Overview: Why S7 CFC Backups Behave Differently from Standard Projects
A recurring source of confusion on Siemens service jobs is the difference between backing up a project stored on the PG/PC and uploading the program from the CPU. The two operations produce very different project trees, and when a PCS7 or CFC program is involved the difference is dramatic: the CFC, SCL, and Graph source files simply do not exist on the CPU at all, so they cannot be retrieved by an upload. Understanding this distinction is the foundation of every reliable S7-300/400 backup strategy, especially for plants that must survive an HMI failure, a CPU swap, or a complete loss of the engineering station.
This reference covers the complete backup workflow for S7-300/400 stations that contain CFC charts (typical for PCS7 V6/V7/V8), standalone SIMATIC Manager projects with CFC option, and the connected HMI panels (WinCC Flexible, WinCC, or TIA Portal panels). It documents the storage model, the upload mechanics, the PCS7 "Upload Station to PG" routine, and the ProSave-based HMI image transfer that allows a replacement panel to be re-flashed with the original configuration.
The Storage Model: What the CPU Actually Holds
An S7-300 or S7-400 CPU stores executable machine code in its load memory. The unit of storage is the block: OB, FB, FC, DB, SDB, SFB, SFC. These blocks contain the compiled result of every language that SIMATIC Manager can edit - STL, LAD, FBD, SCL, Graph, and CFC - but the original graphical representation, the chart layout, the interconnections, and the run-time sequence are reconstructed at compile time and are not part of the on-line image.
| Project Item | Lives in PG Project | Lives in CPU | Survives Upload? |
|---|---|---|---|
| OB / FB / FC / DB compiled code | Yes (sources/blocks) | Yes (load memory) | Yes |
| STL source | Yes | No | No |
| LAD / FBD source | Yes | No | No |
| SCL source | Yes | No | No |
| Graph source (step sequences) | Yes | No | No |
| CFC chart (continuous function chart) | Yes | No - compiled to FCs and DBs | No |
| SFB / SFC (system blocks) | Reference only | Yes (firmware-resident) | Reference only |
| Hardware configuration (HW Config) | Yes | System data blocks (SDB) | Partially (SDB only) |
| Symbol table | Yes | No (downloaded separately) | No |
| Connections / NetPro | Yes | SDBs | No (graph only) |
| HMI project (.hmi, .fwx, .arj) | Yes (on HMI or PG) | No | No |
The CPU never stores the chart. The CFC editor generates an FC that contains the compiled run sequence, plus one or more instance DBs per chart, and a number of shared DBs that the runtime system uses. When you change a CFC chart, edit a run-time group, or add a new block reference, the entire project must be recompiled and the new FC/DB set must be downloaded. There is no incremental CFC download - this is by design and is part of the deterministic run model that PCS7 depends on.
Upload vs. Backup: The Definitive Distinction
Backup means archiving the SIMATIC Manager project as it sits on the engineering station (the PG/PC). The project includes S7 programs, CFC charts, SCL sources, the HW Config, NetPro, the symbol table, and (in PCS7) the WinCC archive. This is a 1:1 copy of the source.
Upload (PG > CPU > PG) is a diagnostic and service function. It pulls the current executable blocks back from the load memory of the CPU. The on-line blocks are written into a project of type Upload Station with one S7 program that contains only the blocks folder.
The decision path for a service engineer is therefore:
- Can the original PG project be recovered (file share, archive, source control)? Use it. This is the only path that preserves the CFC/SCL/Graph source.
- If the PG project is lost, perform Upload Station to PG (PCS7) or PLC > Upload Station to PG (SIMATIC Manager). You will recover the FB/FC/DB set, the SDBs (system data), and - in PCS7 V8 with the appropriate option - the HW Config and symbol table from the SDBs. You will not recover the CFC charts.
- For an HMI failure, you need the original WinCC Flexible project or the runtime image. If only the panel survives, use ProSave to back it up before the panel is decommissioned.
How CFC Compilation Generates the FC Set
When the engineer selects Charts > Compile > Charts as Program (or the equivalent menu in the CFC editor), the compiler walks every chart in run-time order, resolves the block I/O references against the master data library, inserts the run-time sequence number into each block header, and emits a single FC per chart plus its instance DB. Charts that share a run-time group are placed inside the same FC wrapper when the option "Compile charts of a runtime group into one FC" is enabled (default in PCS7 V7/V8).
| Source Item in CFC | Generated Block(s) | Block Number Range |
|---|---|---|
| Each chart | FC (compiled chart) | Configurable, default 1-999 |
| Each chart instance | DB (instance data) | Sequential from chart range |
| Shared runtime DB | DB (sequence, OB lists) | 1-30 reserved |
| Type/instance of user FBs | FB + DB per instance | User-defined |
| Sequencer / SFC if used | SFC + SFB references | From SFC library |
A diagnostic clue that confirms a station was originally built with CFC: the blocks folder contains a large number of FCs that are not visible in the program editor of the upload project, with the comment "// generated by CFC" embedded in the STL view. These FCs are also the reason that an uploaded program does work after a download - the compiled chart is functionally complete - but is impossible to maintain without the original chart.
PCS7 Upload Station to PG Procedure
In PCS7 V7.x and V8.x the Upload Station to PG function is a dedicated menu item in the component view of the plant. It performs a fuller recovery than the basic SIMATIC Manager upload because PCS7 knows the AS station as a complete object.
- Open the PCS7 project shell on the PG, then in the component view right-click the AS station (e.g.
AS01) and choose PLC > Upload Station to PG. - Select the target CPU online interface (MPI/PROFIBUS or TCP/IP via the IE interface of the CPU, for example
192.168.0.10rack 0 slot 2 for an S7-400). - The wizard connects, reads the system data, performs a block upload, and reads the diagnostic buffers. The on-line HW Config is reconstructed from the SDBs, and the symbol table is re-assembled from the SDBs (PCS7 V8.0 SP1 and later).
- The result is a new station object in the project tree with the same name and a suffix _UPL. It contains the S7 program with all blocks, the HW Config, and the symbol table - but no CFC/SCL/Graph source files.
After upload, the program can be edited only in STL/LAD/FBD. The CFC charts must be re-engineered from the I/O list, the WinCC Explorer picture references, and the run-time sequence numbers that can be read out of the FC headers. This is non-trivial and is the reason PCS7 sites invest in disciplined PG backups.
SIMATIC Manager Backup Procedure (S7-300/400, No PCS7)
For a standard S7-300/400 station that uses CFC as an add-on (PCS7 option package or the standalone CFC editor), the workflow is identical to a non-CFC project for the backup, and the CFC-specific concern is only the chart directory.
- Open SIMATIC Manager and the project.
- Select the project root and choose File > Archive. Choose a multi-part archive (a typical S7-300/400 + CFC project is 5-30 MB; PCS7 V8 projects are 50-500 MB). Siemens recommends the standard archive tool that ships with SIMATIC Manager so that the
.zipand ARJ formats are supported without third-party tools. - Verify the archive by restoring it to a temporary directory. Open the restored project and confirm the S7 program, the CFC charts container, the symbol table, and the HW Config are present.
- Store the archive on a write-protected medium, in source control, and on a second site. For plants under IEC 61508 / IEC 61511, retain the archive for the lifetime of the SIS application.
A common pitfall is that the CFC charts are stored in a hidden subdirectory under the S7 program. If the backup tool filters by extension (e.g. *.s7p only), the chart files can be silently dropped. Use a directory-level backup or a tool that respects the SIMATIC Manager .s7l link files.
WinCC Flexible / WinCC HMI Backup with ProSave
An HMI panel - whether a SIMATIC Panel (OP/TP/MP), a Comfort/ KTP panel, or a WinCC Runtime station - holds its project in a compressed image that includes the compiled screens, the tag database, the alarm logs, and (for some panels) the recipe data. The image is platform-specific and cannot be reconstructed from a PLC upload.
Siemens ProSave is the canonical tool for moving images in and out of a panel. It runs on the engineering station and communicates with the panel over Ethernet, PROFIBUS, MPI, or USB depending on the panel series.
- Install ProSave from the WinCC Flexible / TIA Portal installation media. Confirm the version matches the panel firmware (e.g. ProSave V13 SP2 for panels running WinCC Flexible 2008 SP5). A version mismatch is a frequent cause of "incompatible image" errors.
- Connect the PG to the panel using the panel's service port. For Ethernet panels, set the PG to a fixed address in the same subnet (e.g.
192.168.1.10/24if the panel is192.168.1.20) and disable any active firewall rule that blocks ProSave (TCP 2308 / UDP 137/138/139 depending on service). - Launch ProSave, choose Backup, and select the connection type. For Ethernet panels, the default is "Ethernet" with the panel's IP and a transfer mode of "PN/IE".
- Choose the destination directory and the image name (typically the panel order number, e.g.
TP1200_Comfort_6AV2-124-1MC01-0AX0.psb). The.psbfile is the encrypted backup image. - Run the backup. Time required is 1-15 minutes depending on the panel size (TP177 mono takes ~30 s; TP1200 Comfort takes 3-5 min). ProSave prompts for the panel transfer password if one is set in the project.
To restore the image to a replacement panel, the procedure is symmetric: Restore in ProSave, select the .psb, and choose the target panel. The replacement must be the same part number, or a successor explicitly listed in the panel migration matrix. The migration matrix is published in the WinCC Flexible / TIA Portal device manual and is the only document that authorises a panel swap.
*.hmi project) on the engineering station and in a versioned archive, even when a ProSave backup is also taken. The ProSave image is a binary; the WinCC Flexible source is the editable project.
WinCC Runtime PC Backup (PCS7 OS)
A WinCC Runtime station (OS server / OS client in PCS7) holds its configuration in WinCCExplorer.cfg plus the project directory under C:\Program Files\Siemens\Automation\WinCC\<ProjectName>\. The directory contains pictures, tag database, alarm logging, archive databases, and (for redundancy) the partner server configuration. PCS7 V8 and later support the menu OS Project Editor > Backup, but the canonical method is a directory copy of the entire project tree while the WinCC service is stopped.
- Stop the WinCC Runtime:
net stop "CCArchiveMgr" /yfollowed bynet stop "WinCC_<ProjectName>" /y. Wait for the SQL archive to release its.LDFlock. - Copy the project directory to a backup share. The complete directory is required - partial copies break the SQL archive integrity.
- Restart the runtime:
net start "WinCC_<ProjectName>"and verify the runtime comes up green in WinCC Explorer.
For a PCS7 V8 plant, the OS backup is part of the PCS7 Maintenance Station and can be scheduled with the SIMATIC PCS7 Backup/Restore tool that the Maintenance Station installs.
Restoring an HMI When Only the Panel Survives
The ProSave backup is the only path to recover an HMI image when the engineering project is lost. The procedure is:
- Connect a PG to the panel over its service interface.
- Open ProSave, choose Restore, browse to the
.psbfile taken earlier from the failing panel. - Select the target panel. The panel's order number and firmware must match the image - if not, ProSave aborts with error 0x8004xxxx. The WinCC Flexible / TIA Portal knowledge base lists the exact hex codes by panel family.
- ProSave writes the image and reboots the panel. Allow 2-10 minutes. Do not power-cycle the panel during restore; an interrupted restore can leave the panel in a "recovery" state that requires a factory reset via the service menu.
If the failing panel is no longer accessible but a ProSave backup of the same panel is on file, restore directly to the replacement panel. The WinCC Flexible transfer must use the same ProSave version that wrote the backup, otherwise the encrypted image cannot be decrypted.
Complete Plant Backup Strategy
A reliable S7-300/400 + CFC + HMI backup combines PG archives, ProSave images, and the PCS7 Upload Station to PG. The recommended cadence is:
| Item | Method | Frequency | Retention | Storage |
|---|---|---|---|---|
| SIMATIC Manager project | File > Archive | Every approved change | Plant life + 5 years | Network share + off-site |
| HW Config diff | Compare > Online/Offline | Every approved change | Plant life | Source control |
| HMI ProSave image | ProSave > Backup | Every approved change | Plant life + 5 years | Network share + panel SD card (encrypted) |
| OS project directory | Directory copy with WinCC stopped | Weekly or per change | 1 year on site, indefinite off-site | Network share |
| PCS7 Upload Station to PG | Per PCS7 wizard | Quarterly drill | Drill only | Local PG |
| PCS7 Maintenance backup | PCS7 Backup/Restore tool | Weekly | 1 year | Network share |
The quarterly drill is essential: a backup that has never been restored is not a backup. Pick a non-critical weekend, perform Upload Station to PG on a test station, and confirm that the recovered program can be downloaded to a spare CPU and come up in RUN. This is also the moment to verify that the on-line program matches the PG project - a mismatch indicates a change was made on the plant that was never archived.
Verification: Confirming a Successful Backup
- Open the restored project in SIMATIC Manager and check the project tree contains: S7 program with Blocks + Sources, CFC container, HW Config, NetPro, Symbol table.
- Compile the CFC charts: Charts > Compile > Charts as Program. A clean compile (no warnings) confirms the source is consistent.
- Compare the compiled FC/DB set against the FC/DB set on the running CPU: PLC > Compare. A clean compare confirms the backup reflects the current operating program.
- For the HMI, restore the ProSave image to a test panel of the same order number. Boot the panel, navigate the menus, and confirm all screens and recipes load. A passing test panel validates the ProSave image.
- Document the backup label, archive hash (SHA-256), and the engineering responsible. Store this in the plant asset register.
Troubleshooting Matrix
| Symptom | Likely Cause | Action |
|---|---|---|
| Upload Station to PG completes, but the project has no CFC folder | Expected behaviour - the CPU does not store CFC source | Recover CFC source from PG archive or source control. The uploaded program is still executable |
| ProSave returns error 0x80040001 ("Image incompatible") | ProSave version does not match panel firmware | Install the matching ProSave version from the WinCC Flexible / TIA Portal media |
| WinCC Flexible project cannot open, "Project corrupted" | Archive was created with a different SIMATIC Manager / TIA Portal version | Re-archive with the version that wrote the project, or use a project converter |
| Upload Station to PG runs forever, never finishes | Inconsistent SDB set on the CPU (e.g. after a partial download) | Perform a full download to the CPU to reset the SDBs, then retry the upload |
| HMI panel boots with "Transfer failed" after restore | Panel transfer mode not set, or ProSave service port blocked | Enable transfer mode in the panel control panel (Settings > Transfer) and check PG firewall |
| CFC compile fails with "Block <FBxxx> not found" | Master data library not installed or wrong version | Install the PCS7 library matching the plant version (e.g. PCS7 V8.2 Library V8.2) |
| ProSave image restore succeeds, panel shows wrong project | Multiple .psb files in the same directory, wrong file selected |
Rename the .psb files to include the panel order number and date |
FAQ
Why does my uploaded S7-300/400 program not contain the CFC folder?
The CPU stores compiled FC/FB/DB blocks, not the CFC chart source. The chart is compiled to one or more FCs plus instance DBs, which is what the upload returns. The CFC source is only present in the PG project on the engineering station. To recover the chart you must restore the original SIMATIC Manager project archive, not the upload.
Can I edit a CFC chart on a program that was uploaded from the CPU?
No. The upload delivers compiled FC/DB blocks only. The CFC editor requires the original chart. The uploaded program can be downloaded to a replacement CPU and will run, but the chart itself must be re-engineered or restored from the PG backup.
How do I get a complete backup of a PCS7 OS (WinCC Runtime) station?
Stop the WinCC service, copy the entire WinCC project directory (default C:\Program Files\Siemens\Automation\WinCC\<Project>\) to a backup share, then restart the runtime. In PCS7 V8 and later you can also use the Maintenance Station's PCS7 Backup/Restore tool for scheduled OS backups.
What is the difference between a ProSave backup and a WinCC Flexible project archive?
A ProSave backup is an encrypted runtime image of the panel. It restores the panel to its current operating state but cannot be edited. A WinCC Flexible project archive is the editable source project (screens, tags, alarms). Always keep both: the ProSave image lets you recover a failed panel quickly, and the WinCC Flexible source lets you make future changes.
Can I restore a ProSave image to a different panel order number?
Only if the new panel is an explicit successor in the WinCC Flexible / TIA Portal panel migration matrix. ProSave validates the part number during restore and aborts with an incompatible-image error otherwise. The migration matrix is in the device manual for the target panel family.
How often should I run the PCS7 Upload Station to PG drill?
Quarterly is standard for process plants. The drill confirms that the engineering PC, the network path, and the CPU's SDB set are healthy and that the recovered program can be re-downloaded to a spare CPU. Treat the drill as a recovery exercise: a backup that has never been restored is not a working backup.