You can design the mechanism. This is the other half of the machine: the sensing, the logic, the wire, and the safety case that decides whether your motion ever runs. If you specify machines, judge quotations, or lead the people who build them, and your training was mechanical, this is the ground you are missing.
What follows is the big picture first, then the detail. Where a topic has real depth, it sits behind a deep dive toggle you can open or skip. Every number here is attributed, and where a standard is paywalled or a figure is vendor specific, that is said rather than hidden.
- The big picture: one loop, repeated fast
- Sensing and IO: digital, analog, remote, IO-Link
- Relays and the PLC: what each is still for
- Industrial networks: EtherNet/IP, PROFINET, EtherCAT, CC-Link, Modbus
- Drives and motion: VFD, servo, stepper, electronic cam
- Machine safety: stop categories, PL and SIL, safety over a network
- What the specification must say
1. The big picture
Every automated machine is the same loop, repeated fast: measure the world, decide, move something, measure again. Electrical control is the discipline of making that loop fast enough, repeatable enough, and safe enough. Everything below is a variation on it.
Sense. A physical condition becomes an electrical signal. A part is present, a cylinder is home, a temperature is 84 degrees, a shaft is at 137.2 degrees.
Decide. A controller reads those signals, applies logic, and produces commands. In 1970 that logic was a wall of relays. Today it is a program, but the underlying model is unchanged.
Act. A command energizes something: a contactor, a valve solenoid, a drive. The machine moves, which changes what the sensors see, which closes the loop.
The four questions that decide an architecture
- How fast does the loop need to close? A conveyor jam detector can tolerate 20 ms. A flying shear cannot. Speed requirements drive everything downstream: controller class, network choice, whether motion lives in the PLC or in the drive.
- How far apart are the pieces? Distance decides whether you run 200 wires back to one cabinet or put IO nodes on the machine and run one network cable.
- What happens when it fails? If a failure can hurt someone, a separate safety architecture is mandatory and is assessed by its own standards. This is not an add-on and it is not the same as the control program.
- Who has to live with it for fifteen years? Spares, obsolescence, the skills of the maintenance team, and whether anyone can get the source code. This is the question engineers under-weigh and managers cannot.
Think of the controller as the cam shaft and the program as the cam profile. The scan is the shaft speed. Wiring and networks are the linkages that carry motion from the shaft to the stations. Safety is the mechanical stop you fit because you do not trust the linkage. The whole discipline maps onto things you already reason about.
B2. Sensing and IO
Before any logic runs, the physical world has to arrive at the controller as a number or a bit. Most commissioning pain lives here, not in the program. Section marks on this post are the IEC 81346-2 class letters that appear on real schematics. Class B is converting an input variable into a signal for processing.
Digital IO, and the mistake that stops a machine dead
A digital input is a 24 VDC circuit that is either closed or open. The controller reads it as 1 or 0. Almost all machine IO is 24 VDC, which is why blue, the NFPA 79 color for DC control circuits, dominates a modern panel.
The one thing to know cold is sinking versus sourcing, also written NPN versus PNP, because getting it wrong means nothing works and nothing is broken.
| Sensor type | What it does when it triggers | Pairs with | Where you see it |
|---|---|---|---|
| PNP (sourcing) | Connects +24 VDC to the signal wire | A sinking input module, which looks for +24 V | Common in Europe and North America |
| NPN (sinking) | Connects 0 VDC to the signal wire | A sourcing input module, which looks for 0 V | Common in Japan and much of Asia |
Sensor and module must be opposite types. The regional split is a matter of what has historically been on the shelf, not a standard and not a technical superiority argument, and most sensor families now ship in both polarities. It still bites on a machine built in one region and retrofitted in another.
Analog IO: why 4 to 20 mA beats 0 to 10 V
4 to 20 mA current loop
- 4 mA is zero percent, so 0 mA is unambiguously a fault: broken wire, dead transmitter, lost loop power. This is the live zero.
- Current is immune to voltage drop along the cable, so long runs stay accurate.
- Noise couples roughly equally into both conductors of a twisted pair and largely cancels at a low impedance receiver.
- The standing 4 mA can power the transmitter itself, which is why two wire instruments exist.
- More expensive per point, and needs a loop power strategy.
0 to 10 V
- Cheap, simple, and universally supported.
- A cut wire reads as zero percent, which is indistinguishable from a genuine zero reading.
- Conductor resistance and receiver loading degrade accuracy over distance.
- More vulnerable to induced noise from drives and contactors.
Deep dive: NAMUR NE 43 turns live zero into a diagnostic language
Live zero only tells you that zero is bad. NE 43 formalizes the rest of the range so a transmitter can signal its own health in band:
| Signal | Meaning |
|---|---|
| ≤ 3.6 mA | Instrument failure, under-range |
| 3.8 to 20.5 mA | Valid measurement information |
| ≥ 21 mA | Instrument failure, over-range |
The consequence is worth internalizing: a reading above 21 mA means the transmitter has failed, not that the tank is full. A control system that treats it as a full tank will act on a lie. If your specification does not require NE 43 behavior and alarm handling for it, you have bought instruments that cannot tell you they are broken.
Centralized IO versus remote IO
The oldest layout runs every sensor and every actuator back to one cabinet. The alternative puts small IO nodes out on the machine and links them with one network cable. This is one of the few genuinely architectural decisions in panel design.
IO-Link: the layer below the network
IO-Link is worth knowing because it keeps appearing in modern specifications. It is standardized as IEC 61131-9, and it is explicitly not a fieldbus. It is a point-to-point digital link between a master port and one device, running over the same unshielded three wire cable and M12 connector you already use for a proximity sensor.
What that buys you: a sensor stops being a single bit and becomes a device with parameters, an identity, and diagnostics. You can push a recipe change to eighty sensors from the controller instead of sending a technician with a screwdriver, and a failed sensor can be replaced with a blank unit that auto-configures itself from the master.
| Property | Value |
|---|---|
| Standard | IEC 61131-9 (SDCI), Edition 2 published 2022 |
| Transmission rates | COM 1: 4.8 kBaud COM 2: 38.4 kBaud COM 3: 230.4 kBaud |
| Maximum cable | 20 m, unshielded, 3 or 5 conductor |
| Topology | Point to point, one device per master port. Not a bus. |
| Fieldbus dependency | None. The master sits on whatever network you already run. |
IO-Link's real payoff is changeover time and mean time to repair on a high-mix line, not raw speed. If your line runs many product variants, sensor parameters that follow the recipe instead of a technician is a direct output gain. That is the argument to make when someone asks why the sensors cost more.
K3. Relays and the PLC
The PLC did not replace relay logic so much as absorb it. Understanding the relay first is not history, it is the reason ladder logic looks the way it does and the reason hard wiring still wins in a few specific places. Class K is processing signals or information.
Three devices people confuse
Control relay
A small coil moves internal contacts to open or close another circuit. Used for logic and for switching signal level loads. This is the device ladder logic is drawn after.
Contactor
The same electromagnetic principle built for heat, arcing, vibration, and heavy switching duty. This is what actually connects a motor, heater, or large fan to the line.
Overload relay
Not a switch, a protection device. It trips the circuit when sustained overcurrent starts to overheat the motor. It is not short circuit protection, which is the fuse or breaker's job.
Contactor plus overload relay is a motor starter. When a controls engineer says "add a starter," this is the assembly they mean, and it takes panel space and heat budget you should have allowed for.
Hard wired relay logic versus a PLC
Hard wired relay logic
- No software, no firmware revision, no license, no programming toolchain.
- Robust in harsh environments and genuinely easy for a technician to read and repair from the schematic.
- The circuit is visible. What it does is what it is wired to do.
- Any logic change is physical rewiring and new hardware.
- Extensive wiring and large panels.
- Minimal diagnostics and no data to hand upstream.
- Becomes impractical as soon as the logic grows.
PLC
- Logic changes are a download, not a rewire.
- Diagnostics, data, alarms, HMI, and a path to the plant systems.
- Far fewer devices and far less panel volume for the same logic.
- Software becomes an asset you have to own, version, back up, and be able to modify. Many plants discover at the worst moment that they cannot.
- Vendor ecosystem lock-in is real and long lived.
- The behavior is no longer visible from the schematic.
The scan cycle, and why nobody can tell you "the scan time"
A PLC runs a repeating cycle: read the physical inputs into an input image table, service communications, execute the program against that frozen image, write the output image to the physical outputs, run diagnostics, repeat.
The consequence that matters: the program never sees live inputs. A pulse shorter than one scan can arrive and leave without the program ever knowing. That is precisely why high speed counter modules, interrupt inputs, and hardware latching inputs exist, and it is the right question to ask when someone tells you a count is drifting.
Deep dive: why a single scan time figure is meaningless
Vendors do not publish "typical scan time for a small program." They publish per instruction execution time, from which scan time is built. Siemens publishes the following for the S7-1500 family, which is useful precisely because it shows the spread inside one product line:
| CPU | Bit operation | Word operation | Floating point |
|---|---|---|---|
| 1511-1 PN | 60 ns | 72 ns | 384 ns |
| 1513-1 PN | 40 ns | 48 ns | 256 ns |
| 1515-2 PN | 30 ns | 36 ns | 192 ns |
| 1516-3 PN/DP | 10 ns | 12 ns | 64 ns |
| 1517-3 PN/DP | 2 ns | 3 ns | 12 ns |
| 1518-4 PN/DP | 1 ns | 2 ns | 6 ns |
A sixty times spread on bit operations exists inside one family, so "a PLC scans in X milliseconds" is meaningless without the part number. Three further reasons the number moves:
- Scan time is data dependent. Conditional branches, jumps, and skipped subroutines mean the same program takes different times on different scans.
- Communication load shares the cycle and varies with what the HMI and the plant systems are asking for.
- Modern controllers do not run one flat scan at all. Rockwell Logix platforms use continuous, periodic, and event tasks at different rates; Siemens supports cyclic interrupt organization blocks. On these there is no single quantity called "the scan time."
The right specification is therefore not a scan time. It is a response time requirement for a named function: from this sensor edge to that output change, worst case, including network. That is testable. "Fast PLC" is not.
Deep dive: what language the program is written in
IEC 61131-3 is the programming languages standard, currently Edition 4.0 published in 2025. It defines Ladder Diagram (LD), Function Block Diagram (FBD), and Structured Text (ST), plus Sequential Function Chart (SFC) as a structuring element for organizing a program into steps and transitions. Instruction List (IL) was the classic fifth entry and was deprecated from Edition 3.0 in 2013.
- Ladder looks like a relay schematic because it was designed so relay technicians could read it. Excellent for interlocks and machine logic, poor for math and data handling. Maintenance teams can almost always read it.
- Structured Text is a Pascal-like text language. Far better for calculations, recipes, loops, and anything a software engineer would recognize. Worse for a technician debugging at 2 am unless your team is trained on it.
- Function Block Diagram suits signal processing and reusable blocks, and reads naturally to anyone who thinks in block diagrams.
- SFC is the right tool for a sequence of machine states, which is most of what a special purpose machine actually does.
Standardization matters more than the choice. A site that mixes ST and ladder with no rule about which goes where has doubled the skill requirement of every maintenance technician for no gain.
W4. Industrial networks
This is where mechanical engineers most often feel lost, and where the decision is less technical than it looks. There are three layers of traffic on a machine, they have genuinely different requirements, and almost every protocol argument is really an argument about which layer you are talking about. Class W is guiding or transporting from place to place.
A network replaces parallel copper with a shared serial link. You gain wiring reduction, diagnostics per device, and parameter access. You give up the simplicity of one wire per signal, and you take on a timing budget: the data now arrives on a schedule rather than instantly. Everything below is the industry's answer to one question: how do you make Ethernet, which was designed to be non-deterministic, deliver a frame on time every time?
The families you will be asked about
EtherNet/IP
Standard unmodified Ethernet carrying the Common Industrial Protocol. Two traffic types: implicit IO messaging over UDP at a fixed interval, and explicit request and response messaging over TCP for configuration and diagnostics.
- No special hardware or network expertise required, which lowers the plant skill barrier.
- Device Level Ring gives single fault tolerant ring topology without managed switches everywhere.
- Dominant where Rockwell is the site standard, which is most of North America.
- Standard Ethernet means determinism comes from design discipline and segmentation, not from the wire.
PROFINET
Also standard Ethernet cable and connectors, with conformance classes that tell you what a device can actually do. RT bypasses TCP/IP for cyclic data. IRT schedules the network itself for motion grade synchronization.
- Conformance classes A, B and C make capability a purchasable specification rather than a claim.
- IRT reaches cycle times down to 31.25 microseconds with one microsecond jitter, which covers coordinated motion.
- Deep diagnostics and topology awareness at class B and above.
- IRT requires every switch inside the IRT domain to support it, plus synchronized clocks. That is a design constraint, not a drop-in.
EtherCAT
The clever one. A single frame passes through every device in the segment; each device reads its data and inserts its reply on the fly as the frame moves through, delayed by only a few bits. One frame serves the whole segment instead of one frame per device.
- Very high efficiency, the ETG cites over 90 percent telegram data rate utilization.
- Standard Ethernet cable, flexible line, tree, star and daisy chain topology, up to 65,535 devices per segment.
- Slave hardware is inexpensive, which makes dense IO cheap.
- Slave devices need EtherCAT capable hardware, so the device ecosystem is narrower than plain Ethernet.
CC-Link and CC-Link IE
A family, not one protocol, and the distinction matters. The original CC-Link is an RS-485 bus. The IE family is Ethernet based: Controller Network and Field Network at 1 Gbps, Field Network Basic as a software implementation at 100 Mbps, and CC-Link IE TSN which adds Time Sensitive Networking.
- Gigabit at the machine control layer, which is unusual in this group.
- CC-Link IE TSN uses IEEE 802.1AS for synchronization and 802.1Qbv scheduled traffic, so time critical and general traffic share one wire without one starving the other.
- Dominant installed base across Japan, China, South Korea, and much of ASEAN.
- Outside Asia the device ecosystem and the local support depth are thinner.
Modbus RTU and Modbus TCP
The lingua franca. Forty years old, free of licensing, supported by almost every instrument ever made. RTU runs on RS-485 serial, TCP runs on Ethernet at port 502. Master polls, slave answers, up to 247 slave addresses.
- Universal support, no license fee, trivially simple to implement and to debug.
- Perfect for what it is used for: reading a power meter, a temperature controller, a weigh scale.
- Sequential polling, so the master is a bottleneck and throughput falls as the device count rises.
- No device description layer, so there is no standard way to discover what a device is or what its registers mean. You read the manual and map registers by hand.
- Not suitable for motion or interlocks that need a timing guarantee.
OPC UA
Not a machine control network and not a competitor to the four above. It is the vendor neutral way a machine exposes its data upward to MES, historians, and analytics, with an information model so the receiver knows what a value means, not just its address.
- Breaks the "every integration is a custom register map" problem that Modbus leaves you with.
- Built-in security model, which matters the moment OT touches IT.
- Adds a modeling effort that someone has to own, and it is usually nobody's job by default.
Side by side
| Protocol | Owner | Physical layer | Determinism comes from | Pick it when |
|---|---|---|---|---|
| EtherNet/IP | ODVA | Standard Ethernet, 10 M to 1 G and above | Design discipline, segmentation, and CIP Sync time stamping where needed | The site standard is Rockwell, or you need the widest North American device ecosystem |
| PROFINET | PI | Standard Ethernet | RT scheduling, and IRT scheduling of the network itself with IEEE 1588 clocks | The site standard is Siemens, or you need certified capability classes in the purchase spec |
| EtherCAT | ETG | Standard Ethernet cable, EtherCAT slave hardware | Processing on the fly plus distributed clocks | High axis count, dense IO, a machine builder choosing their own stack |
| CC-Link IE TSN | CLPA | Standard Ethernet, 1 Gbps and 100 Mbps | IEEE 802.1AS sync and 802.1Qbv scheduled traffic | Asian supply base, Mitsubishi houses, or you want TSN convergence now |
| Modbus TCP | Modbus Org | Standard Ethernet, port 502 | Nothing. It polls. | Reading instruments and legacy devices, never for motion or interlocks |
| IO-Link | IO-Link Community | Unshielded 3 wire, 20 m, point to point | Not applicable, it is a link not a bus | You want sensor parameters, identity, and diagnostics below the network |
Deep dive: what the ETG actually publishes for EtherCAT performance
These are the EtherCAT Technology Group's own published example figures. Treat them as benchmark examples under favorable conditions, not as guarantees for an arbitrary machine, and say so if you quote them:
- 256 digital IO in 11 microseconds
- 1000 digital IO distributed across 100 nodes in 30 microseconds
- 200 analog IO at 16 bit in 50 microseconds, a 20 kHz sampling rate
- 100 servo axes, 8 bytes in and out each, in 100 microseconds
The ETG's current performance page presents comparisons qualitatively rather than repeating these numbers, which is itself informative: vendors have largely stopped racing on headline microseconds because real machine performance is dominated by topology, cable length, device implementation quality, and what the controller is doing between cycles.
Deep dive: how to actually choose
The honest position is that at the machine control layer these protocols are close enough in capability that the technical comparison is rarely the deciding factor. All four major Ethernet protocols will run your machine. What decides it:
- What is already installed. A second protocol on a site doubles spares, doubles diagnostic tooling, doubles the training burden, and creates a gateway that becomes the first suspect in every intermittent fault. The cost of divergence is almost always higher than the benefit of the better protocol.
- What your maintenance team can diagnose at 3 am. A protocol your team cannot troubleshoot turns a twenty minute fault into a four hour one, whatever its cycle time.
- What your supply base builds. A machine builder forced onto an unfamiliar stack will quote higher, deliver later, and support it worse. That is a real cost, and you pay it.
- Where your spares and support actually are. Regional ecosystem depth beats a specification sheet. This is the strongest argument for CC-Link IE in an Asian electronics plant and for EtherNet/IP in a North American one, and it is not a technical argument at all.
- Only then, technical fit. High axis count coordinated motion genuinely favors EtherCAT or PROFINET IRT. Dense simple IO over long distances favors whatever your standard is. Reading instruments favors Modbus regardless.
The failure mode to recognize: a site with no standard, where each machine arrived with whatever its builder preferred, and the plant now runs four protocols, three HMI platforms, and two PLC families. Every one of those decisions was locally reasonable. Collectively they are the reason maintenance cannot be trained and spares cannot be pooled.
M5. Drives and motion
This is the part of electrical control that is really mechanical engineering wearing a different hat. If you have specified a cam indexer, you already understand most of what a motion controller does. The vocabulary is what is missing. Class M is providing mechanical energy for driving.
Three ways to turn a shaft
VFD
Controls induction motor speed by varying the frequency of the supplied voltage. Classically open loop velocity control. It answers "how fast," not "where."
Servo
A motor with position feedback and a drive that closes a loop around it. It answers "where, exactly, and get there on this trajectory." Handles roughly 100 times its rotor inertia by one vendor's published figure.
Stepper
Commanded to a position without feedback. Cheap and needs no tuning. Its defining risk is step-out: overload it and it silently loses steps with no alert to the controller.
When someone specifies a stepper, ask what happens if it step-outs unnoticed. If the answer is scrap, a crash, or a safety event, it needs either a closed loop stepper or a servo. A closed loop stepper detects and corrects step-out but by the same vendor's published figures handles roughly 30 times rotor inertia against a servo's 100, so it is not a drop-in servo replacement for a high inertia or high dynamic load.
VFD control modes, and why "we have a VFD" is not an answer
The control mode matters more than the drive brand. These are figures published by Yaskawa for their own drives. They are vendor specific, and competing drives publish different numbers, so treat the pattern as the lesson rather than the values.
| Mode | Speed regulation | Torque capability | Feedback | Typical use |
|---|---|---|---|---|
| V/f (scalar) | ±2 to 3 % of max freq | 150 % starting torque at 3 Hz | None | Fans, pumps, simple conveyors |
| V/f with encoder | ±0.03 % of max freq | As above | Encoder | Where speed holding matters |
| Open loop vector | ±0.2 % of max freq | 200 % rated torque at 0.3 Hz | None, but requires motor auto-tuning | Dynamic response, torque limiting, crushers, cappers |
| Closed loop vector | Highest | 200 % torque at 0 rpm | Encoder required | Hoists, cranes, elevators, winders |
Two selection points fall straight out of that table. Open loop vector accuracy depends on the quality of the auto-tune against the actual motor, so a rewound or mismatched motor degrades it. And full torque at genuine zero speed for load holding needs closed loop vector, which is exactly why hoists and elevators are specified closed loop and why a VFD alone is not a brake.
Deep dive: feedback devices, and what each one costs you
- Incremental encoder. Counts pulses relative to wherever it started. Position is lost at power down, so the machine must home on every power cycle. Cheap and everywhere. The homing requirement is a real cycle time and safety consideration on a machine with many axes.
- Absolute encoder, single turn. Reports a unique position within one revolution. No homing needed within a turn.
- Absolute encoder, multi turn. Tracks revolutions as well, usually with a battery or a gear train. No homing at all, which on a multi axis machine with interference zones is worth paying for. The battery becomes a maintenance item, and a dead battery on a Monday morning is a classic cause of a lost machine position.
- Resolver. An analog rotary transformer, absolute within one turn, with no electronics in the sensor head. That is the whole argument for it: heat, shock, vibration, and radiation tolerance that an optical encoder cannot match.
Digital feedback protocols such as EnDat, BiSS and HIPERFACE DSL carry absolute position plus device data over fewer wires, and DSL in particular runs feedback over the motor cable, which removes a connector and a cable from your machine. That is a mechanical win disguised as an electrical spec.
Electronic cam and electronic gearing
Electronic gearing is a constant ratio. The slave axis follows the master at a fixed multiple, exactly as a gear train does. Omron defines it as rotating the servo motor for the number of pulses obtained by multiplying the command pulses by the electronic gear ratio. Its three practical uses are synchronizing two lines, allowing a controller with a lower pulse rate to be used, and setting machine travel per pulse to a convenient figure such as 0.01 mm.
Electronic camming is a position dependent ratio. Siemens puts it precisely: cam disks are electronic gears at a non-constant transition, where a constant drive motion is converted into a non-constant drive motion by applying the laws of motion. The cam profile is a table of points, each carrying master position, slave position, velocity ratio and acceleration ratio, with polynomial interpolation between them.
A mechanical cam indexer gives you the motion law machined into steel: rigid, repeatable, holding position without power, with the torque path taken by the cam and follower rather than by a control loop. A servo cam gives you the same motion law as a table you can change in software.
What you gain going electronic: changeover becomes a data change instead of a machining job, the profile can differ per product variant, and phase relationships between stations can be retuned without disassembly. On a high mix line that is decisive.
What you give up: stiffness, the inherent holding at rest, and the fact that a steel cam cannot be mis-parameterized by a well meaning engineer. A servo axis needs a brake and a safety case to do what a cam does by geometry. Being able to argue both sides of this, rather than assuming electronic is modern and therefore better, is the judgment worth having.
Deep dive: what motion over a network actually means
Once drives sit on a network, the controller can close the position loop centrally and stream a target position to every drive every cycle. That is what makes multi axis coordination, gearing and camming possible across separate drives.
| Name | What it is | Network |
|---|---|---|
| CIP Motion | A CIP extension for closed loop motion over unmodified Ethernet, using CIP Sync (IEEE 1588) time stamping rather than relying on network determinism | EtherNet/IP |
| PROFIdrive | A vendor independent drive profile with scalable application classes, from basic speed control up to multi axis motion with centralized position control | PROFIBUS DP and PROFINET IO |
| Sercos III | Its own IEC standardized Ethernet based real time bus, with several hundred standardized parameters. Strong in machine tools | Its own bus |
| CiA 402, CSP mode | The drive profile standardized as IEC 61800-7. In cyclic synchronous position mode the controller sends a new target position every network cycle and the drive interpolates between them | CANopen originally, now EtherCAT (CoE), POWERLINK and others |
The interesting difference is how they get synchronization. CIP Motion deliberately does not depend on the network being deterministic: it synchronizes device clocks to better than 200 ns with IEEE 1588 and time stamps the data, so a little jitter in arrival time does not matter. PROFINET IRT and EtherCAT instead make the network itself deterministic. Both work. The first keeps standard Ethernet hardware, the second gets tighter cycles.
F6. Machine safety
Safety is not a feature of the control system. It is a parallel system with its own standards, its own architecture, and its own evidence requirements, and in most jurisdictions it is a legal obligation on whoever puts the machine into service. Class F is direct protection against a hazardous condition.
Why a normal relay is not enough
The argument is concrete. An ordinary relay's contacts can weld after repeated switching, so the machine keeps running despite an emergency stop command. A safety relay prevents that with two independent channels driving separate internal relays, so a single failure still opens the circuit, plus automatic testing of the relays on every on-off cycle and a feedback loop that verifies the external contactors actually dropped out.
Redundancy alone does not catch everything. A short between the two channels would make both follow one signal and silently defeat the redundancy. That is detected by pulse testing: the outputs periodically pulse low to prove they can reach 0 V, and the pulse intervals on the two channels are deliberately staggered, so a cross connection shows up as a pulse appearing on the wrong channel at the wrong instant and the system trips safe.
Stop categories, which people get wrong constantly
| Category | What happens | Allowed for emergency stop |
|---|---|---|
| Category 0 | Immediate removal of power to the actuators. An uncontrolled stop. On a drive this is Safe Torque Off. | Yes |
| Category 1 | A controlled stop with power still available to achieve the stop, then power removed once stopped. | Yes |
| Category 2 | A controlled stop with power left available to the actuators throughout. | No |
The categories are defined in IEC 60204-1. Category 2 is not acceptable for emergency stop because power remains at the actuators. The choice between 0 and 1 is a real engineering decision, not a preference: cutting power instantly to a loaded vertical axis or a high inertia spindle can be more dangerous than a controlled stop, which is the case for category 1 plus a brake.
It must take priority over all other functions and controls in every operating mode. It must latch in and stay latched until deliberately released. Releasing it must not by itself restart the machine. And it must remain available and functional at all times. ISO 13850 also separates emergency stop from emergency switching off, which removes power entirely. They are different functions and specifying the wrong one is a common error.
Safety relay or safety PLC
Safety relay
Fixed wired architecture performing defined safety functions. Roughly one device per function.
- Needs only basic electrical knowledge to install and to fault-find.
- No software, no configuration file to lose, no programming license.
- Behavior is evident from the schematic.
- Does not scale. Ten safety functions means ten devices, a lot of wiring, and panel space.
- Little per-device diagnostics, so "which guard is open" is not something the HMI can tell you.
Safety controller or safety PLC
Programmable, certified, with diagnostics and a communications interface.
- Scales to many functions and many zones without a device per function.
- Per-device diagnostics, so the operator learns which device tripped and why.
- Zone logic, muting, and partial stops become practical, which protects throughput.
- The safety program is now an asset requiring version control, validation records, and a competent owner.
- Changes require re-validation, and someone must be authorized to make them.
PL and SIL: the two ways to prove it
There are two parallel routes to demonstrating that a safety function is good enough. They are alternatives, not a hierarchy.
| Standard | Metric | Current status | Character |
|---|---|---|---|
| ISO 13849-1 | Performance Level, PL a to PL e | Edition 4, published 2023. EN version published 2024, with the 2015 edition transitioning out by 15 May 2027 | The common route for machinery. More prescriptive, workable without deep reliability mathematics |
| IEC 62061 | Safety Integrity Level, SIL | Edition 2.0 from 2021, plus Amendment 1 in 2024 and Amendment 2 in March 2026 | The machinery sector standard within the IEC 61508 framework. More at home where electronics and software dominate |
A project called IEC/ISO 17305 intended to merge the two into one standard. It was abandoned in 2015, reportedly because the differences between them were too great to reconcile in the available time, and both standards were revised separately instead. If someone tells you a unified machinery safety standard is coming, that is the history to know. Note that this account is widely reported by vendors rather than stated by ISO or IEC directly.
Deep dive: what actually determines a Performance Level
PL is not a component rating you can buy. It is a property of the whole safety function, from the sensing device through the logic to the final actuator, and it is determined by four things together:
- Category (B, 1, 2, 3, 4), the architecture: single channel, single channel with well tried components, single channel with test, dual channel, dual channel with high diagnostic coverage.
- MTTFD, the mean time to dangerous failure of each channel, rated low, medium or high.
- DCavg, the average diagnostic coverage: how much of the dangerous failure rate your diagnostics actually detect.
- CCF, the measures against common cause failure, because two identical channels that both fail from the same cause are not redundant at all.
Plus systematic failure and software requirements, which are qualitative and are where most real projects are weakest.
Each PL corresponds to a band of average probability of a dangerous failure per hour:
| PL | PFHD, per hour |
|---|---|
| a | ≥ 10-5 to < 10-4 |
| b | ≥ 3 × 10-6 to < 10-5 |
| c | ≥ 10-6 to < 3 × 10-6 |
| d | ≥ 10-7 to < 10-6 |
| e | ≥ 10-8 to < 10-7 |
These bands are the widely reproduced industry figures. ISO 13849-1 is paywalled and does not publish the table publicly, so they are cited here from safety vendor references rather than from the standard itself. Verify against your own copy before using them in a document that carries weight.
Two things follow that are worth saying out loud. First, the required PL for a given function comes from risk assessment under ISO 12100 or from a type C standard for that machine type, not from the designer's preference. Second, buying a PL e rated light curtain does not give you a PL e safety function: a PL e device wired into a category 1 architecture with no diagnostics is not PL e, and that mistake is extremely common.
Safety over a network: the black channel
Once safety devices sit on the same network as everything else, an obvious objection arises: how can you trust a safety signal carried by ordinary switches and ordinary cable that nobody certified?
The answer is the black channel principle. The safety data is wrapped in a self-protecting container carrying a CRC, a sequence counter, a watchdog timeout, and a unique connection identifier. Only the two safety endpoints create and check that container. Everything between them is treated as untrusted and uncertified: if the network corrupts, duplicates, delays, reorders, misroutes, or drops the message, one of those four checks fails and both endpoints go to the safe state. The network therefore needs no safety certification at all, and safety traffic shares one wire with standard traffic.
| Safety protocol | Rides on | Owner | Reaches |
|---|---|---|---|
| CIP Safety | EtherNet/IP and DeviceNet | ODVA | SIL 2 and SIL 3 per IEC 61508 |
| PROFIsafe | PROFINET and PROFIBUS | PI | SIL 3, PL e, Category 4, standardized as IEC 61784-3-3 |
| Safety over EtherCAT (FSoE) | EtherCAT | ETG | Up to SIL 3 |
| CC-Link IE Safety | CC-Link IE TSN, Controller Network, Field Network | CLPA | SIL 3 per IEC 61508 |
Note what this table implies for network selection: choosing a control network is also choosing a safety protocol. They are not independent decisions, and a site running two control networks is running two safety ecosystems with two sets of certified devices and two sets of validation tooling.
7. What the specification must say
Nearly every expensive controls problem traces back to the absence of an enforced standard, or to a specification that bought a machine and forgot to buy the ability to maintain it. These are the clauses that pay for themselves.
Software and intellectual property
- Source code delivered, not just a compiled download, for PLC, HMI, drives, and safety.
- No password protected or locked routines, stated explicitly.
- Comment language specified. A fully commented program in a language your team cannot read is an uncommented program.
- Named ownership of the safety program and who is authorized to modify it.
Evidence and documentation
- Schematics in a native editable format, not only PDF.
- IO list, network topology drawing, and device address list.
- The safety file: risk assessment, required PL per function, the calculation, and the validation record.
- Backup and restore procedure, proven at site acceptance, not asserted.
Acceptance that proves something
- Response time measured for named critical functions, sensor edge to output, not a claimed scan time.
- Every safety function individually exercised and recorded, including the ones nobody expects to use.
- A run at rate with real product, long enough to expose thermal and intermittent faults.
- Deliberate fault injection: pull a network cable, open a guard mid-cycle, drop a phase.
Life cycle
- Obsolescence statement for every major component, with declared support horizon.
- Spares list agreed at order time, not after the first failure.
- Firmware versions recorded, and a rule about who may update them and when.
- A defined position on remote access, because the vendor will ask for it and IT will refuse it.
Six questions worth asking your controls engineers
- What is the worst case response time of this interlock, including the network, and how did you measure it rather than estimate it?
- What happens to this machine if the network trunk is cut mid-cycle? Walk me through the actual state of every axis.
- Which safety function has the highest required PL, and show me the calculation that says we meet it.
- If this controller fails on a Saturday, what exactly does the technician do, and how long does it take?
- What did we standardize away from on this machine, and what did we gain for it?
- Who besides you can modify this program, and how do we know the file on the shelf is the file in the PLC?
For machines placed on the European market, Regulation (EU) 2023/1230, the Machinery Regulation, applies from 20 January 2027 and replaces the Machinery Directive. Anyone specifying or importing machinery on a timeline that crosses that date should already know how their suppliers are handling it.
Sources, and three caveats
Every figure above comes from a named source. Three deserve an explicit warning before you reuse them:
- The ISO 13849-1 PFHD bands are reproduced from safety vendor references, not from the standard itself, which is paywalled.
- The EtherCAT performance figures are the ETG's own published examples under favorable conditions, not guarantees, and the source presentation carries no clear publication date.
- The VFD control mode figures are Yaskawa's published values for their own drives. Competing drives publish different numbers.
- ODVA: EtherNet/IP, CIP Safety, CIP Motion
- PI: PROFINET FAQ, RT versus IRT, PROFIsafe, PROFIdrive
- CLPA: network specifications, CC-Link IE TSN
- ETG: technology, EtherCAT introduction, Safety over EtherCAT
- IO-Link Community and IEC 61131-9:2022
- Modbus Organization FAQ and specifications
- ISO 13849-1:2023, IEC 62061:2021, IEC 62061 Amendment 2:2026, IEC 61131-3:2025
- Pilz: function of a safety relay, emergency stop
- Kollmorgen, stop and emergency stop, Schneider Electric, stop categories
- AutomationDirect, the PLC scan; Siemens S7-1500 technical data for instruction execution times
- RS, PNP versus NPN, Lesman, NAMUR NE 43, IEWC, panel wiring color codes
- ADVANCED Motion Controls, servo versus VFD, Oriental Motor, servo versus stepper
- Omron, electronic gear, Motion Control Tips, electronic camming, Sercos, IEC 81346-2 class letters
Correct anything here against your own copy of the relevant standard before it carries weight in a specification.
Comments