > 2 V during contact bounce → supply issue |
p0099 or the commissioning tool to low / minimum, complete the swap, then restore.
7. Why the Fault Appears on Power-On Only
Three engineering reasons combine to explain the field observation:
- STO is not asserted before power-off. If the E-Stop is not pressed before the main contactor drops, the SINAMICS sees a hard power-down with STO inactive. This is allowed, but the FCP self-test on the next power-up will require a verification cycle, and on borderline hardware (e.g., marginal capacitors on the F-DI filter) it can flag the path as untested.
- Power-on inrush noise. The first 200–800 ms of a power-on produce a large inrush on the DC bus and on the 24 V rail. If F-DI filtering is on the edge, the safety logic can interpret transient logic levels as a failed test and demand a re-test.
- Marginal encoder or SMC module. The Extended Safety Functions on SINAMICS (SS2, SLS, SDI, etc.) close the loop through the encoder. A single dropped sample during the power-on self-test will flag the FCP.
8. Recommended Long-Term Mitigation
- Configure
P9659to a value that fits the maintenance window (Siemens default 8760 h = 1 year). - Implement a PLC-driven FCP at every scheduled shift change or every 24 h, using the FB from the Siemens safety library. This guarantees the warning never propagates to power-on.
- Replace Phoenix-style screw terminals that show oxidation on the E-Stop chain.
- Verify 24 V supply to F-DI with an oscilloscope at the drive terminal, not at the cabinet.
- Always issue E-Stop before opening the main disconnect. This keeps the SINAMICS in a known STO state across the power-down.
- Document the parameter set in the machine's safety acceptance report (per IEC 61800-5-2 / ISO 13849).
9. Verification After Reset
After performing the FCP reset, verify the following sequence before returning the machine to production:
- Online check:
r9773.31 = 0for all axes. -
P9659should display a positive non-zero value (e.g., 8759 h if reset just after the 1-year mark). - Issue an E-Stop and confirm the drive immediately drops torque (STO active, drive LED goes yellow flashing).
- Release E-Stop, acknowledge, and verify the drive re-enables without warning.
- Run a controlled motion on each of the 8 axes at low velocity; verify no F01611 / F30611 appears in the buffer.
- Power-cycle the machine twice to confirm the warning does not return on subsequent cold starts.
10. Related Fault Codes and Parameters
| Code | Type | Meaning |
|---|---|---|
| F01610 | Fault | SI: defective output stage during test stop |
| F01611 | Fault | SI: defect detected during forced checking procedure |
| F30611 | Fault | SI MM: defect during FCP (Motor Module side) |
| C01611 | Warning | SI: forced checking procedure required (this article) |
| A01697 | Info | SI: forced checking procedure is required |
Cross-references in Siemens documentation:
- SINUMERIK ONE: Testing shutdown paths (ID 109974210)
- Application Note – Testing shutdown paths (PDF)
11. Standards Context
The forced checking procedure is mandated by IEC 61800-5-2 (Adjustable speed electrical power drive systems – Safety requirements) and is a key element of ISO 13849-1 (PL e / Cat 4) designs. The purpose is to detect a dormant fault in the shutdown path that would prevent the safety function from operating on demand. The test must be executed at least once within the FCP interval, and any failure of the test places the drive into a safe state and demands operator intervention. Always verify that the FCP interval recorded in your machine's safety validation report matches P9659.
What does the SINAMICS "Shutdown paths require testing" warning mean?
It means the drive's Safety Integrated Forced Checking Procedure (FCP) timer has elapsed or the safety self-test failed. The relevant diagnostic bit is r9773.31 = 1, and the remaining-time parameter is P9659. Cycle the E-Stop and acknowledge the safety message to clear it, per Siemens Support ID 109974210.
Can I reset the warning just by pressing the E-Stop?
Yes, if the safety circuit is hardwired and intact, pressing and releasing the E-Stop followed by the standard SI acknowledge will clear r9773.31. However, if the warning reappears on the next power-on, the FCP self-test is detecting a real hardware issue, not a timer expiry.
Why does P9659 show 0 hours immediately after power-on, even though it was 9000 h before shutdown?
The FCP remaining-time counter is mirrored non-volatilely between the Control Unit and the Motor Module. If the CU is powered down before the save cycle completes (~30 s after SI boot), the mirror can be reset on the next boot. To prevent this, always keep the 24 V supply to the SINAMICS Control Unit live for at least 30 seconds after power-on, and issue E-Stop before opening the main disconnect.
Why does the warning appear only on the right arm of a two-arm machine?
The asymmetry points to a hardware item specific to that arm: an oxidized E-Stop terminal, a marginal 24 V supply on that terminal strip, a failing Motor Module, or an encoder/SMC module with intermittent DRIVE-CLiQ errors. Swap the right and left Motor Modules (with topology comparison level lowered) to determine whether the warning follows the axis or stays in the same physical position.
What is the correct procedure to test the shutdown paths?
Per Siemens Support ID 109974210, the shutdown paths of up to 6 axes can be tested sequentially using the dedicated FB. Ensure Extended Safety Functions are active (r0108.13 = 1), drive is in commissioning or ready state, and follow the FCP block parameterization to assign each axis. The mechanical system must be in a safe state because the test internally pulses STO.