Recovering Editable TIA Portal HMI Projects from Panel Backups

David Krause11 min read
HMI / SCADASiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview

An automation cell ships with a SIMATIC HMI panel loaded with a WinCC TIA Portal V15.1 runtime project, but the original engineering source on the engineering station has been lost, overwritten, or never archived. A new field device such as a flowmeter must be added to the operator screen, and the engineer only possesses the panel-side backup file (the *.psb / *.brk / *.fwx restore image stored in \System\Backup\ on the HMI's internal storage or on a USB stick produced via Service & Commissioning > Backup / Restore).

The reported symptom is straightforward: the runtime project on the panel cannot be opened in TIA Portal V15.1 in an editable form, no tags can be added, no new screen elements can be inserted, and the existing screens cannot be exported for modification.

Root Cause Analysis

WinCC TIA Portal uses a strict one-way compilation pipeline. The engineering source — a multi-component TIA Portal project (.ap15_1) containing the HMI device master, the tag database, the screen editor data, the alarm logs, the script library, and the connection configuration — is compiled by the TIA Portal HMI compiler into a runtime image. That runtime image is what is downloaded to the panel and is what survives on the HMI as a panel backup or panel image.

There is no decompiler. The runtime image is not a project file, it is a binary snapshot optimised for the panel's RT (Runtime) kernel. The HMI operating system loads it directly into memory; it does not maintain source metadata that TIA Portal can read back.

Concretely, the following information is preserved in the panel backup:

  • Compiled screens as rasterised / vector run-time objects
  • The HMI tag database (names, data types, PLC addresses) — accessible only via the live HMI tag interface, not as an editable table
  • Active alarms, logged data archives (CSV / RDB), and recipe data
  • The IP address, PROFINET name, and panel firmware version

The following information is not preserved in a recoverable editable form:

  • Screen layouts as TIA Portal objects (texts, IO fields, buttons, geometry)
  • VBS scripts, C scripts, and faceplate type definitions
  • Cross-references, comments, project version metadata
  • Library references, style definitions, and graphic list sources

This is by design: Siemens documents the unidirectional flow from engineering to runtime in the TIA Portal help under Compiling and loading > Compilation flow and explicitly states that uploading a project from the panel back to the engineering station is not supported as an editing path. The supported use of a panel backup is restoration of the runtime to the same panel hardware.

Why "Upload" Cannot Recover the Editable Project

The TIA Portal menu sequence Online > HMI Device Maintenance > Backup / Restore is the only panel-side transfer dialog. It offers two operations:

Operation Direction Editable in TIA Portal?
Backup (read from panel) Panel → PC/USB No — produces a *.psb / *.brk restore image
Restore (write to panel) PC/USB → Panel No — overwrites runtime with the same compiled image
Project download (compile + load) PC → Panel N/A — requires the source on the PC

The optional Online > HMI Device Maintenance > Load to PG function available on some Unified Panels (V17 and later) transfers the runtime but does not re-import it as a TIA Portal project; it is intended for diagnostics and version comparison, not for source recovery.

Recovery Options — Decision Matrix

Option Feasibility Resulting Project Quality Effort
Recover original TIA Portal source from the engineer's archive, SVN/Git, or engineering PC backup Best, if available 100% original, fully editable Low
Recover via Siemens SIMATIC ProSave "Backup / Restore" reverse — use the *.psb as restore only, not as source Not applicable for source recovery N/A N/A
Reverse-engineer: re-create the TIA Portal project from screenshots, tag list, and PLC program Always possible Functional equivalent, but no original styling/scripts High
Live read-back of tag names via the HMI online tag view, combined with HMI screenshots Partial — tags only, no logic Use to accelerate re-engineering Medium
Contact Siemens Industry Online Support with the panel serial number; request source under a service contract Rarely successful — Siemens does not retain customer source Not available in standard support High
Important: Do not delete the panel backup. The backup is still required to restore the panel to the current operating state if a re-engineered project fails to compile or to verify a side-by-side runtime comparison after re-creation.

Prerequisites for Re-Engineering

  • TIA Portal V15.1 (or V15.1 Update 6 minimum) installed on the engineering PC, with the same HMI option packages (WinCC Comfort/Advanced/Professional) used by the original project
  • The original PLC project, if it is a SIMATIC S7-1200 / S7-1500 / S7-300 / S7-400 with the tag definitions and DB layouts visible
  • The panel backup file (the *.psb or *.brk image) and access to the physical panel for live tag reading
  • A photo or on-screen capture of every HMI screen (mobile phone camera at minimum), including the navigation hierarchy and the system screen
  • Ethernet connectivity between the engineering PC and the panel (PROFINET/IP) on the same subnet
  • ProSave V15.1 installed for direct backup/restoration and firmware updates if a panel restore becomes necessary

Step-by-Step Re-Engineering Procedure

Step 1 — Document the current HMI runtime

  1. Connect the engineering PC to the panel via PROFINET.
  2. Open ProSave, select the device type (e.g., TP900 Comfort, KTP1200, TP1500 Comfort), enter the panel IP, and select Read / Write > Backup > Read. Save the backup to a known path. Confirm the file size is non-zero.
  3. Open the panel's System Information screen (Control Panel > System) and record: device name, firmware version, image version, and build number. Example: TP900 Comfort, FW V15.1.0.0, Image V15.1.0.1.
  4. Capture every runtime screen. Navigate through all menus, sub-screens, alarms, trends, and recipes. Save each capture with a numbered prefix matching the menu hierarchy.

Step 2 — Extract the tag database from the running panel

  1. Start TIA Portal V15.1 and create a new project.
  2. Add a new HMI device matching the panel hardware (e.g., 6AV2 124-1MC01-0AX0 for TP1200 Comfort). Use the same article number to inherit the correct screen resolution (1280 × 800 for Comfort 12" and larger; 800 × 480 for KTP700 / TP700).
  3. Set the HMI's PROFINET IP and the PLC connection parameters to match the live panel.
  4. Compile the empty project and download to the panel only if you intend to overwrite the runtime; otherwise, use Online > Accessible Nodes to browse the live HMI tags without writing.
  5. Open Online > HMI Tags on the engineering PC. The TIA Portal online tag view does not directly read the panel's tag database, but if the PLC is online, you can read the connected PLC tags via the HMI's tag interface. Use Watch table or a temporary HMI tag list to enumerate the tag names referenced by the running screens.
  6. Alternative: open the panel's Diagnostics > Tag Simulation screen and exercise every IO field; record the tag name and the data type shown in the simulation. This produces a partial but useful tag table.

Step 3 — Recover the PLC tag list from the PLC program

  1. Open the connected PLC project (or upload from the PLC using Online > Upload from device on a S7-1200/1500).
  2. Open the PLC's PLC tags and all referenced data blocks (DBs). Export the tag table to CSV / XLSX via Tags > Export.
  3. Cross-reference the PLC tag names with the tag names observed in the HMI tag simulation. The PLC tag names form the namespace of the HMI tags once the connection is established.

Step 4 — Re-create the HMI screens

  1. Create the screens in TIA Portal in the same hierarchy as the captured screenshots. For a Comfort Panel, the default screen size is 1280 × 800 (12") or 1920 × 1080 (15" and 22"); the layout grid is 20 px.
  2. For each screen, add IO fields, buttons, symbolic IO fields, bars, trend views, alarm views, and recipe views that match the captured layout.
  3. Bind each element to the corresponding HMI tag. For PLC tags, the default connection is a single HMI connection pointing to the S7-1200/1500 with the put/get access right; for S7-300/400, configure the connection with the rack/slot.
  4. Re-author any navigation buttons and screen change events. Document the colour scheme and graphic list usage from the screenshots.

Step 5 — Add the new flowmeter tag and screen element

  1. In the PLC project, add the new flowmeter tag (e.g., "Flowmeter_1_ActualFlow" : REAL; in a new DB) and load the PLC program.
  2. Open the HMI project, navigate to HMI Tags, and add a new tag named Flowmeter_1_ActualFlow of type Real. Set the PLC address to the matching DB offset (e.g., %DB20.DBD0). Set the acquisition mode to Cyclic continuous with a 1 s cycle.
  3. On the appropriate process screen, add an IO field and a Bar element bound to the new tag. Configure the bar's minimum/maximum to the flowmeter's engineering range (e.g., 0–50 L/min). Add a label and a unit suffix ("L/min").
  4. Compile the HMI project (full rebuild, not incremental). Resolve all warnings — warnings frequently indicate tag mismatches that will not surface until runtime.
  5. Download the new runtime to the panel. Confirm the panel reboots into the new image.

Verification

  1. After download, the panel performs a restart. The startup screen should match the original.
  2. Navigate to the flowmeter screen and verify that the IO field shows a live value updating at the configured acquisition cycle.
  3. Open Diagnostics > Connection on the panel and confirm the HMI-to-PLC connection is Connected with no error code.
  4. Trigger a tag simulation on the PLC side (force a value in the DB) and verify the HMI reflects the change within two acquisition cycles.
  5. Cycle power on the panel and confirm the runtime persists and the flowmeter tag retains its value (or is correctly re-acquired from the PLC).
  6. Compare the new runtime against the saved original backup by restoring the original backup to a second panel or to the same panel if the new project is not yet signed off. The original backup is now your only rollback.

Preventive Best Practices

  • Use TIA Portal's Project > Archive function to create a versioned, compressed project archive after every functional change. Store archives in a version-controlled repository (SVN, Git, or Teamcenter).
  • Configure ProSave automatic backup of the panel after every download, and store the panel backup in the same version-controlled repository as the engineering source.
  • Document the panel's image version, firmware version, and PROFINET device name on the engineering PC and on the panel's physical label.
  • Maintain a side-by-side folder for each machine containing: the TIA Portal project archive, the ProSave panel backup, the PLC project archive, the wiring diagrams, and the commissioning report.
  • For machine builders, enforce a contractual hand-over package that includes the TIA Portal source and the panel backup as deliverables.

Troubleshooting Matrix

Symptom Likely Cause Resolution
Panel backup cannot be opened in TIA Portal File is a runtime image, not a project Restore via ProSave to the panel; do not attempt to decompile
Download fails with "Device type mismatch" Re-engineered HMI device article number differs from the physical panel Match the panel's article number exactly (e.g., 6AV2 124-1MC01-0AX0)
Tags show "#" placeholder on the screen HMI tag acquisition cycle is too long or connection is down Reduce cycle time, verify the HMI-to-PLC connection, check PLC access rights
Flowmeter value does not update PLC tag is in a non-optimised DB but HMI uses symbolic access only Enable symbolic access on the DB or use absolute addressing in the HMI tag
Compile error: "Variable does not exist in PLC" PLC was recompiled and tag offsets shifted Re-upload the PLC, regenerate the HMI tag references, recompile
Panel boots but screen layout is cropped Wrong screen size selected for the device Verify the device configuration matches the panel's display resolution

Related Siemens Documentation

Refer to the official Siemens Industry Online Support portal for the authoritative TIA Portal V15.1 HMI engineering manuals, WinCC V15.1 system manual, and SIMATIC HMI operator panel device manuals. The TIA Portal help under Visualize processes > Configuring HMI devices > Compiling and loading documents the one-way compile path, and the ProSave readme documents the panel backup file format.

Can I upload an editable HMI project from a panel backup to TIA Portal V15.1?

No. The panel backup (*.psb / *.brk) is a compiled runtime image, not a TIA Portal source. There is no decompiler and no "upload to PG" function that produces an editable project in TIA Portal V15.1. The supported workflow requires the original .ap15_1 engineering source; if that source is lost, the project must be re-engineered.

What is the difference between a panel backup and a TIA Portal project archive?

A TIA Portal project archive (.zap15_1) is a compressed, versioned copy of the engineering source containing the screen editor, tag database, scripts, and configuration. A panel backup is the compiled runtime image used only to restore the HMI to a known operating state. Use Project > Archive for source backup; use ProSave Backup/Restore for runtime backup.

How can I recover the HMI tag list from a running panel without the project source?

Connect the panel to the engineering PC via PROFINET, then use the panel's Diagnostics > Tag Simulation screen to exercise every IO field and record the tag name and data type. Cross-reference the captured names with the PLC tag database. The result is a partial tag table that accelerates re-engineering but does not include scripts, alarms, or screen layout.

What TIA Portal V15.1 option package is required to edit a Comfort Panel project?

WinCC Comfort or higher is required for Comfort Panels (TP700 / TP900 / TP1200 / TP1500 / TP1900 / TP2200). KTP panels require WinCC Basic (KTP400 / KTP700 / KTP900 / KTP1200 Basic). The option must match the device, otherwise the device cannot be added to the project tree.

Can Siemens Industry Online Support supply the original project for a lost source?

No. Siemens does not retain customer engineering projects. The only official paths are to locate the original engineering station, the machine builder's archive, or the customer's version-controlled repository. Re-engineering from a panel backup and a connected PLC is the standard field recovery path.

Back to blog