Wiring Siemens 3TK2828 Safety Relay to Sinumerik 802D PP72/48

David Krause13 min read
Safety SystemsSiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Wiring Siemens 3TK2828-1BB40 Safety Relay to Sinumerik 802D via PP72/48

The Siemens 3TK2828-1BB40 safety relay integrates with the Sinumerik 802D CNC through the PP72/48 PROFIBUS I/O module using standard 24 V DC digital inputs. This guide covers the dual-channel wiring topology, terminal assignments, PROFIBUS address setup, and PLC logic required to monitor an E-stop or guard-door interlock and propagate the safe state to the CNC HMI, the NCK interface, and the axis-drive enable chain.

Functional safety note: The 802D is not a safety-rated controller. The safety function is performed by a certified safety relay (e.g., 3TK2828-1BB40) and the dual-channel wiring that satisfies ISO 13849-1 Performance Level and IEC 62061 SIL targets. The PP72/48 is used only as a status-repeater, not as a safety device. Always validate the design against the machine's risk assessment and applicable C-type standards.

1. System Architecture

The Sinumerik 802D is an entry-level digital controller for standard turning and milling machines. Safety devices (E-stop pushbuttons, guard-door interlocks, light curtains, two-hand controls) are not wired directly to the 802D's fast safety bus because the platform does not expose one in its base configuration. Instead, each field safety device is wired to a certified safety relay whose output contacts are read by the 802D's standard PLC inputs on the PP72/48 I/O module. The PLC then enforces the safe state by clearing NCK interface signals (pulse enable, controller enable) and raising an alarm on the HMI.

The integration path is shown in the topology below.

Field safety device E-stop / guard interlock 3TK2828-1BB40 safety relay (PL e / SIL 3) 13-14, 23-24, 33-34 PP72/48 digital inputs X111-X222 PROFIBUS DP Sinumerik 802D PLC I/Q area + NCK interface HMI alarm + drive enable chain Two-channel wiring, cross-fault monitored

2. Prerequisites

  • Sinumerik 802D controller (article numbers 6FC5610-0BA10-0AA0 or 6FC5610-0BA11-0AA0 for turning; milling variants 6FC5610-0BB10-0AA0 / 6FC5610-0BB11-0AA0). Verify the exact article on the rating plate.
  • PP72/48 I/O module (6FC5611-0BA01-0AA0). Two PP72/48 modules are supported maximum per 802D, addressed via PROFIBUS DIP switches 1-7.
  • Siemens 3TK2828-1BB40 SIRIUS safety relay, screw-terminal variant, 24 V DC coil, four NO safety contacts + one NC signaling contact.
  • 24 V DC PELV/SELV power supply sized for the relay coil plus the input current of the PP72/48 inputs (typically 6 mA per input at 24 V, source: Sinumerik 802D commissioning manual).
  • PROFIBUS DP cable with D-sub 9-pin connector and PROFIBUS terminating resistor switched ON at the last node.
  • Sinumerik 802D Toolbox commissioning DVD or current version of SinuTrain/828D commissioning tool for PLC project transfer.

3. Siemens 3TK2828-1BB40 Safety Relay Specifications

The 3TK2828-1BB40 belongs to the SIRIUS 3TK28 family of safety relays. It is designed for monitoring single- or dual-channel E-stop circuits and protective-door interlocks up to PL e / SIL 3 per ISO 13849-1 and IEC 62061. Always confirm the published rating against the latest Siemens Industry Online Support catalog page for the article number.

Parameter Value Notes
Article number 3TK2828-1BB40 Verify on Siemens Industry Mall
Supply voltage (A1/A2) 24 V DC Observe polarity; PELV supply
Safety contacts 4 NO (13-14, 23-24, 33-34, 43-44) Force-guided per IEC 61810-3
Signaling contact 1 NC (51-52) Used for diagnostics only
Contact rating (utilization cat. AC-15) Up to 6 A at 230 V AC Per Siemens datasheet; derate for DC inductive loads
Contact rating (DC-13) Up to 4 A at 24 V DC For contactor coils use flyback diode
Input channels S11/S12 (ch1), S21/S22 (ch2) Dual-channel with cross-fault monitoring
Response time tA ≤ 30 ms (typical) Add to risk-assessment safety distance
Release time tR ≤ 30 ms Check restart interlock logic
Wire cross-section 0.5 to 2.5 mm² solid/stranded Screw terminals, tightening torque ≈ 0.8 Nm
Operating temperature -25 to +60 °C DIN-rail mount in cabinet
Approvals TÜV, UL, CSA Per Siemens certificate

Confirm the values above against the current Siemens datasheet on Industry Online Support because the catalog data sheet is the binding source.

4. Sinumerik 802D PP72/48 I/O Module

The PP72/48 is the standard distributed I/O for the 802D. It communicates with the 802D over PROFIBUS DP at up to 12 Mbit/s. The 802D's PLC processes the input image exactly like a local rack input.

Parameter Value
Article number 6FC5611-0BA01-0AA0
Digital inputs 72 (24 V DC, sourcing, type 1 per IEC 61131-2)
Digital outputs 48 (24 V DC, 0.5 A per output)
Input current per channel ≈ 6 mA at 24 V
Input filter time 0.5 / 3 / 10 / 20 ms configurable per group
PROFIBUS address 1 to 7 via DIP switches (8 = reserved)
Max modules per 802D 2 (slot mapping: I0..I71 / Q0..Q47, I72..I143 / Q48..Q95)
Power supply 24 V DC, ≈ 1.5 A full load

The PP72/48 input image is mapped by the 802D's PLC firmware. Default mapping places the first PP72/48 (PROFIBUS address 1) at I 0.0 .. I 8.7 and the second at I 9.0 .. I 17.7. The mapping shown here is the default; the actual offset is set in the 802D commissioning tool under "PLC I/O mapping" and must be verified against the project file.

5. Dual-Channel Wiring Topology

The 3TK2828-1BB40 is wired in dual-channel mode with cross-fault monitoring. The two channels are physically routed in separate cables or separated by an earthed barrier, which is required for the relay to detect a short between channels. The following diagram shows the field connections to the relay terminals.

3TK2828-1BB40 24V DC / dual-channel S11S12 ← ch1 contact: E-stop NC1 S21S22 ← ch2 contact: E-stop NC2 (separate cable) A1A2 ← 24 V DC PELV (coil) 1314 → contactor K1 coil A1 2324 → PP72/48 input I0.0 (E-stop ch1) 3334 → PP72/48 input I0.1 (E-stop ch2) 5152 → optional fault feedback to PP72/48 I0.2
Cable routing: Route the two E-stop channels in separate cables or with an earthed divider between them. If both conductors share a multi-core cable, the relay cannot detect a channel-to-channel short and the cross-fault monitoring function is defeated. This is a common cause of certification failures in retrofits.

6. Step-by-Step Wiring Procedure

  1. Isolate the cabinet. Open the main disconnect, lock-out, verify zero voltage on all power buses including the 24 V DC PELV rail and the PROFIBUS segment.
  2. Mount the 3TK2828-1BB40 on a 35 mm DIN rail inside the cabinet, near the E-stop pushbutton and within reach of the PP72/48 input terminals. Maintain ≥ 30 mm clearance above and below for cooling.
  3. Wire the supply. Connect +24 V DC PELV to terminal A1 and 0 V (functional earth reference) to terminal A2. Add a 1 A slow-blow fuse or PTC to protect the coil.
  4. Wire the input circuit. Run two separate cables from the E-stop block: channel 1 from S11 through the first NC contact to S12; channel 2 from S21 through the second NC contact to S22. Tie the second end of S12 and S22 to the same +24 V reference that feeds A1 only if the E-stop block uses a single supply; otherwise follow the device's wiring diagram.
  5. Wire the output contacts.
    • 13-14 to the line contactor K1 coil (drives the main spindle/axes power contactor).
    • 23-24 to PP72/48 input I0.0 on the first module (PROFIBUS address 1), input group 1, terminal X111 pin 4. Use a 24 V jumper from terminal X111 pin 1 (+24 V supply) through the contact into pin 4 (input).
    • 33-34 to PP72/48 input I0.1 (X111 pin 5).
    • 51-52 (NC signaling) optionally to I0.2 for cross-fault diagnostics.
  6. Set the PROFIBUS address on the PP72/48 to a value not used by the 802D HMI panel or any other slave. Typical first PP72/48 is address 3, second is address 4. Power up and verify the PROFIBUS LED on the PP72/48 turns steady green.
  7. Configure inputs in the 802D PLC project. Open the 802D Toolbox, edit the PLC program in the 802D's programming environment, and map I0.0 / I0.1 to the safety-monitoring function block. Set the input filter to 3 ms to reject contact bounce while keeping the response time within the safety distance budget.
  8. Wire the drive enable chain. The 802D drives enable through the NCK interface signals DB31..DB61, DBX8.0 (pulse enable) and DBX8.1 (controller enable). When the safety relay opens, the PLC must clear both signals within one PLC cycle (≤ 40 ms) so the drives remove torque.
  9. Re-apply power in sequence: 24 V DC logic supply, then 400 V main contactor, then drive enable from the 802D.

7. PLC Logic and HMI Integration

Below is a compact representation of the safety-evaluation logic. The 3TK2828-1BB40 output contacts are read into the PP72/48 inputs; the PLC computes a "safe" bit and a "fault" bit, raises an HMI alarm, and clears the NCK enable signals.

// Sinumerik 802D PLC — STL excerpt
// Inputs: I0.0 = ch1 contact closed (E-stop OK)
//         I0.1 = ch2 contact closed (E-stop OK)
//         I0.2 = signaling contact 51-52 (relay healthy, NC closed)
// Output:  Q0.0 = spindle/axis contactor K1 (must drop on E-stop)
//          M100.0 = internal "safety OK" latch
//          M100.1 = internal "cross-fault" flag

NETWORK 1   // Safety OK = ch1 AND ch2 AND signaling healthy
  A   I0.0
  A   I0.1
  A   I0.2
  =   M100.0           // safety OK

NETWORK 2   // Detect inconsistent channel states (cross-fault)
  XN   I0.0            // ch1 open
  X    I0.1            // ch2 closed  (one closed, one open → fault)
  O                   // symmetric:
  X    I0.0            // ch1 closed
  XN   I0.1            // ch2 open
  S   M100.1           // set cross-fault flag

NETWORK 3   // Hold-to-reset (manual restart interlock)
  A   M100.0
  A   I0.3             // reset pushbutton (NO, spring return)
  A   M100.2           // no cross-fault active
  S   M100.3           // safety latched
  AN  I0.0
  O   I0.1             // any channel open → release
  R   M100.3

NETWORK 4   // Drive enable / HMI alarm
  A   M100.3
  AN  M100.1           // suppress on cross-fault
  =   Q0.0             // contactor K1
  =   DB10.DBX56.1     // NCK: emergency stop active (low = OK)

NETWORK 5   // HMI alarm message (SinuTrain / HMI Advanced syntax)
  A   M100.1
  =   DB2.DBX180.0     // raise ALM 700001 "Safety cross-fault"
  AN  M100.0
  =   DB2.DBX180.1     // raise ALM 700002 "E-stop active"
Restart interlock: ISO 13849-1 and most C-type standards for machine tools (e.g., ISO 12100, ISO 16090) require a manual reset after a safety stop. The 3TK2828-1BB40 has no built-in reset input; the reset is implemented in the PLC on a dedicated NO pushbutton wired to a separate PP72/48 input. Never use the safety relay's own output as a reset input.

8. Verification and Commissioning

After wiring and PLC download, perform the following functional tests. Record the results in the machine's acceptance protocol.

Test Action Expected result Acceptance
Channel 1 trip Open E-stop channel 1 only with a jumper Relay does not drop. Cross-fault flag should not raise. OK / Fault
Channel 2 trip Open E-stop channel 2 only with a jumper Relay does not drop. Cross-fault flag should not raise. OK / Fault
Dual-channel trip Press E-stop All 4 NO contacts open within ≤ 30 ms; K1 drops; HMI shows ALM 700002. OK / Fault
Cross-fault simulation Short S11 to S21 with a test lead Relay must drop; PLC sets M100.1; HMI shows ALM 700001 and blocks restart. OK / Fault
Response time Measure from E-stop actuation to K1 dropout with an oscilloscope on 13-14 tA ≤ 30 ms + PLC scan ≤ 40 ms = ≤ 70 ms total OK / Fault
Restart interlock Release E-stop, do not press reset Machine must remain in safe state; K1 stays open. OK / Fault
Reset function Press reset pushbutton K1 closes, NCK interface re-enables, ALM clears. OK / Fault
PROFIBUS health Disconnect PROFIBUS during operation 802D enters follow-up mode; PP72/48 inputs freeze; HMI alarms. OK / Fault

The total stop time used in the safety-distance calculation is:

S = (tA + tPLC + tdrive) × vmax + dintrusion

where tA ≤ 30 ms (relay), tPLC ≤ 40 ms (one scan), tdrive is the drive's deceleration response (read from the Sinamics/Simodrive parameter list, typically 50-150 ms), vmax is the maximum hazardous speed, and dintrusion is the reach distance into the hazard zone per ISO 13855.

9. Troubleshooting Matrix

Symptom Likely cause Diagnostic Remedy
E-stop pressed, relay does not drop Coil not energised; A1/A2 polarity reversed; 24 V missing Measure A1-A2; check LED on relay Correct supply; replace fuse
Relay drops immediately on power-up, will not reset One channel stuck open; signaling contact 51-52 open Read I0.0/I0.1/I0.2; measure at S11/S12, S21/S22 Repair E-stop contact; check wiring
Relay chatters during operation Cross-fault detected; short between channels; bounce from inductive source Inspect cables; check filter time Separate channels; increase filter to 10 ms (verify against safety distance)
Drives do not drop on E-stop PLC logic fault; NCK enable not cleared; wrong address mapped Watch Q0.0 and DB31..DB61, DBX8.0 in online mode Correct ladder; remap inputs in PLC I/O configuration
PP72/48 not seen on PROFIBUS Address conflict; cable polarity; termination missing Check address DIP; bus termination resistor Set unique address; enable terminator at last node
Spurious ALM 700001 with no fault Asymmetric filter on two channels Check filter time of I0.0 vs I0.1 Set both inputs to the same filter
Reset pushbutton does nothing NCK not ready; reset wired to wrong input; PLC scan issue Monitor I0.3 and M100.3 online Re-wire; ensure PLC is in run
Response time exceeds budget PLC cycle time too long; filter time too high Measure with oscilloscope Reduce filter; optimize OB1 cycle; consider fast PLC inputs on PP72/48

10. Field-Proven Caveats

  • The 3TK2828-1BB40 has no automatic reset by default. If your machine uses a "controlled stop / automatic restart" category per IEC 60204-1 §9.2.5.8, you must implement the start/restart interlock in the PLC and the operator panel, not by re-energising the relay coil.
  • Never wire the 3TK2828 coil to a switched power source. The relay must remain energised for the full run-time of the machine; only the field input circuit (S11/S12, S21/S22) opens to drop the contacts.
  • The PP72/48 input filter setting is global per group of 8 inputs. Choose a filter that meets the safety-distance budget but is robust against EMI from VFD cables routed in the same tray.
  • When retrofitting an older 802D to a new safety relay, the 802D's PLC scan time on a heavily loaded project can exceed 40 ms. Profile it with the PLC cycle-time statistic before declaring the response-time budget.
  • Always provide a separate ground reference for the 3TK2828 coil (terminal A2) and the PP72/48 24 V common. Sharing a high-impedance return path can cause nuisance tripping on relay dropout.

11. Standards Reference

Validate the design against the current revisions of these standards. They are cited as reference documents, not as confirmation that the wiring above meets any specific PL/SIL — the integrator must do that calculation.

  • ISO 13849-1:2023 — Safety of machinery: Safety-related parts of control systems
  • IEC 62061:2021 — Functional safety of safety-related control systems
  • IEC 60204-1:2016 — Safety of machinery: Electrical equipment of machines
  • ISO 12100:2010 — General principles for design — Risk assessment and risk reduction
  • ISO 13855:2024 — Positioning of safeguards with respect to the approach speeds of parts of the human body

For background on how a safety relay monitors actuators and the safety contacts, see the Pilz safety-relay lexicon entry for a generic description of monitoring function. Always cross-check with the Siemens device manual, which is the binding source for the 3TK2828-1BB40.

Which PP72/48 inputs should I use for the 3TK2828 safety relay?

Use two adjacent inputs of the same group, e.g., I0.0 and I0.1 on the first PP72/48 (PROFIBUS address 1), to keep the filter time identical and to make the wiring symmetric. Wire the optional 51-52 signaling contact to a third input, e.g., I0.2, for diagnostics.

Do I need a separate reset pushbutton for the 3TK2828-1BB40?

Yes. The relay has no integrated reset. Implement a manual reset by wiring a separate NO pushbutton to another PP72/48 input and gating the restart in the PLC on that input plus a healthy safety state. This satisfies ISO 13849-1 and the restart interlock requirements of IEC 60204-1.

What PROFIBUS address should I set on the PP72/48?

Any address not used by the 802D HMI (usually 6) or by drives on the same segment. Typical first PP72/48 is address 3, second is address 4. Set the address with the on-board DIP switches before applying power.

Can I use only one channel of the 3TK2828-1BB40 with the 802D?

You can, but you lose cross-fault monitoring and typically cap the achievable performance level at PL c / SIL 1. For most machine-tool risk assessments, dual-channel is required. If you must use a single channel, document the rationale in the risk assessment and verify that the achieved PL/SIL is acceptable.

How do I stop the drives immediately when the safety relay drops?

Have the PLC clear the NCK interface signals DB31..DB61, DBX8.0 (pulse enable) and DBX8.1 (controller enable) within one PLC scan after detecting the safety drop. The drives will then execute their configured stop (OFF1/OFF2/OFF3) and remove torque within the drive's deceleration time, which must be added to the safety-distance calculation.

Back to blog