Testing S7-1200 Programs Without a CPU: PLCSIM Setup Guide

David Krause14 min read
S7-1200SiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview: The S7-1200 Offline Simulation Question

Engineers migrating from LOGO! to the SIMATIC S7-1200 frequently assume the new controller inherits the same offline simulation flow that LOGO! Soft Comfort provides. In practice, the S7-1200 followed a different roadmap. Siemens did not ship a dedicated S7-1200 simulator with TIA Portal V11, V12, or the original V13 release, which forced early adopters to debug against a real CPU on the bench using a starter kit or to borrow a CPU from a sister machine. With TIA Portal V13 SP1 (released March 2014) Siemens opened the door to S7-1200 simulation through S7-PLCSIM V13 SP1, and every TIA Portal release since — V14, V15, V15.1, V16, V17, V18, V19 — has retained and expanded that capability. This reference walks through the entire offline-simulation workflow: the firmware and TIA Portal version combinations that unlock PLCSIM for S7-1200, the exact project settings required to download to the virtual PLC, the verification instruments (watch tables, force tables, trace) available inside the simulated instance, and the limitations you must respect before treating the virtual CPU as a faithful stand-in for hardware. It also documents the starter-kit path for engineers who cannot yet run PLCSIM because of an older TIA Portal installation or because they need to validate firmware behaviour below V4.0.

Historical Context: Why S7-1200 Originally Lacked a Native Simulator

Three structural reasons delayed the appearance of a real S7-1200 simulator:

  1. CPU-side simulation hooks. PLCSIM does not emulate the entire instruction set; it requires the active firmware to expose the standard test and commissioning interface defined by the S7-1200/S7-1500 system architecture. S7-1200 firmware prior to V4.0 (released 2013) implemented a subset of that interface. Full PLCSIM compatibility required the firmware rework that shipped as FW 4.0 (CPU 1211C/1212C/1214C) and FW 4.1/4.2 (CPU 1215C/1217C).
  2. Catalog breadth. S7-300/400 PLCSIM could amortise its development cost across the entire 300/400 range. S7-1200 carries a longer tail of compact CPUs (1211C, 1212C, 1214C, 1215C, 1217C) and the F-variant safety controllers. Siemens chose to validate every CPU article before enabling simulation rather than ship a partial implementation.
  3. Tool chain. S7-PLCSIM V5.x (STEP 7 V5.x) was a Win32 application tied to the older STEP 7 manager. The new simulator had to be a TIA Portal plug-in from day one, which pushed the delivery to the TIA Portal V13 timeframe.

Until that release, the only sanctioned path was a starter kit: a CPU bundled with a Basic Panel and a stripped-down TIA Portal that already contained the project's CPU article number. The catalog numbers from the Siemens product list remain valid for bench commissioning today:

MLFB / Catalog Number Description
6AV6651-7AA01-3AA1 SIMATIC S7-1200 + KTP400 BASIC STARTER KIT
6AV6651-7DA01-3AA1 SIMATIC S7-1200 + KTP600 BASIC STARTER KIT
6AV6651-7HA01-3AA1 SIMATIC S7-1200 + KP300 BASIC STARTER KIT
6ES7212-1BD31-4YB0 S7-1200 CPU 1212C DC/DC/DC STARTER KIT
6AV6651-7AA01-3AA0 SIMATIC S7-1200 + KTP400 BASIC STARTER KIT (earlier variant)

These kits ship with the CPU, a Basic HMI panel (KTP400, KTP600, or KP300 depending on order), a power supply, Ethernet cable, and a 12-month TIA Portal licence. The CPU inside the kit is a fully functional 1212C or 1214C and can be used as a permanent bench controller once the development phase is over.

Prerequisites: Hardware, Software, and Firmware Requirements

To commission PLCSIM with an S7-1200 project, the following stack must align:

Layer Minimum requirement Notes
TIA Portal edition STEP 7 Basic V13 SP1 or later Portal V14 and above integrate PLCSIM as a built-in option ("Start simulation").
S7-PLCSIM version S7-PLCSIM V13 SP1 or later Earlier S7-PLCSIM V5.x supports S7-300/400 only.
S7-1200 CPU article CPU 1211C / 1212C / 1214C / 1215C / 1217C Selected in TIA Portal project tree.
CPU firmware (project) V4.0 or higher V4.0 unlocks the PLCSIM test interface on 1211C/1212C/1214C. 1215C/1217C require V4.1+. 1214FC/1215FC F-CPUs are simulated from FW 4.2 onward.
CPU firmware (real CPU if migrating later) ≥ project firmware version Flash with FW update from Siemens support portal if needed.
PC Windows 7 SP1 / 10 / 11 (64-bit) PLCSIM runs as a 32-bit COM server; 64-bit OS supported.
RAM 8 GB minimum, 16 GB recommended For multi-instance simulation or large HMI integration.
Ethernet Single NIC, TCP/IP only PROFINET IO is not simulated; PN device/PN controller to real devices must run on the real CPU.
User rights Administrator for first launch PLCSIM installs a virtual Ethernet adapter and a WinPcap/Npcap filter driver.
Critical: Setting the project CPU firmware below V4.0 and pressing "Start simulation" produces the error 0x80072EE2 ("The operation timed out") during the download handshake. Open the device properties of the S7-1200 CPU, select System > Firmware version, and confirm a value of V4.0 or higher before continuing.

PLCSIM Version Compatibility Matrix for S7-1200

The following matrix reflects the S7-1200 simulation capability of every released PLCSIM build. Use it to choose the smallest TIA Portal version that still meets the project's CPU firmware.

TIA Portal version S7-PLCSIM build S7-1200 simulation supported? Minimum CPU FW Notes
V11 / V12 none No — Use a real CPU (starter kit).
V13 (original) S7-PLCSIM V13 S7-300/400 only — S7-1200 still not in PLCSIM.
V13 SP1 S7-PLCSIM V13 SP1 Yes V4.0 First release that simulates 1211C/1212C/1214C.
V13 SP2 S7-PLCSIM V13 SP2 Yes V4.0 Adds 1215C/1217C support (FW 4.1).
V14 / V14 SP1 PLCSIM V14 Yes V4.0 / V4.1 PLCSIM now integrated in Portal ("Start simulation" toolbar).
V15 / V15.1 PLCSIM V15 / V15.1 Yes V4.2 Adds F-CPU simulation (1214FC/1215FC from FW 4.2).
V16 PLCSIM V16 Yes V4.4 Adds OPC UA server simulation; new event API.
V17 PLCSIM V17 Yes V4.5 Modbus TCP / TCP communication simulated.
V18 PLCSIM V18 Yes V4.5 / V4.6 Multi-instance simulation, secure communication.
V19 PLCSIM V19 Yes V4.6 Restored simulation of S7-1200 motion axis (limited).

Step-by-Step: Enabling PLCSIM for an S7-1200 Project

The following procedure uses TIA Portal V17 + PLCSIM V17 as the reference build. Earlier versions follow the same shape; later versions add a few extra wizards.

  1. Create or open the project. In the project tree, double-click Add new device > SIMATIC PLC > S7-1200 CPU. Choose the article number that matches the real controller (for example 6ES7214-1BG40-0XB0 for CPU 1214C DC/DC/DC, FW 4.5).
  2. Confirm the firmware. Select the CPU in the project tree, open Properties > System > Firmware version, and set the firmware to V4.5 (or whatever matches PLCSIM V17). If the dropdown is greyed out, the device was added from an older TIA Portal version and must be replaced with a current article.
  3. Write or import the program. Open the Program blocks folder, add an OB1 (cyclic main) and the required FBs / FCs / DBs. Migration from LOGO! Soft Comfort can use the LOGO! to S7-1200 migration tool shipped as a TIA Portal add-in (Portal V16 or later).
  4. Compile the program. Right-click the CPU → Compile > All (rebuild). Resolve every error before continuing; PLCSIM rejects a project with unresolved symbolic references.
  5. Launch PLCSIM. Click Online > Simulation > Start (or press Ctrl+Shift+S). Portal starts the PLCSIM instance, which opens a virtual S7-1200 faceplate. The status indicator turns cyan when the simulated CPU is in RUN-capable state.
  6. Download the project to the simulated CPU. Right-click the CPU → Download to device > All. PLCSIM uses the Softbus interface; no Ethernet configuration is required on the host PC. The download completes in 1–3 seconds for a typical project.
  7. Switch the simulated CPU to RUN. Click the green play button on the PLCSIM faceplate, or use Online > CPU operating panel > Run (RUN-P). The status LED turns green; OB1 begins cyclic execution.
  8. Open online diagnostics. Right-click the CPU → Go online > Online & diagnostics. The standard S7-1200 diagnostics buffer is fully available, with timestamped events identical to a real CPU.
  9. Observe tags. Open a watch table, drag the relevant tags from the project tree, click Monitor all (glasses icon). Values update in real time as OB1 executes.
  10. Force inputs/outputs. Right-click an input tag → Modify > Modify to 1. PLCSIM latches the forced value until released. Use this to drive the program through every branch without external wiring.
  11. Stop and reset. Use Online > Simulation > Stop to terminate PLCSIM, or click MRES on the faceplate to wipe the simulated retentive memory.
Tip: PLCSIM V17 and later allow multiple simulated CPUs on the same TIA Portal instance. Add additional S7-1200 devices to the project, repeat step 5, and a second PLCSIM window opens. Use this for multi-CPU projects, replicated line simulations, or testing S7 communication routes between controllers.

Starter Kit Alternative: Real CPU on the Bench

When the project must stay on TIA Portal V11/V12, when the CPU firmware is intentionally pinned below V4.0 to validate field behaviour, or when PROFINET IO behaviour must be tested, a starter kit is the safer path. The kits below are still orderable and carry the original MLFB numbers.

MLFB CPU inside HMI inside Power supply Typical use
6AV6651-7AA01-3AA1 CPU 1214C DC/DC/DC KTP400 Basic mono PN PM1207 included Single-station commissioning, training
6AV6651-7DA01-3AA1 CPU 1214C DC/DC/DC KTP600 Basic color PN PM1207 included Color HMI development
6AV6651-7HA01-3AA1 CPU 1214C DC/DC/DC KP300 Basic mono PN PM1207 included Key-panel operation simulation
6ES7212-1BD31-4YB0 CPU 1212C DC/DC/DC none (PLC-only kit) external Pure PLC development, no HMI
6AV6651-7AA01-3AA0 CPU 1214C (older revision) KTP400 Basic mono PN PM1207 included Spare/legacy

The CPU inside the kit can be flashed with the latest S7-1200 firmware using the Siemens SIMATIC Automation Tool or the TIA Portal Online & diagnostics > Firmware update wizard. After flashing, the CPU behaves exactly like the production CPU, which means every migration step from LOGO! to S7-1200 can be exercised offline.

Supported Simulation Features and Known Limitations

PLCSIM replicates the S7-1200 user program faithfully but not the hardware interfaces. The following matrix summarises what works and what does not.

Feature PLCSIM behaviour Engineer workaround
Cyclic OB (OB1) Full simulation —
Time-of-day OB (OB10 to OB17) Simulated; PLCSIM advances the clock —
Cyclic interrupt OB (OB30 to OB38) Simulated, default 100 ms cycle Cycle time configurable in PLCSIM API
Hardware interrupt OB (OB40) Simulated when triggered from PLCSIM API only Use the API TriggerInputEvent()
Startup OB (OB100) Full simulation —
Process inputs (I area) Forced through PLCSIM faceplate or API Use a watch table with "Modify"
Process outputs (Q area) Captured by PLCSIM faceplate; visible to user program —
PROFINET IO controller Not simulated Use the real CPU for IO commissioning
PROFINET IO device Not simulated Use the real CPU
PROFIBUS DP master/slave Not simulated on S7-1200 Use the real CPU
S7 communication (PUT/GET) Simulated between PLCSIM instances on the same PC Cross-PC requires Softbus IE-PG
Open User Communication (TCON/TSEND/TRCV) Simulated on TCP/IP; UDP partially Verify with a partner application
Modbus TCP server/client Simulated from PLCSIM V17 onward Use the "Modbus library" sample
Web server Not simulated Test on real CPU
SD card (recipe, data log) Not simulated in V13 SP1; partial in V16+ Test on real CPU
Recipes (Recipe management) Simulated via DBs; file storage not simulated —
Trace (function trace) Simulated; recordings visible in TIA trace viewer —
OPC UA server Simulated from PLCSIM V16 onward —
Fail-safe (F) programming Simulated from PLCSIM V15 (FW 4.2+) Validate on real CPU before deployment
Motion control TO (positioning axis) Limited simulation; no real axis Use real CPU for axis tuning
PID_Compact / PID_3Step Algorithm simulated; actual process not Use real process for tuning
High-speed counters (HSC) Simulated via API frequency generator Use SetInputCount()
Pulse generators (PTO/PWM) Not simulated Test on real CPU with motor or scope

Programmatic Verification: Watch Tables, Force Tables, and Traces

PLCSIM does not limit the engineer to manual observation. The same verification instruments used on the real CPU are available against the virtual instance.

Watch table pattern

Open Watch and force tables > Add new watch table. Configure the following columns for a clean diagnostic workflow:

Name           | Address    | Display format | Modify value
"Start PB"      | %I0.0      | BOOL           | 1
"Run motor"     | %Q0.0      | BOOL           | —
"Speed set"     | %MW10      | DEC+-          | 1500
"Actual speed"  | %MW12      | DEC+-          | —
"Fault"         | %MW20      | HEX            | —

Tick Monitor all to refresh every 200 ms, or use Monitor (slow) for one update per cycle. The simulated values change exactly as they would on a wired CPU.

Force table pattern

For repeatable test cases, use a force table. PLCSIM supports up to 30 forced tags simultaneously. Mark the Force column to latch a value across OB cycles, including across simulated CPU STOP-RUN transitions. Use this to lock motor-enable lines while testing interlocks, or to fix a sensor input while exercising a counting sequence.

Trace viewer

TIA Portal V15+ ships a function trace that records OB1 signals, OB35 interrupt signals, and any tag you select. Inside PLCSIM, recordings proceed normally and can be exported as .csv for offline analysis. Typical sample rates:

  • OB1 trace: 10 ms
  • OB35 trace: 1 ms (configurable to 0.5 ms)
  • High-speed trace (PLCSIM V17+): 0.1 ms (API-driven)

PLCSIM API for automation

For headless testing, drive PLCSIM from a .NET application using the Siemens SIMATIC S7-PLCSIM API. Minimal C# sample to set input I0.0 to TRUE for 100 ms:

var plc = new PlcInstance("S7-1200");
plc.Connect();
plc.WriteBool("I0.0", true);
System.Threading.Thread.Sleep(100);
plc.WriteBool("I0.0", false);
plc.Disconnect();

This API is documented in the SIMATIC S7-PLCSIM V17 Function Manual on the Siemens support portal.

Commissioning Workflow: From Simulation to Real CPU

PLCSIM catches the majority of program bugs before they reach hardware. The recommended handover sequence is:

TIA Portal PLCSIM (virtual S7-1200) Real CPU Watch/Force Trace HMI test Hardware FAT
  1. Unit test in PLCSIM. Run the entire program with simulated inputs. Document every input vector and expected output.
  2. Static analysis. Run Program > Compile > Consistency check. Resolve every warning before continuing.
  3. HMI test in PLCSIM. If the project includes a KTP400/KTP600/Comfort Panel, start the HMI runtime against PLCSIM via WinCC > Start runtime. Validate screens, alarms, and tag connections.
  4. Hardware FAT. Power the real CPU on the bench, set its IP to match the project, download the program, run the same input vectors, compare outputs to the PLCSIM run.
  5. On-site SAT. With real wiring connected, run the same vectors one more time. Only changes from the FAT log should be mechanical/electrical, not software.

Troubleshooting Matrix

Symptom Likely cause Remedy
"Start simulation" greyed out CPU article older than FW 4.0, or wrong CPU family Replace device with a V4.0+ S7-1200 article
Download to PLCSIM hangs at "Establishing connection" PLCSIM not running, or Softbus adapter disabled Start PLCSIM from the toolbar; check PLCSIM.VirtualSwitch service
Error 0x80072EE2 during download CPU firmware in project < 4.0 Update firmware in device properties
Inputs in PLCSIM always FALSE despite force Force not ticked in watch table Right-click column → "Force"
OB35 does not fire OB35 not configured in CPU properties Properties > System > Cyclic interrupts > Set OB35 to 100 ms
HMI runtime cannot connect to PLCSIM HMI connection points to wrong IP Set HMI connection to 127.0.0.1 or use the PLCSIM virtual adapter
PROFINET IO does not come up Not simulated Use real CPU; PLCSIM does not emulate IO devices
Web server page blank Not simulated Test on real CPU
PTO/PWM output no waveform Not simulated Use real CPU with motor or oscilloscope
SD card data log empty after run Limited simulation in V13/V14 Use real CPU, or upgrade to PLCSIM V16+
Diagnostics buffer missing events Buffer full (256 entries) Click "Clear buffer" in Online & diagnostics
PLCSIM window disappears on close Portal closed first Stop PLCSIM before closing TIA Portal to keep the project consistent
Multi-instance PLCSIM only opens one Softbus licence limit Each instance requires a separate PLCSIM licence (V14+)

FAQ

Can I test my S7-1200 program without any CPU at all?

Yes, if your TIA Portal installation is V13 SP1 or later and the CPU firmware in the project is set to V4.0 or higher, you can use S7-PLCSIM (Start simulation) to run the entire user program against a virtual S7-1200. For older TIA Portal versions (V11, V12, V13 original) you must use a real CPU, typically the S7-1200 starter kit (for example 6ES7212-1BD31-4YB0).

What is the minimum CPU firmware for S7-1200 simulation?

V4.0 for CPU 1211C, 1212C, and 1214C. CPU 1215C and 1217C require V4.1 or higher. F-CPUs (1214FC/1215FC) require V4.2 and PLCSIM V15 or later. Below these thresholds the simulation handshake times out with error 0x80072EE2.

Does PLCSIM support PROFINET IO for the S7-1200?

No. PLCSIM does not emulate PROFINET IO controllers or devices for the S7-1200. To commission PROFINET IO you must download the project to the real CPU. PLCSIM does simulate S7 communication (PUT/GET), Open User Communication over TCP, and from PLCSIM V17 onward, Modbus TCP.

Which starter kit should I buy for LOGO! to S7-1200 migration training?

For pure PLC development without an HMI, the 6ES7212-1BD31-4YB0 S7-1200 starter kit ships a CPU 1212C DC/DC/DC. For colour HMI development, the 6AV6651-7DA01-3AA1 kit bundles a CPU 1214C with a KTP600 Basic color PN panel. Both include the PM1207 power supply and a TIA Portal licence.

Can I run multiple S7-1200 simulations on one PC at the same time?

Yes, from TIA Portal V14 with PLCSIM V14 onward. Add multiple S7-1200 devices to the project, click Start simulation, and a separate PLCSIM faceplate opens for each CPU. Each instance requires its own PLCSIM licence seat. This is useful for testing S7 routes between two simulated CPUs.

Back to blog