S7-300/400 CFC Backup: Upload vs PG Project Recovery Guide

David Krause15 min read
S7-300SiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview: Why S7 CFC Backups Behave Differently from Standard Projects

A recurring source of confusion on Siemens service jobs is the difference between backing up a project stored on the PG/PC and uploading the program from the CPU. The two operations produce very different project trees, and when a PCS7 or CFC program is involved the difference is dramatic: the CFC, SCL, and Graph source files simply do not exist on the CPU at all, so they cannot be retrieved by an upload. Understanding this distinction is the foundation of every reliable S7-300/400 backup strategy, especially for plants that must survive an HMI failure, a CPU swap, or a complete loss of the engineering station.

This reference covers the complete backup workflow for S7-300/400 stations that contain CFC charts (typical for PCS7 V6/V7/V8), standalone SIMATIC Manager projects with CFC option, and the connected HMI panels (WinCC Flexible, WinCC, or TIA Portal panels). It documents the storage model, the upload mechanics, the PCS7 "Upload Station to PG" routine, and the ProSave-based HMI image transfer that allows a replacement panel to be re-flashed with the original configuration.

The Storage Model: What the CPU Actually Holds

An S7-300 or S7-400 CPU stores executable machine code in its load memory. The unit of storage is the block: OB, FB, FC, DB, SDB, SFB, SFC. These blocks contain the compiled result of every language that SIMATIC Manager can edit - STL, LAD, FBD, SCL, Graph, and CFC - but the original graphical representation, the chart layout, the interconnections, and the run-time sequence are reconstructed at compile time and are not part of the on-line image.

Project Item Lives in PG Project Lives in CPU Survives Upload?
OB / FB / FC / DB compiled code Yes (sources/blocks) Yes (load memory) Yes
STL source Yes No No
LAD / FBD source Yes No No
SCL source Yes No No
Graph source (step sequences) Yes No No
CFC chart (continuous function chart) Yes No - compiled to FCs and DBs No
SFB / SFC (system blocks) Reference only Yes (firmware-resident) Reference only
Hardware configuration (HW Config) Yes System data blocks (SDB) Partially (SDB only)
Symbol table Yes No (downloaded separately) No
Connections / NetPro Yes SDBs No (graph only)
HMI project (.hmi, .fwx, .arj) Yes (on HMI or PG) No No

The CPU never stores the chart. The CFC editor generates an FC that contains the compiled run sequence, plus one or more instance DBs per chart, and a number of shared DBs that the runtime system uses. When you change a CFC chart, edit a run-time group, or add a new block reference, the entire project must be recompiled and the new FC/DB set must be downloaded. There is no incremental CFC download - this is by design and is part of the deterministic run model that PCS7 depends on.

Upload vs. Backup: The Definitive Distinction

Backup means archiving the SIMATIC Manager project as it sits on the engineering station (the PG/PC). The project includes S7 programs, CFC charts, SCL sources, the HW Config, NetPro, the symbol table, and (in PCS7) the WinCC archive. This is a 1:1 copy of the source.

Upload (PG > CPU > PG) is a diagnostic and service function. It pulls the current executable blocks back from the load memory of the CPU. The on-line blocks are written into a project of type Upload Station with one S7 program that contains only the blocks folder.

Rule: An uploaded project is never a substitute for the PG backup. An upload lets you re-download a running system to a replacement CPU, but it does not restore the CFC chart, the SCL source, the symbol table, or the HW Config. The uploaded program is a "black box" of compiled code that you can execute but not edit in CFC/SCL/Graph.

The decision path for a service engineer is therefore:

  1. Can the original PG project be recovered (file share, archive, source control)? Use it. This is the only path that preserves the CFC/SCL/Graph source.
  2. If the PG project is lost, perform Upload Station to PG (PCS7) or PLC > Upload Station to PG (SIMATIC Manager). You will recover the FB/FC/DB set, the SDBs (system data), and - in PCS7 V8 with the appropriate option - the HW Config and symbol table from the SDBs. You will not recover the CFC charts.
  3. For an HMI failure, you need the original WinCC Flexible project or the runtime image. If only the panel survives, use ProSave to back it up before the panel is decommissioned.

How CFC Compilation Generates the FC Set

When the engineer selects Charts > Compile > Charts as Program (or the equivalent menu in the CFC editor), the compiler walks every chart in run-time order, resolves the block I/O references against the master data library, inserts the run-time sequence number into each block header, and emits a single FC per chart plus its instance DB. Charts that share a run-time group are placed inside the same FC wrapper when the option "Compile charts of a runtime group into one FC" is enabled (default in PCS7 V7/V8).

Source Item in CFC Generated Block(s) Block Number Range
Each chart FC (compiled chart) Configurable, default 1-999
Each chart instance DB (instance data) Sequential from chart range
Shared runtime DB DB (sequence, OB lists) 1-30 reserved
Type/instance of user FBs FB + DB per instance User-defined
Sequencer / SFC if used SFC + SFB references From SFC library

A diagnostic clue that confirms a station was originally built with CFC: the blocks folder contains a large number of FCs that are not visible in the program editor of the upload project, with the comment "// generated by CFC" embedded in the STL view. These FCs are also the reason that an uploaded program does work after a download - the compiled chart is functionally complete - but is impossible to maintain without the original chart.

PCS7 Upload Station to PG Procedure

In PCS7 V7.x and V8.x the Upload Station to PG function is a dedicated menu item in the component view of the plant. It performs a fuller recovery than the basic SIMATIC Manager upload because PCS7 knows the AS station as a complete object.

  1. Open the PCS7 project shell on the PG, then in the component view right-click the AS station (e.g. AS01) and choose PLC > Upload Station to PG.
  2. Select the target CPU online interface (MPI/PROFIBUS or TCP/IP via the IE interface of the CPU, for example 192.168.0.10 rack 0 slot 2 for an S7-400).
  3. The wizard connects, reads the system data, performs a block upload, and reads the diagnostic buffers. The on-line HW Config is reconstructed from the SDBs, and the symbol table is re-assembled from the SDBs (PCS7 V8.0 SP1 and later).
  4. The result is a new station object in the project tree with the same name and a suffix _UPL. It contains the S7 program with all blocks, the HW Config, and the symbol table - but no CFC/SCL/Graph source files.
In PCS7 V7.0 the symbol table is not reconstructed. The "Unknown" symbols in the uploaded blocks must be re-typed manually or re-imported from a CSV export. PCS7 V8.2 and later extend the upload to include the connection configuration (NetPro) so that S7 connections are preserved.

After upload, the program can be edited only in STL/LAD/FBD. The CFC charts must be re-engineered from the I/O list, the WinCC Explorer picture references, and the run-time sequence numbers that can be read out of the FC headers. This is non-trivial and is the reason PCS7 sites invest in disciplined PG backups.

SIMATIC Manager Backup Procedure (S7-300/400, No PCS7)

For a standard S7-300/400 station that uses CFC as an add-on (PCS7 option package or the standalone CFC editor), the workflow is identical to a non-CFC project for the backup, and the CFC-specific concern is only the chart directory.

  1. Open SIMATIC Manager and the project.
  2. Select the project root and choose File > Archive. Choose a multi-part archive (a typical S7-300/400 + CFC project is 5-30 MB; PCS7 V8 projects are 50-500 MB). Siemens recommends the standard archive tool that ships with SIMATIC Manager so that the .zip and ARJ formats are supported without third-party tools.
  3. Verify the archive by restoring it to a temporary directory. Open the restored project and confirm the S7 program, the CFC charts container, the symbol table, and the HW Config are present.
  4. Store the archive on a write-protected medium, in source control, and on a second site. For plants under IEC 61508 / IEC 61511, retain the archive for the lifetime of the SIS application.

A common pitfall is that the CFC charts are stored in a hidden subdirectory under the S7 program. If the backup tool filters by extension (e.g. *.s7p only), the chart files can be silently dropped. Use a directory-level backup or a tool that respects the SIMATIC Manager .s7l link files.

WinCC Flexible / WinCC HMI Backup with ProSave

An HMI panel - whether a SIMATIC Panel (OP/TP/MP), a Comfort/ KTP panel, or a WinCC Runtime station - holds its project in a compressed image that includes the compiled screens, the tag database, the alarm logs, and (for some panels) the recipe data. The image is platform-specific and cannot be reconstructed from a PLC upload.

Siemens ProSave is the canonical tool for moving images in and out of a panel. It runs on the engineering station and communicates with the panel over Ethernet, PROFIBUS, MPI, or USB depending on the panel series.

  1. Install ProSave from the WinCC Flexible / TIA Portal installation media. Confirm the version matches the panel firmware (e.g. ProSave V13 SP2 for panels running WinCC Flexible 2008 SP5). A version mismatch is a frequent cause of "incompatible image" errors.
  2. Connect the PG to the panel using the panel's service port. For Ethernet panels, set the PG to a fixed address in the same subnet (e.g. 192.168.1.10/24 if the panel is 192.168.1.20) and disable any active firewall rule that blocks ProSave (TCP 2308 / UDP 137/138/139 depending on service).
  3. Launch ProSave, choose Backup, and select the connection type. For Ethernet panels, the default is "Ethernet" with the panel's IP and a transfer mode of "PN/IE".
  4. Choose the destination directory and the image name (typically the panel order number, e.g. TP1200_Comfort_6AV2-124-1MC01-0AX0.psb). The .psb file is the encrypted backup image.
  5. Run the backup. Time required is 1-15 minutes depending on the panel size (TP177 mono takes ~30 s; TP1200 Comfort takes 3-5 min). ProSave prompts for the panel transfer password if one is set in the project.

To restore the image to a replacement panel, the procedure is symmetric: Restore in ProSave, select the .psb, and choose the target panel. The replacement must be the same part number, or a successor explicitly listed in the panel migration matrix. The migration matrix is published in the WinCC Flexible / TIA Portal device manual and is the only document that authorises a panel swap.

Critical: ProSave cannot recover a project that is not present on the panel. If both the panel and the PG project are lost, the configuration is gone. Always store the original WinCC Flexible source (*.hmi project) on the engineering station and in a versioned archive, even when a ProSave backup is also taken. The ProSave image is a binary; the WinCC Flexible source is the editable project.

WinCC Runtime PC Backup (PCS7 OS)

A WinCC Runtime station (OS server / OS client in PCS7) holds its configuration in WinCCExplorer.cfg plus the project directory under C:\Program Files\Siemens\Automation\WinCC\<ProjectName>\. The directory contains pictures, tag database, alarm logging, archive databases, and (for redundancy) the partner server configuration. PCS7 V8 and later support the menu OS Project Editor > Backup, but the canonical method is a directory copy of the entire project tree while the WinCC service is stopped.

  1. Stop the WinCC Runtime: net stop "CCArchiveMgr" /y followed by net stop "WinCC_<ProjectName>" /y. Wait for the SQL archive to release its .LDF lock.
  2. Copy the project directory to a backup share. The complete directory is required - partial copies break the SQL archive integrity.
  3. Restart the runtime: net start "WinCC_<ProjectName>" and verify the runtime comes up green in WinCC Explorer.

For a PCS7 V8 plant, the OS backup is part of the PCS7 Maintenance Station and can be scheduled with the SIMATIC PCS7 Backup/Restore tool that the Maintenance Station installs.

Restoring an HMI When Only the Panel Survives

The ProSave backup is the only path to recover an HMI image when the engineering project is lost. The procedure is:

  1. Connect a PG to the panel over its service interface.
  2. Open ProSave, choose Restore, browse to the .psb file taken earlier from the failing panel.
  3. Select the target panel. The panel's order number and firmware must match the image - if not, ProSave aborts with error 0x8004xxxx. The WinCC Flexible / TIA Portal knowledge base lists the exact hex codes by panel family.
  4. ProSave writes the image and reboots the panel. Allow 2-10 minutes. Do not power-cycle the panel during restore; an interrupted restore can leave the panel in a "recovery" state that requires a factory reset via the service menu.

If the failing panel is no longer accessible but a ProSave backup of the same panel is on file, restore directly to the replacement panel. The WinCC Flexible transfer must use the same ProSave version that wrote the backup, otherwise the encrypted image cannot be decrypted.

Complete Plant Backup Strategy

A reliable S7-300/400 + CFC + HMI backup combines PG archives, ProSave images, and the PCS7 Upload Station to PG. The recommended cadence is:

Item Method Frequency Retention Storage
SIMATIC Manager project File > Archive Every approved change Plant life + 5 years Network share + off-site
HW Config diff Compare > Online/Offline Every approved change Plant life Source control
HMI ProSave image ProSave > Backup Every approved change Plant life + 5 years Network share + panel SD card (encrypted)
OS project directory Directory copy with WinCC stopped Weekly or per change 1 year on site, indefinite off-site Network share
PCS7 Upload Station to PG Per PCS7 wizard Quarterly drill Drill only Local PG
PCS7 Maintenance backup PCS7 Backup/Restore tool Weekly 1 year Network share

The quarterly drill is essential: a backup that has never been restored is not a backup. Pick a non-critical weekend, perform Upload Station to PG on a test station, and confirm that the recovered program can be downloaded to a spare CPU and come up in RUN. This is also the moment to verify that the on-line program matches the PG project - a mismatch indicates a change was made on the plant that was never archived.

Verification: Confirming a Successful Backup

  1. Open the restored project in SIMATIC Manager and check the project tree contains: S7 program with Blocks + Sources, CFC container, HW Config, NetPro, Symbol table.
  2. Compile the CFC charts: Charts > Compile > Charts as Program. A clean compile (no warnings) confirms the source is consistent.
  3. Compare the compiled FC/DB set against the FC/DB set on the running CPU: PLC > Compare. A clean compare confirms the backup reflects the current operating program.
  4. For the HMI, restore the ProSave image to a test panel of the same order number. Boot the panel, navigate the menus, and confirm all screens and recipes load. A passing test panel validates the ProSave image.
  5. Document the backup label, archive hash (SHA-256), and the engineering responsible. Store this in the plant asset register.

Troubleshooting Matrix

Symptom Likely Cause Action
Upload Station to PG completes, but the project has no CFC folder Expected behaviour - the CPU does not store CFC source Recover CFC source from PG archive or source control. The uploaded program is still executable
ProSave returns error 0x80040001 ("Image incompatible") ProSave version does not match panel firmware Install the matching ProSave version from the WinCC Flexible / TIA Portal media
WinCC Flexible project cannot open, "Project corrupted" Archive was created with a different SIMATIC Manager / TIA Portal version Re-archive with the version that wrote the project, or use a project converter
Upload Station to PG runs forever, never finishes Inconsistent SDB set on the CPU (e.g. after a partial download) Perform a full download to the CPU to reset the SDBs, then retry the upload
HMI panel boots with "Transfer failed" after restore Panel transfer mode not set, or ProSave service port blocked Enable transfer mode in the panel control panel (Settings > Transfer) and check PG firewall
CFC compile fails with "Block <FBxxx> not found" Master data library not installed or wrong version Install the PCS7 library matching the plant version (e.g. PCS7 V8.2 Library V8.2)
ProSave image restore succeeds, panel shows wrong project Multiple .psb files in the same directory, wrong file selected Rename the .psb files to include the panel order number and date

FAQ

Why does my uploaded S7-300/400 program not contain the CFC folder?

The CPU stores compiled FC/FB/DB blocks, not the CFC chart source. The chart is compiled to one or more FCs plus instance DBs, which is what the upload returns. The CFC source is only present in the PG project on the engineering station. To recover the chart you must restore the original SIMATIC Manager project archive, not the upload.

Can I edit a CFC chart on a program that was uploaded from the CPU?

No. The upload delivers compiled FC/DB blocks only. The CFC editor requires the original chart. The uploaded program can be downloaded to a replacement CPU and will run, but the chart itself must be re-engineered or restored from the PG backup.

How do I get a complete backup of a PCS7 OS (WinCC Runtime) station?

Stop the WinCC service, copy the entire WinCC project directory (default C:\Program Files\Siemens\Automation\WinCC\<Project>\) to a backup share, then restart the runtime. In PCS7 V8 and later you can also use the Maintenance Station's PCS7 Backup/Restore tool for scheduled OS backups.

What is the difference between a ProSave backup and a WinCC Flexible project archive?

A ProSave backup is an encrypted runtime image of the panel. It restores the panel to its current operating state but cannot be edited. A WinCC Flexible project archive is the editable source project (screens, tags, alarms). Always keep both: the ProSave image lets you recover a failed panel quickly, and the WinCC Flexible source lets you make future changes.

Can I restore a ProSave image to a different panel order number?

Only if the new panel is an explicit successor in the WinCC Flexible / TIA Portal panel migration matrix. ProSave validates the part number during restore and aborts with an incompatible-image error otherwise. The migration matrix is in the device manual for the target panel family.

How often should I run the PCS7 Upload Station to PG drill?

Quarterly is standard for process plants. The drill confirms that the engineering PC, the network path, and the CPU's SDB set are healthy and that the recovered program can be re-downloaded to a spare CPU. Treat the drill as a recovery exercise: a backup that has never been restored is not a working backup.

Back to blog