Siemens HMI Recipe Data Loss After Power Cycle: Causes & Fix

David Krause20 min read
HMI / SCADASiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview

Recipe data on a Siemens Comfort Panel (TP700/900/1200/1500/1900, KP, KTP, or Unified Comfort Panel) is not retained across a power cycle. After configuring recipes in TIA Portal, downloading the project, saving data records at runtime, and removing power, the operator discovers that the recipes have reverted to defaults or been deleted entirely. On removable media like an SD card, the symptom often appears as "inconsistent" behavior: a few files are present on the card, file names look correct, but the data record body is empty or partial. The root cause is rarely a single switch; it is a combination of HMI storage path configuration, PLC tag retentivity, and the runtime contract between the recipe view element and the PLC data block.

This article covers the Siemens recipe persistence model end-to-end: how the HMI stores data records, how the PLC must be configured for tag retentivity, the differences between internal flash, SD card, USB, and network storage, the specific failure modes that produce empty data files, and a field-proven configuration that survives a hard power cycle without external media.

Root Cause Analysis: Why Recipes Vanish After Power Cycle

Siemens HMIs are not single-component systems. A recipe involves three independently powered storage domains:

  1. HMI runtime memory (volatile) – the working copy of the current recipe in the panel's RAM. Cleared on every power-down.
  2. HMI non-volatile media – internal flash, SD card, USB stick, or network share. This is where "saved" data records should land.
  3. PLC retentive memory – tags or DB members that survive PLC power-down. These are the runtime variables the recipe synchronizes with.

When a recipe is "lost" after a power cycle, the failure is in one or more of these domains. The most common failure chains observed in the field are:

  1. The recipe is configured to write to the SD card, but the card is removed before the HMI has flushed the write buffer, or the card is absent at boot.
  2. The PLC tags referenced by the recipe are not marked retentive, so even if the HMI has the data, the PLC side resets to default values on power-up.
  3. The HMI storage path is left at the default ("Storage Card SD\") but the project was downloaded to a panel without a card present, so the path is unreachable at runtime.
  4. The recipe view element is configured for "manual" save/load and the operator never invokes the save command; what appears to be "saving" is only the volatile copy in HMI RAM.

The reported symptom – "files present on the SD card but values empty" – points to a write-ordering or file-system issue. WinCC TIA writes recipe data records in two passes: a header containing element names, then the data record body. If the HMI loses power between the two passes, or if the SD card's wear-leveling algorithm has not yet committed the second block, the file on disk is structurally present but logically empty. Three files for one recipe is also a known symptom of this: WinCC creates the .csv (or .txt) data file, the element index file, and a transient write-ahead log; if the boot sequence is interrupted, the log file persists alongside partial data files.

Siemens HMI Recipe Architecture

A WinCC TIA recipe is a typed container of recipe elements bound to PLC tags, organized into recipe data records (the saved "instances"). The relationship is one-to-many:

  • 1 Recipe (definition) → N Data Records (saved values)
  • 1 Recipe → M Elements (typed fields, each linked to a PLC tag)

At runtime, the HMI can:

  • Read a data record from non-volatile media into the working buffer.
  • Display and edit the working buffer on a Recipe View control.
  • Transfer the working buffer to the PLC tags (the "Download to PLC" direction).
  • Transfer PLC tag values into the working buffer (the "Read from PLC" direction).
  • Save the working buffer to non-volatile media as a new or existing data record.

Critical point: the PLC tags themselves are not recipe data. They are ordinary PLC variables. The HMI is the authoritative source of saved data records. If you want the PLC to retain recipe values across a power cycle independently, those tags must be marked retentive in the PLC. If you want the HMI to retain the saved data records, the storage path must be on non-volatile media that is actually mounted at runtime. Both must be correct for the operator to see the expected values on the next boot.

PLC Tag Retentivity: The Foundation of Non-Volatile Storage

PLC retentive memory is the only PLC-side memory that survives a power cycle on S7-1200/1500 and S7-300/400 controllers. Recipe data has no special status – the recipe view element writes to the same DB tags the application uses. If those tags are not retentive, the PLC will load zeros (or initial values) on every power-up, regardless of what is in the HMI's saved data records.

Setting Retentivity in TIA Portal (S7-1200/1500)

For S7-1500 and S7-1200 (firmware V4.0+), the retentive area is configured in the PLC device properties, with tag-level overrides possible:

  1. Open the PLC device in the TIA project tree.
  2. Open Properties → General → Retentive memory (or in older portal versions, Properties → Retentive areas).
  3. Define the retentive range for Memory bits (M), Timers, and Counters if used.
  4. For data block tags, open the DB, select the tag(s), and in Properties set the Retain attribute to Retain. For optimized blocks on S7-1500, the retain setting is per-tag.

Verify that the DB holding the recipe tags has retain enabled. A recipe that maps to a non-retentive DB will reset on every power cycle even if the HMI is configured perfectly. The maximum retentive area on S7-1500 is 16 MB by default; on S7-1200, the limit depends on the CPU model (typically 10 KB to 256 KB).

Setting Retentivity in STEP 7 V5.x (S7-300/400)

For legacy controllers, the retain attribute is set in the DB source:

DATA_BLOCK "Recipe_DB"
TITLE = 'Recipe Data'
AUTHOR : 'Eng'
FAMILY : 'Recipes'
{ S7_retentive := 'true' }  // mark entire DB retentive
VERSION : 0.1
  STRUCT
    Setpoint_Temp : REAL;        // retains across power cycle
    Setpoint_Pressure : REAL;    // retains across power cycle
    Cycle_Time : INT;            // retains across power cycle
  END_STRUCT;
END_DATA_BLOCK

Alternatively, mark individual tags with { S7_retentive := 'true' } at the tag level. Tags without the attribute in a retentive DB are still loaded with their initial values on every cold start. For S7-300, the SFB/SFC retain range must also be configured in the CPU properties (Hardware → Retentive Memory).

Critical: On S7-1500, the "Retain" attribute on individual tags overrides the DB-level setting. On S7-300/400, the DB-level setting controls all members unless explicitly overridden. Verify the actual setting in the online view (right-click the DB → "Monitor & Force"), not the offline source. A recipe DB that is retentive in the offline project but has the attribute stripped during download is a known source of "works in lab, fails in production" behavior.

Configuring HMI Storage Locations

The recipe storage path is configured at the recipe level in TIA Portal, not globally per panel. Open HMI → Recipes → [Recipe Name] → Properties → Storage and choose the storage type and path.

Storage Type Options

Storage Path syntax Behavior Recommended use
Internal flash \Storage Card Internal\ (Comfort) or /home/industrial/ (Unified) Soldered NAND, not user-removable, slower writes, firmware-managed journaling Production recipes that must persist without external media
SD card (data slot) \Storage Card SD\ Removable, faster writes, must be present at save and load time Recipe transfer between panels, large data sets
USB storage \Storage Card USB\ Removable, hot-pluggable on most panels Temporary recipe import/export, audit exports
Network path \\server\share\recipes\ Requires network connectivity at save/load time Centralized recipe management, audit trail, recipe library sync

Path Configuration Procedure

  1. In the TIA project tree, expand HMI → Recipes.
  2. Select the recipe (e.g., "Recipe_Production").
  3. In the properties pane, open the General section and confirm the recipe name and data record count.
  4. Open Properties → Storage.
  5. Set Storage location to either "Internal Flash" or "Storage Card SD" depending on your target panel and reliability requirements.
  6. Set the path. For internal flash on a Comfort Panel, the typical path is \Storage Card Internal\Recipes\. For an SD card, use \Storage Card SD\Recipes\.
  7. Compile the HMI project and download.
Field note: On Unified Comfort Panels (MTP/MTP Unified), the internal flash path is /home/industrial/recipes/ in the runtime filesystem. TIA Portal usually resolves this automatically when you select "Internal Flash" from the dropdown, but a manually-entered absolute path will fail at runtime on firmware mismatches between TIA Portal V16/V17/V18 and the panel's firmware version. Always pick the path from the dropdown, not by typing.

The SD Card Inconsistency Issue

The reported symptom – "I changed and saved the recipe, and after cycling the power, the recipe is sometimes saved and sometimes not" – has three documented root causes on Siemens Comfort Panels.

Cause 1: Write-Buffer Flush Timing

WinCC TIA writes the recipe data record to the SD card in two writes: a metadata block (element names, data record name, count) and a payload block. The card's write cache may report the first write as complete before the second has been committed. If the panel loses power between the two writes, the file on the card is half-formed. The file is visible to the file system, but the data record table is empty or partial. On a non-journaled FAT32 SD card, this is the dominant failure mode.

Mitigation: Use internal flash, where Siemens firmware guarantees atomicity of recipe writes via journaling on the panel's embedded filesystem.

Cause 2: SD Card Wear or Compatibility

Not all SD cards are industrial-grade. Consumer cards vary in wear-leveling behavior and power-loss protection. A consumer card that works for 100 power cycles may fail on the 101st. Siemens publishes a list of approved SD cards in the panel's operating instructions (look for the SIMATIC HMI accessory list in the SIOS portal); cards outside that list are not guaranteed to provide non-volatile semantics for recipe writes. Recommended industrial cards are SLC or pSLC with a specified power-loss protection circuit.

Mitigation: Use Siemens-approved SD cards (Siemens part numbers 6AV7671-1CA00-0AA0 and similar) or switch to internal flash for recipe storage.

Cause 3: Card Removal Before Save Completes

If the operator removes the SD card within seconds of pressing "Save" on the recipe view, the data record is not committed. The HMI has no standard way to signal "save complete" to the user, and the recipe view returns to its idle state before the file system has flushed. On power-up, the card is read and the data record is missing.

Mitigation: Add a "Save complete" indicator tag in the HMI, driven by the recipe's "Save complete" system event, and require the operator to wait for it before removing media.

Internal Flash vs. SD Card: Reliability Comparison

For non-volatile recipe storage that must survive a hard power cycle, the reliability hierarchy is:

  1. Internal flash (industrial) – Best. Write cycles are managed by the panel firmware with journaling. Atomic for recipe operations. Typical endurance: 100,000 to 1,000,000 erase cycles per block.
  2. Siemens-approved SD card (SLC or industrial pSLC) – Good. Wear-leveling and power-loss protection are guaranteed by the manufacturer. Typical endurance: 50,000 to 100,000 cycles per block.
  3. Consumer SD card (TLC/QLC, no industrial rating) – Poor. May pass basic functional tests, but recipe persistence is not guaranteed across power cycles. Typical endurance: 1,000 to 3,000 cycles per block.
  4. USB stick – Worst. Hot-pluggable means it is not always present, and consumer USB sticks are not designed for embedded write endurance.

For recipes that change frequently (operator edits per shift) and must persist, internal flash is the recommended target. The total write endurance of the panel's internal flash is more than adequate for typical recipe edit frequencies (a few hundred writes per day over a 10-year service life equals ~3.6 million total writes, well within the panel's spec).

Step-by-Step: Configuring Persistent Recipes on Siemens HMI

This procedure produces a recipe configuration that survives a hard power cycle with no external media and no operator intervention.

Prerequisites

  • TIA Portal V16 or later (V18+ recommended for Unified Comfort Panels).
  • S7-1200/1500 PLC project (S7-300/400 supported with the differences noted above).
  • Comfort Panel, Unified Comfort Panel, or WinCC RT Advanced runtime.
  • Recipe data block created in the PLC project with retentive tags.
  • Firmware versions cross-compatible: TIA Portal V18 supports Comfort Panels firmware V16.0+, Unified Panels firmware V1.0+.

Step 1: Configure the PLC Data Block

  1. Open the PLC project in TIA Portal.
  2. Create a new DB (e.g., DB_Recipe_Data).
  3. Add tags matching the recipe elements, e.g., Temp_Setpoint (REAL), Pressure_Setpoint (REAL), Cycle_Time (INT).
  4. Open DB Properties → Attributes and enable Optimized block access (S7-1500) or leave at default (S7-1200).
  5. For each tag, set the Retain attribute to Retain (or Set in IDB for S7-1500 with optimized access).
  6. Compile the PLC and download.

Step 2: Create the Recipe in TIA Portal

  1. Open the HMI project.
  2. Add a new recipe under HMI → Recipes.
  3. Name the recipe (e.g., Recipe_Production).
  4. Add recipe elements, one per PLC tag. For each element:
    • Set the Name to match the PLC tag name (informational).
    • Set the Connection to the PLC and the Tag to the corresponding PLC DB tag.
    • Set the Data type to match the PLC tag (REAL, INT, BOOL, etc.).

Step 3: Configure Recipe Storage

  1. Open the recipe's Properties → Storage.
  2. Set Storage location to Internal Flash.
  3. Set the path to \Storage Card Internal\Recipes\ (the trailing slash is significant).
  4. Set the file name prefix to a unique string (default is the recipe name).
  5. Confirm the data record count (e.g., 10 data records, named 1 through 10).

Step 4: Configure the Recipe View on a Screen

  1. Open the screen where operators edit recipes.
  2. Add a Recipe View control from the HMI toolbox.
  3. Bind it to the recipe created in Step 2.
  4. Configure the toolbar to expose Save, Save As, Load, Delete, and New commands.
  5. Enable the Synchronize option if you want the recipe view to push the working buffer to PLC tags automatically on edit.

Step 5: Add a "Save Complete" Indicator

  1. Create an HMI tag Recipe_Save_Complete (BOOL).
  2. On the recipe view's Events, bind the "Save completed" event to a script or tag-setting action that sets Recipe_Save_Complete = TRUE.
  3. Add a visibility animation on a "Saved" indicator that shows only when the tag is TRUE.
  4. Reset the tag to FALSE on the next recipe edit.

Step 6: Compile and Download

  1. Compile the HMI project. Resolve any tag or address errors.
  2. Download the HMI project to the panel.
  3. Power cycle the panel and verify recipes are still present.

Synchronization Between HMI and PLC Recipe Data

WinCC TIA offers three synchronization modes for the recipe view element:

Mode Behavior Use case
Manual Operator explicitly clicks "Download to PLC" or "Read from PLC". Recipes changed only on operator command; no automatic PLC updates.
On edit Every change in the recipe view pushes the new value to the PLC tag immediately. Recipes that are tuning live process values; slow-changing operator parameters.
On load Loading a data record from storage pushes all values to PLC tags in one transaction. Recipe selection triggers a full parameter set download (most production scenarios).

For a production line where recipe selection must atomically write all parameters, "On load" is the correct mode. The HMI guarantees that either all tags in the data record are written or none are, by using a single coordinated download operation that the PLC acknowledges as a group. "On edit" is acceptable for low-rate edits but introduces intermediate states where the PLC has partial recipe data, which can cause process alarms if the recipe is read mid-edit by a separate process.

Verifying Recipe Persistence

After configuration, run this verification sequence on the target panel:

  1. Power on the panel. Confirm the HMI boots to runtime with no errors.
  2. Open the recipe view. Verify all configured data records are listed.
  3. Edit data record 1, change a value, and press "Save".
  4. Wait for the "Save complete" indicator to appear.
  5. Power down the panel (hard disconnect at the mains, not a soft stop via the control panel menu).
  6. Wait 30 seconds. Power on the panel.
  7. Open the recipe view. Confirm the edited value is present in data record 1.
  8. Open the PLC project online and view the actual values of the recipe DB tags. Confirm they match the saved data record.
  9. Power cycle again with no operator action. Confirm values are still present.

If the edited value is lost at step 7, the storage path is the first suspect. If the recipe view shows the value but the PLC tags are at default at step 8, PLC retentivity is the suspect. If both are correct but a subsequent power cycle loses data, the storage media is the suspect.

Troubleshooting Matrix

Symptom Likely cause Diagnostic Resolution
All recipes lost after power cycle HMI storage path points to volatile media or unreachable path Check Recipes → Properties → Storage. Check the panel's runtime filesystem at the configured path via ProSave or the panel's control panel → File Explorer. Switch storage location to "Internal Flash" with the default path. Re-download the HMI project.
Recipes present in HMI, PLC tags reset PLC tags not retentive Open the PLC online. View the recipe DB after power-up. Check the DB retain attribute in the offline/online diff. Mark the DB as retentive. Mark all recipe tags as Retain. Re-download the PLC.
File on SD card has names but no values; 3 files per recipe SD card write not atomically committed; transient WAL not cleaned up Remove the card, mount on a PC, and inspect the file. Check the card's journaling state and power-loss protection spec. Replace the SD card with a Siemens-approved industrial card. Switch to internal flash.
Recipe view shows "Path not found" at runtime Path is case-sensitive or panel firmware is older than TIA Portal expects Open the HMI diagnostics (Control Panel → System Properties). Check the panel's firmware version against TIA Portal compatibility matrix. Update panel firmware to the version supported by the installed TIA Portal. Use the default path from the dropdown, not a manually-typed path.
Recipe data changes, but PLC does not respond Synchronization mode is "Manual" and operator never triggers download Check the recipe view's sync mode. Trigger "Download to PLC" manually and confirm. Set sync mode to "On load" or "On edit" as required by the application.
Recipes survive some power cycles, fail on others SD card wear or borderline power supply to the panel Try a different SD card. Measure supply voltage at the panel terminals under load. Log power events in the HMI diagnostics buffer. Use internal flash. Verify the panel's supply voltage is within tolerance (24 V ±10% for most Comfort Panels; ±20% for Unified Panels).
Recipe data records appear renamed or corrupted after download Project re-download overwrote the storage path; the runtime did not preserve user data Check whether the panel was set to "Reset to factory settings" during the last download. Check the HMI transfer settings. Use "Transfer" mode (not "Reset") on subsequent downloads. Back up the internal flash Recipes directory before any major project change.

Best Practices and Preventive Measures

  • Default to internal flash for recipes that must persist. Use external media only for transfer, not for primary storage.
  • Mark the recipe DB retentive at the tag level, not just the DB level, on S7-1500. The tag-level setting overrides block-level defaults and survives DB property changes during project refactoring.
  • Use the dropdown path in the recipe storage configuration, not a manually-typed path. The dropdown values are guaranteed to exist on the panel's firmware version and avoid case-sensitivity issues on Linux-based Unified Panels.
  • Add a "Save complete" indicator on every operator-facing recipe view. The HMI does not have a native visual confirmation, and the operator needs a clear signal that the write has committed to non-volatile media.
  • Do not hot-swap the SD card while a recipe save is in progress. The HMI will not prompt for confirmation, and a partial write will corrupt the data record. If hot-swap is required, build a "safe to remove" LED driven by the recipe view's "Save completed" event.
  • Test the persistence with a hard power cycle, not a soft stop. Soft stops trigger the HMI's orderly shutdown sequence, which flushes the recipe cache. Hard power cycles do not, and are the actual failure mode in field incidents (breaker trips, emergency stops, UPS failures).
  • Document the storage path and the retentive DB structure in the project documentation. Recipe persistence depends on settings that are not visible in the running HMI, and the next engineer to work on the system will not have access to your reasoning. A one-line comment in the PLC tag and a screenshot of the HMI recipe properties saves hours of debugging on the next power cycle incident.
  • Plan retentive memory budget on the PLC. Recipe DBs that grow over the project lifetime (operators adding data records) will eventually push the PLC's retentive area past its configured limit. On S7-1500, 16 MB is the default; on S7-1200 CPUs, the limit ranges from 10 KB (CPU 1211C) to 256 KB (CPU 1516). Verify the headroom during project design, not at commissioning.
  • Keep PLC firmware and TIA Portal versions in sync. Recipes created in TIA Portal V18 may not round-trip correctly through a panel running V15 firmware. Cross-version behavior is documented in the TIA Portal release notes but is not always obvious from the project download dialog.

Why does my Siemens HMI lose all recipe data after a power cycle?

The HMI has not been configured to write recipes to non-volatile storage. The default recipe storage path in TIA Portal is the internal flash, but if the project was downloaded with the path set to a removable medium (SD card, USB) and that medium is absent at save time, the data record is never written. Configure the recipe storage location to "Internal Flash" in the recipe's properties, set the path to \Storage Card Internal\Recipes\, and verify the path with the panel's diagnostics view.

Do I need to mark PLC tags as retentive for recipes to persist?

Yes. The HMI saves recipe data records to its own storage, but the PLC tags that the recipe writes to are ordinary variables. If the recipe DB is not marked retentive, the PLC will load initial values on every power-up, and the HMI will overwrite them with the saved data record only on the next operator action. On S7-1500, set the Retain attribute on each recipe tag in the DB (optimized blocks). On S7-300/400, set { S7_retentive := 'true' } at the DB or tag level in the source.

Why are there three files on my SD card with element names but no values?

WinCC TIA writes recipe data records in two passes plus a transient write-ahead log: a metadata header, a data payload, and a journal file. If the panel loses power or the card is removed between the writes, the data and journal files are present but the payload is empty, and the journal is not cleaned up. This is a documented failure mode on consumer SD cards. Use a Siemens-approved industrial SD card, or switch the recipe storage to internal flash, which uses a journaling file system that guarantees atomic writes and cleans up transient files on boot.

Can I store recipes in internal flash without an SD card?

Yes. Comfort Panels and Unified Comfort Panels have internal flash that is non-removable and retained across power cycles. In the recipe's properties, set the storage location to "Internal Flash" and the path to \Storage Card Internal\Recipes\ (Comfort) or use the Unified default. The panel's firmware will write the data records to the internal NAND, and they will be present on the next boot without any external media.

What happens to a recipe if the HMI is soft-stopped vs. hard power cycled?

A soft stop (operator-initiated via the control panel or a configured tag) triggers the HMI's orderly shutdown, which flushes the write cache and commits any pending recipe data records. A hard power cycle (mains disconnect, breaker trip) does not trigger the orderly shutdown, and any recipe data record that was in the write cache but not yet committed to non-volatile storage will be lost. Test recipe persistence with a hard power cycle to verify the field condition, not a soft stop.

Back to blog