Ladder Logic Basics: Contacts, Coils, and How a Rung Works

Key takeaways

  • Ladder logic is read left to right: contacts (inputs) on the left, coils (outputs) on the right.
  • A normally-open (NO) contact passes power when its tag is 1; normally-closed (NC) passes power when its tag is 0.
  • Contacts in series implement AND logic; contacts in parallel implement OR logic.
  • The seal-in circuit is the software equivalent of a relay latch — a parallel NO contact on the output coil keeps it energised after the Start button is released.
  • The PLC scan cycle executes rungs top to bottom; changes during a scan are not reflected until the next scan.
  • TON, TOF, and TP are the three standard IEC 61131-3 timer types.

What is ladder logic?

Ladder logic (formally Ladder Diagram, or LD, in IEC 61131-3) is the most widely used programming language for PLCs in North America and one of the most common worldwide. It represents control logic as a series of horizontal rungs drawn between two vertical power rails — an appearance that deliberately mimics the relay-based control schematics that preceded PLCs in the 1960s.

The language was designed so that engineers and electricians who already understood relay circuits could read and write PLC programs without learning conventional software development. That goal has made it remarkably durable: despite being nearly 60 years old as a concept, ladder logic is still the language most industrial controls technicians encounter first and use most frequently.

Ladder logic is part of the IEC 61131-3 standard, which defines five programming languages for industrial controllers. The others — Structured Text, Function Block Diagram, Sequential Function Chart, and Instruction List — each have strengths in different applications. Ladder logic is best suited to discrete logic: on/off decisions, interlocks, sequences, and timing.

Power rails and rungs

A ladder diagram has two vertical bars running the full height of the program: the left power rail and the right power rail. Horizontal rungs connect the two rails. Each rung contains the logic for one output action.

In a real relay circuit, current physically flows from the left rail through closed contacts to energise the coil on the right. In a PLC, no current actually flows — the CPU evaluates the boolean state of each contact in the rung from left to right and determines whether the rung "conducts" (is true) or not. The current-flow metaphor is a visual convention only.

A typical ladder diagram looks like this in plain text (real programming tools show proper graphical symbols):

|----[ ]----[ ]----( )----||
|  Start   Stop   Motor  ||
|  PB      PB     Run    ||
Simplified text representation of a single ladder rung. Real software displays graphical contact and coil symbols.

Contacts: normally-open and normally-closed

A contact is an input element in a rung. It examines the value of a tag (a bit in memory) and either passes power (true state) or blocks it (false state). Contacts do not change the value of the tag they are examining.

Normally-open (NO) contact — Examine If Closed (XIC)

A normally-open contact passes power when the tag it examines is 1 (true). In the de-energised state, an NO contact is open (blocking). When the tag goes to 1 — meaning the physical device assigned to that tag is active — the contact closes and passes power.

In Allen-Bradley programming, this instruction is called XIC (Examine If Closed). In Siemens, it is called a Normally Open contact. In most tools it appears as two vertical lines: [ ].

Normally-closed (NC) contact — Examine If Open (XIO)

A normally-closed contact passes power when the tag it examines is 0 (false). In the de-energised state, an NC contact is closed (passing). When the tag goes to 1 — meaning the associated device is active — the contact opens and blocks power.

In Allen-Bradley, this is called XIO (Examine If Open). It appears as two vertical lines with a diagonal slash: [/].

NC contacts are used for:

  • Stop pushbuttons (which are physically NC — they open when pressed, which breaks the circuit in a fail-safe manner)
  • Overload relay contacts (physically NC — they open on trip)
  • Inverting logic (if A is active, do NOT do B)
Why e-stop buttons are wired NC: A normally-closed e-stop wired in series means a broken wire looks the same as a pressed button — the circuit opens and the machine stops. If an e-stop were wired as NO, a broken wire would leave the circuit permanently closed, the machine would never stop from that button, and the failure would be silent. Always wire safety devices fail-safe. (See Machine Safety for functional safety requirements.)

Output coils

A coil is the output element of a rung, placed at the right end. When the rung logic is true (power flows from left to right through all contacts), the coil is energised and sets the associated tag to 1. When the rung logic is false, the coil de-energises and the tag goes to 0.

Common coil types:

Type Symbol Behaviour
Output Energise (OTE) ( ) Tag = 1 while rung is true; tag = 0 when rung is false. The standard coil type.
Output Latch (OTL) (L) Sets tag to 1 when rung is true; does not reset when rung goes false. Must be reset by OTU.
Output Unlatch (OTU) (U) Resets tag to 0 when rung is true. Used as the paired reset for OTL.
One-Shot Rising (OSR) (P) Sets tag to 1 for exactly one scan on the rising edge of the rung condition.

Series and parallel contact logic

Contacts arranged in series on the same rung implement AND logic. All contacts in series must be true (passing) for power to reach the coil.

Contacts arranged in parallel (multiple rungs stacked vertically, or branches within a rung) implement OR logic. Power flows if any parallel path is true.

Series (AND):
|----[A]----[B]----( C )----||
  C = 1 only when A AND B are both 1

Parallel (OR):
|----[A]----------( C )----||
|----[B]-----------      --||
  C = 1 when A OR B (or both) is 1
Series contacts = AND logic; parallel contacts = OR logic.

Complex boolean expressions can be built by combining series and parallel elements. Most PLC programming environments allow nesting of branches to any depth.

The seal-in (latch) circuit

The most fundamental ladder logic pattern is the seal-in circuit — the software equivalent of a relay self-holding circuit. It solves a practical problem: a momentary Start pushbutton only makes contact for as long as you hold it. Without some form of memory, the output would de-energise as soon as you release the button.

The seal-in circuit adds a parallel NO contact from the output coil itself alongside the Start button. When the Start button is pressed, the output coil energises. The parallel contact from the output coil then also closes, providing a second path that keeps the coil energised even after the Start button is released.

|----[Start]----[Stop/NC]----( Motor )----||
|                                          |
|----[Motor]----------------------------|  |
     (seal-in parallel contact)
The seal-in circuit: the Motor contact in parallel keeps the coil energised after the Start button is released. The Stop (NC) contact breaks the circuit when pressed.

To stop the motor, the Stop button (physically NC, appears as an NC contact in the rung) is pressed, opening the circuit. Both the Start path and the seal-in path are now broken, so the coil de-energises and the motor stops. When the Stop button is released, the seal-in contact remains open because the coil tag is now 0 — so the motor does not restart automatically.

The scan cycle and execution order

The PLC executes ladder logic in a continuous cycle called the scan:

  1. Read inputs: All physical input terminals are read and their states copied to the input image table (a block of memory representing current input states).
  2. Execute program: The CPU evaluates every rung from top (Rung 0) to bottom, reading contact states from the image table and writing coil outputs to the output image table.
  3. Write outputs: The output image table is copied to the physical output terminals, energising or de-energising the connected devices.
  4. Housekeeping: Communication updates, diagnostics, system tasks.

A key consequence: a physical input change that occurs during program execution is not seen until the next scan. For most discrete logic, this is irrelevant because the scan cycle (1–20 ms typically) is far faster than any mechanical event. For high-speed inputs (encoder pulses, position latching), dedicated high-speed counter inputs or interrupt tasks are used.

Another consequence: if Rung 5 writes to Tag X, and Rung 1 reads Tag X, Rung 1 will not see the new value until the next scan (because the inputs are fixed at the start of the scan). But if Rung 1 writes to Tag X and Rung 10 reads Tag X, Rung 10 sees the updated value within the same scan, because program execution is top-to-bottom.

Timers (TON, TOF, TP)

Timers are IEC 61131-3 function blocks that measure elapsed time. They are among the most frequently used instructions in ladder logic.

TON — On-Delay Timer

The TON starts timing when its enable input (IN) goes from 0 to 1. After the preset time (PT) elapses, the output (Q) goes to 1. Q stays true as long as IN remains true. When IN goes to 0, the timer resets immediately (elapsed time ET goes to 0 and Q goes to 0).

Uses: Start delays (don't run a pump until a valve has been open for 3 seconds), filter debounce (only trigger if the input is continuously true for 500 ms), time-limited sequences.

TOF — Off-Delay Timer

The TOF output (Q) goes to 1 immediately when IN goes to 1. When IN goes to 0, Q stays 1 for the preset time PT before going to 0. The timer resets (ET = 0, Q = 0 when IN returns to 1).

Uses: Post-run cooling fans (keep the fan running for 60 seconds after the motor stops), conveyor coast-to-stop, alarm acknowledgement windows.

TP — Pulse Timer

The TP generates a fixed-duration output pulse. On a rising edge of IN, Q goes to 1 for exactly PT, regardless of how long IN stays true. Another rising edge of IN cannot re-trigger the timer while it is already timing.

Uses: Fixed-duration solenoid pulses, one-shot alarm notifications, timing windows.

Standard TON ladder rung:

|----[Start_Delay_Enable]----+TON           +----( Delayed_Start )----||
                             | IN     Q     |
                             | PT  T#5s     |
                             | ET  ______   |
                             +TON-----------+
TON timer rung. When Start_Delay_Enable is true, the timer counts up. After 5 seconds, Q (Delayed_Start) becomes true.

Counters (CTU, CTD, CTUD)

Counter function blocks count events (rising edges on the count input).

  • CTU (Count Up): CV increments on each rising edge of CU. Q becomes true when CV ≥ PV. R input resets CV to 0.
  • CTD (Count Down): CV decrements on each rising edge of CD. Q becomes true when CV ≤ 0. LD input loads PV into CV.
  • CTUD (Count Up/Down): Combines both. QU activates when CV ≥ PV; QD activates when CV ≤ 0.

Practical example: A CTU counting part pulses from a proximity sensor. When the counter CV equals 12 (PV = 12), the Q output triggers a "full bin" output and the R input resets the counter to 0 when the bin is emptied.

Data types and tags

Every variable in a PLC program is a tag (Allen-Bradley terminology) or variable (IEC 61131-3 terminology). Tags have a data type, a name, and a value. Common data types:

  • BOOL: Single bit — true (1) or false (0). Used for discrete I/O, status flags, and control bits. This is the type of all contact and coil tags.
  • INT: 16-bit signed integer (–32768 to +32767). Used for counter values, raw ADC readings.
  • DINT: 32-bit signed integer. Used for larger counts, encoder positions.
  • REAL: 32-bit floating-point number. Used for engineering-unit process values, PID parameters.
  • TIME: Time duration value (e.g., T#5s = 5 seconds). This is the data type for timer preset (PT) and elapsed time (ET) values.

Tag naming conventions matter. A tag named Motor_01_Run is self-documenting; a tag named B3:0/3 is not. Modern PLC platforms use symbolic (named) addressing — use it. Organise tags using User-Defined Data Types (UDTs) to group variables for each physical device.

Platform differences

While IEC 61131-3 provides a standard, each vendor implements it slightly differently. Things to be aware of when moving between platforms:

  • Allen-Bradley (Studio 5000): Uses XIC/XIO for NO/NC contacts, OTE/OTL/OTU for coils. Tags are always named (no address-based I/O). Timer preset is a DINT in milliseconds, not a TIME type — e.g., preset 5000 = 5 seconds.
  • Siemens (TIA Portal / S7): Uses standard IEC contact/coil symbols. Timers are IEC-compliant function blocks with TIME inputs. Legacy S7-300/400 programs use different timer instructions (S_ODT etc.) — if you are editing legacy code, identify which generation you are working on first.
  • Mitsubishi (GX Works3): Uses similar symbols but has extensive use of internal relays (M devices) and data registers (D devices). Ladder logic programs are organised in Program Blocks.
  • CODESYS: Strictly IEC 61131-3 compliant. Widely portable across CODESYS-based platforms (Beckhoff TwinCAT, Wago, etc.).

Next steps

Once you are comfortable with the basics, the natural next steps are:

  • Explore the full range of ladder logic symbols — comparison, math, move, and program control instructions.
  • Learn when Structured Text is better than ladder logic for your application — especially for calculations and data manipulation.
  • Practice the PLC programming concepts above on a free simulation tool (CODESYS offers a free runtime; Factory I/O provides a simulated machine environment).

How we researched this

Definitions and programming language specifications are based on IEC 61131-3:2013 (third edition). Instruction naming conventions verified against Allen-Bradley Logix 5000 Controllers General Instruction Set Reference Manual (Publication 1756-RM003) and Siemens TIA Portal STEP 7 Programming Guideline. Timer and counter behaviour verified against both sources. Platform differences verified against current vendor documentation.