Product overview
1.4 S7-1200 Fail-Safe signal modules (SM)
S7-1200 Functional Safety Manual
Manual, 02/2015, A5E03470344-AA
19
S7-1200 Fail-Safe signal modules (SM)
1.4.1
Siemens intends for the S7-1200 fail-safe products to be used to help solve functional safety
in machine applications.
There are three fail-safe SMs in conjunction with the S7-1200 V4.1 or later release:
● SM 1226 F-DI 16 x 24 VDC
● SM 1226 F-DQ 4 x 24 VDC
● SM 1226 F-DQ 2 x Relay
Redundant two-processor functional safety design
The major difference between S7-1200 fail-safe and standard SMs is that failsafe SMs use
redundancy to achieve functional safety, including two processors that control fail-safe
operation. Both processors monitor each other and verify that they are executing the same
code at the same time, automatically test the I/O circuits, and set the fail-safe SMs to safe
state in the event of a fault. Each processor monitors internal and external power supplies
and module internal temperature and can passivate the module if an abnormal condition is
detected.
Safety-related input and output signals form the interface to the process. This enables direct
connection of single-channel and two-channel input signals from devices such as emergency
STOP buttons or light barriers. The fail-safe SM redundantly combines the safety-related
signals internally and passes the unified result on to the CPU in a fail-safe manner for further
processing.
The fail-safe CPU sends the safety-related outputs from the CPU to the fail-safe SM for each
individual output channel. Each output then sets two independent switches for each channel,
a P and M solid-state switch, or two independent relays.