The information provided in this documentation contains general descriptions and/or technical characteristics of the performance of the products contained herein. This documentation is not intended as a
substitute for and is not to be used for determining suitability or reliability of these products for specific user
applications. It is the duty of any such user or integrator to perform the appropriate and complete risk
analysis, evaluation and testing of the products with respect to the relevant specific application or use
thereof. Neither Schneider Electric nor any of its affiliates or subsidiaries shall be responsible or liable for
misuse of the information contained herein. If you have any suggestions for improvements or amendments
or have found errors in this publication, please notify us.
You agree not to reproduce, other than for your own personal, noncommercial use, all or part of this
document on any medium whatsoever without permission of Schneider Electric, given in writing. You also
agree not to establish any hypertext links to this document or its content. Schneider Electric does not grant
any right or license for the personal and noncommercial use of the document or its content, except for a
non-exclusive license to consult it on an "as is" basis, at your own risk. All other rights are reserved.
All pertinent state, regional, and local safety regulations must be observed when installing and using this
product. For reasons of safety and to help ensure compliance with documented system data, only the
manufacturer should perform repairs to components.
When devices are used for applications with technical safety requirements, the relevant instructions must
be followed.
Failure to use Schneider Electric software or approved software with our hardware products may result in
injury, harm, or improper operating results.
Failure to observe this information can result in injury or equipment damage.
Read these instructions carefully, and look at the equipment to become familiar with the device before
trying to install, operate, service, or maintain it. The following special messages may appear throughout
this documentation or on the equipment to warn of potential hazards or to call attention to information that
clarifies or simplifies a procedure.
PLEASE NOTE
Electrical equipment should be installed, operated, serviced, and maintained only by qualified personnel.
No responsibility is assumed by Schneider Electric for any consequences arising out of the use of this
material.
A qualified person is one who has skills and knowledge related to the construction and operation of
electrical equipment and its installation, and has received safety training to recognize and avoid the
hazards involved.
QUALIFICATION OF PERSONNEL
Only appropriately trained persons who are familiar with and understand the contents of this manual and
all other pertinent product documentation as well as all documentation of all components and equipment
of the machine/process are authorized to work on and with this product.
The qualified person must be a certified expert in safety engineering.
The qualified person must be able to detect possible hazards that may arise from parameterization,
modifying configurations, settings, and wiring, and generally from mechanical, electrical, or electronic
equipment. The qualified person must be able to understand the effects that modifications to
configurations, settings, and wiring may have on the safety of the machine/process.
EIO0000003487 11/20205
INTENDED USE
The qualified person must be familiar with and understand the contents of the risk assessment as per ISO
12100-1 and/or any other equivalent assessment as well as all documents related to such risk assessment
or equivalent assessments for the machine/process.
The qualified person must be familiar with the standards, provisions, and regulations for the prevention of
industrial accidents, which they must observe when designing, implementing, and maintaining the
machine/process.
The qualified person must be thoroughly familiar with the safety-related applications and the non-safetyrelated applications used to operate the machine/process.
This product described in the present document is a safety module intended to perform safety-related
functions in a machine/process according to the present document, to the specified related documents,
and to all other documentation of the components and equipment of the machine/process.
The product may only be used in compliance with all applicable safety regulations and directives, the
specified requirements and the technical data.
Prior to using the product, you must perform a risk assessment as per ISO 12100-1 in view of the planned
application. Based on the results of the risk assessment, the appropriate safety-related measures must be
implemented.
Since the product is used as a component in an overall machine or process, you must ensure the safety
of persons by means of the design of this overall machine or process.
Operate the product only with the specified cables and accessories. Use only genuine accessories.
Any use other than the use explicitly permitted is prohibited and can result in hazards.
6EIO0000003487 11/2020
At a Glance
Document Scope
Validity Note
Related Documents
About the Book
This manual describes technical characteristics, installation, commissioning, operation and maintenance
of the safety module XPSUS.
The present document is valid for the products listed in the type code
(see page 15)
For product compliance and environmental information (RoHS, REACH, PEP, EOLI, etc.), go to
www.schneider-electric.com/green-premium
.
The technical characteristics of the devices described in the present document also appear online. To
access the information online, go to the Schneider Electric home page
https://www.se.com/ww/en/download/
.
The characteristics that are described in the present document should be the same as those characteristics that appear online. In line with our policy of constant improvement, we may revise content over time
to improve clarity and accuracy. If you see a difference between the document and online information, use
the online information as your reference.
You can download these technical publications and other technical information from our website at
www.schneider-electric.com/en/download
.
EIO0000003487 11/20207
Product Related Information
HAZARD OF ELECTRIC SHOCK, EXPLOSION OR ARC FLASH
Disconnect all power from all equipment including connected devices prior to removing any covers or
doors, or installing or removing any accessories, hardware, cables, or wires except under the specific
conditions specified in the appropriate hardware guide for this equipment.
Always use a properly rated voltage sensing device to confirm the power is off where and when
indicated.
Where 24 Vdc or Vac is indicated, use PELV power supplies conforming to IEC 60204-1.
Replace and secure all covers, accessories, hardware, cables, and wires and confirm that a proper
ground connection exists before applying power to this equipment.
Use only the specified voltage when operating this equipment and any associated products.
Failure to follow these instructions will result in death or serious injury.
This equipment has been designed to operate outside of any hazardous location. Only install this
equipment in zones known to be free of a hazardous atmosphere.
POTENTIAL FOR EXPLOSION
Install and use this equipment in non-hazardous locations only.
Failure to follow these instructions will result in death or serious injury.
DANGER
DANGER
WARNING
LOSS OF CONTROL
The designer of any control scheme must consider the potential failure modes of control paths and,
for certain critical control functions, provide a means to achieve a safe state during and after a path
failure. Examples of critical control functions are emergency stop and overtravel stop, power outage
and restart.
Separate or redundant control paths must be provided for critical control functions.
System control paths may include communication links. Consideration must be given to the
implications of unanticipated transmission delays or failures of the link.
Observe all accident prevention regulations and local safety guidelines.
Each implementation of this equipment must be individually and thoroughly tested for proper operation
before being placed into service.
Failure to follow these instructions can result in death, serious injury, or equipment damage.
1
For additional information, refer to NEMA ICS 1.1 (latest edition), "Safety Guidelines for the Application,
Installation, and Maintenance of Solid State Control" and to NEMA ICS 7.1 (latest edition), "Safety
Standards for Construction and Guide for Selection, Installation and Operation of Adjustable-Speed Drive
Systems" or their equivalent governing your particular location.
Verify that a risk assessment as per ISO 12100 and/or other equivalent assessment has been
performed before this product is used.
Before performing any type of work on or with this product, fully read and understand all pertinent
manuals.
Verify that modifications do not compromise or reduce the Safety Integrity Level (SIL), Performance
Level (PL) and/or any other safety-related requirements and capabilities defined for your
machine/process.
After modifications of any type whatsoever, restart the machine/process and verify the correct
operation and effectiveness of all functions by performing comprehensive tests for all operating states,
the defined safe state, and all potential error situations.
Failure to follow these instructions can result in death, serious injury, or equipment damage.
Terminology Derived from Standards
The technical terms, terminology, symbols and the corresponding descriptions in this manual, or that
appear in or on the products themselves, are generally derived from the terms or definitions of international
standards.
In the area of functional safety systems, drives and general automation, this may include, but is not limited
to, terms such as
,
message
dangerous
Among others, these standards include:
StandardDescription
IEC 61131-2:2007Programmable controllers, part 2: Equipment requirements and tests.
ISO 13849-1:2015Safety of machinery: Safety related parts of control systems.
EN 61496-1:2013Safety of machinery: Electro-sensitive protective equipment.
ISO 12100:2010Safety of machinery - General principles for design - Risk assessment and risk
EN 60204-1:2006Safety of machinery - Electrical equipment of machines - Part 1: General
ISO 14119:2013Safety of machinery - Interlocking devices associated with guards - Principles
ISO 13850:2015Safety of machinery - Emergency stop - Principles for design
IEC 62061:2015Safety of machinery - Functional safety of safety-related electrical, electronic,
IEC 61508-1:2010Functional safety of electrical/electronic/programmable electronic safety-
IEC 61508-2:2010Functional safety of electrical/electronic/programmable electronic safety-
IEC 61508-3:2010Functional safety of electrical/electronic/programmable electronic safety-
IEC 61784-3:2016Industrial communication networks - Profiles - Part 3: Functional safety
related systems: Requirements for electrical/electronic/programmable
electronic safety-related systems.
related systems: Software requirements.
fieldbuses - General rules and profile definitions.
In addition, terms used in the present document may tangentially be used as they are derived from other
standards such as:
StandardDescription
IEC 60034 seriesRotating electrical machines
IEC 61800 seriesAdjustable speed electrical power drive systems
EIO0000003487 11/20209
StandardDescription
IEC 61158 seriesDigital data communications for measurement and control – Fieldbus for use in
industrial control systems
Finally, the term
zone of operation
is defined as it is for a
ISO 12100:2010
.
hazard zone
may be used in conjunction with the description of specific hazards, and
or
danger zone
in the
Machinery Directive (2006/42/EC
) and
10EIO0000003487 11/2020
XPSUS
Introduction
EIO0000003487 11/2020
Introduc tion
Chapter 1
Introduction
What Is in This Chapter?
This chapter contains the following topics:
Device Overview12
Front View and Side View13
Nameplate14
Type Code15
TopicPage
EIO0000003487 11/202011
Introduction
Device Overview
Outline
The device is a safety module for interruption of safety-related electrical circuits.
The device provides application functions used to monitor signals from different types of sensors/devices.
Equipment with the following types of outputs can be connected to the safety-related inputs of the device:
NO, NC, C/O, for example, Emergency Stop push-buttons, guard door switches, coded magnetic
switches, enabling switches, two-hand control devices
PNP transistors, for example, magnetic switches, proximity switches
OSSD, for example, light curtains
The device is available in four different types: either spring terminals or screw terminals and either
24 Vac/Vdc supply voltage or 48 … 240 Vac/Vdc supply voltage.
Feature summary:
10 application functions
Configurable start function
2 safety-related inputs
2 safety-related relay outputs
1 non-safety-related status/diagnostics output
1 non-safety-related start input with 8 selectable start functions
Connector for connection of extension module XPSUEP to increase the number of safety-related
outputs by 6
12
EIO0000003487 11/2020
Front View and Side View
Front View and Side View
Introduction
1 Removable terminal blocks, top
2 Removable terminal blocks, bottom
3 LED indicators
4 Start function selector
5 Application function selector
6 Connector for optional output extension module XPSUEP (lateral)
7 Sealable transparent cover
EIO0000003487 11/202013
Introduction
Nameplate
Nameplate
The nameplate contains the following data:
1 Device type (refer to chapter Type Code
(seepage15)
)
2 Nominal voltage
3 Frequency range Vac supply
4 Input power
5 Maximum current of safety-related outputs with utilization category AC15 (250 Vac)
6 Maximum current of safety-related outputs with utilization category DC13 (24 Vdc)
7 Maximum total thermal current
8 Maximum Safety Integrity Level (SIL) as per IEC 61508-1:2010
9 Maximum Performance Level and Category as per ISO 13849-1:2015
10 Maximum response time to request at safety-related input
11 Permissible ambient temperature range during operation
12 IP degree of protection
13 Serial number
14 Product version (PV), release (RL), software version (SV)
15 Plant code and date of manufacture (example: PP-2019-W10 means plant code PP, year of
manufacture 2019, week of manufacture 10)
14
EIO0000003487 11/2020
Type Code
Type Code
Introduction
Item123456789
Type code (example)XPSUS12AC
ItemMeaning
1 ... 4Product range
XPSU = Universal
5Product version
S
6Supply voltage
1 = 24 Vac/Vdc
3 = 48 … 240 Vac/Vdc
7 ... 8Number of safety-related outputs
2A = 2 normally open relay contacts
9Terminal type
C = Spring terminals, removable
P = Screw terminals, removable
If you have questions concerning the type code, contact your Schneider Electric service representative.
EIO0000003487 11/202015
Introduction
16
EIO0000003487 11/2020
XPSUS
Technical Data
EIO0000003487 11/2020
Technical Data
Chapter 2
Technical Data
What Is in This Chapter?
This chapter contains the following topics:
Environmental Conditions18
Mechanical Characteristics20
Electrical Characteristics21
Timing Data23
Data Functional Safety24
TopicPage
EIO0000003487 11/202017
Technical Data
Environmental Conditions
Environmental Conditions For Storage
The device complies with class 1K5 as per IEC 60721-3-1:1997 (climatic conditions):
CharacteristicValue
Ambient temperature-40 ... 70 °C (-40 ... 158 °F)
Rate of change of temperature1 °C/min (1.8 °F/min)
Ambient humidity10 ... 100 % relative humidity
The device complies with class 1M2 as per IEC 60721-3-1:1997 (mechanical conditions):
Electrical durability of the safety-related output relay contacts as per IEC 60947-5-1
1 Operating cycles
2 Rated current in A
EIO0000003487 11/2020
Electrical durability of the safety-related output relay contacts as per IEC 60947-5-1
1 Operating cycles
2 Rated current in A
Technical Data
Refer to chapter Timing Data
safety calculations.
(see page 23)
for additional technical data that may affect your functional
EIO0000003487 11/202025
Technical Data
26
EIO0000003487 11/2020
XPSUS
Engineering
EIO0000003487 11/2020
Engineering
Chapter 3
Engineering
What Is in This Chapter?
This chapter contains the following topics:
Electromagnetic Compatibility (EMC)28
Basic Principles of Operation29
Safety-Related Inputs32
Synchronization of Safety-Related Inputs34
Dynamization35
Signal Interlock Monitoring36
TopicPage
EIO0000003487 11/202027
Engineering
Electromagnetic Compatibility (EMC)
Conducted and Radiated Electromagnetic Emissions
Equipment of class A as per IEC CISPR 11 is not intended for use in residential environments and may not
provide adequate protection to radio reception in such environments.
INSUFFICIENT ELECTROMAGNETIC COMPATIBILITY
Verify compliance with all EMC regulations and requirements applicable in the country in which the
device is to be operated and with all EMC regulations and requirements applicable at the installation
site.
Do not install and operate devices of class A as per IEC CISPR 11 in residential environments.
Implement all required radio interference suppression measures and verify their effectiveness.
Failure to follow these instructions can result in death, serious injury, or equipment damage.
According to IEC CISPR 11, device type XPSUS1••• is a group 1, class B device. Class B as per
IEC CISPR 11 corresponds to environment B as per IEC 60947-1.
According to IEC CISPR 11, device type XPSUS3••• is a group 1, class A device. Class A as per
IEC CISPR 11 corresponds to environment A as per IEC 60947-1.
WARNING
28
EIO0000003487 11/2020
Basic Principles of Operation
Introduction
The following sections provide basic information on the principles of operation of the device to assist you
in engineering your application function.
Operating States
The following graphic illustrates the operating states and state transitions of the device:
Engineering
State Transitions
Operating stateDescriptionIn defined
safe state
Off / ConfigurationConfiguration only possible in this operating stateYes
InitializationSelf-testsYes
Run: Outputs DeenergizedRegular operation with safety-related function activeYes
Run: Outputs EnergizedRegular operation with safety-related function not activeNo
ErrorError detectedYes
NOTE: See the chapter Data Functional Safety
State transitionCondition
T1
T2
T3
T4
T5
Power on
Initialization successful
Switch on delay has passed
Start condition fulfilled (for example, automatic start or manual start with start
button pressed)
Safety-related inputs activated
For application functions with signal interlock monitoring: no signal interlock
condition
For application functions with synchronization: synchronization time
requirements met
Safety-related inputs deactivated (corresponds to triggering of the safety-
related function)
Error detected on
(see page 24)
for the defined safe state of the device.
EIO0000003487 11/202029
Engineering
State transitionCondition
T6 Power off
NOTE: Refer to the Activation and Deactivation
and “deactivated” in the present document.
Example with Emergency Stop
The following example uses a machine with an Emergency Stop pushbutton, a start pushbutton for manual
start, and a motor to demonstrate the individual operating states and state transitions. The selected
application function is Monitoring of Emergency Stop Circuits. The selected start function is Manual Start.
The example assumes that the equipment is properly wired and configured.
After the device is powered on, it enters the operating state Initialization (T1).
If the initialization is successful, the device enters the operating state Run: Outputs Deenergized (T2).
If an error is detected, the device transitions to the operating state Error (T5).
On entering the operating state Run: Outputs Deenergized, the device verifies the state of the safety-
related inputs and of the start input. The motor is at a standstill.
If the start pushbutton is not pressed, the start input stays deactivated and the device remains in the
operating state Run: Outputs Deenergized. The motor is at a standstill.
Detailed information on the start functions and the timing can be found in the chapter Start Functions
(see page 56)
If the start pushbutton is pressed, the start input is activated, i.e. the start condition is fulfilled.
The state of the safety-related inputs determines whether the device transitions to the operating state
Run: Outputs Energized.
If the safety-related inputs are not activated (actuator of Emergency Stop pushbutton pushed down), the
device remains in the operating state Run: Outputs Deenergized. The motor remains at a standstill.
If the safety-related inputs are activated (actuator of Emergency Stop pushbutton pulled out), the device
transitions to the operating state Run: Outputs Energized (T3). The motor runs. This operating
corresponds to regular operation of the machine.
If an application function with synchronization
transition only occurs if the safety-related inputs are activated within the synchronization time.
In the operating state Run: Outputs Energized, the device monitors the state of the safety-related inputs.
If the actuator of the Emergency Stop pushbutton is pushed down (safety-related inputs deactivated),
the safety-related outputs are deactivated within the response time (transition T4 to operating state Run:
Outputs Deenergized). The device is again in the defined safe state. The motor is stopped.
This corresponds to the Emergency Stop condition of the machine.
To return to the operating state Run: Outputs Energized (T3), the start input and the safety-related
inputs need to be activated again (start button pressed and actuator of the Emergency Stop pushbutton
pulled out).
If an application function with signal interlock monitoring
occurs if there is no signal interlock condition.
If an application function with synchronization
transition only occurs if the safety-related inputs are activated within the synchronization time.
(see page 32)
for details on the use of the terms “activated”
.
(see page 34)
(see page 34)
of the safety-related inputs is used, this
(see page 36)
is used, this transition only
of the safety-related inputs is used, this
Timing Diagram for Example with Emergency Stop
The following timing diagram provides an overview of the example with Emergency Stop.
30
EIO0000003487 11/2020
Legend
ItemDescription
1
2
3
4
5
6
The first safety-related input (A) is activated (actuator of Emergency Stop button pulled out).
The device remains in the defined safe state.
The second safety-related input (B) is activated (second output contact of Emergency Stop
button).
If an application function with synchronization
output (A) is only activated if the second safety-related input (B) is activated within the
synchronization time.
The start button has not yet been pressed so the start condition is not yet fulfilled and the
device remains in the defined safe state.
The start button is pressed.
The start condition is fulfilled. See the chapter Start Functions
information on the start functions.
The safety-related output is activated within the activation delay time
If an application function with synchronization
the safety-related output is only activated if the two channels of the safety-related input have
been activated within the synchronization time.
The motor runs. The device is not in the defined safe state.
The start button is released.
The safety-related input B is deactivated (actuator of Emergency Stop button pushed).
The safety-related output is deactivated within the response time
The Emergency Stop is triggered. The device is in the defined safe state.
The safety-related input A is deactivated (by second output contact of Emergency Stop
button).
If an application function with signal interlock monitoring
related inputs must be deactivated within the signal interlock monitoring time (between (5)
and (6)).
Only connect a sensor/device to a safety-related input that meets all requirements as per your risk
assessment and that complies with all regulations, standards, and process definitions applicable to your
machine/process.
Failure to follow these instructions can result in death, serious injury, or equipment damage.
The following sections provide basic information on the safety-related inputs such as principle of activation
and deactivation as well as antivalent behavior. Refer to the chapters Electrical Characteristics
(see page 21)
General Information on Activation and Deactivation of Safety-Related Inputs
In the present document, “activation” of a safety-related input means that a safety-related input changes
its state so that the device can enter the operating state Run: Outputs Energized.
The term “deactivation” of a safety-related input means that a safety-related input changes its state so that
the device enters the operating state Run: Outputs Deenergized.
See Operating States
and Electrical Installation
(see page 29)
(see page 41)
for details on the state machine of the device.
for more details on the safety-related inputs.
Activation and Deactivation with Antivalent Behavior Between Two Input Channels of One Safety-Related Input
Depending on the selected application function, the input channels of the safety-related input are
configured for antivalent behavior. Antivalent is defined here as a normally open and a normally closed
contacts working in synchronization.
For example, for application function 5
normally open contact, whereas the signal for input channel S13 is provided by a normally closed contact.
One safety-related input with two input channels with antivalent behavior (magnetic switch with NO at S12
and NC at S13):
If the level at terminal S12 is logically 0 and the level at terminal S13 is logically 1, the safety-related input
is activated.
Timing diagram for one safety-related input with two input channels with antivalent behavior:
(see page 49)
, the signal for input channel S12 is provided by a
32
1 = Activation, transition to operating state Run: Outputs Energized
2 = Deactivation, transition to operating state Run: Outputs Deenergized (defined safe state)
EIO0000003487 11/2020
Truth table for one safety-related input with two input channels with antivalent behavior:
Engineering
Signal state at
S•2
01Safety-related input channel activated, operating state Run: Outputs
10Safety-related input channel deactivated, operating state Run: Outputs
Identical signal states are only permissible within the synchronization time
Signal state at
S•3
Activation State and Operating State
Energized
Deenergized
(see page 29)
(see page 34)
. Otherwise,
identical signal states trigger an alert.
The truth table applies to the wiring diagrams presented for the application functions.
If the magnetic switch in the wiring example above is used for guard monitoring, this means that the
magnetic switch is presented in the activated state and the guard is closed.
Consult the manual of the sensor/device you want to use for your application function for details on signal
state required for activation and deactivation as defined in the present document.
EIO0000003487 11/202033
Engineering
Synchronization of Safety-Related Inputs
Overview
The device can monitor synchronized behavior of the input channels of the safety-related inputs using
various synchronization mechanisms with different synchronization times. If the synchronized input
channels of the safety-related inputs are not activated within the synchronization time, the safety-related
output or outputs are not activated.
The synchronized terminals and the synchronized pairs of terminals of the safety-related inputs and the
corresponding synchronization times are listed for each individual application function
synchronization, including information on the sequences in which the synchronized input channels are
activated, if applicable.
Refer to the chapter Safety-Related Inputs
“activation” in the present document.
(see page 32)
(seepage44)
us ing
for additional information on the use of the term
34
EIO0000003487 11/2020
Dynamization
Dynamization of Inputs
Dynamization is used for cross circuit detection between two safety-related inputs or between one safetyrelated input and the Start input or a cross-circuit to an external power supply unit or to ground.
Dynamization is implemented by means of periodically generated test pulses at the control outputs of the
safety-related inputs S•1 and of the start input Y1.
Whether dynamization of the safety-related inputs is used depends on the selected application function
(see page 43)
The following diagram illustrates the dynamization principle and timing:
Engineering
.
The diagram presents the input channels S11-S12 and S21-S22. The remaining input channels S13 and
S23 use the same logic as the input channels illustrated.
The same logic applies to Y1 and Y2.
DesignationValueExplanation
T
DDUR
T
DINT
T
DDEL
T
DPSHL
2 msDuration of the test pulse. The duration of the test pulse is the
time between the start of the test pulse and the end of the test
pulse.
500 msInterval between test pulses. This interval is the time between the
start of a test pulse and the start of the next test pulse at the same
control output.
40 msMaximum delay of test pulse. This delay is the maximum time
between the start of the test pulse at the control output and the
associated input channel, that is, the maximum time during which
the input expects to “see” dynamization.
At least 70 msPhase shift of test pulses. This time is the phase shift between
the test pulses at the control outputs of the safety-related inputs.
EIO0000003487 11/202035
Engineering
Signal Interlock Monitoring
Overview
Signal interlock is a monitoring function used to detect conditions in which one of the sensors/devices
cannot provide the expected input signal for the device, for example, as a result of contact welding.
The device expects “simultaneous” deactivation of the two safety-related inputs within the signal interlock
monitoring time of 200 ms.
If the two monitored safety-related inputs are not deactivated within 200 ms, this is a signal interlock
condition and the device triggers a signal interlock alert. The device remains in the defined safe state, i.e.,
there is no transition from operating state Run: Outputs Deenergized to operating state Run: Outputs
Energized (T3).
To exit the signal interlock condition, the two affected safety-related inputs must be deactivated for at least
one second. After that, the safety-related inputs can be activated again which activates the safety-related
outputs as well.
Signal interlock is available for certain of the application functions
Examples
The following figure illustrates a condition without signal interlock:
(seepage44)
the device provides.
Both safety-related inputs are deactivated within the signal interlock monitoring time of 200 ms. When they
are activated again, the safety-related outputs are also activated.
The following figure illustrates a condition with signal interlock:
The first safety-related input is deactivated which starts the signal interlock monitoring time of 200 ms. It is
then activated again before the second safety-related input is deactivated. This immediately triggers a
signal interlock alert even though the 200 ms have not yet elapsed.
The following figure illustrates a condition with signal interlock:
36
The first safety-related input is deactivated which starts the signal interlock monitoring time of 200 ms. The
second safety-related remains activated longer than 200 ms. This triggers a signal interlock alert 200 ms
after interlock monitoring has started.
EIO0000003487 11/2020
XPSUS
Installation
EIO0000003487 11/2020
Installat ion
Chapter 4
Installation
What Is in This Chapter?
This chapter contains the following topics:
Prerequisites and Requirements38
Mechanical Installation39
Electrical Installation40
TopicPage
EIO0000003487 11/202037
Installation
Prerequisites and Requirements
Inspecting the Device
Damaged products may cause electric shock or unintended equipment operation.
ELECTRIC SHOCK OR UNINTENDED EQUIPMENT OPERATION
Do not use damaged products.
Keep foreign objects (such as chips, screws or wire clippings) from getting into the product.
Failure to follow these instructions will result in death or serious injury.
DANGER
Verify the product type by means of the type code
Control Cabinet/Enclosure
Install the device in a control cabinet or enclosure with degree of protection IP54 that is secured by a keyed
or tooled locking mechanism.
The ventilation of the control cabinet/enclosure must be sufficient to comply with the specified ambient
conditions for the device and the other components operated in the control cabinet/enclosure.
Label on Extension Module Connector
The connector for connection of the extension module XPSUEP is covered by a label. Do not remove the
label from the connector unless you want to connect the extension module XPSUEP.
INOPERABLE EQUIPMENT
Do not remove the protective label from the extension connector unless you are immediately attaching
an extension module.
Failure to follow these instructions can result in equipment damage.
(see page 15)
NOTICE
and the data printed on the device.
38
EIO0000003487 11/2020
Mechanical Installation
Mounting to DIN Rail
The device can be mounted to the following DIN rails as per IEC 60715:
35 x 15 mm (1.38 x 0.59 in)
35 x 7.5 mm (1.38 x 0.29 in)
Mounting procedure (left illustration)
StepAction
1Slightly tilt the device and hook it onto the DIN rail.
2Push the lower part of the device towards the DIN rail.
3Snap in the DIN rail clip.
Installation
Screw-Mounting
Dismounting procedure (center illustration)
StepAction
1Unlock the DIN rail clip using a screwdriver.
2Pull the lower part of the device away from the DIN rail and lift the device towards the top to
remove it from the DIN rail.
Mounting procedure:
StepAction
1Push the additional fastener into the grooves at the device.
2Prepare the holes.
3Screw the device to the mounting surface using the specified screws and a washer M4 as per
ISO 7093 for each screw.
EIO0000003487 11/202039
Installation
Electrical Installation
General Information
FIRE, ELECTRIC SHOCK OR ARC FLASH
Disconnect all power from all equipment of your machine/process prior to electrical installation of the
Confirm the absence of power using a properly rated voltage sensing device.
Place a "Do Not Turn On" or equivalent hazard label on all power switches and lock them in the non-
Failure to follow these instructions will result in death or serious injury.
Wiring of the device depends on the safety-related function to be implemented. Before wiring the device,
engineer the safety-related function, perform a risk assessment with regard to your machine/process, and
determine the suitability of the device as well as the connected equipment.
Refer to the Schneider Electric Safety Chain Solutions at
examples of wiring the device, including the safety-related outputs with feedback and the start input with
external start condition.
You can wire the device with the terminal blocks in the device or you can remove the terminal blocks. For
the latter, pull the terminal blocks out of the device, connect the individual terminals and push the terminal
blocks back into the device.
Use 75 °C (167 °F) copper conductors to wire the device.
device.
energized position.
DANGER
https://www.se.com
for application-specific
Wire Cross Sections, Stripping Lengths, and Tightening Torques
CharacteristicValue
Stripping length for spring terminals12 mm (0.47 in)
Stripping length for screw terminals7 ... 8 mm (0.28 ... 0.31 in)
Wire cross section, single wire without wire ferrule
Wire cross section, single wire with wire ferrule
Wire cross section, two wires without wire ferrule
Wire cross section, two wires with uninsulated wire
ferrule
Wire cross section, two wires with insulated wire
ferrule
Tightening torque for screw terminals0.5 ... 0.6 N m (4.4 ... 5.3 lb in)
(1) Stranded or solid
Block Diagram and Terminals
The following drawings present the block diagram and the terminals with their designations in the
removable terminal blocks.
(1)
0.2 ... 2.5 mm2 (AWG 24 ... 12)
0.25 ... 2.5 mm2 (AWG 24 ... 12)
(1)
0.2 ... 1.5 mm2 (AWG 24 ... 16)
0.25 ... 1 mm
0.5 ... 1.5 mm
2
(AWG 24 ... 18)
2
(AWG 20 ... 16)
40
EIO0000003487 11/2020
Terminal DesignationExplanation
A1, A2Power supply
Y1Control output (DC+) of start input
Y2Input channel (CH+) of start input
S11, S21Control outputs (DC+) of safety-related inputs
S12, S13, S22, S23Input channels (CH+) of safety-related inputs
B2Terminal for common reference potential for 24 Vdc
13, 14, 23, 24Terminals of the safety-related outputs
Z1Pulsed output for diagnostics
EXTConnector for output extension module XPSUEP
signals. The power supplies of the connected
equipment must have a common reference potential
to be connected to this terminal.
Only connect a sensor/device to a safety-related input that meets all requirements as per your risk
assessment and that complies with all regulations, standards, and process definitions applicable to your
machine/process.
Failure to follow these instructions can result in death, serious injury, or equipment damage.
The device provides two safety-related inputs. Each safety-related input consists of one control output DC+
(terminals S11, S21) and two input channels CH+ (terminals S12–S13, S22–S23).
Each control output DC+ provides a nominal voltage of 24 Vdc to the connected sensor/device. It is also
used for dynamization
Respect the maximum wire resistance of 500 Ω when determining the cable length. The maximum wire
length between a safety-related input and a sensor/device is 30 m (98.43 ft) if the supply via the control
outputs (terminals S•1) of the safety-related inputs are not used.
Wire the terminals of the safety-related inputs according to the wiring diagram for the application function
(see page 44)
Safety-Related Outputs
The wiring of the safety-related outputs depends on the safety-related function to be implemented.
Install fuses with the rating specified in the chapter Electrical Characteristics
(see page 35)
to be implemented.
WARNING
.
(see page 22)
.
EIO0000003487 11/202041
Installation
Start Input
WARNING
UNINTENDED EQUIPMENT OPERATION
Do not use the Start function for safety-related purposes.
Use Monitored Start or Startup Test if unintended restart is a hazard according to your risk
assessment.
Failure to follow these instructions can result in death, serious injury, or equipment damage.
The start input consists of one control output DC+ (terminal Y1) and one input channel CH+ (terminal Y2).
The control output provides a nominal voltage of 24 Vdc to the connected sensor/device. It is also used for
dynamization
The wiring of the start input depends on the start function
For automatic start, bridge terminals Y1 and Y2 or connect terminal Y2 to an external 24 Vdc power supply.
For manual start or monitored start and if the control output Y1 (DC+) is to be used:
Connect terminals Y1 and Y2 to the device providing the start signal, such as a push-button.
For manual start or monitored start and if the device providing the start signal is supplied externally:
Connect terminal Y2 to the device providing the start signal, such as a push-button or a logic controller.
Leave terminal Y1 unconnected.
The common reference potential is established via terminal B2.
Respect the maximum wire resistance of 500 Ω when determining the cable length. The maximum wire
length between the start input and a sensor/device is 30 m (98.43 ft) if the supply via the control output
(terminal Y1) of the start input is not used.
(see page 35)
.
(see page 56)
to be implemented.
Additional, Non-Safety-Related Output Z1
INCORRECT USE OF OUTPUT
Do not use the additional output Z1 for safety-related purposes.
Failure to follow these instructions can result in death, serious injury, or equipment damage.
Connect the semiconductor pulsed output Z1 to a suitable input of the logic controller if you want to use
the diagnostics pattern the output provides.
The maximum wire length between the additional output Z1 and connected equipment is 30 m (98.43 ft)
The common reference potential is established via terminal B2.
Power Supply
Connect the terminals A1 and A2 to a power supply providing the supply voltage specified for the device
in the chapter Electrical Characteristics
Common Reference Potential
Terminal B2 is provided to obtain a common reference potential for 24 Vdc signals.
The power supplies of the connected equipment must have a common reference potential.
WARNING
(see page 21)
.
42
EIO0000003487 11/2020
XPSUS
Functions
EIO0000003487 11/2020
Functions
Chapter 5
Functions
What Is in This Chapter?
This chapter contains the following topics:
Application Functions44
Start Functions56
TopicPage
EIO0000003487 11/202043
Functions
Application Functions
Introduction
The following sections provide an overview of the available application functions and a detailed listing of
requirements and values of each of the application functions. The chapter Configuration
describes the configuration procedure by means of the selectors of the device.
Overview of Application Functions
(see page 62)
Typical applicationsType of outputs of sensor/device providing
the input signal for application function
Monitoring of Emergency Stop circuits
as per ISO 13850 and IEC 60204-1,
stop category 0
Monitoring of guards as per
ISO 14119/14120 with electrical
switches
Monitoring of two-hand control devices,
type III A as per ISO 13851
Monitoring of two-hand control devices,
type III C as per ISO 13851
Monitoring of guards as per
ISO 14119/14120 with electrical
switches
Monitoring of guards as per
ISO 14119/14120 with coded magnetic
switches
Monitoring of proximity switches
Monitoring of three-position enabling
switches as per IEC 60947-5-8
Signals at terminals S22 and S23 are not evaluated. Do
not connect these terminals.
This application function requires the start function selector to be set to positions 1 or 5, automatic start
without startup test. Refer to Start Functions
(see page 56)
for details.
Synchronization:
Synchronized terminalsSynchronization time
S12 synchronized with S13S12 and S13 have to be activated within 0.5 s.
Wiring of the inputs for two-hand control devices
EIO0000003487 11/202047
Functions
Application Function 4
CharacteristicValue/Description
Typical applicationsMonitoring of two-hand control devices,
type III C as per ISO 13851
Type of outputs of sensor/device providing the input signal
for application function
S•• terminals to be connectedS11-S12 and S11-S13, S21-S22 and S21-S23
DynamizationYes
Signal interlock monitoringBetween the pair of terminals S12-S13 and the pair of
This application function requires the start function selector to be set to positions 1 or 5, automatic start
without startup test. Refer to Start Functions
(see page 56)
for details.
Synchronization:
Synchronized terminalsSynchronization time
S12-S13 synchronized with S22-S23S12-S13 and S22-S23 have to be activated within 0.5 s.
Wiring of the inputs for two-hand control devices
48
EIO0000003487 11/2020
Application Function 5
Functions
CharacteristicValue/Description
Typical applicationsMonitoring of guards as per ISO 14119/14120
with electrical switches
Monitoring of guards as per ISO 14119/14120
with coded magnetic switches
Monitoring of proximity switches
Type of outputs of sensor/device providing the input signal
for application function
S•• terminals to be connectedS11-S12 and S11-S13 for sensor/device A
Signals at terminal S22 are not evaluated. Do not connect
this terminal.
This application function requires the start function selector to be set to positions 1 or 5, automatic start
without startup test. Refer to Start Functions
(see page 56)
for details.
Synchronization:
Synchronized terminalsSynchronization time
S13 synchronized with S23S13 and S23 have to be activated within 0.5 s.
Wiring of the inputs for three-position enabling switches
Operation of the contacts of a three-position enabling switch:
Black: Activated
White: Deactivated
1: From position 0 to position 2
2: From position 2 to position 0
Timing of a three-position enabling switch:
50
1: Power on and self test of three-position enabling switch terminated
2: Three-position enabling switch changes from position 0 to position 1
3: Three-position enabling switch changes from position 1 to position 2
4: Three-position enabling switch changes from position 2 to position 1
EIO0000003487 11/2020
5: Three-position enabling switch changes from position 1 to position 0
Functions
EIO0000003487 11/202051
Functions
Application Function 7
CharacteristicValue/Description
Typical applicationsMonitoring of proximity switches
Type of outputs of sensor/device providing the input signal
for application function
S•• terminals to be connectedS12-S13 for sensor/device A
DynamizationNo
Signal interlock monitoringBetween terminals S12 and S13
Synchronization of safety-related inputsNo
Two PNP outputs
S22-S23 for sensor/device B
Between terminals S22 and S23
Wiring of the inputs for sensors/devices with two PNP outputs
52
EIO0000003487 11/2020
Application Function 8
Functions
CharacteristicValue/Description
Typical applicationsMonitoring of proximity switches
Type of outputs of sensor/device providing the input signal
for application function
S•• terminals to be connectedS12-S13 for sensor/device A
DynamizationNo
Signal interlock monitoringBetween terminals S12 and S13
Two PNP outputs
S22-S23 for sensor/device B
Between terminals S22 and S23
Synchronization:
Synchronized terminalsSynchronization time
S12 synchronized with S13S12 and S13 have to be activated within 0.5 s.
S22 synchronized with S23S22 and S23 have to be activated within 0.5 s.
Wiring of the inputs for sensors/devices with two PNP outputs
EIO0000003487 11/202053
Functions
Application Function 9
CharacteristicValue/Description
Typical applicationsMonitoring of electro-sensitive protective
equipment such as type 4 light curtains as per
IEC 61496-1
Monitoring of RFID sensors
Type of outputs of sensor/device providing the input signal
for application function
S•• terminals to be connectedS12-S13 for sensor/device A
DynamizationNo
Signal interlock monitoringBetween terminals S12 and S13
Synchronization of safety-related inputsNo
OSSD (Output Signal Switching Device) outputs
S22-S23 for sensor/device B
Between terminals S22 and S23
Wiring of the inputs for sensors/devices with OSSD outputs
54
EIO0000003487 11/2020
Application Function 10
CharacteristicValue/Description
Typical applicationsMonitoring of electro-sensitive protective
Functions
equipment such as type 4 light curtains as per
IEC 61496-1
Monitoring of RFID sensors
Type of outputs of sensor/device providing the input signal
for application function
S•• terminals to be connectedS12-S13 for sensor/device A
DynamizationNo
Signal interlock monitoringBetween terminals S12 and S13
OSSD (Output Signal Switching Device) outputs
S22-S23 for sensor/device B
Between terminals S22 and S23
Synchronization:
Synchronized terminalsSynchronization time
S12 synchronized with S13S12 and S13 have to be activated within 0.5 s.
S22 synchronized with S23S22 and S23 have to be activated within 0.5 s.
Wiring of the inputs for sensors/devices with OSSD outputs
EIO0000003487 11/202055
Functions
Start Functions
Overview
WARNING
UNINTENDED EQUIPMENT OPERATION
Do not use the Start function for safety-related purposes.
Use Monitored Start or Startup Test if unintended restart is a hazard according to your risk
assessment.
Failure to follow these instructions can result in death, serious injury, or equipment damage.
The device provides several start functions which are selected by means of the start function selector. The
start function determines the start behavior of the device after power-on and for a transition from the
operating state Run: Outputs Deenergized (defined safe state) to the operating state Run: Outputs
Energized.
The start behavior is configured using the following characteristics:
Type of start (automatic/manual start and monitored start)
With or without startup test
With or without dynamization
Refer to the chapter Electrical Installation
(see page 35)
(see page 42)
for additional information on wiring the start input.
Automatic Start
With automatic start, the start input is permanently active. This can be achieved by bridging the start input
or providing an external power supply. When the safety-related input is activated, the safety-related
outputs are activated within a maximum of 100 ms (activation delay).
The following timing diagram illustrates the automatic start:
1 Activation delay (100 ms): maximum time between activation of safety-related input and activation of safety-related
output
2 Response time (20 ms): maximum time between deactivation of safety-related input and deactivation of safety-
related output
3 Recovery time (200 ms): time that must pass before the safety-related input can be activated again
The timing diagram exemplifies the timing using one safety-related input and one safety-related output.
The same logic applies in the case of multiple safety-related inputs and/or safety-related outputs.
Manual Start
56
A manual start requires the start input to be activated. The safety-related outputs are activated after both
the start input and the safety-related inputs have been activated.
EIO0000003487 11/2020
Functions
The following timing diagram illustrates the manual start:
1 Activation delay (100 ms): maximum time between activation of start input and activation of safety-related output
2 Response time (20 ms): maximum time between deactivation of safety-related input and deactivation of safety-
related output
3 Recovery time (200 ms): time that must pass before the safety-related input can be activated again
The timing diagram exemplifies the timing using one safety-related input and one safety-related output.
The same logic applies in the case of multiple safety-related inputs and/or safety-related outputs.
The signal required for activation of the Start input can be provided, for example, via a push-button, or a
logic controller.
Monitored Start with Falling Edge
In the case of a monitored start with falling edge, the start input must be activated and remain active for a
duration of 80 ms. The safety-related outputs are activated with a falling edge of the start input if the safetyrelated inputs have been activated in the meantime.
1 Activation delay (100 ms): maximum time between deactivation of start input and activation of safety-related output
2 Response time (20 ms): maximum time between deactivation of safety-related input and deactivation of safety-
related output
3 Waiting time after power-on (2500 ms): time that must pass between power-on and activation of the start input
4 Minimum duration of start pulse (80 ms): time for which the start input must be activated before the falling edge at
the start input
The timing diagram exemplifies the timing using one safety-related input and one safety-related output.
The same logic applies in the case of multiple safety-related inputs and/or safety-related outputs.
The signal required for activation of the Start input can be provided, for example, via a push-button or a
logic controller.
Startup Test
The startup test is performed after the device is powered on. The startup test is typically used for
applications involving guard monitoring. The start input is permanently activated by, for example, bridging.
After power up, the safety-related inputs must be deactivated and activated before the safety-related
outputs are activated. This is achieved by, for example, opening and closing the guard.
EIO0000003487 11/202057
Functions
1 Activation delay (100 ms): time between activation of safety-related input and activation of safety-related output
2 Response time (20 ms): time between deactivation of safety-related input and deactivation of safety-related output
3 Recovery time (200 ms): time that must pass before the safety-related input can be activated again
The timing diagram exemplifies the timing using one safety-related input and one safety-related output.
The same logic applies in the case of multiple safety-related inputs and/or safety-related outputs.
After power up, the safety-related outputs are not activated before each of the safety-related inputs has
been deactivated and activated again, either concurrently or one after the other, regardless of sequence.
If the safety-related inputs are already inactive at startup (power cycle), the startup test is considered to
have been completed and the safety-related outputs are activated once the safety-related inputs have
been activated and the activation delay has passed. If the safety-related inputs are active at power up, they
must be deactivated and activated again for the startup test to complete.
Configuring the Start Function
The start function is configured by means of the start function selector.
Position of start function selectorConfigured start function
1
2
3
4
5
6
7
8
Manual/automatic start (depends on
sensor/device connected to start input)
Without startup test
With dynamization
Manual/automatic start (depends on
sensor/device connected to start input)
With startup test
With dynamization
Monitored start
Without startup test
With dynamization
Monitored start
With startup test
With dynamization
Manual/automatic start (depends on
sensor/device connected to start input)
Without startup test
Without dynamization
Manual/automatic start (depends on
sensor/device connected to start input)
With startup test
Without dynamization
Monitored start
Without startup test
Without dynamization
Monitored start
With startup test
Without dynamization
58
EIO0000003487 11/2020
Functions
A start function with dynamization is typically if the start input is connected to a start push-button. A start
function without dynamization is typically used if the start input is connected to a logic controller. Refer to
the chapter Dynamization
(see page 35)
for details.
EIO0000003487 11/202059
Functions
60
EIO0000003487 11/2020
XPSUS
Configuration and Commiss ioning
EIO0000003487 11/2020
Configuration and Commissioni ng
Chapter 6
Configuration and Commissioning
What Is in This Chapter?
This chapter contains the following topics:
Configuration62
Commissioning63
TopicPage
EIO0000003487 11/202061
Configuration and Commissioning
Configuration
Overview
The device detects certain technically incorrect configurations (for example, a configured start function
cannot be used with a configured application function). The device cannot detect unwanted configurations
(for example, automatic start has been configured, but a monitored start is required for your application as
a result of your risk assessment).
INEFFECTIVE SAFETY-RELATED FUNCTION AND/OR UNINTENDED EQUIPMENT OPERATION
Only modify the settings of the selectors of the device if you are fully aware of all effects of such
modifications.
Verify that the settings of the selectors match the intended safety-related function and the
corresponding wiring of the device.
Verify that modifications do not compromise or reduce the Safety Integrity Level (SIL), Performance
Level (PL), and/or any other safety-related requirements and capabilities defined for your
machine/process.
Commission the device before it is used for the first time and after each configuration according to the
instructions in the present manual and in compliance with all regulations, standards, and process
definitions applicable to your machine/process
Failure to follow these instructions can result in death, serious injury, or equipment damage.
WARNING
The device is configured by means of the application function selector and the start function selector.
The device must be installed and wired according to the requirements of the safety-related function to be
implemented before you can configure it.
Modifications to the positions of the selectors only become effective after power-up. Remove power from
the device before modifying the position of the selectors. If the positions of the selectors are modified while
power is applied to the device, the device detects a configuration error.
Go through the full commissioning procedure
selectors.
Configuration Procedure
StepAction
(see page 63)
1Verify that the device has been wired according to the safety-related function to be configured.
2Remove power if the device is not powered off.
If an extension module XPSUEP is connected, remove power from the extension module as
well.
3Open the transparent cover of the device.
4Set the application function selector to the required application function.
5Set the start function selector to the required start function.
6Commission the device according to the chapter Commissioning
after having modified the positions of the
(see page 63)
.
62
EIO0000003487 11/2020
Commissioning
Overview
INEFFECTIVE SAFETY-RELATED FUNCTION AND/OR UNINTENDED EQUIPMENT OPERATION
Commission the device before it is used for the first time and after each configuration.
Commission or recommission the machine/process pursuant to all regulations, standards, and
process definitions applicable to your machine/process.
Only start the machine/process if there are no persons or obstructions in the zone of operation.
Verify correct operation and effectiveness of all functions by performing comprehensive tests for all
operating states, the defined safe state, and all potential error situations.
Document all modifications and the results of the commissioning procedure in compliance with all
regulations, standards, and process definitions applicable to your machine/process.
Failure to follow these instructions can result in death, serious injury, or equipment damage.
Commissioning Procedure
StepAction
Configuration and Commissioning
WARNING
1Verify correct mechanical and electrical installation
2Verify correct configuration
3Verify that there are no persons or obstructions in the zone of operation.
4Apply power and start the machine/process.
5Perform comprehensive tests for all operating states, the defined safe state, and all potential
6Close the transparent cover of the device and seal it with the enclosed sealing strip. Additional
7Document all modifications and the results of the commissioning procedure.
application.
(see page 62)
If an extension module XPSUEP is connected, apply power to the extension module at the same
time as to the device.
error situations.
sealing strips are available as an accessory. Refer to the chapter Accessories
additional information.
according to the intended application.
(see page 37)
according to the intended
(see page 74)
fo r
EIO0000003487 11/202063
Configuration and Commissioning
64
EIO0000003487 11/2020
XPSUS
Diagnostics
EIO0000003487 11/2020
Diagnostics
Chapter 7
Diagnostics
INEFFECTIVE SAFETY-RELATED FUNCTION AND/OR UNINTENDED EQUIPMENT OPERATION
Only attempt to resolve alerts and errors detected by the device if you are fully familiar with the safetyrelated applications and the non-safety-related applications as well as the hardware used to operate your
machine/process.
Failure to follow these instructions can result in death, serious injury, or equipment damage.
What Is in This Chapter?
This chapter contains the following topics:
Diagnostics via LEDs66
Diagnostics via Status Output Z169
WARNING
TopicPage
EIO0000003487 11/202065
Diagnostics
Diagnostics via LEDs
Overview
The device features various LEDs
and detected errors.
Recommission the device
application function selector or the start function selector.
LED POWER
StateMeaning
OffNo power supply
Solid onPower supply on
LED STATE
This LED provides information on the state of the safety-related outputs.
StateMeaning
OffSafety-related outputs deactivated
Solid onSafety-related outputs activated
(see page 13)
(see page 63)
that provide status information and information on alerts
if, during troubleshooting, you modify the position of the
LED START
LEDs S••
LED ERROR - Alerts
This LED provides information on the start condition. Refer to the chapter Start Function
(see page 56)
for
detailed information on the conditions and timing of the selected start function.
StateMeaning
OffStart condition not fulfilled
Solid onStart condition fulfilled
FlashingWaiting for start condition to be fulfilled
These LEDs provide information on the state of the corresponding safety-related input terminal.
StateMeaning
OffSafety-related input deactivated
Solid onSafety-related input activated
This LED flashes in conjunction with additional S•• LEDs to indicate alerts. In the case of an alert, the
device transitions to the defined safe state. Remove the cause of the alert to exit the defined safe state and
resume operation. Contact your Schneider Electric service representative if the condition persists.
66
EIO0000003487 11/2020
Diagnostics
StateIn conjunction with additional
MeaningRemedy
LEDs
Additional LEDs State of
additional LEDs
FlashingS•• and S••Flashing
alternatively
FlashingS•• and S••Flashing
synchronously
Synchronization time
exceeded.
Signal interlock condition
of two safety-related
inputs.
The two safety-related
inputs affected by the
signal interlock condition
must be deactivated for
at least 1 second before
the safety-related
outputs can be activated
again.
FlashingS•• and S••Solid onThe state of the safety-
related inputs is identical,
but the selected
application function
requires antivalent
behavior (for example,
normally open contact
and normally closed
contact).
Verify correct operation of the
sensors/devices providing the input
signal.
If synchronization is not required for
your application, use an equivalent
application function without
synchronization.
Ensure that both controls of the two-
hand control device are actuated
within the synchronization time if
you have selected the
corresponding application function.
Ensure that the enabling switch is
operated correctly if you have
selected the corresponding
application function.
Deactivate the two safety-related
inputs affected by the signal
interlock condition for at least
1 second.
Verify correct operation of the
contacts of the sensor/sdevices
providing the input signal.
Verify correct operation of the
sensors/devices providing the input
signal.
Verify correct wiring.
LED ERROR - Detected Errors
This LED lights solid in conjunction with additional LEDs to indicate detected errors. In the case of a
detected error, the device transitions to the defined safe state. You must remove the cause of the detected
error and perform a power cycle of the device to exit the defined safe state and resume operation. Contact
your Schneider Electric service representative if the condition persists.
StateIn conjunction with additional
Solid onSTATE, START
Solid onSTATE, START
Solid onPOWERFlashingPower supply error
Solid onSTATEFlashingError detected at safety-
Solid onSTARTFlashingCross circuit detected at
LEDs
Additional LEDs State of
additional LEDs
Flashing
and S••
synchronously
Solid onConfiguration error
and S••
MeaningRemedy
General error detected.
detected.
Verify correct wiring.
Verify that the positions of the
selectors are appropriate for the
application to be implemented.
detected.
Verify correct wiring.
Use a suitable power supply.
Perform a power cycle.
related output.
start input.
Verify correct wiring.
EIO0000003487 11/202067
Diagnostics
StateIn conjunction with additional
MeaningRemedy
LEDs
Additional LEDs State of
additional LEDs
Solid onSTATE and
START
Flashing
synchronously
Error detected at safetyrelated output of
extension module.
Solid onS••FlashingCross circuit detected at
safety-related input (for
example, incorrect wiring
or application function
with dynamization
selected, but
dynamization not
supported by connected
sensor/device).
Solid onS•• and S••Flashing
synchronously
Cross circuit detected at
safety-related inputs (for
example, incorrect wiring
or application function
with dynamization
selected, but
dynamization not
supported by connected
sensor/device).
Do not use the additional output Z1 for safety-related purposes.
Failure to follow these instructions can result in death, serious injury, or equipment damage.
The pulsed output Z1 provides diagnostics information in the form of a bit pattern. If the output Z1 is
connected to a logic controller, the PreventaSupport library can be used to evaluate the diagnostics
information. The library consists of the function blocks FB_PreventaDiag and FB_PreventaMain. The
function block FB_PreventaDiag converts the bit sequences into diagnostics codes for monitoring the
status of the device. The function block FB_PreventaMain uses the diagnostics codes as input to
perform calculations concerning, for example, maintenance tasks.
Refer to the PreventaSupport Library Guide
Diagnostics Codes
The device encodes diagnostics information into sequences of 10 bits with a total duration of 2 s (each bit
200 ms). The first four bits (0010) represent the beginning of a bit sequence. The next six bits contain the
diagnostics code itself.
The following table lists the bit sequences of the diagnostics codes, the description of the corresponding
status as well as correctives, if applicable.
detected. The position
of at least one of the
selectors has been
modified during
operation.
0010001100Cross circuit detected
at input terminal S12.
0010001101Cross circuit detected
at input terminal S13.
(1) Type of message: E = Error detected, A = Alert, S = Status information
Verify correct wiring.
Use a suitable power supply.
Perform a power cycle.
If the error persists, replace the device.
Verify correct wiring.
Perform a power cycle of the base safety module and
the connected extension module.
If the error persists, replace the extension module.
Verify that the position of the selectors is appropriate
for the application to be implemented.
Perform a power cycle.
If the error persists, replace the device.
Verify correct wiring.
Verify that the sensor/device providing the input signal
is suitable for cross circuit detection by means of
dynamization. If it is not, use an application function
without dynamization or a sensor/device suitable for
dynamization.
Verify correct operation of sensor/device providing the
input signal.
Perform a power cycle.
Verify correct wiring.
Verify that the sensor/device providing the input signal
is suitable for cross circuit detection by means of
dynamization. If it is not, use an application function
without dynamization or a sensor/device suitable for
dynamization.
Verify correct operation of sensor/device providing the
input signal.
Perform a power cycle.
Type
E
E
E
E
E
E
(1)
EIO0000003487 11/202069
Diagnostics
Bit sequenceDescriptionCorrectives
0010001111Cross circuit detected
at input terminal S22.
Verify correct wiring.
Verify that the sensor/device providing the input signal
is suitable for cross circuit detection by means of
dynamization. If it is not, use an application function
without dynamization or a sensor/device suitable for
dynamization.
Verify correct operation of sensor/device providing the
input signal.
Perform a power cycle.
0010001110Cross circuit detected
at input terminal S23.
Verify correct wiring.
Verify that the sensor/device providing the input signal
is suitable for cross circuit detection by means of
dynamization. If it is not, use an application function
without dynamization or a sensor/device suitable for
dynamization.
Verify correct operation of sensor/device providing the
input signal.
Perform a power cycle.
0010110000Cross circuit detected
at start input.
Verify correct wiring.
Verify that the device providing the input signal is
suitable for cross circuit detection by means of
dynamization. If it is not, use a start function without
dynamization or a device suitable for dynamization.
Verify correct operation of device providing the input
signal.
Perform a power cycle.
0010100110Antivalence alert at
input S1•
Set the signal to the required state and retry.
Verify correct configuration
If the condition persists, verify correct wiring and
correct operation of the sensor/device providing the
input signal.
0010100000Antivalence alert at
input S2•
Set the signal to the required state and retry.
Verify correct configuration
If the condition persists, verify correct wiring and
correct operation of the sensor/device providing the
input signal.
0010110011Synchronization alert.
One of the
synchronized safetyrelated inputs is still
deactivated, but the
synchronization time
has already elapsed.
Restore the original condition of the states of the
inputs and retry.
Verify correct operation of sensors/devices providing
the input signals.
Ensure that both controls of the two-hand control
device are actuated within the synchronization time if
you have selected the corresponding application
function.
0010100111Synchronization alert.
Both synchronized
safety-related inputs
have been activated,
but not within the
synchronization time.
Restore the original condition of the states of the
inputs and retry.
Verify correct operation of sensors/devices providing
the input signals.
Ensure that both controls of the two-hand control
device are actuated within the synchronization time if
you have selected the corresponding application
function.
-S
to change its state. In
the case of a
configuration with
antivalent inputs,
inputs S12 and S13 are
expected to change
their states.
(1) Type of message: E = Error detected, A = Alert, S = Status information
Type
E
E
E
A
A
A
A
(1)
70
EIO0000003487 11/2020
Diagnostics
Bit sequenceDescriptionCorrectives
0010110100Input S13 is expected
-S
to change its state.
0010111100Input S22 is expected
-S
to change its state. In
the case of a
configuration with
antivalent inputs,
inputs S22 and S23 are
expected to change
their states.
0010111101Input S23 is expected
-S
to change its state.
0010101011Waiting for startup test. -S
0010101010Waiting for rising edge
-S
for automatic/manual
start or monitored start.
0010101110Start input activated.
-S
Waiting for falling edge
for monitored start.
0010101111Device in operating
-S
state Run:Outputs
Energized, safetyrelated outputs
activated.
(1) Type of message: E = Error detected, A = Alert, S = Status information
Type
(1)
EIO0000003487 11/202071
Diagnostics
72
EIO0000003487 11/2020
XPSUS
Accessories, Service, Maint enance, and Disposal
EIO0000003487 11/2020
Accessories, Service, Mainten ance, and Disposal
Chapter 8
Accessories, Service, Maintenance, and Disposal
What Is in This Chapter?
This chapter contains the following topics:
Accessories74
Maintenance75
Transportation, Storage, and Disposal76
Service Addresses77
TopicPage
EIO0000003487 11/202073
Accessories, Service, Maintenance, and Disposal
Accessories
Accessories
The following accessories are available for the device:
DescriptionCommercial Reference
Coding bits
The coding bits are used if the terminal blocks are removed to help ensure
correct insertion of the terminal blocks into the device.
30 pieces per packaging unit
Sealing strips
The uniquely numbered sealing strips are used to seal the transparent front
cover of the device to help prevent unauthorized access to the configuration
selectors.
10 pieces per packaging unit
XPSEC
XPSES
74
EIO0000003487 11/2020
Maintenance
Service and Repairs
Maintenance Plan
Accessories, Service, Maintenance, and Disposal
The device contains no user-serviceable parts. Do not attempt to open, service, or repair the device.
Maintenance plan:
Ensure that a safety-related function implemented with the device is triggered at the minimum intervals
required by the regulations, standards, and process definitions applicable to your machine/process.
Inspect the wiring at regular intervals.
Tighten the threaded connections at regular intervals.
Verify that the device is not used beyond the specified lifetime
(see page 24)
.
To determine the end of the lifetime, add the specified lifetime to the date of manufacture indicated on
the nameplate
(see page 14)
of the device.
Example: If the date of manufacture indicated on the nameplate is 2019-W10, do not use the device
after week 10, 2039.
As a machine designer or system integrator, you must include this information in the maintenance plan for
your customer.
EIO0000003487 11/202075
Accessories, Service, Maintenance, and Disposal
Transportation, Storage, and Disposal
Transportation and Storage
Ensure that the environmental conditions
respected.
Disposal
Dispose of the product in accordance with all applicable regulations.
https://www.se.com/green-premium
Visit
per ISO 14025 such as:
EoLi (Product End-of-Life Instructions)
PEP (Product Environmental Profile)
(see page 18)
specified for transportation and storage are
for information and documents on environmental protection as
76
EIO0000003487 11/2020
Service Addresses
Schneider Electric Automation GmbH
Schneiderplatz 1
97828 Marktheidenfeld, Germany
Phone: +49 (0) 9391 / 606 - 0
Fax: +49 (0) 9391 / 606 - 4000
Email: info-marktheidenfeld@se.com
Additional Contact Addresses
See the homepage for additional contact addresses:
manual start,
monitored start with falling edge, 57,
monitoring of electro-sensitive protective equipment (type 4 light curtains) as per IEC 61496-1,
56
57
54, 55
monitoring of Emergency Stop circuits as per
ISO 13850 and IEC 60204-1, stop category 0,
45
46
monitoring of guards as per ISO 14119/14120 with
coded magnetic switches,
monitoring of guards as per ISO 14119/14120 with
electrical switches,
monitoring of proximity switches, 49, 52,
monitoring of RFID sensors, 54,
monitoring of three-position enabling switches as
per IEC 60947-5-8,
monitoring of two-hand control devices, type III A
as per ISO 13851,
monitoring of two-hand control devices, type III C
as per ISO 13851,
overview application functions,
signal interlock monitoring,
start functions,
synchronization of safety-related inputs,
47
48
56
49
45, 46, 49
53
55
50
44
36
34
G
guards as per ISO 14119/14120 with coded magnetic
switches, monitoring of,
guards as per ISO 14119/14120 with electrical switches, monitoring of,
49
45, 46, 49
,
E
electrical characteristics,
electrical durability,
electro-sensitive protective equipment (type 4 light
curtains) as per IEC 61496-1, monitoring of,
electromagnetic compatibility,
EMC,
28
Emergency Stop circuits as per ISO 13850 and
IEC 60204-1, stop category 0, monitoring of,
environmental characteristics,
errors, detected,
example Emergency Stop
overview,
timing diagram,
66
30
21
24
54, 55
28
45, 46
18
30
F
functional safety data,
functions
automatic start,
configuration of application functions,
configuration of start function,
dynamization,
light curtains, type 4 as per IEC 61496-1, monitor-
24
56
62
58
35
H
HFT,
24
I
input, start
technical data,
wiring,
42
inputs, safety-related
technical data,
wiring,
41
installation, 38, 39,
control cabinet,
enclosure,
mechanical,
prerequisites,
21
21
40
38
38
39
38
L
L,
24
LEDs,
66
lifetime,
light curtains type 4 as per IEC 61496-1, monitoring
of,
24
54, 55
EIO0000003487 11/202079
Index
M
maintenance,
manual start,
mechanical characteristics,
monitored start with falling edge,
monitoring of electro-sensitive protective equipment
(type 4 light curtains) as per IEC 61496-1,
monitoring of Emergency Stop circuits as per
ISO 13850 and IEC 60204-1, stop category 0,
monitoring of guards as per ISO 14119/14120 with
coded magnetic switches,
monitoring of guards as per ISO 14119/14120 with
electrical switches,
monitoring of proximity switches, 49, 52,
monitoring of RFID sensors, 54,
monitoring of three-position enabling switches as per
IEC 60947-5-8,
monitoring of two-hand control devices, type III A as
per ISO 13851,
monitoring of two-hand control devices, type III C as
per ISO 13851,
mounting,
DIN rail,
screw mounting,
MTTFd,
75
56
20
57
54, 55
45, 46
49
45, 46, 49
53
55
50
47
48
39
39
39
24
N
nameplate,
14
O
operating cycles over lifetime ,
operating state transitions,
operating states,
operation, environmental characteristics,
output Z1
three-position enabling switches as per IEC 60947-58, monitoring of,
tightening torques terminals,
timing data,
transportation, environmental characteristics,
troubleshooting,
two-hand control devices, type III A as per ISO 13851,
monitoring of,
two-hand control devices, type III C as per ISO 13851,
monitoring of,
type code,