Annex 1 of the Report to the Certificate Z10 17 05 67803 015 Safety-Related Programmable System SIMATIC S7 Distributed Safety Manufacturer: Siemens AG DF FA AS Gleiwitzer Str. 555 D-90475 Nürnberg Revision 2.4 dated 2017-07-27 Testing Body: Rail Automation D-80339 München Certification Body: TÜV SÜD Product Service GmbH Ridlerstrasse 65 D-80339 München Distribution, copying or any other use of information in this report in part is strictly prohibited.
Revision Log Version Name Date Changes/History 1.0 J. Blum 2015-12-18 Initial for IEC 61508(ed.2) 1.1 J. Blum 2016-01-19 Release Number 04 added (SN88143T): F-DI 8x24VDC HF (6ES7 136-6BA00-0CA0) F-DQ 4x24VDC/2A PM HF (6ES7 136-6DB00-0CA0) F-PM-E 24VDC/8A PPM ST (6ES7 136-6PA00-0BC0) 1.2 J. Blum 2016-04-21 Release Number 02 added (FM-Approval): F-RQ 1x24VDC/24..230VAC/5A (6ES7 136-6RA00-0BF0) 2.0 J. Blum 2016-06-06 EN ISO 13849-1:2015 (SN88739T) IEC 61511-1:2016 (SN88739T) Replace certificate (Z10 15 11 67803 009 with Z10 16 06 67803 012) due to updated standard 2.1 C. Dirmeier 2016-10-13 Release Number 05 added (SN90106T): F-PM-E 24VDC/8A PPM ST (6ES7 136-6PA00-0BC0) 2.2 C. Dirmeier 2017-01-27 FW Version V5.0.1 added (SN90400T): 2.3 G. Effenberger 4 F-DO DC24V/2A (6ES7 138-4FB04-0AB0) 2017-05-16 New certificate number Added chapter 1.3 2.4 P. Weiß 2017-07-27 New version of S7 F Configuration Pack (SF91373T): V5.5 SP13 added Module added (SN90962T): F-DQ 8x24VDC/0.5A PP HF (6ES7 136-6DC00-0CA0) Content 1 HARDWARE AND FIRMWARE COMPONENTS... 3 1.1 CPU`S WHICH ARE SUITABLE FOR SAFETY-RELATED APPLICATIONS BY USING A FAIL-SAFE- APPLICATION PROGRAM... 3 1.1.1 CPU ET 200S... 3 1.1.2 CPU ET 200pro... 3 1.1.3 CPU S7-300... 3 1.1.4 CPU S7-400 *... 4 1.1.5 Soft-PLC... 4 1.2 F-MODULES... 5 1.2.1 ET 200SP... 5 1.2.2 ET 200M... 5 1.2.3 ET 200S... 6 1.2.4 ET 200pro... 6 1.2.5 ET 200eco... 7 1.2.6 ET 200iSP... 7 1.2.7 Interference-Free Components... 7 1.3 USE WITH COMPONENTS LISTED IN CERTIFICATE SIMATIC SAFETY SYSTEM... 7 2 SAFETY-RELEVANT SOFTWARE COMPONENTS... 8 3 NON-SAFETY RELEVANT SOFTWARE COMPONENT... 10 Phone: +49 (89) 5791-1473; Fax: -2933 Page 2 of 10
Safety-Certified and Interference-Free Components 1 Hardware and Firmware Components The following system components are certified safety-related. This allows the components to be used to process safety critical signals and functions: 1.1 CPU`s which are suitable for safety-related applications by using a fail-safeapplication program 1.1.1 CPU ET 200S Name Order Number Release Number / Firmware Version IM151-7 F-CPU 6ES7 151-7FA21-0AB0 01 or higher / V3.3.2 or higher IM151-8F PN/DP 6ES7 151-8FB01-0AB0 01 or higher / V3.2.1 or higher 1.1.2 CPU ET 200pro Name Order Number Release Number / Firmware Version IM154-8F PN/DP 6ES7 154-8FB01-0AB0 01 or higher / V3.2.1 or higher IM154-8FX PN/DP 6ES7 154-8FX00-0AB0 01 or higher / V3.2.5 or higher 1.1.3 CPU S7-300 Name Order Number Release Number / Firmware Version CPU315F-2 DP 6ES7 315-6FF04-0AB0 01 or higher / V3.0.0 or higher CPU315F-2 PN/DP 6ES7 315-2FJ14-0AB0 01 or higher / V3.1.0 or higher CPU317F-2 DP 6ES7 317-6FF04-0AB0 01 or higher / V3.3.1 or higher CPU317F-2 PN/DP 6ES7 317-2FK14-0AB0 01 or higher / V3.1.0 or higher CPU317TF-3 PN/DP 6ES7 317-7UL10-0AB0 01 or higher / V3.2.9 / 4.1.5 or higher CPU319F-3 PN/DP 6ES7 318-3FL01-0AB0 01 or higher / V3.2.0 or higher Phone: +49 (89) 5791-1473; Fax: -2933 Page 3 of 10
1.1.4 CPU S7-400 * Name Order Number Release Number / Firmware Version CPU414F-3 PN/DP 6ES7 414-3FM06-0AB0 01 or higher / V6.0.0 or higher CPU414F-3 PN/DP 6ES7 414-3FM07-0AB0 01 or higher / V7.0.0 or higher CPU416F-2 DP 6ES7 416-2FN05-0AB0 01 or higher / V5.0.1 or higher CPU416F-2 DP 6ES7 416-2FP07-0AB0 01 or higher / V7.0.0 or higher CPU416F-3 PN/DP 6ES7 416-3FS06-0AB0 01 or higher / V6.0.0 or higher CPU416F-3 PN/DP 6ES7 416-3FS07-0AB0 01 or higher / V7.0.0 or higher * The sinusoidal vibrations service conditions does not comply with the increased requirements of IEC 61131-2 2 nd and 3 rd Ed. The requirements of IEC 61131-2:1992 are fulfilled. 1.1.5 Soft-PLC Name Order Number Release Number / Firmware Version WinAC RTX F 2010 - --- / V4.5.0 or higher Phone: +49 (89) 5791-1473; Fax: -2933 Page 4 of 10
1.2 F-Modules 1.2.1 ET 200SP F-DI 8x24VDC HF 6ES7 136-6BA00-0CA0 01 to 04 / V1.0.5 8 channel digital input module 24VDC F-DQ 4x24VDC/2A PM HF 6ES7 136-6DB00-0CA0 01 to 04 / V1.0.3 4 channel digital output module 24VDC F-DQ 8x24VDC/0.5A PP HF 6ES7 136-6DC00-0CA0 01 / V1.0.0 8 channel digital output module 24VDC F-PM-E 24VDC/8A PPM ST 6ES7 136-6PA00-0BC0 01 to 05 / V1.0.5 power module 24VDC; P- / M-switch F-RQ 1x24VDC/24..230VAC/5A 6ES7 136-6RA00-0BF0 01 to 02 1 channel digital relay output module 24VDC/5A, 24 230VAC/5A 1.2.2 ET 200M DI 24 x DC24V 6ES7 326-1BK02-0AB0 01 24 channel digital input module 24VDC DI 8 x NAMUR 6ES7 326-1RF01-0AB0 01 8 channel NAMUR digital input module for intrinsically-safe sensors DO 10 x DC 24V/2A PP 6ES7 326-2BF10-0AB0 03 / V1.0.2 10 channel digital output module 24VDC/2A, P-switch DO 8 x DC24V/2A PM 6ES7 326-2BF41-0AB0 01 8 channel digital output module 24VDC/2A, P/M-switch AI 6 x 0/4 20 ma HART 6ES7 336-4GE00-0AB0 04 / V1.0.3 6 channel analog input module, HART Safety Protector 6ES7 195-7KF00-0XA0 04 Safety protector protects the fail-safe signal modules from possible overvoltage Phone: +49 (89) 5791-1473; Fax: -2933 Page 5 of 10
1.2.3 ET 200S 4/8 F-DI DC24V 6ES7 138-4FA05-0AB0 01 / V6.0.3 4/8 channel digital input module 24VDC 4 F-DO DC24V/2A 6ES7 138-4FB04-0AB0 01 / V5.0.0, V5.0.1 4 channel digital output module 24VDC/2A; P/M switch 4F-DI/3F-DO 6ES7 138-4FC01-0AB0 02 4 channel digital input / 3 channel digital output module 24VDC/2A 1F-RO DC24V/5A, AC24...230V/5A 6ES7 138-4FR00-0AA0 03 1 channel digital relay output module DC24V/5A, AC24 230V/5A PM-E F pm DC24V 6ES7 138-4CF03-0AB0 02 Power module 24VDC; P/M switch PM-E F pp DC24V 6ES7 138-4CF42-0AB0 02 Power module 24VDC; P/P switch PM-D F DC24V 3RK1903-3BA02 01 Power module 24VDC for failsafe motor starters 1.2.4 ET 200pro 8/16 F-DI DC24V 6ES7 148-4FA00-0AB0 06 8/16 channel digital input module 24VDC 4/8 F-DI/4 F-DO DC24V/2A 6ES7 148-4FC00-0AB0 06 4/8 channel digital input 24VDC and 4 channel digital output module 24VDC/2A P- / M-switch (combined) F-Switch 6ES7 148-4FS00-0AB0 03 2 channel digital input 24VDC and 3 channel digital P- / P-switch module Phone: +49 (89) 5791-1473; Fax: -2933 Page 6 of 10
24VDC (combined) 1.2.5 ET 200eco 4/8 F-DI DC24V 6ES7 148-3FA00-0XB0 05 4/8 channel digital input module 24VDC 1.2.6 ET 200iSP 4F-DO Ex 17,4V/40mA 6ES7 138-7FD00-0AB0 02 / V1.0.1 4 channel digital output module 17,4VDC/40mA PP-switch 8F-DI Ex NAMUR 6ES7 138-7FN00-0AB0 02 / V1.0.1 8 channel NAMUR digital input module 4F-AI Ex HART 6ES7 138-7FA00-0AB0 02 / V1.0.1 4 channel analog input module, HART 1.2.7 Interference-Free Components All other components of the S7 family are 'interference-free' and allowed to be used; however, they are not certified for process safety critical signals and functions. Using these components does not interfere with the proper functioning of the safety-related modules. For details on architectural, configuration and implementation requirements please refer to the corresponding user manuals. 1.3 Use with components listed in certificate SIMATIC Safety System The following components can also be used with components listed within the certificate of SIMATIC Safety System: - F-CPUs: CPU ET 200S, CPU ET 200pro, CPU S7-300, CPU S7-400 and Soft-PLC - F- modules: ET 200SP, ET 200M, ET 200S, ET 200pro, ET 200eco and ET 200iSP. For details, please see chapter 2.4 of report to the certificate of SIMATIC Safety System. Phone: +49 (89) 5791-1473; Fax: -2933 Page 7 of 10
2 Safety-Relevant Software Components Software Component / Name The Optional Package S7 Distributed Safety includes the following F application blocks and F system blocks: Symbolic name Function in safety program Signature Initial value signature F_SCA_I F application block D8CA 2452 F_CTU F application block 8AC9 2452 F_CTD F application block F77D 2452 F_CTUD F application block 7C8F 2452 F_TP F application block 669E 980D F_TON F application block 6B7E 980D F_TOF F application block 14B4 980D F_ACK_OP F application block 351F A150 F_2HAND F application block EEB8 6EF7 F_MUTING F application block 606B AF14 F_1oo2DI F application block 6AA7 2C7D F_2H_EN F application block 26CD 6EF7 F_MUT_P F application block CB71 7D3C F_ESTOP1 F application block 2E11 AE5E F_FDBACK F application block F521 F965 F_SFDOOR F application block 86DA 76E6 F_ACK_GL F application block 8B12 F2DE F_SENDDP F application block F0B9 4E03 F_RCVDP F application block 42F1 54E4 F_SENDS7 F application block 71D7 9BFF F_RCVS7 F application block 4D3C E1A5 F_SHL_W F application block 4D39 - F_SHR_W F application block E4E3 - F_BO_W F application block 20A5 - F_W_BO F application block BD67 - Version S7 Distributed Safety Programming V5.4 SP5 S7 F-Configuration Pack V5.5 SP11/12/13, G. Effenberger hone: +49 (89) 5791-1473; Fax: -2933 Page 8 of 10
Symbolic name Function in safety program Signature Initial value signature F_INT_WR F application block A78A - F_INT_RD F application block BA20 - F_CTRL_1 F system block 504C BED9 1 F_CTRL_2 F system block 40BA 9E40 F_IO_BOI F system block FAFA B79C F_RTGCO2 F system block D292 7A4A 2 F_IO_CGP F system block EDA2 DC2F F_DIAG_N F system block 99CA 3612 FISCA_I F system block A0FB 50E4 FICTU F system block 2304 A28F FICTD F system block 7AC0 A28F FICTUD F system block E51F E876 FITP F system block 7E15 3326 FITON F system block E1DF ED43 FITOF F system block 69AF 3326 FIACK_OP F system block BDC3 B593 FI2HAND F system block 7131 F85A FIMUTING F system block D5F9 B0C4 FI1oo2DI F system block C2E2 AEAA FI2H_EN F system block 6855 5F72 FIMUT_P F system block E8D5 2C45 FIACK_GL F system block 9FB4 D360 FISHL_W F system block 146E 8E58 FISHR_W F system block AB8F 8E58 FIBO_W F system block 963B BED5 FIW_BO F system block 7A7F BED5 FIINT_WR F system block CFA9 980D FIINT_RD F system block 1D3F 980D 1 To difference the modification of F_CTRL_1 in version 5.4 SP5 from previous versions it is necessary to consider the F_CTRL_1 version (header) 1.6. 2 To difference the modification of F_RTGCO2 in version 5.4 SP5 from previous versions it is necessary to consider the F_CTRL_1 version (header) 1.1. Phone: +49 (89) 5791-1473; Fax: -2933 Page 9 of 10
3 Non-Safety Relevant Software Component Function STEP 7 3 Version V5.3 + Service Pack 3 or higher Munich, 2017-07-27 Rail Automation P. Supavatanakul Technical Certifier 3 Further restrictions specific to modules or versions of the optional package S7 Distributed Safety can be found in the corresponding user documentation. Phone: +49 (89) 5791-1473; Fax: -2933 Page 10 of 10