S7-1200 as OPC UA Client: Capability Matrix and Migration Guide

David Krause14 min read
S7-1200SiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview: The S7-1200 OPC UA Client Question

OPC UA (IEC 62541) is the de-facto interoperability standard for industrial data exchange, and many engineers want to consolidate a SIMATIC S7-1200 into an existing OPC UA topology as a client that not only reads and writes nodes but also subscribes to a publisher for change-driven updates. The short answer: the first-generation S7-1200 CPUs (firmware 4.x) are server-only for OPC UA. Real client capability, including monitored-item subscriptions and the Publish/Subscribe (Pub/Sub) profile, lives in the S7-1500 family, and the S7-1200 G2 (second generation) was added to the client-capable family in TIA Portal V21 documentation. This reference covers the exact CPU / firmware / TIA Portal combinations, instruction set, security setup, and migration steps you need to implement or upgrade a Siemens OPC UA client.

Engineering note: A common misreading is that the S7-1200 firmware 4.4 release brought "OPC UA client" support. It did not. Firmware 4.4 expanded the S7-1200 Server surface (companion specifications, more nodes, methods). Client capability is a separate capability line that maps to firmware, TIA Portal version, and CPU generation.

S7-1200 Classic (First Generation) OPC UA Capabilities

The first-generation S7-1200 lineup (CPU 1211C / 1212C / 1214C / 1215C / 1217C, order numbers 6ES7211-1xxx, 6ES7212-1xxx, 6ES7214-1xxx, 6ES7215-1xxx, 6ES7217-1xxx) supports OPC UA strictly in the Server role. The Server is enabled in TIA Portal under Device Configuration → Properties → OPC UA → OPC UA Server, requires firmware V4.4 or higher, and exposes a configurable node set derived from PLC data blocks, tags, and methods. Authentication, encryption (Security Policies None, Basic128Rsa15, Basic256, Basic256Sha256), and certificate exchange are configured in the same dialog. Reference the official application example at the Siemens Support site: S7-1200 OPC UA Server Documentation V1.0.

Feature S7-1200 Classic (1st Gen)
OPC UA Server Yes, firmware V4.4.0+ (also V4.5/V4.6/V4.7)
OPC UA Client No
Subscriptions / Monitored Items (as client) No
Pub/Sub (UADP, broker-based) No
Companion Specifications Yes, limited to supported address space
Methods (server-side) Yes
Read / Write from external client Yes

The S7-1200's own documentation and the TIA Portal help text make the role explicit: in the project tree, the OPC UA option is labeled Server, and no Client instruction blocks (e.g. OPC_UA_Connect, OPC_UA_ReadList) appear in the instruction catalog for these CPUs. Programmatic attempts to use OPC UA client instructions with an S7-1200 classic CPU will fail at compile time or at the firmware check inside TIA Portal.

S7-1200 G2 (Second Generation) OPC UA Client Support

The second-generation S7-1200 (S7-1200 G2) was introduced with an extended instruction set, and the TIA Portal V21 documentation explicitly groups OPC UA client instructions under "S7-1500, S7-1200 G2". That means the G2 family accepts the same client-side FB / instruction family as the S7-1500: OPC_UA_Connect, OPC_UA_Disconnect, OPC_UA_NamespaceGetIndexList, OPC_UA_NodeGetHandleList, OPC_UA_ReleaseHandleList, OPC_UA_ReadList, OPC_UA_WriteList, OPC_UA_MethodCall, and subscription blocks where the firmware supports them. See the official help page: OPC UA Instructions for Client Programs (S7-1500, S7-1200 G2).

Feature S7-1200 G2
OPC UA Server Yes (firmware per TIA V21 release notes)
OPC UA Client Yes (TIA V21 instruction set, firmware per device release notes)
Subscriptions / Monitored Items (as client) Per firmware release notes — confirm with the exact G2 firmware order
Pub/Sub (UADP, broker-based) Confirm with firmware release notes; treat as project-specific
Security Policies None, Basic128Rsa15, Basic256, Basic256Sha256 (per CPU config)
Authentication Anonymous, UserName/Password, Certificate
Field note: Because the S7-1200 G2 line and the S7-1500 share the same client instruction family in TIA V21, code portability is high. Programs written for the S7-1500 (instructions + UDTs) can be reused on a G2 with little or no change, provided the firmware version supports every instruction used. Always cross-check the instruction's "validity" entry in the TIA Portal information system before porting.

S7-1500 OPC UA Client Capability Matrix

The S7-1500 family is the workhorse for OPC UA client work in the SIMATIC lineup. All standard CPUs (1511-1 PN through 1518-4 PN/DP, plus the 1519 and the compact ET 200 CPUs) implement the full client/server role, monitored-item subscriptions, and (since firmware V2.9) the Pub/Sub profile. The full server-side of an S7-1500 CPU can be set as Server, Client, or both simultaneously — useful for hub-style architectures where the 1500 brokers data between lower-tier devices.

CPU Class Server Client Monitored-Item Subscriptions Pub/Sub (UADP) Pub/Sub (Broker, MQTT)
S7-1505-S (PC-based) Yes Yes Yes Per firmware Per firmware
CPU 1511-1 PN Yes Yes Yes Yes (V2.9+) Yes (V2.9+)
CPU 1513-1 PN Yes Yes Yes Yes Yes
CPU 1515-2 PN Yes Yes Yes Yes Yes
CPU 1516-3 PN/DP Yes Yes Yes Yes Yes
CPU 1517-3 PN/DP Yes Yes Yes Yes Yes
CPU 1518-4 PN/DP Yes Yes Yes Yes Yes
CPU 1518-4 ODK Yes Yes Yes Yes Yes
CPU 1519-3 PN/DP Yes Yes Yes Yes Yes
ET 200SP CPU 1510/1512/1514 Yes Yes Yes Per firmware Per firmware

Subscriptions, Monitored Items, and Pub/Sub

An OPC UA client performs three principal interactions with an OPC UA server:

  1. Read / Write on demand: pull values or push values into specific nodes (e.g. via OPC_UA_ReadList and OPC_UA_WriteList).
  2. Monitored-Item Subscriptions: register interest in a node and receive a notification (DataChange / Event) from the server when the value changes, exceeds a dead-band, or at a defined sampling interval. The subscription carries publishing interval, lifetime count, and keep-alive count.
  3. Pub/Sub (UADP / Broker / MQTT): publisher pushes a network frame on a multicast or broker path; subscribers consume it without a dedicated session. Pub/Sub is brokerless UDP-based (UADP) or broker-based (MQTT) and is targeted at high-fanout, time-sensitive distribution.

The S7-1200 classic CPU cannot perform any of the three client interactions. The S7-1200 G2 implements the first two (read/write + monitored items) per the TIA V21 instruction list, while Pub/Sub support is firmware-dependent and must be confirmed against the specific G2 firmware release notes. The S7-1500 implements all three, with Pub/Sub on brokerless UADP and broker-based MQTT supported from firmware V2.9 (per the SIMATIC S7-1500 system manual release notes).

Decision path: If your project requires Pub/Sub (UADP multicast over Ethernet, or MQTT broker fan-out to cloud), choose an S7-1500 (firmware V2.9+). If you only need read/write and standard monitored-item subscriptions and you are on the S7-1200 platform, use an S7-1200 G2 with TIA Portal V21. If you are locked to the S7-1200 classic line, plan a hardware migration.

TIA Portal Configuration for OPC UA Client

  1. Add the OPC UA server endpoint. In the PLC device configuration, navigate to Properties → Communication → OPC UA. For an S7-1500 / S7-1200 G2 client, create a new Client interface and assign the server URL, port (default 4840), security policy, and authentication mode.
  2. Configure certificates. Generate or import the client certificate, then export it for installation on the server's trusted list. Conversely, install the server's certificate into the client trust store. The OPC UA instructions consult these trust lists at runtime.
  3. Enable User management. If the server enforces authorization, add a user to Users and roles with read/write/method-call rights that match the server's policy. Anonymous is supported but should never be used in production.
  4. Insert a client interface DB. In the program, declare an instance DB of the type generated when you create the client interface. This DB carries connection parameters and the ConnectionHwnd handle consumed by read/write instructions.
  5. Call OPC_UA_Connect in startup OB 100 / OB Startup. The block returns Done, Busy, Error, and Status; do not call read/write/method blocks until Done = TRUE for the connection.
  6. Use OPC_UA_ReadList / OPC_UA_WriteList in OB1 or a cyclic OB at a rate appropriate to the application. Group reads/writes by namespace index to minimize call overhead.
  7. Register monitored items with the subscription block, then process the resulting data-change events in a callback or queue mechanism tied to the client interface DB.
  8. Disconnect cleanly in OB 100 (restart) and OB Shutdown / Shutdown OB (stop). Unregister all monitored items first, then call OPC_UA_Disconnect.

OPC UA Client Instruction Reference (S7-1500 / S7-1200 G2)

The following blocks are part of the TIA V21 OPC UA client instruction family. The signatures are conceptual; always cross-check the input/output pin list against the TIA Portal information system for the specific instruction version you are using.

Instruction Function Key Inputs Key Outputs
OPC_UA_Connect Establishes a session to an OPC UA server ConnectionHwnd (in/out), ServerEndpointUrl, SessionSettings Done, Busy, Error, Status, ConnectionHwnd
OPC_UA_Disconnect Tears down a session cleanly ConnectionHwnd Done, Busy, Error, Status
OPC_UA_NamespaceGetIndexList Returns namespace URI / index mapping ConnectionHwnd, NamespaceArray Done, Error, Status
OPC_UA_NodeGetHandleList Resolves node IDs to runtime handles ConnectionHwnd, NodeIDList NodeHwndList, Error, Status
OPC_UA_ReadList Reads a list of nodes in a single call ConnectionHwnd, NodeHwndList, ReadList ValueList, Error, Status
OPC_UA_WriteList Writes a list of nodes in a single call ConnectionHwnd, NodeHwndList, WriteList Done, Error, Status
OPC_UA_MethodCall Invokes an OPC UA method on the server ConnectionHwnd, ObjectNodeHwnd, MethodNodeHwnd, InputArgs OutputArgs, Error, Status
OPC_UA_Browse Walks the server's address space ConnectionHwnd, StartingNode, BrowseDirection ReferenceList, ContinuationPoint, Error
Subscription block (per firmware) Creates/refreshes a subscription and registers monitored items PublishingInterval, SamplingInterval, QueueSize, Deadband SubscriptionHwnd, MonitoredItemHwnd, Notification

Example: Read Three Tags in a Single List Call

// PLC tag setup
TYPE UDT_NodeHwndList :
  STRUCT
    hTemp   : DInt;   // handle to ns=2;s="DB_Temp".TempValue
    hPress  : DInt;   // handle to ns=2;s="DB_Temp".PressValue
    hFlow   : DInt;   // handle to ns=2;s="DB_Temp".FlowValue
  END_STRUCT
END_TYPE

VAR
  iDbConnHwnd : DInt;        // from OPC_UA_Connect
  iNodeHwnds  : UDT_NodeHwndList;
  arrRead     : ARRAY[1..3] OF LReal;
  bDone       : Bool;
  bBusy       : Bool;
  bErr        : Bool;
  wStatus     : Word;
END_VAR

// Call (SCL)
OPC_UA_ReadList(
    ConnectionHwnd := iDbConnHwnd,
    NodeHwndList   := iNodeHwnds,
    ReadList       := arrRead,
    Done           => bDone,
    Busy           => bBusy,
    Error          => bErr,
    Status         => wStatus
);

Example: Subscription Parameters (Monitored Items)

// Recommended starting values for a 100 ms class subscription
PublishingInterval : TIME := T#100ms;   // server sampling dispatch
SamplingInterval    : DInt := 50;       // ms, server-side sampling
QueueSize           : DInt := 10;       // 10 queued notifications
LifetimeCount       : DInt := 600;      // 60 s at 100 ms interval
KeepAliveCount      : DInt := 10;       // 1 s keep-alive
Deadband            : LReal := 0.5;     // absolute, per item

Workarounds for S7-1200 Classic CPUs

When the controller is locked to a first-generation S7-1200, the OPC UA client role is unavailable on the PLC itself. The two standard engineering workarounds are:

  1. Use a SCADA / HMI as a relay. Deploy an OPC UA client in the SCADA layer (WinCC Unified, Ignition, iFIX, FactoryTalk, custom .NET / C#) that subscribes to the external publisher and exposes the data to the S7-1200 via the S7 communication protocol (PUT/GET, ISO-on-TCP, S7-comm over the LAN). The S7-1200 acts as the data sink via a vendor-specific driver rather than OPC UA. Latency is bounded by the SCADA's poll cycle and S7-driver throughput.
  2. Add an S7-1500 (or ET 200SP CPU) as a gateway. Place an S7-1500 in the same PROFINET subnet; the 1500 acts as the OPC UA client to the external server and writes the values into shared PROFINET / S7 connections that the S7-1200 reads. This is the most common pattern in brownfield upgrades and is the closest "native" substitute for an in-PLC OPC UA client.

Both patterns preserve the S7-1200's existing program; you do not need to re-engineer the application — you add a broker outside the 1200. The decision between the two is primarily cost: a single SCADA license versus a single S7-1500 + power supply + I/O.

Migration Path: S7-1200 to S7-1500

For greenfield OPC UA client projects, an S7-1500 (CPU 1511-1 PN or higher) with firmware V2.9+ is the reference choice. If the project is forced to stay on S7-1200 hardware, the S7-1200 G2 plus TIA Portal V21 is the correct platform. The migration steps are:

  1. Inventory the existing S7-1200 program: list of OB, FB, FC, DB, I/O map, and any library elements. TIA Portal's Project → Device proxy or a portability tool generates a starting point.
  2. Replace the CPU in the project with the target CPU (S7-1500 or S7-1200 G2). TIA Portal highlights instruction differences; resolve any S7-1200-only instructions (e.g. certain motion blocks) with their S7-1500 equivalents.
  3. Re-compile and download to the new hardware. Cross-check retain tags; the retain mechanism is similar but the on-board / SIMATIC memory card configuration differs.
  4. Re-create the OPC UA server on the new CPU (if the old one was server-side), then add the client interface, certificates, and instructions per the section above.
  5. Run a parallel-mode validation: keep the legacy 1200 controlling the process, mirror the new CPU's reads/writes into shadow tags, and compare for 24–72 hours before cutover.

Verification, Diagnostics, and Common Faults

Diagnose OPC UA client behaviour with three tools: the TIA Portal online diagnosis view, the CPU's web server diagnostic page, and the OPC UA client's Status and Error outputs.

Symptom Likely Root Cause Corrective Action
OPC_UA_Connect returns Status = 0x80000000 (BadCommunicationError) Wrong endpoint URL, port blocked, or DNS resolution failure Verify opc.tcp://<ip>:4840 from a URCap-free PC; check firewall and PROFINET topology
Status 0x801F0000 (BadSecurityChecksFailed) Certificate not in server's trust list, or trust chain invalid Re-export client cert from the device configuration, install on server, restart server
Status 0x80200000 (BadUserAccessDenied) User not authorized, or anonymous rejected Configure the user under Users and roles, map the role to the right endpoints, and re-try
ReadList returns Status = 0x80340000 (BadNodeIdUnknown) Node ID string does not match server address space Use OPC_UA_Browse from the server to confirm the actual NodeID, then update the program
Subscription yields no DataChange events Sampling interval too long, or dead-band too wide for the signal Reduce SamplingInterval and Deadband, raise QueueSize
Client compiles but does not appear in instruction list (S7-1200 classic) CPU is server-only; the block family is not exposed Plan migration to S7-1200 G2 or S7-1500
Pub/Sub broker connection refused Broker URL wrong, MQTT port (8883) blocked, client ID collision Verify broker logs, confirm port and TLS, set a unique client ID, refresh CA bundle
Verification checklist (post-deployment):
  • OPC_UA_Connect.Done = TRUE within 5 s of startup.
  • Initial ReadList returns expected values within 1 sampling interval.
  • Subscription receives at least one DataChange within 2× publishing interval when the source value steps.
  • Web server diagnostic page reports the active OPC UA session count = 1.
  • Server-side trust list contains the client certificate's thumbprint.
  • Disconnect in OB 100 / Shutdown OB completes with Error = FALSE.

Security and Performance Constraints

Production OPC UA clients must run with a non-None security policy. Configure Basic256Sha256 unless the server demands a specific policy, and use a 2048-bit RSA client certificate generated by the TIA Portal device configuration. The S7-1500 supports security policies None, Basic128Rsa15, Basic256, Basic256Sha256, and Aes128-Sha256-RsaOaep (policy per CPU firmware). For session throughput, the S7-1500 sustains hundreds of monitored items per session; the S7-1200 G2 has lower limits, and the S7-1200 classic is server-only. When designing a hub-style architecture with an S7-1500 acting as both client and server, count both incoming and outgoing sessions against the CPU's OPC UA connection limit (firmware-dependent; see system manual).

Summary of the Decision

Need Recommended Siemens CPU Required TIA Portal Required Firmware
OPC UA Server only S7-1200 classic (1st gen) TIA V15+ V4.4.0+
OPC UA Server + basic Client (R/W) S7-1200 G2 TIA V21 Per G2 release notes
OPC UA Server + Client + Monitored Items S7-1200 G2 or S7-1500 TIA V21 (G2) / TIA V15+ (1500) Per device release notes
OPC UA Pub/Sub (UADP, MQTT) S7-1500 TIA V17+ (UADP from V2.9; MQTT per release) V2.9+
Large node counts / high throughput S7-1516/1517/1518/1519 TIA V17+ V2.9+

Frequently Asked Questions

Can a first-generation S7-1200 act as an OPC UA client?

No. S7-1200 classic CPUs (1211C, 1212C, 1214C, 1215C, 1217C) support the OPC UA Server role only, starting with firmware V4.4. The OPC UA client instruction set is not exposed in the instruction catalog and is not enabled by firmware updates. To get client behavior on a 1200-line controller, you must use the S7-1200 G2 (second generation) with TIA Portal V21.

Which Siemens CPUs support OPC UA subscriptions and Pub/Sub?

Full monitored-item subscriptions and the OPC UA Pub/Sub profile (UADP and MQTT) are available on the S7-1500 family from firmware V2.9 onward. The S7-1200 G2 implements read/write and (per its firmware release notes) monitored items, but Pub/Sub support is firmware-dependent and must be verified against the specific G2 firmware order.

What is the minimum TIA Portal version for OPC UA client programming?

OPC UA client instructions on the S7-1500 are available from TIA Portal V14 SP1 (basic) and TIA Portal V15 (expanded method call and namespace handling). For the S7-1200 G2 client instructions, use TIA Portal V21. The client interface DB is generated by the TIA Portal dialog and must match the firmware version of the target CPU.

How do I make an S7-1200 classic read OPC UA data without buying a 1500?

Place a SCADA or HMI (for example WinCC Unified) in the network as an OPC UA client to the external server, then forward the values to the S7-1200 via the S7 protocol (PUT/GET or S7-comm driver). The 1200 receives S7 telegrams, not OPC UA, but the data flow achieves the same end result with no PLC program change beyond the receiving side.

What status codes should I expect from a failed OPC UA connect?

Common S7-1500 OPC UA client status values: 0x80000000 BadCommunicationError (network or URL), 0x801F0000 BadSecurityChecksFailed (certificate/encryption), 0x80200000 BadUserAccessDenied (auth or authorization), 0x80340000 BadNodeIdUnknown (wrong node path on the server). Read the Status word from the failing instruction and map it to the OPC UA error code namespace in the OPC UA specification IEC 62541 part 6 for the canonical meaning.

Does an S7-1200 G2 need a license for OPC UA client?

Server and client OPC UA on the S7-1500 and S7-1200 G2 are typically included with the CPU firmware. Some companion-specification features (for example specific industry information models) may require a separate runtime license. Confirm the exact license scope against the CPU's order number and the current TIA Portal V21 license terms for the G2 line.

Back to blog