Problem Statement: Grayed-Out "Download Backup" on S7-1200
Engineers using TIA Portal V13 with an S7-1200 CPU running firmware version 3 frequently encounter a non-functional "Download backup" entry in the Online menu. The option appears grayed out (inactive) even when the project is opened, the CPU is added as a device, the user is connected online (the "Go online" action completes and the status indicator turns green), and the CPU responds to STOP/RUN commands. This behavior is not a defect, an installation error, a license deficiency, or a corrupted project file—it is the expected state of the TIA Portal menu when working with the S7-1200 platform, because the "Online Backup" function does not apply to this controller family.
The Siemens TIA Portal documentation explicitly limits the Online Backup (also surfaced in the menu as "Download backup") to the following device types: S7-300, S7-400 with Flash memory card, ET 200S, and ET 200Pro. The S7-1200 is intentionally not listed because its backup mechanism is implemented through a different workflow, not because the function is hidden, locked, or licensed. Operators who interpret the gray menu as a configuration error typically waste hours searching for non-existent options, license keys, or service packs. The remainder of this reference maps the three legitimate backup paths for the S7-1200, the TIA Portal version compatibility matrix, the part numbers involved, and the field-tested step-by-step procedure for each path.
Why "Download Backup" is Grayed Out on S7-1200
The "Online Backup" feature in TIA Portal targets the legacy backup model used by S7-300/400: a complete image of the load memory is streamed to the engineering station (PG/PC) and written to a single archive file. The S7-1200 architecture differs in three respects that make this model unsuitable:
- Load memory topology. S7-1200 stores the user program, hardware configuration, and PLC tags on internal flash memory that is permanently mounted on the CPU. There is no separate load memory image that can be streamed as a single binary block; the program is always present in flash, so an "image" backup would simply duplicate the on-line blocks with no incremental value.
- Service concept. Service on S7-1200 is performed with a SIMATIC memory card (SD card, part number prefix 6ES7954-8). The card acts as a transfer medium, a service medium, a recipe medium, a data-log medium, and a firmware update medium. The intended field-service workflow is: pull the SD card from the CPU, duplicate its contents on a card reader, and write the duplicate back to the original card or a replacement card if a restore is needed.
- Configuration delivery. Modern engineering practice (since the S7-1200 generation) is to maintain the canonical project on the engineering station and download it to the PLC. Recovery is performed by re-downloading the project from the engineering station, not by restoring a binary image captured at an earlier point in time.
Because of these architectural differences, the TIA Portal menu item is intentionally disabled for S7-1200 devices. Engineers should ignore the gray menu and use one of the three alternatives described in this reference.
Three Supported Backup Methods for S7-1200
Three backup paths are supported on S7-1200 CPUs running firmware V3.x with TIA Portal V13 or later. The choice of method depends on what is being backed up, what hardware is available, whether a TIA Portal project already exists, and how the file will be used for restore.
| Method | Source | Output Format | Use Case | CPU State Required |
|---|---|---|---|---|
| Upload to PG/PC | Online blocks | Editable TIA Portal project (.ap13 / .ap14 / .ap15) | Recover missing source project; modify and re-download | Online, any state |
| Backup from online device | Online blocks + hardware configuration | Compressed backup file (.s7pbkp, internally a ZIP) | Capture complete service snapshot including hardware config | Online, any state |
| SIMATIC memory card | Internal flash copy | Native S7-1200 file system (SIMATIC.S7S, S7_JOB\, etc.) | Field service without a PG/PC, firmware update, mass deployment | Insert card with CPU powered; no STOP required |
Each method captures a different subset of the PLC's persistent state. The table below maps what is captured and what is not.
| Persistent Element | Upload to PG/PC | Backup from Online Device | SIMATIC Memory Card |
|---|---|---|---|
| OB / FB / FC / DB blocks | Yes | Yes | Yes |
| PLC tags / DB initial values | Yes | Yes | Yes |
| Hardware configuration (DI/DO/AI/AO modules) | Partial (no module discovery) | Yes | Yes |
| CPU properties (IP, protection, time zone) | Partial | Yes | Yes |
| Active DB values (current process data) | No (only initial values) | No (only initial values) | No (only initial values) |
| Recipe / data logs | No | No | Yes (read via card reader) |
| Firmware on the card | No | No | Yes |
| Web server custom pages | No | No | Yes |
The selection logic is summarized in the following decision diagram.
TIA Portal V13 and S7-1200 FW V3 Compatibility Matrix
Firmware version 3 of the S7-1200 was released by Siemens in 2014 (CPU order numbers ending in -0XB0 for compact CPUs). The version of TIA Portal in use must match the firmware on the CPU; otherwise the project will not compile, online operations will be restricted, and the "Backup from online device" menu will remain grayed out.
| TIA Portal Version | Released | S7-1200 FW Support | Backup from Online Device (S7-1200) |
|---|---|---|---|
| V13 (base) | 2014-03 | FW V1, V2 only | Not supported |
| V13 SP1 | 2015-02 | FW V1, V2, V3 (partial) | Available with Update 4+ |
| V13 SP2 | 2015-06 | FW V1, V2, V3, early V4 | Yes |
| V14 (no SP) | 2016-09 | FW V4 fully | Yes |
| V14 SP1 | 2017-09 | FW V4.1, V4.2 | Yes |
| V15 / V15.1 / V16 | 2018+ | FW V4.4+ | Yes |
%ProgramFiles%\Siemens\Automation\.To check the TIA Portal version: launch TIA Portal, click Help > About. The "TIA Portal Version" field shows the version string (e.g., "V13 SP1 Update 9" or "V13 SP2"). The corresponding device description files are listed in Options > Support Packages > Installed Support Packages. If a Hardware Support Package (HSP) is missing for the CPU, install it from the Siemens Industry Online Support portal.
CPU Identification and Compatible SIMATIC Memory Cards
Before performing a backup, identify the CPU order number and the SIMATIC memory card part number. The order number is printed on the front of the CPU, on the packaging label, and in TIA Portal under Online & Diagnostics > Diagnostics > Device Information. The firmware version appears in the same dialog under the "Firmware" field.
| CPU Model | Order Number (FW V3) |
|---|---|
| CPU 1211C DC/DC/DC | 6ES7211-1AE40-0XB0 |
| CPU 1211C AC/DC/RLY | 6ES7211-1BE40-0XB0 |
| CPU 1212C DC/DC/DC | 6ES7212-1AE40-0XB0 |
| CPU 1212C AC/DC/RLY | 6ES7212-1BE40-0XB0 |
| CPU 1214C DC/DC/DC | 6ES7214-1AG40-0XB0 |
| CPU 1214C AC/DC/RLY | 6ES7214-1BG40-0XB0 |
| CPU 1215C DC/DC/DC | 6ES7215-1AG40-0XB0 |
| CPU 1215C AC/DC/RLY | 6ES7215-1BG40-0XB0 |
| CPU 1217C DC/DC/DC | 6ES7217-1AG40-0XB0 |
| SIMATIC Memory Card | Order Number | Capacity | Typical Use |
|---|---|---|---|
| SMC 4 MB | 6ES7954-8LC02-0AA0 | 4 MB | Small programs (under 1 MB) |
| SMC 12 MB | 6ES7954-8LE02-0AA0 | 12 MB | Most standard programs |
| SMC 24 MB | 6ES7954-8LF02-0AA0 | 24 MB | Programs with recipes or web pages |
| SMC 256 MB | 6ES7954-8LL02-0AA0 | 256 MB | Firmware update + program on one card |
| SMC 2 GB | 6ES7954-8LP02-0AA0 | 2 GB | Large logs, multiple firmware versions |
| SMC 32 GB | 6ES7954-8LT03-0AA0 | 32 GB | Maximum capacity, introduced 2018+ |
Method 1: Upload Blocks from Device to PG/PC
This method generates a fresh, editable TIA Portal project from the online blocks. It is the correct choice when the original project file is missing or out of date, and the engineer needs to modify, document, archive, or re-download the program. The output is a complete project file that can be opened, edited, recompiled, and downloaded.
Prerequisites
- TIA Portal V13 SP1 or later installed (matching the CPU firmware)
- S7-1200 reachable on the same subnet (PROFINET, Ethernet, or routed through a network gateway)
- CPU is online (the status indicator next to the device in the project tree shows a green check mark)
- Know-how protection password if the CPU is configured with block protection (otherwise the protected blocks upload as "unreadable" placeholders)
- At least 200 MB of free disk space for the new TIA Portal project file
Step-by-Step Procedure
- Open TIA Portal. If a project is open, close it (Project > Close). The upload creates a new, untitled project.
- Click Online > Accessible Devices. The "Accessible Nodes" dialog opens.
- Select the network interface that reaches the CPU. For built-in Ethernet, choose the PG/PC interface assigned to the Intel, Realtek, or Broadcom adapter connected to the plant network. For CP 1613/1623 or CP 5711, choose the corresponding Siemens interface. Click Start Search.
- The accessible devices list populates with the CPU IP, MAC, and device name. Double-click the target CPU to open the Online & Diagnostics view.
- From the project tree, right-click the project root (top-level entry), then select Upload from device > Software (only). The "Upload preview" dialog appears.
- Confirm the upload. TIA Portal creates a new, untitled project, transfers the blocks from the CPU, and places them under Program blocks > System blocks / Program blocks.
- Save the project immediately: Project > Save As, then choose a name and a folder. The file extension is
.ap13for V13 projects,.ap14for V14,.ap15for V15, etc. - Compile the project to confirm integrity: Project > Compile > Software (rebuild all). The status bar must show "Compile finished without errors".
Transfer Time Estimate
The upload time is dominated by the PROFINET/Ethernet transfer. Use the formula below to estimate the worst-case time for a known project size:
t_transfer (seconds) = S (KB) × 1024 × 8 / (R (Mbps) × 10^6 × η)
Where:
- S = total program size in KB (DB initial values + code blocks + system data)
- R = nominal link rate in Mbps (100 for PROFINET, 1000 for gigabit Ethernet)
- η = utilization factor, typically 0.4–0.6 for TCP/IP S7 communication, lower under heavy plant traffic
For example, a 500 KB program over 100 Mbps Ethernet at η = 0.5 yields t = 500 × 1024 × 8 / (100 × 10^6 × 0.5) = 4.10 / 50000 = 0.082 s. TIA Portal typically adds 10–30 s of overhead for handshake, compile, and metadata. Plan for 30–60 s of total wall-clock time for a typical 1–2 MB program.
Method 2: Backup from Online Device
This method creates a compressed archive containing the complete CPU state: blocks, hardware configuration, IP settings, time settings, and CPU properties. The file can be restored with Online > Restore from online device backup to the same CPU type, or downloaded to a new CPU of the same type as a clone. The output is a single .s7pbkp file, which is a ZIP archive with a TIA Portal–specific structure (folders Program blocks, IM, CPU, SystemData).
Prerequisites
- TIA Portal V13 SP1 Update 4 or V13 SP2 (or any V14+ version)
- Online connection to the target CPU
- CPU must be in STOP or RUN; both work for backup, and the operation does not interfere with running I/O scan
- Read-access to all blocks (no exclusive password, no read-only password protection)
- At least 50 MB of free disk space for the resulting archive
Step-by-Step Procedure
- Open the project that contains the CPU device, or open the CPU in Online & Diagnostics from the accessible devices view.
- Right-click the CPU in the project tree. Choose Online & Diagnostics if not already open.
- From the Online menu, click Backup from online device. The dialog Create backup of online device opens.
- Select the storage path and filename. The default extension is
.s7pbkp. To inspect the contents, rename to.zipand extract with any standard tool such as 7-Zip, WinRAR, or the Windows 10 built-in ZIP support. - Click Start Backup. The progress bar shows the transfer state. A typical 50-block program completes in 30–120 seconds over PROFINET.
- Verify the backup file size matches the expected size. A 1 MB project will produce a backup file of similar order of magnitude; the compression ratio is roughly 2:1 to 5:1 for textual SCL code and roughly 1.1:1 for compiled STL/FBD code.
Step-by-Step: Restore from Backup
- Connect to the target CPU online.
-
Online > Restore from online device backup. Select the
.s7pbkpfile. - TIA Portal matches the file to the CPU order number. If the order number differs, the restore is refused. The CPU must be reset to factory defaults or be in a compatible state (CPU order number identical, firmware version equal or higher).
- Confirm the transfer. The CPU goes to STOP, the program is overwritten, the CPU restarts.
- Wait for the MAINT LED to clear and the RUN LED to return solid green (or solid yellow in STOP). The process takes 10–60 seconds depending on the program size.
Method 3: SIMATIC Memory Card Program Copy
The SD card is the only field-service path that does not require a PG/PC. The card is inserted into the CPU, and the program is copied from internal flash to the card (or vice versa) by a power-cycle operation or by a menu action in TIA Portal. This method is the standard for field service on machines shipped with a SMC in the accessory bag.
Copy from CPU to Card (Program Backup)
- Insert a SIMATIC memory card (any size 4 MB or larger) into the CPU's card slot. The CPU must remain powered.
- Power-cycle the CPU (turn off, wait 5 seconds, turn on) OR use the TIA Portal menu Online & Diagnostics > Functions > Program copy from internal flash to SIMATIC memory card.
- The MAINT LED flashes during the copy. The RUN/STOP, ERROR, and MAINT LEDs indicate progress: MAINT solid + STOP solid = copy complete.
- Remove the card once the MAINT LED returns to its previous state. The card now contains a complete copy of the CPU program in the directory structure
S7_JOB\S7OSwith the main fileSIMATIC.S7S.
Copy from Card to CPU (Program Restore)
- Insert the source card into the CPU. Power off.
- Power on the CPU. The CPU detects a card with a valid program and offers to copy it. Press the selector switch (the front-panel knob) within 10 seconds to confirm, or use TIA Portal to trigger the copy remotely.
- The CPU copies the program from card to internal flash. On completion, the CPU restarts with the new program. The RUN/STOP LED indicates the new state.
Card File System Reference
The SIMATIC memory card file system is FAT32 with a specific directory layout:
| Path | Content |
|---|---|
\SIMATIC.S7S |
Main program file (S7-1200 native format) |
\S7_JOB\ |
Job directory for transfer operations |
\S7_JOB\S7OS\ |
Operating system / firmware file (if present) |
\LOG\ |
Data log files created by the DataLog instructions |
\Recipes\ |
Recipe files created by the Recipe instructions |
\UserFiles\ |
User-defined files written by FileWriteC / FileReadC |
\Webserver\ |
Custom web server HTML and JS files |
Use Cases
- Field service without a PG/PC. A technician carries a pre-loaded card, not a laptop, and updates a fleet of identical machines.
- Mass deployment. One card programs 50 identical machines during commissioning.
-
Firmware update. The card can hold a firmware file (file extension
.upd) that the CPU applies during power-up if a newer firmware is detected. - Data extraction. Data logs, recipes, and user files can be copied from the CPU to the card for offline analysis.
Project Migration and Version Compatibility
If the backup must be loaded into a TIA Portal version different from the source CPU firmware supports, the project requires migration. The TIA Portal migration rules are summarized below.
| Source Project | Target TIA Portal | Migration Required | Outcome |
|---|---|---|---|
| V13 (FW V3) | V13 SP1 / V13 SP2 | No (same major version) | Direct open |
| V13 (FW V3) | V14 / V14 SP1 | Yes (forward) | Successful, hints shown |
| V13 (FW V3) | V15 / V15.1 / V16 | Yes (forward) | Successful with warnings |
| V14 (FW V4.2) | V13 SP2 | Yes (backward, limited) | Refused if features are missing |
| V13 SP2 (FW V3) | V13 (base) | Yes (backward) | Refused if FW V3 instructions are used |
To migrate: open the project in the target TIA Portal, follow the migration wizard that appears automatically. The wizard reports any unsupported features (e.g., new instructions introduced in V14 SP1 such as PEEK_BOOL variants, or new motion control blocks). Resolve or accept the warnings before saving. The migrated project should be compiled with Project > Compile > Software (rebuild all) and downloaded to a test PLC before being deployed to production.
Verification: Confirm a Successful Backup
-
Method 1 (Upload to PG/PC). Open the saved
.ap13file. Verify the program blocks, hardware configuration, and PLC tags are present. Compare the block count to the source CPU under Online & Diagnostics > Diagnostics > Device Information > Block Counters. Compile the project: Project > Compile > Software (rebuild all). The status bar must show "Compile finished without errors". -
Method 2 (Backup from online device). Open the
.s7pbkpfile in TIA Portal: Project > Retrieve. The wizard extracts the archive and displays the project. Compare block count and DB initial values to the running CPU. As a final verification, restore the backup to a second CPU of the same order number and confirm the second CPU starts in the expected state. -
Method 3 (Memory card). Insert the card into a card reader attached to the PG/PC. The card appears as a removable drive. Verify the file
SIMATIC.S7Sand the directoryS7_JOBare present. The file size ofSIMATIC.S7Sreflects the program size. A 200 KB program produces a SIMATIC.S7S of approximately 200–300 KB.
Troubleshooting Matrix
| Symptom | Likely Cause | Action |
|---|---|---|
| "Download backup" grayed out | Function not supported for S7-1200 (architectural) | Use one of the three documented methods |
| "Backup from online device" grayed out | TIA Portal version mismatch (e.g., V13 base on FW V3) | Update to V13 SP2 or V14; install matching HSP |
| Upload to PG/PC produces empty blocks | Know-how protection active | Provide the protection password or contact machine builder |
| CPU not in accessible devices list | IP/subnet mismatch, firewall, wrong network interface | Set PG/PC interface to the same subnet, disable Windows Firewall for the network profile, ping the CPU |
| Restore fails with "Order number mismatch" | Backup file is for a different CPU model | Generate a new backup from the correct CPU or update the project hardware |
| MAINT LED solid after card copy, RUN does not start | Program on card has different firmware | Check SIMATIC.S7S header; update firmware or program accordingly |
| Online connection drops during backup | Network instability, CPU in heavy cycle | Reduce cycle load, switch to a direct Ethernet cable, retry |
| Backup file is unexpectedly small (< 10 KB) | CPU in error state, blocks not loaded to flash | Perform a STOP→RUN cycle, then re-backup |
| SD card is not recognized | Third-party SD card, corrupted file system | Use genuine SIMATIC SMC; reformat with the CPU |
| Online connection succeeds but blocks are not visible | CPU has no user program (empty flash) | Check CPU diagnostic buffer for download errors |
Field-Proven Tips and Edge Cases
- Backing up a password-protected CPU. The CPU allows backup with the configured read access password ("Read access" protection level in Siemens terminology), but the protected blocks in the backup are encrypted. Store the password with the backup file; otherwise the restore is useless when no CPU-side copy exists.
- Backing up while the process is running. All three methods work with the CPU in RUN. The "Upload to PG/PC" captures a snapshot; the process data in the snapshot is not the current values but the values at the time of block fetch (initial values for DBs).
- Backing up a CPU with active OPC UA server. The server security certificates are not included in the backup. Re-import the certificates after a restore. The certificates live in the CPU's certificate store, which is separate from the load memory.
-
Comparing two backups. Open the first
.s7pbkpin TIA Portal, save the project. Open the second backup, save as a different file. Use a folder-diff tool (e.g., WinMerge) on the extractedProgram blocksdirectory to identify which blocks changed between the two snapshots. - Time zone in backups. The CPU stores the time in UTC internally. The backup file includes the local time zone offset. When restoring to a CPU in a different time zone, the wall-clock time displays in the local zone without conversion errors.
- Backup before firmware update. Always perform a backup before applying a firmware update. The firmware update process is destructive of the program on some CPU versions; the backup is the only recovery path.
- Backup of a CPU with active forcing. Forced I/O points are not part of the program; they are stored in the CPU's force table. The force table is not included in any backup method. Re-apply the force table manually after a restore.
Windows 10 Engineering Station Considerations
The user reports TIA Portal V13 on Windows 10. Several Windows 10 behaviors affect S7-1200 communication, backup, and project integrity:
- Network profile. Windows 10 disables network discovery by default on public networks. Set the network profile to Private in Settings > Network & Internet > Status > Network status. The CPU responds to PROFINET discovery only on private profiles.
- Windows Backup of the engineering station. Use the built-in Windows Backup to protect the engineering station itself (TIA Portal project files, license keys, custom libraries, TIA Portal Help database). See the Microsoft Windows Backup documentation for the procedure. This is a separate concern from PLC backup, but both are required for a complete recovery strategy.
-
Firewall rules. Windows Defender Firewall blocks ISO-on-TCP (port 102) and PROFINET (UDP 34964) by default. Add inbound rules for
Siemens.Automation.Portal.exeandS7oiehsx64.exe(the TIA Portal communication service). Without these rules, the CPU will not appear in the accessible devices list. - Power management. USB-attached CP 5711 / PC adapters may be suspended by Windows 10 USB selective suspend. Disable in Device Manager > USB Root Hub > Power Management > Allow the computer to turn off this device to save power.
-
Antivirus exclusions. Exclude the TIA Portal installation directory (
%ProgramFiles%\Siemens\Automation\) and the project directory from real-time scanning. Several antivirus products quarantine.s7pbkpfiles as encrypted archives, breaking backup workflows. - OneDrive / cloud sync. Do not store TIA Portal project files in OneDrive, Dropbox, or any cloud-synced folder. The sync client can write a partial file mid-save, corrupting the project. Use a local or mapped network drive.
FAQ
Why is the "Download backup" item grayed out in the Online menu of TIA Portal V13 when I am connected to an S7-1200?
The "Online Backup" function applies only to S7-300, S7-400 with Flash memory card, ET 200S, and ET 200Pro. The S7-1200 uses three alternative backup workflows: Online > Upload to PG/PC, Online > Backup from online device, and program copy to a SIMATIC memory card. The gray menu is the documented, expected state for S7-1200; it is not a defect.
Which TIA Portal version is required to use "Backup from online device" on an S7-1200 FW V3?
Use TIA Portal V13 SP1 Update 4 or later, or V13 SP2, or any V14+ version. The TIA Portal V13 base release does not support S7-1200 FW V3. Verify the version in Help > About and confirm the matching Hardware Support Package is installed under Options > Support Packages.
Can I back up an S7-1200 CPU without a TIA Portal project file?
Yes. Use Online > Accessible Devices to reach the CPU, then Upload to PG/PC to create a new TIA Portal project from the online blocks, or Backup from online device to create a .s7pbkp archive. The SIMATIC memory card path is the only field-service option that does not require a PG/PC.
What is the difference between "Upload to PG/PC" and "Backup from online device"?
Upload to PG/PC produces an editable .ap13 TIA Portal project that can be modified and re-downloaded. Backup from online device produces a .s7pbkp archive that captures blocks, hardware configuration, and CPU properties; it is restored with Online > Restore from online device backup as a unit. Use Upload when the source project is lost; use Backup when a service snapshot is required.
Will backing up a CPU with know-how protection include the protected block code?
No. Know-how-protected blocks are encrypted in the CPU load memory. The backup file contains the encrypted form. The engineer must supply the protection password to decrypt and view the code; without the password, the protected blocks upload as placeholders labeled "Block is protected".
What is the difference between a SIMATIC memory card and a regular SD card?
SIMATIC memory cards (order numbers 6ES7954-8*) are qualified for industrial temperature range (-25 °C to +70 °C), have a controlled write-cycle profile, and contain a proprietary FAT32 layout with the file SIMATIC.S7S. Consumer SD cards from Sandisk, Samsung, etc., are not recognized by S7-1200 CPUs and trigger MAINT LED errors. Always use genuine SIMATIC memory cards.