Testing a PLC program so that it fails safe
Normally closed wiring, fault injection, the test log, forcing and its dangers, what happens at STOP and at power-up, the cross reference, and a commissioning procedure. The method every TP is assessed on.
30 min
On this page
A program that works when everything is healthy has only just begun its tests. Break a wire, open a door, stall a motor, and watch what it does. (Lab Works booklet)
Design for the failures you will have
- Stops and safety devices normally closed, tested with a normally open contact: a broken wire or a lost supply stops the machine.
- Proof, not assumption: a movement ends on a position switch and a time-out; a motor is running when its speed sensor says so, not when its contactor is commanded.
- No restart by itself: after a stop, a fault or a power return, a new command is needed.
- Latched faults: a trip stays until RESET, and RESET does nothing while the cause is still present.
- One safe state per output, written in your specification: is the brake applied, the valve closed, the motor stopped when the program stops?
Fault injection
Each TP has a fault-injection table: the test, the safe reaction required, what you observed. On the bench you pull a patch lead or switch an NC input OFF while the machine runs. On this site you do the same with the panel.
Try it on the start/stop station: start the motor, then switch F2_NC (the overload) OFF, then ON again. Then open the Timing diagram and do the same with STOP_NC.
Drag an instruction onto the rung (or click it, then click a place). Drop below a contact to put it in parallel. Click an element to edit its address; Delete removes it.
No errors: the program compiles.
| Test | Safe reaction required | Observed |
|---|---|---|
| Overload opens while running | RUN OFF at once, no restart when it closes | |
| STOP wire broken (I0.1 OFF) while running | RUN OFF | |
| START held when the overload recloses | RUN only restarts on a new START? |
The last line is a question worth asking: with the simple self-holding circuit, a START held while the overload recloses restarts the motor. Is that acceptable for your machine? If not, start on the rising edge of START.
STOP, power-up and forcing
- In STOP, the S7-200 sets the outputs to the state chosen in the System Block (by default OFF). Check that OFF is safe for every output.
- At power-up or STOP → RUN,
SM0.1is 1 for one scan: initialise your steps and flags there. Retentive memory (configured in the System Block) keeps its value; a GRAFCET step kept after a power cut can restart a machine by itself. - Forcing overrides the program and the switches. Never leave a force in place: the status chart shows forced values with a lock, and Debug → Unforce All removes them.
Commissioning, in order
- Wiring and I/O check, program in STOP: operate every input, see its LED and status chart value; force each output alone and see the actuator move. Sign each line.
- Functional tests, in RUN: the normal cycle, each mode, each step of the GRAFCET.
- Fault injection: every line of the table, at the worst moment (during a movement, at a transition).
- Documentation: the commented listing, the symbol table, the test log with the instructor's signatures.
Where to go next
The TP pages (Labs → PLC-200 labs) give the bench set-up, the I/O tables and the fault-injection tables of each TP. Write your GRAFCET in the player, your networks in the ladder editor or in Micro/WIN, test them here, then demonstrate them on the bench.