Migrating TIA WinCC Pro to WinCC V8.1 for IEC 60870-5-104

David Krause17 min read
SCADA ConfigurationSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview: The IEC 60870-5-104 Gap in TIA Portal

Energy utilities and grid operators standardise on the IEC 60870-5-104 protocol (IEC 104) for substation telecontrol over TCP/IP. The protocol rides on TCP port 2404 and uses Application Service Data Units (ASDUs) for telemetry, telecontrol, and parameterisation between control centres and RTUs, IEDs, or bay controllers.

Within the SIMATIC TIA Portal, WinCC Professional (ES and RT) is the integrated HMI/SCADA option for S7-1200 and S7-1500 controllers. It supports S7 communication, OPC UA, Modbus TCP (via the SIMATIC Modbus/TCP PN CPU package), PROFINET, and a number of third-party drivers installed by the S7-1500 Software Controller / WinCC RT — but it does not ship with a native IEC 60870-5-104 master channel. Engineers in dispatching and substation automation have historically filled this gap with external protocol gateways (e.g., SIMATIC WinCC V8 gateway stacks, KISTERS, or HMS Anybus) that translate IEC 104 to OPC UA or S7 tags. Each gateway is a failure surface, a configuration burden, and an additional line item.

SIMATIC WinCC V8.1 (the "Classic" line) closes that gap. WinCC V8.1 ships with a native IEC 60870-5-104 channel master driver, supports up to 18 redundant server pairs (36 servers), and is on a Siemens long-term support contract that runs at minimum into the mid-2030s. For small engineering teams that already standardise on S7-1200/1500 hardware, migrating the SCADA layer to WinCC V8.1 is the most direct path to native IEC 104 polling without giving up the TIA Portal PLC workflow.

Field scope: This document covers the engineering decision and migration workflow for a working PLC/SCADA team. It does not replace the official SIMATIC WinCC V8.1 System Manual and WinCC V8.1 Communication Manual; always cross-check tag limits, licensing tiers, and channel counts against the installed SIMATIC WinCC V8.1 release notes for your build (8.1.0, 8.1.1, or later).

Why WinCC V8.1 (Classic) for Energy Dispatching

WinCC V8.1 is the last release of the WinCC Classic line, modernised with current SQL Server, current Windows Server, and continued security updates. Siemens positions it as the bridge product until WinCC Unified reaches feature parity for the energy / process industries. Practically, this gives you:

  • Native IEC 60870-5-104 master — no external gateway hardware or VM.
  • Native IEC 60870-5-101 serial — supports legacy substation RTUs.
  • OPC UA server and client — for hand-off to a control-centre SCADA/EMS.
  • S7 channel to S7-1200/1500 — direct symbolic tag access without exporting tag lists.
  • Redundancy — up to 18 redundant server pairs.
  • Long-term support — contractually supported well past the WinCC Professional V20 line.

For a small PLC/SCADA team that already owns TIA Portal licences, the only new line items are WinCC V8.1 RT (or RT Server) licences and the WinCC V8.1 Option IEC 60870-5-104 channel licence. No protocol gateway hardware, no serial port server, no OPC UA bridge.

Architecture Comparison: WinCC Professional vs WinCC V8.1

Capability WinCC Professional (TIA Portal) WinCC V8.1 (Classic)
IEC 60870-5-104 master Not native (requires external gateway or custom DLL) Native channel driver, included with V8.1 option
IEC 60870-5-101 serial Not supported Native (via COM port or serial terminal server)
OPC UA Server + client (as of V16+) Server + client (DA, AC, HA profiles)
S7-1200/1500 symbolic tag access Yes, direct from TIA Portal Yes, via S7 channel; tag import via CSV or AS-OS engineering
Redundancy Single RT, optional redundant RT (1+1) Up to 18 redundant server pairs (18 × 2 = 36 servers)
Picture system WinCC Unified / WinCC Professional screen editor PDL (Picture Designer Library) and Graphics Designer
Tag limit (power tags) 8 192 (RT 4 096, ES 8 192) 256 000 to 1 500 000+ depending on licence tier
Archive tags / alarms 3 200 archive tags typical limit Up to 150 000 archive tags / 150 000 alarms
SQL backend SQL Server Express (WinCC Professional RT) SQL Server 2022 Standard / Enterprise (required for V8.1)
OS Windows 10/11 (RT), Windows Server 2019+ (ES) Windows Server 2019 / 2022 (64-bit) only
Engineering tool TIA Portal (single project) WinCC Explorer (standalone) + TIA Portal for PLC
Long-term support window Tied to TIA Portal major version lifecycle 10+ year LTS contract
Typical project size sweet spot Up to ~3 000 tags, single station 3 000 to 1 000 000+ tags, multi-server
Tag limits depend on licence. WinCC V8.1 ships in 256, 1 024, 8 192, 65 536, 256 000, and 1 500 000 power-tag tiers. Always verify the exact tier for the order number on your license key USB (e.g., 6AV6371-1... series for RT, 6AV6371-2... for server). Tier is locked by the license; up-sizing requires a license upgrade, not a re-install.

System Requirements and Licensing for WinCC V8.1

WinCC V8.1 is a 64-bit Windows Server application. The current build line (8.1.0 / 8.1.1) is qualified for:

  • OS: Windows Server 2019 Standard/Datacenter, Windows Server 2022 Standard/Datacenter (64-bit). Workstation OS (Windows 10/11) is supported only for engineering on WinCC V8.1 ES.
  • SQL Server: Microsoft SQL Server 2022 Standard or Enterprise (English/international). SQL Server 2019 is not supported on V8.1.
  • CPU: Intel Xeon or AMD EPYC, 4+ physical cores for a 1 024-tag RT, 8+ for redundancy.
  • RAM: 16 GB minimum, 32 GB recommended for archive servers.
  • Disk: SSD, separate OS / project / archive spindles; archive partition sized to ≥ 30 days of tag changes at the project's log rate.

Licence categories (Siemens 6AV6 order numbers):

  • 6AV6371-1... — WinCC V8.1 RT (single station, up to licensed tag count).
  • 6AV6371-2... — WinCC V8.1 Server (multi-client). Required for redundant server pairs.
  • 6AV6371-3... — WinCC V8.1 Client.
  • 6AV6371-4... — WinCC V8.1 WebNavigator / WinCC WebUX.
  • 6AV6371-6... — Options: IEC 60870-5-104 Channel, IEC 60870-5-101 Channel, Redundancy, Audit, Process Historian, Performance Insight.

For an IEC 104 dispatching project you typically order: 1× WinCC V8.1 Server (or 2× for redundancy), 1× IEC 60870-5-104 Channel option per server, N× WinCC V8.1 Client, and optionally WinCC WebUX for browser-based operator access.

SQL Server Migration: From WinCC V8.0 to V8.1

WinCC V8.0 ships with Microsoft SQL Server 2019. WinCC V8.1 requires Microsoft SQL Server 2022. The two SQL Server major versions cannot coexist on the same machine under a single WinCC instance. When upgrading a host from V8.0 to V8.1 you must:

  1. Export the WinCC V8.0 project with WinCC Project Duplicator and back up the project folder.
  2. Stop all WinCC services (CCMsgMgr, CCDmServer, CCArchiveMgr, CCAlgRt, CCLicense).
  3. Uninstall WinCC V8.0 through Control Panel → Programs and Features.
  4. Uninstall Microsoft SQL Server 2019 (any instance named WINCC) and the SQL Server 2019 Native Client.
  5. Reboot. Confirm no residual HKLM\SOFTWARE\Microsoft\Microsoft SQL Server keys remain.
  6. Install Microsoft SQL Server 2022 Standard (English) with the same instance name WINCC and the same collation SQL_Latin1_General_CP1_CI_AS.
  7. Install WinCC V8.1, point to the existing WINCC SQL instance, and restore the project with WinCC Project Duplicator or by opening the project file directly.
Data loss risk. Skipping step 4 (the SQL Server 2019 uninstall) is the single most common reason a V8.0 → V8.1 upgrade fails mid-install with error 0x80070643 -2147023293 ("Fatal error during installation"). The V8.1 setup binds to SQL 2022 components; a 2019 instance already on the box will block the install. Back up the project archive database (<Project>_L<n>) before uninstalling.

Parallel Installation Restrictions

The TIA Portal installation guide states explicitly that parallel installation of WinCC Professional (ES and RT) with WinCC V7.x or WinCC V8.x on the same machine is not permitted. This is a hard rule, not a recommendation, and it comes from the shared SQL Server instance model and overlapping services (CCAlgRt, CCDmServer, etc.). Practical implications for a migration:

  • Do not expect to keep TIA WinCC Professional RT on the same host as WinCC V8.1 RT. You must use a separate engineering host for the TIA Portal ES if you want to keep the TIA Workflow alive for PLC work.
  • A different WinCC Professional version (e.g., TIA V17 Pro on a separate host talking to a V8.1 server) is supported across the network — the two instances simply do not share the same host OS image.
  • The exception is WinCC V7.x and WinCC V8.x themselves, which can run side-by-side on the same Windows Server for staged migrations.

See the TIA Portal V21 Parallel Installation documentation for the full matrix of permitted co-installations.

Migration Workflow: TIA Portal Project to WinCC V8.1

The migration is broken into five phases. Plan a 2–4 week engineering window for a project with 1 000–5 000 tags and 30–100 HMI screens.

Phase 1 — Discovery and Tag Audit

  1. Export the TIA Portal tag table: PLC Tags → Export to Excel. Capture DB name, byte offset, bit offset, data type, and HMI tag name.
  2. Export the WinCC Professional HMI tag list: HMI Tags → Export. This becomes the wincc_tag_import.csv for the V8.1 project.
  3. Inventory HMI screens, scripts (VB / C), alarms, and archives. Note which screens use WinCC Unified widgets — these have no PDL equivalent.
  4. Inventory any custom C actions, ODK, or OPC UA servers that touch WinCC Pro runtime.

Phase 2 — Build the WinCC V8.1 Project Skeleton

  1. On a dedicated Windows Server 2022 host, install SQL Server 2022 Standard and WinCC V8.1 RT.
  2. Open WinCC Explorer and create a new project: Project name = substation or dispatching site name, Project type = Single-User or Multi-User Project.
  3. Set the computer name and startup list. Add the S7 channel to the S7-1200/1500 PLC(s) and the IEC 60870-5-104 channel to the substation RTUs.

Phase 3 — Import Tags and Configure Channels

Tag import in WinCC V8.1 uses Tag Management → Add new driver → AS-OS Engineering or CSV import. Recommended path:

  1. Open AS-OS Engineering in WinCC V8.1. Set the TIA Portal project path or a STEP 7 / TIA Portal export file.
  2. Map the PLC tag DB symbols to WinCC V8.1 external tags. Use the S7 channel's symbolic access where the PLC project is available.
  3. For IEC 104: open Tag Management → IEC 60870-5-104 Channel, add a connection per substation. Configure Common address (CASDU), IP address, TCP port 2404, and the ASDU types in scope (e.g., M_SP_NA_1 = single-point information, M_ME_NC_1 = measured value short floating-point, C_SC_NA_1 = single command).

Phase 4 — Picture Migration: PDL vs TIA Screens

WinCC V8.1 uses the PDL (Picture Designer Library) format. TIA WinCC Professional uses its own screen format. There is no direct binary conversion. The engineering path is one of:

  • PDL extraction from compiled TIA RT project: The compiled WinCC Professional RT directory contains a GRACS folder. WinCC V8.1 can open compiled screen files from that path; this is a partial recovery, not a clean migration, and works best for static, script-free screens. It is useful as a starting point for layout reference.
  • Screen rebuild in WinCC V8.1 Graphics Designer: The recommended path. Re-author screens with PDL objects. Most static widgets (text, I/O field, bar, slider, status displays) have direct equivalents; vector graphics, custom faceplates, and WinCC Unified widgets must be rebuilt.
  • WinCC V8.1 Faceplate library: Use the included Siemens HMI Template Suite faceplates for motor starters, valves, and circuit breakers to recover engineering time on standard ISA-101 graphics.

Phase 5 — Alarm, Archive, and User Administration

  1. Recreate the alarm classes (Errors, Warnings, Information, Process) and the message configuration. Import the alarm text from the TIA tag export.
  2. Configure the Tag Logging archive: define the archive tags, the acquisition cycle (1 s, 5 s, 1 min), the storage location, and the swap-out policy. Allocate at least 30 days of local storage before swap-out to a network share.
  3. Configure User Administrator: mirror the TIA Portal user groups, assign WebUX and client rights, and enable the audit trail option for energy compliance (IEC 62443, NERC CIP overlap).

IEC 60870-5-104 Channel Configuration Reference

The IEC 104 channel in WinCC V8.1 is configured under Tag Management → [Driver] IEC 60870-5-104. The key parameters are listed below.

Parameter Default Field-proven value Notes
TCP port (local and remote) 2404 2404 Standard. Some utilities tunnel IEC 104 through 19999 or a custom port; match the RTU.
Common address (CASDU) 1 Site-specific (1–65 534) Must match the RTU station address. Use one CASDU per substation.
Time-out t0 (connect) 30 s 10 s Faster failover detection.
Time-out t1 (ack) 15 s 15 s Per IEC 104 § 8.1.
Time-out t2 (no ack) 10 s 10 s Per IEC 104 § 8.1.
Time-out t3 (test frame) 20 s 20 s Test APDU interval. Lower (5–10 s) for fast-failover on microwave links.
k (max unack APDU) 12 12 Per IEC 104 § 8.1.
w (latest ack after) 8 8 Per IEC 104 § 8.1.
General Interrogation (GI) Off On, on connection establish + every 15 min Re-syncs all static points after a link drop.
Time sync Off On, master Server pushes UTC time to RTU per IEC 60870-5-104 § 7.3.
ASDU cause-of-transmission filter All Spontaneous + Interrogated + Background scan Reduces noise; matches RTU capability.
Redundancy mode Off On (two channels, two NICs) RTU normally supports dual NIC; confirm before enabling.
Cause-of-transmission (COT) is where IEC 104 integrations go wrong. A common field fault: the SCADA requests General Interrogation (COT=20) and the RTU replies with a spontaneous burst of background-scan data (COT=2) on the same socket; the master confuses the two and raises a "data mismatch" alarm. Filter COTs explicitly in the channel configuration and log every received APDU during commissioning.

Integration with S7-1200/1500 PLCs

WinCC V8.1 keeps the PLC engineering in TIA Portal. The link between the V8.1 SCADA project and the TIA Portal project is the AS-OS Engineering import or a manual CSV/OPC UA bridge. Two clean patterns are common in energy projects:

Pattern A — Direct S7 Channel with Symbolic Access

  1. In TIA Portal, mark the S7-1200/1500 DBs as optimised only if you do not need symbolic WinCC access. For WinCC V8.1 S7 channel symbolic access, set the DB to non-optimised and enable Accessible from HMI/OPC UA on the DB properties.
  2. Export the TIA Portal project to a .zap archive (or share the project directory read-only on the network).
  3. In WinCC V8.1, open AS-OS Engineering and point to the TIA project. The wizard reads the PLC tag table and the HMI tag table, then maps TIA HMI tags to WinCC V8.1 external tags.
  4. Build the S7 connection in Tag Management → SIMATIC S7-1200, S7-1500 Channel. Set the PLC IP, rack 0, slot 1, and enable Symbolic access.

Pattern B — OPC UA Hand-off

  1. Enable the OPC UA server on the S7-1500 CPU (firmware V2.9 or later). Author the OPC UA interface in TIA Portal.
  2. In WinCC V8.1, add the OPC UA WinCC Channel driver. Add the S7-1500 OPC UA endpoint URL (e.g., opc.tcp://192.168.10.20:4840).
  3. Browse the OPC UA address space and import tags.

Pattern A is preferred for hard real-time polling (sub-second); Pattern B is preferred for brownfield integration or when the S7-1500 must also feed other SCADA systems.

Redundancy, Scalability, and Long-Term Support

WinCC V8.1 supports up to 18 redundant server pairs. In the field this is configured as follows:

  1. Install WinCC V8.1 Server on both hosts. Install the Redundancy option licence on both.
  2. Open the project on the master server. In Server-to-Server Communication, add the partner server name and the redundancy TCP port (default 5000/5001 for control and archive sync).
  3. Enable Server Redundancy in Computer Properties. Set the fail-over trigger threshold (default: 25 s partner heartbeat miss).
  4. Configure each client's Preferred Server and Failover Server in the WinCC Client configuration.

At 18 server pairs (36 servers) WinCC V8.1 can address a multi-site utility's full substation fleet in a single logical project tree, with hot-standby fail-over and a 10+ year LTS contract window. This is the headline scalability win over WinCC Professional's single-station-plus-redundant-RT model.

Common Pitfalls and Field-Proven Caveats

Pitfall Symptom Fix
SQL 2019 not uninstalled before V8.1 install Setup aborts with 0x80070643 Uninstall SQL 2019 fully, reboot, reinstall SQL 2022, then WinCC V8.1
WinCC Professional RT kept on the V8.1 host Setup refuses to start; channel conflicts Move TIA Pro to a separate engineering host. Per TIA parallel-install rules, this is not permitted
IEC 104 GI and spontaneous burst collide on socket Data-mismatch alarms, sticky values Filter cause-of-transmission; log APDUs during commissioning
DB is optimised, no HMI access flag S7 channel symbolic access fails at runtime Switch DB to non-optimised, tick "Accessible from HMI/OPC UA"
Picture migration expected as binary PDLs missing, screens blank Re-author screens in WinCC V8.1 Graphics Designer; do not rely on the GRACS folder for production
Tag count over licence tier Runtime starts in "degraded" mode, license error in diagnostics Count tags in WinCC Explorer; upsize licence (e.g., 6AV6371-1... tier bump)
Time sync to RTU not enabled Sequence-of-events timestamps drift in archive Enable IEC 104 time sync (COT=6) from server; verify RTU accepts
Redundancy heartbeats crossing VLANs False fail-overs Open ports 5000/5001 between server pair; add QoS DSCP for control plane
Archive on same disk as OS I/O starvation under heavy alarm burst Move archive DB to dedicated SSD; set swap-out to a NAS
Custom VB script from TIA Pro pasted into V8.1 Syntax errors (VBScript vs WinCC V8.1 C / VB) Rewrite using WinCC V8.1 VBScript reference; test on isolated screen first

Verification and Commissioning Checklist

Use this checklist before cutover. Each item must be ticked and the result documented in the site acceptance test (SAT) report.

  1. WinCC V8.1 RT starts, no licence errors in WinCC Explorer → Tools → System Diagnostics.
  2. Tag count inside the licensed tier; License.TierLimit and License.Used reported in diagnostics.
  3. S7 channel: connection to S7-1500 CPU at Online → S7-1200/1500 Channel Diagnostics shows Connected, no quality 0x1F (bad).
  4. IEC 104 channel: Connection Diagnostics shows Connected, GI completed, no APDU timeouts in the last 24 h.
  5. General Interrogation received from every configured CASDU within 30 s of connect.
  6. Time sync (COT=6) sent and acknowledged; RTU clock drift < 1 s.
  7. Spontaneous burst of M_ME_NC_1 measured values is shown on the operator screen with the correct quality code.
  8. Single command (C_SC_NA_1) is sent, select-before-operate acknowledged, and the corresponding status flag (M_SP_NA_1) reflects the new state within 5 s.
  9. Redundancy fail-over: pull network on master server, partner takes over within the configured heartbeat × 2 window, no operator screen loss.
  10. Archive: forced a tag change, verified the value is stored in the SQL archive within one acquisition cycle and visible in Tag Logging → Trends.
  11. User administration: forced an invalid login, account lockout behaves per energy cyber-security policy (NERC CIP / IEC 62443 alignment).
  12. Audit trail: every operator action is logged with user, timestamp, and action.
  13. Backup: WinCC project backup and SQL archive backup run on schedule, restore was tested on a bench host.

Recommendation for a Small PLC/SCADA Team

For a small engineering team in the energy industry running 1 000 to 50 000 tags across one to ten substations, migrating the SCADA layer from WinCC Professional to WinCC V8.1 is technically straightforward and economically favourable once an external IEC 104 gateway is in the loop. The three conditions that make the switch clean are:

  1. The PLC engineering stays in TIA Portal; WinCC V8.1 is a SCADA-side replacement only.
  2. You have a Windows Server 2022 host (or can procure one) for the V8.1 RT and SQL Server 2022.
  3. You accept a screen rebuild: TIA Pro HMI screens are not binary-compatible with WinCC V8.1 PDLs, and the time spent on PDL re-authoring is the dominant engineering cost in the migration.

For projects under 3 000 tags with no IEC 104 requirement, WinCC Professional remains the right tool. Above that threshold, or whenever IEC 60870-5-104 / 101 polling is required, WinCC V8.1 is the lower-risk, lower-TCO path on a 10-year horizon.

Does WinCC Professional support IEC 60870-5-104 natively?

No. WinCC Professional (TIA Portal) does not ship with a native IEC 60870-5-104 master. Native IEC 104 support is provided by the SIMATIC WinCC V8.1 IEC 60870-5-104 Channel option under the WinCC Classic line.

Can WinCC Professional and WinCC V8.1 be installed on the same machine?

No. The TIA Portal parallel-installation guide explicitly forbids running WinCC Professional ES/RT alongside WinCC V7.x or V8.x on the same host. Use a separate engineering machine for TIA Portal ES. See the TIA V21 parallel-installation rules.

Which SQL Server does WinCC V8.1 require?

Microsoft SQL Server 2022 Standard or Enterprise, English/international, collation SQL_Latin1_General_CP1_CI_AS, instance name WINCC. SQL Server 2019 must be uninstalled before WinCC V8.1 setup; mixed major versions on the same host are not supported.

How do I reuse TIA Portal HMI screens in WinCC V8.1?

There is no binary conversion. Two practical paths: (1) open compiled TIA RT files from the project GRACS folder as a layout reference, or (2) re-author screens in the WinCC V8.1 Graphics Designer using PDL objects and the Siemens HMI Template Suite faceplates. Pattern (2) is the recommended production path.

How many redundant server pairs does WinCC V8.1 support?

Up to 18 redundant server pairs, i.e. 36 servers, in a single project tree. Fail-over is partner-heartbeat driven, default 25 s threshold, with TCP ports 5000/5001 for control and archive synchronisation.

What is the long-term support window for WinCC V8.1?

WinCC V8.1 is the bridge product between WinCC V7.x and WinCC Unified, sold with a 10+ year LTS contract window. Always confirm the exact end date with the current Siemens Product Lifecycle Status before commitment.

Back to blog