Siemens S5-100U EEPROM Program Recovery and S7 Migration

David Krause15 min read
SiemensTechnical ReferenceTIA Portal
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Overview: Recovering a S5-100U Program and Planning the S7 Migration

The SIMATIC S5-100U sits in the small-PLC tier of the legacy SIMATIC S5 family. Machines built in the late 1980s and 1990s with this controller are still in service in water treatment, packaging, materials handling, and small process skids, and the original STEP 5 program often exists only on a removable EEPROM submodule. When a modernization project begins, the first engineering task is to lift the program out of that EEPROM so it can be documented, printed, and re-implemented on a current S7-1200, S7-1500, or S7-300/400 controller. The S5-100U does not have a directly compatible modern S7 drop-in; it is replaced controller-for-controller with a new CPU and new I/O, while the program logic is ported manually or with a converter tool.

This reference covers the four engineering work-streams that the field engineer must complete in sequence:

  1. Identify the S5-100U CPU variant and the EEPROM submodule (memory size, firmware).
  2. Acquire or re-commission a Siemens Programmiergerät (PG) that can run STEP 5, plus the correct TTY / V.24 programming cable.
  3. Read the EEPROM either in-circuit (CPU still powered in the rack) or out-of-circuit (EEPROM pulled and read on a memory module adapter).
  4. Convert the resulting STEP 5 program (STL / LAD / CSF) to STEP 7 (S7-300/400) or TIA Portal (S7-1200/1500) and rebuild the I/O address map.
Field note: The S5-100U is end-of-life and Siemens A&D no longer services individual EEPROM reads. The work must be performed either with retained legacy PG hardware, a SIMATIC Field PG running STEP 5, or by a third-party migration specialist. The OEM's "Tryed SIEMENS unable to help with S5" outcome is expected for service contracts and is not a fault in the procedure.

2. S5-100U System Architecture and EEPROM Identification

The S5-100U is a modular, slot-based PLC with a 16-bit internal bus. The CPU is the leftmost module, followed by I/O modules in a single tier (a maximum of 32 modules per rack, but the S5-100U is typically configured with 4 to 8 modules in practice). The PLC is programmed in STEP 5 and stores user code in either an internal RAM backed by a battery, or an external memory submodule.

2.1 CPU variants used in the S5-100U

CPU Order Number (MLFB) Designation User Memory Scan Time / 1 Kbit Notes
6ES5 100-8MA02 CPU 100 1 KB statements approx. 7 ms Smallest, bit-logic heavy
6ES5 102-8MA02 CPU 102 2 KB statements approx. 5 ms Counter/timer expansion
6ES5 103-8MA02 CPU 103 4 KB statements approx. 2.5 ms Adds analog flag area
6ES5 104-8MA11 CPU 104 10 KB statements (rare) approx. 1.5 ms Not in all catalogs; check MLFB

Locate the MLFB on the front label of the CPU (e.g., 6ES5 103-8MA02). The user memory size determines which EEPROM submodule will be installed: a CPU 100 will use a 2 KB EEPROM, while a CPU 103 with a heavily loaded program may use a 4 KB or 8 KB submodule.

2.2 EEPROM submodules

The EEPROM submodule is a small blue or green PCB that clips into a hinged flap on the front of the CPU. It is held in place by a single retaining screw.

EEPROM Order Number Capacity Compatible CPUs
6ES5 371-0LA11 2 KB CPU 100, 102, 103
6ES5 371-0LA12 4 KB CPU 102, 103
6ES5 371-0LA21 2 KB (later rev.) CPU 100, 102, 103
6ES5 371-0LA22 4 KB (later rev.) CPU 102, 103
6ES5 374-0LA11 8 KB (rare) CPU 103

The EEPROM can be read either in-circuit (through the programming port on the front of the CPU) or out-of-circuit (with the module removed and inserted into a memory module adapter). For a working machine that can be stopped briefly, the in-circuit read is preferred because it does not disturb the battery-backed RAM and is reversible if the EEPROM has been left empty.

3. Required Hardware: Programming Devices and Cables

STEP 5 only runs on the original Siemens PG family or on a SIMATIC Field PG with a DOS/Win32 STEP 5 installation. The PG must be equipped with a TTY (20 mA current loop) port or, more commonly, a V.24 (RS-232) port plus the dedicated Siemens programming cable. A modern Windows laptop with a USB-to-serial adapter is not a reliable substitute because STEP 5 expects the timing of the Siemens TTY link layer.

3.1 Compatible programming devices

PG Model Interface STEP 5 Versions Supported Notes
PG 605 (6ES5 305-5MA) V.24 (RS-232) STEP 5 / S Portable, monochrome LCD
PG 615 (6ES5 315-1MA) TTY and V.24 STEP 5 V3.x – V6.x Mainstream 1990s
PG 635 (6ES5 335-3MA) TTY and V.24 STEP 5 V3.x – V6.x Larger keyboard, color option
PG 685 (6ES5 385-1MA) TTY and V.24 STEP 5 V3.x – V7.x Portable, color LCD
PG 720 P (6ES7 720-1...) V.24, TTY optional STEP 5 V6.x – V7.x + STEP 7 Bridge PG for migration
PG 740 (6ES7 740-1...) V.24, MPI, TTY STEP 5 V6.x – V7.x + STEP 7 Common on second-hand market
PG 760 / PG 770 V.24, MPI/DP STEP 5 V7.x + STEP 7 Best option for S5/S7 bridge
SIMATIC Field PG M2/M4 V.24, MPI/DP, Ethernet STEP 5 V7.2 + STEP 7 V5.x + TIA V13 Modern portable; use if available

3.2 Required cables

Siemens Order Number Length Connector A (PG) Connector B (PLC) Use
6ES5 736-0AK00 3.2 m DB-15 male (PG) DB-15 male (CPU) PG to S5-100U, TTY link
6ES5 736-0BC00 5 m DB-15 male DB-15 male Longer TTY run
6ES5 734-1BD20 3 m DB-25 male DB-15 male For older PG 605/615
6ES5 736-2xx00 (memory adapter) — PG EPROM socket — Out-of-circuit EEPROM read

If the available PG only has a 25-pin V.24 port, the cable must be the DB-25 to DB-15 variant (6ES5 734-1BD20). A standard DB-9 null-modem cable will not communicate with the S5-100U.

3.3 Link-layer specifics

The S5-100U programming port is a 15-pin male sub-D on the front of the CPU. The interface uses TTY (20 mA current loop) at 9600 bit/s, even though the cable is labelled V.24. The PG must therefore be set to TTY mode, not RS-232. In STEP 5 the default interface is "IF 1 / S5-DOS" and the baud rate is auto-negotiated to 9600.

4. Required Software: STEP 5 Versions and Installation

STEP 5 Version Host OS Last Service Pack Notes
STEP 5 / S (DOS) MS-DOS 5.0+ — For PG 605/615
STEP 5 V3.x (DOS) MS-DOS 5.0+ — Adds graphic editor
STEP 5 V6.x (Windows) Windows 3.11 / 95 / 98 / NT 4 V6.6 HF3 First 32-bit version
STEP 5 V7.x (Windows) Windows NT 4 / 2000 / XP V7.23 Coexists with STEP 7 V5.x
STEP 5 V7.2 Windows XP SP3 HF7 Final release; reads every S5-100U EEPROM variant

STEP 5 V7.23 running on a SIMATIC Field PG (or on a Windows XP SP3 virtual machine on legacy hardware) is the most flexible combination. It can read the S5-100U EEPROM and then export the program as STL source so that the same PC can import it into STEP 7 V5.x using the S5 to S7 converter.

4.1 Installation order for a migration PC

  1. Install Windows XP SP3 (or a Windows XP VM) on a stable partition.
  2. Install STEP 5 V7.2 + HF7. Restart.
  3. Install STEP 7 V5.5 + SP4 (for the S5 → S7 converter tool).
  4. Verify the "S5 to S7 Converter" entry in the STEP 7 program group is present.
  5. Connect the PG to the S5-100U and run the "IF Interface Test" in STEP 5 to confirm the link.

5. EEPROM Read Procedure: In-Circuit and Out-of-Circuit

5.1 In-circuit read (preferred when machine can be briefly stopped)

  1. Place the S5-100U in "STOP" mode via the mode switch on the front of the CPU. The PLC is in RUN/STOP/RESET, the middle position is STOP.
  2. Connect the 6ES5 736-0AK00 cable between the programming port (15-pin) on the CPU and the PG.
  3. Start STEP 5 on the PG. Select File → Online → Set Interface and choose S5-DOS (TTY) at port 1.
  4. Choose File → Read S5 File from PLC (or in V7.x, Online → S5 File → Read from PLC).
  5. Select the file type: STL (Statement List) plus DB (Data Block) plus FX (Flag Word). The dialog offers "STL/CSF/LAD" — keep STL for export.
  6. STEP 5 reads the program from the EEPROM through the TTY port and writes the file to disk. Typical file extension is *.S5D.
  7. Save the file with a meaningful name, e.g., SIMATIC_S5_100U_LINE1.S5D.

5.2 Out-of-circuit read (EEPROM removed)

  1. Power down the S5-100U rack. Wait 30 s for the bus to discharge.
  2. Open the EEPROM flap on the CPU. Loosen the single retaining screw and lift the submodule out.
  3. Insert the submodule into the appropriate memory-module adapter:
    • For PG 605/615/635/685/720: the adapter is the 6ES5 736-2xx00 series, inserted into the EPROM socket on the side of the PG.
    • For Field PG M2/M4: a USB memory-module adapter is required; the EEPROM must be erased and re-read in STEP 5.
  4. Run File → Read S5 File from Memory Submodule in STEP 5.
  5. After the read, return the EEPROM to the CPU and re-tighten the screw before powering up.
Important: Out-of-circuit reads on Field PG M2/M4 must be followed by an "Erase" + "Re-write" cycle if the read process uses a UV-erasable EPROM. The S5-100U EEPROM submodule is electrically erasable, not UV-erasable, so no UV lamp is required. Verify the label: blue/green PCB = EEPROM (electrically erasable), ceramic window with quartz crystal = UV-erasable EPROM.

6. Program Documentation: Printing and Exporting

Once the S5 file is on disk, print and export:

  1. File → Print → Cross-reference to print every I/O and flag address in use.
  2. File → Print → Program Listing to print the full STL/LAD.
  3. File → Export → STL Source to create an *.AWL (Anweisungsliste) file that the S5 to S7 converter can read.
  4. File → Export → Documentation to create a PDF of the entire project for the file cabinet.

6.1 Common STEP 5 operators and their S7 equivalents

STEP 5 Operator Meaning STEP 7 / TIA Equivalent
U E 0.0 AND Input 0.0 A I 0.0
UN E 0.1 AND NOT Input 0.1 AN I 0.1
O A 1.0 OR Output 1.0 O Q 1.0
= A 2.0 Assign Output 2.0 = Q 2.0
L IB 0 Load Process Image Input Byte 0 PIB 0 / IB 0
T MW 10 Transfer to Flag Word 10 T MW 10 (same)
SP T 1 Pulse Timer T1 (50 ms) SP T 1 / pulse timer S_PULSE
ZR Z 1 Counter Z1 decrement CD C 1 / S_CD
JU FB 10 Jump Unconditional FB10 UC FB 10 / CALL FB 10
DO DW 5 Data Operation on DW5 DB5.DBX / L DBB 5

7. S5 to S7 Conversion Strategy

Two practical paths exist. The choice is driven by the target S7 platform and the amount of program re-engineering the plant is willing to fund.

7.1 Path A: STEP 5 → STEP 7 V5.x converter (for S7-300/400)

The S5 to S7 Converter is a free tool bundled with STEP 7 V5.5. It ingests an *.AWL file from STEP 5 and produces an S7 source file. The conversion is mechanical: it remaps operators (U→A, E→I, A→Q, M→M, T→T, Z→C) but does not re-engineer the I/O. The engineer must:

  1. Map every S5 input byte (E 0..n) to an S7 input byte (I 0..n) by re-wiring or by adjusting the S7 hardware configuration.
  2. Map every S5 output byte (A 0..m) to an S7 output byte (Q 0..m) by the same method.
  3. Manually re-create the function blocks (FB) that use S5-specific constructs (e.g., SU subtract unipolar, RU round).
  4. Replace the battery backup on the S5-100U with the retentive bit area on the S7-1200/1500 (use the system memory byte for non-volatile flags).

7.2 Path B: Manual re-implementation in TIA Portal (for S7-1200/1500)

For modern plants, the converter is often skipped entirely. The engineer reads the S5 program only to understand the logic, then re-implements the function in TIA Portal V18 or later. The advantages are:

  • Modern data types (BOOL, INT, REAL, STRING) replace the S5 flag-word world.
  • Symbolic addressing replaces absolute addressing.
  • Optimized block access enables HMI integration via TIA tags.
  • Safety integration (F-CPU) is possible.

The cost is engineering time: a 1 KB STEP 5 program with 4 I/O and 2 timers typically requires 2 to 4 hours of re-engineering. The same program in TIA Portal is functionally identical but vastly more maintainable.

8. I/O Address Mapping for the S5-100U

The S5-100U has no hardware configuration in the modern sense; the slot order defines the I/O addresses. S5-100U I/O modules are addressed starting at 0.0 by default, with digital input modules occupying the E (Input) area and digital output modules occupying the A (Output) area. The rack is one tier, so module 1 occupies byte 0, module 2 byte 1, etc.

Module Order Number Description Bytes Occupied Direction
6ES5 441-4UA12 4 DI 24 V 0.0..0.3 (1 byte) Input
6ES5 451-4UA12 8 DI 24 V 0.0..0.7 (1 byte) Input
6ES5 430-4UA12 4 DO 24 V / 0.5 A 0.0..0.3 (1 byte) Output
6ES5 431-4UA12 8 DO 24 V / 0.5 A 0.0..0.7 (1 byte) Output
6ES5 460-4UA12 4 AI ±10 V 0,2,4,6 (2 bytes each) Input
6ES5 470-4UA12 4 AO ±10 V 0,2,4,6 (2 bytes each) Output

For a 12-machine fleet with "not many I/O, maybe up to 16," a single S7-1200 CPU 1214C DC/DC/DC with a SM 1223 (8 DI / 8 DO) and a SM 1234 (4 AI / 2 AO) module is the typical modern replacement. The S7-1200 I/O address map is defined in the TIA Portal device configuration, not by slot.

9. Commissioning the S7 Replacement

  1. Build the S7 program in TIA Portal (or convert with the S5 to S7 Converter for S7-300/400).
  2. Wire the new S7 panel one-to-one with the S5-100U I/O list. Mark every wire with the S5 address on the source end and the S7 address on the destination end to make troubleshooting easier.
  3. Use the TIA Portal "Go online" feature to compare the I/O state live with the S5 program running in parallel. This is the only way to validate the conversion.
  4. Run the S7-1200 in parallel with the S5-100U for at least 8 hours, watching all analog values and interlocks. If the field device count is small ("up to 16"), this step is fast.
  5. Once stable, switch the machine to the S7 PLC, mark the S5-100U "Spare / Decommissioned," and retain the S5 program on the engineering PC plus a printed copy in the machine documentation folder.

10. Field-Validated Caveats and Common Pitfalls

  • Battery on the S5-100U: if the original battery is dead and the program was only on the EEPROM, the in-circuit read still works (the EEPROM is the source of truth, not the RAM). If the program was only in RAM and the battery is dead, the program is gone. Always check the battery first.
  • STEP 5 license: STEP 5 V7.23 requires a hardware dongle (the parallel-port key or the USB key on Field PG). Without the dongle, STEP 5 will run in demo mode and refuse to read from the PLC. Source the dongle with the PG, or buy a STEP 5 license transfer.
  • EEPROM write-protection: the EEPROM submodule has a jumper or switch on its PCB to lock out writes. If the read succeeds but the read-back shows blank, the jumper is set to "Read Only." Set the jumper to "Read/Write" before retrying.
  • Custom function blocks: if the original program used custom FBs (FB 100–FB 255), these must be re-created from the STL source. The S5 to S7 converter does not auto-generate FB code; it inlines the calls.
  • Analog scaling: S5-100U analog values are 12-bit raw. S7-1200 analog values are also 12-bit raw, but the engineering unit scaling is done in the user program, not in the module. Port the scaling formula unchanged.
  • Operator display panel: if the machine uses a SIMATIC OP5 or OP15 panel, those are not supported on S7-1200/1500. Plan for a new KTP700 Comfort or similar panel as part of the migration scope.

11. Equipment and Spare-Parts Retention

For a 12-machine fleet, retain at least one of each:

  • CPU module (e.g., 6ES5 103-8MA02) as a spare, with the EEPROM clone and the program printed.
  • Each unique I/O module in use (e.g., 6ES5 451-4UA12, 6ES5 430-4UA12).
  • One PG (PG 740 or Field PG M2) with STEP 5 V7.23 + HF7 installed and licensed, for any future reading of the S5 backup or programming a spare EEPROM.
  • One programming cable (6ES5 736-0AK00) verified working.

This is the equivalent of a 1:1 spare for the entire fleet's control layer and protects the project against single-point failures during the phased migration.

12. Frequently Asked Questions

Can Siemens still read an S5-100U EEPROM in 2025?

Siemens A&D formally declared the S5-100U end-of-life and does not offer EEPROM reading as a service. The work must be performed with retained legacy hardware (PG 605/615/635/685/720/740 or Field PG) running STEP 5 V7.23, or contracted to a third-party migration specialist.

Which cable connects a Field PG to an S5-100U?

Use Siemens order number 6ES5 736-0AK00 (3.2 m) or 6ES5 736-0BC00 (5 m). Both are 15-pin male to 15-pin male and carry the TTY (20 mA current loop) signal at 9600 bit/s. A standard DB-9 null-modem cable will not work.

How do I migrate a STEP 5 STL program to STEP 7?

Export the program from STEP 5 as an *.AWL file, then use the S5 to S7 Converter bundled with STEP 7 V5.5 SP4. The converter performs mechanical operator remapping (U→A, E→I, A→Q) but does not re-engineer the I/O hardware map. After conversion, manually re-create custom FBs and remap the I/O addresses in the S7 hardware configuration.

What replaces an S5-100U with about 16 I/O?

A SIMATIC S7-1200 CPU 1214C DC/DC/DC with one SM 1223 (8 DI / 8 DO) digital module and, if needed, one SM 1234 (4 AI / 2 AO) analog module. The full migration path is documented in the Siemens S5 to S7-1200/1500 application note, and a typical 1 KB STEP 5 program requires 2–4 hours of re-engineering in TIA Portal V18 or later.

Is the EEPROM electrically or UV-erasable?

The S5-100U EEPROM submodule (6ES5 371-0LAxx) is electrically erasable — no UV lamp is required. If the module has a quartz window in a ceramic package, it is a UV-erasable EPROM (less common on S5-100U) and requires a UV eraser. Check the PCB color and label: green/blue PCB = EEPROM, ceramic with quartz = EPROM.

Back to blog