UrWrench LLC

PLC Maintenance Mastery

The Complete Training Manual - FREE SAMPLE
By Erick T. Colunga | UrWrench LLC
71 Chapters + 4 Appendices  |  520 Knowledge Checks & Review Questions  |  289-Question Final Assessment Pool
From base-level maintenance technician to SME-level PLC knowledge
Written for the maintenance technician who already has the basics - hand tools, a multimeter, and sound electrical skills - this manual builds SME-level PLC knowledge on top of them. Field experience completes the journey. This free sample holds excerpts from 6 of the 71 chapters (Chapters 1, 6, 13, 34, 45, and 60), including an Allen-Bradley ControlLogix platform chapter and a Siemens TIA Portal platform chapter, a preview of the Chapter 71 capstone, 16 of the manual's 289 diagrams, 6 of its 68 photos, the study plan, and the license terms. You can also try the Final Assessment on 10 real questions from its pool, with scoring and explanations, and try Practice mode on 3 chapter Knowledge Checks. Every excerpt is reproduced exactly as it appears in the full manual, diagrams included. On a phone? See how to open the file on a phone or tablet.
The Full Manual

What's in the Full Manual

Here is everything your license includes. Every number below is an exact count from the current edition of the manual.

  • 71 chapters in 16 Parts, from relay logic to the capstone, plus 4 appendices: A, PLC Platform Quick Reference; B, Terms, Acronyms, and Abbreviations; C, Troubleshooting Quick Reference Tables; and D, Other PLC Brands You Will Meet.
  • 16 PLC platforms covered in depth (9 Allen-Bradley, 4 Siemens, and 3 Schneider Electric), plus the legacy Modicon 984. Appendix D introduces the other brands you will meet.
  • 284 Knowledge Checks (four options each, A to D, with the reason each wrong option is wrong) and 236 Review Questions with model answers: 520 in all.
  • 195 worked solutions (model answers) for the Hands-On Exercises in Chapters 1-70.
  • A hands-on capstone in Chapter 71: build, commission, break, and fix a batch mix and transfer skid, with 12 fault cards, a self-grading rubric, and a 20-skill sign-off sheet.
  • 289 technical diagrams drawn inline (ladder logic, wiring, SFC, FBD, timing, network, safety, flowcharts, block diagrams, and simplified software screens). Tap or click any diagram to open it full screen.
  • 68 photos of real hardware and plant equipment.
  • 1,390 callouts: safety warnings, field tips, field experience, learning objectives, and more.
  • A Final Assessment with a 289-question pool, 4 choices per question: each Full Exam draws 135 questions, balanced across the Parts of the book, and 95 correct (70%) passes. Practice mode gives you 20 questions from the chapter Knowledge Checks.
  • A four-semester study plan (about 390 hours) with a 29-chapter core path for maintenance technicians.
  • A printable course completion document for your own records when you pass the Final Assessment. It is not a certification or a license.
  • Search, a Print Section button, and no internet needed: the manual is one HTML file that runs in your browser.
Before You Start

How to Open This File on a Phone or Tablet

This free sample works the same way as the full manual. Here is the full manual's own note, word for word.

The manual is a single HTML file that runs in a web browser and works with no internet connection. On a computer, open it in your browser. On a phone or tablet:

  • Download or save the file to the device first. Do not try to read it from inside an email or a messaging app.
  • Open it in a full web browser, such as Chrome, Safari, or Edge.
  • If the search box or the Reveal Answer buttons do nothing, you are probably in a file-preview app, not a browser. Some preview apps show the text but will not run the search, the quizzes, or the Final Assessment. Open the file in a browser instead.
  • Give it a moment to load, because it is a large file. Turn the device sideways for wide tables, and zoom in on a diagram when its labels are small.

A tablet or a computer is the better screen for long study sessions and for the Final Assessment.

Delivery: Send Download Links, Not Email Attachments

To pass the manual to the people your license covers, send a link to the file, not the file itself. Many company email systems block or strip .html attachments, and the file is large. Business licensees can keep the file on a secured internal drive or LMS, as the license terms allow, and send the link from there.

From the Full Manual's Front Matter

Recommended Study Plan - Four Semesters

This plan is laid out the way colleges schedule technical coursework, in 16-week semesters: four of them at about 6 hours a week, roughly 390 hours in all. If you can give it about 12 hours a week, the accelerated option finishes in two semesters. Combine reading with hands-on practice whenever possible.

📘 Why This Book Is Long, and How to Use It

This manual is long on purpose, and you are not meant to read every page with the same care. It holds about 1.2 million words because it does three jobs at once:

  • A course. It takes you from relay logic to troubleshooting, maintaining, and protecting PLC systems, with Knowledge Checks, Review Questions, Hands-On Exercises, and a capstone.
  • A multi-brand reference. It covers 16 platforms from Allen-Bradley, Siemens, and Schneider Electric, plus the other brands in Appendix D, because a technician works on whatever the plant bought. About a quarter of the book is the platform chapters (30-48), and most readers study only the ones for their own plant.
  • A manual for the job. Each chapter is written to be opened again on a breakdown call, months after you first read it. That is why chapters repeat the key safety points and point you to the sections you need, instead of assuming you remember a page from another Part.

Use it in layers:

  • Core versus reference. The core path below is 29 chapters, a little over 40 percent of the text. Study those in depth, add the platform track and systems chapters for your plant, and read the rest once, lightly, coming back when you need it.
  • The Quick Guide. Near the top of every chapter, a box tells you whether the chapter is core or reference for you and lists the points that matter most “if you only have 20 minutes.” In Chapters 1-29 and 53-71 the box is titled Quick Guide and includes a one-page checklist to print and keep where you do the work. In the platform and HMI chapters (30-52) it is titled “Core or Reference?”. Read it before the chapter, and again when you review.
  • The fast track. If you need to be useful on PLC faults soon, the Troubleshooter Fast Track below gets you started in about 48 hours over 8 weeks, and then leads into the full plan.

How to Read This Manual

The chapters build on each other, and most readers should take them in order. Six reading paths matter more than the chapter numbers.

âš  Safety First: Chapter 6 Before Any Hands-On Work in the Plant

Everyone reads Chapter 6, Safety in PLC Work: Electrical Hazards, LOTO, and Arc Flash, before doing any hands-on work in the plant - opening a cabinet, taking a meter reading, or any exercise that puts you in front of live equipment. It is numbered 6 because it builds on the electrical fundamentals in Chapter 5, but it is one of the shorter chapters. If you want to do the cabinet exercises in Chapters 1, 4, and 5 as you reach them, read Chapter 6 first. Until you do, those exercises are look-only or done alongside a qualified person, as each one explains. Your site’s electrical safety and LOTO procedures always take priority over this book.

The Core Path for Maintenance Technicians

If your job is keeping machines running, you do not have to study every page in depth. Start with the core path: 29 chapters, a little over 40 percent of the book, built around finding and fixing faults. Take them in order, using the semester plan below as your calendar and skipping the rows that hold only reference chapters for you. Then add the chapters for the equipment in your own plant.

TrackChaptersHow to Use Them
Core (everyone)1, 3-10, 12-19, 26, 49, 53, 57-64, 71Study in depth. Foundations, safety, and I/O (1, 3-10); reading and editing programs (12-19); networking fundamentals (26); HMI fundamentals (49); VFDs (53); the whole troubleshooting Part (57-62); preventive maintenance, backup, and change management (63-64); and the capstone (71).
Your plantAllen-Bradley: 27, 30-40, 50
Siemens: 28, 41-45, 51
Schneider: 46-48, 52
Other brands: Appendix D
Systems: 11, 20-25, 29, 54-56
Study in depth only the platform chapters for the brands in your plant, and within a brand, the families you actually have (a plant with ControlLogix and no PLC-5 studies Chapters 34 and 35 and treats Chapter 31 as reference). Do the same for systems: Chapter 11 for thermocouples, RTDs, and high-speed counters; Chapters 20-22 for the languages your programs use; Chapters 23-25 in a process plant; Chapter 29 for Modbus, DeviceNet, or ControlNet; Chapter 54 for servo and motion; Chapters 55-56 if your plant has safety PLCs.
Reference2, 65-70, and the platform chapters for brands you do not haveRead once, lightly, and come back when you need them. In Chapter 2, read Section 2.12, which introduces the 16 platforms the manual covers. Appendices A-C are quick references for the whole book.

The core path is a starting point, not a finish line. The Final Assessment draws questions from all 71 chapters (Chapters 1 through 70, plus fault-diagnosis questions from the Chapter 71 capstone, usually two per attempt), so if you plan to take it, read the rest of the book at least once first. That is the default “All platforms” track. When you start the Full Exam you can instead choose a platform track that matches the Your plant row above: Allen-Bradley focus, Siemens focus, or Schneider focus. A brand track leaves out the other two brands’ chapters from that row (the Siemens focus, for example, leaves out Chapters 27, 30-40, and 50 for Allen-Bradley and Chapters 46-48 and 52 for Schneider). It still has 135 questions, and each Part of the book keeps its share of the questions that remain. Questions from the shared chapters can still use an example from any brand, as those chapters do. The track is printed on the completion document and in the exported results. Platform Tracks, below, says what a focus track still includes.

Platform Tracks: Allen-Bradley, Siemens, and Schneider Electric Plants

This table spells out the “Your plant” row above by brand. Follow the track for the controllers in your plant; a plant with two brands follows both tracks. On each track, the track core chapters are for everyone in that plant, and the by family chapters are for the controller families and panels you actually have. The other brands’ platform chapters (Parts VI-VIII) stay reference for you. Several core chapters also have sections written for one brand at a time; the last column lists the ones for your brand, and they belong to your study of those core chapters.

TrackTrack CoreBy Family (Study the Ones You Have)Your Brand’s Sections in Core Chapters
Allen-Bradley plant27 (EtherNet/IP); 30 (the Allen-Bradley map for Chapters 31-40)Logix controllers (ControlLogix, CompactLogix, GuardLogix): 34 and 39, then 35 for ControlLogix 5580 or CIP Security, 36 for CompactLogix 5370, 37 for CompactLogix 5380
SLC 500 and MicroLogix: 32 and 40, plus 33 for MicroLogix (a MicroLogix plant with no SLC 500 still reads Sections 32.5-32.8)
PLC-5: 31
Micro800: 38
PanelView or FactoryTalk View: 50
DeviceNet or ControlNet: 29
GuardLogix safety and CIP Safety: 55-56
53.4 (drives over EtherNet/IP); 58.1-58.6 (Allen-Bradley faults; 58.3 for RSLogix 500); 59.3 (forcing); 60.5 (EtherNet/IP troubleshooting); the Allen-Bradley parts of 63.7 and 64.6 (preventive maintenance and backup)
Siemens plant28 (PROFINET and PROFIBUS); 41 (the Siemens map for Chapters 42-45)S7-300 or S7-400 with STEP 7 Classic: 42
S7-1200: 43
S7-1500 or ET 200SP: 44, after 43
Any controller programmed in TIA Portal: 45, after 43 and 44
Siemens HMI panels and WinCC: 51
Safety PLCs and PROFIsafe: 55-56
53.5 (drives over PROFINET); 58.7-58.9 (diagnostic buffer, LEDs, reading diagnostics in the program); 59.4 (forcing); 60.6 (PROFINET troubleshooting); the Siemens parts of 63.7 and 64.6
Schneider Electric plant46 (the Modicon map for Chapters 47-48); Chapter 29 Sections 29.1-29.4 and 29.10 (Modbus, the Modicon’s native protocol)Modicon Quantum or 984: 47
Modicon M340 or M580, or a Quantum-to-M580 migration: 48
Magelis, Harmony, or third-party OEM panels: 52
Safety PLCs, including M580 Safety: 55 (and Section 48.7)
53.6 (drives over Modbus); 58.10-58.11 (%SW system words and LEDs); 59.5 (forcing); 60.7 (Modbus troubleshooting); the Schneider parts of 63.7 and 64.6

For controllers from other brands, add Appendix D to the core path and to whichever track your plant also follows. For each brand it covers the product families, the software, the addressing, going online and taking a backup, and where the fault information lives, and Section D.8 maps the vocabulary you already know onto each one. For a brand the book does not cover, use the method in Section 57.11 for a controller you have never seen.

Siemens and Schneider tracks: the Allen-Bradley comparisons. The Siemens and Schneider chapters often explain a feature by comparing it with its Allen-Bradley equivalent, and Chapter 43 compares the S7-300 to S7-1200 move with the SLC 500 to CompactLogix move that Part VI covers. You do not need the Allen-Bradley platform chapters to follow them. The core programming chapters (12-19) teach mostly with Allen-Bradley Logix examples and have platform-difference sections (such as 14.6, 15.13, 16.14, and 17.15), so you will already know the terms the comparisons use. The mapping sections (41.7 and 46.3) translate the product lines, and Section 45.19 translates everyday TIA Portal and Studio 5000 tasks. Treat the side-by-side comparison sections (42.13, 43.9, 44.15, 47.15, 48.10, and 51.11) as optional: skim them for the translation and skip the Allen-Bradley detail.

Your track and the Final Assessment. The exam’s platform tracks, chosen in Exam Setup when you start the Full Exam, use the brand chapter lists in the “Your plant” row of the Core Path table (Allen-Bradley 27, 30-40, and 50; Siemens 28, 41-45, and 51; Schneider 46-48 and 52). A focus track leaves out the other two brands’ lists. It does not leave out the shared chapters, such as Chapter 29 and Chapters 55-56, or your own brand’s chapters for families your plant does not have: on the Allen-Bradley focus, for example, the PLC-5 and SLC 500 chapters are still in the exam. So before an attempt on a focus track, read every chapter on your brand’s list at least once, not only the families you have. The default All platforms track draws from every chapter.

The Troubleshooter Fast Track: Useful on Faults in 8 Weeks

If you already work in maintenance and need to be useful on PLC faults soon, start here. The fast track takes about 48 hours: 8 weeks at about 6 hours a week, or 6 weeks at about 8 hours a week. It uses the Quick Guides at the top of the chapters, Chapter 6 in full, the key sections of the troubleshooting Part (Chapters 57-62), the platform chapters for your plant, and Appendix C.

It is a starting path, not a replacement for the full plan. It teaches you to work a fault on a machine that was running yesterday: safely, methodically, and from evidence. It does not teach you to write, commission, or change control programs, it covers only part of the core path, and it does not prepare you for the Final Assessment. When you finish, go on to the core path and your platform track from Chapter 1, with the semester plan as your calendar. The sections you studied on the fast track will go faster the second time, and you will read them again with a working method behind them.

How to work each week:

  • Quick Guide first. Read the chapter’s Quick Guide before its sections: the 20-minute list and, where the chapter has one, the one-page checklist. Print the checklists for Chapters 6, 7, 8, 57, 59, and 60 and keep them with your tools.
  • Then the sections. Read the listed sections in full. Then try all of that chapter’s Knowledge Checks; if one covers a section you skipped, read that section before you reveal the answer.
  • Then the exercises. Do the listed exercises in their paper, practice, or bench version. A workplace extension needs your supervisor’s authorization and comes after Chapter 6, and no exercise is ever a reason to change a running machine.
  • The fault-card drill. At the end of weeks 3-8, open the named capstone fault card in Section 71.9 and read only its Symptom and Hints. Write down the domain you would suspect first (from week 5 on, use the five domains in Section 57.3), your first three checks in order, and what each result would tell you. Do not open its Reveal Answer: row 18 of the Chapter 71 skills sign-off sheet asks you to solve a fault card you have not seen solved, so keep the answers for the day you work the card on a bench.
WeekStudyExercises and DrillsHours
1Safety first. Chapter 6 in full: the qualified person, LOTO for PLC cabinets, arc flash, NFPA 70E, when energized work is justified, stored energy, and voltage testing.Chapter 6 Exercise 1 (LOTO Procedure Walkthrough) and Exercise 3 (Meter Inspection and Lead Test), practice versions; every Knowledge Check and Review Question in Chapter 6.6
2How the PLC thinks. Chapter 3: Quick Guide; Sections 3.2 and 3.3 (the scan cycle and image tables), 3.9-3.11 (power-up and power-down, operating modes, fault handling), and 3.13. Chapter 1, if relay schematics are new to you: Sections 1.5, 1.8, and 1.11. Chapter 12: Quick Guide, and Section 12.10 if you will practice on a simulator or a bench.Chapter 3 Exercise 1 (Draw the Scan Cycle from Memory) and Exercise 4 (Failure Analysis); Chapter 1 Exercise 2 (Seal-In Circuit Trace), practice version.6
3Inputs and outputs at the terminal. Chapter 7: Quick Guide; Sections 7.1 (sinking and sourcing) and 7.8-7.10 (leakage current, LED indicators, diagnosing failed inputs). Chapter 8: Quick Guide; Sections 8.8 (fuse protection) and 8.11-8.13 (output failure modes, the troubleshooting procedure for failed outputs, common field problems).Chapter 7 Exercise 3 (Sinking vs. Sourcing Wiring Sketch); Chapter 8 Exercise 2 (Flyback Suppression Inspection), practice version. With a bench, also Chapter 7 Exercise 2 and Chapter 8 Exercise 3. Fault-card drill: Fault Cards 1 and 2.6
4Reading the logic. Chapter 13: Quick Guide; Sections 13.2-13.5, 13.7-13.9, 13.12, 13.16, and 13.18. Chapter 14: Quick Guide; Sections 14.2-14.6, 14.9, and 14.10. Chapter 15: Quick Guide.Chapter 13 Exercise 3 (Existing Program Rung Analysis), on the sample program in Section 12.11 or, with authorization, a plant program opened read-only; Chapter 14 Exercise 1 (Timer Timing Diagram Trace). Fault-card drill: Fault Cards 8 and 9.6
5The troubleshooting method. Chapter 57: Quick Guide; Sections 57.1-57.8 (the mindset, the troubleshooting cycle, the five domains, fault trees, half-splitting, the 5 Whys, information gathering, common traps) and 57.13-57.15 (documentation, real-world scenarios, the reference checklist). Appendix C: print it, read Section C.9 (the quick diagnostic decision tree), and scan Sections C.1-C.4.Exercise 57.1 (Troubleshooting Methodology Drill), paper version on the Section 57.3 story, so your fault cards stay unseen; Exercise 57.2 (Diagnostic Tool Preparation). Fault-card drill: Fault Card 3.6
6Fault codes and forcing. Chapter 58: Quick Guide; the sections for your platform (Logix: 58.1, 58.2, and 58.4-58.6; SLC 500 and MicroLogix: 58.1 and 58.3; Siemens: 58.7-58.9; Schneider: 58.10 and 58.11), then 58.12 and 58.13. Chapter 59: Quick Guide; Sections 59.1, 59.7-59.9, 59.11, 59.12, and 59.15, plus your platform’s section (59.3, 59.4, or 59.5).Exercise 58.1 (Fault Code Reference Guide Creation), paper version for the platform closest to yours; Exercise 59.2 (Force Policy Development). Fault-card drill: Fault Card 7.6
7Your plant’s platform. The chapters on your platform track (see the table above): read each one’s “Core or Reference?” box and 20-minute list, then the sections you will use on a breakdown call. Logix: 34.11, 39.8, 39.12, 39.13, and 39.18. SLC 500 and MicroLogix: 32.10, 40.6, 40.9, 40.13, 40.14, and 40.19. Micro800: 38.6, 38.12, and 38.15. S7-300 and S7-400: 42.10, 42.11, and 42.15. S7-1200 and S7-1500 in TIA Portal: 43.12, 44.3, 44.12, 45.8-45.11, 45.17, and 45.18. Modicon: 46.6, then 47.13 and 47.16 (Quantum) or 48.5 (M340 and M580).One exercise in your own software, on a bench, a simulator, or an offline copy: Chapter 39 Exercise 2 (Complete Cross-Reference Trace); Chapter 32 Exercise 3 (Tracing an Output with Cross-Reference) or Chapter 40 Exercise 3 (Compare Online vs. Backup); Chapter 38 Exercise 2 (Motor Start/Stop with a Run Timer); Exercise 45.2 (Watch Table and Cross-Reference Practice); or Exercise 48.2 (Control Expert Project Exploration). Fault-card drill: Fault Cards 10 and 12.6
8Networks and intermittent faults. Chapter 26: Quick Guide; Sections 26.4, 26.5, 26.8, and 26.9. Chapter 60: Quick Guide; Sections 60.1, 60.2, 60.4, your network’s section (60.5 EtherNet/IP, 60.6 PROFINET, or 60.7 Modbus), and 60.12. Chapter 62: Quick Guide; Sections 62.1, 62.7, 62.15, and 62.16. Chapters 61 and 64: Quick Guides.Exercise 60.13.3 (IP Address Spreadsheet), bench version or, with authorization, the workplace extension; Exercise 61.15.2 (Neutral-to-Ground Voltage Check), paper version. Fault-card drill: Fault Card 11. Then the milestone check below.6
âš™ Fast Track Milestone

At the end of the fast track, you should be able to:

  • Put a PLC cabinet in a safe state under your site’s LOTO procedure, prove your meter with test-verify-test, and recognize when a task becomes energized work that needs a qualified person (Chapter 6).
  • Explain what the scan cycle and the image tables mean for what you see online, and what a controller does on power-up, in each operating mode, and on a fault (Chapter 3).
  • Decide whether a failed input or output is in the field device, the wiring, or the I/O point, from the indicators, the tag online, and meter readings taken one point at a time (Chapters 7 and 8).
  • Read a rung aloud in one sentence, find the first false instruction, and follow a seal-in, an interlock, or a timer while the machine runs (Chapters 13 and 14).
  • Work any fault with the troubleshooting cycle: observe, ask what changed, name the domain, test one hypothesis at a time, prove the fix, and write the root cause and the work-order entry (Chapter 57 and Appendix C).
  • Read and record the fault log or diagnostic buffer on your plant’s controllers, check for forces every time you go online, and follow the forcing rules (Chapters 58 and 59).
  • Use cross-reference, a watch or data monitor table, and the compare tool in your plant’s software to find where a tag is written and what changed (your platform track).
  • Find a duplicate IP address or a bad cable, and start a log for an intermittent fault (Chapters 26, 60, and 62).

Check yourself honestly against each line, and go back to the week behind any line you cannot do yet. If you have a practice bench (Section 12.10), ask a qualified supervisor, lead technician, or mentor to watch you perform rows 1, 4, 5, 14, and 16 of the Chapter 71 skills sign-off sheet (Section 71.11). Those initialed rows are your fast-track record. Then start the core path.

Already on the semester plan? A maintenance group that follows the full plan can bring troubleshooting forward without the fast track: read the Chapter 57 Quick Guide and Sections 57.1-57.3 (about 40 minutes of reading) right after Chapter 8, in weeks 7-9 of Semester 1, and use them on every exercise from then on. Study the whole chapter in its place in Semester 3.

Software Early: Chapters 39 and 45 Alongside Part III

Part III (Chapters 12-22) teaches programming. If you already have access to Studio 5000 Logix Designer or TIA Portal, you can read Chapter 39 (Studio 5000 Mastery) or Chapter 45 (TIA Portal Mastery) alongside Part III and practice each programming chapter in the real software, instead of waiting for Parts VI and VII. Practice on a bench controller or a simulator, never on a controller that runs a machine. If you do not have either package, follow the paper and simulator paths in the Set Up Your Practice Lab section of Chapter 12: work each exercise on paper, then enter it in a free or low-cost simulator as soon as you have one.

Experienced Electricians and Technicians: What You Can Skim

If you already work on industrial controls, you can skim - not skip - these chapters, then use their Knowledge Checks to confirm you have not missed anything:

  • Chapter 1 (Relay Logic) if you already read and troubleshoot relay ladder schematics and seal-in circuits.
  • Chapter 2 (History of the PLC) - it is context, not technique. Read Section 2.12, which introduces the 16 platforms the manual covers.
  • Chapter 5 (Electrical Fundamentals) if you are an experienced industrial electrician, but read Section 5.3 (grounding and bonding) and Section 5.8 (PLC-specific meter measurements).
  • Platform chapters for hardware your plant does not have, such as the PLC-5 (Chapter 31) or Modicon Quantum (Chapter 47). Come back to them when you meet that hardware.

Do not skim Chapter 3 or Chapter 6. The scan cycle and image tables in Chapter 3 are where experienced electricians most often get caught out, and Chapter 6 covers PLC-specific hazards - separate feeds, backfeed, and stored energy - that general LOTO training often misses. The Final Assessment draws questions from Chapters 1 through 70 and includes fault-diagnosis questions from the Chapter 71 capstone (usually two per attempt); the capstone itself is assessed hands-on with its rubric and skills sign-off sheet.

📘 The Capstone: Build, Break, and Fix

Chapter 71, “Capstone: Build, Break, and Fix,” comes after Chapter 70. Set up your practice lab early - the Set Up Your Practice Lab section of Chapter 12, in weeks 3-4 of the plan below - and grow it as you go, then complete the capstone on it before you take the Final Assessment. The plan gives the capstone eight weeks of its own. You do not have to wait until the end to start: watch for the running “Capstone Project Step” callouts in earlier chapters, which let you work toward the capstone as you learn each skill.

How Long This Manual Takes

This is a big book, and it deserves an honest schedule. The chapters and appendices hold about 1.2 million words in all, counted from the current text in September 2026. About 178,000 of them, roughly 15 percent, are the answers, explanations, and worked solutions behind the Reveal buttons, which you work through as part of the Knowledge Checks, Review Questions, and Hands-On Exercises below. About 37,000 more are the labels inside the diagrams. The main text is about 985,000 words: about 960,000 in the 71 chapters and about 26,000 in Appendices A-D. Read at the pace that technical material full of new ideas really takes - about 130 words a minute - the main text and the diagrams take about 130 hours of reading. The core path alone is about 400,000 words of main text; with its diagrams, that is about 54 hours of reading. Reading speed varies from person to person: at 100 words a minute the main text and the diagrams take about 170 hours, and at 160 words a minute about 107.

This plan was first drawn up for about one million words and about 120 hours of reading. The chapters have grown since then, so the figures here are recounted from the current text, and the total, the Semester 3 hours, and the training-manager figure below have gone up to match. Then add the work that turns reading into skill:

  • About 50 hours for the Knowledge Checks and for writing out answers to the Review Questions. That includes reading the explanations and model answers behind their Reveal buttons, about 100,000 words.
  • About 130 hours for the Hands-On Exercises and the running Capstone Project Steps. That includes checking your work against the worked solutions, about 71,000 words.
  • About 6 hours to set up a simulator-only practice lab, or about 12-20 hours to build and test a first hardware bench (Section 12.10). The total below assumes the simulator path, so add 6-14 hours if you build the bench.
  • 40-80 hours for the Chapter 71 capstone, depending on how far into the extended tier you go. The plan gives the core capstone about 50 hours.
  • About 20 hours for the semester reviews, the final review, and the Final Assessment.

That comes to roughly 390 hours (about 386 by the figures above, and 391 in the semester tables below) - more if you read slowly or do every extended exercise, less if you skim the chapters the reading paths above allow. For comparison, a college semester credit hour stands for about 45 hours of work (one hour in class and two hours outside it, each week of a roughly 15-week semester), and a community college’s two-course PLC sequence - an introductory PLC course and a PLC applications course, each with weekly labs - runs about 300-350 hours of class, lab, and homework. This manual asks for a similar total, spread over more topics, with your own practice lab standing in for the college lab.

Choose Your Pace

PlanLengthHours per WeekWho It Fits
Standard: four semesters64 weeks (four 16-week semesters)About 6 (about 6.5 in Semester 3)Technicians studying around a full-time job. The weekly load is about that of one two-credit college course.
Accelerated: two semesters32 weeks (two 16-week semesters)About 12 (about 13 while you work through Semester 3)Learners with more time, or an employer-sponsored program. The weekly load is about that of a lab-based college PLC course. Work two plan weeks every calendar week: your first semester covers Semesters 1 and 2 below, and your second covers Semesters 3 and 4.

Training managers: the standard plan gives each learner about 195 hours of related instruction a year for two years, more than the 144 hours a year the U.S. Department of Labor recommends for registered apprenticeships. Pair it with supervised time on real equipment and the skills sign-off sheet in Chapter 71.

The Four-Semester Plan

Each semester is 16 weeks. The load is balanced by the actual length of each chapter and its exercises, so some rows cover four chapters and some cover one. The last week of each semester includes a review: rework the Knowledge Checks you missed and redo the Review Questions you found hardest before you move on.

Semester 1: Safety, Foundations, I/O, and Core Programming (about 93 hours)

WeeksChaptersFocus AreaHours
1-2Chapter 6, then Chapters 1-2Safety first; relay logic; the invention of the PLC12
3-4Chapter 3; Chapter 12: Set Up Your Practice LabHow a PLC works; install your software and order any hardware now, so your lab is ready when programming starts in week 1011
5-6Chapters 4, 5, 7Hardware, electrical fundamentals, digital inputs12
7-9Chapters 8-11Digital outputs, analog inputs and outputs, specialty I/O17
10-12Chapters 12-14Programming concepts, ladder logic, timers - on your practice lab16
13-14Chapters 15-16Counters; comparison and math instructions12
15-16Chapters 17-18 + reviewData handling; program flow and organization; semester review13

Semester 2: Advanced Programming, Process Control, Networks, and Allen-Bradley (about 96 hours)

WeeksChaptersFocus AreaHours
1-2Chapters 19-20Sequencers and state machines; Function Block Diagrams11
3-4Chapters 21-22Structured Text; SFC and IL11
5-6Chapters 23-24Process control fundamentals; PID configuration and tuning11
7-9Chapters 25-28Instrumentation; networking fundamentals; EtherNet/IP; PROFINET and PROFIBUS18
10-12Chapters 29-33Modbus, DeviceNet, ControlNet, and other protocols; the Allen-Bradley ecosystem; PLC-5; SLC 500; MicroLogix20
13-16Chapters 34-39 + reviewControlLogix 5570 and 5580; CompactLogix 5370 and 5380; Micro800; Studio 5000 Mastery; semester review25

Semester 3: Siemens, Schneider, HMIs, Drives, Safety Systems, and Troubleshooting (about 104 hours)

WeeksChaptersFocus AreaHours
1-2Chapters 40-42RSLogix 500 Mastery; the Siemens ecosystem; S7-300 and S7-40012
3-4Chapters 43-45S7-1200; S7-1500; TIA Portal Mastery13
5-6Chapters 46-48 + Appendix DSchneider Electric Modicon platforms; Other PLC Brands You Will Meet11
7-8Chapters 49-51HMI fundamentals; PanelView and FactoryTalk View; Siemens HMI panels and WinCC13
9-10Chapters 52-54Magelis and other HMIs; VFDs; servo and motion control12
11-13Chapters 55-58Safety PLCs and safety networks; systematic troubleshooting; fault codes and diagnostics21
14-16Chapters 59-62 + reviewI/O forcing; communication troubleshooting; power quality; intermittent faults; semester review22

Semester 3 is the heaviest semester for reading: its platform, safety-system, and troubleshooting chapters are long, and reading alone fills close to half of each row’s hours. It runs about 104 hours, or about 6.5 hours a week. The 10 hours added when the plan was recounted went here, 8 of them to weeks 11-16, so the troubleshooting chapters keep enough time for their exercises. If 6.5 hours a week is more than you have, take 18 weeks for this semester instead of 16, and slide the rest of the schedule.

Semester 4: Maintenance Programs, Cybersecurity, Career, Capstone, and Final Assessment (about 98 hours)

WeeksChaptersFocus AreaHours
1-2Chapters 63-65Preventive maintenance; backup and change management; spare parts13
3-4Chapters 66-68Documentation; industrial cybersecurity; remote access11
5Chapters 69-70Career pathways; growing your lab and continuing education7
6-13Chapter 71Capstone: build and commission the skid, run the functional tests, then break and fix it with the twelve fault cards50
14-15Chapter 71 + Appendices A-CCapstone portfolio, self-grading rubric, and skills sign-off with an experienced technician; final review with the quick-reference appendices12
16Final AssessmentTake a Practice Mode quiz, then the 135-question Final Assessment5

The capstone’s optional extended tier adds about 15-25 hours. Give it three or four more weeks, before or after the Final Assessment.

âš™ Study Tip

Plan on about 6 hours of study a week on the standard plan, or about 12 on the accelerated plan, and treat the Hands-On Exercises as part of the plan, not an extra - that is where most of the hours go. Review each chapter’s Knowledge Checks and Review Questions before moving on to confirm understanding. If you fall behind, slide the whole schedule rather than squeezing the next rows: the troubleshooting chapters in Semester 3 and the capstone in Semester 4 are the last places to cut corners. The chapters build on each other, so apart from the reading paths above, skipping ahead will leave gaps that make later material harder to absorb.

For Instructors and Training Managers

The manual can run as a structured course as well as self-study. Here is how to set it up.

  • Syllabus. Use the four-semester plan above as the course calendar: each row gives the weeks, chapters, focus, and hours. The accelerated plan fits a program that meets about 12 hours a week. For a maintenance crew with limited study time, assign the core path plus the chapters for your plant’s brands; the platform tracks above list them by brand and controller family.
  • A fast start for a crew. For technicians who need to be useful on faults soon, assign the Troubleshooter Fast Track first (8 weeks at about 6 hours a week, about 48 hours), then the core path and the platform track. The fast-track milestone and rows 1, 4, 5, 14, and 16 of the Chapter 71 skills sign-off sheet give you something to check and file at the end of the 8 weeks. The fast track does not replace the core path, and it does not prepare a learner for the Final Assessment.
  • Progress checks. Each chapter opens with its learning objectives, and its “How this chapter checks your progress” map shows which Knowledge Checks, Review Questions, and Hands-On Exercises cover them. The answers are in every learner’s copy behind the Reveal buttons, so use the Review Questions as written or spoken assignments and grade the reasoning, not just a letter.
  • Hands-on proof. The Chapter 71 capstone is the practical exam. Score it with its rubric - a score of 1 or 2 in Safety means the capstone is not complete, whatever the total - and have a supervisor, lead technician, or mentor who is qualified on the equipment watch each skill and initial the skills sign-off sheet in Section 71.11. That sheet, not the written test, is the record of hands-on skill.
  • The Final Assessment. It runs inside each learner’s own copy of the manual. By default it is self-administered and open book: the learner may use the manual and notes, and the exam screen and the completion document say so. If your program relies on it, supervise it: have a proctor watch the attempt, closed book, and file the result with the Chapter 71 sign-off sheet. So that the record matches, the proctor ticks “Proctored, closed-book attempt” in Exam Setup on the exam menu (and can enter their name) before the learner starts. The completion document and the exported results then state that the attempt was declared proctored and closed book, and the proctor signs page 2 of the completion document; the file cannot check the declaration itself. The Full Exam has a 3-hour time limit and a 24-hour wait between attempts for the same name. The time limit counts from the moment the attempt starts and keeps running if the learner closes the exam, returns to the menu or reloads the page, so closing the exam to search the manual does not stop the clock. In Exam Setup you or the learner can also choose a platform track (All platforms, Allen-Bradley focus, Siemens focus, or Schneider focus) to match the Your plant chapters in the Core Path table; the track is recorded too. The exam menu lists every Full Exam attempt made in that browser, the completion document shows the attempt number and how many Full Exam attempts were started in that browser in the last 24 hours under any name, an attempt finished in less than 30 minutes is flagged as unusually fast with the minutes it took, and the Export My Results button saves a small results file you can keep in your training records. The 70% pass mark is a conventional cut score, common in self-study programs; it was not set by a formal standard-setting study, so your program may set its own, using the exact number correct in the export. The course completion document is for the holder’s own records. It is not a certification or a license, and it does not replace the safety training your site is required to provide.
  • Plant exercises. An exercise that puts a learner in front of live plant equipment needs your site’s authorization and a qualified person, and Chapter 6 comes first.
  • Licensing. The Business License covers training inside one company. For any other arrangement, such as a school or a program that serves several employers, ask at sales@urwrench.com before you start.
Free sample excerpt: Chapter 1, Sections 1.1 and 1.2 in full, with Knowledge Check 1.1. Reproduced exactly as it appears in the full manual, diagrams included.
Chapter 1

The Birth of Industrial Control: Relay Logic and Hardwired Systems

Before there were programmable logic controllers, before there were touchscreens and Ethernet cables running across factory floors, there were relays. Thousands of them. Bolted into metal cabinets the size of walk-in closets, wired together by hand, humming and clicking every second of every shift. If you want to understand PLCs, you have to understand what came before them - because a PLC does not do anything new. It does the same job relays did, just faster, smaller, and without all the wiring. This chapter is where you build your foundation. Everything in this manual grows from the soil we lay down right here.

📘 Learning Objectives

By the end of this chapter, you will be able to:

  1. Identify a relay's coil and contacts, and state whether each NO and NC contact is open or closed with the coil energized and de-energized
  2. Distinguish a control relay, a contactor, and a motor starter, explain what the overload relay adds, and recognize a common contactor fault such as a buzzing coil
  3. Trace current through a seal-in start/stop circuit step by step, and explain why the Stop button is NC and the auxiliary contact is wired in parallel with Start
  4. Arrange series (AND) and parallel (OR) contacts to meet a written control requirement
  5. Read a relay ladder diagram: find its contacts and coils, and describe one rung from L1 to L2 in plain words
  6. List the maintenance and change problems of hardwired relay panels that led to the PLC

How this chapter checks your progress: Objective 1: Knowledge Check 1.1; Review Question 1.1; Exercise 1. Objective 2: Knowledge Check 1.5; Review Question 1.3. Objective 3: Knowledge Check 1.2; Review Question 1.2; Exercise 2. Objective 4: Knowledge Checks 1.3 and 1.4. Objective 5: Exercise 3. Objective 6: Knowledge Check 1.6; Review Question 1.4. Use the worked solutions under the exercises to check your own work.

Also covered in this chapter: Timing relays (on-delay, off-delay, and repeat cycle; timing is assessed with PLC timers in Chapter 14), control panel layout and wiring practices, common relay panel failures, and the troubleshooting walkthrough in Section 1.11.

📘 Quick Guide

Core chapter - study it in depth. This chapter is on the Core Path for every reader (see the Recommended Study Plan at the front of the manual). If you already read and troubleshoot relay ladder schematics and seal-in circuits, you can skim it, then use its Knowledge Checks to confirm you have not missed anything.

If you only have 20 minutes: the maintenance points that matter most in this chapter.

  • Know what 'normal' means: an NO or NC contact's normal state is with the coil de-energized, not with the machine running. Stop buttons and E-stops are NC, so a broken wire stops the machine instead of leaving you with a Stop that does not work. But a short or jumper across an NC circuit looks exactly like a healthy closed contact (Sections 1.2 and 1.5).
  • Read the seal-in symptom. Runs only while Start is held: the auxiliary (seal-in) contact block is faulty, its wiring is broken, or the seal-in wires are on the wrong terminals. Will not stop: if the coil drops out but the motor runs, the main contacts are welded or stuck; if the coil stays in, the Stop contacts are welded or bypassed. De-energize at the disconnect and investigate (Section 1.5).
  • Voltage chase the rung: black lead on L2 and leave it there, prove full voltage on L1, then move the red lead point by point from left to right. Where you lose voltage is where the problem is. The same method works on every PLC output circuit (Section 1.8).
  • Set the overload from the motor nameplate FLA as the overload maker's instructions direct, not from the contactor size. Never jumper out an overload that keeps tripping: find the root cause, and if someone asks you to bypass it, document it and escalate. Short circuits are the job of the fuses or breaker ahead of the starter (Section 1.4).
  • Replace like for like. Never swap AC and DC coils, even at the same voltage: match the coil voltage and type printed on the relay. A replacement contactor must be the same NEMA size or larger, and a replacement timer must be the same type, TON or TOF (Sections 1.2, 1.4 and 1.6).
  • If the whole panel is dead, check the control transformer secondary fuse first. Before you replace it, ask why it blew: look for shorted coils, pinched wires, or water intrusion (Section 1.9).
  • Never bypass forward/reverse interlock wiring. If you find the interlock contacts jumpered out, stop and report it: both contactors in at once is a phase-to-phase short and an arc flash (Section 1.7).

On the job: one-page checklist. Print this list and keep it where you do the work.

Check the obvious first: main disconnect on, E-stop pulled out, no tripped breakers on the MCC feeding the machine, and the operator pressing the correct button (Section 1.11).
Before live measurements, wear the PPE the panel's arc flash label or your site's risk assessment calls for. Most relay panels also contain 480 VAC (Section 1.11).
Open the panel and look first, touch nothing: power-on indicator, buzzing or chattering relays, burning smell, burned wires, water (Section 1.11).
Pull the ladder diagram, find the rung for the device that is not working, and use the cross-references and wire numbers to find every contact involved (Section 1.8).
Voltage chase from L1 to L2, contact by contact, with your reference lead on L2 (Section 1.8).
At the terminal blocks, measure the field side to split the problem into field wiring or panel wiring (Section 1.9).
De-energize and lock out before any continuity test. Treat orange or yellow wires as possibly live even with the panel disconnect off, and verify with your meter (Sections 1.9 and 1.11).
Replace with the same coil voltage and AC or DC type, the same NEMA size or larger, and the same timer type (Sections 1.2, 1.4 and 1.6).
For an intermittent fault you cannot reproduce with the door open, check every termination on the circuit with a calibrated torque screwdriver (Section 1.9).
After the fix, test Start, test Stop, test E-stop. Every time (Section 1.11).

1.1 Before Automation: The Manual Factory

Picture a factory floor in 1920. Every machine is run by a human operator. A worker stands at a punch press and pulls a lever to engage the drive. Another worker watches a tank fill and closes a valve by hand when the level looks right. A third worker watches a temperature gauge on a furnace and adjusts the fuel flow based on experience and gut feel.

It worked. For decades, it worked. But it had limits.

âš  Why This Matters to You

You might be tempted to skip this chapter. Relays are old technology. You were hired to learn PLCs. But here is the truth: every PLC program you will ever see is drawn as a ladder diagram - a direct imitation of the relay circuits in this chapter. The symbols are the same. The logic is the same. The start/stop circuit you learn here is the same start/stop circuit running inside the PLC code on any packaging line, conveyor system, or CNC machine in your plant. Maintenance techs who skip this chapter struggle for years with PLC troubleshooting because they never understood the underlying logic. Techs who nail this chapter pick up PLC programming in weeks. Your call.

Humans get tired. They get distracted. They take breaks. They make mistakes - and on a factory floor, mistakes mean scrap product, damaged equipment, or injuries. As production volumes grew through the early twentieth century, manufacturers needed a way to make machines do repetitive tasks without a human standing over every switch.

The answer was the electromechanical relay.

A relay is, at its core, an electrically operated switch. You send current through a coil of wire, that coil becomes an electromagnet, and the magnetic field pulls a set of contacts closed (or pushes them open). Remove the current, and a spring returns everything to its resting position. That is the entire concept. One electrical circuit controlling another electrical circuit - without anyone touching anything.

This simple device changed manufacturing forever. By wiring relays together in specific patterns, engineers could build logic into electrical circuits. If this switch AND that switch are both on, then start the motor. If the pressure gets too high, shut everything down. If the operator presses Start, keep the motor running even after they release the button. All of this could be done with relays, wire, and nothing else.

1.2 The Electromechanical Relay: How It Actually Works

You need to understand a relay at the physical level - not as an abstract symbol on a drawing, but as a real thing you can hold in your hand, hear click, and troubleshoot with a meter. Let's break one open.

The Coil

A relay coil is a spool of thin copper wire wound around an iron core. When you apply voltage to the coil terminals, current flows through the wire and generates a magnetic field. The iron core concentrates that field and makes it stronger. This is the same principle as any electromagnet - if you have ever picked up nails with a wire wrapped around a bolt connected to a battery, you already understand relay coils.

The coil has a rated voltage. Common control relay coil voltages are 24 VDC, 120 VAC, and 240 VAC. Apply the correct voltage and the relay pulls in. Apply too little and it may not pull in at all, or it may chatter - rapidly vibrating between pulled in and dropped out. Apply too much and you burn the coil. A burned coil smells like scorched varnish and is one of the most recognizable smells on a factory floor.

âš™ Field Tip: Checking a Relay Coil

To check whether a relay coil is good, remove power and measure resistance across the coil terminals with your multimeter set to ohms. A good coil will show a measurable resistance - typically anywhere from 10 ohms to several thousand ohms depending on the coil voltage and design. An open coil reads OL (overload/infinite resistance). A shorted coil reads near zero ohms. Both are failed coils. Write down the expected resistance from the manufacturer's datasheet and keep it in your notes. Someday at 2 AM you will be grateful you did.

The Armature

The armature is the moving part. It is a hinged piece of iron (or steel) positioned near the core of the coil. When the coil energizes, the magnetic field pulls the armature toward the core. This physical movement is what operates the contacts. When the coil de-energizes, a return spring pushes the armature back to its resting position.

If you have ever held a relay in your hand and applied power to the coil, you felt the click. That click is the armature snapping into the energized position. De-energize the coil and you feel it click back. That tactile, audible feedback is one of the reasons old-school relay techs could troubleshoot by ear - a stuck relay sounds different from a healthy one.

The Contacts

Contacts are the switch elements of the relay. They are small metal pads or buttons, usually made of silver alloy, that either touch each other (closed/conducting) or are separated by an air gap (open/not conducting). The armature movement pushes the contacts together or pulls them apart.

A single relay can have multiple sets of contacts. A common small control relay might have four sets. Each set operates simultaneously when the coil energizes. This means one coil, one input signal, can control four separate output circuits at the same time. This was an enormously powerful concept in early industrial control.

Normally Open (NO) and Normally Closed (NC)

This is one of the most important concepts in all of industrial controls, so read this carefully.

"Normal" does not mean "the way it usually runs." Normal means the state of the contact when the coil is de-energized - no power applied, relay sitting on a shelf. That is the normal state.

Normally Open (NO): When the coil is de-energized, the contact is open. No current flows through it. When you energize the coil, the contact closes and current flows. Think of a drawbridge that normally sits raised: nothing crosses until someone lowers it. The electrical path is normally broken. Energize to connect.

Normally Closed (NC): When the coil is de-energized, the contact is closed. Current flows through it freely. When you energize the coil, the contact opens and breaks the circuit. The electrical path is normally complete. Energize to disconnect.

The figure below puts the coil, core, armature, return spring and contacts together in one relay with a single Form C contact set: a common terminal (COM) that touches the NC contact at rest and swings over to the NO contact when the coil energizes. You will meet the COM and Form C names again in the Contact Nomenclature box later in this section.

Cutaway of a relay with one Form C contact set, shown twice. Left, de-energized: no voltage on coil terminals A1-A2, the return spring holds the hinged armature up, so COM touches NC and COM-NO is open. Right, energized: the coil magnetizes the iron core, which pulls the armature down against the spring, so COM leaves NC and touches NO. NC NO COM A2 A1 Return spring Armature (hinged) Pivot Coil on iron core DE-ENERGIZED (the "normal" state) no voltage on coil A1-A2 COM-NC closed COM-NO open The return spring holds the armature up NC NO COM A2 A1 Return spring Armature (hinged) Pivot Coil on iron core ENERGIZED rated voltage on coil A1-A2 COM-NO closed COM-NC open The magnetized core pulls the armature down

Why do both types exist? Because control logic needs both. Sometimes you need something to turn ON when a signal arrives (use NO). Sometimes you need something to turn OFF when a signal arrives (use NC). And sometimes - this is critical for safety - you need a circuit that is conducting by default and only breaks under a specific condition.

âš  Critical Safety Concept: NC Contacts in Emergency Stops

Emergency stop circuits almost always use normally closed contacts. Here is why: if the wire to an NO emergency stop button breaks, the circuit sees the same thing as "button not pressed" - and the machine keeps running. You have lost your safety device and nobody knows it. But if the wire to an NC emergency stop button breaks, the circuit sees the same thing as "button pressed" - and the machine stops. A broken wire fails the system to a safe state. This principle is called "fail-safe design," and you will see it everywhere in industrial controls. NC for safety. Always.

Two more things a pro knows. First, E-stop and safety-switch contacts are "direct opening" (also called positive opening) contacts, marked with an arrow inside a circle: pushing the button mechanically forces the contacts apart even if they have welded. NFPA 79 requires this for E-stops. Second, a single NC circuit has one blind spot: a short or a jumper across its wires looks exactly like a healthy closed contact. That is why modern safety circuits use two channels and a safety relay that checks them against each other - you will meet those in Chapter 55.

AC Relays vs. DC Relays

Relay coils are designed for either AC or DC voltage, and the difference matters more than you might think.

DC relay coils produce a steady magnetic field when energized. The pull-in is smooth and consistent. DC relays tend to be quieter and generate less heat. They are common in modern control panels that run on 24 VDC control voltage.

AC relay coils produce a magnetic field that fluctuates with the AC waveform - 60 times per second on a 60 Hz system. This means the magnetic force drops to zero 120 times per second (twice per cycle). Without a special design feature, the armature would vibrate at 120 Hz, producing a loud buzz and rapid mechanical wear. To prevent this, AC relays use a shading coil (also called a shading ring) - a small copper ring embedded in the pole face. The shading coil creates a slight time delay in part of the magnetic field, so that when the main field passes through zero, the shaded portion is still pulling the armature. This keeps the armature seated smoothly.

If a shading coil breaks or falls out, the AC relay will buzz loudly and chatter. It will still sort-of work - the armature is pulled in most of the time - but the vibration will rapidly wear out the contacts, loosen terminations, and eventually burn the coil. A buzzing relay is not just an annoyance. It is a relay about to fail.

âš  Never Swap AC and DC Relays

An AC coil and a DC coil of the same voltage rating are not interchangeable. If you put 24 VDC on a 24 VAC coil, the coil will overheat and burn because the AC coil has very low wire resistance - it was designed to rely on inductive reactance (impedance) to limit current, and that reactance only exists with alternating current. Apply DC and the reactance disappears, leaving only the low wire resistance, so current flow far exceeds the coil's rating. If you put 120 VAC on a 120 VDC coil, the relay may not pull in reliably, because the coil's inductance adds reactance that cuts the current below what the coil needs. If it does pull in, it will buzz and chatter, because a DC coil has no shading coil to carry it through the zero crossings, and its solid iron core heats up from AC eddy currents. Always replace a relay with the exact same coil voltage and type (AC or DC). The coil rating is printed on the relay body or on its label. Read it before you install.

📘 Contact Nomenclature

On wiring diagrams and relay datasheets, you will see contacts labeled in several ways. Common labels include NO, NC, COM (common - the shared terminal between an NO and NC pair), Form A (a single NO contact), Form B (a single NC contact), and Form C (a changeover contact that has one COM, one NO, and one NC - also called SPDT, single pole double throw). A relay with "4PDT" contacts has four Form C sets - four poles, each with double throw. You do not need to memorize every combination right now, but know these terms exist so they don't surprise you on a datasheet.

✎ Knowledge Check 1.1
A relay's normally closed (NC) contact is in what state when the relay coil has no power applied?
Correct: C. "Normally closed" means the contact is closed (conducting) in its normal state - which is coil de-energized. When you apply power to the coil, the NC contact opens. The word "normal" always refers to the coil's de-energized condition, not the machine's running condition.
Why the others are wrong:
A - Open with no current flow describes a normally open (NO) contact at rest. An NC contact opens when the coil is energized, not when it is de-energized.
B - "Normal" refers to the relay's de-energized state, not the machine's running condition. With no coil power, an NC contact is closed whether the machine is running or stopped.
D - A standard control relay has no memory. Its return spring puts the contacts back to their shelf state whenever the coil is de-energized, so the NC contact is closed. Holding the last position is what a latching relay does.
The full Chapter 1 continues with 1.3 Control Relays vs. Power Relays; 1.4 Motor Starters: Contactors with a Bodyguard; 1.5 The Seal-In Circuit: The Most Important Circuit in Industrial Controls; 1.6 Timing Relays: Adding the Element of Time; 1.7 Building a Control Sequence: Putting Relays Together; 1.8 Reading a Relay Ladder Diagram; 1.9 Hardwired Control Panel Layout and Wiring Practices; 1.10 The Reality of Maintaining Relay Panels; 1.11 Practical Troubleshooting: Walking Through a Real Scenario; 1.12 The Logic Functions of Relay Circuits; 1.13 The Breaking Point: Why Relays Were Not Enough; 1.14 Relay Logic in the Modern Plant. It then gives you 5 more Knowledge Checks (1.2-1.6), the Hands-On Exercises with 3 worked solutions, the Chapter Summary and Key Takeaways, and 4 Review Questions with model answers. Continue reading in the full manual: all 71 chapters and 4 appendices at this depth.
Free sample excerpt: Chapter 6, Sections 6.1 to 6.3 in full, with Knowledge Check 6.1. Reproduced exactly as it appears in the full manual, diagrams included.
Chapter 6

Safety in PLC Work: Electrical Hazards, LOTO, and Arc Flash

This chapter is focused on purpose. It is not short, because the rules that keep you alive in a PLC cabinet are not few, but it carries no padding: safety training that drones on with filler gets skimmed, and skimmed safety content is worthless. The Quick Guide and the one-page checklist below give you the core in a few minutes, and the sections behind them give you the reasons. Everything here is a non-negotiable. No filler, no slogans, no clip art of a cartoon guy wearing a hard hat. Just the things that keep you alive and unburned when you open a PLC cabinet. You already have the electrical fundamentals from Chapter 5. Now you need the rules for working around those voltages - because knowing what 480VAC is and knowing how to not get killed by it are two very different things.

📘 Learning Objectives

By the end of this chapter, you will be able to:

  1. Identify every energy source in a PLC cabinet, including sources the main disconnect does not control, and list the lockout steps in order
  2. Perform the test-verify-test voltage check with a meter of the correct CAT rating
  3. Read an arc flash label and select PPE whose arc rating meets or exceeds the incident energy
  4. Identify stored-energy hazards, such as a drive's DC bus, and verify zero energy before touching them
  5. Determine when energized troubleshooting is permitted under NFPA 70E, and which permit, PPE, and work practices apply

How this chapter checks your progress: Objective 1: Review Question 6.1; Exercise 1; Chapter 71 sign-off row 1. Objective 2: Knowledge Check 6.1; Review Question 6.4; Exercise 3; Chapter 71 sign-off row 1. Objective 3: Knowledge Check 6.2; Exercise 2. Objective 4: Knowledge Check 6.3. Objective 5: Knowledge Check 6.4; Review Questions 6.2 and 6.3. Use the worked solutions under the exercises to check your own work.

Also covered in this chapter: What "qualified person" means (Section 6.1), how PLC techs actually get hurt, and ESD protection for modules.

📘 Quick Guide

Core chapter - study it in depth. This chapter is on the Core Path for every reader (see the Recommended Study Plan at the front of the manual). Read it before any hands-on work in the plant, and do not skim it. Your site's electrical safety and LOTO procedures always take priority over this book.

If you only have 20 minutes: the maintenance points that matter most in this chapter.

  • Being a qualified person is a competency, not a job title. If you are not trained on a specific hazard or piece of equipment, you must say so and stop. An unqualified person never crosses the restricted approach boundary and never does energized electrical work (Section 6.1).
  • A PLC cabinet may have more than one power feed, and the main disconnect does not kill them all. Look for separate feeds for lights, heaters, and receptacles, UPS-backed circuits, external 24VDC feeds, and backfeed from other panels; NFPA 79 calls for externally fed wires to be orange (yellow on older panels). Every source gets its own lock (Section 6.2).
  • Test-verify-test, every time: prove your tester on a known live source, verify zero phase to phase, phase to ground, and phase to neutral, then prove the tester on the live source again. Never skip the second live test. Until the test proves zero, the conductors count as energized, so a qualified person does it with the arc-rated PPE on the label, shock protection, and a CAT III 600V meter. A listed, permanently mounted absence-of-voltage tester can replace the portable meter only for the conductors it is wired to (Section 6.2).
  • Read the arc flash label before you open the door. Your arc-rated PPE must be rated at or above the incident energy on the label. No label means an unknown hazard, not a low one, and above 40 cal/cm² the only safe option is LOTO (Section 6.3).
  • Energized troubleshooting is justified when the fault can only be diagnosed with the system running. The permit exemption for testing and troubleshooting waives only the paperwork, not the PPE and safe work practices, and physical work such as replacing modules or re-terminating wires is not done energized when de-energizing is possible (Sections 6.4 and 6.5).
  • When you do work energized: the one-hand rule, insulated tools, no jewelry or dangling items, a barricaded area, and an emergency plan. Air-test your rubber gloves before each use, and do not use a pair whose last electrical test was more than six months ago (Section 6.5).
  • A VFD's DC bus can hold a lethal charge for many minutes. Wait at least the discharge time on the drive's label, then measure the DC bus with your meter; a dark charge LED is not proof (Section 6.7).

On the job: one-page checklist. Print this list and keep it where you do the work.

Read the arc flash label before you open the door and confirm you have the PPE it calls for. If the label is missing or illegible, do not proceed (Section 6.3).
Decide energized or de-energized. If the task can be done de-energized, lock it out (Section 6.9).
Inspect your meter and leads: CAT III 600V minimum, no cracked insulation, finger guards on the probes. Check the dial and the lead jacks before you probe (Section 6.8).
Notify affected personnel and identify every energy source from the drawings, including separate feeds, UPS circuits, external 24VDC, and pneumatic or hydraulic connections (Section 6.2).
Stop the machine with its normal stop controls and let it come to rest. Do not use Program mode as a stop button (Section 6.2).
Lock the main disconnect and every other source, each with its own lock and tag, and bleed any pneumatic or hydraulic pressure (Section 6.2).
Wait at least the discharge time on each drive's label, then measure the DC bus (Sections 6.2 and 6.7).
Where you can, check through the viewing window that the disconnect blades are open, try Start with everyone clear, then do test-verify-test (Section 6.2). Treat the circuit as energized and wear the PPE on the arc flash label, with shock protection, until your test proves zero (Section 6.2).
If you must work energized: correct PPE, insulated tools, one hand, no jewelry, barricades, and know where the nearest AED is and how to call for help (Section 6.5).
When finished: remove your tools, reinstall covers and guards, make sure everyone is clear, remove only your own lock, notify affected personnel, then re-energize and verify operation (Section 6.9).

6.1 What "Qualified Person" Actually Means

NFPA 70E defines a qualified person as someone who has "demonstrated skills and knowledge related to the construction and operation of electrical equipment and installations and has received safety training to identify the hazards and reduce the associated risk." That is not a credential you hang on the wall. It is a standard you must meet before you touch energized equipment.

âš  Why This Matters to You

Stories like this one, drawn from real field events, play out in plants every year. A maintenance tech at a food processing plant opened a PLC cabinet to troubleshoot a conveyor fault. The cabinet had a main disconnect on the door, and he turned it off. He did not lock it. He did not test for zero energy. While he was probing terminals, a supervisor on the other side of the plant saw the conveyor was down and sent an operator to "flip it back on." The disconnect handle turned. The tech took 480VAC across his hand and through his chest. He survived - barely - with third-degree burns on both hands and an irregular heartbeat that never fully resolved. Everything you read in this chapter exists because someone, somewhere, learned it the worst possible way.

In practical terms, a qualified person:

  • Has been trained on the specific electrical hazards of the equipment they are about to work on
  • Can identify exposed live parts and determine their nominal voltage
  • Knows the approach boundaries - limited, restricted, and arc flash - for the voltages present
  • Knows how to select and use PPE appropriate for the hazard
  • Has been trained in and can perform LOTO procedures
  • Understands the test instruments being used and their ratings

There is also an "unqualified person" under NFPA 70E. An unqualified person may cross the limited approach boundary only after a qualified person has advised them of the hazards, and only while that qualified person continuously escorts them. An unqualified person may never cross the restricted approach boundary and never performs energized electrical work - with or without supervision. (The one exception is formal on-the-job training: a trainee who has shown he can do a specific task safely, working under the direct supervision of a qualified person, is treated as qualified for that task only.) Unqualified workers can still work on equipment that has been placed in an electrically safe work condition under lockout. This is relevant because many plants have maintenance techs at different skill levels working in the same space.

âš  Your Employer's Responsibility - and Yours

NFPA 70E requires your employer to provide documented training and to verify that you are qualified for the tasks you are assigned. But the standard also puts responsibility on you: if you are not trained on a specific hazard or piece of equipment, you are obligated to say so. "My boss told me to do it" is not a legal defense and it is not a medical treatment. If you are not qualified for the task, stop and speak up.

For PLC work specifically, being a qualified person means you understand the voltage levels inside the cabinet (Chapter 5 covered this), you know which circuits the main disconnect controls and which it does not, you can identify arc flash hazards, and you can perform LOTO correctly. By the end of this chapter, you will have the knowledge foundation. Your employer must provide the formal, documented training and verify your competence. This manual is educational material, not a substitute for site-specific safety training.

6.2 Lockout/Tagout for PLC Cabinets

You have had LOTO training. You know the basics: shut it off, lock it out, verify zero energy. In the US, lockout/tagout on machines and equipment is required by OSHA 29 CFR 1910.147 (The Control of Hazardous Energy), and for work on or near electrical circuit parts, 29 CFR 1910.333(b) sets the lockout and tagging rules. Your site's written energy control procedure is how your employer meets those rules, so follow it. But PLC cabinets have specific complications that generic LOTO training does not cover. This section addresses those complications head-on.

How PLC Cabinet LOTO Differs from Motor LOTO

Locking out a motor is straightforward. You open the disconnect, lock it, verify the motor is de-energized. One energy source, one disconnect, one lock. PLC cabinets are different in several important ways:

Multiple energy sources. A PLC cabinet may have more than one incoming power feed. The main disconnect handles the primary power - typically 480VAC stepped down through a control transformer. But the cabinet may also have a separate 120VAC circuit for a cabinet heater, a separate feed for a network switch that runs on a UPS, a 24VDC feed from an external power supply on another machine, or a separate circuit for cabinet lighting and convenience outlets. The main disconnect does not kill these. You must identify every energy source entering the cabinet.

Stored energy. After you open the main disconnect, the PLC does not go dead instantly. Power supplies have capacitors that hold charge. Large capacitors on VFD DC buses inside the same cabinet can hold lethal voltage for minutes. The 24VDC supply may have enough holdup time to keep the PLC running for 20-50 milliseconds after AC power is removed. That is far too short for you to reach anything - it is there so the PLC rides through a brief power dip. The real stored-energy dangers are drive DC buses and anything on a UPS. UPS-backed circuits stay energized after the main disconnect opens for as long as the UPS battery lasts, which can be minutes to hours, and longer still where the UPS is also backed by a generator or a second feed (UPS types and runtime are covered in Chapter 61). Opening the disconnect does not de-energize them: the UPS output must be isolated and locked out as its own energy source, then verified dead.

Backfeed paths. Outputs wired to external loads can backfeed voltage into the cabinet through unexpected paths. Common examples: an interlock circuit from the next machine's panel that lands on terminals in this cabinet, a PLC output module whose field power (L1 or +24V) is fed from a different panel, or a motor starter coil in an MCC bucket that is powered by the bucket's own control transformer and switched by a contact in your cabinet. All of these stay live when your disconnect is open. NFPA 79 calls for these externally fed conductors to be orange (yellow on older panels) - when you see an orange wire, assume it is live until your meter proves otherwise. This is not theoretical. It happens.

âš  The Separate-Feed Trap

A common installation practice is to feed the cabinet's interior lighting, thermostat-controlled heater, or convenience receptacle from a separate 120VAC branch circuit - not through the main disconnect. This means those circuits are live when the main disconnect is off and locked out. If you do not know this and you brush against the wiring for that cabinet light while reaching for a PLC module, you are making contact with a live 120VAC circuit that you believed was dead. Before your first LOTO on any unfamiliar cabinet, study the electrical drawings and identify every circuit entering the enclosure. If drawings are not available, trace every wire that enters the cabinet from outside.

The PLC Cabinet LOTO Procedure

Here is the procedure, specific to PLC cabinets. This supplements your plant's LOTO procedure - it does not replace it. Your plant procedure may have additional requirements.

1
Notify affected personnel. Anyone who operates or monitors the equipment controlled by this PLC needs to know it is going down. This includes operators, supervisors, and any other maintenance techs working on related equipment.
2
Identify all energy sources. Review the electrical drawings. Identify every circuit entering the cabinet. Note the main power feed, any separate feeds for lighting/heating/receptacles, any external 24VDC feeds, any network equipment on UPS power, and any pneumatic or hydraulic connections to devices inside the cabinet. This is the step that PLC cabinet LOTO adds beyond simple motor LOTO.
3
Perform an orderly shutdown. Stop the machine with its normal stop controls (the Stop button or an HMI cycle stop) and let it finish its motion and come to rest in a safe position before you touch the disconnect. Do not use Program mode as a stop button - it sends every output to its Program-mode state (normally off) at once, with no orderly sequence, much like pulling the plug (Chapter 3). An orderly stop prevents hydraulic valves slamming to their spring-return position under full load, parts left half-clamped, and axes stopped in awkward places. It also means you are not opening the disconnect under full motor load.
4
Open and lock the main disconnect. Turn the disconnect handle to OFF. Apply your personal lock and tag. If multiple people are working, each person applies their own lock. Use a multi-lock hasp if needed.
5
Isolate all other energy sources. Lock out any separate circuit breakers feeding the cabinet. Disconnect any external 24VDC feeds. Remove UPS connections if present. Bleed any pneumatic or hydraulic pressure. Each separate energy source gets its own lock.
6
Wait for stored energy to dissipate. Wait at least the discharge time printed on each drive's warning label before opening it - anywhere from 3 minutes to 15 minutes or more, depending on the make and size. For standard PLC power supplies, 60 seconds is typically sufficient, but check the manufacturer's documentation. Do not trust timing alone - you will verify with your meter in the next step.
7
Verify zero energy - test-verify-test. First, wherever the disconnect lets you, look at its blades through the viewing window to confirm they are open - a handle can read OFF on a disconnect with welded contacts. Then try it: with everyone clear, press the machine's Start button (or command it from the HMI) to prove that nothing moves, and return the controls to off. Then do the test-verify-test, which gets its own section below because it is the most critical step and the one most often done wrong. NFPA 70E calls the end result of all these steps an "electrically safe work condition."

Here is the whole procedure on one strip, with step 7 broken out into its parts:

PLC cabinet lockout/tagout sequence in seven numbered steps: 1 notify affected personnel; 2 identify all energy sources; 3 orderly shutdown; 4 open and lock the main disconnect; 5 isolate all other energy sources; 6 wait for stored energy to dissipate; 7 verify zero energy - check the disconnect blades are open through the viewing window, try Start and return the controls to off, then test the tester on a known live source, verify zero voltage phase-to-phase, phase-to-ground and phase-to-neutral, and test the tester on the known live source again. The result is an electrically safe work condition. PLC CABINET LOTO - the Section 6.2 steps, in order 1 NOTIFY Operators, supervisors and techs on related equipment 2 IDENTIFY SOURCES Main feed, separate feeds, external 24 VDC, UPS, air and hydraulics 3 ORDERLY SHUTDOWN Normal stop, machine at rest in a safe position. Not Program mode. 4 LOCK DISCONNECT Handle OFF. Your own lock and tag - every worker applies their own. 5 ISOLATE THE REST Lock separate breakers, disconnect external 24 VDC, remove UPS, bleed air and hydraulics. One lock each. 6 WAIT Stored energy: wait at least the discharge time on each drive label. Timing alone is not proof: verify next. This strip supplements your plant LOTO procedure; it does not replace it. Your plant procedure may add steps. Before your first LOTO on a cabinet, find every feed on the drawings. 7 VERIFY ZERO ENERGY TEST - VERIFY - TEST Blades open? check viewing window Try Start, then controls off TEST tester on known live VERIFY zero ph-ph, ph-gnd, ph-N TEST again on known live Result: an electrically safe work condition (NFPA 70E). If the tester fails either live test, do not trust the zero reading. Get another tester and start over.

The Test-Verify-Test Procedure

This is the procedure that keeps you alive when everything else fails. A lock can be removed by someone else (it should not be, but it happens). A disconnect can fail internally (contacts welded shut). The only thing that stands between you and a lethal shock is your own voltage test - and it is only as good as the instrument you are using.

The procedure is simple and absolute:

  1. Test your voltage tester on a known live source. Verify it reads voltage correctly. This confirms the tester is working, the batteries are good, and the leads are intact.
  2. Verify the circuit you are about to work on reads zero voltage. Test phase-to-phase, phase-to-ground, and phase-to-neutral. All must read zero.
  3. Test your voltage tester on the known live source again. This confirms the tester did not fail between your first test and your verification. If it reads correctly, your zero-voltage reading was real.

If your tester does not read correctly on either the first or second live test, do not trust the zero reading. Get a different tester and start over.

âš  The Absence-of-Voltage Test Is Itself Energized Work

Until your test proves zero, every conductor you are about to test is energized, and you treat it that way. Verifying absence of voltage is the last step in establishing an electrically safe work condition, so while you are doing it, that condition does not exist yet. That means:

  • A qualified person does the test (Section 6.1). A trainee does it only under the direct supervision of a qualified person where the site's program allows it (Exercise 3).
  • Wear the arc-rated PPE the arc flash label calls for, or the PPE for the equipment's row of the category table where that method applies (Section 6.3), plus shock protection: rubber insulating gloves of the right class with leather protectors, because your hands and probes are inside the restricted approach boundary (Sections 6.4 and 6.5). NFPA 70E's table for estimating arc flash likelihood (Table 130.5(C)) lists work on energized conductors, including voltage testing, as a task where an arc flash can occur: a probe that slips between two phases, or a lead left in the amps jack, can start one (Sections 6.3 and 6.8).
  • Use a meter rated for the location and the voltage: CAT III 600V minimum, leads to match, inspected before use, and set to the right function before the probes go in (Section 6.8). Keep the one-hand habit and the probe technique from Section 6.8.
  • Only after all three steps pass (live, zero, live) on every conductor you will touch is that part of the cabinet in an electrically safe work condition. Anything you did not test, such as a separate feed that is deliberately left on, keeps its energized-work rules and its PPE.
📘 Permanently Mounted Absence-of-Voltage Testers (AVTs)

Some newer PLC and MCC panels have an absence-of-voltage tester (AVT) mounted in the door: a small indicator unit wired to the conductors inside the enclosure and listed to UL 1436, which includes requirements written specifically for AVTs. You press its test button with the door still closed. The unit checks its own operation against a known voltage source before and after the test, tests each phase phase to phase and phase to ground, and gives its absence-of-voltage indication (typically a green light) only when every test passes. Since its 2018 edition, NFPA 70E has allowed an adequately rated, permanently mounted AVT that is listed and labeled for the purpose, and installed per the manufacturer's instructions, to verify absence of voltage at the point where it is installed, in place of the portable meter. Its big advantage is that you verify before anyone opens the door, so nobody is exposed during the test.

What an AVT does not replace:

  • The lockout itself. Steps 1 to 6 still happen: identify every source, stop the machine, open and lock every disconnect, and release stored energy. The AVT only replaces the portable-meter part of step 7.
  • Anything it is not wired to. An AVT tests only the conductors it is connected to, usually the load side of the main disconnect in that enclosure. Separate feeds, UPS circuits, external 24VDC, backfeed paths, and a drive's DC bus need their own verification unless the drawings show the AVT covers them.
  • Your site's procedure. Use an AVT for verification only where your written energy control procedure says so, and follow the manufacturer's instructions for what its indications mean.
  • Doubt. If the AVT does not give its absence-of-voltage indication, shows a fault, or you have any reason to doubt it, the panel is energized: do the portable-meter test-verify-test with full PPE, as above.
âš  Non-Negotiable: Never Skip the Second Live Test

Voltage testers fail. Leads break internally with no visible damage. Batteries die mid-test. A tester that reads zero on a dead circuit tells you nothing if you have not confirmed the tester is actually working. The second live test - after your zero reading - is the step that catches a failed tester. A tech who tests on a known source, gets a zero reading on the work circuit, and then assumes the tester is still good has defeated the entire purpose. Test. Verify. Test. Every single time. No exceptions.

âš™ Practical Tip: Your Known Live Source

Where do you find a known live source in a PLC cabinet that you just locked out? You do not - because it is locked out. Use a separate, verified live source nearby: a live receptacle, a test block at the MCC, or a portable proving unit designed for this purpose (such as the Fluke PRV240). Some plants install a dedicated "proof of life" receptacle near PLC cabinets specifically for this. Know where yours is before you start the LOTO.

✎ Knowledge Check 6.1
You are about to perform LOTO on a PLC cabinet. You open and lock the main disconnect. Using the test-verify-test method, you test your meter on a known live receptacle and it reads 122VAC - good. You then probe inside the PLC cabinet and read 0V on the main bus. You immediately begin working. Which step of the test-verify-test method did you skip?
Correct: B. The test-verify-test procedure requires three steps: (1) test the meter on a known live source, (2) verify zero voltage on the work circuit, (3) test the meter on the known live source again. The third step confirms the meter did not fail between the first test and the zero-voltage reading. Without that final confirmation, you cannot trust that the zero reading was real. The meter could have failed during your verification, giving you a false zero.
Why the others are wrong:
A - Notifying affected personnel is part of the full LOTO procedure, but it is not part of test-verify-test, and it happens before the lockout, not after the zero reading.
C - Checking for stored energy is a separate LOTO step; test-verify-test is about proving your meter, and the gap here is the missing re-test on a known live source after the zero reading.
D - Checking the meter's fuse and battery is good practice, but it is not one of the three test-verify-test steps. The step skipped here is the second test on the known live source after the zero reading.

6.3 Arc Flash: What It Is and Why PLC Techs Must Understand It

Arc flash is not just a hazard for the electricians working on switchgear and MCCs. PLC cabinets with 480VAC incoming power, or even 240VAC with sufficient available fault current, present a real arc flash hazard. If you open a PLC cabinet that has an arc flash label on it - and it should have one - you need to understand what that label means and what PPE it requires.

Danger High Voltage warning sign on an electrical panel enclosure

What Happens During an Arc Flash

An arc flash is an explosive release of energy caused by an electrical fault through the air between conductors or between a conductor and ground. The air ionizes and becomes a conductor itself. Temperatures at the arc point can reach 35,000 degrees Fahrenheit - about three to four times the surface temperature of the sun. The result is a blast of superheated plasma, molten metal, intense light, a pressure wave, and shrapnel from vaporized copper conductors and destroyed components.

Arc flash events in PLC cabinets are less common than in high-current switchgear, but they do happen. Common causes:

  • A dropped tool, washer, or loose screw bridging live 480VAC terminals
  • A meter probe slipping off a terminal and contacting an adjacent conductor
  • A corroded or loose connection arcing under load when the cabinet door is open
  • Vermin (mice, snakes) creating a fault path inside the enclosure
  • Using an improperly rated meter or leads on a high-energy circuit

Arc Flash Labels and Incident Energy

NFPA 70E requires arc flash labels on equipment likely to require examination, adjustment, servicing, or maintenance while energized. The label tells you the critical information:

  • Incident energy - measured in calories per square centimeter (cal/cm²) at a specific working distance. This is the number that determines your PPE.
  • Arc flash boundary - the distance from the arc source where incident energy drops to 1.2 cal/cm² (the threshold for a second-degree burn on unprotected skin). Do not be inside this boundary without proper PPE.
  • PPE category - a number from 1 to 4 that simplifies PPE selection (detailed below). A label shows either the incident energy or the PPE category, never both - NFPA 70E does not allow the two methods to be mixed on one label. Some labels show a minimum arc rating or a site-specific PPE level instead.
  • Nominal voltage - always on the label. Many labels also list the shock approach boundaries.

If the cabinet does not have an arc flash label, treat it as if the hazard is unknown. NFPA 70E requires you to either perform or obtain an arc flash study before working on the equipment, or use the PPE category tables as a fallback - but the tables are a fallback only for equipment that falls inside the limits the tables themselves state (see "The Category Method Has Limits" below).

PPE Categories for Arc Flash

NFPA 70E defines four PPE categories, and each one sets a minimum arc rating for the clothing and a list of required PPE (Table 130.7(C)(15)(c)). The category for a task comes from the equipment label or from the table row for that equipment type, not from an incident energy number: a label shows either an incident energy or a PPE category, never both, and the two methods are never mixed on the same equipment. The minimum arc ratings line up with incident energy levels, which is why the categories are often described that way. Here is what each requires:

PPE Category Min Arc Rating Required PPE Typical PLC Cabinet Scenario
1 4 cal/cm² Arc-rated long-sleeve shirt and pants (or coverall), arc-rated face shield (or arc flash suit hood), hard hat, safety glasses or goggles, hearing protection, heavy-duty leather or arc-rated gloves (or rubber insulating gloves with leather protectors), leather work shoes Low-energy 240VAC panels with limited fault current, some 480VAC panels with very low available fault current
2 8 cal/cm² Arc-rated long-sleeve shirt and pants (or coverall), arc-rated face shield with balaclava or arc-rated flash suit hood, hard hat, safety glasses or goggles, hearing protection, heavy-duty leather or arc-rated gloves (or rubber insulating gloves with leather protectors), leather work shoes Many typical PLC cabinets with 480VAC incoming power, moderate available fault current
3 25 cal/cm² Arc-rated flash suit (jacket, pants, hood with face shield), arc-rated gloves (or rubber insulating gloves with leather protectors), hard hat, safety glasses or goggles, hearing protection, leather work shoes PLC cabinets in substations or near large switchgear with high available fault current
4 40 cal/cm² Arc-rated flash suit (jacket, pants, hood with face shield) rated for 40 cal/cm², arc-rated gloves (or rubber insulating gloves with leather protectors), hard hat, safety glasses or goggles, hearing protection, leather work shoes Rare for standalone PLC cabinets - typically applies to main switchgear or high-fault-current locations
âš  Above 40 cal/cm²

NFPA 70E does not set a hard ceiling at 40 cal/cm² - arc-rated suits above 40 exist - but at that level the blast pressure, flying debris, and sound can injure you even through a suit, and many companies' electrical safety programs forbid energized work there. Treat it as a de-energize-only situation. If you encounter a label showing greater than 40 cal/cm² on a PLC cabinet, the only safe option is LOTO.

âš  The Category Method Has Limits

The PPE category method (NFPA 70E 130.7(C)(15)) is allowed only when the equipment is inside the limits listed for its equipment type in Table 130.7(C)(15)(a) for AC equipment (Table 130.7(C)(15)(b) for DC): a maximum available fault current, a maximum fault clearing time, and a minimum working distance. Each row of the table is a specific equipment type with its own limits, PPE category, and arc flash boundary. Examples from the 2024 edition, all at an 18 in (455 mm) working distance:

  • Panelboards or other equipment rated 240 V and below: up to 25 kA available, cleared within 2 cycles (0.03 s): PPE category 1, arc flash boundary 19 in (485 mm).
  • Panelboards or other equipment rated above 240 V and up to 600 V: up to 25 kA, 2 cycles: PPE category 2, arc flash boundary 3 ft (900 mm).
  • 600 V class motor control centers: up to 65 kA, 2 cycles: PPE category 2, arc flash boundary 5 ft (1.5 m). The same MCCs with up to 42 kA and a 20-cycle (0.33 s) clearing time: PPE category 4, arc flash boundary 14 ft (4.3 m).
  • Other 600 V class (277 V through 600 V nominal) equipment: up to 65 kA, 2 cycles: PPE category 2, arc flash boundary 5 ft (1.5 m).

If the available fault current or the clearing time of the upstream protective device is unknown, or is higher or longer than the row allows (a large feeder, or a breaker with a long time delay), or you must work closer than the listed working distance, the table does not apply. An incident energy analysis is then required (NFPA 70E 130.5(G)), done by the people who run your plant's arc flash program - not estimated at the cabinet. The "Typical PLC Cabinet Scenario" column in the table above only illustrates where each category tends to show up; it is never a way to pick a category. The category comes from the equipment label, or from the table row for that equipment type after its limits have been checked. Always use the edition of NFPA 70E your site has adopted: the rows and numbers can change from one edition to the next.

Most PLC cabinets you will encounter fall into Category 1 or Category 2. The 480VAC incoming section presents the highest hazard. Once you are downstream of the control transformer - in the 120VAC and 24VDC section of the cabinet - the arc flash energy is dramatically lower, often below the threshold for Category 1. But you still need to verify this with the arc flash label or study for that specific installation. Do not assume.

âš™ Read the Label Before You Open the Door

The arc flash label is on the outside of the cabinet for a reason - so you can read it before you open the door and expose yourself to the hazard. Get in the habit: walk up to any PLC cabinet, read the label, confirm you have the right PPE, then open the door. If the label is missing or illegible, do not proceed until you get the information from your plant's arc flash study or electrical safety program.

The full Chapter 6 continues with 6.4 NFPA 70E Essentials for PLC Maintenance; 6.5 When Energized Work Is Justified - And How to Do It Safely; 6.6 How PLC Techs Actually Get Hurt; 6.7 Stored Energy: Capacitors, Power Supplies, and Hold-Up Time; 6.8 Voltage Testing Procedures and Meter Safety; 6.9 Putting It All Together: The Safety Mindset for PLC Work. It then gives you 3 more Knowledge Checks (6.2-6.4), the Hands-On Exercises with 3 worked solutions, the Chapter Summary and Key Takeaways, and 4 Review Questions with model answers. Continue reading in the full manual: all 71 chapters and 4 appendices at this depth.
Free sample excerpt: Chapter 13, Sections 13.1 to 13.4 in full, with Knowledge Check 13.1. Reproduced exactly as it appears in the full manual, diagrams included.
Chapter 13

Ladder Logic: The Foundation

This is the chapter you have been building toward. Every concept from every previous chapter - relay logic, PLC hardware, I/O wiring, data types, program organization - converges right here. You are about to write your first PLC program. And you are going to write it in ladder logic, the most widely used PLC language, especially in North American plants. You already know what ladder logic looks like because you studied relay ladder diagrams in Chapter 1. The symbols are almost identical on purpose - when PLC manufacturers invented ladder logic in the late 1960s, they designed it so that every electrician who could read a relay schematic could read a PLC program without retraining. That decision shaped the entire industry. The contacts, the coils, the rungs, the left-to-right power flow - all of it came straight from the relay world you already understand. The difference is that now, instead of physical wires and metal contacts, you have software instructions and memory bits. Same logic. No wiring. Infinitely changeable. This chapter teaches you every foundational ladder logic instruction, shows you exactly how the PLC evaluates each rung, and walks you through building complete working programs from scratch. By the end, you will be able to write a start/stop motor control program with interlocks, indicators, and fault logic - the same program structure running inside thousands of machines in every factory you will ever walk into.

📘 Learning Objectives

By the end of this chapter, you will be able to:

  1. Choose XIC or XIO for a field device from its wiring and the logic you need, including an NC Stop button examined with XIC
  2. Write and test a start/stop seal-in rung with an overload contact, and predict what it does when a wire breaks or a contact is misplaced
  3. Translate a written requirement or a Boolean expression into series and parallel branches, and verify it with a truth table
  4. Choose between OTE with a seal-in and OTL/OTU, and check that every OTL has a matching OTU
  5. Find and correct an output that is written in more than one place (a double coil)
  6. Read any rung as one plain sentence: the output energizes when these conditions are true

How this chapter checks your progress: Objective 1: Knowledge Check 13.1. Objective 2: Knowledge Checks 13.2 and 13.3; Exercise 1; Chapter 71 sign-off row 8; Chapter 71 capstone (Fault Card 9). Objective 3: Knowledge Check 13.5; Review Questions 13.2 and 13.4; Exercise 2. Objective 4: Review Question 13.1; Exercise 3. Objective 5: Knowledge Check 13.4; Review Question 13.3; Chapter 71 sign-off row 15; Chapter 71 capstone (Fault Card 10). Objective 6: Exercise 3. Use the worked solutions under the exercises to check your own work.

Also covered in this chapter: One-shot instructions (ONS, OSR, OSF), forward/reverse interlocking, indicator sequencing, and rung documentation practices.

📘 Quick Guide

Core chapter - study it in depth. This chapter is on the Core Path for every reader (see the Recommended Study Plan at the front of the manual).

If you only have 20 minutes: the maintenance points that matter most in this chapter.

  • Choose XIC or XIO from the logic you need, not from the device's wiring. A hardwired NC Stop button reads 1 when not pressed, so the motor run rung examines it with XIC. A broken wire drops the input to 0 and stops the motor - the fail-safe comes from the wiring (Section 13.4).
  • Stop, E-stop, overload, and other safety conditions belong in the series path, before any branch opens. Put one inside a parallel branch and the seal-in or another branch can bypass it (Sections 13.11 and 13.16).
  • Never write the same tag on two OTE instructions. The last rung scanned wins, so you can stare at a rung with every condition true and an output that will not come on. Search the program for every OTE on the tag (Section 13.5).
  • A bit set by OTL stays set until an OTU (or another write) clears it, and on Allen-Bradley controllers it survives a power cycle. A latch that drives motion can restart it when the PLC returns to Run, so look for first-scan logic that clears it (Sections 13.6 and 13.16).
  • Rungs are evaluated top to bottom, left to right. A rung that examines a bit set further down the program sees it one scan late, so produce data before you consume it (Section 13.7).
  • Software interlocks are never enough on their own. Forward/reverse contactors also need a hardwired interlock, such as an NC auxiliary contact from each contactor in series with the other's coil (Section 13.12).
  • Read every rung as one sentence: the output is ON when these conditions are true. If the sentence does not match what the machine should do, the rung is wrong (Section 13.18).

On the job: one-page checklist. Print this list and keep it where you do the work.

Find the rung that drives the faulted output and read it as one sentence.
Go online and find the first condition that is not satisfied, working left to right along the series path.
Check each NC device (Stop, overload, E-stop): its input should read 1 when healthy, and it should be examined with XIC in the run rung.
Search for every OTE on the output tag. More than one means a double coil.
If OTL/OTU is used, find both the latch and the unlatch rungs. When both are true on the same scan, the lower rung wins; the unlatch is normally placed below the latch so it takes priority.
Confirm that the safety conditions sit in series ahead of any branch, and that the seal-in branch goes around Start only.
On forward/reverse or sequenced equipment, check the cross-interlocks in the program and the hardwired interlock in the panel.
After any change, update the rung comment and tag descriptions: what the rung does for the machine, how the device is wired, and what a wire break does (Section 13.17).

13.1 From Relay Diagrams to Ladder Logic

In Chapter 1, you learned to read relay ladder diagrams - two vertical lines representing the power rails (L1 and L2), with horizontal rungs connecting them. Each rung had contacts on the left (the conditions) and a coil on the right (the output). Current flowed from left to right. If all the contacts in a path were closed, the coil energized. If any series contact was open, the coil stayed de-energized.

Screenshot of ladder logic programming environment showing rungs and function blocks
Photo: “StxLadder-v1.4.9”. By DoNothing. Source: https://commons.wikimedia.org/wiki/File:StxLadder-v1.4.9.png. License: CC BY-SA 4.0, https://creativecommons.org/licenses/by-sa/4.0/. Also offered under the GFDL; used here under CC BY-SA 4.0. Resized.

PLC ladder logic is that same diagram, drawn on a computer screen instead of paper, with one critical difference: there are no wires. Every "contact" in a ladder logic program is a software instruction that examines a bit in memory. Every "coil" is a software instruction that writes to a bit in memory. The PLC's processor evaluates each rung mathematically, determining whether there is logical continuity from the left rail to the output instruction. If there is continuity, the output instruction executes (the bit turns on). If there is no continuity, the output instruction does not execute (the bit turns off or stays off).

âš  Why This Matters to You

You can understand PLC hardware perfectly and still be useless on the floor if you cannot read and write ladder logic. When a machine faults on the night shift and the operator is standing behind you waiting, you need to open that program, find the rung that controls the faulted output, read the conditions, and determine which input is not satisfied - in minutes, not hours. When engineering asks you to add a new indicator light or a safety interlock, you need to write a clean, correct rung and download it without breaking everything else. Ladder logic is not academic. It is the language your machines speak. The instructions in this chapter are the words. Learn them the way you learned your first language - by using them, not just reading about them.

The symbols look the same on purpose. Here is the mapping:

Relay Diagram Element Ladder Logic Instruction What It Does
Normally Open (NO) contact XIC - Examine If Closed Checks if a bit is ON (1). Passes power if true.
Normally Closed (NC) contact XIO - Examine If Open Checks if a bit is OFF (0). Passes power if true.
Relay coil OTE - Output Energize Turns a bit ON when the rung has continuity; OFF when it does not.
Latched relay (mechanically held) OTL - Output Latch Turns a bit ON when the rung has continuity. Stays ON even when continuity is lost.
Release of latched relay OTU - Output Unlatch Turns a bit OFF when the rung has continuity. Used to release an OTL.

That is the entire foundation. Five instructions. If you understand these five instructions and how they combine, you can read and write the majority of ladder logic programs in the industrial world.

âš™ The Names Are Confusing at First

"Examine If Closed" does not mean "check if the contact is closed." It means "examine the addressed bit and pass logical power if the bit's value is 1 (closed/true/on)." The instruction examines a memory location, not a physical contact. Similarly, "Examine If Open" means "pass logical power if the bit's value is 0 (open/false/off)." Once you stop thinking about physical contacts and start thinking about bit states, the names make perfect sense. XIC asks: "Is this bit a 1?" XIO asks: "Is this bit a 0?"

13.2 Anatomy of a Ladder Logic Rung

Every ladder logic rung has the same basic structure. Understanding this structure is essential before you write a single line of code.

The Left Rail

The left vertical line represents the power source - conceptually, L1 in a relay diagram. In the PLC, there is no actual voltage here. The left rail represents "logical power available." Every rung starts with power available on the left. The PLC's job is to determine whether that logical power can flow through the rung's conditions to reach the output on the right.

Input Conditions (Contacts)

Between the left rail and the output, you place input conditions - the XIC and XIO instructions. These are your logic tests. Each one examines a specific tag (a memory address) and either passes or blocks logical power flow based on the tag's current value. You can have one condition, or you can have dozens. You can arrange them in series, in parallel, or in complex nested combinations.

The Output Instruction (Coil)

At the right end of the rung, you place the output instruction - OTE, OTL, OTU, or one of many other output-type instructions you will learn in later chapters. The output instruction is what the rung "does" when it evaluates as true. In RSLogix 500 (SLC 500 and MicroLogix), only one output instruction can sit at the rightmost position of a rung, though you can have multiple outputs on separate branches of the same rung (more on this later). Studio 5000 Logix Designer is more flexible: it lets you place several output instructions in series at the end of a rung, and even put an output partway along a rung with more conditions after it, because each instruction simply hands its rung condition on to the next. Many programmers still put multiple outputs on parallel branches in Logix, because that layout reads the same way on every platform.

The Right Rail

The right vertical line represents the return path - conceptually, L2/neutral. Studio 5000 and RSLogix 500 draw the right rail; Siemens TIA Portal leaves it off. Either way, the output instruction connects to it automatically.

A Simple Rung

Here is the simplest possible rung - one input, one output:

Ladder logic diagram: the simplest rung, one XIC contact Start_PB driving the Motor_Run OTE coil.Start_PBMotor_Run

Read it left to right: "If Start_PB is true (bit = 1), then energize Motor_Run (set bit = 1)." The contact symbol (two short vertical bars, typed as ] [ when ladder is written as plain text) represents an XIC instruction. The coil symbol (a pair of parentheses, typed as ( )) represents an OTE instruction. This is identical to a relay diagram with one NO contact and one coil on a rung.

📘 Ladder Symbols on Screen and in Plain Text

The rungs in this manual are drawn with the same graphical symbols your programming software uses (RSLogix 5000/Studio 5000, Siemens TIA Portal, and so on): an XIC is two vertical bars, an XIO is two vertical bars with a slash through them, and an OTE is a pair of parentheses. When ladder logic is written as plain text - in an email, a forum post, a work instruction, or an old program printout - the same instructions are typed as characters: ] [ is an XIC (NO contact symbol). ]/[ is an XIO (NC contact symbol, with a slash through it). ( ) is an OTE. (L) is an OTL. (U) is an OTU. Learn to read both forms. The logic is identical.

13.3 XIC: Examine If Closed

The XIC instruction is the workhorse of ladder logic. You will use it more than any other instruction. It is the NO contact - the normally open contact equivalent from relay logic.

How It Works

An XIC instruction examines a single bit in memory. If that bit is 1 (true/on/set), the instruction passes logical continuity - it acts like a closed contact, allowing power to flow through. If the bit is 0 (false/off/cleared), the instruction blocks logical continuity - it acts like an open contact.

Bit Value XIC Result Relay Equivalent
1 (True / ON) True - passes continuity NO contact is closed (coil is energized)
0 (False / OFF) False - blocks continuity NO contact is open (coil is de-energized)

When to Use XIC

Use XIC when you want logic to be true when something is ON. Most input devices in a PLC system are wired as normally open and produce a 1 when activated. Push a pushbutton - the input bit goes to 1. A proximity sensor detects a part - the input bit goes to 1. A motor contactor pulls in and its auxiliary contact closes - the feedback input bit goes to 1. In all these cases, you use XIC to check for the active condition.

Ladder logic diagram: XIC Prox_Sensor_1 driving the Part_Present OTE coil.Prox_Sensor_1Part_Present

Translation: "When the proximity sensor input is ON (bit = 1), set the Part_Present bit ON." When the sensor turns off (bit returns to 0), the XIC goes false, and the OTE de-energizes Part_Present.

âš  XIC Does Not Mean "The Input Is a Normally Open Device"

This is a common source of confusion. An XIC instruction examines a bit value, and that is the whole of its job. The bit might be an input wired to a normally open pushbutton, or it might be an internal tag set by another rung, or it might be a status bit from a timer instruction. XIC does not know or care what the bit represents physically. It only asks: "Is this bit a 1 right now?" Whether the physical device connected to that input is wired NO or NC is a wiring and I/O question, not a programming question. Keep these concepts separate in your mind.

13.4 XIO: Examine If Open

The XIO instruction is the NC contact equivalent. It is the logical opposite of XIC.

How It Works

An XIO instruction examines a single bit in memory. If that bit is 0 (false/off/cleared), the instruction passes logical continuity - it acts like a closed NC contact in its normal (de-energized) state. If the bit is 1 (true/on/set), the instruction blocks logical continuity - it acts like an NC contact that has been opened by energizing the coil.

Bit Value XIO Result Relay Equivalent
0 (False / OFF) True - passes continuity NC contact is closed (coil is de-energized, contact at rest)
1 (True / ON) False - blocks continuity NC contact is open (coil is energized, contact pulled away)

When to Use XIO

Use XIO when you want logic to be true when something is OFF. The most common use cases:

Stop pushbuttons and emergency stops: In Chapter 1 you learned that stop buttons are wired NC for fail-safe reasons. In PLC systems, a hardwired NC stop button is typically wired to an input that reads 1 when the button is not pressed (the NC contact is closed, current flows, the input sees voltage). When someone presses Stop, the NC contact opens, current stops, and the input goes to 0. In the motor run rung you want logic that is true while the input is 1 (button not pressed), so you examine that input with XIC, not XIO - the danger callout below walks through why. XIO still has a job with stop buttons: on a separate rung, an XIO on the NC stop input is true only while the button is pressed (or the wire is broken), which is exactly what you want when you need to detect a stop event, for example to log it or reset a sequence.

Overload contacts: An overload relay has an NC contact that opens when the overload trips. This is wired to a PLC input that reads 1 during normal operation and 0 when the overload has tripped. In the motor run rung you examine this input with XIC, so the rung breaks when the overload trips. An XIO on the same input is true only when the overload has tripped, which makes it the right instruction for an overload alarm or fault-light rung - you will see exactly that in Rung 8 of Section 13.15.

Interlocks: When you want to prevent something from running while another thing is active, XIO is your tool. "Do not run Motor B while Motor A is running" translates to an XIO on Motor_A_Running in the rung that controls Motor B.

Ladder logic diagram: interlock rung: XIO Motor_A_Run driving the Motor_B_Cmd OTE coil, so Motor B can be commanded only while Motor A is not running.Motor_A_RunMotor_B_Cmd

Translation: "Motor B can only be commanded ON when Motor A is NOT running." The ]/[ symbol represents the XIO - notice the slash through the contact, just like the diagonal line through an NC contact on a relay diagram.

âš  The NC Stop Button Confusion

This trips up nearly every new programmer. The physical stop button is NC. It is wired so the PLC input reads 1 during normal running conditions (button not pressed). When the button is pressed, the input reads 0. Now - do you use XIC or XIO in your program? Think about it from the logic perspective: you want the motor rung to be TRUE during normal running. The stop input is 1 during normal running. So you use XIC on the stop input in the motor run rung. The XIC is true when the input is 1 (not pressed), and false when the input is 0 (pressed). The fail-safe behavior comes from the wiring, not the programming instruction. If the wire breaks, the input goes to 0, the XIC goes false, and the motor stops - fail-safe. Many instructors teach this wrong. Get it right now.

✎ Knowledge Check 13.1
A stop pushbutton is wired as a hardwired NC contact to a PLC input. During normal machine operation (stop button NOT pressed), the PLC input reads 1. When the stop button IS pressed, the input reads 0. To use this stop button in a motor control rung, which instruction should you use on that input tag, and why?
Correct: A. The programming instruction is chosen based on the logic you need, not the physical contact type of the device. You want the motor run rung to be true during normal operation. The input is 1 during normal operation. XIC passes continuity when the bit is 1, so you use XIC. This also gives you fail-safe behavior: a broken wire drops the input to 0, the XIC goes false, and the motor stops. This is one of the most commonly misunderstood concepts in PLC programming - make sure you internalize it before moving on.
Why the others are wrong:
B - This confuses the device wiring with the program logic. The NC contact makes the input read 1 during normal running, and XIO is false when its bit is 1, so the motor could never run.
C - The stop input does not energize when Stop is pressed - with an NC button it de-energizes and reads 0. XIO on this input would be false during normal running and true only while Stop is pressed.
D - Right instruction, wrong reason. The instruction follows the bit state the rung needs, not the contact type of the device: an NC high-level switch that must raise an alarm when it opens is examined with an XIO in the alarm rung, because that rung has to go true when the input drops to 0. XIC is right here only because this stop input reads 1 in normal running and the run rung must be true then. The same logic settles the broken-wire question: a broken wire drops the input to 0, which would make an XIO true, so the motor would keep running. XIC on the NC stop input is what gives fail-safe stopping.
The full Chapter 13 continues with 13.5 OTE: Output Energize; 13.6 OTL and OTU: Latch and Unlatch; 13.7 Power Flow and Rung Evaluation; 13.8 Series and Parallel Logic: AND, OR, and Branches; 13.9 Seal-In Circuits in Ladder Logic; 13.10 Boolean Logic Mapped to Ladder; 13.11 Complete Program: Start/Stop Motor Control; 13.12 Interlocking: Preventing Conflicting Outputs; 13.13 One-Shot Instructions: Detecting Transitions; 13.14 Complete Program: Indicator Light Sequencing; 13.15 Complete Program: Forward/Reverse Motor with Full Interlocks and Indicators; 13.16 Common Programming Mistakes; 13.17 Good Rung Documentation Practices; 13.18 How to Think in Ladder Logic. It then gives you 4 more Knowledge Checks (13.2-13.5), the Hands-On Exercises with 3 worked solutions, the Chapter Summary and Key Takeaways, and 4 Review Questions with model answers. Continue reading in the full manual: all 71 chapters and 4 appendices at this depth.
Free sample excerpt: Allen-Bradley platform chapter. Chapter 34, Sections 34.11 to 34.14 in full (controller properties and firmware, online editing, memory management, and ControlLogix-specific features such as redundancy), with Knowledge Check 34.3. Reproduced exactly as it appears in the full manual, diagrams included.
Chapter 34

ControlLogix 5570: The Proven Workhorse

In Chapter 30, you learned the entire Allen-Bradley product line and where each platform fits. In Chapters 31 through 33, you went deep on the legacy platforms - PLC-5, SLC 500, and MicroLogix - the systems you will encounter in brownfield plants for years to come. Now you arrive at ControlLogix, the Allen-Bradley flagship platform, starting with the ControlLogix 5570. The 5570 is no longer the newest ControlLogix - the 5580 (Chapter 35) and now the 5590 have followed it - but it is installed in huge numbers, and nearly everything you learn on it carries forward. ControlLogix is the platform Rockwell Automation recommends for any application that requires high I/O count, redundancy, safety integration, multi-discipline control (discrete, process, motion, safety in one chassis), or distributed architecture across a large plant. If someone is commissioning a new refinery control system, a new automotive body shop, a new water treatment plant, or a new pharmaceutical batch system, and they are standardizing on Allen-Bradley, they are installing ControlLogix. You already know the concepts - tag-based addressing, producer/consumer networking, tasks, programs, routines. You learned them in earlier chapters as platform-neutral principles. This chapter makes them concrete. This chapter puts them in the 1756 chassis, with real part numbers, real configuration screens, real firmware revisions, and real field considerations. By the end, you will understand every piece of hardware in a ControlLogix system, how those pieces communicate, how the program architecture works, and how to configure, maintain, and manage the controller that you will work with more than any other for the remainder of your career.

34.11 Controller Properties and Firmware Management

Controller properties define the fundamental configuration of the ControlLogix system. They are set when the project is created and can be modified (some only offline). Firmware management is a critical maintenance skill that every ControlLogix technician must master.

Controller Properties

The controller properties dialog in Studio 5000 contains:

  • Name: The controller name that appears in the project and on the network. Use descriptive names (e.g., WTP_Main_Controller, Line3_PackagingPLC, Boiler_Control).
  • Chassis Type: The 1756 chassis size (A4, A7, A10, A13, A17). Must match the physical chassis.
  • Slot: The slot number where the controller is installed. Must match the physical installation.
  • Firmware Revision: The controller's firmware version (e.g., v30.014, v31.012, v33.011). Set during project creation and must match the physical controller's firmware.
  • Communication Path: The network path used by Studio 5000 to communicate with the controller. Typically set through RSLinx or FactoryTalk Linx (e.g., AB_ETHIP-1\192.168.1.10\Backplane\0 for Ethernet to slot 0).
  • Redundancy: For redundancy-enabled controllers, specifies whether this is the primary or secondary controller in a redundancy pair.
  • Safety: For GuardLogix controllers, specifies safety task configuration and safety signature requirements.

Firmware Versions and Compatibility

Firmware is the operating system of the controller. It determines what features are available, what instructions are supported, and what communication protocols the controller can use. Firmware management is governed by two critical compatibility rules:

  1. The Studio 5000 major version must match the controller firmware major revision. If the controller is running firmware v31, you need Logix Designer v31 installed to go online with it. Studio 5000 v30 cannot go online with it, and a newer version such as v33 cannot either unless you convert the project to v33 and flash the controller to v33 - which is a firmware change, not a quick fix. That is why maintenance laptops carry several versions side by side (Chapter 30, section 30.4). Minor revisions do not need to match, and the Studio 5000 launcher opens each project in the version it needs. The rule applies to every Logix controller - ControlLogix, CompactLogix, and GuardLogix - and later chapters refer back to it here. This is one of the most common "I can't connect" problems in the field. Before you leave the shop for a service call, verify that your Studio 5000 version matches the controller firmware version at the site.
  2. I/O module firmware must be compatible with the controller firmware. When you upgrade a controller's firmware, verify that all I/O modules in the chassis (and on remote I/O networks) have firmware compatible with the new controller version. Rockwell publishes compatibility matrices in the Product Compatibility and Download Center (PCDC). Check the matrix before every firmware upgrade.
âš™ The Firmware Version Mismatch: A Field Story

You arrive at a plant for a service call. The production line is down. The ControlLogix controller is faulted. The maintenance tech says they tried to go online with Studio 5000 but got an error. You ask what version of Studio 5000 they have. Version 28. You look at the controller front panel and note the firmware revision: v31. That is the problem. Studio 5000 v28 cannot communicate with a v31 controller. The tech needs Logix Designer v31 installed - a newer or older version will not go online. But the plant laptop only has v28. Now someone has to purchase, download, install, and activate Studio 5000 v31 before the first troubleshooting step can even begin. The line sits idle while software licensing is sorted out. This scenario is preventable. Keep every major version of Logix Designer that runs in your plant installed side by side, with an activation that covers them. Know the firmware versions of every controller on your network before you need to troubleshoot them.

Firmware Update Tools

Controller firmware is updated using one of two tools:

  • ControlFLASH: A standalone utility that updates firmware on Allen-Bradley modules. You connect to the controller (via USB, or Ethernet through a communication module - the 5570 has no serial port), select the target module, select the firmware revision to flash, and execute. ControlFLASH can update controller firmware, I/O module firmware, and communication module firmware. It is available as a free download from Rockwell. Rockwell's newer ControlFLASH Plus does the same job with a device browser, can update several devices in one session, and can pull firmware kits from the PCDC.
  • AutoFlash: A feature within Studio 5000 that automatically offers to flash a module's firmware when a version mismatch is detected during download. If you download a project configured for firmware v31 to a controller running v30, Studio 5000 will offer to flash the controller to v31 as part of the download process. This is convenient but should be used with caution - make sure you understand the implications of the firmware change before accepting.

Firmware Upgrade and Downgrade Considerations

  • Upgrading: Generally safe, but always check the release notes for known issues and the compatibility matrix for I/O module compatibility. Some firmware upgrades are irreversible on certain modules. Back up the current project before upgrading. After upgrading, verify that all I/O modules come online and that the project runs correctly.
  • Downgrading: Sometimes necessary when a firmware upgrade introduces a bug or incompatibility. Downgrading a controller may require downgrading the project revision as well (a v31 project cannot run on a v30 controller). Downgrading is riskier than upgrading because newer firmware may have added features or data structures that the older firmware cannot support. Always have a backup of the project at the target firmware revision before downgrading.
  • Redundancy: In redundancy systems, firmware upgrades must follow a specific procedure (typically update the secondary controller first, switchover, then update the original primary). Rockwell publishes detailed firmware upgrade procedures for redundancy pairs. Follow them exactly.

34.12 Online Editing

Online editing is the ability to modify a ControlLogix program while the controller is in Run mode and the process is active. This is one of the most powerful and most dangerous capabilities of the platform. Every online edit has the potential to affect the running process. ControlLogix provides a structured edit workflow to manage this risk.

The Online Edit Workflow

  1. Go Online: Connect Studio 5000 to the running controller. Verify that the offline project matches the online project (Studio 5000 will warn you if they do not match).
  2. Start Pending Edits: Start pending rung edits (or open a pending edit on an ST or FBD routine). You now work on a pending copy; the controller keeps running the original logic.
  3. Make Your Edits: Add, modify, or delete rungs. The running program is not affected yet.
  4. Accept Pending Edits: Studio 5000 verifies the edits and downloads them to the controller. The controller still runs the original logic - nothing in the process has changed yet. If there are errors, the accept fails and you fix them first.
  5. Test Accepted Edits: The controller starts running the new logic, while the original is kept. Watch the process carefully. If anything goes wrong, click Untest Accepted Edits and the original logic runs again on the next scan.
  6. Assemble Accepted Edits: When the test is successful, assemble the edits. The original logic is deleted and the change is permanent. There is no undo after this step - only another edit.
  7. Cancel: Before you assemble, you can cancel pending or accepted edits to throw them away. This is your safety net.
âš  Online Edits on Production Systems

Every online edit should be treated as a production change with real consequences. Even adding a single rung to a running program can change timing, affect scan time, and alter the behavior of downstream logic. Before making any online edit, you should: (1) have a current backup of the offline project, (2) understand exactly what the edit will change and what outputs it could affect, (3) have operations personnel aware that an edit is being made, (4) be prepared to cancel the edit immediately if something goes wrong, and (5) document the change in your plant's change management system. Online editing is not the place for experimentation. If you are not sure what an edit will do, do not test it on a running production system. Use a spare controller on the bench, simulate, or test during a scheduled downtime.

What You Cannot Edit Online

Some changes cannot be made while the controller is in Run mode:

  • Adding or deleting tasks
  • Adding or deleting programs
  • Changing task configuration (period, priority)
  • Changing controller properties (name, slot, chassis type)
  • Changing I/O module configuration (electronic keying, RPI) on some module types
  • Modifying User-Defined Types (UDTs) - changing the structure of a UDT requires an offline edit and download

These changes require the controller to be in Program mode, which stops the process. Plan for these changes during scheduled downtime.

✎ Knowledge Check 34.3
A ControlLogix 5570 system has a periodic task configured at 20 ms containing PID control logic. During commissioning, you notice the task execution time (visible in Task Properties online) is averaging 18 ms and occasionally spiking to 22 ms. What is the problem, and what should you do?
Correct: A. A task averaging 18 ms of a 20 ms period uses 90% of it, well past the 80% guideline, and the 22 ms spikes mean overlaps are already occurring. On each overlap the controller skips that trigger and logs a minor fault (Type 6, Code 2), so the PID loop quietly misses executions with no major fault to warn you. Fix it by lengthening the period if the process dynamics allow (for example to 50 ms), moving non-critical logic to a slower task, or reducing preemption from higher-priority tasks.
Why the others are wrong:
B - An average below the period does not help when the peaks exceed it. Each spike past 20 ms is an overlap that skips a PID execution.
C - All 5570 controllers share the same processor core and execution speed. A larger-memory model runs the same logic no faster.
D - A continuous task has no fixed period, so the PID's time between executions would change from scan to scan and the loop timing gets worse. PID logic belongs in a periodic task whose period leaves headroom.

34.13 Memory Management

ControlLogix controllers have a fixed amount of user memory (determined by the controller model) that holds the program, tags, I/O configuration, and all data. Understanding how memory is used and how to monitor it is essential for large projects.

What Consumes Memory

  • Tags: Every tag consumes memory proportional to its data type. A DINT uses 4 bytes. A REAL uses 4 bytes. A TIMER uses 12 bytes. A UDT uses the sum of its members. An array of 1,000 DINTs uses 4,000 bytes. Large arrays and data-logging buffers are the biggest memory consumers in most projects.
  • Program logic: Every rung, every function block, every line of Structured Text consumes memory. Complex programs with thousands of rungs and many Add-On Instruction instances consume significant memory.
  • I/O configuration: Each I/O module connection consumes memory for the I/O data, connection management, and module configuration. Systems with hundreds of I/O modules consume significant I/O memory.
  • Produced/consumed tags: Each produced or consumed tag consumes additional memory for the connection management overhead.
  • Trends and data logging: If the controller is configured to store historical data locally, the trend buffers consume memory proportional to the number of tags trended and the buffer depth.

Monitoring Memory Usage

In Studio 5000, go to the Controller Properties dialog while online. The Memory tab (called Capacity on the 5580) shows used and available memory. Rockwell recommends keeping at least 15-20% free memory for online edits, runtime data expansion, and safety margin. If memory usage exceeds 80%, consider optimizing: reduce array sizes, remove unused tags, consolidate redundant logic, or upgrade to a higher-memory controller.

The I/O Memory usage is displayed separately from user (program) memory. A system with many I/O modules or many produced/consumed tag connections can exhaust I/O memory even when user memory is plentiful. Monitor both.

34.14 ControlLogix-Specific Features

ControlLogix has capabilities that are not available on CompactLogix or any other Allen-Bradley platform. These features are the reasons ControlLogix is selected over CompactLogix for critical and large-scale applications.

Controller Redundancy (1756-RM2)

ControlLogix supports full controller redundancy using the 1756-RM2 Redundancy Module. A redundant system has two identical chassis, each holding a controller, a redundancy module, and communication modules - but no I/O. All I/O in a redundant system is remote, on EtherNet/IP or ControlNet, so that whichever controller is primary can reach it. The two RM2 modules are linked by a fiber-optic synchronization cable. One controller is primary (actively controlling the process) and the other is secondary (mirroring the primary's state, ready to take over instantly).

If the primary controller fails, the secondary takes over within milliseconds - a bumpless transfer that does not disturb outputs, does not lose data, and does not interrupt the process. This is a hard requirement for applications where any controller downtime is unacceptable: continuous chemical processes, power generation, water treatment, oil and gas, and pharmaceutical manufacturing.

Key redundancy points:

  • Both controllers must be the same model and firmware revision.
  • Both chassis must hold the same controller and communication modules in the same slot positions. I/O modules are not allowed in a redundant controller chassis.
  • The RM2 modules connect the two chassis via a fiber optic synchronization link.
  • Firmware upgrades on redundant systems follow a specific procedure (update secondary, switchover, update former primary).
  • Redundancy is not available on CompactLogix. If a project requires redundancy, it must be ControlLogix.

A typical redundant system looks like this. Notice where the I/O is - and where it is not allowed:

ControlLogix redundancy block diagram: two identical chassis, primary and secondary, each holding a controller in slot 0, a 1756-EN2TR EtherNet/IP module in slot 1 and a 1756-RM2 redundancy module in slot 2, with no I/O modules. The two RM2 modules are linked directly by a fiber-optic sync cable, and both EN2TR modules connect to an EtherNet/IP network where all the I/O sits in remote chassis. Chassis A - PRIMARY (in control) Chassis B - SECONDARY (synchronized) Power supply Controller slot 0 1756-EN2TR slot 1 1756-RM2 slot 2 no I/O modules slot filler only Power supply Controller slot 0 1756-EN2TR slot 1 1756-RM2 slot 2 no I/O modules slot filler only Fiber-optic sync cable, direct RM2 to RM2 EtherNet/IP I/O network Remote I/O chassis adapter + I/O modules Remote I/O chassis adapter + I/O modules Remote I/O chassis adapter + I/O modules Both chassis: same chassis size, same modules in the same slots, same catalog numbers and firmware. No I/O in either controller chassis - all I/O is remote, so whichever controller is primary can reach it (EtherNet/IP; ControlLogix 5570 systems can also use ControlNet). Each chassis can use one power supply or a redundant pair (1756-PA75R/PB75R through a 1756-PSCA2 adapter). If the primary fails, the secondary takes over bumplessly and becomes the new primary.

Safety Integration (GuardLogix)

The 1756-L7xS controllers (S-suffix) are GuardLogix processors - they run both a standard task and a safety task in the same controller. The safety task uses a restricted instruction set and a safety partner coprocessor (1756-L7SP in the adjacent slot) that independently verifies safety function execution. The safety architecture differs by generation: the GuardLogix 5570 (1756-L7xS) always requires a safety partner (1756-L7SP) for any safety function and is certified for SIL 2 and SIL 3 depending on the overall safety function design. The newer GuardLogix 5580 (1756-L8xES) can achieve SIL 2 / PLd (Category 3) without a safety partner; a safety partner (1756-L8SP) is required only for SIL 3 / PLe.

The safety task has its own tag database (safety tags), its own program and routines, and its own execution period. Safety I/O modules (Guard I/O) communicate using CIP Safety protocol, which provides end-to-end safety data integrity across standard Ethernet infrastructure. The safety program is locked with a safety signature - any modification invalidates the signature and requires re-validation.

GuardLogix allows standard control and safety control in the same chassis, on the same network, programmed in the same project file. This integration eliminates the need for a separate safety PLC, simplifies wiring, and reduces cost compared to standalone safety systems. Safety systems are covered in depth in Chapter 55.

I/O Event Tasks

ControlLogix supports I/O event tasks that trigger directly from a change on an I/O module. When the configured input changes state, the I/O module sends an event notification through the backplane, and the controller immediately executes the event task - without waiting for the normal scan cycle. This provides the fastest possible response to a discrete input change. I/O event tasks are used for applications like high-speed packaging line registration and product detection, where a very fast response to one input change matters. They are never a substitute for an emergency stop - an E-stop must work through hardwired or safety-rated devices, not standard program logic.

Multiple Controllers in One Chassis

Unlike any legacy AB platform, ControlLogix allows multiple controllers in the same chassis. Each controller operates independently, has its own program, and manages its own I/O. The controllers communicate with each other through produced/consumed tags over the backplane. This is used in applications where different parts of a system are controlled by different teams or have different update rate requirements, but sharing a chassis reduces wiring and cabinet space.

Enterprise Connectivity

ControlLogix's Ethernet capabilities (1756-EN2T and variants) provide direct connectivity to enterprise systems - historians, MES (Manufacturing Execution Systems), SCADA, and ERP interfaces. The EtherNet/IP protocol supports both real-time control traffic and IT-level data access on the same network. Rockwell's FactoryTalk software suite (FactoryTalk Historian, FactoryTalk ProductionCentre, FactoryTalk VantagePoint) connects directly to ControlLogix tags over EtherNet/IP. Third-party systems access ControlLogix data through EtherNet/IP explicit messaging or through OPC UA. A 5570 has no OPC UA server of its own, so OPC UA comes through Rockwell's FactoryTalk Linx Gateway or another OPC UA server; a ControlLogix 5580 or 5590 at firmware v36 or later also has an embedded OPC UA server (turned off until you enable it, and not on the 1756-L81E). This enterprise integration capability is a key reason ControlLogix is selected for plant-wide control systems.

Before these sections, the full Chapter 34 gives you the chapter's learning objectives and 34.1 The 1756 Chassis: The Foundation; 34.2 Power Supplies; 34.3 Controller Selection: The 1756-L7x Family; 34.4 I/O Modules: The 1756 I/O Family; 34.5 Communication Modules; 34.6 Backplane Communication: ControlBus and the Producer/Consumer Model; 34.7 Tag-Based Addressing: The Paradigm Shift; 34.8 Produced and Consumed Tags; 34.9 I/O Configuration in Studio 5000; 34.10 Program Architecture: Tasks, Programs, and Routines (with Knowledge Checks 34.1 and 34.2). After them it continues with 34.15 Why ControlLogix Is the Flagship; 34.16 The Transition from Legacy to Logix: What Changes in Your Workflow. It then gives you 1 more Knowledge Check (34.4), the Hands-On Exercises with 3 worked solutions, the Chapter Summary and Key Takeaways, and 3 Review Questions with model answers. Continue reading in the full manual: all 71 chapters and 4 appendices at this depth.
Free sample excerpt: Siemens platform chapter. Chapter 45, Sections 45.17 to 45.19 in full (online diagnostics and the diagnostic buffer, daily maintenance workflows, and the TIA Portal vs. Studio 5000 quick reference), with Knowledge Check 45.4. Reproduced exactly as it appears in the full manual, diagrams included.
Chapter 45

TIA Portal Mastery: The Complete Walkthrough

Reading tip: if you have TIA Portal access, you can read this chapter alongside Part III (Chapters 12-22) and practice the programming chapters in the real software.

In Chapter 39, you mastered Studio 5000 Logix Designer - the unified software environment for Allen-Bradley ControlLogix and CompactLogix. This chapter is the Siemens mirror image. TIA Portal (Totally Integrated Automation Portal) is the single engineering environment for every Siemens automation component: S7-1200 and S7-1500 controllers, WinCC HMI panels, SINAMICS drives, PROFINET networks, and safety systems. You have already used TIA Portal concepts throughout Chapters 42 through 44. In Chapter 43, you learned the basics with the S7-1200. In Chapter 44, you used TIA Portal Professional with the S7-1500. Each time, you learned just enough about the software to accomplish the task at hand. This chapter consolidates everything into one complete walkthrough. TIA Portal is the operating table where you examine, diagnose, and operate on every Siemens controller in the plant. It is where you create projects, configure hardware, write and edit programs, go online to troubleshoot, monitor data, trace signals, compare project versions, update firmware, manage libraries, and develop HMI screens. By the end of this chapter, you will navigate TIA Portal like you have used it for years - because you will understand not just what each feature does, but when and why you use it in the daily workflow of a maintenance professional. If Chapter 39 was your Studio 5000 mastery, this is your TIA Portal mastery. Together, they make you the technician who can walk into any plant, sit down at any workstation, and get to work.

45.17 Online Diagnostics: Beyond Program Monitoring

TIA Portal's diagnostic capabilities go far beyond program monitoring. When you are online with a CPU, you have access to a complete diagnostic suite that covers hardware, software, communication, and system status.

The Diagnostic Buffer

The diagnostic buffer is a timestamped event log stored in the CPU. It records:

  • CPU state changes (RUN to STOP, STOP to RUN, power cycles)
  • Hardware faults (module failures, PROFINET device loss, wire breaks on analog channels)
  • Program errors (OB not found, runtime errors, watchdog timeout)
  • User-defined diagnostic events (events your program generates using SFC or system functions)

Access the diagnostic buffer through Online > Online & Diagnostics > Diagnostic buffer, or by expanding the online diagnostics node in the project tree. Events are listed most recent first, with timestamps. Each event shows an event ID, a text description, and additional details. This is equivalent to the fault log in a ControlLogix controller, but typically more detailed, especially for hardware and communication events.

In the illustration below, Diagnostic buffer (1) is selected in the Online & diagnostics navigation. The events list (2) puts the newest entry at number 1. Select an entry to read its details (3), including the event ID. Help on event (4) explains the entry, and for a program error Open in editor (5) jumps to the block that caused it. Tick Freeze display (6) so new events do not move the list while you read.

Simplified illustration of TIA Portal Online and diagnostics for PLC_1 with the Diagnostic buffer open: 1 Diagnostic buffer in the Diagnostics navigation; 2 the events list, number 1 is the newest; 3 details on the selected event, including its event ID; 4 Help on event; 5 Open in editor; 6 Freeze display. The Functions group lists Assign IP address, Set time, Firmware update, Assign PROFINET device name, Reset to factory settings, and Format memory card. Events shown are examples. Your screen layout may differ by version. PLC_1 [CPU 1516F-3 PN/DP] > Online & diagnostics (simplified) Diagnostics General Diagnostic status Diagnostic buffer 1 Cycle time Memory PROFINET interface [X1] Functions Assign IP address Set time Firmware update Assign PROFINET device name Reset to factory settings Format memory card Diagnostic buffer Freeze display 6 Events (examples) No. Date and time Event 2 1 09/14/2026 06:02:11.415 IO device failure: Conv2_IO 2 09/14/2026 05:58:40.102 Wire break: analog input channel 3 3 09/14/2026 05:12:03.880 Operating mode change: STOP to RUN 4 09/14/2026 05:11:58.004 Power on Details on event 1 Description: IO device failure: Conv2_IO Event ID: shown here as a hex number Module, slot, and whether the event is incoming or outgoing 3 Help on event 4 Open in editor 5 Open it: Online > Online & diagnostics, or double-click Online & diagnostics under the PLC in the project tree, then select Diagnostic buffer. 1 Diagnostic buffer the CPU's timestamped event log 2 Events newest first - number 1 is the latest entry 3 Details on event full text, event ID, and the module involved 4 Help on event explains the entry and what to do about it 5 Open in editor for a program error, jumps to the block that caused it 6 Freeze display stops new events from moving the list while you read Simplified illustration - your screen layout may differ by version

Module Diagnostics

When you select a specific module in the online device view, the Inspector window shows module-level diagnostics:

  • Module status: OK, fault, maintenance required, or not available.
  • Channel-level diagnostics (S7-1500): Individual channel status for each I/O point. If an analog input channel has a wire break, the diagnostics identify the specific channel - not just the module. This per-channel diagnostic capability is more detailed than what ControlLogix provides, where faults are typically reported at the module or point level.
  • Communication status: For PROFINET devices, the diagnostics show link status, connection status, data exchange status, and error counters for each port.

PROFINET Diagnostics

For distributed I/O systems, PROFINET diagnostics are critical:

  • Device status in Network view. When online, Network view shows the status of every PROFINET device with color-coded icons: green (OK), yellow (maintenance required), red (fault), gray (not reachable).
  • Topology mismatch detection. If you configured the physical port connections in Topology view, TIA Portal detects when the actual cabling does not match the configured topology and highlights the mismatched connections.
  • Device replacement workflow. When replacing a failed PROFINET IO device, TIA Portal provides a guided workflow: assign the device name to the new hardware, verify the IP address, and confirm that data exchange resumes.

45.18 Putting It All Together: Daily Maintenance Workflows

Everything in this chapter exists to support specific maintenance workflows. Here are the most common scenarios and the TIA Portal operations each requires, organized as procedural references you can follow during the task.

Workflow 1: Machine Down - Immediate Troubleshooting

  1. Connect laptop to the PROFINET network (direct to CPU or through a plant switch).
  2. Launch TIA Portal. Open the project file for the affected machine.
  3. Go online (Ctrl+K). Verify that the offline/online comparison shows a match. If it does not, save a copy of your offline project, run Compare > Offline/Online to see what differs, and then upload the CPU's version so you troubleshoot the program that is actually running.
  4. Check the diagnostic buffer (Online > Online & Diagnostics > Diagnostic buffer). The most recent entry often identifies the root cause.
  5. If the fault involves a specific tag, use cross-reference (F11, or the Inspector window Info > Cross-references tab) to find every block that uses it.
  6. Open the relevant block. Switch on monitoring (Ctrl+T, or the "Monitoring on/off" toolbar button). Read the power flow to find where the logic is blocked.
  7. Use a watch table to monitor multiple related tags simultaneously.
  8. If the fault is an I/O device, check Network view for device status. Check module diagnostics for channel-level faults.
  9. Resolve the issue. If an online edit is needed, make the edit, compile, and download the affected block.
  10. Save the project (Ctrl+S). Archive to the network backup.

Workflow 2: Replacing a Failed PROFINET IO Device

  1. Identify the failed device from the CPU diagnostic buffer or from Network view (red icon on the failed device).
  2. Physically replace the device. Connect the Ethernet cable to the new device.
  3. Assign the device name to the new hardware. In TIA Portal's Network view, right-click the device and select Assign device name, then pick the new module from the list of accessible nodes (a factory-new module shows no device name) and assign the configured name. If the module came from another machine, reset it to factory settings first. On projects with configured topology and device replacement without exchangeable medium, the controller names a factory-new replacement automatically and this step is not needed. (Section 28.2)
  4. The IO controller (CPU) detects the correctly named device and resumes data exchange. Verify in Network view that the device shows green (OK).
  5. If the device is not automatically configured (rare with PROFINET IO), download the device configuration from TIA Portal.

Workflow 3: Backing Up the Current Program

  1. Connect to the CPU and go online.
  2. If mismatched, upload from the device (Online > Upload from device) to capture the current running program.
  3. Save the project with a descriptive name including the date (File > Save As, or Project > Save as).
  4. Archive the project (Project > Archive) to create a compressed .zap file. Store the .zap file on a network drive, USB drive, and/or in a version control system.
  5. Verify the archive by opening it on a different machine or by extracting and opening it in TIA Portal.

Workflow 4: Commissioning a New Device in an Existing System

  1. Open the project offline. Add the new hardware in Device configuration (drag from hardware catalog).
  2. Configure the device: assign I/O addresses, set module parameters, assign the PROFINET device name and IP address.
  3. In Network view, connect the new device to the appropriate IO controller.
  4. Create the PLC tags for the new I/O addresses in the tag table.
  5. Write the program logic for the new device in the appropriate blocks.
  6. Test in PLCSIM if possible.
  7. Schedule a maintenance window. Download the updated project to the CPU.
  8. Physically install the new device. Assign the device name.
  9. Verify data exchange in Network view. Test all new I/O points with watch tables.
  10. Test the new logic online. Verify correct operation. Save and archive.
âš™ The Cross-Platform Professional

If you have read both Chapter 39 (Studio 5000 Mastery) and this chapter, you now have the software knowledge base an SME works from for maintaining both Allen-Bradley and Siemens systems. Hours spent applying it on real equipment are what turn that knowledge into SME-level skill. Notice how the workflows are nearly identical between platforms: go online, check diagnostics, find the problem in the program, cross-reference the tag, monitor the logic, resolve the issue, save and archive. The menus are in different places. The shortcuts are different. The terminology changes (rungs vs. networks, Controller Organizer vs. project tree, tag database vs. tag tables). But the diagnostic thinking is universal. When you sit down at a plant that runs Siemens instead of Allen-Bradley, you are not starting from zero. You are translating between dialects of the same language. That translation ability is what makes you the technician every plant wants on their team.

45.19 TIA Portal vs. Studio 5000: Quick Reference

This table serves as a rapid translation guide between the two platforms. Keep it accessible when transitioning between environments.

Concept / Task TIA Portal Studio 5000
Project structure Folder on disk (multiple files). One project can contain multiple PLCs, HMIs, and drives. Single .ACD file. One project = one controller.
Navigation hub Project tree (left pane in Project view) Controller Organizer (left pane)
Hardware configuration Device configuration (graphical device view) I/O tree (hierarchical list)
Network topology view Network view (graphical, integrated) None built-in (FactoryTalk Linx browser shows devices, but no topology diagram)
Tag definition PLC tag tables + Data blocks Tag database (controller and program scope)
Main program entry point OB1 (Main) MainRoutine in MainProgram (Continuous Task)
Reusable logic with state Function Block (FB) + Instance DB Add-On Instruction (AOI)
Reusable logic without state Function (FC) Subroutine (JSR to a routine)
Timed/periodic execution Cyclic OB (e.g., OB35, configurable cycle time) Periodic Task (configurable rate)
Event-driven execution Hardware interrupt OB (e.g., OB40), diagnostic OB (OB82) Event Task (module input data state change, etc.)
Go online Ctrl+K (direct Ethernet, no middleware) Communications > Who Active (requires FactoryTalk Linx / RSLinx)
Cross-reference Tools > Cross-references (F11), or Inspector window > Info > Cross-references (Shift+F11) Ctrl+E
Real-time data monitoring Watch table Watch window / Quick Watch
Signal recording Trace (CPU-level, scan-cycle resolution) Trend (configured in Controller Organizer)
I/O forcing Force table (forces persist through power cycles and downloads) I/O forcing in tag monitor (forces persist through power cycles, may clear on download)
Project compare Compare > Offline/Online or Offline/Offline Tools > Compare
Firmware update Integrated in TIA Portal (Online > Online & Diagnostics) or via SIMATIC Memory Card ControlFLASH / ControlFLASH Plus (separate utility)
HMI development Integrated (WinCC in same project) Separate application (FactoryTalk View Studio)
Simulation PLCSIM (included) / PLCSIM Advanced (separate license) Emulator: FactoryTalk Logix Echo, a separate purchase that is not included with Studio 5000 (as of 2026 Rockwell offers a 30-day trial). It emulates ControlLogix 5580/5590, CompactLogix 5380 and their GuardLogix versions, not the 5570 or 5370, and it replaced the older Studio 5000 Logix Emulate (Section 12.10)
Library management Project library + Global library (types with versioning) Add-On Instructions (.L5X export/import)
Project archive format .zap (compressed archive) .ACD (project file, .ACD can be archived as .L5X)
✎ Knowledge Check 45.4
You are called to troubleshoot a Siemens S7-1500 system where a conveyor is not starting. You go online with TIA Portal and the program matches your offline project. You find the output tag for the conveyor motor (Q12.0) and open the cross-reference. It shows Q12.0 is written in three blocks: FC20 Network 4 (a SET instruction), FC22 Network 12 (a RESET instruction), and FC25 Network 1 (a direct coil assignment). All three blocks are called from OB1. What is the most likely cause of the unexpected output behavior, and what is the best diagnostic approach?
Correct: B. When cross-reference shows multiple blocks writing to the same output, the last write in the scan cycle wins. If FC25 executes after FC20 and FC22, and FC25's coil is de-energized, the output is off regardless of what FC20's SET did earlier in the scan. Determine the call order of FC20, FC22, and FC25 in OB1, then monitor each block online to see which SET, RESET, or coil instruction is active. This "last writer wins" behavior is the same in Siemens and Allen-Bradley - if multiple routines write to the same tag in Studio 5000, the last one in the execution order determines the final value. The cross-reference already told you the likely issue: three blocks competing for the same output.
Why the others are wrong:
A - Nothing points to the output module yet. The cross-reference already shows three competing writes to Q12.0, which explains the behavior without a hardware fault.
C - SET has no priority over later writes. Whichever instruction writes Q12.0 last in the scan decides its state, and FC25's coil may well be that last write.
D - The CPU never skips blocks because of load; a scan that runs too long trips the cycle time monitoring (watchdog) instead.
Before these sections, the full Chapter 45 gives you the chapter's learning objectives and 45.1 Portal View vs. Project View: Two Ways Into the Same Project; 45.2 Project Creation: Starting From Scratch; 45.3 Device Configuration: Defining the Hardware; 45.4 Network View: Seeing the Big Picture; 45.5 PLC Tag Tables: Organizing Your Data; 45.6 Program Blocks: Building the Logic; 45.7 The Program Editors: LAD, FBD, SCL, STL, and GRAPH; 45.8 Going Online: Connecting to a Running Controller; 45.9 Watch Tables, Force Tables, and the Trace Function; 45.10 Cross-References: Finding Everything; 45.11 Comparing and Merging Projects; 45.12 Firmware Management; 45.13 Library Management: Reusable Building Blocks; 45.14 HMI Integration: WinCC in TIA Portal; 45.15 PLCSIM: Offline Simulation; 45.16 Keyboard Shortcuts That Save Time (with Knowledge Checks 45.1, 45.2, and 45.3). After them it gives you the Hands-On Exercises with 3 worked solutions, the Chapter Summary and Key Takeaways, and 3 Review Questions with model answers. Continue reading in the full manual: all 71 chapters and 4 appendices at this depth.
Free sample excerpt: Chapter 60, Sections 60.1 and 60.2 in full. Reproduced exactly as it appears in the full manual.
Chapter 60

Communication Troubleshooting

You have fifty-nine chapters behind you. You understand EtherNet/IP from Chapter 27, PROFINET and PROFIBUS from Chapter 28, Modbus and serial protocols from Chapter 29, and networking fundamentals from Chapter 26. You know what these protocols are, how they work, and how to configure them. This chapter teaches you what to do when they stop working. Communication failures are one of the most common causes of unplanned PLC system downtime. Many technicians who support ControlLogix systems will tell you the same thing: connection timeout faults - lost communication with a remote I/O rack, a drive, a third-party device - are among the most frequent entries in the fault log. The reason is simple: communication depends on a chain of components, and every link in that chain can fail. The cable. The connector. The switch port. The switch power supply. The module hardware. The module configuration. The IP address. The device name. The baud rate. The termination resistor. The firmware version. The network load. The electrical noise from a VFD cable running parallel to your Ethernet cable. Any one of these can break the chain, and the PLC's response is always the same: "connection timed out." That single fault message tells you nothing about which link failed. Your job is to find it. This chapter gives you a systematic method for doing exactly that - starting at the physical layer and working up through data link, network, and application, using the right diagnostic tools at each layer, on every protocol you will encounter in the field. The technicians who master this material do not guess. They do not swap parts randomly. They do not call the integrator first. They work the problem from the bottom up, isolate the failure in minutes, and fix it. That habit is one of the things that separates a parts-swapping technician from the subject-matter expert the plant calls when everyone else is stuck.

📘 Learning Objectives

By the end of this chapter, you will be able to:

  1. Apply the layered method, physical layer first, and use the failure pattern (one device or many at once) before touching hardware
  2. Diagnose physical-layer and link faults with link LEDs, switch port counters, and a cable tester, including a duplex mismatch
  3. Troubleshoot an EtherNet/IP connection fault when link, ping, and port counters are all good
  4. Bring a PROFINET device online by its device name, including a replacement interface module
  5. Isolate a fault on a Modbus RTU RS-485 daisy chain from which slaves respond
  6. Find a duplicate IP address and document a network segment in an IP address spreadsheet
  7. Troubleshoot legacy networks (DH+, Remote I/O, DH-485, DeviceNet and ControlNet) with the one-rate, unique-address and two-terminator rules, the right de-energized and energized meter checks, and each network's status codes

How this chapter checks your progress: Objective 1: Knowledge Check 60.1; Review Question 60.1; Exercise 60.13.1. Objective 2: Knowledge Check 60.1; Review Question 60.2; Exercise 60.13.2. Objective 3: Knowledge Check 60.4. Objective 4: Knowledge Check 60.2; Review Question 60.3. Objective 5: Knowledge Check 60.3. Objective 6: Exercise 60.13.3; Chapter 71 sign-off row 16; Chapter 71 capstone (Fault Card 11). Objective 7: Review Questions 60.4 and 60.5. Use the worked solutions under the exercises to check your own work.

Also covered in this chapter: RS-232 and RS-485 serial wiring, termination and bias, Modbus exception codes, intermittent communication faults, Wireshark captures of industrial protocols, and network documentation.

📘 Quick Guide

Core chapter - study it in depth. This chapter is on the Core Path for every reader (see the Recommended Study Plan at the front of the manual).

If you only have 20 minutes: the maintenance points that matter most in this chapter.

  • Work from the bottom up, starting with a five-minute physical check before you open a laptop: power LED, connectors fully seated, link LED at both ends, activity LED, and any red or amber LEDs. Do not move to higher layers until you have a link light (Section 60.1).
  • Read the failure pattern before you touch hardware. Two independent lines dropping at once points to a shared resource, such as a switch whose power supply failed. If every device drops at the same moment, check the PLC fault log and the switch uptime counter before you blame the network (Sections 60.1 and 60.9).
  • A managed switch tells you what the LEDs cannot. CRC errors mean cable damage or EMI, collisions on a modern port mean a duplex mismatch, and discards mean congestion. The counters are cumulative, so compare them with a baseline you recorded during normal operation (Section 60.3).
  • On EtherNet/IP, read the NS indicator first: flashing green means the device has an IP address but no connection, flashing red means a connection timed out, and solid red means a duplicate IP. Set each RPI to the slowest value the application can tolerate, not the fastest the device accepts (Section 60.5).
  • PROFINET finds devices by name, not IP address. "IO device not found" usually means the device has no name, the wrong name, or a replacement that never got the old name. Check with "Accessible devices", and pick the name from the project instead of retyping it (Section 60.6).
  • On a Modbus RTU daisy chain, the break is between the last slave that responds and the first one that does not. If no slave responds, check baud rate, parity, and stop bits on every device, A/B polarity, and termination: about 60 ohms between A and B with every device powered off (Section 60.7).
  • A maintenance laptop with a leftover static IP can knock a PLC or I/O rack offline. Check your IP address spreadsheet before you plug in. To confirm a conflict, clear the ARP entry, ping again, and see whether the MAC address changes (Section 60.4).

On the job: one-page checklist. Print this list and keep it where you do the work.

Walk to the device and do the physical check: power LED (meter the supply and check the fuse or breaker if it is off), connectors seated and M12 rings tight, link and activity LEDs, red or amber LEDs. If this means opening an energized panel, have a qualified person open it and follow your site's PPE and LOTO rules.
Note whether one device or many dropped. If many dropped at once, look first at what they share, such as the switch and its power supply, or the PLC itself.
Before you connect your laptop, confirm in the IP address spreadsheet that its address is free on that network.
Swap in a known-good patch cable. If the link does not come back, test the permanent run with a cable tester (a TDR shows the distance to a break).
Ping the device from a laptop on the same subnet. If it fails, check the IP address, subnet mask, VLAN, and arp -a for a conflict.
Read the switch port counters (CRC errors, collisions, discards), compare them with your baseline, and check speed and duplex at both ends of the link.
At the application layer, read the module fault code in the Studio 5000 I/O tree or the TIA Portal diagnostic buffer, or read a known register with a standalone Modbus poll tool.
On a replacement device, assign the PROFINET name from the hardware configuration, or compare the catalog number, series, and firmware against the I/O tree entry.
For an intermittent fault, match the fault timestamps against temperature, vibration, equipment operation, and network traffic. Run a ring-buffer Wireshark capture on a mirrored port (Section 60.10).
After any device change, update the IP address spreadsheet and network map, and back up the switch configuration.

60.1 The Layered Troubleshooting Method: Bottom-Up, Every Time

âš  Why This Matters to You

A food processing plant runs three Allen-Bradley ControlLogix lines. At 10 PM on a Thursday, two of the three lines go down simultaneously. The operators report that HMIs on both lines froze and then displayed communication loss alarms. The third line is still running. The on-call technician arrives and finds both ControlLogix processors are faulted with connection timeout errors on their remote I/O racks. The remote racks are in different locations. The two affected lines share one network switch in the main MCC room. The third line, still running, connects through a different switch. The technician checks the shared switch - all LEDs are dark. The switch has lost power. A 24VDC power supply feeding the switch has failed. The technician swaps the power supply from the spare parts shelf, the switch boots in 45 seconds, both ControlLogix processors re-establish their I/O connections, the technician clears the faults, and both lines are running in under ten minutes. Without systematic troubleshooting knowledge, a different technician might have spent an hour at the remote racks swapping modules, checking cables, and rebooting processors - because the fault messages pointed at the remote devices, not at the switch. The clue was that two independent lines failed simultaneously. That points to a shared resource. The shared resource was the switch. The switch was dead because its power supply failed. Ten minutes versus two hours. That is what this chapter teaches you.

Amprobe clamp meter with test leads for measuring current and voltage - the meter that checks the 24 VDC supply feeding a network switch or I/O adapter, the first test in the physical layer
Network troubleshooting starts at Layer 1, and Layer 1 starts with power. In the story above, a meter check of the 24 VDC feeding the shared switch finds the fault before any network tool is needed.
Photo: “Multimeter used to test conductivity”. By Connor.delaney6. Source: https://commons.wikimedia.org/wiki/File:Multimeter_used_to_test_conductivity.JPG. License: CC BY-SA 3.0, https://creativecommons.org/licenses/by-sa/3.0/. Resized.

Communication troubleshooting has a method, and the method is non-negotiable: start at the physical layer and work up. This is not a suggestion. It is not one approach among many. It is the approach that works, and every experienced controls engineer and network specialist uses it whether they articulate it that way or not. The reason is practical: in most plants, the large majority of communication failures turn out to be physical layer problems. Bad cables, loose connectors, failed switch ports, dead power supplies. If you skip the physical layer and start troubleshooting at the application layer - checking PLC configurations, verifying IP addresses, analyzing protocol settings - you will waste time on most of the failures you encounter.

The layered model is a simplified form of the OSI model you learned in Chapter 26. The first three rows below are OSI Layers 1, 2, and 3. The fourth row groups everything above the network layer - OSI Layers 4 through 7, from transport up to the application protocol - because on the plant floor you troubleshoot those together as "the application". So for industrial communication troubleshooting, there are four levels that matter. When this chapter says "the application layer" or "the upper layers", it means that whole group, not OSI Layer 4 (transport) on its own.

Layer What It Covers Diagnostic Tools Common Failures
1 - Physical Cables, connectors, patch panels, switch hardware, module hardware, power supplies, fiber optic links Visual inspection, LED indicators, cable testers, TDR, fiber light meter, multimeter Damaged cable, loose connector, broken fiber, failed switch, failed module, lost power, wrong cable type
2 - Data Link Ethernet frames, MAC addressing, switch forwarding, duplex negotiation, VLAN tagging Switch port statistics, error counters, MAC address tables, Wireshark (Layer 2 capture) CRC errors, duplex mismatch, excessive collisions, VLAN misconfiguration, MAC table overflow
3 - Network IP addressing, subnetting, routing, ARP resolution, ICMP (ping) Ping, traceroute, ARP table (arp -a), ipconfig/ifconfig, Wireshark (Layer 3 capture) IP conflict, wrong subnet mask, wrong gateway, ARP failure, routing issue between subnets
Upper layers (OSI 4-7) - Application EtherNet/IP CIP, PROFINET IO, Modbus TCP/RTU, protocol-specific configuration PLC diagnostic buffers, protocol analyzers, Wireshark with protocol dissectors, platform-specific tools (RSLinx, TIA Portal diagnostics, Modbus poll) RPI timeout, wrong device name, wrong module configuration, firmware mismatch, wrong function code, exception responses
âš™ The 70/20/10 Rule of Thumb for Communication Failures

A common rule of thumb among network techs is 70/20/10: in a well-maintained industrial network, roughly 70% of communication failures are physical layer, 20% are network layer (IP configuration), and 10% are application layer (protocol configuration). It is field wisdom, not a measured statistic, and the split varies from plant to plant, but the order holds. In a poorly maintained network, the physical layer share is even higher. This is why you always start at the bottom. If you troubleshoot top-down, you will spend 30 minutes analyzing protocol configurations for a problem that turns out to be a cable someone ran over with a forklift. Start at Layer 1. Look at the LEDs. Check the cables. Verify power. Then move up.

The Five-Minute Physical Check

Before you open a laptop, before you launch any software, before you log into any switch - do a five-minute physical check. Walk to the device that lost communication and answer these questions with your eyes and hands:

  • Does the device have power? Check the power LED on the device. Check the power supply voltage with a multimeter if the LED is off. Check the fuse or circuit breaker feeding the power supply. A dead device cannot communicate. This sounds obvious. It catches problems far more often than you would expect.
  • Is the Ethernet cable connected at both ends? Push the RJ45 connector in firmly and listen for the click. For M12 connectors, verify the connector is fully seated and the locking ring is tight. A connector that looks connected but is not fully seated is one of the most common physical layer failures in industrial environments.
  • Is the link LED on? Check the link LED on the device's Ethernet port and on the switch port it connects to. Link LED on means the physical layer is working - there is electrical connectivity between the two endpoints. Link LED off means Layer 1 is broken. Do not proceed to higher layers until you have a link light.
  • Is the activity LED blinking? Link with no activity means the physical connection is good but no data is flowing. Link with activity means data is being exchanged. This tells you whether the problem is above Layer 1.
  • Are there any red or amber LEDs? Red LEDs on PLC modules, drives, and managed switches indicate fault conditions. Amber LEDs often indicate warnings or degraded states. Read them. They are the device telling you what is wrong.

This five-minute walk-through eliminates the majority of communication failures before you touch a keyboard. The technicians who consistently resolve communication problems fastest are not the ones with the most sophisticated tools - they are the ones who never skip the physical check.

60.2 Cable and Connector Troubleshooting

Cables and connectors are the most vulnerable components in any industrial network. They run through cable trays with sharp edges. They pass through conduit with tight bends. They get stepped on, run over, pinched by panel doors, and soaked by washdowns. They connect to devices that vibrate, devices in hot enclosures, and devices in cold outdoor environments. The cable itself might be rated for all of those conditions. The connector termination - the point where a human being stripped wire, crimped pins, and tightened screws - is only as good as the person who made it.

Common Cable Failures

Failure Type Cause Symptoms How to Detect
Open (broken conductor) Physical damage, excessive bend radius, pull tension during installation, vibration fatigue at connector Complete loss of link (link LED off on both ends). If one of the pairs that only Gigabit uses (pins 4-5 or 7-8) is broken, many switches and network cards "downshift" and link at 100 Mbps instead of 1 Gbps (which requires all four pairs). A broken 1-2 or 3-6 pair kills the link at any speed. A port that should run at 1 Gbps but shows 100 Mbps is a cable clue. Cable tester shows open on specific pair. TDR shows distance to break. Simple continuity test with multimeter on disconnected cable.
Short (conductors touching) Crushed cable, water intrusion corroding insulation, improper termination (whiskers from stripped conductors touching adjacent pins) Complete loss of link. Switch port may show error state. Cable tester shows short between specific conductors. Multimeter shows near-zero resistance between pins that should be isolated.
Miswire (wrong pinout) Conductors landed on the wrong pins, reversed within a pair, or terminated to no standard at all. Common on field-terminated cables. Opens, shorts, reversed wires, or wires on the wrong pins: no link or an erratic link. Note that a cable with T568A on one end and T568B on the other is just a crossover cable - nearly every modern switch and industrial device has Auto-MDIX and links normally through it, and Gigabit ports also correct pair swaps and polarity on their own. So a link that comes up does not prove the wiremap is right. Cable tester with wiremap function shows exactly which pins are connected to which.
Split pair Wires from different twisted pairs used for a single signal pair. Continuity test passes, but the twist geometry is wrong, destroying crosstalk cancellation. Link may establish but with high error rates. Intermittent communication. Works on short runs, fails on longer runs. Cable tester continuity test passes - this is the danger. Cable tester with NEXT (Near End CrossTalk) testing. A basic wiremap-only tester will NOT catch split pairs. You need a tester that measures crosstalk.
Excessive length Cable run exceeds 100-meter maximum for copper Ethernet (328 feet, including patch cables at both ends) Intermittent link drops, CRC errors, reduced speed negotiation. May work when the environment is cool and fail when it heats up (resistance increases with temperature). Cable tester with length measurement. TDR. Verify total path length including all patch cables.
EMI interference Ethernet cable routed parallel to VFD power cables, near large contactors, or through areas with welding equipment. Unshielded cable in high-EMI environment. Intermittent CRC errors on switch port counters. Communication works most of the time but drops under specific conditions (when a particular motor starts, when welding occurs nearby). Correlate communication errors with equipment operation. Check cable routing against installation standards (minimum separation from power cables). Switch port error counters show CRC errors correlated with events.

Cable Testers and TDR

A cable tester is not optional equipment for a PLC maintenance technician. You need one. The type you need depends on what you are testing (prices are approximate as of 2026 and will change):

Basic cable tester (wiremap only): Tests continuity, identifies opens, shorts, and miswires. Does NOT test cable quality, crosstalk, or length. Costs $50-$200. Examples: Fluke MicroMapper, Klein VDV Scout Pro. This is the minimum for verifying patch cables and field-terminated connectors. It catches the most common wiring errors but will not catch split pairs or marginal cable quality.

Qualification tester: Tests wiremap plus cable length, bandwidth capability, and basic crosstalk. Can determine if a cable will support 100 Mbps or 1 Gbps. Costs $500-$1,500. Examples: Fluke CableIQ, Fluke LinkRunner. This is the recommended level for industrial maintenance. It catches everything a basic tester catches plus split pairs and length violations.

Certification tester: Full TIA/ISO certification testing including insertion loss, NEXT, ELFEXT, return loss, propagation delay, and delay skew. Produces a pass/fail report against a specific cable standard (Cat5e, Cat6, Cat6A). Costs $5,000-$15,000. Examples: Fluke DSX-5000, Fluke DSX-8000. This is an installation contractor tool. You do not need one for maintenance unless you are also responsible for installing new cable infrastructure.

TDR (Time Domain Reflectometer): Sends a pulse down the cable and measures reflections. Tells you the distance to a fault (open, short, impedance mismatch) with accuracy of a few feet. Built into many qualification and certification testers. Some standalone TDR tools exist. A TDR is invaluable for finding cable breaks in long runs where you know the cable is bad but do not know where the damage is. If you have a 250-foot cable run through a cable tray and the TDR says the break is at 180 feet, you know exactly where to look instead of pulling the entire cable.

M12 Connector Issues

Industrial Ethernet environments use M12 D-coded connectors (4-pin, for 100 Mbps) and M12 X-coded connectors (8-pin, for Gigabit). M12 connectors are robust, IP67-rated, and designed for vibration and washdown environments. But they have failure modes that RJ45 connectors do not:

  • Locking ring not fully tightened: The M12 connector has a threaded locking ring. If it is not fully tightened, the connector can vibrate loose over time. This is a very common M12 failure mode. The symptoms are intermittent: the connection works when the connector happens to be making good contact and drops when vibration pulls it slightly apart. Hand-tight is not tight enough. Use a wrench or connector tool to achieve the specified torque (typically 0.5-0.6 Nm for M12).
  • Cross-threaded locking ring: If the locking ring is cross-threaded, it feels tight but the connector is not fully seated. The pins may not make full contact. Symptoms are identical to a loose connector: intermittent or no link.
  • Contaminated contacts: In washdown environments, if the IP67 seal is compromised (cracked gasket, damaged connector body), water enters the connector and corrodes the pins. This can cause intermittent contact or short circuits between pins.
  • Wrong coding: M12 connectors come in multiple codings (A-coded for sensors, B-coded for PROFIBUS, D-coded for 100 Mbps Ethernet, X-coded for Gigabit Ethernet). Physically, different codings have different key positions to prevent cross-connection. But field wiring mistakes happen - someone uses an A-coded connector shell with Ethernet pinout, or uses a D-coded connector where X-coded is required for Gigabit.
âš  The Patch Cable Swap Test

When you suspect a cable problem but cannot immediately test the installed cable, the fastest diagnostic is the patch cable swap test. Disconnect the short patch cable between the device and the panel-mounted jack (or between the switch and the patch panel). Replace it with a known-good patch cable. If the link comes back, the original patch cable was the problem. If it does not, the problem is in the permanent cable run, the device, or the switch port. This takes 30 seconds and eliminates one of the most common failure points. Keep a few known-good Cat5e and Cat6 patch cables in your tool bag at all times. Label them "KNOWN GOOD - TEST ONLY" and never leave them installed permanently. They are diagnostic tools, not repair parts.

The full Chapter 60 continues with 60.3 Switch Diagnostics: Port Statistics and Error Counters; 60.4 IP Address Conflicts: Detection and Resolution; 60.5 EtherNet/IP Troubleshooting; 60.6 PROFINET Troubleshooting; 60.7 Modbus Troubleshooting; 60.8 Serial Communication Troubleshooting: RS-232 and RS-485; 60.9 Intermittent Communication Faults: The Hardest Problems; 60.10 Wireshark for Industrial Protocols; 60.11 Network Documentation: Your Most Valuable Troubleshooting Asset; 60.12 Communication Troubleshooting Master Decision Table. It then gives you 4 more Knowledge Checks (60.1-60.4), the Hands-On Exercises with 3 worked solutions, the Chapter Summary and Key Takeaways, and 5 Review Questions with model answers. Continue reading in the full manual: all 71 chapters and 4 appendices at this depth.
Free sample excerpt: the Chapter 71 capstone. You see the machine, the troubleshooting method, one of the 12 fault cards, the rubric, and the first 10 rows of the skills sign-off sheet.
Chapter 71

Capstone: Build, Break, and Fix

Everything in this manual has led to this chapter. You have learned the pieces one at a time: inputs and outputs, ladder logic, timers, counters, math, sequences, analog scaling, alarms, networks, safety, troubleshooting, and change management. A plant does not hand you pieces. It hands you a machine, a drawing package, and a problem at 3 a.m. This chapter gives you one complete machine, the Batch Mix and Transfer Skid, and asks you to do the whole job on it. You will read its written Sequence of Operation, build its I/O list and tag database, write and run its program, commission it point by point, and document it the way Chapter 66 describes. Then you, or a partner, will break it on purpose with twelve fault cards, and you will find and fix each fault using the methods from the troubleshooting chapters. The skid is small enough to run on the practice bench you built in Section 12.10 (a MicroLogix 1100 or a Micro820, nine toggle switches, two potentiometers, six LED indicators, and a two-contact E-stop) and complete enough to implement properly in Studio 5000 Logix Designer or TIA Portal. When you can build this skid, prove it, break it, and fix it without looking at the answers, you are no longer someone who has read about PLCs. You are someone who can maintain, troubleshoot, and program them.

P and ID of the Batch Mix and Transfer Skid: ingredient valves XV-101 and XV-102 with closed limit switches ZSC-101 and ZSC-102 feed mix tank T-101, which has agitator M-101 on a VFD, heater H-101 controlled by PLC function TIC-102 from TT-102, level transmitter LT-101, level switches LSH-101 and LSL-101, an independent high limit TSHH-102, and transfer pump P-101 to the holding tank.SINGREDIENT AXV-101ZSC101SINGREDIENT BXV-102ZSC102T-101MM-101 (VFD)H-101 HEATERTT102TIC102LSH101LT101LSL101TSHH102independent high limit,opens heater powerP-101TO HOLDING TANKCircle: field instrument. Diamond in square: PLC function.Dashed line: electrical signal. S: solenoid actuator.
The capstone machine. From Chapter 71, Section 71.2, “The Machine: Batch Mix and Transfer Skid”.
Section 71.2 of the full chapter describes this skid in full, followed by its sequence of operation, I/O list and tag database, safety requirements, program structure and key rungs, required deliverables, and a 12-test commissioning plan.

71.9 Break It: The Twelve Fault Cards

This is where the capstone turns into troubleshooting practice. The best way to use the cards is with a partner: your partner opens a card's answer, injects the fault while you are out of the room, and closes the answer. You come back to a skid that "was working yesterday." If you work alone, inject a card, then set it aside for a day before you try it, so you do not remember what you did.

Work every card the same way, using the cycle from Chapter 57:

  1. Observe. What is the skid doing? What step is it in? Which alarms, in what order? What do the controller and I/O status indicators show? Check forces.
  2. Name the domain (Section 57.3): mechanical, electrical, PLC hardware, network, or program logic.
  3. Choose the tool: the program online, the cross-reference, a meter, the I/O list, the compare tool.
  4. Find it, fix it, and prove the fix by rerunning the functional test that covers it.
  5. Write it up: the root cause with the 5 Whys (Section 57.6) and a work-order entry (Section 57.13).

Time yourself. Record your time, the domain you named first, and whether it was right. That record is what the rubric grades.

🛠 Fault Card 2: The Pump Runs on the Screen, Not in the Tank
Symptom: The batch reaches TRANSFER. P101_Run is on in the program and the controller's status indicator for O:0/4 is lit, but the pump indicator stays dark and the level does not fall. Ten minutes later ALM06 trips with Fault_Step = 50.

Hints: The controller says it is doing its job. Section 8.12 (systematic procedure for failed outputs) and Section 8.8 (fuse protection). What does a relay output need besides a closed contact?
Inject (partner): with the bench unplugged, remove the +24 VDC jumper (or pull the inline fuse) that feeds the VAC/VDC terminal for O:0/4. Each relay output on this controller has its own.

Find it: Domain: electrical, and the point of this card is to prove that before anyone blames the PLC hardware. The logic is true and the status indicator shows the controller energized the relay, so work outward with a meter. Measure from the O:0/4 terminal to 0 V: 0 V. Measure at that group's VAC/VDC terminal: 0 V. There is no source for the contact to pass. Trace the feed back to the missing jumper or the open fuse.

Fix: Unplug, restore the feed, and on a real skid find out why a fuse opened before you replace it with the same rating (a shorted coil or a pinched wire). Never upsize a fuse to make it hold.

Root cause and lesson: An open output supply circuit. The status indicator only proves the controller's side. The TRANSFER timeout caught it; on the real skid, a pump running-feedback input would catch it in seconds, which is a good design improvement to write up.

On the Micro820 bench: O-04, O-05, and O-06 share one common, CM3, so removing the CM3 feed would also darken the heater and change the symptom. Use one of these two injections. (A) Same symptom: with the bench unplugged, lift the wire from O-05 to the pump indicator at the indicator end. In TRANSFER, P101_Run is on and the O-05 output status indicator is lit, the pump indicator stays dark, and ALM06 trips after 10 minutes with Fault_Step = 50. Measure from O-05 to 0 V: 24 V, so the contact and its CM3 feed are good. Measure at the pump indicator's terminal: 0 V. The break is in the field wire between them. (B) Same lesson about the missing source: with the bench unplugged, remove the feed to CM3. Now the batch sticks in HEAT with H101_Cmd on and the O-04 status indicator lit, but the heater indicator dark and the temperature not rising, and 30 minutes later ALM06 trips with Fault_Step = 30. Measure from O-04 to 0 V: 0 V. Measure at CM3: 0 V. Trace the feed back to the missing jumper or the open fuse. On a shared common, one missing feed takes out every output in the group, and that pattern is itself a clue.
Fault Cards 1 and 3 through 12 are in the full chapter, followed by Knowledge Check 71.3.

71.10 Self-Grading Rubric

Grade yourself honestly, or better, have an experienced tech grade you, and have them witness the practical skills on the sign-off sheet in Section 71.11. Each row scores 1 to 4. The target is at least 3 in every row, and 4 in Safety. A score of 1 or 2 in Safety means the capstone is not complete, whatever the total. This rubric is for your own development; it is separate from the manual's Final Assessment.

Criterion 1 - Not yet 2 - Developing 3 - Proficient 4 - Exemplary (SME-track)
Function The normal batch does not complete The normal batch completes; some SOO conditions are missing All twelve functional tests pass All tests pass on the first run, and you found and fixed an SOO gap
Safety E-stop or guard handled in PLC logic, or a force used to get running Hardwired stop present, but reset restarts something, or the independent limits pass through the PLC Hardwired stop; the PLC only monitors; no automatic restart; no forces Level 3, plus LOTO on every hands-on step and every safety behavior tested and signed
Program quality One routine, hard-coded numbers Routines exist; some double writes or magic numbers remain Section 71.6 structure, one writer per output, setpoints in tags, every rung commented Level 3, plus reusable valve logic (AOI or FB) and a clean cross-reference
Commissioning No checkout records Some points checked; no loop checks Every point checked at the device and signed; loop checks at 0, 50, and 100% Level 3, plus acceptance criteria met with zero open punch items
Documentation Program only I/O list or SOO, but not both All eight deliverables in Section 71.7 Level 3, and a tech who has never seen the skid can find any point in under a minute
Troubleshooting Fewer than 6 cards solved 6 to 9 cards solved, some by trial and error All 12 solved, domain named correctly on at least 9 All 12, domain right on at least 11, each in under 20 minutes, with a written root cause
Change management No backup Backup exists but is not verified Verified backups, a change log entry for every change, card 12 found with the compare tool Level 3, plus a written change request with a rollback plan for one change

71.11 Skills Sign-Off Sheet

This sign-off sheet, not the written Final Assessment, is how an employer verifies hands-on skill: the Final Assessment shows what you know, and each initialed row shows that a qualified person watched you do the job. Print it and keep it with your portfolio. Ask a supervisor, a lead technician, or a mentor who is qualified on the equipment to watch you perform each skill. They initial a row only when you did the whole task correctly and safely without coaching. Skills on your bench count; skills performed on a plant machine count only under your site's procedures and with your employer's authorization.

Evaluator Guidance

  • Who may sign. A supervisor, lead technician, instructor, or mentor who can perform the skill themselves, knows the platform the learner is using, and is qualified on the equipment under your site's rules. For row 1, and for any row performed on plant equipment rather than the bench, the evaluator must also be authorized under the site's lockout/tagout and electrical safety program, and any energized measurement is made only by a qualified person, as NFPA 70E uses that term, under the site's energized-work procedure. The learner never initials their own sheet, and a fellow learner does not sign.
  • How to observe. Watch the whole task live, from start to finish. The learner performs it; describing it does not count. You may answer questions about the equipment (where a terminal is, which pot is which), but not about the method. If the learner needed coaching on the method, leave the row blank for that session and write what was missing. Initial a row only when you saw every part of its pass criterion. The pass criteria below are the minimum; your site may add its own.
  • Safety stop rule. Stop the task at once, by word and, if needed, by removing power, if the learner starts hands-on work before the energy is removed and verified; reaches into energized parts outside the site's energized-work procedure; forces, jumpers, or bypasses the E-stop, the guard, Safety_OK, LSH-101, or any other protective input; restarts equipment without warning or with someone in the way; or does anything else that could hurt a person or damage equipment. A safety stop ends that attempt. The row is not initialed, the reason and date are written on the sheet, and the learner repeats the whole task on a later attempt, not just the step that was stopped. Record the stop when you score the Safety row of the rubric in Section 71.10.
  • Records. Write the date and your initials in the row, complete the name, title, signature, and date table below the sheet, and keep a copy with the learner's portfolio. An employer can file a copy with its training records.
# Practical skill (performed, not described) Where taught Pass criterion: what the evaluator must see Date performed Supervisor or mentor initials
1Remove energy before hands-on work: unplug the bench and keep the plug in your control, or apply your site's lockout/tagout and verify zero energy with a tested meterChapter 6; Section 71.5, Rule 5Before any terminal is touched: the plug pulled and kept in the learner's control, or the learner's own lock and tag applied under the site procedure. The meter is proved on a known live source, the points to be worked on (supply terminals, and +24 VDC to 0 V) test dead, and the meter is proved again on the live source. No hands-on work starts before this, and a PLC output reading 0 or a controller in Program mode is never treated as isolation.
2Wire a 24 VDC input and a relay output with its source, and explain every common connectionSection 12.10; Chapters 7 and 8The wiring matches the learner's bench drawing and is done with the bench unplugged. The input device switches +24 VDC to the input terminal, with that group's input common to 0 V; the output group's VAC/VDC terminal is fed from its fused source, and the load returns to 0 V. The learner points to each common and says what current flows through it, then proves both points: the input bit follows the device, and the load runs when the output is commanded.
3Wire the two-contact E-stop so it removes output power without the PLC, and prove it (FT-03)Section 12.10; Section 71.5One NC contact of the E-stop is in series with the +24 VDC that feeds the output groups for O:0/0 to O:0/4, and the second NC contact is wired to I:0/9 (Safety_OK). With a process output commanded on, pressing the E-stop darkens every process output indicator at once, even though the output bit can still be 1 in the program; the beacon still works; releasing and resetting restarts nothing until Start is pressed. FT-03 is recorded as a pass.
4Diagnose a failed digital input with a meter and the program onlineSection 7.10; Fault Card 1On a fault the learner did not see injected: the learner goes online and confirms the input bit does not follow the device, measures at the input terminal against its common with the device operated and released, and says from those readings whether the fault is in the field (device or wiring) or at the input point. The fault is found and fixed with the energy removed, and the fix is proved by operating the device and watching the bit change. No part is swapped before the measurements point to it.
5Diagnose a failed output by measuring outward from the output terminalSection 8.12; Fault Card 2The learner confirms the rung is true and the output status indicator is on, then measures to 0 V at the output terminal, the group's VAC/VDC terminal, and the load, one point at a time, moving outward until the reading changes, and names the break from that change. The fault is fixed with the energy removed, and the load is proved running. The controller or module is not blamed or swapped before the measurements show it.
6Loop check an analog input at 0, 50, and 100% and record the meter reading, raw count, and scaled valueSections 9.6, 9.9, and 64.10; Section 71.8For each analog channel, the learner sets 0%, 50%, and 100% of range (0.00, 5.00, and 10.00 V on the bench), measured with the meter at the input terminals, and records the meter reading, the raw count, and the scaled value at each point. The scaled values are within the checkout-sheet tolerance (plus or minus 1%), only the channel being moved changes, and the alarms trip at their setpoints.
7Make the first connection to a controller and confirm its catalog number and firmwareSection 12.10Without help, the learner sets the laptop's Ethernet port to a static address on the controller's subnet (or sets up the driver and port the platform uses), finds or sets the controller's address, browses to it, and reads the catalog number and firmware revision from the controller itself. Both are recorded and compared with the nameplate and with what the project expects, and the existing program is uploaded before anything is downloaded over it.
8Write, download, and test a start/stop seal-in with an NC stop examined with XICChapter 13The stop condition (the NC stop button, examined with XIC) is in series ahead of a branch in which the seal-in contact wraps only Start. Online, the evaluator sees: Start latches the output, releasing Start keeps it on, and Stop drops it. With the stop wire lifted (bench unplugged, then powered back up), Start cannot turn the output on. The learner explains why XIC is the right instruction for an NC-wired stop.
9Write and test timer and counter logic, including the preset and time baseChapters 14 and 15; Fault Card 8The learner writes an on-delay timer and a count-up counter (or the platform's equivalents), downloads, and shows online the accumulator rising to the preset, the done bit setting, and each reset working. The learner states the real time (preset times time base on a MicroLogix, milliseconds in Logix, the time value in IEC), checks it with a stopwatch, and shows the counter counting once per false-to-true transition of its input, not once per scan.
10Write a sequence with step timeouts and find where a stuck sequence is waitingChapter 19; Fault Card 4The sequence has a step number, a transition condition out of every step, and a timeout on every step that waits on a physical condition (Section 19.14; a step that ends on its own timer, such as MIX, and the IDLE step need none); each timeout raises an alarm and records the step where it stopped. With a transition held false by the evaluator, the learner uses the step number and reads the transition rung to name the exact condition the sequence is waiting for, without guessing or forcing, and proves it by making that condition true.
The full sheet has 20 rows. The other 10 are: 11. Build the I/O list and tag database in the Chapter 66 format; 12. Commission the skid: I/O checkout at the device and outputs commanded from Checkout mode, with no forcing; 13. Run the functional test script, including the power-loss test, and record the results; 14. Check for forces on going online, find a force, and remove it correctly; 15. Find a double-coiled output with the cross-reference and correct it; 16. Find a duplicate IP address with network diagnostic tools; 17. Take a verified backup and compare the controller against the approved program; 18. Solve an unseen fault card: name the domain, find and fix the fault, prove the fix, and write the root cause and work-order entry; 19. Make one online edit to a running program with a change log entry, then save the offline file (Extended tier); 20. Present the complete capstone deliverables package and walk a reviewer through it. It ends with signature lines for the learner and the supervisor or mentor.
The full Chapter 71 also includes the Hands-On Exercises for every capstone checkpoint, complete example programs, the Chapter Summary, and the Chapter Review Questions. The Final Assessment draws its questions from the chapters; the capstone is assessed hands-on with its rubric and sign-off sheet.

Try the Final Assessment: 10 Sample Questions

These 10 questions are taken word for word from the Final Assessment pool, one from each of 10 different Parts of the book, with 4 choices each. Answer them, press Submit, and you get your score and an explanation for every question, just as the full manual grades its exams. The answer choices are shuffled each time you open this page or press Try Again, as they are on every attempt in the full manual.

In the full manual, each Full Exam draws 135 questions from the pool of 289, balanced across the Parts of the book, and 95 correct (70%) passes.

Question 1 Part I, Chapter 3
An SLC 5/05 normally scans in about 10 ms. Since a second HMI was added, polling large data tables over Ethernet, the scan time climbs toward 25 ms, although no logic, I/O module, or task setting has changed. Using the four-phase scan cycle, which phase is absorbing the extra time?
Question 2 Part II, Chapter 7
A technician installs a PNP proximity sensor on an input module that has its COM terminal wired to DC+ (positive rail). The input LED never illuminates even though the sensor's own LED confirms target detection. What is wrong?
Question 3 Part III, Chapter 14
A TON with a 5-second preset never sets its DN bit. Online, the timer's EN bit stays solidly on, but ACC keeps snapping back to zero before it gets anywhere near 5 seconds. What should you check next?
Question 4 Part IV, Chapter 23
A tank temperature loop's HMI faceplate shows 190 F as the target, 182 F from the RTD, and the controller output at 64%, driving a steam valve. An operator asks what each number is. Which reading of the faceplate is correct?
Question 5 Part V, Chapter 27
A new firewall is installed between a ControlLogix and its remote I/O adapter. It passes TCP port 44818 but blocks UDP port 2222. What do you expect to see?
Question 6 Part VI, Chapter 34
In a ControlLogix 5570 system, the controller can be installed in any slot in the 1756 chassis. What is the reason for this flexibility?
Question 7 Part VII, Chapter 44
A signal module on an S7-1500 rack has failed. There is no bill of materials in the panel, the module's label is unreadable, and your laptop is at the other end of the plant. How can you get its exact order number and firmware version right now?
Question 8 Part X, Chapter 53
A PowerFlex 525 on EtherNet/IP faulted and has been repaired, but pressing Reset on the HMI does not clear its fault. Online, you see the drive's fault reset command bit is held at 1 all the time; a programmer set it that way to keep the drive clear. Why does the fault not clear?
Question 9 Part XI, Chapter 55
What is the fundamental architectural difference between a standard PLC and a safety PLC that enables the safety PLC to achieve a SIL 3 rating?
Question 10 Part XII, Chapter 58
A ControlLogix 5570 controller's OK LED is flashing red and the controller is in Faulted mode. Studio 5000 shows 'Major Fault - Type 4, Code 20.' What type of problem does this indicate, and what should the technician do?
0 of 10 answered

Try Practice Mode: 3 Chapter Knowledge Checks

Practice mode in the full manual quizzes you on the chapter Knowledge Checks. Here are 3 of them, word for word from Chapters 9, 58, and 67. Pick an answer for each and press Check My Answers. You will see whether each answer is right; if it is wrong, you see why the answer you chose is wrong, in the book's own words, then the correct answer and the full explanation.

Q1 Knowledge Check 9.1, Ch. 9: Analog Inputs: Signals, Scaling, and Calibration
A 4-20mA pressure transmitter with a range of 0-200 PSI is connected to a PLC analog input. The PLC reads 0mA on this channel. What does this indicate?
Q2 Knowledge Check 58.2, Ch. 58: Fault Codes, Diagnostic Buffers, and Status Registers
You are maintaining an SLC 5/04 processor at a water treatment facility. The processor is faulted: the RUN indicator is off and the FLT indicator is flashing red. You go online with RSLogix 500 and check the status file. S:1/13 = 1 and S:6 = 0454h. What does this tell you, and what is the most likely cause?
Q3 Knowledge Check 67.3, Ch. 67: Industrial Cybersecurity Fundamentals
It is the middle of the night. A critical production line is down. The PLC has faulted and you need to connect with your engineering laptop to diagnose the issue. Your approved engineering laptop is at the other facility, 45 minutes away. You have your personal laptop in your car with Studio 5000 installed (a licensed copy from your previous employer). The control network port is available in the panel. The plant manager is calling every 15 minutes asking when the line will be back up. What should you do?
From the Full Manual's Legal Page

License Terms

Read the terms before you buy. This is the copyright notice and license text from the full manual, word for word.

© 2026 UrWrench LLC. All rights reserved.

No part of this manual may be reproduced, distributed, or transmitted in any form or by any means, including photocopying, recording, or other electronic or mechanical methods, without the prior written permission of the publisher, except as permitted under the license terms below.

License Tiers

LicensePriceDetails
Individual License$199One named person, for personal and professional use
Business License$999Unlimited employees and contractors of the licensed company, for internal training only

License Terms in Plain Language

Individual License ($199). The license belongs to one named person: the buyer. You may use the manual for your own study and your own work, at home or on the job, and keep copies on the computers, tablets, and phones you use yourself. It is yours alone. Do not share your copy, or access to it, with anyone else, including co-workers. A co-worker who wants the manual needs a license of their own, or your company needs a Business License. If a company pays for an Individual License, the license still belongs to the one person named on the purchase.

Business License ($999). The license belongs to one company: the legal entity named on the purchase, at all of its sites. A parent company, subsidiary, affiliate, or any other separate legal entity needs a license of its own. Any number of the licensed company’s employees and contractors may use the manual, for training inside the company only. Contractors may use it only for work they do for the licensed company. The manual may not be shared with anyone outside the licensed company, such as other companies, customers, suppliers, or the public.

Where a Business License copy may be kept. The licensed company may store the manual on a secured internal network drive, intranet, or learning management system (LMS) that only its own employees and contractors can reach, and on the devices they use for company training. It may not be posted on a public website or on any system that people outside the company can reach.

When people leave. When an employee leaves the licensed company, or a contractor’s work for it ends, that person’s right to use the manual ends. They must stop using it and delete or return any company copies, electronic or printed.

Printing. Under either license you may print pages for your own use. Business licensees may also print pages and chapters for internal training, such as shop binders, class handouts, and laminated quick-reference pages like the troubleshooting checklist in Chapter 57 or the tables in Appendix C. Printed copies carry the same limits as the file: they stay with the licensed person, or inside the licensed company.

How printing works in the file. The printer button in the manual prints the chapter, the Part, or the range of chapters you choose, with or without the quiz answers. Printing the whole file straight from the browser’s own Print menu is blocked and produces only a notice page, so use the printer button instead. Every printed copy, however it was made, is covered by the license: the same terms apply to paper as to the file.

Proof of license. Your purchase receipt or invoice is your license record, so keep it. A licensed copy may also show the licensee’s name.

Licensee stamp. Copies purchased from UrWrench are stamped with the licensee’s name and a license ID. The stamp appears on the cover, at the top of this page, on everything printed with the printer button (in the line at the top of the printout, and in the page footer and side margin, which most current browsers repeat on every printed page), and on the Final Assessment course completion document. A review or unstamped copy has no licensee line at all: it shows no licensee name and no license ID. If your purchased copy is not stamped, or the stamp is wrong, write to sales@urwrench.com.

Permanent license and updated editions. The license is permanent. If UrWrench releases an updated edition, license holders receive it at no extra cost.

Refunds. Refunds are handled under the policy shown at the point of purchase.

No resale. You may not sell, sublicense, rent, or give away the manual or a copy of it, and you may not pass the license on to another person or company. Anything these terms do not allow stays under the copyright notice above.

No warranty (“as is”). To the extent permitted by law, the manual is provided “as is”, without warranty of any kind, express or implied, including any implied warranty of merchantability, fitness for a particular purpose, accuracy, or non-infringement. UrWrench LLC and the author do not warrant that the manual is free of errors, that it will meet your requirements, or that it satisfies the rules of any particular site, standard, or regulator. Some places do not allow implied warranties to be excluded, so some of these exclusions may not apply to you. This does not affect refunds under the policy shown at the point of purchase.

Limitation of liability. To the extent permitted by law, the total liability of UrWrench LLC and the author for any claim relating to this manual is limited to the price paid for the license, and neither is liable for indirect, incidental, special, or consequential damages, such as lost production, lost profits, or damaged equipment.

Questions. If you are not sure whether a use is covered, ask first at sales@urwrench.com.

Ready for the Full Training?

The complete PLC Maintenance Mastery Training Manual includes:

✓ 71 chapters + 4 appendices, including the Chapter 71 Build, Break, and Fix capstone
✓ 520 interactive Knowledge Checks and Review Questions (284 + 236)
✓ 195 worked solutions for the Hands-On Exercises in Chapters 1-70
✓ 12 capstone fault cards, a self-grading rubric, and a skills sign-off sheet
✓ 1,390 callouts (warnings, tips, field experience notes)
✓ 289 technical diagrams (ladder logic, wiring, SFC, FBD, timing, network, safety, block diagrams and simplified software screens)
✓ 68 photos
✓ 16 PLC platforms covered in depth, plus the legacy Modicon 984
✓ Allen-Bradley, Siemens, and Schneider Electric ecosystems, plus Appendix D on other brands
✓ Final Assessment: 289-question pool, 135 questions per attempt with a 3-hour time limit that keeps running once you start, a 24-hour wait between attempts, optional platform tracks (Allen-Bradley, Siemens or Schneider focus), an optional proctored closed-book declaration, an attempt record and a results export, plus a Practice mode built from the chapter Knowledge Checks
✓ Four-semester study plan with a core path for maintenance technicians
✓ Printable course completion document for your own records
✓ Works completely offline - no internet required

$199 Individual License  |  $999 Business License

Individual License: one named person, for personal and professional use. Business License: unlimited employees and contractors of the licensed company, for internal training only.

The license is permanent. If UrWrench releases an updated edition, license holders receive it at no extra cost. Read the full license terms.

Contact us to purchase: sales@urwrench.com

UrWrench LLC

By Erick T. Colunga