STW1 is the 16-bit control word the PLC writes; ZSW1 is the 16-bit status word the drive returns. Several STW1 bits must be held at 1 permanently for the drive to be runnable at all — including bit 10, "control by PLC", which is the most commonly forgotten. In practice you write just two values: 16#047E puts the drive in the ready state, and 16#047F adds bit 0 and starts the motor. Returning to 16#047E produces a controlled ramp stop. On the feedback side, ZSW1 bit 2 (operation enabled) is the only honest "running" signal — never drive an HMI lamp from your own command bit.
- OFF2 and OFF3 are active-low: the bits must be 1 for normal operation, and clearing them stops the drive.
- Pass through
16#047Ebefore16#047F. Jumping from 0 straight to the run value often fails. - Bit 7, fault acknowledge, is edge-triggered. Holding it high hides a repeating fault that will damage the motor.
- Every Siemens drive implementing PROFIdrive uses these same bits, so this knowledge transfers from G120 to S120 unchanged.
Try it first: the Live PLC–VFD Simulator lets you set these bits and watch STW1 and ZSW1 change in your browser — no PLC needed.
Why a Bit Pattern Instead of Commands
A SINAMICS drive runs a state machine defined by the PROFIdrive profile. It moves between states such as "switching on inhibited", "ready to switch on", "ready to operate" and "operation enabled", and it changes state only when the control word presents the right bit pattern for that transition.
This is why there is no "start" instruction. The PLC does not command an action; it presents a condition, and the drive's state machine responds. Understanding that distinction resolves most of the confusion beginners have with drive integration — including why a value that looks correct sometimes does nothing.
Block Diagram: Telegram 1 Words Between PLC and G120
Before decoding the bits, see where the words travel. With Standard Telegram 1 the PLC and the drive exchange two 16-bit words in each direction on every PROFINET cycle — STW1 is the first word the PLC writes, ZSW1 the first word it reads back.
Where are STW2 and ZSW2? Not in a 2/2 telegram. In Standard Telegram 1 the second word out is the speed setpoint NSOLL_A and the second word in is the actual speed NIST_A. Many projects label them CW_02 or "word 2", which is fine, but the real STW2 and ZSW2 only appear in larger telegrams such as Telegram 3 — see SINAMICS G120 Telegram Types Compared.
| Word | PLC address | Bytes | Drive side | Content |
|---|---|---|---|---|
| PZD1 out | %QW256 | %QB256 (bits 8–15), %QB257 (bits 0–7) | r2050[0] → r2090 | STW1 control word |
| PZD2 out | %QW258 | %QB258, %QB259 | r2050[1] | NSOLL_A speed setpoint |
| PZD1 in | %IW256 | %IB256 (bits 8–15), %IB257 (bits 0–7) | p2051[0] = r0052 | ZSW1 status word |
| PZD2 in | %IW258 | %IB258, %IB259 | p2051[1] = r0063 | NIST_A actual speed |
STW1 — Every Control Bit
| Bit | Name | Tag name (copy) | Meaning when 1 | Normal handling | Default value | Binary → Hex | STW1 value |
|---|---|---|---|---|---|---|---|
| 0 | ON / OFF1 | ON_OFF1 | Run. A falling edge ramps the drive down using the configured deceleration time. | Driven by the machine sequence | 0 | Bits 3–01110 = E | 16#047EReady to operate |
| 1 | OFF2 | OFF2 | No coast stop. Clearing it removes pulses instantly and the motor coasts. | Held at 1 | 1 | ||
| 2 | OFF3 | OFF3 | No quick stop. Clearing it stops on the separate, faster OFF3 ramp. | Held at 1 | 1 | ||
| 3 | Enable operation | En_Oper | Pulse enable — the output stage may switch. | Held at 1 | 1 | ||
| 4 | Enable ramp generator | En_RFG | Without it the ramp output is forced to zero. | Held at 1 | 1 | Bits 7–40111 = 7 | |
| 5 | Continue ramp generator | Cont_RFG | Without it the ramp output freezes at its current value. | Held at 1 | 1 | ||
| 6 | Enable setpoint | En_SP | Allows NSOLL_A to reach the ramp generator. | Held at 1 | 1 | ||
| 7 | Acknowledge fault | Ack_Flt | Rising edge clears an acknowledgeable fault. | Pulsed only | 0 | ||
| 8 | Reserved | Res_08 | Not used in standard operation | Left at 0 | 0 | Bits 11–80100 = 4 | |
| 9 | Reserved | Res_09 | Not used in standard operation | Left at 0 | 0 | ||
| 10 | Control by PLC | Ctrl_PLC | The drive accepts the telegram at all. | Held at 1 — most commonly forgotten | 1 | ||
| 11 | Reverse | Rev | Inverts the sign of the setpoint. | Only where mechanics allow reverse | 0 | ||
| 12 | Reserved | Res_12 | Not used in standard operation | Left at 0 | 0 | Bits 15–120000 = 0 | |
| 13 | MOP raise | MOP_Up | Raises the motor potentiometer setpoint while held. | Usually 0 | 0 | ||
| 14 | MOP lower | MOP_Dn | Lowers the motor potentiometer setpoint while held. | Usually 0 | 0 | ||
| 15 | CDS select | CDS | Selects command data set 1 instead of 0. | Usually 0 | 0 |
Read each hex digit from the bottom of its group upwards: the lowest bit is the rightmost binary digit. Bits 3–0 give 1110 = E, bits 7–4 give 0111 = 7, bits 11–8 give 0100 = 4 and bits 15–12 give 0000 = 0. Written from bit 15 down to bit 0 that is 16#047E.
Short tag names with the bit address and a comment. Copy the list into your tag table, watch table or documentation. The addresses assume the telegram starts at %QW256; Siemens stores the high byte first, so bits 0–7 sit in %Q257 and bits 8–15 in %Q256. Change the byte numbers to match your hardware configuration and keep the swap.
// STW1 - word %QW256 (bits 0-7 = byte %Q257, bits 8-15 = byte %Q256)
// Name Type Address Comment
ON_OFF1 Bool %Q257.0 // Bit 0 - ON / OFF1 ramp stop
OFF2 Bool %Q257.1 // Bit 1 - No coast stop - keep TRUE
OFF3 Bool %Q257.2 // Bit 2 - No quick stop - keep TRUE
En_Oper Bool %Q257.3 // Bit 3 - Enable operation (pulses)
En_RFG Bool %Q257.4 // Bit 4 - Enable ramp generator
Cont_RFG Bool %Q257.5 // Bit 5 - Continue ramp generator
En_SP Bool %Q257.6 // Bit 6 - Enable setpoint
Ack_Flt Bool %Q257.7 // Bit 7 - Fault acknowledge - pulse only
Res_08 Bool %Q256.0 // Bit 8 - Reserved
Res_09 Bool %Q256.1 // Bit 9 - Reserved
Ctrl_PLC Bool %Q256.2 // Bit 10 - Control by PLC - keep TRUE
Rev Bool %Q256.3 // Bit 11 - Reverse direction
Res_12 Bool %Q256.4 // Bit 12 - Reserved
MOP_Up Bool %Q256.5 // Bit 13 - Motor potentiometer raise
MOP_Dn Bool %Q256.6 // Bit 14 - Motor potentiometer lower
CDS Bool %Q256.7 // Bit 15 - Command data set select
The active-low behaviour of bits 1 and 2 catches people out. OFF2 and OFF3 are enables, not commands. A PLC that leaves them at 0 while setting bit 0 has told the drive both to run and to coast, and the drive obeys the stop.
Practise the state machine on live hardware
Drive the control word by hand, watch the status word respond, then wrap it in a reusable block. Pune classroom or live online.
The Three Values You Actually Write
| Value | Bits set | Effect |
|---|---|---|
16#0000 | None | Everything disabled. The drive sits in switching-on-inhibited. |
16#047E | 1, 2, 3, 4, 5, 6, 10 | Ready to operate. Enabled and waiting, motor stationary. |
16#047F | Above plus bit 0 | Running. The motor ramps to the setpoint. |
16#04FE | 047E plus bit 7 | Fault acknowledge pulse from the ready state |
The sequence matters. Hold 16#047E for at least one PLC scan and confirm the drive reports ready before writing 16#047F. Many first integrations write the run value immediately at power-up, find nothing happens, and start suspecting the network — when the state machine simply never passed through the ready state.
Stopping is the same transition in reverse. Writing 16#047E clears bit 0 and produces an OFF1 ramp stop using the drive's deceleration time. Writing 16#0000 instead clears the OFF2 enable as well and the motor coasts — a different and usually unintended outcome.
ZSW1 — Every Status Bit
| Bit | Meaning when 1 | Tag name (copy) | Use it for |
|---|---|---|---|
| 0 | Ready to switch on | Rdy_SwOn | Precondition before issuing the run command |
| 1 | Ready to operate | Rdy_Oper | Confirms the drive accepted the enable bits |
| 2 | Operation enabled | Oper_En | The genuine "running" feedback for HMI and interlocks |
| 3 | Fault active | Fault | Alarm condition; latch and display with the fault number |
| 4 | No coast stop active | No_OFF2 | Confirms OFF2 is not asserted |
| 5 | No quick stop active | No_OFF3 | Confirms OFF3 is not asserted |
| 6 | Switching on inhibited | SwOn_Inh | Explains a drive that refuses to start after a fault |
| 7 | Warning active | Warning | Log it, do not stop the machine |
| 8 | Speed deviation within tolerance | Spd_OK | "At speed" permissive for downstream equipment |
| 9 | Control requested | Ctrl_Req | The drive is asking the PLC to take control |
| 10 | Comparison speed reached or exceeded | Spd_Cmp | Threshold signalling |
| 11 | Setpoint reached / limit not exceeded | No_Limit | Detects a drive stuck at a current or torque limit |
| 12 | Application specific | App_12 | Brake control and similar functions, set by drive parameters |
| 13 | Application specific | App_13 | Brake control and similar functions, set by drive parameters |
| 14 | Application specific | App_14 | Brake control and similar functions, set by drive parameters |
| 15 | Application specific | App_15 | Brake control and similar functions, set by drive parameters |
Short tag names with the bit address and a comment. Copy the list into your tag table, watch table or documentation. The addresses assume the telegram starts at %IW256; Siemens stores the high byte first, so bits 0–7 sit in %I257 and bits 8–15 in %I256. Change the byte numbers to match your hardware configuration and keep the swap.
// ZSW1 - word %IW256 (bits 0-7 = byte %I257, bits 8-15 = byte %I256)
// Name Type Address Comment
Rdy_SwOn Bool %I257.0 // Bit 0 - Ready to switch on
Rdy_Oper Bool %I257.1 // Bit 1 - Ready to operate
Oper_En Bool %I257.2 // Bit 2 - Operation enabled - real running signal
Fault Bool %I257.3 // Bit 3 - Fault active
No_OFF2 Bool %I257.4 // Bit 4 - No coast stop active
No_OFF3 Bool %I257.5 // Bit 5 - No quick stop active
SwOn_Inh Bool %I257.6 // Bit 6 - Switching on inhibited
Warning Bool %I257.7 // Bit 7 - Warning active
Spd_OK Bool %I256.0 // Bit 8 - Speed deviation within tolerance
Ctrl_Req Bool %I256.1 // Bit 9 - Control requested
Spd_Cmp Bool %I256.2 // Bit 10 - Comparison speed reached
No_Limit Bool %I256.3 // Bit 11 - Setpoint reached / limit not exceeded
App_12 Bool %I256.4 // Bit 12 - Application specific
App_13 Bool %I256.5 // Bit 13 - Application specific
App_14 Bool %I256.6 // Bit 14 - Application specific
App_15 Bool %I256.7 // Bit 15 - Application specific
Bit 6, switching on inhibited, is the underused one. A drive that will not start after a fault is usually reporting this bit, and the cause is that the run command was still present when the fault cleared. The state machine requires the run bit to go low and high again — an important detail if your program holds bit 0 permanently.
Using ZSW1 Correctly on the HMI
The rule is simple and frequently broken: show what the drive says, not what the PLC asked for.
A green "running" lamp driven from the PLC's own command bit will stay lit while the drive is tripped, because the command is still being written. The operator sees a running machine that is not turning. Drive the lamp from ZSW1 bit 2 instead and the indication is always truthful.
The same applies to interlocks. A downstream conveyor that starts because the upstream drive was commanded to run, rather than because it reports operation enabled, will start into a stationary line. Use bit 2 for run interlocks and bit 8 or 11 where the downstream equipment needs the upstream drive to be at speed.
Fault Acknowledge Is an Edge
Bit 7 clears a fault on its rising edge. Holding it at 1 permanently is a mistake that looks like a working system: faults clear the instant they appear, the HMI stays green, and nobody notices that a motor is tripping on overload every thirty seconds until the winding fails.
Handle it properly in code. Detect a rising edge on the operator's reset input, set bit 7 for a short fixed time — around 200 ms — then clear it. A single scan is not enough: it can be shorter than the PROFINET update time, so the pulse may never reach the drive. In a reusable function block this belongs inside the block with a static "previous state" variable, so no caller can get it wrong.
Also acknowledge only what the operator asked for. Automatic, cyclic acknowledgement — pulsing bit 7 on a timer to "keep the line running" — converts a protective device into a decorative one.
Step-by-Step Lab: Drive the State Machine by Hand
Hands-on- A G120 configured with Standard Telegram 1 on an S7-1200 or S7-1500, with tags for STW1, NSOLL, ZSW1 and NIST.
- A motor on a test bench or uncoupled. No program logic is needed — everything is done from a watch table.
- Estimated time: 30 minutes.
Set up a hexadecimal watch table
Put STW1 and ZSW1 into a watch table with hexadecimal display format, and NSOLL and NIST as decimal.
Try the wrong thing first
With STW1 at 0, write 16#047F directly and observe.
Do it in the right order
Write 16#0000, then 16#047E, check ZSW1, set NSOLL to 8192, then write 16#047F.
Compare the two stop behaviours
While running, write 16#047E and observe the stop. Restart, then write 16#0000 and observe again.
Provoke a fault and acknowledge it properly
Disconnect the network cable briefly, reconnect, then write 16#04FE once and return to 16#047E.
Find switching-on inhibited
Cause a fault while STW1 is at 16#047F, acknowledge without dropping bit 0, and watch ZSW1 bit 6.
You have the bits if you can explain why 047F failed from zero but worked from 047E, why 0000 coasted while 047E ramped, and why the fault cleared on an edge rather than a level. Next step is putting all of it inside one standard function block so no future program can get the sequence wrong.
These bits are one piece of Siemens PLC and VFD networking — the wider picture covers hardwired control, USS, Modbus, PROFIBUS and PROFINET.
Frequently asked questions
What is 16#047E and 16#047F in the control word?
16#047E sets the OFF2, OFF3, pulse enable, ramp enable, ramp continue, setpoint enable and control-by-PLC bits — the drive is enabled but stationary. 16#047F adds bit 0, the run command. Returning to 16#047E produces a controlled ramp-down stop.
Why does the drive not start when I write 16#047F directly?
The PROFIdrive state machine expects to pass through the ready state first. Write 16#047E, confirm the drive reports ready in ZSW1, then write 16#047F. Jumping straight to the run value from zero frequently does nothing.
Which STW1 bit is most often forgotten?
Bit 10, control by PLC. Without it the drive ignores the entire telegram regardless of what else the control word contains, and it produces no fault to explain why.
Should I use my own command bit or ZSW1 for the HMI running lamp?
Always ZSW1 bit 2, operation enabled. A lamp driven from the PLC's command bit stays lit while the drive is tripped, showing the operator a running machine that is not turning.
Why did my drive stop clearing faults properly?
Most likely bit 7 is being held at 1 rather than pulsed. It is edge-triggered, so holding it high clears every fault the instant it appears and hides a repeating condition — such as a motor tripping on overload every few seconds — until real damage occurs.
What does ZSW1 bit 6, switching on inhibited, mean?
The drive will not start until the run command is removed and re-applied. It usually appears when a fault was acknowledged while the run bit was still set. Drop bit 0, then set it again to clear the condition.
Why hold the fault acknowledge bit for 200 ms instead of one PLC scan?
The PLC scan can be shorter than the PROFINET update time of the drive. A one-scan pulse may fall between two telegram updates and never reach the drive. A short fixed pulse of 100 to 200 ms always arrives and still gives a clean rising edge.