Problem Overview
WinCC Comfort, WinCC Professional, and the TIA Portal basic panels treat HMI tags as the smallest accessible unit. When an alarm word such as "AlarmWord" of data type WORD or INT is generated by the PLC program, the HMI cannot directly toggle one bit of that tag through standard tag configuration. A direct MOVE instruction in the PLC replaces the entire word and risks overwriting neighbouring alarm triggers. The challenge is to expose a single bit of a 16-bit word to an HMI operator (for acknowledge, reset, or test) without disturbing the other 15 bits and without bloating the PLC tag list.
This article documents four field-proven approaches for S7-1200 and S7-1500 controllers with TIA Portal V15.1 through V18:
- Slice access (symbolic bit access on S7-1200/1500).
- WinCC system function
SetBitInTag. - Absolute symbolic addressing on a non-optimized data block.
- A dedicated HMI interface DB that mirrors trigger bits into a word of bool tags.
Each method is compared for complexity, performance, and suitability for safety-relevant or audit-relevant alarm handling.
Prerequisites
- TIA Portal V15.1 or later (V16+ recommended for full SCL slice syntax support). Reference: Siemens TIA Portal programming and operating manual.
- STEP 7 for S7-1200/1500 with firmware V4.2 or higher for full slice access on tags and DB members.
- WinCC (Comfort/Professional) V15.1 or matching the TIA Portal version.
- HMI connection configured as an S7 connection (not OPC UA) so that bit-level access is permitted by the HMI runtime.
- PLC tag
AlarmWordof typeWORDin a non-optimized data block (required for absolute addressing methods). - Disable "Access optimization" on the DB if you intend to use absolute addresses. The attribute can be set per DB in DB properties → Attributes → Optimized block access.
Method 1 — Slice Access on S7-1200 and S7-1500
The S7-1200/1500 CPUs support direct slice access on tags of type BYTE, WORD, DWORD, LWORD, SINT, INT, DINT, and LREAL. This is the cleanest method when both the PLC logic and the HMI can be modified.
ST/SCL Example
// Slice syntax (SCL)
IF "AlarmWord".%X0 THEN // access bit 0 of AlarmWord
"HMI_Trigger_0" := TRUE;
END_IF;
"AlarmWord".%X7 := "OperatorAck_Bit7"; // write to a single bit
Ladder Logic Example
In LAD/FBD, the slice is dragged directly from the tag using the "Absolute address" dropdown in the tag operand. The tag will appear as "AlarmWord".X0 (a boolean operand) once you open the operand selection on a contact or coil.
| Slice Notation | Meaning | Bit Range |
|---|---|---|
"AlarmWord".%X0 |
Bit 0 (LSB of low byte) | 0 |
"AlarmWord".%X7 |
Bit 7 (MSB of low byte) | 7 |
"AlarmWord".%X8 |
Bit 8 (LSB of high byte) | 8 |
"AlarmWord".%X15 |
Bit 15 (MSB of high byte) | 15 |
"AlarmWord".%B0 |
Low byte | 0-7 |
"AlarmWord".%B1 |
High byte | 8-15 |
Slice access works for reading and writing in any block (OB, FB, FC, DB). It is also fully supported inside FBs with multi-instance capability. See the S7-1200/1500 programming reference for full syntax.
WORD in S7-1200/1500 is stored in little-endian (Intel) order. Bit 0 is the LSB of the low byte. If your external device or older S7-300 program is using big-endian / bit 0 at the MSB, you must either swap the bytes first ("AlarmWord" := SWAP("AlarmWord")) or use the slice indexes in reverse. See Siemens FAQ "Byte order within WORD and DWORD tags".Method 2 — WinCC System Function SetBitInTag
If the PLC program is locked (third-party OEM, signed library, or validated code that cannot be modified), use the HMI system function "SetBitInTag". This function sets or resets a specific bit of any tag reachable from the HMI without changing the others.
Configuration Steps
- Open the HMI tag list in TIA Portal and add the word tag
AlarmWord(acquisition mode: Cyclic continuous, or Cyclic on demand if the HMI only reads). - Create a button event on the screen (for example, Press event).
- Add system function SetBitInTag. Parameters: Tag =
AlarmWord, Bit = 0 to 15, Reset = FALSE for set, TRUE for reset. - To clear a bit, call the function again with the same tag and bit number, but enable the "Reset" input.
Properties Table
| Property | Value / Range |
|---|---|
| Function name | SetBitInTag |
| Tag data type | WORD, DWORD, INT, DINT (signed allowed, bit index absolute) |
| Bit index | 0 .. (tag length in bits − 1) |
| Reset input | 0 = set, 1 = reset |
| Acquisition mode | Cyclic continuous recommended |
| Update rate | 100 ms typical (1 s for non-critical alarms) |
WinCC also exposes SetBitInTag (while key is pressed) and InvertBitInTag. Reference: WinCC Engineering V16 — System Functions.
SetBitInTag issues a single tag write. The HMI driver maintains the read image; if acquisition mode is Cyclic on demand, the bit will not be re-read until the next trigger. Set acquisition to Cyclic continuous for guaranteed reflection in the HMI display.Method 3 — Absolute Symbolic Addressing on a Non-Optimized DB
This is the historical method from STEP 7 V5.5 and remains valid in TIA Portal. It uses a separate Bool tag in the same DB, with the HMI tag pointing to its absolute bit address inside the word.
DB Layout (Non-Optimized)
DATA_BLOCK "DB_Alarms"
{ S7_Optimized_Access := 'FALSE' }
VERSION : 0.1
NON_RETAIN
STRUCT
AlarmWord : WORD; // 16 trigger bits, byte 0-1
Spare1 : BOOL; // byte 2.0
Spare2 : BOOL; // byte 2.1
...
END_STRUCT;
END_DATA_BLOCK
Linking the HMI to a Single Bit
- Create a new HMI tag of type
BOOL. - In the HMI tag properties, switch the addressing mode from Symbolic to Absolute (or use Symbolic with S7 connection and reference the
"DB_Alarms".AlarmWord.x0syntax — TIA Portal V17+ accepts symbolic bit access directly). - Set address:
DB20.DBX0.0(bit 0 of byte 0 of DB 20). - Repeat for each bit that must be reachable from the HMI (DBX0.0 … DBX1.7).
Memory Map
| Absolute Address | Tag Name (suggested) | Bit |
|---|---|---|
| DB20.DBX0.0 | AlarmTrigger_00 |
0 |
| DB20.DBX0.1 | AlarmTrigger_01 |
1 |
| ... | ... | ... |
| DB20.DBX0.7 | AlarmTrigger_07 |
7 |
| DB20.DBX1.0 | AlarmTrigger_08 |
8 |
| ... | ... | ... |
| DB20.DBX1.7 | AlarmTrigger_15 |
15 |
The HMI sees 16 individual BOOL tags. Each one writes a single bit; the other bits of AlarmWord are untouched because the HMI driver uses the S7 "Write bit" primitive (single-bit PUT) rather than a word write. Reference: S7-1500 DB access modes (optimized vs. non-optimized).
AlarmWord can still use the full 16-bit value. The HMI's single-bit write is atomic and does not interfere with the 16-bit read in the PLC. If the PLC also writes that bit, the bit will appear to flicker if HMI write and PLC write are not synchronized — typically resolved by giving the HMI priority during operator action or by using a "Request" model rather than direct bit assignment.Method 4 — Dedicated HMI Interface Data Block
For larger alarm clusters (32+ alarms) or when the alarm word is generated by a library whose bit semantics are confidential, isolate the HMI-visible booleans in a separate interface DB updated by the application code.
Structure
DATA_BLOCK "HMI_Interface"
{ S7_Optimized_Access := 'FALSE' }
VERSION : 0.1
NON_RETAIN
STRUCT
AlarmWord_HMI : WORD; // copy of AlarmWord, refreshed every OB1
TriggerBits : ARRAY[0..15] OF BOOL; // 16 individual bool tags
END_STRUCT;
END_DATA_BLOCK
Update Logic (OB1 / Cyclic OB)
// SCL
"HMI_Interface".AlarmWord_HMI := "Application".AlarmWord;
// Replicate to bools for HMI bit access (looped for brevity)
FOR i := 0 TO 15 DO
"HMI_Interface".TriggerBits[i] := "Application".AlarmWord.%X[i];
END_FOR;
Advantages:
- Keeps the application DB protected; only the interface DB is exposed to the HMI.
- The HMI can read both the word and any individual bit without address conflict.
- Easy to add an Operator Acknowledge overlay that ORs into the mirror without affecting the source word.
Comparison of the Four Methods
| Criterion | Slice Access | SetBitInTag | Absolute Bool Tags | Interface DB |
|---|---|---|---|---|
| PLC code change required | Yes (small) | None | DB structure only | Mirror logic only |
| HMI code change required | Use slice in tag | Configure system function | Add 16 BOOL tags | Add 16 BOOL tags |
| Optimized DB supported | Yes | Yes | No | Optional |
| Read-modify-write race | No (atomic slice) | No (HMI-side atomic) | No (atomic single-bit PUT) | Possible (PLC loop) |
| Communication overhead | Low (one access per bit) | Medium (write per event) | Low | Medium (loop scan) |
| Suitable for F-runtime / TÜV | Yes (with care) | Less ideal (event-driven) | Yes | Yes (with documented mirroring) |
| Recommended for new projects | ★★★★★ | ★★★ | ★★★★ | ★★★★ |
Step-by-Step — Recommended Method (Slice Access)
- Open the PLC program in TIA Portal and navigate to the data block containing
AlarmWord. - Ensure the block attribute Optimized block access is set to your project's standard (slice access works in both modes for S7-1500; S7-1200 supports slice on DBs from firmware V4.0).
- Compile the project. Open the HMI tag list and add
AlarmWordas a tag of typeWORD. - For the individual bit, add a new HMI tag of type
BOOLwith PLC tag"DB_Alarms".AlarmWord.%X0(TIA Portal will accept symbolic bit access on a S7-1500/1200 connection). - Drag the BOOL tag onto a button or indicator in the HMI screen.
- Compile the HMI, download to the panel, and test with a watch table in the PLC: set
AlarmWordto16#0001and confirm the HMI bit 0 turns on; set bit 7 and verify bit 0 remains unaffected.
Verification Procedure
-
Watch table test in TIA Portal: enter
"AlarmWord" := 16#AAAA, force each bit, and confirm the HMI display updates within one acquisition cycle. - Cross-write test: from the HMI, write bit 0 = TRUE; verify in the watch table that only bit 0 changed (e.g., 16#0001 → 16#0000 does not happen on a neighbouring bit).
- Cyclic scan check: enable tracing on the S7 connection. The HMI driver should issue only one PUT per bit toggle, not a 16-bit word write.
-
Byte-swap sanity check: write
16#0100(bit 8) and confirm the HMI shows bit 8 active and bit 0 inactive. If the HMI shows the opposite, your external device is using big-endian and you must add aSWAPat the source.
Troubleshooting Matrix
| Symptom | Likely Cause | Fix |
|---|---|---|
HMI cannot find AlarmWord.%X0
|
Firmware too old (< V4.2) or wrong PLC family | Update CPU firmware or use Method 3 |
| Operator write clears other bits | HMI tag configured as WORD with full overwrite | Switch to BOOL tag pointing to slice or absolute bit |
| Bit ordering is reversed | Byte-swap between PLC and external device | Apply SWAP or remap bit indexes |
| Compiler error "Slice not supported" | DB has Optimized access on S7-1200 firmware < 4.0 | Update firmware or set DB to non-optimized |
| Tag shows greyed out in HMI | HMI tag not connected to S7 area pointer | Re-establish connection in Devices & Networks |
| Write succeeds in simulation but not online | PLC protection level requires password for write | Adjust protection level in PLC properties |
| Bit flickers at 1 Hz | PLC overwrites the same bit the HMI just wrote | Use acknowledge/request handshake or move bit to a status-only tag |
| Alarm class does not fire | Bit never reaches the alarm word | Use cross-reference (Ctrl+Alt+F) to find tag fan-out |
Edge Cases and Field Notes
-
Signed integers:
SetBitInTagon anINTorDINTtag works on the underlying bit pattern. Be aware that toggling the sign bit (bit 15 of INT, bit 31 of DINT) produces a value that the PLC will interpret as negative. Use aWORD/DWORDalias if the application expects only unsigned values. - Retentive behaviour: Writing a single bit through a non-optimized DB is also a single-bit PUT and updates the image; it is not a full word write. The PLC's startup OB does not need to re-initialise the word unless the tag is configured as retentive and the HMI is offline at startup.
- Performance: S7-1200/1500 single-bit PUTs are extremely fast (sub-millisecond on the backplane). The HMI driver packs consecutive bit writes into one telegram if the acquisition cycle aligns; do not assume each call is a separate request.
- Audit trail: For 21 CFR Part 11 or similar audit environments, prefer the interface DB method: the HMI writes to a separate OperatorAck tag, and the application code records the audit entry when it processes the request.
-
Web HMI / Unified Comfort Panel: TIA Portal V17+ supports the same slice notation. On WinCC Unified,
SetBitInTagis replaced by a JavaScript call:Tags("AlarmWord").WriteBit(0, true);. See WinCC Unified — Tag access via scripting.
FAQ
Can I write a single bit of a WORD tag from a WinCC HMI without modifying the PLC program?
Yes. Use the HMI system function SetBitInTag on the WORD tag and specify the bit index (0-15). Set the "Reset" input to 0 to set the bit, 1 to reset it. Acquisition mode should be "Cyclic continuous" so the HMI always sees the current value.
What is the correct slice syntax in TIA Portal SCL for a single bit of a WORD?
Use "MyWord".%X0 through "MyWord".%X15 for bits, "MyWord".%B0 and "MyWord".%B1 for bytes. Slice access is supported on S7-1200 firmware V4.0+ and all S7-1500 CPUs.
Why does my HMI show the wrong bit when the PLC writes 16#0100?
Byte ordering mismatch. The S7 stores the WORD little-endian: bit 8 is in the high byte. If your HMI panel or external device interprets the word big-endian, bit 0 will appear as the MSB. Add a SWAP("MyWord") at the source, or remap the bit indexes.
Do I need to disable optimized block access for slice access on S7-1500?
No. Slice access is fully supported on optimized DBs in S7-1500. You only need to disable optimization for the absolute-addressing method (Method 3) or when the HMI uses the legacy S7 PUT/GET mechanism without symbolic information.
How do I expose 32 alarm bits from a DWORD to a WinCC Comfort panel?
Create 32 HMI BOOL tags, each pointing to a slice of the DWORD: "AlarmDWord".%X0 through "AlarmDWord".%X31. Drag them onto indicators. Alternatively, configure a 32-tag array in a non-optimized DB and link the panel to DBX0.0 .. DBX3.7. The communication cost is one PUT per bit, and the PLC retains the 32-bit value as a single source of truth.