SINAMICS S120 SIL3 Limits: S120 Safety Integrated Workarounds
Overview of Safety Integrated in SINAMICS S120
The SINAMICS S120 drive family implements Siemens' Safety Integrated (SI) functions, providing integrated safety features like STO (Safe Torque Off), SS1 (Safe Stop 1), SS2 (Safe Stop 2), SOS (Safe Operating Stop), SLS (Safely-Limited Speed), SDI (Safe Direction), and SLP (Safely-Limited Position). These functions are realized inside the drive firmware, eliminating external safety relays in most applications.
The S120 supports Safety Integrated on multiple control unit platforms:
- CU320-2 (Control Unit 320-2 DP / PN) — used in multi-axis configurations with separate Motor Modules.
- CU310-2 (Control Unit 310-2 DP / PN) — used in single-axis Blocksize configurations.
- SINAMICS S120 Combi — integrated power and control in one unit.
- SINAMICS HLA — hydraulic drive variant (with encoder restrictions).
A frequent question from system integrators is whether the SINAMICS S120 — particularly configurations built on the CU320-2 — can achieve SIL 3 (Safety Integrity Level 3) per IEC 62061, or PLe (Performance Level e) per ISO 13849-1. The answer requires understanding the difference between SIL and SIL CL, and the design constraints imposed by the S120 hardware architecture.
SIL, SIL CL, PL, and Category: Clearing the Confusion
Before discussing the S120 limits, clarify the standards landscape and the PFHd-to-SIL/PL mapping:
| Standard | Title | Scope |
|---|---|---|
| IEC 61508 | Functional safety of E/E/PE systems | Generic standard for safety instrumented systems |
| IEC 62061 | Functional safety of safety-related control systems (machinery) | Machinery-specific, derived from IEC 61508 |
| EN ISO 13849-1 | Safety-related parts of control systems | Performance Level (PL a–e) and Category (B, 1, 2, 3, 4) |
| EN 954-1 | (Superseded by ISO 13849-1) | Cat 1–4 legacy reference |
Key relationships:
- SIL (Safety Integrity Level) applies to the complete safety function: sensor, logic, and actuator.
- SIL CL (SIL Claim Limit) is the maximum SIL a subsystem can claim. Per IEC 62061, the achieved SIL of a safety function is the minimum of the SIL CLs of all subsystems.
- PFHd (Probability of dangerous Failure per Hour) maps directly from PL to SIL:
| PFHd (1/h) | PL | SIL |
|---|---|---|
| ≥ 10⁻⁵ to < 10⁻⁴ | a | 1 |
| ≥ 10⁻⁶ to < 10⁻⁵ | b | 2 |
| ≥ 10⁻⁷ to < 10⁻⁶ | c / d | 2 |
| ≥ 10⁻⁸ to < 10⁻⁷ | e | 3 |
| < 10⁻⁸ | — | Not defined by IEC 62061 |
The S120 Safety Integrated subsystem has a SIL CL of 2, which mathematically caps any safety function that uses only S120 drive-internal safety at SIL 2, regardless of the F-CPU connected upstream.
Why SINAMICS S120 is Limited to SIL CL 2
The S120 architecture implements safety functions through two independent channels:
- Channel 1: The CU320-2 or CU310-2 processor monitors safe inputs (F-DI, PROFIsafe, terminals) and triggers the stop functions.
- Channel 2: The Motor Module (or Power Module Blocksize) provides a hardware-based shutdown path via the EP terminal (Enable Pulses) and the safe pulse suppression circuitry.
The system monitors both 24 V+ and M of the safe input wiring for cross-faults and wire-breakage, and includes cross-checking between the two channels. The S120 detects short-circuits between channels, broken wires, and stuck-at faults on the EP terminal.
Despite the two-channel design, the certification carried by Siemens for the S120 — as documented in the SINAMICS S120 Function Manual Safety Integrated (F manual, edition 12/2018) — lists the S120 subsystem at SIL CL 2, PL d, Category 3. The subsystem PFHd figure falls in the 10⁻⁷ to < 10⁻⁶ /h range, which corresponds to PL d / SIL 2.
To reach SIL 3, the system integrator must either:
- Add an external safety device (contactor, brake, or second drive path) to compensate for the S120's SIL CL 2 cap, or
- Use a control system that distributes the safety function across multiple SIL CL 2 subsystems in a redundant architecture.
Achievable Safety Levels with the S120
Standalone S120: SIL 2, PL d, Cat 3
A single S120 axis, with Safety Integrated enabled (STO, SS1, etc.) and an F-CPU communicating via PROFIsafe, achieves:
- SIL 2 per IEC 62061 (limited by S120 SIL CL 2)
- PL d per ISO 13849-1
- Category 3 (dual-channel with monitoring)
S120 + External Contactor: PLe / Cat 4 per ISO 13849-1
By adding an external contactor in the motor feeder (line or delta contactor), the safety function structure becomes redundant. The combined S120 + contactor subsystem can claim:
- PLe per ISO 13849-1
- Category 4 per ISO 13849-1 (the EN 954-1 Cat 4 reference in older Siemens documentation maps to ISO 13849-1 Cat 4)
This is the architecture documented in the TÜV-certified report referenced in Siemens application support (entry 39700245), and is the conventional path to PLe in S120 installations.
S120 + SINUMERIK or F-CPU with Redundant Architecture: SIL 3
Higher-level safety functions can reach SIL 3 if the overall system architecture distributes the safety function across multiple SIL CL 2 subsystems, each performing a portion of the safety function, with the combined PFHd meeting the SIL 3 threshold. This approach is used in:
- SIMATIC S7-1500F with F-DI 16×24VDC (6ES7526-1BH00-0AB0) and SINAMICS S120 — see TIA Portal documentation "Application 3: Safety mode SIL3 / Cat.4 / PLe"
- SINUMERIK ONE / 840D sl with SINAMICS S120 in redundant configurations
STO via Terminals on Power Modules Blocksize (CU310-2)
The CU310-2 + Power Module Blocksize configuration supports STO via terminal wiring directly on the power module, without requiring the F-CPU PROFIsafe path. This is documented in section 5.2.3 of the SINAMICS S120 Safety Integrated Function Manual (11/2017 edition, entry 109754301).
Wiring (Power Module Blocksize Terminal X200)
| Terminal | Signal | Function |
|---|---|---|
| X200.1 (24 V) | STO+ channel 1 | +24 V enable, channel 1 |
| X200.2 (M) | STO− channel 1 | Ground reference, channel 1 |
| X200.3 (24 V) | STO+ channel 2 | +24 V enable, channel 2 |
| X200.4 (M) | STO− channel 2 | Ground reference, channel 2 |
When both channels are energized, the power module enables gate firing (STO inactive). De-energizing either channel — or both — triggers STO.
Commissioning Steps
- In STARTER or Startdrive (TIA Portal), navigate to the drive's Safety Integrated configuration.
- Select the safety function set (e.g., STO via terminals, SS1, etc.).
- For STO via terminals, set
p9601.0 = 1(enable Safety Integrated functions, terminal-based) andp9650 = 0(STO debounce time, default 0 ms; raise to 5–10 ms for noisy environments). - Configure the F-CPU connection (if PROFIsafe is used) or wire the terminals directly (terminal-based STO).
- Set the SBT (Safe Brake Test) parameters if a brake is present.
- Run a test stop with the safety validator tool and document the acceptance test per the S120 Safety Acceptance Test checklist.
Encoder Restrictions for Safety Functions
When using the S120 with safety functions that require an encoder (SS2, SLS, SDI, SLP), the first encoder in the topology must be on the SINAMICS S120, not on a SINAMICS HLA or SINAMICS S120 Combi drive. The S120 Combi and HLA do not carry the same encoder safety certification and cannot act as the master encoder for the S120's safety functions.
SIL 3 Application Example: F-DI Module + SINAMICS S120
A documented SIL 3 / Cat 4 / PLe configuration uses the SIMATIC S7-1500F CPU with the digital input module 6ES7526-1BH00-0AB0 (F-DI 16×24VDC) and the SINAMICS S120.
Architecture (ASCII Flow)
[F-DI 6ES7526-1BH00-0AB0] (E-stop, light curtain, guard door)
|
v
[SIMATIC S7-1500F CPU] ---PROFIsafe---> [SINAMICS S120 STO/SS1]
|
+--- DO (standard) ---> [Safety Contactor K1]
Configuration Path in TIA Portal
- Add the F-CPU and F-DI module to the device configuration.
- Configure the F-DI module's PROFIsafe destination address (must match the drive's
p9610/p9810). - In the SINAMICS S120 device configuration, enable Safety Integrated and select the PROFIsafe telegram (typically telegram 30 or 901).
- Map the safety stop function in the F-CPU safety program: sensor input → F-DI → F-CPU logic → PROFIsafe telegram → drive STO/SS1.
- Compile the safety program and download to the F-CPU.
- Run the safety acceptance test in TIA Portal's Safety Administration Editor.
The "Application 3: Safety mode SIL3 / Cat.4 / PLe" reference in the TIA Portal manual collection documents the precise parameter set required for this configuration.
Regular STO Test Requirement for SIL 3
When the S120 is used in a SIL 3 application, the S120 Function Manual Safety Integrated states:
To satisfy the requirements of SIL 3, you must regularly check the STO functionality.
This means the STO function cannot be treated as "fit and forget." The system integrator must implement:
-
Automatic test cycle: A scheduled test pulse that triggers STO and verifies both channels shut down the drive within the time specified in
p9651(STO safe delay time) and that no fault prevents restart. - Diagnostic coverage: The test must detect dangerous faults, including cross-channel faults and stuck-at faults on the EP terminals.
- Proof test interval: Siemens specifies a maximum interval for the STO test in the F manual. The system must track test execution and raise an alarm if the interval is exceeded.
For S120, the typical STO proof test interval is 1 year, though the exact value must be taken from the project's safety validation report.
Verification and Commissioning Checks
| Step | Verification | Pass Criterion |
|---|---|---|
| 1 | Drive accepts Safety Integrated configuration |
p9601/p9801 indicates SI enabled, no F-FFFF F-code faults |
| 2 | STO test pulse (off / on within p9650 ms) |
Drive disables pulses, restart requires de-energize-then-energize of both STO channels |
| 3 | Cross-fault test (short between channels) | F01611 or F30611 fault is raised, drive latches into safe state |
| 4 | Wire-break detection (open one channel wire) | F01611 fault after p9650 debounce time |
| 5 | PROFIsafe communication test (if used) | PROFIsafe watchdog expires and STO is triggered within the configured F_WD_Time |
| 6 | Safety acceptance test report | All test cases from the S120 safety acceptance test list passed and signed |
| 7 | Encoder consistency (if SLS/SDI used) | Both encoders agree within the configured tolerance (p9322/p9321) |
| 8 | Brake test (if SBT enabled) | Brake holds the load for the test duration, no slip detected |
Troubleshooting Matrix
| Fault Code | Description | Likely Cause | Action |
|---|---|---|---|
| F01610 | SI P1 (CU): Defective | CU320-2 / CU310-2 internal safety channel 1 fault | Replace CU, or update firmware; verify with S7-1500F safety program version |
| F01611 | SI P1 (CU): Defective, F-DI discrepancy | F-DI input states disagree across channels | Check wiring, verify p9650 debounce time matches application |
| F30610 | SI P2 (Motor Module / Power Module): Defective | Motor Module channel 2 fault | Replace Motor Module / Power Module; check for ground faults |
| F30611 | SI P2 (MM/PM): Defective, EP terminal | EP terminal fault, stuck-at or open circuit | Inspect EP wiring, replace module if persistent |
| F01680 | SI P1 (CU): Checksum error in safety parameters | Safety parameter set (p96xx/p98xx) corrupted |
Re-load safety parameters from project, perform acceptance test |
| F01681 | SI P1 (CU): Incorrect parameterization | Safety parameter conflict (e.g., SLS limit inconsistent) | Review S120 Safety Integrated parameter list, refer to F manual |
| F08501 | PROFIsafe communication failure | F-Host F_WD_Time expired, telegram timeout | Check PROFINET cable, verify F-CPU is in RUN, check p9610/p9810
|
| F30600 | SI P2: STO active but channel 1 not active | Asymmetric shutdown, cross-fault | Inspect wiring, perform cross-fault test |
| C30711 | SI P2: EP terminal diagnostic warning | EP wiring marginal (intermittent contact) | Check terminal torque, inspect connector |
Achieving SIL 3 in Practice: Design Patterns
Pattern A: F-CPU + S120 + External Contactor
The most common path. The S120 handles STO/SS1, and a safety contactor on the motor side provides the second physical shutdown path. The F-CPU coordinates both via PROFIsafe to the drive and a standard output to the contactor. The combined system can claim PLe / Cat 4 / SIL 3 depending on the contactor's certification and the proof test interval enforced on the S120.
Pattern B: Dual-Drive Redundancy
In applications where the contactor is not acceptable (e.g., where a coast-down is dangerous), two S120 axes can be configured in a redundant safety architecture, each acting as a SIL CL 2 subsystem, with the combined system meeting SIL 3 PFHd. Both drives must receive the same stop command, and the F-CPU must verify that both shut down within the safe delay time.
Pattern C: S120 + SINUMERIK Safety Integrated
In CNC applications, the SINUMERIK 840D sl / ONE safety logic combined with SINAMICS S120 achieves the higher safety levels required for machining safety (safe reduced speed, safe limited position for the tool). SINUMERIK's safety kernel is certified for SIL 3 and the S120 is the certified drive subsystem within that envelope.
Key Parameter Set
| Parameter | Description | Typical Value / Range |
|---|---|---|
| p9601 | SI enable, CU (drive-side) | 1 (enable integrated SI) |
| p9650 | SI STO debounce time | 0–1000 ms (typical 0–10 ms) |
| p9651 | SI STO safe delay time | Per application (e.g., 50 ms) |
| p9660 | SI SS1 delay time | 0–30000 ms |
| p9610 / p9810 | PROFIsafe address (channel 1 / 2) | 1–65534, must match F-CPU telegram |
| p9620 | SI signal source for STO | 0 (terminal), 1 (PROFIsafe), 2 (both) |
| p9321 / p9322 | SLS / SDI encoder tolerance | Per mechanical design |
| p9700 / p9701 | SI copy / compare function | Used during commissioning |
| r9771 | SI diagnostics: status word | Read-only, indicates active safety state |
| r9780 / r9781 | SI checksum expected / actual | Used to verify parameter integrity |
Safety Acceptance Test Procedure
- Verify the S120 firmware version matches the F manual revision used for the safety design (e.g., V5.2 SP3 or later for the 12/2018 F manual).
- Verify the safety parameters (
p96xx,p98xx) have been loaded from the offline project and the checksum (r9781) matches the offline checksum (r9780). - Test each safety function in turn: STO, SS1, SS2, SLS, SDI, SLP, SBT (whichever are enabled in the project).
- For each function, record the response time, the stop category, and the fault message (if any) on the acceptance test sheet.
- Test the fault path: simulate wire break on each STO channel, verify F01611 / F30611 is raised and the drive latches.
- Test the PROFIsafe path: disconnect the PROFINET cable, verify F08501 is raised within the configured F_WD_Time.
- Sign and archive the acceptance test report per ISO 13849-1 / IEC 62061 requirements.
Cross-Platform Notes
| Drive Family | Max Safety Level (Standalone) | Reaching SIL 3 Path |
|---|---|---|
| SINAMICS S120 | SIL 2 / PL d / Cat 3 | Add contactor, dual-drive, or pair with SINUMERIK |
| SINAMICS G120 / G120C / G120D | SIL 2 / PL d / Cat 3 | Same as S120 |
| SINAMICS V90 | No integrated SI | External safety via F-CPU + contactor only |
| Allen-Bradley PowerFlex 755 | SIL CL 3 (with 20-750-S card) | Standalone SIL 3 / PLe with safety option module |
| ABB ACS880 + FSO-12/-21 | SIL 3 / PLe | Standalone SIL 3 / PLe with FSO module |
Notes on Design Trade-offs
- The two-channel design of the S120 (CU + Motor Module) provides diagnostic coverage that meets Category 3, but the residual failure probability is bounded by the S120's published PFHd figure.
- For SIL 3 in PFHd terms (PFHd < 10⁻⁷ /h), a single S120 subsystem does not meet the requirement. Two redundant SIL 2 subsystems (each with PFHd ≈ 5×10⁻⁷) combined in parallel meet SIL 3 only if the architecture is proven to handle common-cause failures — this requires the TÜV-certified report referenced in the F manual.
- The proof test interval for SIL 3 applications must be set shorter than the worst-case dangerous failure interval, and the system must enforce the test automatically (typically via the F-CPU safety program calling the STO test routine at every machine start-up or once per shift).
- Where the S120 is paired with an external contactor, the contactor's PFHd contribution must be added to the overall safety function PFHd, and the worst-case stop time (contactor dropout + S120 STO time) must be within the safety function's response time budget.
Official Documentation References
- SINAMICS S120 Function Manual Safety Integrated (F manual, 12/2018 edition) — the primary parameter and certification reference.
- SINAMICS S120 Safety Integrated Function Manual (11/2017 edition, entry 109754301) — section 5.2.3 documents STO via terminals on Power Modules Blocksize.
- TIA Portal Manual Collection — F-DI 16×24VDC (6ES7526-1BH00-0AB0): Application 3: Safety mode SIL3 / Cat.4 / PLe — SIL 3 architecture with F-CPU and S120.
- Siemens application support entry 39700245 — TÜV-certified report for S120 + external contactor achieving PLe / Cat 4.
Conclusion
The SINAMICS S120 Safety Integrated subsystem is certified to SIL CL 2, PL d, Category 3 as a standalone drive. Reaching SIL 3 / PLe is possible through one of three documented paths: adding an external contactor, using a redundant dual-drive architecture, or pairing the S120 with an F-CPU and higher-level safety logic that distributes the SIL 3 requirement across multiple SIL CL 2 subsystems. The S120's two-channel monitoring (CU + Motor Module EP terminal) provides the diagnostic coverage needed for Category 3, but the SIL cap remains a hard limit of the subsystem.
When designing a SINAMICS S120 system to SIL 3, verify the safety function structure, the proof test interval for STO, the encoder topology (S120 Combi / HLA restrictions), and the F-CPU configuration against the SINAMICS S120 Safety Integrated Function Manual and the TIA Portal safety configuration guidance.
FAQ
Can a single SINAMICS S120 with CU320-2 achieve SIL 3?
No. The S120 subsystem is certified to SIL CL 2 per IEC 62061, which caps any safety function using only the drive at SIL 2. To reach SIL 3, add an external contactor, use a redundant dual-drive architecture, or combine the S120 with an F-CPU that distributes the SIL 3 requirement across multiple SIL CL 2 subsystems.
What safety functions are supported on the SINAMICS S120?
The S120 Safety Integrated function set includes STO (Safe Torque Off), SS1 (Safe Stop 1), SS2 (Safe Stop 2), SOS (Safe Operating Stop), SLS (Safely-Limited Speed), SSM (Safe Speed Monitor), SDI (Safe Direction), SLP (Safely-Limited Position), and SBT (Safe Brake Test). Each has its own parameter set and PFHd figure.
How do I configure STO via terminals on a Power Module Blocksize?
Wire the four STO terminals (X200.1–X200.4) on the Power Module Blocksize, set p9601.0 = 1 to enable Safety Integrated, p9650 for the debounce time, and p9620 = 0 to select terminal-based STO. Then perform the safety acceptance test per the S120 Function Manual section 5.2.3.
What proof test interval is required for SIL 3 with the S120?
The SINAMICS S120 Safety Integrated Function Manual requires regular STO functionality testing to satisfy SIL 3. The maximum interval is documented in the project's safety validation report and is typically 1 year for S120 applications, but it depends on the safety function's PFHd budget and the SIL 3 demand mode.
Can I use a SINAMICS S120 Combi or HLA as the first encoder for safety functions?
No. The SINAMICS S120 Safety Integrated Function Manual explicitly states that SINAMICS HLA or SINAMICS S120 Combi must not be operated as the first encoder. Only the SINAMICS S120 (Blocksize or chassis) can be the first encoder in safety functions that require an encoder (SLS, SDI, SLP).