TIA Portal is the engineering software for Siemens SIMATIC S7 controllers. You can write the same logic as ladder (LAD), function block diagram (FBD) or structured control language (SCL), and some CPU families, such as the S7-300 and S7-400, also support statement list (STL). This page explains ten instructions and block concepts in Siemens terms, shows the equivalent in IEC 61131-3 and gives you a short exercise for each.
Two ideas make Siemens code look different from other vendors. First, bits are usually addressed by absolute area letter and number, such as I0.0 for an input and Q0.0 for an output, with symbolic names layered on top. Second, code and memory are split into blocks: organisation blocks run the cycle, function blocks (FB) own memory, functions (FC) do not, and data blocks (DB) hold values.
What the browser editor does and does not simulate
The exercises run in our browser Siemens dialect, which accepts STL contact statements (A, AN, O, S, R, =) and SCL assignments and block calls, with IEC timers, counters and edge blocks. It does not simulate LAD networks, the MOVE box with EN and ENO, the CMP boxes or instance data blocks as separate objects. Where a unit needs one of those, it says so and the exercise uses the closest simulated form.
How the S7 cycle works and where scan time shows up
An S7 CPU runs the organisation block OB1, the main program cycle, over and over. In the default configuration the CPU copies the physical inputs into the process image of inputs at the start of the cycle, runs the program against that image, and writes the process image of outputs to the physical outputs at the end of the cycle. The program therefore sees one consistent snapshot of the inputs for the whole cycle.
The cycle time is the time for one such pass, including the program and the CPU's own housekeeping. The CPU monitors it against a configurable maximum cycle time, and TIA Portal shows the current, shortest and longest cycle time in the online diagnostics. Interrupt organisation blocks, such as cyclic interrupts, can run in the middle of OB1 when code must run on a fixed period regardless of the main cycle.
Because the snapshot is taken once per cycle, a pulse on an input that is shorter than the cycle can be missed. Peripheral addressing, written with a :P suffix on a tag, reads the module directly instead of the image when a program needs the current value.
A contact asks whether a bit is on or off and lets power through the rung accordingly. Siemens draws them as the same two shapes every ladder language uses: open for "pass when on" and closed for "pass when off".
What it does exactly
In LAD the normally open contact passes when its operand is 1, and the normally closed contact passes when its operand is 0. In STL the same two ideas are A (AND with the bit) and AN (AND with the inverse of the bit); O and ON do the same for parallel branches.
Contacts only read. The operand can be an input such as I0.0, an internal memory bit such as M0.0, an output or a bit inside a data block. A series of contacts is an AND, and a parallel branch is an OR.
The IEC and editor equivalent
The IEC contacts are | SELECT_ON | and | NOT INTERLOCK |, or in structured text SELECT_ON AND NOT INTERLOCK. STL needs no brackets for a plain AND chain: A SELECT_ON, AN INTERLOCK, = LAMP.
What the scan does with it
STL keeps a running result of the chain, and A, AN, O and ON combine it with the next bit. The chain ends at an assignment or a set or reset, which starts a fresh chain for the next statement.
VAR
SELECT_ON AT %I0.0 : BOOL;
INTERLOCK AT %I0.1 : BOOL;
LAMP AT %Q0.0 : BOOL;
END_VAR
A SELECT_ON
AN INTERLOCK
= LAMP
Selector on and interlock off, in STL.
Common mistakes
Reading AN as "and not pressed". It means AND with the inverse of the bit, whatever the bit represents.
Mixing A and O in one chain without brackets. STL evaluates AND before OR, so write A( and ) around a group when you mean to override that.
What you can now do: You can write a normally open and a normally closed condition as A and AN and read them back as a ladder rung.
The coil at the end of a rung writes the answer somewhere: a lamp, a motor contactor or an internal bit. The Siemens assignment coil writes whatever the rung says, every scan, true or false.
What it does exactly
In LAD the output coil is --( )--, in STL it is = and in SCL it is the := assignment. Each cycle it writes the rung result to its operand: 1 when the conditions are true and 0 when they are not. It does not remember anything between cycles.
Assigning the same operand in two places is legal but almost always a mistake, because the statement executed later overwrites the earlier one. One assignment at the end of one rung, with parallel branches or O statements for the alternative conditions, is the clean pattern.
The IEC and editor equivalent
The IEC output coil is := LAMP ; in ladder text, or LAMP := condition; in structured text. TIA Portal also has a negated output coil that writes the inverse.
What the scan does with it
The write goes to the process image of outputs, and the physical output changes when the CPU copies that image out at the end of the cycle. A later statement in the same cycle that assigns the operand again replaces the value before it is ever copied out.
A ALARM_1
O ALARM_2
= HORN
Two alarms, one assignment, using O.
Common mistakes
Duplicating one output in two networks, so one condition seems to be ignored. The compiler does not stop you.
Using = on a bit that should be latched. It will follow the rung and drop the instant the rung drops.
What you can now do: You can merge alternative conditions into a single assignment and avoid the duplicated-output bug.
A set and a reset let you remember something. Set turns a bit on and leaves it on; reset turns it off. Neither one does anything while its own condition is false.
What it does exactly
In LAD these are the --(S)-- and --(R)-- coils, and in STL the S and R statements. When the condition is true, S writes 1 to the operand and R writes 0; when the condition is false, the operand is left exactly as it was. There is also a pair of set-dominant and reset-dominant memory boxes in the instruction tree for the same job.
Which one wins if both conditions are true in the same cycle is decided by the order of execution: the statement that runs last leaves its value. Put the reset after the set to make stop dominate, which is the safe habit for a motor.
The IEC and editor equivalent
These are the IEC set and reset coils, written with the S and R coil symbols in ladder text. In this editor use the STL forms A START, S MOTOR, A STOP, R MOTOR.
What the scan does with it
Because the bit holds its value through false conditions, the result survives from one cycle to the next. After a CPU restart the value depends on whether the operand is retentive, so a latched bit that must survive power loss is placed in a retentive memory area or data block.
A START
S MOTOR
A STOP
R MOTOR
Start sets, stop resets, and the reset runs last so stop wins.
Common mistakes
Setting a bit in one place and resetting it in another with no way to see that from the first, then losing track of who clears it. Keep S and R for one bit next to each other.
Placing the set after the reset for a motor, so a held START beats STOP.
What you can now do: You can latch a bit with S and R and use statement order to decide whether stop or start wins.
The on-delay timer waits before it says yes. The input must stay on for the whole preset time before the output turns on, and any drop in the input starts it over.
What it does exactly
The IEC TON in TIA Portal has the inputs IN and PT, and the outputs Q and ET. PT is a TIME value such as T#3s. ET counts up from zero while IN is true, and Q turns on when ET reaches PT. If IN falls before that, ET returns to zero and Q stays off.
Every timer call needs its own storage, called the instance. You declare it as a variable of type TON, either as its own data block or inside the calling function block, and the instance stores ET, Q and the previous input state. The same instance cannot time two separate things at once.
The IEC and editor equivalent
This is the IEC TON itself, so the call is T_PUMP(IN := PUMP_REQ, PT := T#3s); and the output is T_PUMP.Q. The same names exist in CODESYS and in this editor.
What the scan does with it
The timer works from the CPU clock, so ET reflects real elapsed time rather than a count of cycles. The call has to run every cycle while it is timing. If the code containing the call is skipped, the timer is not evaluated and does not advance.
VAR
PUMP_REQ AT %I0.0 : BOOL;
PUMP_RUN AT %Q0.0 : BOOL;
T_PUMP : TON;
END_VAR
T_PUMP(IN := PUMP_REQ, PT := T#3s);
PUMP_RUN := T_PUMP.Q;
Pump starts three seconds after the request.
Common mistakes
Calling the timer only inside a condition. A call that does not run every cycle cannot time properly.
Reading PUMP_REQ instead of the timer's Q as the pump command, which removes the delay.
What you can now do: You can delay an output with an IEC TON, name IN, PT, ET and Q, and say what the instance stores.
The off-delay timer keeps an output on for a while after its cause has ended, for example a fan that cools a motor down after it stops.
What it does exactly
The IEC TOF has the same pins as the TON: IN, PT, Q and ET. Q is on while IN is true. When IN falls, ET starts counting, and Q stays on until ET reaches PT, then Q goes off. If IN becomes true again before then, ET returns to zero and Q stays on.
This is a delay on turn-off, so the instruction is chosen by what must happen when the signal goes away, not when it arrives. The Q output, not the input, drives the fan.
The IEC and editor equivalent
The call is T_FAN(IN := MOTOR, PT := T#4s); and the fan follows T_FAN.Q. It is the IEC TOF, identical in CODESYS and in this editor.
What the scan does with it
On the cycle IN falls, Q is still on, and it stays on across the following cycles until the clock says the preset time has passed. Because it is time based, scan time does not change the run-on length.
T_FAN(IN := MOTOR, PT := T#4s);
FAN := T_FAN.Q;
The fan runs four seconds after the motor stops.
Common mistakes
Using a TON on the inverted input to imitate a TOF, which switches on at the wrong moment when the input starts false.
Forgetting that Q is on at the very start only if IN was true first; a TOF that has never seen IN true keeps Q off.
What you can now do: You can build a run-on with the IEC TOF and explain what Q does when IN rises and when it falls.
A counter keeps a running tally of events, such as parts passing a sensor, and tells you when the tally has reached a target.
What it does exactly
The IEC CTU in TIA Portal has the inputs CU, R and PV, and the outputs Q and CV. CV is the current count. Each rising edge on CU adds 1 to CV, Q turns on when CV is greater than or equal to PV, and a true R input sets CV back to zero and Q off.
The count lives in the counter's instance, like a timer's state, so each counter in the program is its own instance. The preset PV is an integer, and the data type chosen for the counter (INT is the usual default) sets how high CV can go.
The IEC and editor equivalent
The call is PART_COUNT(CU := PART_SENSOR, R := RESET_PB, PV := 5); and the output is PART_COUNT.Q, the same as the IEC CTU in CODESYS and in this editor.
What the scan does with it
The counter compares the new CU value with the one it stored on the previous call, so it must be called every cycle to see every edge. A pulse shorter than one cycle on a normal input can be missed, so fast sensors use a high-speed counter input instead.
Copying a value from one place to another is the most common data job in a PLC: take the speed the operator typed and hand it to the drive.
What it does exactly
In LAD and FBD the MOVE box has an enable input EN, a source IN and a destination OUT1, plus an enable output ENO. When EN is true the value at IN is copied to the destination, and ENO follows. When EN is false nothing is copied and the destination keeps its old value. In STL the same job is two statements: L loads a value and T transfers it.
MOVE does not convert or scale. Source and destination should be the same data type, or the type conversion boxes must sit in between. In SCL the assignment SPEED_CMD := SPEED_SET; does the same copy.
The IEC and editor equivalent
The IEC function is MOVE. In this editor write SPEED_CMD := MOV(SPEED_SET);. The editor runs it on every scan, so the EN contact of the real MOVE box is not modelled here.
What the scan does with it
MOVE copies the value that exists when it executes. A source that is written later in the same cycle reaches the destination one cycle late, which matters when two blocks pass a value along a chain.
VAR
SPEED_SET AT %IW0 : INT;
SPEED_CMD AT %QW0 : INT;
END_VAR
SPEED_CMD := MOV(SPEED_SET);
Copy the operator's speed set-point to the drive.
Common mistakes
Expecting MOVE to scale a raw analog value. It copies the number as it is.
Moving a value into an input address, which a program must never write.
What you can now do: You can copy a value with MOVE and state when the destination does and does not change.
Compare blocks answer a number question, such as is the temperature above 80?, and give a yes-or-no result a rung can use.
What it does exactly
In LAD the compare contact carries its operator in its name: ==, <>, >, >=, < or <=. The contact is true when the comparison between its two operands holds. Both operands must be the same data type, which you choose on the block, such as Int, DInt or Real.
The comparison is strict for > and <, so a value equal to the limit is not above it. Use >= or <= when the limit itself should count. In SCL the same test is written as an expression, for example IF TEMP > 80 THEN.
The IEC and editor equivalent
The IEC functions are GT, GE, EQ, NE, LE and LT. This editor runs the IEC form IS_HOT := GT(TEMP, 80); because it does not simulate the Siemens compare boxes or SCL comparison expressions.
What the scan does with it
The compare reads its operands when the contact is evaluated, so a value changed by a block later in the cycle is seen on the next cycle. The result is not stored anywhere unless you assign it to a bit.
Most of the time you care that a signal is on. Sometimes you care that it has just turned on. An edge detector gives one scan of "yes" at the moment of change.
What it does exactly
TIA Portal offers two forms. The P_TRIG and N_TRIG instructions (rising and falling edge) take the signal and a separate memory bit that remembers the previous state. The R_TRIG and F_TRIG function blocks do the same job with their own instance data, so they need no hand-picked memory bit.
On the cycle the signal goes from 0 to 1, the output is 1; on every later cycle, even while the signal stays at 1, the output is 0. The falling-edge versions respond to 1 to 0 instead.
The IEC and editor equivalent
The IEC function blocks are R_TRIG and F_TRIG with input CLK and output Q, so the call is AUTO_EDGE(CLK := MODE_AUTO); and the pulse is AUTO_EDGE.Q. These names are the same in CODESYS and in this editor.
What the scan does with it
The pulse lasts exactly one cycle, so everything that uses it must run in that same cycle after the edge block. A block that executes before the edge block in the cycle reads the old value and never sees the pulse.
Siemens splits a program into blocks. Some blocks are only a recipe, some carry a notebook for remembering things between runs, and some are just a table of values. Knowing which is which explains why two timers need two names.
What it does exactly
An organisation block (OB) is called by the CPU, with OB1 running every cycle. A function (FC) is code without memory of its own: its local variables are lost when it ends. A function block (FB) has memory: the values it stores between calls live in an instance data block (instance DB) tied to each call. A global data block (DB) is a named table of values that any block can read.
Standard blocks such as TON and CTU are function blocks, so each use needs its own instance. Calling one instance for two different jobs makes both jobs share one memory. Two pumps need two timer instances, either as separate instance DBs or as multi-instances inside the calling FB.
The IEC and editor equivalent
In IEC 61131-3 the FC and FB correspond to FUNCTION and FUNCTION_BLOCK, and an instance is a variable of the FB type. This editor models the idea directly: declare T_PUMP_A : TON; and T_PUMP_B : TON; and call each once.
What the scan does with it
An instance keeps its stored values from one cycle to the next, which is what lets a timer know how long it has been timing. A call made twice per cycle on one instance runs its logic twice against the same memory, and the second call overwrites what the first stored.
A means AND with the bit, which is a normally open contact in series. AN means AND with the inverse of the bit, a normally closed contact in series. O and ON do the same for parallel branches. These are the international mnemonics, and older German-language projects use U and UN.
What is the difference between an FB and an FC?
A function (FC) has no memory of its own, so its local variables are lost when it ends. A function block (FB) stores values between calls in an instance data block. Timers and counters are function blocks, so each use needs its own instance.
How does an S7 CPU read its inputs?
By default the CPU copies the physical inputs into a process image at the start of each cycle and runs the program against that image, then writes the output image to the outputs at the end of the cycle. Peripheral access with a :P suffix reads a module directly.
Does the browser editor simulate TIA Portal ladder?
No. It runs STL contact statements and SCL assignments and block calls, with IEC timers, counters and edge blocks. LAD networks, the MOVE box with EN and ENO, the compare boxes and separate instance data blocks are not simulated, and the units that cover them say which equivalent the exercise uses.
Training material. Follow your site procedures, local electrical code and the manufacturer's instructions. Lockout/tagout and a qualified person are required for real equipment.