Siemens S7-200 PLC Technical Reference and CPU Comparison Guide

David Krause15 min read
S7-200SiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Siemens S7-200 PLC Family Overview and Positioning

The SIMATIC S7-200 is Siemens' micro-PLC platform, designed for small standalone machines, OEM equipment, and remote telemetry applications. The S7-200 occupies the price/performance tier below the modular S7-300 and S7-400 lines, trading scalability and instruction breadth for compact form factor and lower unit cost. Across three decades the family has shipped in three distinct generations: the legacy S7-21x series (CPU 212, 214, 215, 216), the enhanced S7-22x series (CPU 221, 222, 224, 224XP, 226), and the current S7-200 SMART successor line. Detailed electrical and mechanical specifications are documented in the official SIMATIC S7-200 Programmable Controller System Manual.

Position the S7-200 against the rest of the SIMATIC portfolio as follows:

Criterion S7-200 (legacy) S7-200 SMART S7-1200 S7-300
Target application size Small machine, < 100 I/O Small machine, < 256 I/O Small/medium machine, < 256 I/O Medium/large process, > 256 I/O
Programming software STEP 7 Micro/WIN V4.0 SP9 STEP 7 Micro/WIN SMART STEP 7 Basic (TIA Portal) STEP 7 (TIA Portal)
Cost positioning Lowest (legacy / surplus) Low Mid High
Status (2024) Spare-part only Active Active Phased out for new designs
Successor path S7-200 SMART or LOGO! S7-1200 / ET 200S S7-1500 S7-1500
Engineering note: The S7-200 hardware lineage predates the broader S7 architecture and was integrated into the SIMATIC portfolio after Siemens acquired the original manufacturer. This explains some architectural and instruction-set differences when comparing the S7-200 against the S7-300/400 instruction set.

S7-21x Series CPU Specifications (Legacy Generation)

The S7-21x generation uses the STEP 7 Micro/WIN V3.x or V4.0 programming environment and is no longer in active production. Field installations remain widespread in water/wastewater, OEM machinery, and remote telemetry. Key specifications per the S7-200 system manual:

Parameter CPU 212 CPU 214 CPU 215 CPU 216
Program memory 512 words 2 K words 4 K words 4 K words
Data memory 512 words 2 K words 4 K words 5 K words
Bit execution time 1.2 µs 0.8 µs 0.8 µs 0.8 µs
On-board digital I/O 8 DI / 6 DQ 14 DI / 10 DQ 14 DI / 10 DQ 24 DI / 16 DQ
On-board analog I/O None None None None
Communication ports 1 (PPI) 1 (PPI) 1 (PPI/freeport) 2 (PPI/freeport)
Expansion modules None Up to 7 Up to 7 Up to 7
High-speed counters 2 (4 kHz) 3 (4 kHz) 3 (4 kHz) 4 (4 kHz)
PWM / pulse outputs 1 (2 kHz) 2 (2 kHz) 2 (2 kHz) 2 (2 kHz)
Real-time clock No Optional cartridge Built-in Built-in

The CPU 216 remains the most deployed legacy CPU because of its 24 DI / 16 DQ on-board density and dual PPI/freeport interfaces. Municipal water utilities operate CPU 216 fleets driving lift-station RTUs where the Siemens Modbus slave subroutine (application tip 26719739) is loaded into Subroutine 0 and polled by SCADA masters at 9.6 kbps.

Power supply requirements are identical across the S7-21x family: 85 to 264 VAC at 47 to 63 Hz with a 24 VDC sensor output delivering up to 180 mA (CPU 214/215) or 280 mA (CPU 216). Hold-up time on 24 VDC supply loss is 10 ms minimum, which is sufficient to ride through contactor coil collapse but not sufficient for graceful shutdown.

S7-22x Series CPU Specifications (Enhanced Generation)

The S7-22x series introduced parameterized subroutines (pass-by-value local variables), PID auto-tune, recipe storage on cartridge, and a redesigned STEP 7 Micro/WIN V4.0 development environment. The S7-200 system manual specifies the following comparison across the S7-22x CPUs:

Parameter CPU 221 CPU 222 CPU 224 CPU 224XP CPU 226
Program memory 4 KB 4 KB 8 KB 12 KB 16 KB
Data memory 2 KB 2 KB 8 KB 10 KB 10 KB
Bit execution time 0.22 µs 0.22 µs 0.22 µs 0.22 µs 0.22 µs
On-board digital I/O 6 DI / 4 DQ 8 DI / 6 DQ 14 DI / 10 DQ 14 DI / 10 DQ 24 DI / 16 DQ
On-board analog I/O None None None 2 AI / 1 AQ None
Communication ports 1 (RS-485) 1 (RS-485) 1 (RS-485) 2 (RS-485) 2 (RS-485)
Max expansion modules None 2 7 7 7
High-speed counters 4 (30 kHz) 4 (30 kHz) 6 (30 kHz) 6 (100 kHz + 200 kHz diff.) 6 (30 kHz)
PWM / pulse outputs 2 (20 kHz) 2 (20 kHz) 2 (20 kHz) 2 (100 kHz) 2 (20 kHz)
PID loops 8 8 8 8 8
Real-time clock Cartridge only Cartridge only Built-in Built-in Built-in

The CPU 224XP is the workhorse for motion-friendly applications because its two 100 kHz high-speed counters and 100 kHz pulse outputs can command stepper drives directly through Q0.0 and Q0.1. The CPU 226 (and 226XM) is the right choice when a pick-and-place retrofit must replace a legacy Allen-Bradley PLC-5 while driving 24 inputs and 16 outputs of I/O in the original junction-box footprint. The dual RS-485 ports let one port face the HMI and the other port face a Modbus RTU master without requiring the CP 243-1 Ethernet module.

S7-200 SMART CPU Specifications

The current generation is the SIMATIC S7-200 SMART, documented in the S7-200 SMART System Manual. It retains the S7-200 programming paradigm but adds an integrated Ethernet port, a micro SD card slot, and updated I/O density. The CPU naming convention shifts from CPU 22x to SR20/ST20/ST30/ST40/ST60.

Parameter SR20 ST20 SR30 ST30 SR40 ST40 SR60 ST60
Relay / Transistor Relay Transistor Relay Transistor Relay Transistor Relay Transistor
Digital inputs 12 12 18 18 24 24 36 36
Digital outputs 8 8 12 12 16 16 24 24
Program memory 12 KB user program (V2.5 firmware and later)
Data memory Up to 30 KB V-memory
Bit execution time 0.15 µs
Communication ports 1 RS-485 + 1 Ethernet (PROFINET-ready)
Max expansion 6 modules (EM digital, EM analog, EM RTD, EM TC)
High-speed counters Up to 6 (200 kHz on transistor CPUs)
Pulse outputs Up to 3 (100 kHz / 200 kHz on transistor)
Selection rule: Specify the relay output variant (SRxx) for 24 VDC low-current I/O, mixed-voltage solenoids, and contactor coils. Specify the transistor variant (STxx) when any high-speed counter above 30 kHz or any PTO motion profile is required. Connecting a 100 kHz pulse train into a relay output bank will damage the contacts within hours.

I/O Expansion and Module Catalog

The S7-200 family uses a side-mounted bus that carries 5 VDC power and a proprietary protocol; digital and analog expansion modules are hot-replaceable only on the S7-200 SMART. Representative EM module functions from the S7-200 system manual:

Module family Function Notes
EM 221 8 DI 24 VDC Sink/source selectable, 5 VDC and 24 VDC variants
EM 222 8 DQ 24 VDC / relay 2 A relay contact rating; transistor variants up to 5 A
EM 223 4 DI / 4 DQ combo Combines DI/DQ on one module; reduces expansion slot count
EM 231 4 AI ±10 V / 0–20 mA 12-bit resolution; configurable per channel
EM 232 2 AQ ±10 V / 0–20 mA 12-bit, voltage or current per channel
EM 235 4 AI / 1 AQ combo 12-bit, configurable ranges via DIP switches
EM 277 PROFIBUS-DP slave Bridges S7-200 to PROFIBUS master
CP 243-1 Ethernet / IT functions Sends email, serves web pages
CP 243-2 AS-Interface master Up to 62 AS-i slaves
EM 253 Positioning module Single-axis stepper/servo control

The legacy platform does not include a PROFIBUS DP master module or a dedicated ASCII/Basic interpreter module. For barcode readers and programmable instruments without ASCII capability, use the freeport USS or user-defined protocol mode on Port 0/Port 1, accepting that throughput is limited to 187.5 kbps without parity or to 115.2 kbps with proper shielded cable.

STEP 7 Micro/WIN Programming Environment

The S7-200 development tool is STEP 7 Micro/WIN V4.0 SP9 (the last release compatible with Windows 10). The environment supports three programming languages:

  • LAD (Ladder): IEC 61131-3 graphical; default for relay-logic substitution.
  • FBD (Function Block Diagram): IEC 61131-3 graphical; useful for math and signal conditioning.
  • STL (Statement List): Siemens text language; required for indirect addressing and pointer manipulation.

The editor enforces a single global symbol table across the entire project. Parameterized subroutines (introduced in the S7-22x) accept local variables that are passed by value, allowing libraries of reusable FB-style logic. However, arbitrary symbolic address mapping is restricted — you cannot assign an arbitrary byte offset to an arbitrary name without using the AT attribute workaround introduced in firmware V1.20 of the S7-22x CPUs.

Field note: For projects that exceed ~4 KB of code or that need structured multi-engineer development, upgrade to STEP 7 (TIA Portal) on the S7-1200 or S7-1500. Micro/WIN's project file (.mwp) is single-user, has no diff/merge capability, and has no source-control integration.

A minimal PID loop using the PID wizard expansion:


NETWORK 1    // Auto-tune trigger
LD     SM0.0
CALL   PID0_INIT, VB100, VW200, VW202, 0, 1.0, 0.1, 0.0
NETWORK 2    // Manual mode disable
LD     I0.0
EU
RST    M0.1

The PID0_INIT call expands to the standard Siemens PID instruction with table pointer VB100, process variable VW200, setpoint VW202, mode 0 = auto, gain 1.0, sample time 0.1 s, integral/derivative = 0 for first commissioning. The PID0 table occupies 36 bytes starting at VB100 and must not overlap any other variable region in V memory.

Communication Protocols and Interfaces

The S7-200 RS-485 ports natively support three modes:

Mode Use case Baud Master / Slave
PPI (Point-to-Point Interface) Micro/WIN programming, HMI panels, S7-200-to-S7-200 peer 9.6 / 19.2 / 187.5 kbps Slave (CPU) / Master (HMI or CPU)
MPI (Multi-Point Interface) Read/write S7-300/400 data areas 19.2 / 187.5 kbps Slave only
Freeport (user-defined) Modbus RTU, USS drive protocol, ASCII barcode readers 1.2 to 115.2 kbps Either (program-controlled)

The S7-200 SMART adds PROFINET via the on-board Ethernet port for programming, HMI, and S7-protocol PUT/GET peer communication up to 16 active connections. Freeport on the S7-200 SMART is still RS-485 but supports Modbus RTU master without a separate library. Newer Siemens Industrial Edge devices extend the S7-200 SMART with cloud-ready MQTT and OPC UA Pub/Sub on top of the native PROFINET stack.

Pinout reminder (RS-485 Port 0/Port 1): Pin 3 = B (Data−), Pin 8 = A (Data+). On the 9-pin sub-D shell, the shield is bonded to the connector shell. Terminate with 120 Ω between A and B at each end of the trunk; never place termination at stubs. The legacy PC/PPI cable 6ES7 901-3CB30-0XA0 ships pre-terminated for one CPU end only.

Freeport receive programming template:


NETWORK 1
LD     SM0.1
MOVB   9, SMB30        // 9600 bps, no parity, 8 data, 1 stop
MOVB   200, SMB87      // RCV enable, idle detect, msg timeout
MOVB   50, SMB88       // Start char = any
MOVB   16#0A, SMB89    // End char = LF
MOVW   +1000, SMW92    // Inter-character timeout 1000 ms
ATCH   RCV_DONE, 23    // Event 23 = RCV complete
ENI

Wiring, Removable Connectors, and Field Installation

The legacy S7-200 ships with screw-type fixed terminal blocks on most CPU variants. Removable terminal blocks are available as separately ordered accessories because field retrofits (especially when replacing an Allen-Bradley PLC-5 with an S7-224) require that the field wiring be unplugged and reseated without disturbing stranded conductors. Fixed blocks force a re-strip of every wire during a junction-box swap-out.

CPU / EM Removable block description
CPU 222 / 224 / 224XP / 226 Set of four 8-pin removable blocks
CPU 221 / 222 (small frame) Set of two 10-pin removable blocks
EM 223 / EM 235 10-pin removable blocks per module

Wire gauge accepted by the removable blocks is 0.3 to 1.0 mm² (22 to 17 AWG). Torque to 0.4 N·m. The on-board 24 VDC sensor supply (marked "L+" / "M" on the lower terminal row) delivers up to 180 mA on the CPU 222/224 and 280 mA on the CPU 226 — sufficient for approximately 12 standard 24 VDC 3-wire sensors at 20 mA each. For additional sensors, add an external 24 VDC power supply that shares the same ground reference as the CPU chassis.

Application Case Studies

Case 1 — Pick-and-place retrofit (S7-224 in place of PLC-5): A packaging machine previously controlled by an Allen-Bradley PLC-5 was split into four zones (pick-and-place, resistance welder, conveyor, RF seal, operator interface). Each zone consumes 40 inputs and 36 outputs, total 76 I/O points. An S7-224 per zone (with one EM 223 + one EM 235) handles the full program in approximately 4 KB of code. Compared to an equivalent S5-95U implementation, the S7-224 program is roughly 40 percent smaller while delivering more diagnostic functionality.

Case 2 — Wastewater lift-station RTU (CPU 216 fleet): A municipal utility standardized on the CPU 216 because of its dual RS-485 ports: Port 0 in PPI for laptop programming, Port 1 in freeport Modbus RTU slave. The Siemens application subroutine 26719739 implements the Modbus slave in Subroutine 0, polled by a SCADA master at 9.6 kbps. CPU 216 RTU populations of 600+ units have demonstrated MTBF figures of 12+ years because the CPU has no moving parts and no fan.

Case 3 — Small servo axis (CPU 224XP + EM 253): The CPU 224XP delivers two 100 kHz pulse trains directly from its transistor outputs (Q0.0 and Q0.1), sufficient to command a stepper drive through an indexer. For a single servo axis with closed-loop feedback, an EM 253 positioning module accepts differential A/B/Z encoder inputs and provides one direction/step pulse output, configurable for S-curve or trapezoidal profiles up to 200 kHz with 1 ms acceleration ramp resolution.

Migration to S7-200 SMART and Beyond

New designs should not specify the legacy S7-200 CPU 21x/22x. Specify the S7-200 SMART line. For applications that outgrow the S7-200 SMART, the natural upgrade is the connected S7-1200 with PROFINET, or for data-heavy applications, an ET 200S distributed I/O node coordinated by an Industrial Edge gateway.

Legacy part Drop-in S7-200 SMART equivalent Modern S7-1200 equivalent
CPU 222 (8 DI / 6 DQ) SR20 (12 DI / 8 DQ) CPU 1211C (6 DI / 4 DQ)
CPU 224 (14 DI / 10 DQ) SR40 (24 DI / 16 DQ) CPU 1212C (8 DI / 6 DQ)
CPU 224XP (with on-board analog) SR40 + EM AE04 CPU 1214C (14 DI / 10 DQ + 2 AI)
CPU 226 (24 DI / 16 DQ) SR60 (36 DI / 24 DQ) CPU 1215C (14 DI / 10 DQ + 2 AI)
EM 277 PROFIBUS slave CM DP01 PROFIBUS slave CM 1243-5 PROFIBUS master
CP 243-1 Ethernet On-board Ethernet On-board PROFINET

Program conversion from Micro/WIN to TIA Portal is supported via the S7-200 SMART migration tool in TIA V17 and later. The tool maps the S7-200 symbol table to a TIA Portal DB, preserves LAD/FBD networks, and flags any STL instructions requiring manual review. SM (Special Memory) bits and V-memory addresses require explicit remapping because the TIA Portal address model differs from the legacy Micro/WIN flat memory model.

Troubleshooting Matrix

Symptom Likely cause Diagnostic step Corrective action
SF (System Fault) LED solid red Programming error, retentive memory lost, scan watchdog exceeded Connect Micro/WIN, read PLC → Information → Last Error Clear with menu PLC → Clear → Power Cycle; correct the program error before reuse
RUN LED off, STOP LED flashing Firmware update in progress or fatal hardware fault Cycle power and observe; if persistent, verify 24 VDC supply is within 20.4–28.8 V Replace CPU if 24 VDC is correct and fault repeats after firmware reload
Port 1 communication fails at 187.5 kbps but works at 19.2 kbps Cable capacitance exceeds spec, missing termination Measure trunk length; verify 120 Ω at each end Add termination, shorten stub to < 0.3 m, or drop to 19.2 kbps
EM 235 analog reads full scale (32767) on all channels DIP-switch range misconfigured for 0–20 mA signal but DIP set for ±10 V Read module DIP-switch setting against current-loop wiring Reconfigure DIP-switch and power cycle
CPU will not connect via PPI but Micro/WIN sees it Incorrect PPI address or baud mismatch with CPU Port 0 setting Use Micro/WIN → Communications → Set PG/PC Interface Match baud and address; restore default (address 2, 9.6 kbps) by holding reset 3 s
Real-time clock loses time on power cycle Battery cartridge dead (CPU 222/224) or coin cell exhausted Measure battery voltage under load Replace BC 293 cartridge; battery is rated 5 years
Freeport receive buffer overflows at high baud SMB87/88 receive message control not updated for new buffer Monitor SMB86 (RCV status) and SMB92 (msg length) Extend SMB92 length, add inter-character timeout, or lower baud
SF LED on after hot-plug of EM 222 EM module inserted while CPU under power (legacy S7-200 only) Cycle CPU power Insert EM modules with CPU power OFF; S7-200 SMART supports hot-plug

FAQ

What replaced the Siemens S7-200 for new designs?

The current Siemens replacement is the SIMATIC S7-200 SMART line (SR/ST 20–60) documented in the S7-200 SMART System Manual. For projects requiring PROFINET, structured programming in TIA Portal, or more than 256 I/O, migrate to the S7-1200 with the Siemens Industrial Edge ecosystem.

Can the S7-200 be programmed in TIA Portal?

No — STEP 7 Micro/WIN V4.0 SP9 is the only native programming tool for the S7-200 CPU 21x/22x. TIA Portal programs the S7-200 SMART natively and includes a migration utility that converts Micro/WIN projects (.mwp) into TIA V17+ projects with manual review of any STL instructions.

How many expansion modules does each S7-200 CPU support?

The CPU 221 supports none, the CPU 222 supports two, and the CPU 224 / 224XP / 226 support seven. Each EM module counts as one; an EM 223 four-in/four-out combo counts as one module even though it provides eight points.

Does the S7-200 support PROFIBUS DP master?

No — the EM 277 module is a PROFIBUS DP slave only. There is no master module for the legacy S7-200. For PROFIBUS master functionality, migrate to the S7-1200 with a CM 1243-5 communications module, or use the S7-200 SMART CM DP01 module for slave-side replacement of the EM 277.

What is the bit execution time of the S7-224 versus the S7-224XP?

Both CPUs execute a binary instruction in 0.22 µs per the S7-200 system manual. The CPU 224XP differs by adding two 100 kHz high-speed counters, two 100 kHz pulse-train outputs, and on-board analog (2 AI / 1 AQ). For purely digital applications, the CPU 224 and CPU 224XP execute identical boolean logic at the same speed.

Back to blog