An emergency stop, universally shortened to E-stop, is the big red mushroom button that lets anyone bring equipment to an immediate safe halt in a hazard. Its power comes not from the button itself but from how it is wired: a hardwired, fail-safe circuit that does not depend on software to work. This guide explains what an E-stop is, how its normally-closed maintained circuit works, and how it differs from a full emergency shutdown system.
Emergency Stop (E-Stop) in one line: An emergency stop is a manually operated safety device, typically a red mushroom-head pushbutton on a yellow background, that a person presses to immediately stop equipment in an emergency. It works through a hardwired, normally-closed circuit that de-energizes the machine when pressed, latches in the stopped state, and requires a deliberate manual reset before operation can resume, so it fails to the safe state and cannot be silently overridden.
The defining feature of an E-stop is that its contacts are normally closed, meaning the circuit is complete and current flows while the button is not pressed. Pressing the button opens the contacts and breaks the circuit, which drops out the control power that keeps the equipment running. Wiring it this way makes it fail-safe: if a wire breaks, a contact corrodes, or a connection comes loose, the circuit opens on its own and the equipment stops, exactly as if someone had pressed the button. A fault can only ever make the system safer, never bypass the stop.
This is why an E-stop is deliberately not run through a PLC as a normal input. The stopping function is hardwired directly into the control power path so it works even if the controller or its software fails. The button interrupts the circuit that energizes contactors and safety relays, cutting power to motors and actuators through physical means rather than trusting a program to notice the button and react.
The button also uses maintained contacts, so it stays latched in the pressed, open state after it is hit rather than springing back. That keeps the equipment locked out until someone physically resets the button, usually by twisting or pulling the mushroom head to release it. Releasing the button alone does not restart anything - it only re-closes the E-stop contacts and allows a separate, deliberate restart to be attempted.
An E-stop is intentionally hard to defeat and hard to accidentally clear. Its large mushroom head is easy to hit quickly with a palm or elbow from any angle, and once struck it stays in. The maintained latching behavior means the machine cannot restart just because a hazard passed - a person must go to the button, understand why it was pressed, and consciously reset it.
Reset is deliberately a two-stage affair. First the button itself is released by turning or pulling it, which re-closes the safety circuit. Second, a separate restart action is required to bring the equipment back to life - the machine does not lurch back into motion the instant the button pops out. This separation prevents an unexpected restart while someone is still in the danger zone, which is one of the core hazards the E-stop exists to prevent.
In a control panel the E-stop circuit typically drives a dedicated safety relay or safety module rather than an ordinary relay, and multiple E-stop buttons around a machine or site are wired in series so that pressing any one of them breaks the whole chain. That series wiring means every button has authority to stop everything, and a fault anywhere in the chain trips the system safe.
It helps to separate the E-stop device from the emergency shutdown system as a whole. An E-stop is a specific piece of panel hardware - a button and its hardwired circuit - that a person presses locally to halt equipment. An emergency shutdown system is the broader engineered function that brings a whole process to a safe state, often automatically in response to sensed conditions like high pressure or fire, and may trip many valves and drivers at once. An E-stop button can be one initiator of that larger function, but the two are not the same thing.
Because the E-stop must remain a reliable, self-contained hardwired safety device, it deliberately does not depend on a network or a controller to do its job. What monitoring adds is awareness, not control of the stop itself. A spare contact on the E-stop circuit is commonly wired back to the field controller as a status input, so the control system knows the E-stop has been activated even though it played no part in the stopping.
In a cloud SCADA platform like Merobix, that status becomes a remotely visible alarm - an operator far from the site can see that an emergency stop has been triggered and dispatch someone or investigate, without the platform ever being in the safety path. The hardwired circuit does the safety-critical work locally and instantly, and the cloud layer simply reports that it happened, which is the right division of responsibility for a safety device.
So it fails safe. With normally-closed contacts the circuit is complete during normal operation, and pressing the button opens it to stop the equipment. If a wire breaks or a contact fails, the circuit also opens on its own and the equipment stops, so any fault makes the system safer and the stop can never be silently bypassed.
An E-stop is a specific button and its hardwired circuit that a person presses locally to halt equipment. An emergency shutdown system is the broader function that brings a whole process to a safe state, often automatically in response to sensed hazards, and can trip many devices at once. An E-stop button can trigger such a system but is not the same as it.
The maintained, latching action keeps the equipment stopped until a person releases the button and performs a separate restart, so the machine cannot spring back to life on its own. This two-stage reset ensures someone consciously checks that the hazard is clear and no one is in the danger zone before operation resumes.
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.