Resolve Know-How Protection Locks in STEP 7 V5.7 to TIA V17 CFC

David Krause12 min read
SiemensTIA PortalTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Problem Overview

Engineers maintaining legacy S7-300/S7-400 controllers frequently run into a hard failure mode when porting a STEP 7 V5.7 project containing Continuous Function Chart (CFC) blocks into TIA Portal V17 (or V16/V18): the migration tool silently re-locks almost every block it touches by tagging them with Know-How Protection (KHP). Once this state is written into the TIA project, the user can no longer open the affected FBs, FCs, DBs, or UDTs because the password that was used in the original STEP 7 V5.7 source is not transferable to the new TIA project format.

The result is a TIA Portal project that compiles, but contains logic that cannot be viewed, edited, or downloaded for service. This article documents the root cause, the official Siemens guidance, the pre-migration cleanup procedure, the supported text-export options for CFC logic, and the manual reconstruction strategy that is required when targeting an S7-1500 CPU.

Critical: If the original STEP 7 V5.7 source archive or the original know-how protection password is not retained, the affected blocks cannot be recovered after migration. Always secure a working backup of the S7 project before starting any migration attempt.

2. Root Cause Analysis

Three distinct constraints collide during a STEP 7 V5.7 → TIA Portal migration of CFC logic. Each must be addressed before the migration will succeed cleanly.

2.1 Know-How Protection Translation Behavior

Siemens' online documentation for TIA Portal explicitly states the rule that trips most engineers: "Note that the calling block may not carry any know-how protection, as the block call has to be adapted during compilation. If there is no compatible instruction ..." The TIA migration compiler rewrites every block interface and call site during the porting pass. Because KHP blocks cannot be inspected by the compiler, the migration tool preserves the protection state by writing the converted block back into the TIA project as a KHP block — but with a TIA-format internal hash instead of the original STEP 7 V5.7 password. From the engineer's perspective this looks like the blocks have been "re-locked" with a password they no longer possess.

2.2 CFC Source Format Is Not Translatable

CFC is a graphical, sheet-oriented continuous-flow language that lives on top of STEP 7 V5.x as an optional add-on (PCS 7 or the CFC option package). The TIA Portal CFC editor has been present since V14, but it is scoped to S7-1500 targets only and only within specific PCS 7 / PLC engineering contexts. A standalone S7-300/S7-400 CFC cannot be converted 1:1 because the runtime model, the chart container objects, and the implicit run-order groups do not have direct equivalents in the S7-1500 firmware class.

2.3 Interface and Library Dependencies

Most CFC charts reference the CFC Library, the PCS 7 Basis Library, and frequently S7 Standard Library > Standard Blocks. After migration these references resolve against TIA libraries only when the called FB/FC itself was free of KHP. A protected wrapper anywhere in the call chain collapses the entire chart to an unopenable black box in TIA.

Table 1 — Root Cause Matrix for CFC Migration Failure
Symptom in TIA Portal Underlying Cause Locked By
Block opens with KHP banner and unknown password Compiler could not rewrite interface of KHP-protected block STEP 7 V5.7 KHP
CFC chart not visible in S7-1500 program CFC runtime object not supported for S7-1500 outside PCS 7 scope TIA Portal target
Compile error "Block type unknown" CFC Library FBs absent in TIA Library reference
FB opens but body is empty after migration Source block was protected and emptied during conversion STEP 7 V5.7 KHP

3. Official Siemens Guidance

Siemens publishes the constraints in the TIA Portal online help under the migration chapter. The relevant entry is:

Key extract: "Note that the calling block may not carry any know-how protection, as the block call has to be adapted during compilation. If there is no compatible instruction ..." The same guidance appears in the V17 help under the path Migration → STEP 7 projects → Special points to observe → Migrating program blocks. Always read this page for the exact TIA version that will perform the migration, because the wording and the supported source blocks can shift between service packs.

Documentation rule: The TIA Portal help is version-specific. A clean migration against V17 SP1 should be verified against the V17 SP1 help, not the V20 mirror shown above. The rule itself — "no KHP on calling blocks" — has been stable since V14.

4. Prerequisites

Before touching any migration wizard, confirm the following pre-conditions. Missing any item forces a re-do of the entire procedure.

  1. STEP 7 V5.7 (or V5.6) with the CFC option package installed on the engineering workstation that will perform the export.
  2. Source project backup: a complete .zip or folder backup of the original S7-300/400 project including S7PROG\, ...\Charts\, and ...\Sources\.
  3. Know-how protection passwords for every FB, FC, DB, and UDT that is currently KHP-protected. Inventory them with the SIMATIC Manager "Know-How Protection" dialog and store the list in a password vault before continuing.
  4. TIA Portal V17 (or matching target version) installed with the S7-1500 support package and, if PCS 7 logic is involved, the PCS 7 V9.0/V9.1 engineering components.
  5. TIA Portal SIMATIC Migration Tool licensed and accessible from Project → Migrate project.
  6. CFC source export license for the version of STEP 7 that owns the project.

5. Pre-Migration Cleanup in STEP 7 V5.7

The cleanup sequence below must be performed in SIMATIC Manager (or the CFC Editor) before the TIA Migration Tool is invoked.

5.1 Inventory the Protected Blocks

  1. Open the STEP 7 V5.7 project in SIMATIC Manager.
  2. Right-click the S7 program → Object Properties → Know-How Protection. Note every block flagged with a padlock icon.
  3. Export the list to khp_inventory.csv with columns: Block Name, Block Number, Block Type, Password Required (Y/N), Original Author.

5.2 Remove Know-How Protection

  1. For each protected block: right-click → Object Properties → Know-How Protection → Remove.
  2. Enter the original password. The block icon loses the padlock.
  3. Save and compile the S7 program (Program → Compile and Download Objects) to confirm no protection remains.
Audit requirement: Customers who received KHP blocks from a third-party integrator or from a Siemens OEM typically do not own the password. In that case, the only legal path is to request the unprotected STL/SCL source from the original author before any migration can proceed. Migrating protected blocks produces an unrecoverable TIA project.

5.3 Export CFC Charts as Text

CFC has no native "export to STL" path, but the following three text-based extractions preserve enough information to rebuild the chart on the S7-1500.

5.3.1 Source File Export (preferred)

  1. In SIMATIC Manager, select Options → CFC → Chart Export (or Tools → Charts → Export depending on the option package).
  2. Choose Format: SCL Source or AWL Source. The export produces one .scl or .awl file per chart.
  3. Store the sources in ...\S7PROG\Sources\ so the TIA Migration Tool picks them up automatically.

5.3.2 Printout to PDF for Visual Reference

  1. Open each chart in the CFC Editor.
  2. Chart → Print → Print to File (PDF). The printout contains sheet layout, I/O wiring, and run-order group numbers — exactly the data needed to re-sheet the chart on TIA.

5.3.3 Cross-Reference List

  1. Options → Cross-References for each chart. Save as cref_chart_X.txt — these lists identify which shared DBs and instance DBs the chart writes to.

5.4 Recompile and Archive

  1. Compile the cleaned S7 program with Program → Compile All.
  2. Verify zero KHP blocks remain: Edit → Find → "Know-how protected".
  3. Re-archive the project as ProjectName_CleanForMigration.zip.

6. Performing the Migration to TIA Portal V17

  1. Launch TIA Portal V17. Project → Migrate project.
  2. Select the cleaned .s7p file.
  3. Choose target CPU family: S7-1500.
  4. Run the migration. Expected warnings:
    • "CFC charts cannot be migrated automatically — manual conversion required."
    • "Library references to PCS 7 Basis Library need re-resolution."
  5. Confirm the resulting TIA project opens, compiles, and that no blocks are flagged KHP.

7. Manually Rebuilding CFC Logic on S7-1500

Because the S7-1500 firmware does not execute classic STEP 7 V5.x CFC runtime objects, every chart must be translated into an equivalent TIA construct. Use the decision tree below.

Table 2 — CFC Construct → S7-1500 Equivalent
CFC Construct S7-1500 Equivalent Notes
Single-sheet chart with <30 blocks Single FB in LAD/FBD Re-sheet using the PDF printout as wiring guide.
Multi-sheet chart with run-order groups Multiple FBs called from a sequencer OB Preserve run-order by calling FBs in priority order from OB30/OB35.
Sequencer chart (SFC transition logic) SCL state machine inside an FB Translate transitions to CASE/WHEN statements.
Chart that drives actuators directly FB + dedicated I/O DB Keep instance DB naming to preserve HMI tags.
CFC using PCS 7 APL blocks APL V9.x library in TIA Re-link APL FBs from PCS 7 V9 library set.

7.1 Re-Sheet Procedure

  1. Open the CFC PDF printout and the exported .scl source side by side.
  2. In TIA Portal, create a new FB FB_Chart<NNN> in the S7-1500 program.
  3. For each block on the printout: place the corresponding instruction from the TIA library, wire the inputs and outputs per the PDF, and assign the same instance DB names that the HMI references.
  4. Insert the chart-level FB into a run-order OB (typically OB30 for 100 ms or OB35 for 1000 ms).

7.2 State-Machine Translation

For SFC-style CFC charts, the standard SCL skeleton is:

FUNCTION_BLOCK FB_Chart100_StateMachine VAR iState : INT := 0; bStart : BOOL; bStop : BOOL; bRun : BOOL; END_VAR BEGIN CASE iState OF 0: // Idle IF bStart THEN iState := 10; END_IF; 10: // Run bRun := TRUE; IF bStop THEN iState := 0; END_IF; ELSE iState := 0; END_CASE; END_FUNCTION_BLOCK

Each transition condition from the original chart becomes a guard inside the appropriate CASE branch. Keep the original transition names as comments so the HMI fault texts remain traceable.

8. Migration Topology

The end-to-end flow from the legacy CPU to the S7-1500 replacement is summarized below.

S7-300/400 CPU STEP 7 V5.7 + CFC SIMATIC Manager Remove KHP / Export SCL TIA Migration Tool V17 / S7-1500 target TIA Portal: Manual CFC reconstruction as FB / SCL on S7-1500 Re-sheet blocks, re-wire I/O, preserve HMI tag names, validate in PLCSIM

9. Verification Checklist

After migration and manual re-sheating, run the following acceptance checks before commissioning the S7-1500.

  1. KHP scan: Project → Search → "Know-how protected" — must return zero hits.
  2. Compile clean: Project → Compile → Software (rebuild all) — zero errors, zero warnings about missing block types.
  3. PLCSIM simulation: Run every reconstructed FB inside S7-PLCSIM V17 against the original test vectors; I/O must match the legacy CPU behavior within tolerance.
  4. Cross-reference audit: Open HMI tags and confirm every tag still resolves to a valid DB or instance DB.
  5. Run-order timing: Capture OB30/OB35 execution time; sum of FB times must stay under the configured cyclic interrupt budget.
  6. Sign-off: Document migrated FB names against the original chart names so the maintenance team can find the new code.

10. Troubleshooting Matrix

Table 3 — Failure → Cause → Fix
Failure Observed Likely Cause Corrective Action
All blocks locked after migration Pre-migration KHP not removed in V5.7 Repeat §5.2 against the field report project.
Compile error "FB4100 unknown" CFC Library FB not migrated Install PCS 7 V9.x library; re-link FBs.
OB1 cycles longer than 100 ms on S7-1500 CFC reconstructed as a single huge FB Split per the original run-order groups; call from cyclic OB.
HMI loses live tags Instance DB renamed during rebuild Restore original DB names; update HMI tag DB if necessary.
Password prompt appears in TIA on every block open Migration tool retained KHP state for calling blocks Re-migrate after removing all KHP on calling and called blocks.
"Block type incompatible" on S7-1500 Legacy ANY/POINTER parameters in V5.7 FB interfaces Convert to VARIANT in the reconstructed SCL FB.

11. Field-Proven Caveats

  • PCS 7 vs. standalone CFC: If the project is part of a PCS 7 V8.x plant, prefer PCS 7 V9.x migration tooling. Standalone STEP 7 + CFC migration strips the chart containers entirely.
  • SFC inside CFC: Charts that embed SFC sequencers must be exported as separate .scl sources; the migration tool cannot infer transition logic from a chart printout.
  • Library version skew: The PCS 7 Basis Library V8.x FBs are not bit-compatible with V9.x. Re-test every alarm and interlock after the upgrade.
  • HMI tag continuity: Siemens WinCC V7.x tags pointing to instance DBs of the original charts must be re-mapped in TIA WinCC. Skipping this leaves the operator screen with "Address error" badges.
  • Audit trail: KHP removal is logged only locally in STEP 7 V5.7. Customers in regulated industries (FDA 21 CFR Part 11, ISA-99) must capture a screenshot of the inventory list before and after the removal for the validation dossier.

12. FAQ

Why does TIA Portal V17 lock my STEP 7 V5.7 blocks with know-how protection after migration?

The TIA migration compiler cannot rewrite the interface of a know-how protected block. It therefore preserves the protected state and writes the converted block back with an internal TIA hash that is not the original STEP 7 V5.7 password. Remove every KHP flag in SIMATIC Manager before starting the migration, as documented in the TIA Portal migration help.

Does TIA Portal V17 support migrating CFC charts to an S7-1500 automatically?

No. The TIA V17 migration tool warns "CFC charts cannot be migrated automatically — manual conversion required." CFC runtime objects are scoped to S7-1500 only inside PCS 7 V9.x; a standalone STEP 7 V5.7 CFC must be re-sheeted as LAD/FBD/SCL FBs by the engineer.

Can I export a CFC chart as text so I can rebuild it later?

Yes. In SIMATIC Manager use Options → CFC → Chart Export with format SCL Source or AWL Source. The resulting .scl/.awl files plus a PDF printout of the chart contain enough information to re-sheet the logic on the S7-1500.

What happens if I do not have the original know-how protection password?

The protected blocks cannot be recovered. The migration will succeed technically but the body of every KHP block becomes invisible in TIA Portal. Always secure the original password list from the project author or system integrator before any migration attempt.

Which OB should call my reconstructed CFC FBs on the S7-1500?

Use a cyclic interrupt OB such as OB30 (100 ms) or OB35 (1000 ms) and call the FBs in the same priority order as the original CFC run-order groups. This preserves the deterministic execution that CFC relied on in STEP 7 V5.x.

Back to blog