Siemens S7-1200 Program Transfer Without TIA Portal: 5 Methods

David Krause15 min read
S7-1200SiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Siemens S7-1200 Program Transfer Without TIA Portal: 5 Field-Proven Methods

OEMs and system integrators who ship SIMATIC S7-1200 CPUs to remote customer sites regularly encounter the same constraint: the engineering workstation in the lab carries a TIA Portal license, but the operator PC at the customer location does not. Program updates, however, must still reach the PLC. This reference consolidates the five procedures that Siemens-documented and field-proven for delivering a TIA Portal V13 (or later) project to an S7-1200/S7-1500 CPU without installing TIA Portal at the customer site.

The methods covered are: (1) SIMATIC Memory Card (SMC) offline transfer, (2) the SIMATIC Automation Tool with a project archive, (3) a TIA Portal trial license, (4) a TIA Portal floating license on USB media, and (5) the S7-1200 Tool / memory-reset (MRES) procedure. Each is rated against cost, complexity, and connectivity requirements so the field engineer can pick the right procedure per customer.

Applies to: SIMATIC S7-1200 CPU firmware V1.x through V4.x, S7-1500 CPU firmware V1.x through V2.x, ET 200S/SP CPU, and the S7-1200F/S7-1500F safety variants (with the additional consideration that F-CPU program transfer is restricted to authorized personnel and must not bypass signed signature procedures). All references to TIA Portal apply to V13 SP1 and later unless otherwise noted.

1. Prerequisites and Assumptions

Before any of the five methods can be executed, the following conditions must be met at the lab and at the customer site:

  • The TIA Portal project is fully compiled and passes the consistency check (Project → Compile → Software (rebuild all)).
  • The CPU article number (e.g. 6ES7214-1AG40-0XB0) and firmware version (read via Online → Accessible devices or from the CPU display) at the customer site match the device configuration in the project.
  • The customer PC has administrator rights and a free USB port capable of reading a SIMATIC Memory Card or a standard SD card with the appropriate adapter.
  • Network reachability between the customer PC and the PLC has been verified. For PROFINET this is typically IP 192.168.0.1/24 on the CPU, default gateway 192.168.0.2.
Critical compatibility check: A project compiled for CPU firmware V4.4 cannot be downloaded to a CPU running V4.3. If the lab and customer firmware diverge, downgrade the device configuration in TIA Portal before exporting, or plan a firmware update on-site as a separate procedure.

2. Method 1 — SIMATIC Memory Card (SMC) Offline Transfer

The SIMATIC Memory Card is the most widely used mechanism for OEM program delivery. The S7-1200 retains its program in internal load memory when no card is present; the card itself functions as a transfer medium and as external load memory. The complete procedure is documented in chapter 2.7.3 of the S7-1200 System Manual.

S7-1200 Programmable Controller — System Manual (entry ID 107672495)

2.1 Required hardware

Article number Description Capacity
6ES7954-8LF02-0AA0 S7-1200 SIMATIC Memory Card 4 MB
6ES7954-8LE02-0AA0 S7-1200 SIMATIC Memory Card 2 MB
6ES7954-8LC02-0AA0 S7-1200 SIMATIC Memory Card 256 KB
6ES7648-0DC50-0AA0 S7-1200 SD card reader (USB) n/a

2.2 Lab procedure

  1. In TIA Portal, open the project that targets the remote CPU.
  2. Select the CPU device view and right-click the CPU → SIMATIC Memory Card → Add user-defined card (or insert the SMC into the PLC's card slot and use Project → Card Reader/USB memory).
  3. Drag the Program blocks, System blocks, and PLC tags folders onto the card target in the project tree.
  4. Select Project → Card Reader/USB memory → Write to memory card. TIA Portal will format the SMC with a FAT16 file system and write the S7_JOB.S7S and SIMATIC.S7S container files.
  5. Verify by inserting the SMC into a lab CPU of the same article number and powering on. The CPU should perform an automatic download and transition from STOP with orange SF/MAINT to RUN with green RUN LED.
  6. Ship the SMC to the customer by courier, along with the printed procedure (see §2.3).

2.3 Customer procedure

  1. Place the machine in a safe state. The CPU will lose its current program and retain only the program stored on the card unless the CPU is configured to copy RAM to card. Confirm the machine's E-STOP and guarding are functional before proceeding.
  2. Power down the S7-1200 CPU.
  3. Insert the shipped SMC into the card slot of the CPU.
  4. Restore power. The CPU performs a memory reset and then copies the program from the card to internal flash. The MAINT LED blinks yellow during this phase; the RUN LED turns solid green once transfer is complete (typically 30 to 90 seconds for a 1 MB project).
  5. Verify by reading the diagnostics buffer (Online → Online & diagnostics → Diagnostics buffer) from any PC or HMI that can reach the CPU.
Field caveat: If the customer CPU currently contains a password-protected program, the SMC download will be blocked. The PLC must be reset to factory settings (MRES) before the new card can be accepted. The MRES procedure is documented in §6 of this article.

3. Method 2 — SIMATIC Automation Tool

The SIMATIC Automation Tool is a free utility from Siemens that performs batch operations on a network of S7-1200, S7-1500, ET 200, and certain legacy S7-300/S7-400 CPUs without requiring TIA Portal to be installed. It can update firmware, change IP addresses, transfer projects, and read diagnostic buffers on up to several hundred devices from a single operator PC.

SIMATIC Automation Tool — Tool for Service and Commissioning (entry ID 98161300)

3.1 Tool capabilities relevant to program transfer

  • Scans a subnet for S7-1200/S7-1500 devices via PROFINET discovery (DCP) and lists them with article number, firmware, and current operating mode.
  • Pushes a compiled TIA Portal project archive (.zap or .ap13/.ap14/.ap15/.ap16/.ap17/.ap18/.ap19) to one or many CPUs.
  • Sets the CPU to RUN, STOP, or performs a memory reset before download.
  • Verifies the download by comparing the program CRC after transfer.

3.2 Lab procedure

  1. Compile the project in TIA Portal.
  2. Select Project → Archive → Archive and save as a .zap file. Confirm the archive contains the device configuration by opening it in TIA Portal on a second machine.
  3. Email or upload the .zap archive to the customer via a secure file-transfer mechanism. Archives of S7-1200 projects are typically 200 KB to 5 MB, so email attachments are feasible for most installations.

3.3 Customer procedure

  1. Install the SIMATIC Automation Tool on the customer PC. No TIA Portal installation is required.
  2. Launch the tool and click Add device → Network scan. The tool broadcasts DCP discovery packets and lists every Siemens controller on the subnet.
  3. Select the target CPU in the device table.
  4. From the Operations panel, select Program download and browse to the .zap file delivered by the lab.
  5. If required by the lab procedure, tick Memory reset before download and Start (RUN) after download.
  6. Click Execute. The tool reports per-step status; the entry Download completed successfully (CRC match) confirms the program on the PLC matches the archive.
Export-control note: The SIMATIC Automation Tool is freely downloadable from Siemens Industry Online Support but may be subject to German and US export-control regulations (AL: N, ECCN: EAR99 for current releases; verify with your export compliance officer before shipping to embargoed destinations).

3.4 Compatible firmware and tool versions

SIMATIC Automation Tool version Supported TIA Portal archive Min CPU firmware
V3.0 SP3 V13..V16 archives S7-1200 V4.0 / S7-1500 V1.6
V4.0 SP1 V13..V17 archives S7-1200 V4.2 / S7-1500 V1.8
V5.0 V13..V18 archives S7-1200 V4.4 / S7-1500 V2.6
V6.0 (current as of 2024-2025) V13..V19 archives S7-1200 V4.5 / S7-1500 V2.9

Check the release notes of the installed tool for the exact matrix; new TIA Portal major versions sometimes ship with a tool revision that does not yet accept older archives.

4. Method 3 — TIA Portal Trial License

A TIA Portal trial license is a fully-functional time-limited license that Siemens makes available for evaluation. The duration is up to 21 days of actual use from first launch per license key. For short commissioning or troubleshooting visits where the customer does not want a permanent TIA Portal installation, the trial license is the lowest-friction option.

4.1 Activation procedure

  1. From the lab, request a trial license key through the Siemens License Web Portal. The customer receives an email with a license certificate.
  2. Install TIA Portal at the customer site using the standard setup media (DVD or downloaded ISO).
  3. Transfer the license certificate (.txt) via USB stick and import via Automation License Manager → Install.
  4. Launch TIA Portal and confirm the license appears in the License Manager. The trial timer begins on first detected use of TIA Portal.
Use case: The trial license approach suits a single commissioning visit where the engineer is on-site with a laptop. For permanent in-house capability at the customer, the floating USB license (Method 4) or the Automation Tool (Method 2) is more cost-effective over the lifetime of the machine.

5. Method 4 — TIA Portal Floating License on USB Media

A floating license is not tied to a single PC; it resides on a USB dongle (the "license key USB media" or simply "USB stick") and can be moved between engineering workstations. One dongle covers all TIA Portal components (STEP 7, WinCC, PLCSIM, etc.) up to the bundle purchased. For an OEM supporting many customer sites, one floating license per service engineer is more economical than one license per site.

5.1 Lab procedure

  1. Purchase a TIA Portal floating license (article family 6ES7822-1A... — refer to Siemens price list for current part numbers).
  2. Siemens delivers the USB dongle with a license certificate.
  3. Import the certificate into the Automation License Manager on any PC that will host TIA Portal.

5.2 Customer procedure

  1. Install TIA Portal (V13 or matching version) on the customer PC using the standard media.
  2. Insert the USB license key. Windows detects it as a removable drive with a license container.
  3. Start TIA Portal. The License Manager reads the dongle and unlocks the software.
  4. Connect to the PLC via PROFINET, perform the program transfer (Online → Download to device), and close TIA Portal.
  5. Remove the USB dongle and ship it back to the OEM. The next visit reuses the same dongle.

5.3 Cost justification model

For an OEM servicing n customer sites per year with a TIA Portal license list price of approximately €3,500 (Basic) to €11,000 (Professional) at 2024 reference pricing, the floating license breaks even once n > 2 customer visits per year would have otherwise required individual installations. Always confirm the current list price with Siemens DI sales before preparing a business case.

6. Method 5 — S7-1200 Tool and the MRES Procedure

Two sub-procedures belong here. The first uses the legacy S7-1200 Tool (an early commissioning utility from Siemens that has been superseded by the SIMATIC Automation Tool but still ships with some older installations). The second is the memory reset (MRES) sequence combined with a memory card, which is the procedure machine builders traditionally used on S7-300/S7-400 and which still works on S7-1200.

S7-1200 System Manual — Chapter 2.7.3 Memory Card Operation

6.1 S7-1200 Tool procedure

  1. Install the S7-1200 Tool on the customer PC.
  2. Connect the PC to the CPU via PROFINET.
  3. Use the tool's Program download function to push the .zap archive. The tool is single-device only — for fleet updates, prefer the SIMATIC Automation Tool.

6.2 MRES procedure with memory card

  1. Insert the SMC containing the new program.
  2. Power on the CPU. The CPU transitions to STOP with the MAINT LED blinking.
  3. Use the CPU display (if present) or TIA Portal to perform a memory reset: navigate to Settings → Reset → Memory reset. On a CPU without a display, perform MRES via the mode selector by holding the selector in the MRES position for 3 seconds, releasing for 3 seconds, then holding again for 3 seconds.
  4. The CPU copies the program from the SMC into internal load memory and transitions to RUN if the project permits.
Mode selector caveat: On the S7-1211C, S7-1212C, and S7-1214C/DC/DC/DC variants without a display, the only MRES interface is the mode selector. Document the exact sequence for the customer technician and confirm it on the lab bench before shipping the card.

7. Method Comparison Matrix

Method Cost at customer Connectivity required Suitable for fleet updates Reversibility / rollback Field-engineer skill
1. SMC transfer €0 (SMC reused) None — power cycle only Yes (one card per site) Insert previous card; SMC retains last program Low (plug-and-play)
2. SIMATIC Automation Tool €0 (free tool) PROFINET access Yes (batch) Re-run with previous archive Medium (one-time setup)
3. Trial license €0 (trial) PROFINET access No (single install) Requires full TIA Portal High
4. Floating USB license ~€3,500-€11,000 per OEM engineer PROFINET access Yes (one dongle, many sites) Re-run with previous archive High
5. S7-1200 Tool / MRES €0 (tool) PROFINET access (Tool only) No (single device) Insert previous card Medium

8. Field Commissioning Checklist

Use the following checklist on every customer visit, regardless of which transfer method is selected:

  1. Capture a backup of the existing PLC program before any transfer. With TIA Portal: Online → Upload from device → Save as .zap. Without TIA Portal: insert a blank SMC, perform MRES, then power cycle — the previous program is then on the card.
  2. Photograph the CPU display or the diagnostic LEDs before and after the transfer.
  3. Confirm the CPU article number printed on the front panel (e.g. CPU 1214C DC/DC/DC 6ES7214-1AG40-0XB0) matches the TIA Portal device configuration.
  4. Read the diagnostics buffer after transfer and verify the entry Download of program successful (CRC: 0xA3F2...).
  5. Force I/O and verify each output in manual mode before returning the machine to automatic operation.
  6. Sign the commissioning log with the customer representative. The log must include the project archive hash (SHA-256) so the lab can prove which version is on the PLC.

9. Troubleshooting Matrix

Symptom Likely cause Resolution
CPU stays in STOP with MAINT blinking yellow after SMC insertion Card is not a valid SMC; card contains a V18 archive on a V4.2 CPU Verify the SMC part number; downgrade TIA Portal archive or upgrade CPU firmware
SIMATIC Automation Tool reports "Device not reachable" PC subnet differs from CPU subnet; firewall blocks UDP/34964 (DCP) Set PC to 192.168.0.x/24; add firewall rule for UDP/34964
Download fails with error "Configured device differs from connected device" Article number mismatch between project and physical CPU Right-click device in TIA Portal → Detect module differences or re-scan with the Automation Tool
Password prompt blocks SMC download Existing CPU program is password-protected Perform MRES to clear the password; document the customer's password reset procedure
F-CPU refuses transferred program Safety program signature mismatch or wrong F-CPU target Verify the F-CPU article number; transfer must originate from authorized safety engineer with the F-signature password
Trial license expired mid-visit Trial timer ran out Switch to Automation Tool method (Method 2) for the remainder of the visit
USB license key not detected on Windows 11 23H2 CodeMeter runtime not updated Install CodeMeter 7.40a or later from WIBU-SYSTEMS website

10. Security and Audit Considerations

Program transfer outside the TIA Portal environment bypasses the integrated user-management and trace features that an OEM normally relies on. Compensating controls the lab should put in place:

  • Sign the project archive with the SIMATIC Project Signature before export. The signature is verified by the Automation Tool on download and rejected if the file is tampered with.
  • Apply know-how protection to the function blocks. The S7-1200 supports block-level password protection; the password is supplied out-of-band to the customer, never embedded in the archive.
  • Maintain a CSV log of every archive SHA-256 hash shipped, the destination site, and the receiving technician's signature.
  • For F-CPU programs, only a person listed in the safety responsibility matrix may sign and ship the archive. The Siemens SIMATIC Safety — Configuration and Programming manual describes the F-signature workflow.

11. Recommended Procedure by Scenario

Based on the methods covered, the following decision tree applies for an OEM with a single TIA Portal V13 Basic license in the lab:

  • Single site, no IT infrastructure, mail is the only channel: Method 1 (SMC).
  • Multiple sites with PROFINET access and trained technicians: Method 2 (SIMATIC Automation Tool).
  • Engineer visits site with laptop for one-off commissioning: Method 3 (Trial license) or Method 4 (Floating USB) depending on visit frequency.
  • Legacy equipment that still ships with the S7-1200 Tool: Method 5 with verification on the bench before deployment.

12. References Inside This Article

All Siemens documentation referenced in this article is freely available on Siemens Industry Online Support. The following entries are cited above:

  • S7-1200 System Manual — entry ID 107672495
  • SIMATIC Automation Tool — entry ID 98161300

Can I send a TIA Portal V13 archive to a customer who only has the SIMATIC Automation Tool installed?

Yes. The SIMATIC Automation Tool V3.0 SP3 and later accept TIA Portal archives from V13 SP1 upward. Verify the version matrix in the tool's release notes because not every Automation Tool release handles every TIA Portal version.

Will the S7-1200 start automatically after I insert the memory card and power on?

If the project on the card is valid for the CPU article number and firmware, the CPU performs an automatic memory reset and transitions to RUN. The MAINT LED blinks yellow during the transfer (typically 30-90 seconds for projects under 1 MB) and then RUN turns solid green. If the CPU stays in STOP with MAINT blinking indefinitely, the archive is incompatible — see the troubleshooting matrix.

How do I push a program to an S7-1200 over the internet without a VPN?

The SIMATIC Automation Tool supports any IP-routable network path including internet and 4G/5G routers, but you must expose TCP port 102 (S7Comm) and UDP port 34964 (PROFINET DCP) through the firewall. For internet deployments, a VPN or a TeleService gateway (e.g. SINEMA RC) is strongly recommended because S7Comm has no native authentication and the protocol is widely exploited.

What happens to the password protection when I download a new program from a memory card?

The new program on the card overwrites the password-protected program only after a memory reset. If the existing program is password-protected, the card download is rejected and the CPU retains the old program. The technician must perform MRES first; document this step clearly so the customer does not lose a password they still need for online diagnostics.

Does a floating USB license work with TIA Portal V19 on Windows 11 24H2?

Yes, but the CodeMeter runtime that ships with V19 must be at version 7.40a or later. Older CodeMeter runtimes do not enumerate the USB license correctly under Windows 11 24H2 and Windows silently drops the dongle. Update the runtime from the WIBU-SYSTEMS website before deploying.

Back to blog