← Back to all lessons
Wiring 8
Pro

Wiring 8 — Dual-Channel E-Stop with Safety Relay (Cat 3)

What you'll learn

EN ISO 13849-1 defines Performance Levels (PL a–e) for safety functions. Category 3 mandates **single-fault tolerance**: a single failure anywhere in the safety function — a welded contact, a broken wire, a stuck contactor — must not cause the loss of the safety function. The machine must either stop safely or the fault must be detected before the next demand. Cat 3 achieves this through **redundancy**: duplicate channels that independently execute the same safety action, combined with **monitoring**: the system detects when a fault has occurred and prevents restart until it is resolved.

Lab time: ~25 minutes.

Lesson briefing

Dual-Channel E-Stop with Safety Relay (Cat 3)

Why Category 3?

EN ISO 13849-1 defines Performance Levels (PL a–e) for safety functions. Category 3 mandates single-fault tolerance: a single failure anywhere in the safety function — a welded contact, a broken wire, a stuck contactor — must not cause the loss of the safety function. The machine must either stop safely or the fault must be detected before the next demand. Cat 3 achieves this through redundancy: duplicate channels that independently execute the same safety action, combined with monitoring: the system detects when a fault has occurred and prevents restart until it is resolved.

Dual-Channel E-Stop

The emergency stop button in this circuit is a dual-channel device. It contains two independent NC contacts — channel 1 and channel 2 — that are mechanically linked to the same mushroom head but electrically separate. Each channel feeds a different input pair on the safety relay (S11/S12 for channel 1, S21/S22 for channel 2).

If the button is pressed, both channels open simultaneously. If one channel fails welded (stuck closed), the other still opens — the safety relay detects the discrepancy because only one channel responded, and it locks out rather than allowing restart. If one channel develops an open fault (wire break), the relay detects the immediate loss of that channel and de-energises. Either way, a single fault does not allow the machine to run unsafely.

The Safety Relay's Role

The safety relay monitors both input channels continuously. When both channels are healthy and closed, and a valid hardware reset has been issued, the relay energises its two independent output contacts (13/14 and 23/24). Each output contact drives one contactor coil completely independently. If either output contact welds shut, the other remains fully functional and will still open on the next E-stop demand — the fault tolerance extends through the relay's own output stage.

Two Independent Relay Outputs — Strict Cat 3

Output contact 1 (terminals 13/14) drives KM1's coil directly. Output contact 2 (terminals 23/24) drives KM2's coil directly. These are two electrically separate contacts inside the relay — not one contact feeding two coils in parallel or series. This means:

  • If contact 1 welds: Contact 2 still opens; KM2 drops out; the series power path is broken. The motor stops.
  • If contact 2 welds: Contact 1 still opens; KM1 drops out; the series power path is broken. The motor stops.
  • If both weld simultaneously: This is a double fault — Cat 3 does not require coverage of simultaneous independent failures. The fault is detected by the EDM loop before the next restart attempt.

Series Contactors — Redundant Interruption

Both KM1 and KM2 contactors sit in series on the motor power circuit. Mains enters KM1's line side; KM1's load side feeds KM2's line side; KM2's load side feeds the motor. For the motor to run, BOTH sets of main contacts must be closed. If one contactor's main contacts weld shut, the other still opens on the next E-stop — power is interrupted. A single contact failure cannot leave the motor live.

Hardware EDM Loop via S33/S34

The relay's External Device Monitoring (EDM) loop uses terminals S33 and S34. S33 receives a permanent +24V supply. S34 connects to the start of a series chain: reset push-button NO contact, then KM1's NC auxiliary contact (21/22), then KM2's NC auxiliary contact (21/22), returning to 0V. The relay only re-arms when this entire loop is conducting — which requires all three conditions to be true simultaneously:

  1. The operator has pressed and held the reset push-button.
  2. KM1's NC aux is closed — confirming KM1 has dropped out (not welded).
  3. KM2's NC aux is closed — confirming KM2 has dropped out (not welded).

If either contactor sticks energised, its NC aux remains open, the EDM loop stays broken, and the relay refuses to re-arm regardless of how many times the operator presses Reset. The fault must be resolved before the machine can restart. This is a hardware-only interlock — no PLC is involved in the safety function, so a PLC failure, program error, or power loss to the PLC cannot bypass the EDM check.

This combination — dual-channel input monitoring, two independent output contacts, and a hardware EDM loop — is the complete strict Cat 3 implementation per EN ISO 13849-1.

Wire Discipline

Safety circuits must be wired with care for identification and fault tracing. In real cabinets, safety wiring uses a distinct colour (yellow or orange in some markets) and is routed in a separate duct from standard control wiring. Every safety wire should be individually ferrule-numbered to match the wiring schedule.

Hints

Hint 1

The E-stop has two independent NC channels. Channel 1 forms a loop between the safety relay's S11 and S12: wire sr-1.S11 → estop-1.NC1-IN, then estop-1.NC1-OUT → sr-1.S12. Channel 2 forms an identical loop between S21 and S22 using NC2-IN and NC2-OUT. Each channel is independent — never bridge the two channels together.

Hint 2

Sign up to unlock the full hint sequence.

Hint 3

Sign up to unlock the full hint sequence.

Hint 4

Sign up to unlock the full hint sequence.

Hint 5

Sign up to unlock the full hint sequence.

This lesson uses 13 placed components on the lab canvas. Components are vendor-neutral (no proprietary trademarks); the wiring rules apply to any equivalent industrial part.

Sign up to preview

Create a free account to preview this Pro lab; upgrade to open the interactive circuit.

Sign up to preview

You might also like

Competency and practice field guide

Machine safety-circuit wiring lesson: implementation, evidence and troubleshooting

Direct answer

Machine safety-circuit wiring lesson becomes useful when it connects hazard, safety function, safe state, device contacts, channel separation, discrepancy, reset, output devices, edm, diagnostics, bypass control and restart policy with protective-device demand through two input channels, safety logic, safety outputs, contactors or drive enable, energy removal, measured stop and reset authorization, then proves each protective demand reaches the declared safe state and deliberate reset is possible only after inputs and feedback return correctly under normal, boundary, fault and recovery conditions. The objective is a repeatable engineering or learning result, not merely activity inside a page or tool.

This guide is written for electrical and PLC learners tracing emergency-stop or guard inputs through a safety relay or controller to contactors, feedback and a verified safe state. The intended result is specific: the learner can explain channel behavior, reset conditions and external-device monitoring and can identify why standard status wiring is not safety validation.

a guarded machinery training cell used to inspect emergency stopping, safety relays, light curtains, overload protection and drive safe-torque-off boundaries while studying dual-channel safety circuit, reset and monitored outputs
The scene keeps dual-channel safety circuit, reset and monitored outputs connected to a declared operating condition, observable evidence, safe boundaries and a result another person can reproduce.

System map / 02

Six concepts that control the result

Treat these as connected checkpoints. Each checkpoint has an expected state, an observable state and a boundary to the next part of the system. That structure prevents a software indication from being mistaken for physical proof.

NODE 01observable

Define the operating contract

hazard, safety function, safe state, device contacts, channel separation, discrepancy, reset, output devices, EDM, diagnostics, bypass control and restart policy. For dual-channel safety circuit, reset and monitored outputs, record the initial condition, actor, requested change, observable result and stopping condition before selecting a tool or implementation.

NODE 02observable

Map the evidence path

protective-device demand through two input channels, safety logic, safety outputs, contactors or drive enable, energy removal, measured stop and reset authorization. Separate request, internal state, output or service, physical or user-visible result and independent feedback so each boundary can be inspected.

NODE 03observable

Prove normal operation

each protective demand reaches the declared safe state and deliberate reset is possible only after inputs and feedback return correctly. Run more than one cycle from a known state and retain the values, timings or artifacts that demonstrate repeatability.

NODE 04observable

Exercise a boundary case

cross fault, channel disagreement, welded contactor, held reset, stuck input, supply loss, bypass, diagnostic fault and power return. Choose minimum, maximum, simultaneous, delayed or restart conditions that reveal assumptions hidden by the happy path.

NODE 05observable

Diagnose a controlled fault

a hazard, device, channel, logic, reset, output, final-device, feedback, stopping, calculation or validation mismatch. Preserve the first symptom, divide the system at a measurable boundary and change one condition only after predicting the result.

NODE 06observable

Transfer and hand over

the complete function designed and validated on target machinery by competent persons under the applicable standards and test plan. Restore normal state, remove temporary changes, repeat affected checks and document which claims remain limited to the learning environment.

Procedure / 03

A six-step practice and commissioning workflow

Run the steps in order the first time. Later, the same structure becomes a diagnostic loop: define the expected condition, observe the boundary, interpret the difference and choose one proving action.

  1. 01

    Write the acceptance case

    Convert hazard, safety function, safe state, device contacts, channel separation, discrepancy, reset, output devices, edm, diagnostics, bypass control and restart policy into initial conditions, one stimulus and observable pass criteria.

    Evidence: Another person can repeat the case without guessing the intended result.

    Avoid: Using page completion or an animation as the acceptance criterion.

  2. 02

    Build the map

    Document protective-device demand through two input channels, safety logic, safety outputs, contactors or drive enable, energy removal, measured stop and reset authorization and name who owns each state or decision.

    Evidence: Every request and result has a source, destination and useful inspection point.

    Avoid: Using the same value as command, status and independent feedback.

  3. 03

    Run the baseline

    Apply each protective demand reaches the declared safe state and deliberate reset is possible only after inputs and feedback return correctly from a clean start and record the expected evidence.

    Evidence: Repeated runs produce the same bounded result.

    Avoid: Changing several parameters before a baseline exists.

  4. 04

    Challenge assumptions

    Test cross fault, channel disagreement, welded contactor, held reset, stuck input, supply loss, bypass, diagnostic fault and power return without changing the acceptance contract.

    Evidence: Limits, timing and restart behavior reach defined states.

    Avoid: Testing only one ideal sequence.

  5. 05

    Isolate one failure

    Introduce or analyse a hazard, device, channel, logic, reset, output, final-device, feedback, stopping, calculation or validation mismatch and locate the first disagreement.

    Evidence: The proving action distinguishes the leading hypotheses.

    Avoid: Resetting, forcing or replacing before evidence is retained.

  6. 06

    Close the evidence loop

    Complete the complete function designed and validated on target machinery by competent persons under the applicable standards and test plan and repeat the affected regression cases.

    Evidence: A learner completes the surface by explaining the result, passing a changed case and identifying what still requires supervised target-equipment practice.

    Avoid: Treating an acknowledged message or one successful rerun as handover.

Diagnostic matrix / 04

Symptoms, proving points and next actions

The table is a reasoning aid, not a parts-replacement chart. Preserve the initial symptom, inspect the named boundary and use the interpretation to choose the next controlled test. Site safety procedures and equipment manuals remain authoritative.

Diagnostic symptoms, inspection points, interpretations and next actions for Machine safety-circuit wiring lesson: implementation, evidence and troubleshooting
Observed symptomInspectInterpretationNext proving action
The expected result is unclearRequirement, initial state, actor, stimulus, units and pass conditionThe learner, instructor and assessor may be solving different versions of the task.Rewrite one observable acceptance case before continuing.
Internal state changes but the outcome does notRequest, final owner, output or service boundary and independent feedbackA software or interface indication proves intent at one layer, not the complete outcome.Trace the first boundary after the changing state.
Normal case passes but an edge case failsLimits, timing, simultaneous events, reset and restart assumptionsThe implementation contains a hidden assumption exposed by the changed condition.Add the failed boundary as a permanent regression case.
The failure disappears after resetOriginal symptom, histories, diagnostics, timestamps and active causeReset changed evidence or state without proving the initiating cause.Reproduce under a controlled condition and preserve pre/post-event data.
Simulator and target disagreeModel boundary, software version, task timing, I/O behavior, data types and configurationA learning model and the intended target do not share one of the recorded assumptions.Reduce the case and verify against current target documentation.
The result cannot be explainedPrediction, observation, proving action, alternative hypotheses and limitationsActivity occurred but the evidence is not yet transferable or reviewable.Have the learner defend the signal path and repeat a changed case.

Product evidence / 05

What the browser practice can actually demonstrate

The browser platform can retain programs, scenario results, attempts and observable machine state so practice is attached to evidence rather than seat time alone.

Where simulation stops

The lesson cannot perform risk assessment, select architecture, calculate achieved performance, determine stopping time or validate machinery safety.

Commissioning notebook / 06

Six cases that turn the concepts into evidence

Use these as written briefs rather than click-through instructions. For every case, state the expected condition before acting, retain the first useful observation and explain why the final result proves the requirement. A different program or component choice can still be correct when it produces the same bounded behavior and evidence.

Case 01

predict → observe → prove

Prove define the operating contract

Engineering context. hazard, safety function, safe state, device contacts, channel separation, discrepancy, reset, output devices, EDM, diagnostics, bypass control and restart policy. For dual-channel safety circuit, reset and monitored outputs, record the initial condition, actor, requested change, observable result and stopping condition before selecting a tool or implementation. Begin with a written normal condition and identify which request, state, physical result or communication value will provide independent confirmation. Do not begin by changing the configuration; the initial state is part of the evidence and should remain reproducible.

Controlled setup. Use the “Write the acceptance case” stage of the workflow: convert hazard, safety function, safe state, device contacts, channel separation, discrepancy, reset, output devices, edm, diagnostics, bypass control and restart policy into initial conditions, one stimulus and observable pass criteria. The acceptance record should show this result: another person can repeat the case without guessing the intended result. Record initial conditions, the exact stimulus and the observation point so another learner can repeat the case without relying on your memory.

Fault challenge. Introduce or analyse “The expected result is unclear” as one bounded deviation. Inspect requirement, initial state, actor, stimulus, units and pass condition The working interpretation is that the learner, instructor and assessor may be solving different versions of the task. The next proving action is to rewrite one observable acceptance case before continuing. Change only one condition before observing the result, and preserve timestamps or measurements where timing matters.

Review and recovery. The most common trap here is using page completion or an animation as the acceptance criterion. After restoring the cause, repeat the normal case and at least one stop, timeout, disconnect or restart boundary relevant to this topic. Remove temporary forces and bypasses, return the model to a known state and retain the evidence that both operation and recovery are deliberate.

Explain it aloud: What is a dual-channel safety circuit? A defensible short answer is: It uses separate signal paths so specified faults can be detected and handled according to the designed safety architecture.

Case 02

predict → observe → prove

Prove map the evidence path

Engineering context. protective-device demand through two input channels, safety logic, safety outputs, contactors or drive enable, energy removal, measured stop and reset authorization. Separate request, internal state, output or service, physical or user-visible result and independent feedback so each boundary can be inspected. Begin with a written normal condition and identify which request, state, physical result or communication value will provide independent confirmation. Do not begin by changing the configuration; the initial state is part of the evidence and should remain reproducible.

Controlled setup. Use the “Build the map” stage of the workflow: document protective-device demand through two input channels, safety logic, safety outputs, contactors or drive enable, energy removal, measured stop and reset authorization and name who owns each state or decision. The acceptance record should show this result: every request and result has a source, destination and useful inspection point. Record initial conditions, the exact stimulus and the observation point so another learner can repeat the case without relying on your memory.

Fault challenge. Introduce or analyse “Internal state changes but the outcome does not” as one bounded deviation. Inspect request, final owner, output or service boundary and independent feedback The working interpretation is that a software or interface indication proves intent at one layer, not the complete outcome. The next proving action is to trace the first boundary after the changing state. Change only one condition before observing the result, and preserve timestamps or measurements where timing matters.

Review and recovery. The most common trap here is using the same value as command, status and independent feedback. After restoring the cause, repeat the normal case and at least one stop, timeout, disconnect or restart boundary relevant to this topic. Remove temporary forces and bypasses, return the model to a known state and retain the evidence that both operation and recovery are deliberate.

Explain it aloud: Why monitor contactor feedback in a safety circuit? A defensible short answer is: External-device monitoring helps detect a contactor that did not return to its expected de-energized state before reset.

Case 03

predict → observe → prove

Prove prove normal operation

Engineering context. each protective demand reaches the declared safe state and deliberate reset is possible only after inputs and feedback return correctly. Run more than one cycle from a known state and retain the values, timings or artifacts that demonstrate repeatability. Begin with a written normal condition and identify which request, state, physical result or communication value will provide independent confirmation. Do not begin by changing the configuration; the initial state is part of the evidence and should remain reproducible.

Controlled setup. Use the “Run the baseline” stage of the workflow: apply each protective demand reaches the declared safe state and deliberate reset is possible only after inputs and feedback return correctly from a clean start and record the expected evidence. The acceptance record should show this result: repeated runs produce the same bounded result. Record initial conditions, the exact stimulus and the observation point so another learner can repeat the case without relying on your memory.

Fault challenge. Introduce or analyse “Normal case passes but an edge case fails” as one bounded deviation. Inspect limits, timing, simultaneous events, reset and restart assumptions The working interpretation is that the implementation contains a hidden assumption exposed by the changed condition. The next proving action is to add the failed boundary as a permanent regression case. Change only one condition before observing the result, and preserve timestamps or measurements where timing matters.

Review and recovery. The most common trap here is changing several parameters before a baseline exists. After restoring the cause, repeat the normal case and at least one stop, timeout, disconnect or restart boundary relevant to this topic. Remove temporary forces and bypasses, return the model to a known state and retain the evidence that both operation and recovery are deliberate.

Explain it aloud: What should I learn first about dual-channel safety circuit, reset and monitored outputs? A defensible short answer is: Start with the operating contract and evidence path: hazard, safety function, safe state, device contacts, channel separation, discrepancy, reset, output devices, edm, diagnostics, bypass control and restart policy, followed by protective-device demand through two input channels, safety logic, safety outputs, contactors or drive enable, energy removal, measured stop and reset authorization. Add advanced features only after the baseline is predictable.

Case 04

predict → observe → prove

Prove exercise a boundary case

Engineering context. cross fault, channel disagreement, welded contactor, held reset, stuck input, supply loss, bypass, diagnostic fault and power return. Choose minimum, maximum, simultaneous, delayed or restart conditions that reveal assumptions hidden by the happy path. Begin with a written normal condition and identify which request, state, physical result or communication value will provide independent confirmation. Do not begin by changing the configuration; the initial state is part of the evidence and should remain reproducible.

Controlled setup. Use the “Challenge assumptions” stage of the workflow: test cross fault, channel disagreement, welded contactor, held reset, stuck input, supply loss, bypass, diagnostic fault and power return without changing the acceptance contract. The acceptance record should show this result: limits, timing and restart behavior reach defined states. Record initial conditions, the exact stimulus and the observation point so another learner can repeat the case without relying on your memory.

Fault challenge. Introduce or analyse “The failure disappears after reset” as one bounded deviation. Inspect original symptom, histories, diagnostics, timestamps and active cause The working interpretation is that reset changed evidence or state without proving the initiating cause. The next proving action is to reproduce under a controlled condition and preserve pre/post-event data. Change only one condition before observing the result, and preserve timestamps or measurements where timing matters.

Review and recovery. The most common trap here is testing only one ideal sequence. After restoring the cause, repeat the normal case and at least one stop, timeout, disconnect or restart boundary relevant to this topic. Remove temporary forces and bypasses, return the model to a known state and retain the evidence that both operation and recovery are deliberate.

Explain it aloud: How do I practise dual-channel safety circuit, reset and monitored outputs effectively? A defensible short answer is: Use short cases with known initial conditions, a written prediction, one action and an observable result. Then alter a boundary or fault and explain why the evidence changed.

Case 05

predict → observe → prove

Prove diagnose a controlled fault

Engineering context. a hazard, device, channel, logic, reset, output, final-device, feedback, stopping, calculation or validation mismatch. Preserve the first symptom, divide the system at a measurable boundary and change one condition only after predicting the result. Begin with a written normal condition and identify which request, state, physical result or communication value will provide independent confirmation. Do not begin by changing the configuration; the initial state is part of the evidence and should remain reproducible.

Controlled setup. Use the “Isolate one failure” stage of the workflow: introduce or analyse a hazard, device, channel, logic, reset, output, final-device, feedback, stopping, calculation or validation mismatch and locate the first disagreement. The acceptance record should show this result: the proving action distinguishes the leading hypotheses. Record initial conditions, the exact stimulus and the observation point so another learner can repeat the case without relying on your memory.

Fault challenge. Introduce or analyse “Simulator and target disagree” as one bounded deviation. Inspect model boundary, software version, task timing, I/O behavior, data types and configuration The working interpretation is that a learning model and the intended target do not share one of the recorded assumptions. The next proving action is to reduce the case and verify against current target documentation. Change only one condition before observing the result, and preserve timestamps or measurements where timing matters.

Review and recovery. The most common trap here is resetting, forcing or replacing before evidence is retained. After restoring the cause, repeat the normal case and at least one stop, timeout, disconnect or restart boundary relevant to this topic. Remove temporary forces and bypasses, return the model to a known state and retain the evidence that both operation and recovery are deliberate.

Explain it aloud: What counts as proof of competence? A defensible short answer is: A repeatable artifact or system result plus an explanation of the signal path is stronger than time spent, screenshots or a copied answer. Physical competence requires separate supervised evidence.

Case 06

predict → observe → prove

Prove transfer and hand over

Engineering context. the complete function designed and validated on target machinery by competent persons under the applicable standards and test plan. Restore normal state, remove temporary changes, repeat affected checks and document which claims remain limited to the learning environment. Begin with a written normal condition and identify which request, state, physical result or communication value will provide independent confirmation. Do not begin by changing the configuration; the initial state is part of the evidence and should remain reproducible.

Controlled setup. Use the “Close the evidence loop” stage of the workflow: complete the complete function designed and validated on target machinery by competent persons under the applicable standards and test plan and repeat the affected regression cases. The acceptance record should show this result: a learner completes the surface by explaining the result, passing a changed case and identifying what still requires supervised target-equipment practice. Record initial conditions, the exact stimulus and the observation point so another learner can repeat the case without relying on your memory.

Fault challenge. Introduce or analyse “The result cannot be explained” as one bounded deviation. Inspect prediction, observation, proving action, alternative hypotheses and limitations The working interpretation is that activity occurred but the evidence is not yet transferable or reviewable. The next proving action is to have the learner defend the signal path and repeat a changed case. Change only one condition before observing the result, and preserve timestamps or measurements where timing matters.

Review and recovery. The most common trap here is treating an acknowledged message or one successful rerun as handover. After restoring the cause, repeat the normal case and at least one stop, timeout, disconnect or restart boundary relevant to this topic. Remove temporary forces and bypasses, return the model to a known state and retain the evidence that both operation and recovery are deliberate.

Explain it aloud: Why test faults and restart behavior? A defensible short answer is: Because a hazard, device, channel, logic, reset, output, final-device, feedback, stopping, calculation or validation mismatch or cross fault, channel disagreement, welded contactor, held reset, stuck input, supply loss, bypass, diagnostic fault and power return can expose assumptions that never appear during ideal startup and steady operation.

Answer surface / 07

Questions people ask about Machine safety-circuit wiring lesson

These concise answers define the operating, training and product boundaries most often missed in broad summaries. The full workflow and diagnostic table above provide the evidence behind them.

What is a dual-channel safety circuit?

It uses separate signal paths so specified faults can be detected and handled according to the designed safety architecture.

Why monitor contactor feedback in a safety circuit?

External-device monitoring helps detect a contactor that did not return to its expected de-energized state before reset.

What should I learn first about dual-channel safety circuit, reset and monitored outputs?

Start with the operating contract and evidence path: hazard, safety function, safe state, device contacts, channel separation, discrepancy, reset, output devices, edm, diagnostics, bypass control and restart policy, followed by protective-device demand through two input channels, safety logic, safety outputs, contactors or drive enable, energy removal, measured stop and reset authorization. Add advanced features only after the baseline is predictable.

How do I practise dual-channel safety circuit, reset and monitored outputs effectively?

Use short cases with known initial conditions, a written prediction, one action and an observable result. Then alter a boundary or fault and explain why the evidence changed.

What counts as proof of competence?

A repeatable artifact or system result plus an explanation of the signal path is stronger than time spent, screenshots or a copied answer. Physical competence requires separate supervised evidence.

Why test faults and restart behavior?

Because a hazard, device, channel, logic, reset, output, final-device, feedback, stopping, calculation or validation mismatch or cross fault, channel disagreement, welded contactor, held reset, stuck input, supply loss, bypass, diagnostic fault and power return can expose assumptions that never appear during ideal startup and steady operation.

Can browser practice replace official software or hardware?

No. It can build concepts and diagnostic reasoning. Exact firmware, I/O electrical behavior, networking, safety and commissioning require current official tools, documentation and target equipment.

How should progress be documented?

Keep the requirement, initial state, program or configuration, observed values, fault hypothesis, proving action, recovery result and a concise limitations statement.