S7-400 Memory Verification: Comparing Work RAM vs FEPROM Storage

David Krause13 min read
S7-400SiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview of S7-400 Memory Architecture

The Siemens SIMATIC S7-400 separates program and data storage into three distinct memory regions: load memory, work memory, and system memory. Understanding the role of each region is essential before any comparison between working memory and EPROM/Flash storage is attempted, because each region uses different physical media, has different endurance characteristics, and exposes different read/write paths to STEP 7 / TIA Portal.

Memory Region Physical Media Volatility Function
Load Memory Integrated RAM + FEPROM or MMC Non-volatile (card portion) Stores the full user program, configuration, and connection data for cold restart
Work Memory (Code + Data) Integrated SRAM (battery-backed) Volatile without battery Active execution area: holds the compiled logic blocks currently running
System Memory Integrated SRAM Volatile without battery Holds process image (I/O), bit memory (M), timers (T), counters (C), and stack

The S7-400 line splits across two hardware generations. The classic CPU 412, 414, 416, and 417 series accept 5 V FEPROM (Flash EPROM) memory cards with capacities from 64 KB up to 64 MB, depending on the order number. The newer CPU 41x PN/DP generation (for example 6ES7414-3EM07-0AB0) replaced FEPROM with Micro Memory Cards (MMC), which are Flash-based, support up to 8 GB in later firmware versions, and behave differently under STEP 7. The verification workflow must respect which card type is installed.

Batteries are mandatory for the work memory retention. A depleted backup battery on an FEPROM-equipped CPU causes the work memory (and the RAM portion of load memory) to lose its contents on power-down, while the FEPROM card retains the program. MMC-equipped CPUs do not require a battery for the program, only for the clock and certain retentive data.

Memory Types: RAM, FEPROM, and MMC

Each storage medium has a characteristic speed, write endurance, and access path. The table below summarizes the electrical and operational properties an engineer must consider when designing a verification procedure.

Property RAM (SRAM) FEPROM MMC (Flash)
Non-volatile No (battery-backed) Yes Yes
Read speed Fastest (direct CPU access) Moderate (page-buffer transfer to RAM) Moderate (page-buffer transfer to RAM)
Write endurance Unlimited (write cycles) Limited (typical 100k-1M block erase cycles per sector) Limited (typical 100k-1M block erase cycles per sector)
Program update path Direct online download Must transfer through RAM and "Download to Memory Card" Download to card via STEP 7 / TIA Portal
Encryption support N/A No Yes (KNOW_HOW_PROTECT, block privacy, anti-read) on supported CPUs
Suitable for archive master No (volatile) Yes (older 41x series) Yes (current 41x PN/DP)

FEPROM and MMC both rely on floating-gate transistor storage; electrically erased and programmed in blocks rather than byte-by-byte. This is why neither card can host a hot-swap patch in the way RAM can: a complete block must be transferred, and the CPU internally copies it into work memory before the logic is re-evaluated.

Block Storage Locations and Identification

Within STEP 7 (SIMATIC Manager) and TIA Portal, every online block exposes a "storage location" property that resolves to one of four possible values: Work memory (RAM), Load memory (RAM), Load memory (FEPROM), or Load memory (MMC). Engineers often confuse the RAM inside the load-memory region with the FEPROM card itself; they are two distinct partitions. The flow below shows the resolution order STEP 7 follows when locating a block.

  1. CPU receives a request for block (for example OB1).
  2. Work memory is searched first. If the block exists with a valid runtime signature, the CPU executes it from RAM.
  3. If the block is not in work memory, the CPU copies the block from the load-memory portion of the FEPROM/MMC into work memory and marks the source as "passive load-memory image".
  4. Block-container metadata in the online view reflects whether the live copy lives in RAM or only in non-volatile storage.

This dual-storage behaviour is the root cause of the comparison question: at any moment, work memory may contain a newer revision than the FEPROM/MMC, even though both originated from the same download. The engineer's goal is therefore to compare the live logic (work memory) with the archived version (FEPROM/MMC) before relying on the card for backup.

Why Direct Online Comparison Is Limited

STEP 7 and TIA Portal do not provide a single "Compare Work RAM vs FEPROM" command. The reason is technical: blocks in work memory and blocks on the FEPROM/MMC share identical block headers and signatures after a normal download, so a byte-level diff returns no meaningful difference. The actual divergence shows up only in three cases:

  • An online edit was made and saved only to RAM (without a "Download to Memory Card").
  • The card was last programmed from a different STEP 7 project than the one currently online.
  • The card has been written by a different CPU with mismatched module type or firmware.

When a block exists in work memory but is absent from the FEPROM/MMC, the online block view in STEP 7 (SIMATIC Manager) shows the block with a yellow/white striped icon and the entry "Not loaded into target system" or "Block exists only in RAM". This visual indicator is the first quick check.

A "Upload to PG/PC" from STEP 7 reads work memory only, not the FEPROM card. To inspect the FEPROM/MMC contents, use the dedicated card management function described in the next section.

Step-by-Step Verification Procedure (STEP 7 / SIMATIC Manager)

This procedure is the canonical answer to the question: how do I know if my EPROM/Flash has the latest program? It assumes the classic CPU 412/414/416/417 series with FEPROM.

Prerequisites

  • STEP 7 V5.5 or V5.6 with the S7-400 option installed.
  • Online connection to the CPU via PROFIBUS, MPI, or Industrial Ethernet.
  • PG/PC administrator rights to read/write the FEPROM card.
  • Reference project (the project believed to be the "master") stored offline on the engineering station.

Procedure

  1. Open the S7 project that contains the offline master, or create a new empty project.
  2. Go online: PLC > Online & Diagnostics, select the CPU, and click "Go Online".
  3. In the project tree, expand Program Blocks. Each block carries an icon that tells you where it lives:
    • Solid block icon: block is in work memory and load memory.
    • Yellow-striped block icon: block exists only in work memory (not on card).
    • Grey/dimmed block icon: block exists only in load memory (passive copy).
  4. Right-click Program Blocks and choose Compare Online/Offline. This compares the work-memory copy against the offline project (your master). Mismatches are highlighted in red.
  5. To inspect the FEPROM card specifically, use PLC > Manage Memory Card (FEPROM) or, on the SFC dialog, call SFC 82 "READ_FPM" via a test program if you need script-driven access. The card contents appear as a separate listing.
  6. Export the FEPROM listing to a CSV via File > Export. Compare the exported list (block name, timestamp, checksum) against the offline master.
  7. If a block on the card is older than the offline master, transfer the master onto the card using PLC > Download to Memory Card. Confirm the "Delete passive image" prompt to keep RAM and card synchronized.
  8. Cycle power or execute an SFC that triggers an initialization restart if STEP 7 reports signature mismatches after the card update.

Verification

After the procedure, every block icon in the online view must appear solid, and Compare Online/Offline must report zero differences. The diagnostic buffer entry "Memory card initialized, blocks transferred to work memory" confirms the card image is current.

Step-by-Step Verification Procedure (TIA Portal)

TIA Portal (V15 and later) replaces the SIMATIC Manager workflow but exposes the same logical check, with a more graphical interface and a clearer MMC/FEPROM separation.

Prerequisites

  • TIA Portal V16 or newer with S7-400 support package installed.
  • Online connection via PN/IE, MPI, or PROFIBUS.
  • An MMC (or, on legacy CPUs, an FEPROM) is physically installed.
  • The offline project on the engineering station.

Procedure

  1. Open the TIA Portal project and select the S7-400 station.
  2. Go online: Online > Go Online & Compare. TIA Portal automatically diffs every online block against the offline project.
  3. Inspect the "Compare" editor. Differences appear as red icons; right-click any block and select Go to Online Block to view the work-memory version.
  4. To compare against the MMC rather than against your offline master, use Online & Diagnostics > Memory Card > Read from Memory Card. The dialog lists every block stored on the MMC together with timestamps and CRC32 checksums.
  5. Save the MMC contents as a local project using Save as on the read dialog. Open the saved project side-by-side with the master project and use Compare again to identify which blocks diverge.
  6. To update the MMC after a verification failure, right-click the CPU and select Download to Memory Card. Choose the option "Delete passive load-memory image" to prevent stale copies from being loaded on next startup.
  7. Confirm by re-reading the MMC after the download. The block timestamps must reflect the new download.

Verification

Open Online & Diagnostics > Diagnostic Buffer and confirm no entries of type "Load memory inconsistent" or "Passive load-memory image activated". The Compare editor must report No differences.

MMC vs FEPROM Migration Considerations

Plants that still operate classic CPU 41x systems occasionally migrate to the PN/DP generation. The migration changes the verification workflow because MMC, unlike FEPROM, can be read directly by a card reader on the PG without the CPU being online. Both card types store the block header (SSB - System Software Block) and the block body in the same Siemens proprietary format, but the file system differs.

Aspect FEPROM (legacy 41x) MMC (CPU 41x PN/DP)
Card reader required Yes (CPU must read it) Yes (standard SD reader works on PG)
Direct upload from card Not via standard STEP 7 dialog (only via PG/PC direct read of blocks in work memory) Full project upload supported
Hot swap while CPU is RUN Not allowed Allowed only with specific firmware and "Update MMC in RUN" SFC
Firmware update location Card itself (firmware stored on FEPROM) Internal flash, MMC only stores user program
Encryption Not supported KNOW_HOW_PROTECT blocks supported

When migrating, an engineer who relied on "Upload from FEPROM" to recover a forgotten master must instead use the MMC "Save as Project" workflow. The old FEPROM cannot be inserted into the PN/DP CPU without reformatting; the file systems are incompatible.

Online Block Properties Reference Table

The following table maps the STEP 7 / TIA Portal block-container state to the underlying memory region. Use this as a field diagnostic checklist.

Online Icon Work Memory Load Memory Action Required
Solid block Present, current Present, current None; card and RAM agree
Yellow striped block Present, current Absent or older Download the block to the memory card
Grey dimmed block Not present Present only Force a copy from load memory to work memory (restart or SFC)
Question mark icon Unknown (CPU unreachable or wrong password) Unknown Establish online connection; provide correct password
Red "X" Block corrupted or version mismatch Same Re-download the block; clear diagnostic buffer entries first

Troubleshooting Matrix

Symptom Likely Cause Diagnostic Step Corrective Action
Block exists online but offline shows nothing Online-only edit was made Right-click the block, choose "Block Consistency" Download the block to the memory card and to the offline project
Compare Online/Offline shows differences after every restart FEPROM/MMC has older blocks than work memory Diagnostic buffer: search for "Passive load-memory image" Run "Download to Memory Card" with "Delete passive image"
CPU reports SF (System Fault) after card swap New card is empty or from another project Diagnostic buffer: "Card not parameterized" Download project to the new card or insert the original card
Cannot upload from card on legacy CPU FEPROM requires CPU to copy blocks to RAM first Go online, force a warm restart Use "Upload to PG" once blocks are in RAM, then verify against card via "Manage Memory Card"
TIA Portal "Read from Memory Card" returns only firmware blocks CPU was not in STOP during card insertion Insert card with CPU in STOP Reinsert card in STOP; re-issue "Read from Memory Card"

Safety and Operational Notes

Every verification procedure that ends with a download to the FEPROM/MMC should be executed in a controlled window:

  • Bring the process to a safe state before triggering any download that could cause an OB100 / OB101 startup.
  • Disable the safety-relevant FB/FCs (for example F-Systems blocks) from being overwritten if a different version is on the card.
  • Document the offline master checksum before and after the download; STEP 7 can generate a project checksum via Project > Check Project Consistency.
  • Keep at least two master copies of the MMC image (one on PG, one in a fire-resistant safe) per IEC 62443 operational guidelines.
  • Never swap an MMC while the CPU is in RUN unless the firmware specifically supports "Update in RUN". On FEPROM-equipped CPUs, the slot is only safe with power removed.
A failed "Download to Memory Card" operation can leave the card in a half-programmed state. Always run "Read from Memory Card" immediately after to confirm every block was written.

Field-Proven Caveats

From practical experience on installed S7-400 systems:

  • The CRC32 shown in TIA Portal "Read from Memory Card" is computed over the block body and excludes the timestamp, so two blocks with different timestamps but identical logic will show the same CRC. Use the timestamp column, not the CRC, for true version comparison.
  • On CPU 417 (for example 6ES7417-4XT05-0AB0), passive load-memory images are stored in a dedicated area of the card. Removing the card disables this area; restoring the same card later re-activates it without re-downloading.
  • Some plant operators store both an FEPROM and an MMC on a project. The verification workflow must treat them independently; do not assume one card's contents match the other.
  • If the CPU password is unknown, "Read from Memory Card" still works on MMC-equipped CPUs because the MMC image is not encrypted by the CPU password. This is a deliberate Siemens design choice for offline recovery.

Quick Verification Checklist

  1. Go online with the CPU.
  2. Confirm every block icon is solid (work memory and load memory agree).
  3. Run Compare Online/Offline against the offline master project.
  4. Run Read from Memory Card and export the listing.
  5. Diff the exported listing against the offline master.
  6. Resolve any divergence with Download to Memory Card.
  7. Cycle power or trigger a warm restart; verify the diagnostic buffer is clean.

Can I upload the program directly from the EPROM card on a classic S7-400 CPU?

No. STEP 7 (SIMATIC Manager) does not provide an "Upload from FEPROM" dialog. The card must be read by the CPU itself; blocks are first copied into work memory during a restart, then "Upload to PG" can read them. On newer MMC-equipped CPUs (CPU 41x PN/DP), TIA Portal can read the card directly without the CPU being online.

How do I know if my FEPROM or MMC contains the latest program?

Go online and inspect the Program Blocks container. Solid block icons indicate that work memory and the memory card agree. Yellow-striped icons mean the block exists only in work memory and was never transferred to the card. Use "Compare Online/Offline" or "Read from Memory Card" to confirm the timestamps match your offline master.

What is the difference between "Passive load-memory image" and an active block?

An active block has a copy in work memory and is currently executing. A passive load-memory image is a block stored on the FEPROM or MMC that the CPU does not need at runtime but keeps as a fallback for a warm restart. After a power loss, the passive image becomes the active block.

Does the battery on an S7-400 CPU also back up the FEPROM card?

No. The battery backs up the integrated SRAM (work memory and the RAM portion of load memory). The FEPROM or MMC is non-volatile and retains its contents without battery power. On MMC-equipped CPUs the battery is required only for the realtime clock and for retentive M/T/C data.

Is it safe to swap an MMC while the S7-400 CPU is in RUN?

Only on CPU 41x PN/DP firmware versions that support "Update in RUN" via SFC 83 / SFC 84. On legacy FEPROM-based CPUs, the slot must be empty (CPU power removed). Hot-removal on a non-supporting firmware will trigger an SF (System Fault) and a STOP transition.

Back to blog