Wiring Siemens 3TK2828-1BB40 Safety Relay to Sinumerik 802D via PP72/48
The Siemens 3TK2828-1BB40 safety relay integrates with the Sinumerik 802D CNC through the PP72/48 PROFIBUS I/O module using standard 24 V DC digital inputs. This guide covers the dual-channel wiring topology, terminal assignments, PROFIBUS address setup, and PLC logic required to monitor an E-stop or guard-door interlock and propagate the safe state to the CNC HMI, the NCK interface, and the axis-drive enable chain.
1. System Architecture
The Sinumerik 802D is an entry-level digital controller for standard turning and milling machines. Safety devices (E-stop pushbuttons, guard-door interlocks, light curtains, two-hand controls) are not wired directly to the 802D's fast safety bus because the platform does not expose one in its base configuration. Instead, each field safety device is wired to a certified safety relay whose output contacts are read by the 802D's standard PLC inputs on the PP72/48 I/O module. The PLC then enforces the safe state by clearing NCK interface signals (pulse enable, controller enable) and raising an alarm on the HMI.
The integration path is shown in the topology below.
2. Prerequisites
- Sinumerik 802D controller (article numbers 6FC5610-0BA10-0AA0 or 6FC5610-0BA11-0AA0 for turning; milling variants 6FC5610-0BB10-0AA0 / 6FC5610-0BB11-0AA0). Verify the exact article on the rating plate.
- PP72/48 I/O module (6FC5611-0BA01-0AA0). Two PP72/48 modules are supported maximum per 802D, addressed via PROFIBUS DIP switches 1-7.
- Siemens 3TK2828-1BB40 SIRIUS safety relay, screw-terminal variant, 24 V DC coil, four NO safety contacts + one NC signaling contact.
- 24 V DC PELV/SELV power supply sized for the relay coil plus the input current of the PP72/48 inputs (typically 6 mA per input at 24 V, source: Sinumerik 802D commissioning manual).
- PROFIBUS DP cable with D-sub 9-pin connector and PROFIBUS terminating resistor switched ON at the last node.
- Sinumerik 802D Toolbox commissioning DVD or current version of SinuTrain/828D commissioning tool for PLC project transfer.
3. Siemens 3TK2828-1BB40 Safety Relay Specifications
The 3TK2828-1BB40 belongs to the SIRIUS 3TK28 family of safety relays. It is designed for monitoring single- or dual-channel E-stop circuits and protective-door interlocks up to PL e / SIL 3 per ISO 13849-1 and IEC 62061. Always confirm the published rating against the latest Siemens Industry Online Support catalog page for the article number.
| Parameter | Value | Notes |
|---|---|---|
| Article number | 3TK2828-1BB40 | Verify on Siemens Industry Mall |
| Supply voltage (A1/A2) | 24 V DC | Observe polarity; PELV supply |
| Safety contacts | 4 NO (13-14, 23-24, 33-34, 43-44) | Force-guided per IEC 61810-3 |
| Signaling contact | 1 NC (51-52) | Used for diagnostics only |
| Contact rating (utilization cat. AC-15) | Up to 6 A at 230 V AC | Per Siemens datasheet; derate for DC inductive loads |
| Contact rating (DC-13) | Up to 4 A at 24 V DC | For contactor coils use flyback diode |
| Input channels | S11/S12 (ch1), S21/S22 (ch2) | Dual-channel with cross-fault monitoring |
| Response time tA | ≤ 30 ms (typical) | Add to risk-assessment safety distance |
| Release time tR | ≤ 30 ms | Check restart interlock logic |
| Wire cross-section | 0.5 to 2.5 mm² solid/stranded | Screw terminals, tightening torque ≈ 0.8 Nm |
| Operating temperature | -25 to +60 °C | DIN-rail mount in cabinet |
| Approvals | TÜV, UL, CSA | Per Siemens certificate |
Confirm the values above against the current Siemens datasheet on Industry Online Support because the catalog data sheet is the binding source.
4. Sinumerik 802D PP72/48 I/O Module
The PP72/48 is the standard distributed I/O for the 802D. It communicates with the 802D over PROFIBUS DP at up to 12 Mbit/s. The 802D's PLC processes the input image exactly like a local rack input.
| Parameter | Value |
|---|---|
| Article number | 6FC5611-0BA01-0AA0 |
| Digital inputs | 72 (24 V DC, sourcing, type 1 per IEC 61131-2) |
| Digital outputs | 48 (24 V DC, 0.5 A per output) |
| Input current per channel | ≈ 6 mA at 24 V |
| Input filter time | 0.5 / 3 / 10 / 20 ms configurable per group |
| PROFIBUS address | 1 to 7 via DIP switches (8 = reserved) |
| Max modules per 802D | 2 (slot mapping: I0..I71 / Q0..Q47, I72..I143 / Q48..Q95) |
| Power supply | 24 V DC, ≈ 1.5 A full load |
The PP72/48 input image is mapped by the 802D's PLC firmware. Default mapping places the first PP72/48 (PROFIBUS address 1) at I 0.0 .. I 8.7 and the second at I 9.0 .. I 17.7. The mapping shown here is the default; the actual offset is set in the 802D commissioning tool under "PLC I/O mapping" and must be verified against the project file.
5. Dual-Channel Wiring Topology
The 3TK2828-1BB40 is wired in dual-channel mode with cross-fault monitoring. The two channels are physically routed in separate cables or separated by an earthed barrier, which is required for the relay to detect a short between channels. The following diagram shows the field connections to the relay terminals.
6. Step-by-Step Wiring Procedure
- Isolate the cabinet. Open the main disconnect, lock-out, verify zero voltage on all power buses including the 24 V DC PELV rail and the PROFIBUS segment.
- Mount the 3TK2828-1BB40 on a 35 mm DIN rail inside the cabinet, near the E-stop pushbutton and within reach of the PP72/48 input terminals. Maintain ≥ 30 mm clearance above and below for cooling.
- Wire the supply. Connect +24 V DC PELV to terminal A1 and 0 V (functional earth reference) to terminal A2. Add a 1 A slow-blow fuse or PTC to protect the coil.
- Wire the input circuit. Run two separate cables from the E-stop block: channel 1 from S11 through the first NC contact to S12; channel 2 from S21 through the second NC contact to S22. Tie the second end of S12 and S22 to the same +24 V reference that feeds A1 only if the E-stop block uses a single supply; otherwise follow the device's wiring diagram.
-
Wire the output contacts.
- 13-14 to the line contactor K1 coil (drives the main spindle/axes power contactor).
- 23-24 to PP72/48 input
I0.0on the first module (PROFIBUS address 1), input group 1, terminal X111 pin 4. Use a 24 V jumper from terminal X111 pin 1 (+24 V supply) through the contact into pin 4 (input). - 33-34 to PP72/48 input
I0.1(X111 pin 5). - 51-52 (NC signaling) optionally to
I0.2for cross-fault diagnostics.
- Set the PROFIBUS address on the PP72/48 to a value not used by the 802D HMI panel or any other slave. Typical first PP72/48 is address 3, second is address 4. Power up and verify the PROFIBUS LED on the PP72/48 turns steady green.
-
Configure inputs in the 802D PLC project. Open the 802D Toolbox, edit the PLC program in the 802D's programming environment, and map
I0.0/I0.1to the safety-monitoring function block. Set the input filter to 3 ms to reject contact bounce while keeping the response time within the safety distance budget. -
Wire the drive enable chain. The 802D drives enable through the NCK interface signals
DB31..DB61, DBX8.0(pulse enable) andDBX8.1(controller enable). When the safety relay opens, the PLC must clear both signals within one PLC cycle (≤ 40 ms) so the drives remove torque. - Re-apply power in sequence: 24 V DC logic supply, then 400 V main contactor, then drive enable from the 802D.
7. PLC Logic and HMI Integration
Below is a compact representation of the safety-evaluation logic. The 3TK2828-1BB40 output contacts are read into the PP72/48 inputs; the PLC computes a "safe" bit and a "fault" bit, raises an HMI alarm, and clears the NCK enable signals.
// Sinumerik 802D PLC — STL excerpt
// Inputs: I0.0 = ch1 contact closed (E-stop OK)
// I0.1 = ch2 contact closed (E-stop OK)
// I0.2 = signaling contact 51-52 (relay healthy, NC closed)
// Output: Q0.0 = spindle/axis contactor K1 (must drop on E-stop)
// M100.0 = internal "safety OK" latch
// M100.1 = internal "cross-fault" flag
NETWORK 1 // Safety OK = ch1 AND ch2 AND signaling healthy
A I0.0
A I0.1
A I0.2
= M100.0 // safety OK
NETWORK 2 // Detect inconsistent channel states (cross-fault)
XN I0.0 // ch1 open
X I0.1 // ch2 closed (one closed, one open → fault)
O // symmetric:
X I0.0 // ch1 closed
XN I0.1 // ch2 open
S M100.1 // set cross-fault flag
NETWORK 3 // Hold-to-reset (manual restart interlock)
A M100.0
A I0.3 // reset pushbutton (NO, spring return)
A M100.2 // no cross-fault active
S M100.3 // safety latched
AN I0.0
O I0.1 // any channel open → release
R M100.3
NETWORK 4 // Drive enable / HMI alarm
A M100.3
AN M100.1 // suppress on cross-fault
= Q0.0 // contactor K1
= DB10.DBX56.1 // NCK: emergency stop active (low = OK)
NETWORK 5 // HMI alarm message (SinuTrain / HMI Advanced syntax)
A M100.1
= DB2.DBX180.0 // raise ALM 700001 "Safety cross-fault"
AN M100.0
= DB2.DBX180.1 // raise ALM 700002 "E-stop active"
8. Verification and Commissioning
After wiring and PLC download, perform the following functional tests. Record the results in the machine's acceptance protocol.
| Test | Action | Expected result | Acceptance |
|---|---|---|---|
| Channel 1 trip | Open E-stop channel 1 only with a jumper | Relay does not drop. Cross-fault flag should not raise. | OK / Fault |
| Channel 2 trip | Open E-stop channel 2 only with a jumper | Relay does not drop. Cross-fault flag should not raise. | OK / Fault |
| Dual-channel trip | Press E-stop | All 4 NO contacts open within ≤ 30 ms; K1 drops; HMI shows ALM 700002. | OK / Fault |
| Cross-fault simulation | Short S11 to S21 with a test lead | Relay must drop; PLC sets M100.1; HMI shows ALM 700001 and blocks restart. | OK / Fault |
| Response time | Measure from E-stop actuation to K1 dropout with an oscilloscope on 13-14 | tA ≤ 30 ms + PLC scan ≤ 40 ms = ≤ 70 ms total | OK / Fault |
| Restart interlock | Release E-stop, do not press reset | Machine must remain in safe state; K1 stays open. | OK / Fault |
| Reset function | Press reset pushbutton | K1 closes, NCK interface re-enables, ALM clears. | OK / Fault |
| PROFIBUS health | Disconnect PROFIBUS during operation | 802D enters follow-up mode; PP72/48 inputs freeze; HMI alarms. | OK / Fault |
The total stop time used in the safety-distance calculation is:
S = (tA + tPLC + tdrive) × vmax + dintrusion
where tA ≤ 30 ms (relay), tPLC ≤ 40 ms (one scan), tdrive is the drive's deceleration response (read from the Sinamics/Simodrive parameter list, typically 50-150 ms), vmax is the maximum hazardous speed, and dintrusion is the reach distance into the hazard zone per ISO 13855.
9. Troubleshooting Matrix
| Symptom | Likely cause | Diagnostic | Remedy |
|---|---|---|---|
| E-stop pressed, relay does not drop | Coil not energised; A1/A2 polarity reversed; 24 V missing | Measure A1-A2; check LED on relay | Correct supply; replace fuse |
| Relay drops immediately on power-up, will not reset | One channel stuck open; signaling contact 51-52 open | Read I0.0/I0.1/I0.2; measure at S11/S12, S21/S22 | Repair E-stop contact; check wiring |
| Relay chatters during operation | Cross-fault detected; short between channels; bounce from inductive source | Inspect cables; check filter time | Separate channels; increase filter to 10 ms (verify against safety distance) |
| Drives do not drop on E-stop | PLC logic fault; NCK enable not cleared; wrong address mapped | Watch Q0.0 and DB31..DB61, DBX8.0 in online mode | Correct ladder; remap inputs in PLC I/O configuration |
| PP72/48 not seen on PROFIBUS | Address conflict; cable polarity; termination missing | Check address DIP; bus termination resistor | Set unique address; enable terminator at last node |
| Spurious ALM 700001 with no fault | Asymmetric filter on two channels | Check filter time of I0.0 vs I0.1 | Set both inputs to the same filter |
| Reset pushbutton does nothing | NCK not ready; reset wired to wrong input; PLC scan issue | Monitor I0.3 and M100.3 online | Re-wire; ensure PLC is in run |
| Response time exceeds budget | PLC cycle time too long; filter time too high | Measure with oscilloscope | Reduce filter; optimize OB1 cycle; consider fast PLC inputs on PP72/48 |
10. Field-Proven Caveats
- The 3TK2828-1BB40 has no automatic reset by default. If your machine uses a "controlled stop / automatic restart" category per IEC 60204-1 §9.2.5.8, you must implement the start/restart interlock in the PLC and the operator panel, not by re-energising the relay coil.
- Never wire the 3TK2828 coil to a switched power source. The relay must remain energised for the full run-time of the machine; only the field input circuit (S11/S12, S21/S22) opens to drop the contacts.
- The PP72/48 input filter setting is global per group of 8 inputs. Choose a filter that meets the safety-distance budget but is robust against EMI from VFD cables routed in the same tray.
- When retrofitting an older 802D to a new safety relay, the 802D's PLC scan time on a heavily loaded project can exceed 40 ms. Profile it with the PLC cycle-time statistic before declaring the response-time budget.
- Always provide a separate ground reference for the 3TK2828 coil (terminal A2) and the PP72/48 24 V common. Sharing a high-impedance return path can cause nuisance tripping on relay dropout.
11. Standards Reference
Validate the design against the current revisions of these standards. They are cited as reference documents, not as confirmation that the wiring above meets any specific PL/SIL — the integrator must do that calculation.
- ISO 13849-1:2023 — Safety of machinery: Safety-related parts of control systems
- IEC 62061:2021 — Functional safety of safety-related control systems
- IEC 60204-1:2016 — Safety of machinery: Electrical equipment of machines
- ISO 12100:2010 — General principles for design — Risk assessment and risk reduction
- ISO 13855:2024 — Positioning of safeguards with respect to the approach speeds of parts of the human body
For background on how a safety relay monitors actuators and the safety contacts, see the Pilz safety-relay lexicon entry for a generic description of monitoring function. Always cross-check with the Siemens device manual, which is the binding source for the 3TK2828-1BB40.
Which PP72/48 inputs should I use for the 3TK2828 safety relay?
Use two adjacent inputs of the same group, e.g., I0.0 and I0.1 on the first PP72/48 (PROFIBUS address 1), to keep the filter time identical and to make the wiring symmetric. Wire the optional 51-52 signaling contact to a third input, e.g., I0.2, for diagnostics.
Do I need a separate reset pushbutton for the 3TK2828-1BB40?
Yes. The relay has no integrated reset. Implement a manual reset by wiring a separate NO pushbutton to another PP72/48 input and gating the restart in the PLC on that input plus a healthy safety state. This satisfies ISO 13849-1 and the restart interlock requirements of IEC 60204-1.
What PROFIBUS address should I set on the PP72/48?
Any address not used by the 802D HMI (usually 6) or by drives on the same segment. Typical first PP72/48 is address 3, second is address 4. Set the address with the on-board DIP switches before applying power.
Can I use only one channel of the 3TK2828-1BB40 with the 802D?
You can, but you lose cross-fault monitoring and typically cap the achievable performance level at PL c / SIL 1. For most machine-tool risk assessments, dual-channel is required. If you must use a single channel, document the rationale in the risk assessment and verify that the achieved PL/SIL is acceptable.
How do I stop the drives immediately when the safety relay drops?
Have the PLC clear the NCK interface signals DB31..DB61, DBX8.0 (pulse enable) and DBX8.1 (controller enable) within one PLC scan after detecting the safety drop. The drives will then execute their configured stop (OFF1/OFF2/OFF3) and remove torque within the drive's deceleration time, which must be added to the safety-distance calculation.