Automation

Ladder logic

A ladder program is an ordered stack of rungs read once per scan: series contacts are AND, parallel branches are OR, and a coil writes the process image the moment its rung is solved, so the next rungs already see the new value. This tool checks a program structurally — every input combination, timer outputs treated as constrained free variables — and runs it on a bench with a real clock, scan by scan.

Calculate now

Free, no sign-up. Runs in your browser — nothing you type leaves this page.

When to use

When writing or reviewing PLC logic before download: a start/stop command with seal-in, a star-delta transition with a TON, a parts counter, a set/reset latch. It is especially useful for the defects that compile without complaint — the same coil written in two rungs, a field NC stop read by an NC contact, an emergency stop in a parallel branch, a rung reading a coil written further down.

A ladder program is ordered, and order is behaviour

In ladder, contacts and coils are not physical parts: they are references to symbols in a table that ties the field address to the logic. Each rung has a series/parallel network and one or more outputs, and the PLC solves the rungs top to bottom in every scan. A coil writes the process image at once, so a rung below already reads the new value; a rung above reads it one scan later. That is why the same logic can behave differently just by moving a rung — and why this tool checks order explicitly.

A seal-in rung is the software image of a hard-wired contactor circuit: the same K1 = (S1 + K1) · S0 · EMG drawn with real contacts and coils is checked by the relay logic simulator. The outputs these rungs drive are usually the starters of a motor control centre, whose drawers, breakers and contactors are sized in MCC drawer sizing.

What the structural check covers

The tool verifies the symbol table (undeclared, duplicated tags or addresses), the shape of each rung (no output, no contact, shorted branch, contradiction, the same contact twice), the writes (one symbol, one coil; plain coil mixed with SET/RESET; SET without RESET; timer or counter driven twice), the field polarity of inputs against how they are read, and the emergency stop reach. It then sweeps every combination of inputs and timer/counter outputs — up to 12 variables — to flag outputs always on or never reached, inputs with no effect, and programs that cycle between scans.

Emergency stop and field polarity

The emergency must be NC in the field (ISO 13850 §4.3.4, IEC 60204-1 §10.7.4) and read by an NO contact in the rungs that energise outputs. Then the tool follows dominance: does operating the emergency force every physical output to 0, through series, parallel and intermediate coils, in scan order? An emergency in a parallel branch, a bypass key over it or an output that the emergency never reaches fails the program. A latched SET/RESET output is reported as not assessed, because the ladder alone does not say whether an active SET re-energises it on the next scan.

The bench: timers and counters with a clock

The verdict answers “can the program ever do this”; the bench answers “what happens from here”. It scans the program against a virtual clock — 10 ms per scan by default — running TON, TOF, TP and RTO timers and CTU, CTD and CTUD counters for real, showing power flow rung by rung. Inputs can be toggled and memory bits forced; a forced bit that a coil rewrites lasts one scan, exactly as on a PLC.

Where the inputs and outputs come from

The symbols in the table are addresses in the process image, and on a real plant many of them arrive over a fieldbus rather than on a local I/O card: remote I/O and drives on a PROFIBUS DP network, motor starters on DeviceNet, or field instruments on Ethernet-APL. This tool does not model the network — the bus cycle adds to the response time on top of the scan — so those segments are sized in their own tools. The hard-wired field signals — stop, emergency, overload contacts — go into the cable list of the project.

What this tool does not cover

JMP/LBL, MCR, subroutines and user function blocks, FOR loops, comparison and math instructions, certified safety function blocks and indirect addressing are out of scope. The structural verdict ignores presets, CPU scan time and field device delays. It does not determine Performance Level (ISO 13849-1) or SIL (IEC 62061), and “no findings” means none of the implemented checks fired. For hard-wired contactor circuits, use the relay logic tool.

Formulas and fundamentals

Rung network series: A · B | parallel: A + B | NC contact: /A = ¬A | rising edge: ↑A = A ∧ ¬A(previous scan)

The network is a series/parallel tree of contacts, nested up to 12 levels; a bridge arrangement is not representable (nor compiled by Siemens LAD or Studio 5000). Contacts and coils are references to a declared symbol of class I, Q, M, T or C.

Scan semantics read inputs → solve rungs 1…N in order → write outputs

A coil writes the process image immediately: rungs below see the new value in the same scan. A contact reading a symbol written in a later rung sees the previous scan's value — a one-scan lag, flagged as read-before-write.

Timer and counter constraints (structural analysis) TON: Q ⇒ IN | TOF: IN ⇒ Q | reset ⇒ ¬Q

In the verdict, the output of each timer and counter is swept as a free variable restricted by the block semantics. Combinations violating the restriction are not physically reachable and are discarded. The question answered is "is there any instant in which the program does X", not "when".

Timers on the bench TON: ET = min(PT, ET + Δt) while IN, else ET = 0; Q = (ET ≥ PT)

On the bench the blocks run against a virtual clock with step Δt = scan time. TOF holds Q for PT after IN falls; TP gives a PT pulse on the rising edge of IN; RTO accumulates and holds when IN falls, cleared only by reset.

Counters on the bench CTU: CV = CV + 1 on ↑CU, Q = (CV ≥ PV) | CTD: CV = CV − 1 on ↑CD, Q = (CV ≤ 0)

Counting happens on the rising edge of the count input. Reset clears a CTU and reloads PV into a CTD.

Emergency stop reach (dominance) series dominated ⇔ any child dominated | parallel dominated ⇔ all children dominated

A symbol declared as emergency dominates; a NO contact on a dominated symbol dominates; a coil written by a dominated rung becomes dominated, following intermediate coils in scan order. Edge contacts never dominate (a one-scan pulse does not hold an output at zero). Outputs written by SET/RESET are reported as not assessed.

Stabilisation between scans state(k) = state(k − p): p = 1 stable, p > 1 cyclic

The program is scanned repeatedly with constant inputs until a state repeats. Period 1 is a fixed point; a longer period means outputs blinking at the CPU scan rate. No repetition within 64 scans is an error.

Standards & methods

  • IEC 61131-3 — Ladder Diagram (LD) language and notation (also shown as Siemens LAD and Rockwell Studio 5000 mnemonics)
  • ISO 13850 §4.1.1 — emergency stop must act on every hazardous output and must not be overridden
  • ISO 13850 §4.3.4 and IEC 60204-1 §10.7.4 — emergency device with positive opening (NC in the field)
  • IEC 60204-1 §9.2.2 — every machine command needs a stop function
  • IEC 60204-1 §9.4.2.1 — inverted reading of an NC field device fails to the unsafe side
  • ISO 13849-1 and IEC 62061 — PL and SIL not determined (declared out of scope)

Typical reference values

Quantity Typical range Note
Sweep variables for the exhaustive analysis up to 12 (field inputs read + timer/counter outputs read) 4096 combinations; above that the always-on, unreachable and no-effect checks are not stated
State table rows emitted up to 8 variables (256 rows) —
Scans to stabilise 64 —
Program limits 100 rungs · 200 symbols · 40 elements per rung · nesting depth 12 —
Bench scan time 10 ms default, 1 to 10000 ms —
Timer blocks TON · TOF · TP · RTO (preset in ms) —
Counter blocks CTU · CTD · CTUD (preset PV) —
Contacts and coils — IEC / Siemens LAD / Studio 5000 NO --| |-- XIC · NC --|/|-- XIO · coil --( )-- OTE · set (S) OTL · reset (R) OTU —

Worked example

Star-delta start with seal-in, TON transition and emergency stop

Inputs

S1 start (%I0.0)
NO in the field read by NO contact
S0 stop, EMG emergency, FT1 overload (%I0.1–%I0.3)
NC in the field read by NO contacts
Rung D1 — run command M-MARCHA
(S1 + M-MARCHA) · S0 · EMG · FT1 seal-in
Rung D2 — timer T-TRANS (TON)
5000 ms, driven by M-MARCHA
Rungs D3 / D4 — star / delta contactors
M-MARCHA · /T-TRANS | M-MARCHA · T-TRANS · /K-ESTRELA —
Bench scan time
10 ms

Results

Verdict
OK 0 errors, 0 warnings, 3 information notes
Sweep variables
5 4 inputs + T-TRANS output → 32 combinations
Feasible combinations
17 of 32 15 discarded by TON (Q ⇒ IN)
Rest state
stable after 1 scan all outputs at 0
S1 pulse at t = 10 ms
M-MARCHA = 1, K-ESTRELA = 1 sealed, timer counting
Transition at t = 5.00 s (ET = PT)
K-ESTRELA = 0, K-TRIANGULO = 1 same scan, no overlap
EMG opened
all outputs = 0 in the next scan, ET reset to 0

The verdict carries three information notes: S0 and EMG are NC in the field and read by NO contacts (the intended fail-safe reading), 15 of the 32 combinations are unreachable because a TON cannot be done with its input at 0, and timing is outside the structural analysis. The bench fills that gap: the star contactor drops and the delta picks up in the same scan at 5.00 s, because D4 reads K-ESTRELA written in D3 just above — no one-scan lag. Opening EMG drops the run command, and through it both contactors, in one scan.

Run your own calculation Create a free account and get this for your own inputs in seconds.

Common mistakes

  • Reading an NC field stop or emergency by an NC contact in a rung that energises an output. The chain then enables only with the signal at 0 — button pressed, wire broken or terminal loose. For stop and emergency it is an error; without a declared role it is a warning.
  • Declaring the emergency stop as NO in the field. ISO 13850 §4.3.4 and IEC 60204-1 §10.7.4 require positive opening; a broken wire would leave the emergency without effect. It is an error.
  • Writing the same coil in two rungs. Vendor editors compile it with a warning and the last write of the scan wins, which makes behaviour depend on rung order. Here it is an error, as is mixing a plain coil with SET/RESET on the same symbol.
  • Sealing a command with no condition in series, K1 = S1 + K1. Nothing can turn it off; IEC 60204-1 §9.2.2 requires a stop function. It is an error regardless of notation — the same command written with SET is failed as SET without RESET.
  • Putting the emergency in a parallel branch, or a bypass key in parallel with it. The other branch closing is enough to keep the output energised: the emergency does not reach that output, and a bypass over it is an error under ISO 13850 §4.1.1.
  • Reading a coil written further down the program. The value arrives one scan late; if the emergency reaches an output only through that coil, the output stays on for one full scan after the stop is pressed.
  • Leaving a timer without a preset. With PT absent or zero the block switches in the first scan and the delay does not exist.

Frequently asked questions

Why read an NC emergency stop with an NO contact (XIC)?

Because an NC field device sits at 1 at rest. Read by an NO contact, the rung enables only while the signal is 1, so pressing the button, a broken wire or a loose terminal all drop the command. Read by an NC contact, the rung would enable only at 0 — exactly the failure states — which is a fail-to-danger inversion.

Is a double coil really an error? My PLC compiles it.

It compiles, and the last write of the scan wins. That makes the output depend on rung order, which a signed memorial cannot rely on. The tool treats it as a design rule: combine the conditions in one network, or accumulate in memory bits and write the output in a single rung. SET/RESET pairs are exempt.

How does the tool deal with timers if it does not simulate time in the verdict?

In the structural analysis each timer output is a free variable constrained by the block — a TON cannot be done with its input at 0. That answers whether the program can ever do something, for any preset. The bench runs the timers against a clock to show when.

How does it check that the emergency stop reaches every output?

By dominance: operating the emergency must force each physical output to 0, following series and parallel and chains of intermediate coils in scan order. An emergency in a parallel branch does not dominate, an edge contact does not count, and outputs held by SET/RESET are reported as not assessed.

Does it support Siemens LAD and Studio 5000 notation?

The notation is a project attribute: IEC 61131-3 names, Siemens LAD symbols or Studio 5000 mnemonics (XIC, XIO, OTE, OTL, OTU, ONS). It changes labels on the screen and in the memorial, never the evaluation.

What is out of scope?

JMP/LBL, MCR, subroutines and user function blocks, FOR loops, comparison and math instructions, certified safety blocks and indirect addressing. It does not determine ISO 13849-1 Performance Level or IEC 62061 SIL.

Glossary

Rung
One line of the ladder program — a contact network and one or more outputs.
Process image
Memory copy of inputs and outputs that the rungs read and write during the scan.
Seal-in
NO contact of the coil itself in parallel with the start condition, holding the coil on.
TON
On-delay timer — output Q goes to 1 when input IN has stayed at 1 for the preset PT.
Double coil
The same symbol written by more than one coil instruction; the last write in the scan wins.
Read-before-write
Contact reading a symbol whose coil is in a later rung, seeing the previous scan's value.