Resolving WinCC HMI Simulation Time Reset to 01-01-1990
When the WinCC Advanced Runtime simulation forces the Windows system clock to 01-01-1990 00:00:00 and only advances the seconds field before snapping back, the fault almost always lies in a stale or improperly initialised PLC date/time tag that the HMI is reading through the Date/Time PLC area pointer or through a direct HMI tag link. This article walks through the diagnosis, root cause, and corrective procedure in TIA Portal V20, including how an unused DATE_AND_TIME tag with the S7 default start value of DT#1990-01-01-00:00:00 can still overwrite the HMI time during simulation.
Problem Description
The reported symptoms in WinCC Advanced (TIA Portal) simulation are reproducible across Comfort Panels, RT Advanced, and RT Professional projects:
- On Start Runtime in the WinCC simulation, the Windows host clock is forced to 01-01-1990 00:00:00.
- The HMI clock display updates only the seconds field. After 00:00:10 the value resets to 00:00:00 instead of advancing through minutes, hours, and days.
- The Windows host clock occasionally flickers back to the current time, then returns to 01-01-1990 in a 1-2 second cycle.
- The PLC clock on the S7-1500 or S7-1200 CPU reports the correct local time when read online.
- The fault disappears when the user creates a fresh project with a single [Date/Time] I/O field, confirming that the issue is project-specific and not a WinCC installation defect.
- PLC-side time reads via
RD_SYS_Tare correct, but the HMI continues to display 1990-01-01.
DATE_AND_TIME (DT) BCD word that is being polled but never advanced by the user program. The HMI increments the seconds byte by simple addition without carrying into minutes, hours, or days, so the value oscillates inside the lowest BCD nibble of byte 5.Root Cause Analysis
WinCC RT Advanced simulation runs entirely on the engineering PC. By default it uses the Windows system time for all HMI tags of the type Date/Time. The simulation only deviates from the host clock when one of the following data sources is configured in the HMI connection or in the device configuration:
-
Area Pointer "Date/Time PLC" – a contiguous data area in the PLC that the HMI polls and uses to overwrite its internal clock master. Length is 16 bytes for an S7-300/400
DATE_AND_TIMEstructure and 12 bytes for an S7-1200/1500DTLstructure. -
Direct HMI tag link – an HMI tag mapped to a PLC tag of type
DATE_AND_TIMEorDTLthat is then bound to a Date/Time I/O field on a screen. - Time synchronisation job from the PLC – when the S7-1500 is configured as the time master (or as a slave following a master), it broadcasts its clock via the connection and the HMI follows that master.
In the reported case, none of the three mechanisms was supposed to be active. The cross-reference showed the offending CPUTimeDate tag in the DB was unused, and the tag was not in the HMI tag list. Yet the moment the simulation started, the HMI latched onto 1990-01-01 00:00:00 — the S7 DATE_AND_TIME minimum BCD value — and drove the host clock with it.
Three plausible explanations exist for the persistence of the stale value, and in practice one or more of them are present in parallel:
- A previously configured Date/Time PLC area pointer still pointed at a DB word range that contained the unused
CPUTimeDatetag, even after the tag was removed from the HMI tag list. The pointer survives in the HMI connection configuration independently of the tag list. - An old HMI tag with a PLC link of type
DATE_AND_TIMEwas deleted from the tag list, but the compiled RT image still pointed to the DB byte offset, so the simulator kept reading the residual value. - The S7-1500 slave clock was enabled in the device configuration and the CPU wrote its current time into the DB only after startup. Until the first write, the area pointer held the initial value of the DB tag — which the engineer had set to 1990-01-01 00:00:00 for the
CPUTimeDatestructure.
Once the offending DB tag was deleted, all three potential pathways were severed, and the simulation reverted to the Windows system clock. The flicker between correct and 1990-01-01 also stopped because the multiplexer no longer had a competing source.
Diagnostic Procedure
Follow this ordered checklist before deleting any tag. Each step eliminates one possible pathway without touching production logic.
- Verify the host clock — confirm that the Windows time is correct before starting the WinCC simulation. A bad host clock produces identical symptoms and is the cheapest variable to rule out.
- Open the HMI connection in the TIA project tree: Project → Devices → [HMI] → Connections → [PLC connection] → Area Pointers. Note whether Date/Time PLC is active and the start address it points to. Disable the pointer temporarily and recompile the HMI.
- Open the PLC device configuration for the S7-1500: Properties → Time of day → Time synchronisation. If Synchronisation type is set to Slave or Slave with follow-up, the CPU will only listen — meaning that until a master writes the time, the PLC clock and any data area it exposes stays at the CPU start-of-day value.
- Run the simulation with the area pointer disabled. If the time advances correctly, the pointer was the carrier. Re-enable it and proceed to step 5.
-
Cross-reference every DB tag of type
DATE_AND_TIME: PLC programming → DB → right-click tag → Cross-references. Any tag with zero usage but a non-zero start value is a suspect. - Open the HMI tag list and filter for tags with Date/Time or String PLC data type pointing to the suspect DB. Use Find (Ctrl+F) for the DB number and the tag name.
- Watch the suspect address online with Monitor & Force. If the bytes remain at 16#90 16#01 16#01 16#00 16#00 16#00 16#00 16#00 (the BCD encoding of 1990-01-01 00:00:00.000) the tag is never written by the user program and the HMI is reading the default.
- Rebuild the WinCC runtime image: right-click the HMI device and select Compile → Software (rebuild all). A clean rebuild clears cached pointers in the compiled *.fwx file under the project's <project>\IM\HMI\ folder.
Solution
Apply the corrective actions in the order below. The complete fix typically requires both the removal of the stale tag and the explicit re-establishment of a clean time path.
Step 1: Remove the stale DATE_AND_TIME tag
In the PLC project, delete the CPUTimeDate tag (or rename it so it is no longer a DATE_AND_TIME structure). Compile the PLC program and download to PLCSIM or the physical CPU. The start value of DT#1990-01-01-00:00:00 is removed from the DB initial image.
Step 2: Clean the WinCC runtime image
In the TIA Portal HMI project, right-click the HMI device and select Compile → Software (rebuild all). This regenerates the *.fwx file and forces the simulation to re-bind every tag. The build log should report zero warnings of the form "Tag has no link to a PLC tag" for any address in the suspect DB.
Step 3: Re-configure the time source explicitly
Choose exactly one of the following three strategies and disable the other two. Mixing strategies is the most common cause of the flicker between host time and PLC time.
Strategy A — Host clock only (recommended for pure simulation):
- Open HMI Connections → Area Pointers and clear the Date/Time PLC address.
- Open Properties → Time of day on the S7-1500 and set synchronisation to None.
- Use the local WinCC system tag
@LocalTimefor any clock display on screen.
Strategy B — PLC as time master:
- Configure the S7-1500 as NTP client or use the
WR_SYS_Tinstruction in the user program to set the CPU clock from a trusted source. - Re-enable Date/Time PLC and point it at a dedicated DB with a
DTLtag of 12 bytes (S7-1200/1500) that the program updates every cycle with the result ofRD_SYS_T. - Set the area pointer acquisition cycle to 1 s (default 2 s is too slow and produces visible flicker on a healthy network).
Strategy C — External NTP for both PC and PLC:
- Point the engineering PC and the S7-1500 at the same NTP server (e.g., a plant server on the trusted network).
- Disable the Date/Time PLC area pointer entirely.
Step 4: Rebuild and re-test
Download the HMI project to the simulator and verify that the Windows clock and the HMI clock both hold the correct time. If the seconds counter still rolls over at 10, repeat step 7 of the diagnostic procedure and recheck the suspect area for stale DATE_AND_TIME bytes.
Step 5: Sample SCL code for the Date/Time PLC pointer
The following SCL code maintains a DTL tag that is suitable as the target of the Date/Time PLC area pointer on an S7-1500. The tag must be 12 contiguous bytes. The WinCC area pointer must be configured with the start address of the YEAR member and a length that covers the entire DTL structure.
// SCL - block title: fbtTimeSync (FC, cyclic OB1)
#retValRead := RD_SYS_T(RET_VAL := #retVal);
IF #retValRead = "0" THEN
"DB_TimeSync".CPUTime_DTL.YEAR := #retValRead.YEAR;
"DB_TimeSync".CPUTime_DTL.MONTH := #retValRead.MONTH;
"DB_TimeSync".CPUTime_DTL.DAY := #retValRead.DAY;
"DB_TimeSync".CPUTime_DTL.WEEKDAY := #retValRead.WEEKDAY;
"DB_TimeSync".CPUTime_DTL.HOUR := #retValRead.HOUR;
"DB_TimeSync".CPUTime_DTL.MINUTE := #retValRead.MINUTE;
"DB_TimeSync".CPUTime_DTL.SECOND := #retValRead.SECOND;
"DB_TimeSync".CPUTime_DTL.NANOSECOND := #retValRead.NANOSECOND;
END_IF;
For an S7-300/400 DATE_AND_TIME tag the program can use READ_CLK / SET_CLK or simply call the IEC library function DT_TO_DTL after reading the CPU clock into a temporary.
Verification
After applying the fix, confirm the following five checks before closing the project:
- Host clock stability — start the simulation and leave it running for 10 minutes. The Windows clock must not deviate from the real time by more than 1 s.
- HMI clock display — the [Date/Time] I/O field on every screen shows the host or PLC time without resetting.
- PLC online monitor — the date/time bytes in the area pointed at by Date/Time PLC change at least once per acquisition cycle.
- WinCC diagnostics buffer — Tools → HMI Diagnostics reports no warning of class "Time synchronisation failure" or "Area pointer length mismatch".
- Compile-clean — Compile → Software (rebuild all) on the HMI device returns zero errors and zero warnings.
Area Pointer "Date/Time PLC" Reference
The area pointer is configured under the HMI connection in TIA Portal. The parameter set is small but every field has a direct effect on the symptom described above.
| Parameter | Default | Notes |
|---|---|---|
| Active | false | Must be enabled for PLC → HMI time push. Disabling restores host-clock behaviour. |
| PLC address (start) | DBn.DBX0.0 | Must point to a contiguous 12-byte (DTL) or 16-byte (DATE_AND_TIME) area. Mismatched length is reported as a warning in the HMI compile log. |
| Length | 16 bytes | 12 bytes for S7-1200/1500 with DTL; 16 bytes for S7-300/400 with DATE_AND_TIME. |
| Acquisition cycle | 2 s | Lower values (0.5–1 s) eliminate flicker but increase WinCC tag load. |
| Update on screen change | false | Recommended false for time tags; setting true causes screen-load spikes. |
DATE_AND_TIME tag is DT#1990-01-01-00:00:00 and that value will reach the HMI within one acquisition cycle of the simulation starting.DATE_AND_TIME Data Type Layout (S7-300/400)
The S7-300/400 DATE_AND_TIME (DT) is an 8-byte BCD structure. The minimum legal value is 1990-01-01 00:00:00.000, which is byte-for-byte the value the host clock in the reported case.
| Byte | Content | BCD example (1990-01-01 00:00:00.000) |
|---|---|---|
| 0 | Year (90–89, BCD) | 16#90 |
| 1 | Month (01–12, BCD) | 16#01 |
| 2 | Day (01–31, BCD) | 16#01 |
| 3 | Hour (00–23, BCD) | 16#00 |
| 4 | Minute (00–59, BCD) | 16#00 |
| 5 | Second (00–59, BCD) | 16#00 |
| 6 | Milliseconds high + middle | 16#00 |
| 7 | Milliseconds low + weekday (high nibble) | 16#00 |
When the HMI receives this raw image and interprets it without the program ever incrementing it, the seconds counter simply rolls over at the 0–9 BCD boundary, producing the 00:00:10 → 00:00:00 pattern observed in the field. The flicker is the RT simulator alternating between the host clock and the PLC area pointer on each acquisition cycle.
S7-1500 Time Synchronisation in TIA Portal V20
On the S7-1500, time synchronisation is configured under Properties → Time of day → Time synchronisation. TIA Portal V20 introduces a revised NTP client wizard and exposes the slave clock as a configurable object. The relevant parameters are:
| Parameter | Options | Effect on HMI time |
|---|---|---|
| Synchronisation type | None / Slave / Slave with follow-up / Master / NTP | Slave-only configurations leave the CPU clock at 1990-01-01 until a master writes; HMI inherits that value through the area pointer. |
| Time zone | UTC offset list | Mismatch between CPU and HMI time zone produces a 1 h or 24 h offset without changing the date. |
| Update interval | 1 s – 24 h | Long intervals (≥ 1 h) make the HMI clock appear to "stick" at the last update value. |
| Follow-up after loss | Slow / Fast | Slow follow-up holds the CPU at 1990-01-01 for hours after a cold start if no master is reachable. |
For TIA Portal V20 specifically, the Basic Panels and RT Advanced runtime documentation is available at Starting Runtime on the HMI device (Basic Panels) - WinCC TIA Portal V20. The page confirms that the local simulation always uses the host clock unless the project explicitly subscribes to a PLC time source via the area pointer mechanism.
Time Synchronisation Flow
The SVG below shows the three competing time sources and the path that wins in the reported fault case. Solid red lines are the active (incorrect) path; dashed grey lines are the disabled paths that the project was supposed to use.
Edge Cases and Related Symptoms
Several symptoms that look identical to the one above have different root causes and are worth distinguishing during commissioning:
| Symptom | Likely cause | First check |
|---|---|---|
| Time stuck at 1990-01-01, seconds only | Stale DATE_AND_TIME tag in DB | Cross-reference every DT tag in the project DBs. |
| Time stuck at 1970-01-01 | WinCC reading a DTL tag with a zeroed YEAR (S7-1500 default) | Check the YEAR word at the start of the DTL structure. |
| Time is correct but offset by ±1 h | Time zone mismatch between CPU and HMI | Compare Properties → Time of day on CPU and HMI. |
| Time flickers host ↔ PLC every 2 s | Acquisition cycle conflicts with NTP on the PC | Disable NTP on the engineering PC or raise the area pointer cycle to 10 s. |
| Time jumps by hours on screen change | "Update on screen change" enabled on a Date/Time PLC area pointer | Set the option to false for time tags. |
| Time is correct in PLCSIM but wrong on physical HMI | Hardware clock battery low on the panel | Replace the buffer capacitor / battery on the Comfort Panel. |
| Time stops at 23:59:59 then wraps to 1990-01-01 | DTL YEAR word exceeded UINT range or corrupted by non-atomic write | Use a single MOV block to update the DTL structure; never write members individually from different OBs. |
Preventing Recurrence
Three engineering practices eliminate the entire class of faults:
-
Never initialise a
DATE_AND_TIMEtag with a literal start value other than the current local time. If the program does not maintain the tag, set its start value toDT#1990-01-01-00:00:00and remove it from any area pointer range. Better: delete the tag entirely and recompile. - Use a single time source. Pick host clock, PLC master, or NTP — not two. Document the choice in the HMI tag comment and in the project functional specification.
- Compile-rebuild the HMI after every DB structural change. A normal incremental compile does not always re-resolve area pointer ranges; only a full rebuild forces a regeneration of the RT image.
-
Reserve a dedicated time-sync DB. Use a DB with a single
DTLtag whose start value is left at the IEC default. Update the tag in a cyclic OB (OB1 or OB30) so that it is always written at least once after every cold start. - Validate time path in the FAT. On the factory acceptance test, run the HMI for 30 minutes after a CPU cold start and confirm the displayed time is within 1 s of the reference clock.
FAQ
Why does the Windows clock follow the HMI in the WinCC simulation?
WinCC RT Advanced writes the active time source back to the host operating system time as part of its TimeService tick. If the simulation is forced to a stale PLC value, the host clock is overwritten with that same value, which is why both clocks snap to 1990-01-01 together.
What is the S7 default start value of a DATE_AND_TIME tag?
The S7-300/400 DATE_AND_TIME minimum value is DT#1990-01-01-00:00:00.000, encoded as eight BCD bytes starting at 16#90. This is the value the PLC presents to the HMI whenever the user program does not write the tag, and it is the same value the host clock is forced to in the reported symptom.
Can the area pointer point to a tag that the program never uses?
Yes. The Date/Time PLC area pointer is a pure address range; it does not check whether the user program writes to it. A never-written tag will deliver the start value to the HMI for the entire project life, which is why the offending tag was visible in cross-reference as unused yet still affected the HMI time.
How do I force the HMI to use only the Windows system time?
Open HMI Connections → [PLC connection] → Area Pointers and clear the Date/Time PLC address. On the S7-1500 set Properties → Time of day → Synchronisation type to None. Use the WinCC system tag @LocalTime on screen objects.
Does a clean recompile of the HMI device fix the fault?
Often, yes. A full rebuild (Compile → Software (rebuild all)) regenerates the RT image and forces the simulator to re-bind every tag. The underlying stale PLC tag must still be removed or the fault will return on the next cold start.