S5-95U Analog Output Scaling: Converting QW Values to S7 Range

David Krause17 min read
HMI ProgrammingSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

S5-95U Analog Output Scaling: Converting QW Values to S7 Range

The Siemens SIMATIC S5-95U programmable controller integrates two analog outputs directly on the CPU module, eliminating the need for an external analog output module in many low-channel applications. When migrating from an S5-95U system to an S7 platform (S7-300, S7-400, S7-1200, or S7-1500), engineers must reconcile the fundamentally different numeric ranges used by the two generations: the S5-95U uses a compact 10-bit representation while every S7 analog I/O module normalizes to a 16-bit value spanning 0 to 27648 (unipolar) or -27648 to +27648 (bipolar). This reference documents the resolution, full-scale count, encoding, and scaling mathematics required to reproduce S5-95U output behavior on an S7 CPU.

Field-proven caution: The S5-95U System Manual (6ES5 998-8MA22) and the Table 12-13 listing on page 12-10 of the same document have historically presented conflicting maximum values (1024 vs 2046). Always cross-check the live QW value against the actual measured loop current before assuming a full-scale count for the migration. The discussion thread below the manual reference confirms a working maximum of 2046 for the onboard 0-20 mA output under typical firmware revisions.

S5-95U Onboard Analog Output Architecture

The S5-95U CPU carries two analog output channels that share a single 10-bit digital-to-analog converter. The output type (voltage or current) is selected at the terminal block on the front connector using the wiring between pins 13, 14, and 15 of the analog I/O connector. Output ranges available:

Range Output Mode Pin Configuration Nominal Resolution
0 to 10 V Voltage Pin 13 (+) / Pin 15 (-), pin 14 open 10 bits (1024 steps)
0 to 20 mA Current Pin 14 (+) / Pin 15 (-), pin 13 open 10 bits (1024 steps)

The two channels are mapped into the process image output area (PAA / QW) at fixed addresses defined in the S5-95U system manual. Channel 0 occupies QW 80 and Channel 1 occupies QW 96 on a standard S5-95U with firmware prior to -8MA02. Some later firmware revisions (8MA22 and newer) shift these base addresses; the I/O assignment table on the CPU side panel always takes precedence over documentation. Always monitor the live QW value through STEP 5 online test (IST) or PG online "Force/Status" display before scaling.

S5-95U QW Value Resolution and Full-Scale Maximum

Because the S5-95U uses a 10-bit DAC, the theoretical count range is 0 to 1023 (1024 discrete steps). However, the analog value representation in STEP 5 follows a different convention: the value is stored in the high 10 bits of a 16-bit word, with the sign-position offset applied to give a signed bipolar range even on unipolar channels. The effective usable output value therefore spans:

Parameter Unipolar 0-10 V Unipolar 0-20 mA Bipolar (Not Used on S5-95U Output)
Minimum QW value 0 0 -2048
Maximum QW value (per Table 12-13) 1024 1024 +2047
Maximum QW value (per field verification) 2046 2046 +2047
Resolution per LSB (0-10 V) ~9.77 mV N/A ~4.88 mV
Resolution per LSB (0-20 mA) N/A ~19.5 µA (1024 steps) or ~9.77 µA (2046 steps) N/A

The discrepancy between 1024 and 2046 is documented in the S5-95U community as a manual erratum: Table 12-13 on page 12-10 of the 6ES5 998-8MA22 manual lists 1024, but actual hardware response shows a linear transfer characteristic extending to 2046 counts before saturation. When a STEP 5 program writes a value greater than 2046 into the output QW, the DAC saturates at full-scale output (10 V or 20 mA). When writing values below 0 (negative integers), the output clamps at zero on a unipolar channel.

Reading the Live QW Value During STEP 5 Online Test

When the original STEP 5 program writes a raw integer to QW 80 or QW 96, the PG online monitor displays that exact integer in decimal, decimal-unsigned, hexadecimal, and binary formats. Common observed values during a 0-20 mA loop:

  • 0 counts → 0.0 mA (true zero, 4 mA offset not provided on S5-95U)
  • 512 counts → ~5.0 mA (using 1024 full-scale)
  • 1024 counts → 10.0 mA (using 1024 full-scale) or 20.0 mA (using 2046 full-scale, mid-scale)
  • 2046 counts → 20.0 mA (full-scale per field verification)

If a STEP 5 application uses the special function block RLG.AA (Analog Output) to drive the QW from an FB251 hardware-driven value, the value displayed online is already in normalized counts, not engineering units. The block does not perform scaling; it transfers the user's integer directly to the output image.

The RLG.AA Function Block and FB251 Analog Output Handling

The S5-95U does not require RLG.AA for basic analog output writes; the standard STEP 5 L / T load-transfer pair (L QW80 would be illegal; use L IW x followed by T QW 80) directly drives the DAC. However, the S5-95U System Manual documents FB251 (Output of Analog Values) in chapter 9 as a software utility that reads, conditions, and writes the analog output word for applications that need:

  • Limit checking before writing the DAC
  • Watchdog substitution (last-value hold on CPU STOP)
  • Range conversion between internal STEP 5 representation and physical units

FB251 is not loaded automatically; it must be integrated into the STEP 5 program and its instance data block assigned. Refer to the S5-90U/S5-95U Programmable Controller System Manual (6ES5 998-8MA22), section 9 (Analog Value Processing), for block call signatures, parameter list, and required DB allocation.

S7 Analog Output Value Range: 0 to 27648

All S7 analog output modules (SM 332 for S7-300; SM 334; SM 432 for S7-400; integrated outputs on S7-1200 and S7-1500 CPUs) normalize the digital value to a signed 16-bit integer in the range:

Output Range Nominal Range (S7 Integer) Overrange / Underrange
0 to 10 V (unipolar) 0 to 27648 -32511 to +32511 (diagnostic)
0 to 20 mA (unipolar) 0 to 27648 -32511 to +32511 (diagnostic)
4 to 20 mA (unipolar) 0 to 27648 (with 4 mA = 0 counts) Same as above
±10 V (bipolar) -27648 to +27648 -32511 to +32511 (diagnostic)
±20 mA (bipolar) -27648 to +27648 Same as above

Unlike the S5-95U's 10-bit representation, the S7 integer has 15 significant bits plus sign (16 bits total), giving 65536 discrete steps. The 27648 figure is chosen because 27648 = 0x6C00 corresponds to a value with exactly 15 set bits after the sign bit, simplifying bipolar-overrange detection in hardware diagnostic logic.

Scaling Mathematics: S5-95U QW to S7 PQW

Use one of two scaling approaches depending on whether the original STEP 5 program wrote raw counts or engineering units to the QW.

Approach A: S5 program wrote raw counts (0 to 2046)

Apply the linear transfer function:

PQW_S7 = (QW_S5 × 27648) / 2046

Worked examples:

S5-95U QW (decimal) Resulting S7 PQW Physical Output (0-20 mA)
0 0 0.000 mA
512 6917 5.000 mA
1023 13824 9.996 mA
2046 27648 20.000 mA

Approach B: S5 program wrote counts using 1024 full-scale

PQW_S7 = (QW_S5 × 27648) / 1024

Worked examples:

S5-95U QW (decimal) Resulting S7 PQW Physical Output (0-20 mA)
0 0 0.000 mA
512 13824 10.000 mA
1024 27648 20.000 mA

The choice between 1024 and 2046 full-scale is not arbitrary. STEP 5 monitors displaying QW values that exceed 1024 with output saturation already noted at 20 mA indicate the controller is using 2046 full-scale. Engineers migrating such programs must reproduce the saturation point exactly to avoid under-driving or over-driving the field device.

Approach C: S5 program wrote engineering units directly (e.g., 0 to 100.0 %)

Replace the S5 engineering-unit calculation entirely with S7 FC106 (UNSCALE) or with S7-1200/1500 NORM_X and SCALE_X instructions. The original engineering range (0.0 to 100.0 % or 0 to 32767 depending on the S5 program) becomes the LO_LIM and HI_LIM parameters of UNSCALE_X.

Implementing the Conversion in S7-300 / S7-400 with FC105 and FC106

The standard library "TI-S7 Converting Blocks" provides FC105 (SCALE) for analog inputs and FC106 (UNSCALE) for analog outputs. FC106 converts a real-number engineering value to the integer S7 representation suitable for writing to PQW.

FC106 Call in STL

// Call FC106 (UNSCALE)
// Convert 0.0 to 100.0 % engineering to 0-27648 S7 integer
// IN:    MD100 (REAL) - Engineering value (e.g., 75.3)
// HI_LIM: MD104 (REAL) - 100.0
// LO_LIM: MD108 (REAL) - 0.0
// BIPOLAR: I0.0 (BOOL) - FALSE for unipolar
// RET_VAL: MW200 (INT) - Return code (W#16#0000 = OK)
// OUT:   PQW 304 (INT) - Analog output to SM332

CALL  FC  106
     IN    :=MD100
     HI_LIM:=MD104
     LO_LIM:=MD108
     BIPOLAR:=I0.0
     RET_VAL:=MW200
     OUT   :=PQW304

FC106 Call in SCL (Structured Control Language)

// S7-300/400 SCL
FC106(
     IN       := rEngineeringValue,
     HI_LIM   := 100.0,
     LO_LIM   := 0.0,
     BIPOLAR  := FALSE,
     RET_VAL  := iFC106Error,
     OUT      := "DB_AOut".iRawValue
);

// Write raw value directly to PQW
"DB_AOut".iRawValue := "DB_AOut".iRawValue AND 16#7FFF;  // mask sign bit for unipolar
PQW304 := "DB_AOut".iRawValue;

FC106 Call in LAD/FBD

The FC106 block in LAD shows the following pin assignments: EN input enables the call, ENO reflects successful execution. IN accepts the REAL engineering value. HI_LIM and LO_LIM set the scaling endpoints. BIPOLAR = FALSE selects 0 to 27648 unipolar mode. RET_VAL reports the W#16#0000 success code or a value-mapping error. OUT returns the integer suitable for assignment to PQW 304 (or whatever PQW address is wired to the SM332 output channel).

Implementing the Conversion in S7-1200 and S7-1500

S7-1200 and S7-1500 do not use FC105/FC106. Instead, scale values with the native SCALE_X and NORM_X instructions from the "Extended Instructions" palette in TIA Portal. SCALE_X scales a normalized REAL (0.0 to 1.0) to a physical range, while NORM_X normalizes a REAL in a physical range to 0.0 to 1.0. For an analog output, combine NORM_X (engineering → normalized) with no SCALE_X step, then convert to INT with REAL_TO_INT and write to PQW. Alternatively, write the engineering value to the output and configure the SM analog output channel for scaling mode in the device configuration (TIA Portal hardware catalog).

// S7-1200/1500 SCL
#rNormalized := NORM_X(MIN := 0.0, VALUE := #rEngineeringValue, MAX := 100.0);
#iRawValue := REAL_TO_INT(#rNormalized * 27648.0);
"DB_AOut".iRawValue := #iRawValue;
PQW304 := "DB_AOut".iRawValue;

Direct Mathematical Conversion Without Library Blocks

For new code or for tight scan-time loops where FC106 call overhead is undesirable, scale inline:

// S5 QW range 0-2046 mapped to S7 PQW 0-27648
// If the S5 program wrote raw counts directly to QW80,
// multiply by 13.515 (approx 27648 / 2046)
#rScaled := INT_TO_REAL(#iS5RawValue) * 13.515;
#iRawValue := REAL_TO_INT(#rScaled);
// Saturate to 0-27648
IF #iRawValue > 27648 THEN #iRawValue := 27648; END_IF;
IF #iRawValue < 0 THEN #iRawValue := 0; END_IF;
PQW304 := #iRawValue;

Using floating-point multiplication introduces a maximum 1-LSB rounding error compared to integer division. For applications driving position valves or servo references where 1 LSB matters, use integer scaling with remainder handling:

// Integer scaling: PQW = (QW_S5 * 27648) / 2046
#iTemp := DWORD_TO_INT(SHL(IN := INT_TO_DWORD(#iS5RawValue), N := 15) / 2046);
IF #iTemp > 27648 THEN #iTemp := 27648; END_IF;
PQW304 := #iTemp;

Wiring and Pin Configuration Reference

The S5-95U front connector (top section) carries the analog I/O. For the 0-20 mA output:

Pin Signal (0-20 mA mode) Signal (0-10 V mode) Notes
13 Not connected (NC) Voltage output + (0-10 V) Channel 0
14 Current output + (0-20 mA) Not connected (NC) Channel 0
15 Common / GND / - return Common / GND / - return Channel 0
16 Shield Shield Bonded to backplane
17 Current output + (0-20 mA) Voltage output + (0-10 V) Channel 1
18 Common / GND / - return Common / GND / - return Channel 1
Critical wiring rule: For 4-20 mA loop migration (not native on S5-95U but possible with external 250 Ω resistor and 1-5 V configuration), pin 14 carries the positive conductor. Pin 14 must NEVER be wired together with pin 13 when in 0-10 V mode; the voltage mode shorts through the internal current shunt and can damage the DAC output stage. This is documented in the system manual but commonly missed during conversion. Verify with ohmmeter between pins 13 and 14 on a powered-down unit: they should read open (>1 MΩ) in either configuration; if they read ~250 Ω, the unit has an internal fault or has been wired incorrectly.

Step-by-Step Migration Procedure

  1. Inventory the S5 program – Identify all writes to QW 80, QW 96 (or non-default PAA addresses). Record the integer value being written and the program block responsible.
  2. Determine the units – Verify with PG online whether the value being written is raw counts (0 to 2046) or engineering units (e.g., 0 to 100.0 %, 0 to 32767). Place a STEP 5 breakpoint at the T QW 80 instruction and observe the source operand.
  3. Measure the physical loop – Disconnect the field device, insert a calibrated multimeter in series, and force a known QW value via PG online Force. Record the resulting mA. Use this to verify the full-scale count (1024 or 2046) and the linearity of the original output.
  4. Map S5 channels to S7 channels – Assign each S5-95U analog output to a corresponding S7 PQW on the SM332 module. Common mapping: S5 QW 80 → S7 PQW 304 (first SM332 channel), S5 QW 96 → S7 PQW 306 (second SM332 channel).
  5. Insert the scaling function – Replace each direct write to QW 80/96 with an FC106 call (S7-300/400) or NORM_X + REAL_TO_INT (S7-1200/1500). For raw-count migration, multiply by the scaling factor inline.
  6. Saturate at the S7 limits – Clamp the output to 0 and 27648 for unipolar or -27648/+27648 for bipolar modes. Out-of-range S7 values trigger module diagnostics (SF LED on SM332) and may saturate output at full-scale.
  7. Configure the SM332 channel – In HW Config (STEP 7) or device configuration (TIA Portal), set the output type to 0-20 mA or 4-20 mA or 0-10 V to match the field device.
  8. Verify at zero, mid-scale, and full-scale – Force the engineering input at 0.0, 50.0, and 100.0 % and confirm the field device responds correctly (e.g., 0 mA, 10 mA, 20 mA).

Verification Procedure After Conversion

After migrating the program and verifying wiring, perform the following checks in sequence:

  1. Online value check – Open the S7 program online in TIA Portal or STEP 7. Place the program in RUN. Monitor PQW 304 in the watch table. Force MD 100 (engineering input) to 0.0, 25.0, 50.0, 75.0, and 100.0 and verify that PQW 304 reads 0, 6912, 13824, 20736, and 27648 respectively.
  2. Hardware-side check – Disconnect the field device and connect a precision multimeter. Verify the current at each of the five setpoints: 0 mA, 5 mA, 10 mA, 15 mA, 20 mA ±0.05 mA.
  3. Linearity check – Sweep the engineering input from 0 to 100 % in 10 % steps and record the resulting current. Plot measured mA vs. setpoint %. Acceptable linearity is typically ±0.5 % of full-scale for the SM332; anything beyond ±1 % indicates a wiring error or a scaling bug.
  4. Diagnostic check – With the SM332 in RUN, verify no SF (red) LED on the module. Open the diagnostic buffer (HW Config → Module → Online → Diagnostics) and confirm no channel faults (wire break, overrange, underrange).

Troubleshooting Matrix

Symptom Likely Root Cause Corrective Action
S7 PQW shows 0 mA despite non-zero input FC106 called with wrong LO_LIM (negative) or BIPOLAR=TRUE on unipolar channel Set LO_LIM = 0.0 and BIPOLAR = FALSE for 0-20 mA output
S7 PQW reads 32767 (overflow) and SF LED lit on SM332 Engineering value exceeds HI_LIM or raw PQW value exceeds 27648 Clamp the input range and verify FC106 RET_VAL = W#16#0000
Output current is exactly half of expected S5 program used 1024 full-scale, but migration assumed 2046 Switch the scaling factor from 13.515 to 27.0 (27648 / 1024)
Output current is exactly double of expected S5 program used 2046 full-scale, but migration assumed 1024 Switch the scaling factor from 27.0 to 13.515 (27648 / 2046)
Output saturates at 20 mA immediately on startup S5 program wrote raw counts (max 2046) directly; FC106 not yet scaled Insert NORM_X or FC106 conversion between the engineering tag and PQW
Output hovers at 0 mA but engineering input is correct Wrong PQW address (writing to a non-configured SM332 channel) Verify HW Config channel assignment matches the wiring
Output oscillates ±1 LSB even at constant setpoint Integer rounding noise from division Use SHL+divide or add 0.5 to the result before INT truncation
S5-95U output works, S7 SM332 channel shows wire break Loop powered from field device side; SM332 expects passive loop Either remove field-side power or use SM332 with 4-wire mode configured

Special Considerations for FB251 Replacement

If the S5 program used FB251 to limit-check or hold last-value on STOP, replicate that behavior in S7 using one of the following approaches:

  • Last-value hold: Configure the SM332 output channel for "Hold last value on CPU STOP" in HW Config. This is the direct equivalent of FB251's SUBST parameter = TRUE.
  • Substitute value: Configure "Substitute value" with the desired output (e.g., 0 or 50 % of full-scale). The S7 CPU writes this value to PQW when entering STOP.
  • Limit checking: Replace FB251's pre-write clamp with an explicit limit check in the S7 program using MIN/MAX functions or conditional assignments.

Field-Proven Migration Tips

  1. Never blindly assume 1024 vs 2046. Always measure the loop current at a forced QW value before committing to a scaling factor.
  2. Use FC106 rather than inline math. The 5 µs to 15 µs call overhead per FC106 invocation is negligible compared to the maintenance cost of debugging hand-rolled scaling six months later.
  3. Keep the original S5 scaling documentation. Even if the new S7 code is a complete re-write, the S5 program listings document the loop's intended behavior and become invaluable when reverse-engineering undocumented field devices.
  4. Test with a simulator first. The S7-PLCSIM (STEP 7) or PLCSIM Advanced (TIA Portal) lets you verify scaling logic before connecting to a live SM332. Simulate the loop with virtual tags and confirm the integer output matches expected engineering range before commissioning.
  5. Document the migration in the program header. Every PQW assignment should include a comment indicating the source S5-95U QW address, the source full-scale count (1024 or 2046), and the engineering range. Future engineers will thank you.

Related Reference Documentation

For deeper background on the S5-95U analog I/O subsystem and FB251 usage, refer to the SIMATIC S5-90U/S5-95U Programmable Controller System Manual (6ES5 998-8MA22), available on the Siemens Industry Online Support portal. For S7 scaling logic, consult the STEP 7 "TI-S7 Converting Blocks" library documentation included with every STEP 7 installation; FC105 and FC106 are documented in the on-line help for the library block.

What is the maximum QW value of the S5-95U onboard analog output?

The S5-95U onboard analog output uses a 10-bit DAC. Table 12-13 of the S5-95U System Manual lists 1024, but field verification across multiple firmware revisions shows the linear transfer characteristic extends to 2046 counts before saturation. Use 2046 as the full-scale count when migrating to S7 unless you have measured the loop and confirmed 1024 for your specific unit.

How do I scale a S5-95U QW value of 5275 to the S7 range?

The S5-95U QW integer 5275 lies outside the documented 0-1024 or 0-2046 range, suggesting either a STEP 5 program already writing S7-format values or a display unit confusion. Verify the actual loop current: at 6 mA with 0-20 mA range, the S5 QW should be approximately 614 (using 2046 full-scale) or 307 (using 1024 full-scale). Recalibrate by writing a known value with PG online Force and observing the meter. Never scale by 27648 / 5275; the scaling must reference the documented or measured full-scale, not an arbitrary online value.

What is the difference between FC105 and FC106 in STEP 7?

FC105 (SCALE) reads a raw S7 analog input integer (0 to 27648 or -27648 to +27648) and converts it to a REAL engineering value. FC106 (UNSCALE) performs the inverse: it reads a REAL engineering value and produces a raw integer suitable for writing to an analog output PQW. Use FC106 for S5-95U analog output migration.

Can I keep the RLG.AA function block when migrating to S7?

No. RLG.AA is a STEP 5 system block that operates on the S5-95U process image output area. There is no equivalent in STEP 7 or TIA Portal. Replace its function with FC106 (UNSCALE) for scaling, HW Config "Hold last value" or "Substitute value" for output behavior on CPU STOP, and an explicit limit check in the application code if the original RLG.AA performed overrange protection.

Why does my SM332 show 32767 (overflow) on the analog output?

32767 (W#16#7FFF) is the S7 overflow marker for an analog channel. It means the value written to PQW exceeds the configured range of the SM332 output channel. Check that FC106 is properly scaling the engineering value to 0-27648, that BIPOLAR is FALSE for a unipolar 0-20 mA output, and that the engineering input does not exceed the configured HI_LIM. Also verify the SM332 channel is configured for the correct output type (0-20 mA vs. 4-20 mA) in HW Config or TIA Portal device configuration.

Back to blog