A Category 1 emergency stop delay is application-specific, not a single number stamped in the standard. ISO 13850 only requires that the machine complete a controlled deceleration before power is removed, leaving the actual delay setting to the risk assessment and the drive's ramp capability [S2][S5].
In a typical SS1-t (time-controlled Safe Stop 1) implementation, the timer that holds the STO off after the stop command is set somewhere between roughly 0.5 s for a low-inertia servo axis and several seconds for a large flywheel or centrifuge, provided the drive's deceleration ramp can reach zero inside that window [S1][S2].
What ISO 13850 and IEC 60204-1 actually say about the delay
ISO 13850 permits only Category 0 and Category 1 for emergency stop functions, and it does not pin a numeric delay value: Category 1 is defined as "a controlled stop with power available to the machine actuators to achieve the stop, then removal of power when the stop is achieved" [S2][S5]. IEC 60204-1 carries the same three-stop-category model (0, 1, 2) and similarly leaves the delay to the application [S2].
IEC 61800-5-2 operationalises this for drives with three SS1 sub-flavours: SS1-d triggers STO when motor speed drops below a limit, SS1-r monitors the deceleration ramp and trips STO if the ramp breaks, and SS1-t triggers STO after an application-specific time delay, which is the variant that forces the engineer to choose a number [S2].
Where the delay number comes from in a real design
For an ABB ACS355-based reference design, the category 1 sequence is: emergency stop button opens, the safety timer relay starts a controlled deceleration ramp on the drive, and after a preset time delay the relay's timed contacts open and activate the drive's integrated STO input, cutting the output to the motor [S1]. The published example does not lock in a single delay value, because the timer is a parameter tied to the machine's inertia and the drive's deceleration ramp [S1].
Siemens' STEP 7 Safety V21 ESTOP1 block models the same logic with a dedicated input, TIME_DEL, which holds the Q_DELAY enable output for the configured time before the function drops the actuator enable, again with the value set application-by-application [S3]. The instruction's own documentation makes clear that Q_DELAY is reset to 0 after the time delay set at TIME_DEL, which is the specifier's job to populate [S3].
Choosing the value: 4 engineering criteria

Four practical criteria drive the number, and they should be checked together rather than one at a time. (1) Mechanical stopping time: with the worst-case load inertia and the drive's programmed decel ramp, measure or calculate how long the axis actually takes to reach zero speed; the STO trigger must be later than that, or you cut power mid-ramp and turn the controlled stop into a coast-down. (2) Risk-assessment window: the hazard analysis under ISO 12100 sets a maximum permissible stopping time, and the chosen delay must keep the machine inside that window [S5]. (3) Safety relay / drive STO input response time: the timer's tolerance and the STO circuit's reaction time add directly to the delay, and ABB's example chains an INCA1 E-stop button, an RT7 safety timer relay, and the ACS355 STO input, each with its own datasheet value [S1]. (4) SIL/PL headroom: the example design is sized for SIL 3 (IEC 62061) and PL e (ISO 13849-1), and any timer change must be re-validated against the safety integrity calculation, not just the wiring diagram [S1].
A defensible starting point for a single-axis VFD without a mechanical brake is to set the time delay equal to the drive's decel ramp time plus 10 to 20 percent margin, then verify with a measured stop-time test on the loaded machine. The decision on which type of stop fits the hazard is upstream: Category 0 suits machines with no inertia and no coast-down hazard, while Category 1 is the right answer where the mechanical organ has inertia or where other safety systems depend on a synchronised stop [S2].
Common pitfalls when sizing the delay
Setting the delay too short is the classic mistake: STO fires while the motor is still spinning, and the drive logs an SS1-t fault or the load coasts unpredictably, which can be worse than a Category 0 stop. Setting it too long defeats the purpose of the safety function, because the hazard window defined in the risk assessment is no longer met, and the system falls out of its declared SIL/PL [S1][S5].
Another recurring error is treating the time delay as a substitute for ramp monitoring: SS1-t only checks the clock, not the actual motor speed, so a stuck decelerator or an overloaded drive goes undetected until the timer expires. Where this matters, the specifier should pick SS1-d or SS1-r instead, both of which trigger STO based on measured speed or ramp profile rather than a pure time [S2].
Testing and verification cadence

Functional testing of the E-stop circuit is not a one-time event, and the practical cadence for production equipment is once per month to once per year, depending on the equipment type and environment [S8]. Each test should record the measured stop time and confirm it is still inside the time-delay window plus the safety relay's tolerance; drift in the drive's deceleration ramp or in the brake's response is the usual early warning that the configured delay is no longer adequate [S8].
After any change to the mechanical load, the drive's deceleration parameters, or the safety relay's part number, the category 1 delay value has to be re-calculated and the SIL/PL re-checked, because the safety function as a whole is only as good as its slowest verified parameter [S1][S5]. For related hardware context, emergency stop pushbutton selection and the broader emergency stop function pages cover the upstream button and the system-level requirements.
Where this fits alongside other safety hardware
Category 1 stop logic is only one piece of an E-stop system; it sits between the emergency stop button wiring and the drive's STO input, and the timer relay is the component that actually defines the delay. For a controlled-pour casting line with significant flywheel inertia, a related reference on tilting gravity die casting machine controlled-pour mechanism and 2026 spec snapshot shows how the same SS1-t logic is sized for a heavy rotating load, where the time delay can run into multiple seconds before STO is safe to assert. Hydraulic power units present a different inertia profile and call for a separate stop-time calculation, covered in gear, vane, or piston pump choosing for a hydraulic power unit. [S1]
Trackable signals for the next planning cycle: monitor whether IEC 61800-5-3 (functional safety extensions for encoder-less drives) cites any new minimum delay values, and watch for vendor-specific SS1-t timer parameter guidance in the next ACS355 and SINAMICS firmware releases, since these data sheets are where concrete default values appear in practice.
Detailed specification references: emergency light.