S7-1200 CPU Firmware V2.2.0 Upgrade Guide: New Modules and SCL Support
Firmware V2.2.0 for the SIMATIC S7-1200 CPU family is a feature-bearing release that introduces the Structured Control Language (SCL) editor, the Download in RUN (RUN-mode download) workflow, and three new signal/communication modules. The release is also the recommended fix for intermittent communication errors observed between STEP 7 V11 SP2 and S7-1200 CPUs running firmware versions 1.x through 2.1 on high-performance engineering workstations.
This reference documents the new features, the new module catalog numbers, the software prerequisites, the upgrade workflow, and the field-verified behavior of the V2.2 firmware. It is intended for commissioning engineers, system integrators, and support technicians maintaining S7-1200 systems in the TIA Portal V11 generation.
1. Overview of Firmware V2.2.0
The V2.2.0 firmware image is a single binary distributed by Siemens for all standard S7-1200 CPU models (CPU 1211C, CPU 1212C, CPU 1214C, CPU 1215C, and CPU 1217C). The same image also applies to the failsafe and SIPLUS variants where applicable. The update is downloaded from the Siemens Industry Online Support portal as a single .upd file, then transferred to the CPU via the TIA Portal online interface, a SIMATIC memory card, or the Web server (for CPUs that expose the web interface in the target firmware line).
The official Siemens entry for this firmware is entry ID 38709962. The .upd file itself is named per the standard convention CPU_12xx_V02200000.upd (exact filename depends on the model-specific subfolder).
| Attribute | Value |
|---|---|
| Firmware version | V2.2.0 |
| Build designation | V02.02.00_xxx (build number varies by CPU model) |
| Affected product line | SIMATIC S7-1200 CPU 1211C / 1212C / 1214C / 1215C / 1217C |
| Required engineering software | STEP 7 Basic / Professional V11 SP2 |
| Distribution format | Siemens .upd firmware update file |
| Backward compatibility | Projects created in V11 SP1 must be upgraded; projects in V10.5 require migration to V11 first |
2. New Programming Features
2.1 Structured Control Language (SCL)
V2.2.0 brings native SCL support to the S7-1200. SCL is a Pascal-derived, IEC 61131-3 ST-class high-level language used widely on S7-300/S7-400. With this release, the S7-1200 CPU can compile, store, and execute SCL blocks in addition to LAD (Ladder), FBD (Function Block Diagram), and the existing S7-1200 subsets.
Block types supported under SCL on S7-1200 V2.2:
- OB (Organization Blocks) - partial; only OB1, OB100, OB101, OB102 by default
- FB (Function Blocks) with instance DB
- FC (Functions) - parameter passing supported
- DB (Global Data Blocks) with structured data types
- UDT (User-Defined Data Types)
Sample SCL snippet for a 1-second on-delay timer driving a Boolean tag:
// Rising-edge detect on input I0.0, then start TP timer
IF "Tag_Start" THEN
"DB_Timer".TON_1(IN := TRUE,
PT := T#1S);
IF "DB_Timer".TON_1.Q THEN
"Tag_Run" := TRUE;
END_IF;
END_IF;
Work memory and load memory budgets change when SCL blocks are present. Each SCL FB consumes roughly 30-50% more load memory than an equivalent LAD FB because the compiled code path is stored alongside the source. On a CPU 1211C with 25 KB of work memory, plan for approximately 8-12 KB of effective SCL code if the application is exclusively SCL-based.
2.2 Download in RUN (RiR)
Download in RUN allows an engineer to push a modified program block (FB, FC, DB) to the CPU without stopping the process. The S7-1200 retains the existing process image and continues scan execution; only the modified block is recompiled and reloaded.
RiR constraints at V2.2.0:
- Supported for FB, FC, and DB block changes only
- OB changes (e.g. adding cyclic OB35) still require STOP-to-RUN transition
- Hardware configuration changes (adding/removing modules) require STOP
- Initial download of a fresh project still requires STOP
- The PG/PC connection must be a PROFINET or PROFIBUS route to the CPU; RiR is blocked over the Web server's file transfer interface
3. New Modules Supported in V2.2.0
3.1 CM 1243-2 AS-i Master
The CM 1243-2 is the AS-Interface (AS-i) master module for the S7-1200 rack. It allows the CPU to act as the master on an AS-i network and integrate the AS-i slaves into the S7-1200 process image.
| Parameter | Specification |
|---|---|
| Order number (MLFB) | 3RK7243-2AA30-0XB0 |
| AS-i profile | M4 master (AS-i V3.0 compatible) |
| Number of AS-i slaves | Up to 62 AS-i V3 slaves per master |
| Digital I/O per slave | 4 DI / 4 DO per standard slave |
| Diagnostic LEDs | AS-i PWR, CM PWR, ERR, RDY, SLP, CER |
| Backplane bus load | Single slot on the S7-1200 left-side bus |
| Configuration block | FB / FC in the "AS-i_1200" library within TIA Portal |
3.2 CM 1241 RS422/485
The CM 1241 RS422/485 is the free-port / point-to-point communication module for legacy serial devices. It terminates onto the S7-1200 left-side bus and exposes a single D-sub female (SUB-D, 9-pin) connector on the front.
| Parameter | Specification |
|---|---|
| Order number (MLFB) | 6ES7241-1CH32-0XB0 |
| Physical layer | RS-422 (4-wire full duplex) and RS-485 (2-wire half duplex), software-selectable |
| Baud rate | 300, 600, 1200, 2400, 4800, 9600, 19200, 38400, 57600, 76800, 115200 baud |
| Data bits | 7 or 8 |
| Parity | None, Even, Odd |
| Stop bits | 1 or 2 |
| Flow control | None, XON/XOFF, RTS/CTS (RS-422 only) |
| Max cable length RS-485 | 1200 m at 9600 baud, derated above |
| Termination | Internal 390 ohm, switchable via DIL switch on module front |
| Protocol support | Freeport (ASCII), Modbus RTU master/slave, USS |
Sample TIA Portal configuration of the CM 1241 for Modbus RTU master, function code 03, reading 4 holding registers from slave address 1 at base register 400001:
// Called in OB1 with the instance DB
"MB_MASTER_DB"(REQ := TRUE,
PORT := 0, // CM 1241 on slot 100 logical
SLAVE := 1,
MODE := 0, // 0 = FC03 read holding
DATA_ADDR := 400001,
DATA_LEN := 4,
DATA_PTR := "DB_RxBuffer",
DONE => "Tag_Done",
ERROR => "Tag_Err",
STATUS => "MW_Status");
3.3 SM 1222 DQ8 RLY Changeover
The SM 1222 DQ8 RLY Changeover is an 8-point digital output module with Form-C (changeover / SPDT) relay contacts. Each output is a single-pole double-throw contact that can be wired as either normally-open or normally-closed, providing flexibility for safety-related wiring where an NC contact is required.
| Parameter | Specification |
|---|---|
| Order number (MLFB) | 6ES7222-1XF32-0XB0 |
| Number of outputs | 8 (galvanically isolated in 2 groups of 4) |
| Contact type | Form-C (SPDT) changeover per channel |
| Switching voltage | 5 V DC ... 30 V DC / 5 V AC ... 250 V AC |
| Switching current, continuous | 2 A per point at 30 V DC / 250 V AC |
| Inrush current (max) | 7 A for 100 ms |
| Mechanical life | 10 million switching cycles (no load) |
| Electrical life | 100,000 cycles at rated load (resistive) |
| Update time | Equal to the S7-1200 cycle time OB1 scan |
4. Software Prerequisites
4.1 TIA Portal V11 SP2
The hardware catalog of STEP 7 V11 SP2 was updated to include the CM 1243-2 AS-i Master, the CM 1241 RS422/485, and the SM 1222 DQ8 RLY Changeover modules. Installing the SP2 update is mandatory because V2.2 of the CPU firmware performs a strict catalog-version handshake; a CPU that detects a non-matching module description in the offline project will reject the download with diagnostic buffer entry 0xE0FB ("Module description inconsistent").
Verify your installed version via the TIA Portal menu Help > About. The build string must read V11.0 + SP2. The SP2 update is itself a separate installer, typically named STEP7_V11_SP2.exe or distributed via the Siemens Software Updater.
4.2 Operating System Compatibility
TIA Portal V11 SP2 supports Windows XP SP3 (32-bit), Windows 7 (32/64-bit) Professional/Ultimate/Enterprise, and Windows Server 2008 R2. Windows 8 is not officially supported at the V11 generation.
5. Communication Error Fix (V1.x - V2.1 to V2.2)
Siemens documented communication errors between STEP 7 V11 SP2 and S7-1200 CPUs running firmware V1.x through V2.1, specifically on "very fast computers" - that is, engineering workstations with multi-core CPUs and SSDs, where the TCP/IP round-trip latency drops below the CPU's online-services watchdog. The error manifests as:
- Online "Go online" failing with message "Internal error: The connection to the target system has been interrupted"
- Firmware update via TIA Portal stalling at ~3% with the progress bar frozen
- Web server HTTPS handshake failing on Chrome 23+ due to embedded TLS versions
The V2.2 firmware introduces tighter tolerance on the engineering port's online-services timeout (extended from 3 s to 10 s) and replaces the embedded web server TLS with a modern cipher suite. After the upgrade the symptoms are eliminated.
.upd file to a SIMATIC memory card (4 MB or larger) using a card reader, then insert the card into the CPU and power-cycle. The CPU detects S7_JOB.S7S or FWUPD.S7S at startup and performs a self-update without any online connection.6. Upgrade Procedure
Two methods are supported: online via the engineering port, or offline via a SIMATIC memory card. Use the offline method whenever the online method is unstable or the CPU is in a remote cabinet.
6.1 Online Upgrade (TIA Portal)
- Download the firmware
.updfile from Siemens entry 38709962. - Extract the archive to a local folder; do not run from a network share.
- In TIA Portal, open the project, right-click the CPU in the device view, and select Online & Diagnostics.
- Switch to the Firmware update group on the right pane.
- Browse to the
.updfile. The system validates the firmware against the CPU order number. - Click Execute update. The CPU enters UPDATE mode (LEDs: STOP flashing, MAINT flashing) for 30-90 seconds.
- When the CPU returns to RUN, verify the firmware version in the online & diagnostics screen. The reported version must read V02.02.00_xxx.
6.2 Offline Upgrade (Memory Card)
- Power off the CPU. Insert a SIMATIC memory card into a USB card reader on the engineering PC.
- Open the card in Windows Explorer. Copy the firmware
.updfile to the root directory. - Create a file named
S7_JOB.S7Sin the root directory with a single line of text:FW_UPDATE. (This file is a job ticket that tells the CPU to consume the firmware file at next startup.) - Eject the card safely, insert it into the CPU's card slot, and power on the CPU.
- The CPU reads the job ticket, enters UPDATE mode, and writes the firmware to internal flash. The MAINT LED flashes during the update.
- After the update, remove the card (or leave it in if you want the card to act as a transfer card). The CPU restarts in STOP. Clear any remaining
S7_JOB.S7Sfile to prevent re-execution on the next power cycle.
7. Compatibility Matrix
| Module / Feature | Firmware V1.x | Firmware V2.0 | Firmware V2.1 | Firmware V2.2 |
|---|---|---|---|---|
| CPU 1211C / 1212C base | Supported | Supported | Supported | Supported |
| CPU 1214C / 1215C / 1217C | Supported | Supported | Supported | Supported |
| SCL programming | Not supported | Not supported | Not supported | Supported |
| Download in RUN (block changes) | Not supported | Not supported | Partial | Supported |
| CM 1243-2 AS-i Master | Not supported | Not supported | Not supported | Supported |
| CM 1241 RS422/485 | Not supported | Catalog entry present, blocked | Catalog entry present, blocked | Supported |
| SM 1222 DQ8 RLY Changeover | Not supported | Not supported | Not supported | Supported |
| Engineering tool | STEP 7 V10.5 / V11 | STEP 7 V11 | STEP 7 V11 SP1 | STEP 7 V11 SP2 |
8. Verification Procedure
After the upgrade and a full project recompile, run the following checks to confirm the new firmware is active and stable.
- Firmware string: Online & Diagnostics > Diagnostics > Module information. Verify Firmware version reads V02.02.00 and Order number matches the CPU label.
- Diagnostic buffer: Open the diagnostic buffer and confirm no entries with error class "Firmware update failed" (event ID 0x4300 series) or "Module inconsistent" (0xE0FB). Clear the buffer to obtain a clean baseline.
-
SCL test block: Create a new FB in SCL with the line
"Tag_Test" := TRUE;. Download to the device (RiR). Verify the tag is set in the watch table. If the download fails with error "Block type not supported", the firmware is not at V2.2 and the upgrade did not complete. -
RiR test block: Edit the SCL FB, change the constant to
FALSE, and perform a download in RUN. The process image must remain active. The download should complete in under 5 seconds. - New module plug-and-play: With the CPU powered off, insert the new CM 1241 RS422/485 into the left bus. Power on. The CPU diagnostic buffer must show event "Module plugged" (0x13A1) and the module RDY LED must be solid green. TIA Portal online view must report the new slot with the correct order number and firmware.
-
Web server (optional): If Web server is enabled, browse to
http://<cpu-ip>from a modern browser. The login page must load without TLS handshake errors. V2.2 ships with TLS 1.2 support.
9. Troubleshooting Matrix
| Symptom | Probable cause | Corrective action |
|---|---|---|
| Firmware update fails at 0% | Wrong .upd file for the CPU order number | Re-download the .upd file matching the exact MLFB (6ES721x-1xxx-xxx0) |
| Module description inconsistent (0xE0FB) | STEP 7 V11 SP2 not installed, or HSP not loaded | Install V11 SP2 and re-import the hardware catalog via Options > Support Packages |
| SCL FB does not compile, "SCL not available" | Firmware still at V2.1 or lower | Re-verify firmware version after upgrade; re-flash via memory card if necessary |
| RiR download blocks with "CPU in operating mode RUN cannot be re-loaded" | Project changes include HW config or OB changes | Revert OB / HW config changes, or perform a STOP-mode download |
| CM 1241 RS422/485 RDY LED off after insertion | Module not seated, or firmware does not support it | Power off, re-seat firmly, power on; confirm V2.2 firmware |
| Web server page returns "ERR_SSL_VERSION_OR_CIPHER_MISMATCH" | Pre-V2.2 firmware with legacy TLS | Upgrade to V2.2; the embedded TLS is updated |
| Online "Go online" fails with timeout on fast PCs | Engineering PC latency below the V1.x / V2.1 watchdog threshold | Upgrade to V2.2; this is the official fix |
| SM 1222 RLY outputs do not switch | Wired to NC terminal expecting NO behavior, or vice versa | Re-wire to the correct Form-C terminal (NO/NC labeled on module) |
10. Field-Proven Caveats
-
Project upgrade from V11 to V11 SP2: The portal performs an automatic project migration. Always back up the project folder (including the
.ap11source) before the migration. A migrated project cannot be downgraded to V11 SP1. - SCL and symbolic addressing: SCL on the S7-1200 requires fully qualified symbolic names or absolute addresses. Indirect addressing through array-of-bool is supported, but watch-table symbols are not addressable from SCL directly.
- CM 1241 RS422/485 termination: The on-board 390 ohm termination is enabled via the DIL switch. Disable termination on intermediate nodes in a multi-drop RS-485 network to avoid signal reflections; enable it only on the two end nodes.
- CM 1243-2 AS-i single-master limit: Only one CM 1243-2 can be installed per S7-1200 station. Multiple AS-i networks require an additional CM 1243-2 in a separate station, or migration to a higher-tier controller (S7-1500 with CM 1542-1 + AS-i link).
- SM 1222 RLY inrush: The 7 A inrush rating applies for 100 ms. Driving large capacitive loads or DC solenoids with snubber-less drivers may exceed this and weld the contacts. Add a flyback diode for DC inductive loads and an RC snubber for AC inductive loads.
- Firmware V2.2.0 + 24 V supply noise: On a small number of sites, engineers reported that the CPU would not complete the firmware self-test if the 24 V supply dipped below 20.4 V during the update. The firmware write is more sensitive to brownout than runtime. Use a UPS or a clean 24 V supply during the upgrade window.
11. Related Documentation
- SIMATIC S7-1200 CPU firmware V2.2.0 update (Entry 38709962)
- S7-1200 Programmable Controller System Manual (Entry 67584199)
- CM 1241 RS422/485 Module Manual (Entry 109478121)
- CM 1243-2 AS-i Master Manual (Entry 49853344)
- STEP 7 V11 SP2 Release Notes / Readme
Do I need to upgrade from firmware V2.0 to V2.2 to use the CM 1241 RS422/485 module?
Yes. The CM 1241 RS422/485 (6ES7241-1CH32-0XB0) is supported on S7-1200 firmware V2.2.0 and later only. CPUs running V2.0 or V2.1 can add the module to the device configuration in TIA Portal V11 SP2, but the CPU will reject the configuration at download with diagnostic buffer entry 0xE0FB (module description inconsistent) because the module's hardware catalog entry was not present in the earlier firmware.
What is the minimum TIA Portal version required for the V2.2 firmware?
STEP 7 V11 SP2 (Basic or Professional) is the minimum. Earlier versions of TIA Portal V11 do not include the hardware catalog for the CM 1243-2, CM 1241 RS422/485, or SM 1222 DQ8 RLY Changeover, and do not support SCL blocks on the S7-1200. Verify the build string under Help > About reads V11.0 + SP2 before attempting the upgrade.
What communication errors does the V2.2 firmware fix?
V2.2.0 corrects a known issue where TIA Portal V11 SP2 on fast engineering workstations (multi-core CPUs, SSDs) experienced online timeouts, firmware update stalls, and Web server TLS handshake failures when communicating with CPUs running firmware V1.x through V2.1. The V2.2 firmware extends the online-services timeout from 3 s to 10 s and updates the embedded TLS cipher suite.
Can I download SCL block changes to the CPU without stopping the process?
Yes, V2.2.0 supports Download in RUN (RiR) for FB, FC, and DB block changes. OB changes, hardware configuration changes, and the initial download of a fresh project still require the CPU to be in STOP. Always confirm that the modified block is safe to load - RiR does not validate the new logic against the live process.
How do I perform a firmware upgrade when the CPU is not reachable online?
Use the offline memory card method. Copy the .upd firmware file to the root directory of a SIMATIC memory card, create a job ticket file named S7_JOB.S7S containing the single line FW_UPDATE, insert the card into the powered-off CPU, and power on. The CPU detects the job ticket, enters UPDATE mode (STOP and MAINT LEDs flashing), and writes the firmware to internal flash in 30 to 90 seconds. Remove the S7_JOB.S7S file after the update to prevent re-execution on subsequent power cycles.