REQUEST FOR QUOTE → Request a quote
SpecForge Editorial Team

Category 1 Emergency Stop Delay: How to Set It Right

Table of Contents
  1. What ISO 13850 and IEC 60204-1 actually say about the delay
  2. Where the delay number comes from in a real design
  3. Choosing the value: 4 engineering criteria
  4. Common pitfalls when sizing the delay
  5. Testing and verification cadence
  6. Where this fits alongside other safety hardware
Category 1 Emergency Stop Delay: How to Set It Right

A Category 1 emergency stop delay is application-specific, not a single number stamped in the standard. ISO 13850 only requires that the machine complete a controlled deceleration before power is removed, leaving the actual delay setting to the risk assessment and the drive's ramp capability [S2][S5].

In a typical SS1-t (time-controlled Safe Stop 1) implementation, the timer that holds the STO off after the stop command is set somewhere between roughly 0.5 s for a low-inertia servo axis and several seconds for a large flywheel or centrifuge, provided the drive's deceleration ramp can reach zero inside that window [S1][S2].

What ISO 13850 and IEC 60204-1 actually say about the delay

ISO 13850 permits only Category 0 and Category 1 for emergency stop functions, and it does not pin a numeric delay value: Category 1 is defined as "a controlled stop with power available to the machine actuators to achieve the stop, then removal of power when the stop is achieved" [S2][S5]. IEC 60204-1 carries the same three-stop-category model (0, 1, 2) and similarly leaves the delay to the application [S2].

IEC 61800-5-2 operationalises this for drives with three SS1 sub-flavours: SS1-d triggers STO when motor speed drops below a limit, SS1-r monitors the deceleration ramp and trips STO if the ramp breaks, and SS1-t triggers STO after an application-specific time delay, which is the variant that forces the engineer to choose a number [S2].

Where the delay number comes from in a real design

For an ABB ACS355-based reference design, the category 1 sequence is: emergency stop button opens, the safety timer relay starts a controlled deceleration ramp on the drive, and after a preset time delay the relay's timed contacts open and activate the drive's integrated STO input, cutting the output to the motor [S1]. The published example does not lock in a single delay value, because the timer is a parameter tied to the machine's inertia and the drive's deceleration ramp [S1].

Siemens' STEP 7 Safety V21 ESTOP1 block models the same logic with a dedicated input, TIME_DEL, which holds the Q_DELAY enable output for the configured time before the function drops the actuator enable, again with the value set application-by-application [S3]. The instruction's own documentation makes clear that Q_DELAY is reset to 0 after the time delay set at TIME_DEL, which is the specifier's job to populate [S3].

Choosing the value: 4 engineering criteria

how long should a category 1 emergency stop delay be set? - Choosing the value: 4 engineering criteria
how long should a category 1 emergency stop delay be set? - Choosing the value: 4 engineering criteria

Four practical criteria drive the number, and they should be checked together rather than one at a time. (1) Mechanical stopping time: with the worst-case load inertia and the drive's programmed decel ramp, measure or calculate how long the axis actually takes to reach zero speed; the STO trigger must be later than that, or you cut power mid-ramp and turn the controlled stop into a coast-down. (2) Risk-assessment window: the hazard analysis under ISO 12100 sets a maximum permissible stopping time, and the chosen delay must keep the machine inside that window [S5]. (3) Safety relay / drive STO input response time: the timer's tolerance and the STO circuit's reaction time add directly to the delay, and ABB's example chains an INCA1 E-stop button, an RT7 safety timer relay, and the ACS355 STO input, each with its own datasheet value [S1]. (4) SIL/PL headroom: the example design is sized for SIL 3 (IEC 62061) and PL e (ISO 13849-1), and any timer change must be re-validated against the safety integrity calculation, not just the wiring diagram [S1].

A defensible starting point for a single-axis VFD without a mechanical brake is to set the time delay equal to the drive's decel ramp time plus 10 to 20 percent margin, then verify with a measured stop-time test on the loaded machine. The decision on which type of stop fits the hazard is upstream: Category 0 suits machines with no inertia and no coast-down hazard, while Category 1 is the right answer where the mechanical organ has inertia or where other safety systems depend on a synchronised stop [S2].

Common pitfalls when sizing the delay

Setting the delay too short is the classic mistake: STO fires while the motor is still spinning, and the drive logs an SS1-t fault or the load coasts unpredictably, which can be worse than a Category 0 stop. Setting it too long defeats the purpose of the safety function, because the hazard window defined in the risk assessment is no longer met, and the system falls out of its declared SIL/PL [S1][S5].

Another recurring error is treating the time delay as a substitute for ramp monitoring: SS1-t only checks the clock, not the actual motor speed, so a stuck decelerator or an overloaded drive goes undetected until the timer expires. Where this matters, the specifier should pick SS1-d or SS1-r instead, both of which trigger STO based on measured speed or ramp profile rather than a pure time [S2].

Testing and verification cadence

how long should a category 1 emergency stop delay be set? - Testing and verification cadence
how long should a category 1 emergency stop delay be set? - Testing and verification cadence

Functional testing of the E-stop circuit is not a one-time event, and the practical cadence for production equipment is once per month to once per year, depending on the equipment type and environment [S8]. Each test should record the measured stop time and confirm it is still inside the time-delay window plus the safety relay's tolerance; drift in the drive's deceleration ramp or in the brake's response is the usual early warning that the configured delay is no longer adequate [S8].

After any change to the mechanical load, the drive's deceleration parameters, or the safety relay's part number, the category 1 delay value has to be re-calculated and the SIL/PL re-checked, because the safety function as a whole is only as good as its slowest verified parameter [S1][S5]. For related hardware context, emergency stop pushbutton selection and the broader emergency stop function pages cover the upstream button and the system-level requirements.

Where this fits alongside other safety hardware

Category 1 stop logic is only one piece of an E-stop system; it sits between the emergency stop button wiring and the drive's STO input, and the timer relay is the component that actually defines the delay. For a controlled-pour casting line with significant flywheel inertia, a related reference on tilting gravity die casting machine controlled-pour mechanism and 2026 spec snapshot shows how the same SS1-t logic is sized for a heavy rotating load, where the time delay can run into multiple seconds before STO is safe to assert. Hydraulic power units present a different inertia profile and call for a separate stop-time calculation, covered in gear, vane, or piston pump choosing for a hydraulic power unit. [S1]

Trackable signals for the next planning cycle: monitor whether IEC 61800-5-3 (functional safety extensions for encoder-less drives) cites any new minimum delay values, and watch for vendor-specific SS1-t timer parameter guidance in the next ACS355 and SINAMICS firmware releases, since these data sheets are where concrete default values appear in practice.

Detailed specification references: emergency light.

Frequently asked questions

What is the typical Category 1 emergency stop delay range for an SS1-t implementation?

In a typical SS1-t (time-controlled Safe Stop 1) implementation, the timer that holds the STO off after the stop command is set between roughly 0.5 s for a low-inertia servo axis and several seconds for a large flywheel or centrifuge, provided the drive's deceleration ramp can reach zero inside that window.

Does ISO 13850 specify a numeric value for the Category 1 stop delay?

No. ISO 13850 permits only Category 0 and Category 1 for emergency stop functions and does not pin a numeric delay value. Category 1 is defined as a controlled stop with power available to the actuators, followed by removal of power when the stop is achieved, leaving the actual delay to the risk assessment and the drive's ramp capability.

What is a defensible starting value for the Category 1 delay on a single-axis VFD without a mechanical brake?

A defensible starting point for a single-axis VFD without a mechanical brake is to set the time delay equal to the drive's decel ramp time plus 10 to 20 percent margin, then verify with a measured stop-time test on the loaded machine.

When should SS1-t be replaced by SS1-d or SS1-r instead of a pure time delay?

SS1-t only checks the clock, not the actual motor speed, so a stuck decelerator or an overloaded drive goes undetected until the timer expires. Where that risk matters, the specifier should pick SS1-d (triggers STO when motor speed drops below a limit) or SS1-r (monitors the deceleration ramp and trips STO if the ramp breaks) instead.

9 sources
  1. How to implement an emergency stop, category 1, with an ...
  2. STOP FUNCTIONS
  3. STEP 7 Safety V21 instructions - ESTOP1
  4. Stop Category 1 & 0 (Oct 29, 2024)
  5. ISO 13850 Emergency Stop Function Ensuring Safety in ... (Sep 17, 2024)
  6. Emergency Stop Usage | Mike Holt's Forum (Nov 1, 2021)
  7. Emergency stops in industrial safety (Jan 2, 2024)
  8. NFPA 79 & OSHA Emergency Stop Requirements With ...
  9. Emergency Stop Requirements — What's So Confusing ... (Mar 6, 2009)

Need to source matching manufacturers or get a quote?

SpecForge connects industrial buyers with verified manufacturers. Submit your requirement and we will route it to matched suppliers.

Submit RFQ now →
Ask SpecForge AI