Overview
The SM 1226 F-DQ 4 × 24 V DC is a fail-safe digital output module for the S7-1200 PLC family. It provides four independent fail-safe outputs (F-DQ a.0 through F-DQ a.3) that can each be used in safety functions up to SIL 3 / PL e / Category 4 per ISO 13849-1. The module is a common replacement for electromechanical safety relays in PL-d machinery applications such as contactor shutdown, valve control, and two-hand circuits.
Each of the four output channels is implemented internally as two solid-state switches in a P/M switching arrangement. This dual-switch architecture is the key to understanding how a single F-DQ channel can satisfy PL-d requirements without external redundancy, and also how multiple channels can be combined for higher-category systems.
Module Identification and Variants
The SM 1226 family ships in three principal variants. Confirm the exact MLFB (order number) on the side of the module before wiring, because internal switch topology and external ratings differ.
| Variant | MLFB | Output Type | Typical Use |
|---|---|---|---|
| SM 1226 F-DQ 4 × 24 V DC / 2 A | 6ES7226-6DA32-0XB0 | 4 × solid-state, 24 V DC, 2 A | Standard PL-d / PL-e outputs |
| SM 1226 F-DQ 2 × Relay | 6ES7226-6RA32-0XB0 | 2 × relay NO contacts | Burner controls, AC loads |
| ET 200SP F-DQ 4 × 24 V DC / 2 A PM HF | 6ES7136-6DB00-0CA0 | 4 × solid-state, P/M switching, HF diagnostics | Distributed ET 200SP safety |
ISO 13849-1 Performance Level Requirements
PL-d (Performance Level d) per ISO 13849-1:2023 requires:
- Category 3 architecture: dual-channel with cross-fault monitoring, or single-channel with proven components and well-tried safety principles.
- PFHd (probability of dangerous failure per hour) between 10-7 and 10-6 / h, i.e. ≥ 10,000× lower than PL-a.
- DCavg (diagnostic coverage) ≥ 60% (medium).
- MTTFd of each channel ≥ 30 years (high).
- CCF (common-cause failure) score ≥ 65 from the checklist in Annex F.
For PL-e, Category 4 is required, meaning a single fault must not lead to loss of the safety function and the fault must be detected. The SM 1226 is designed and certified to satisfy both PL-d/Cat. 3 and PL-e/Cat. 4 on each individual output channel, which is why a single channel can perform a PL-d shutdown.
Internal Architecture of a Single F-DQ Channel
Per the Siemens S7-1200 Functional Safety Manual, each F-DQ output is built from:
- An upper P-switch (high-side, sourcing from +24 V DC).
- A lower M-switch (low-side, sinking to 24 V DC ground).
- A pulse-pattern diagnostic read-back path through the load.
- A short-circuit / cross-circuit test generator active in the OFF state.
The two switches are driven by an internal 1oo2 logic. A dark pulse test is applied continuously: both switches are momentarily opened, the read-back ADC checks that the channel reaches the OFF potential, and the switches are re-closed. If the read-back disagrees with the commanded state, the channel is passivated and the F-CPU is informed via the PROFIsafe telegram.
Because two physical switches are present per output, the SM 1226 can be wired as if it were a Cat. 3 redundant pair internally — even when only one terminal pair is used externally. This is the single most common point of confusion when migrating from safety relays to the F-DQ.
F-Monitoring Time and Passivation
Every F-DQ channel has a configurable F-monitoring time (default 100 ms, range 1 ms to 65535 ms in TIA Portal). This is the maximum interval allowed between two valid PROFIsafe telegrams. If the F-CPU does not refresh the channel within this window, the SM 1226 drives the channel to the safe (de-energized) state and reports a passivation event to the F-CPU.
Recommended values for typical PL-d discrete wiring:
| Application | F-monitoring time | Rationale |
|---|---|---|
| Contactor coil shutdown | 100 ms (default) | Coil dropout ~30 ms; 100 ms gives 3× margin. |
| Brake release valve | 50 ms | Valve response < 20 ms; tighter diagnostic. |
| Long PROFIsafe cycle (PROFINET 1 ms update × 32 nodes) | 150–250 ms | Accommodate worst-case jitter. |
| Burner safety (SM 1226 F-DQ 2 × Relay variant) | 100 ms | Per burner application note. |
Wiring Topologies for PL-d
Three wiring patterns cover most PL-d applications. All three are valid provided the load ratings, wire cross-section, and cable routing constraints from the F-DQ 4×24VDC/2A PM HF manual are observed.
Topology 1: Single F-DQ Channel Driving One Contactor Coil (PL d / Cat. 3)
The simplest, most common pattern. One output (e.g. F-DQ a.0) drives a single 24 V DC contactor coil. The internal 1oo2 structure of the channel delivers PL d / Cat. 3 to the actuator.
- Source: F-DQ a.0+
- Return: F-DQ a.0-
- Load: contactor coil K1, suppressor diode across the coil.
Topology 2: Single F-DQ Channel Driving Two Coils in Series (PL d / Cat. 3)
Used when two contactors must both drop out for a safe stop. Connecting the two coils in series on a single F-DQ channel means a single channel fault (e.g. welded P-switch) cannot prevent de-energization as long as the M-switch of the second leg opens. This is the topology Siemens documents in the S7-1200 F-CPU configuring guide for motor shutdown.
Topology 3: Two F-DQ Channels Driving Two Independent Coils (PL e / Cat. 4)
Where a single fault must not be able to prevent shutdown (Cat. 4), use two F-DQ channels — F-DQ a.0 and F-DQ a.1 — each driving one contactor coil. The F-CPU confirms both channels de-energize. This is the equivalent of the legacy "two redundant contactors driven by a safety relay" pattern, but with the safety logic inside the F-CPU.
Topology 4: Two Parallel Coils on One F-DQ Channel (Two-Hand Control Variant)
When two operator push-buttons (e.g. 3SU1 two-hand station) each contain a coil that must release the machine when either is released, the two coils can be wired in parallel between F-DQ a.0+ and F-DQ a.0-. The internal dark-test still detects a short to ground or to +24 V on either branch. This reaches PL d / Cat. 3 and, with the right sensor and F-block selection, PL e / Cat. 4.
Why One F-DQ Channel Can Reach PL-d
PL-d / Category 3 requires that a single fault does not lead to loss of the safety function and that a single fault is detected. The F-DQ channel delivers this by:
- Dual internal switches (P and M) — a welded P-switch is detected by the next dark test, which will see the load voltage stay high and passivate the channel.
- Continuous dark-pulse diagnostics — DCavg ≥ 90% on the output (per Siemens FMEDA data).
- External short-circuit detection — any short between F-DQ a.0+ and 24 V ground, or between F-DQ a.0- and +24 V, is detected and passivates the channel within one monitoring cycle.
- Cross-circuit detection between channels — short between F-DQ a.0+ and F-DQ a.1+ is detected by the asymmetric read-back path. A short between +24 V supply and F-DQ a.0+ is only detected when the F-DQ tries to switch off; a stuck-high output then cannot drop the load.
Configuration in TIA Portal
Prerequisites
- S7-1200 CPU with firmware ≥ V4.2 that supports PROFIsafe (CPU 1212FC, 1214FC, 1215FC, 1217FC, or a standard CPU with F-capability activation via Siemens Support).
- TIA Portal V15.1 or later with the "STEP 7 Safety" option package installed.
- F-Destination Address (F-DestAddr) for the SM 1226, set on the DIP switch on the left side of the module. Default is 1024; assign a unique value per F-slave on the PROFINET line.
Step-by-Step Configuration
- Add the SM 1226 F-DQ 4 × 24 V DC to the device configuration. Right-click the S7-1200 CPU slot, choose Add new submodule, and pick the F-DQ from the catalog.
- Open the Properties > PROFIsafe tab and enter the F-DestAddr matching the DIP switch. Set the F-monitoring time to 100 ms (or the value from the table above).
- Open Properties > DQ parameters. For each channel, configure:
- Channel activated: enable only the channels you need; unused channels save CPU time and dark-test cycles.
- Output type: P-type (high-side, sourcing) or P/M-type (sourcing + sinking, the default for fail-safe).
- Behavior on CPU STOP: Substitute value 0 (recommended for PL-d) or Keep last value (only for special bumpless applications).
- Reintegration mode: Automatic for non-critical actuators, Manual when a re-arm pushbutton is mandated by the risk assessment.
- In the safety program (F-FB or F-DB), wire the F-DQ output tag (e.g.
FDB_DO0) to the actuator. The tag is aBOOLdriven by the F-CPU; the user program cannot write it directly — only the F-runtime library blocks (FDBACK,ESTOP1,TwoHand) may write it. - Compile the safety program (F-Compile) and download the F-block container separately from the standard program. TIA Portal prompts you for the safety password; this password is independent of the PLC password.
Comparison: SM 1226 F-DQ vs. Electromechanical Safety Relay
| Criterion | Safety relay (e.g. SIRIUS 3SK1) | SM 1226 F-DQ 4 × 24 V DC |
|---|---|---|
| Wiring | Fixed terminals, hardwired logic | Programmable in F-CPU |
| Outputs per device | 2–4 NO contacts | 4 solid-state, 24 V DC, 2 A each |
| Max PL / Category | Up to PL e / Cat. 4 (model-dependent) | PL e / Cat. 4 per channel |
| Diagnostics | LED only | PROFIsafe diagnostics, passivation log, dark-test counters |
| Re-arming | Manual reset terminal | Software: manual or automatic |
| Load flexibility | AC or DC | DC only (relay variant for AC) |
| Lifecycle | Mechanical wear on contacts | Solid-state, no mechanical wear |
| Cost per channel | Higher above 2 outputs | Lower for 4 outputs (one module covers four actuators) |
Commissioning and Verification
After wiring and configuration, perform these checks before energising production:
-
Address check: in TIA Portal online view, confirm the F-DestAddr on the module matches the configuration; mismatch yields
SFLED and DIAG "Address conflict". - Dark-test verification: force each F-DQ channel ON in the F-watch table, measure the load voltage with a true-RMS voltmeter, and confirm the value is +24 V DC ±10% with <1 V ripple from the dark-test pulse.
-
Passivation test: disconnect the PROFIsafe cable to simulate a lost telegram. Within the F-monitoring time, the channel must drop to 0 V and the F-CPU must report
Channel passivatedin the diagnostic buffer. - Cross-circuit test: short F-DQ a.0+ to F-DQ a.1+ with a 1 m wire. The dark-test must detect the fault and passivate both channels within one monitoring cycle.
-
Stop-category test: trigger the E-stop and measure the time from E-stop actuation to contactor dropout. Compare against the calculated safety reaction time:
t_safety = t_sensor + t_F-CPU + t_monitoring + t_actuator. Typical PL-d target: < 30 ms for contactor shutdown, < 250 ms for valve shutdown. - Reintegration test: clear the passivation, apply a manual reset, and confirm the channel re-arms only after the F-block acknowledges the request.
Troubleshooting Matrix
| Symptom | SF LED | Diagnostic buffer text | Likely cause | Action |
|---|---|---|---|---|
| Channel stays OFF after F-CPU requests ON | Solid red | "Channel passivated, discrepancy time exceeded" | Load resistance too low, or short to ground | Measure load: must be ≥ 100 kΩ to chassis ground (HF) or > 1 MΩ (non-HF). Check wiring. |
| All 4 channels passivated simultaneously | Flashing red | "PROFIsafe address error" | F-DestAddr mismatch with TIA configuration | Re-set the DIP switch; reload the F-block container. |
| Intermittent passivation under load | Red | "Short circuit to P-supply detected" | Inductive kick from contactor coil | Add suppressor diode (1N4007 or RC snubber) directly at the coil. |
| DIAG "Wire break" on idle channel | Off, but F-CPU reports it | "Wire break F-DQ a.x" | Open wire on unused output | Disable the channel in DQ parameters; do not leave floating outputs enabled. |
| Channel ON, but contactor chatters | Off | None | Supply voltage sag or dark-test pulse too aggressive | Check 24 V DC supply at the module terminals; verify ripple < 5%. |
Frequently Asked Questions
Does the SM 1226 F-DQ need two output channels for PL d?
No. Each F-DQ channel is internally built from two switches (P and M) with continuous dark-pulse diagnostics, which satisfies Category 3 architecture on its own. One channel can drive a single contactor coil at PL d. Use two channels only when the risk assessment requires Cat. 4 (PL e).
What is the default F-monitoring time and when should it be changed?
The default is 100 ms, which suits most contactor and valve applications. Reduce it to 50 ms for fast brakes; increase to 150–250 ms when the PROFIsafe cycle is long (e.g. PROFINET update 1 ms with 32 F-devices on one line).
Can I leave unused F-DQ channels unconnected?
Wire them to a defined load (e.g. a 10 kΩ resistor to 24 V) or disable them in TIA Portal under DQ parameters. Floating outputs trigger wire-break diagnostics and can passivate the module.
Does the SM 1226 F-DQ 4 × 24 V DC support AC loads?
No — the solid-state variant is DC only. For AC burner loads, use the SM 1226 F-DQ 2 × Relay variant (6ES7226-6RA32-0XB0), which provides two relay NO contacts rated for AC-15 loads up to 230 V AC.
How is the SM 1226 different from the ET 200SP F-DQ 4×24VDC/2A PM HF?
The SM 1226 is a centralized S7-1200 module on the right-hand signal slice bus. The ET 200SP F-DQ (6ES7136-6DB00-0CA0) is a distributed PROFINET safety slave with P/M switching and HF (high-frequency) diagnostics that allow chassis-ground resistance down to 100 kΩ. Both are PL e / SIL 3 capable per channel, but the ET 200SP version is preferred for distributed cabinets.