Overview: Siemens SIMATIC License Key USB Sticks
Siemens delivers SIMATIC software entitlements on physical USB sticks classified as Class A media. Each stick contains one or more cryptographically signed license keys that authorise the runtime of STEP 7, TIA Portal, WinCC, PCS 7, S7-PLCSIM, S7-SCL, and other SIMATIC engineering tools. Because the license keys are stored in a hidden, encrypted partition that is invisible to standard file system browsers, the only authoritative method to enumerate stick contents is the Automation License Manager (ALM), which Siemens bundles with every SIMATIC software release.
During commissioning, the standard engineering question is: how do I confirm that a stick I have just received from a Siemens order contains the license keys I paid for? This is especially important in regulated environments (pharmaceutical, medical device, GAMP 5) where installation qualification (IQ) protocols must demonstrate that delivered media is complete, uncorrupted, and bound to the correct MLFB line items. The procedure also applies retroactively: if a stick is found loose in a spares cabinet years after delivery, ALM is the only way to identify what software it entitles.
License Key Classes: A, B, C, and Floating
Siemens differentiates license keys by physical media and licensing model. The class is encoded in the MLFB suffix and dictates how the key is consumed at runtime.
| Class | Media | MLFB Suffix Pattern | Consumption Model |
|---|---|---|---|
| Class A (Klasse A) | USB stick (typically 2 GB+ with hidden partition) | ...-0KA5, ...-0KA8 | Single license; transferred to local hard drive C:\ or license server |
| Class B | USB stick + parallel port hardware key (legacy) | ...-0KB5 | Legacy dongle-based; requires parallel port hardware present |
| Class C | 3.5" floppy disk (legacy pre-2010) | ...-0KC5 | Historical distribution; floppy disk transfer to local drive |
| Floating (network) | USB stick (server-bound) | ...-0KA5 with "FLOATING LICENSE" descriptor | Network-wide checkout via Siemens License Server |
| Upgrade | USB stick | ...-0KA5 with "POWER PACK" or "UPGRADE" descriptor | Version migration requiring existing base license |
| Runtime / RT | USB stick | ...-0KA5 with "RUNTIME" descriptor | Target HMI/PC runtime, not engineering station |
Modern deliveries (post-2015) are almost exclusively Class A. The source MLFB 6ES7810-4CC10-0KA5 confirms a Class A delivery: the trailing 0KA5 suffix is the Class A marker in the Siemens ordering structure.
MLFB Number Decoding for Software Orders
The Siemens MLFB (Maschinenlesbare Fabrikatebezeichnung, or machine-readable product designation) is a structured code that uniquely identifies every product. Software orders follow the same convention as hardware orders. The example from the source is:
6ES7810-4CC10-0KA5
Field-by-field interpretation of this MLFB:
| Field | Value | Meaning |
|---|---|---|
| Prefix | 6ES7 |
SIMATIC S7 product family |
| Subcategory | 810 |
STEP 7 base system software |
| Variant | 4 |
Product variant identifier (software edition, language group) |
| Configuration | CC10 |
CC = Chinese localisation; 10 = STEP 7 V5.5 release marker |
| License class suffix | 0KA5 |
Class A; floating license variant; 1 concurrent user |
The descriptor in the order documentation further clarifies the entitlement. For 6ES7810-4CC10-0KA5 the full descriptor reads:
SIMATIC S7, STEP7 V5.5 CHINESE FLOATING LICENSE F.1 USER E-SW, SW AND DOCU. ON DVD, LICENSE KEY ON USB STICK KLASSE A, 2 LANGUAGES (E,C), EXECUTABLE UNDER WIN XP PROF CHINESE, WIN 7 PROF CHINESE, WIN 7 ULTIMATE, REFERENCE-HW: S7-300/400, C7
Five operative fields are extractable from this descriptor and must be cross-checked against the ALM contents:
- Software title — STEP 7 V5.5
- Language pack — English + Chinese (2 languages)
- License model — Floating License for 1 user
- Distribution media — DVD for software + USB stick for license key
- Supported operating systems — Windows XP Professional Chinese, Windows 7 Professional Chinese, Windows 7 Ultimate
Field 5 is the most commonly misread: a STEP 7 V5.5 Chinese license is not a generic STEP 7 V5.5 license. The same MLFB root with a different language code (e.g. 0AA5 for German, 0BA5 for English) is a different commercial product. The ALM tool displays the bound language; mismatching language is a known cause of "license not valid for this product" errors at install time.
Why a USB Stick Can Contain Multiple License Keys
Siemens bundles multiple license keys on a single USB stick whenever an order aggregates several software titles. Typical bundle structures include:
- STEP 7 Professional bundle — STEP 7 base + S7-PLCSIM + S7-SCL + S7-GRAPH on a single stick
- TIA Portal Engineer bundle — STEP 7 Professional + WinCC Professional + Safety Advanced
- PCS 7 component bundle — CFC + SFC + SCL + DOCPRO
- Multi-user site license — single physical stick shipped for an N-user floating license, where the stick remains with the license server and is not consumed per user
Each key is independent within the stick's hidden partition. Transferring one key to a target PC does not affect the other keys on the same stick, and individual keys can be moved back and forth repeatedly. This is critical for audit: a stick with n keys is valid for installing n distinct software products (or, for floating licenses, serving n concurrent users).
Automation License Manager: Installation
ALM is the only sanctioned tool to read, transfer, repair, and back up Siemens license keys. It is installed standalone on the IQ workstation so that the full engineering software does not need to be deployed for license verification.
- Insert the SIMATIC software DVD (or mount the ISO image) and run
Setup.exefrom the root. - When the component tree appears, deselect every product (STEP 7, WinCC, PCS 7, TIA Portal, etc.).
- Locate the Automation License Manager component in the tree; it appears as a sub-component under every SIMATIC setup. Tick only this checkbox.
- Accept the licence agreement and the default install path (
C:\Program Files\Siemens\Automation\Automation License Manager). - Complete the setup and reboot if prompted. ALM registers a Windows service and adds a Start menu entry under
SIMATIC > Automation License Manager.
Supported host operating systems for ALM (as of the V5.5 / V13 era referenced by the source MLFB) include Windows XP Professional SP3, Windows 7 Professional SP1, and Windows 7 Ultimate, matching the supported OS list of the underlying engineering software. Newer ALM releases (V6.x and later) extend support to Windows 10 and Windows Server 2016/2019/2022 for the host, although the license keys themselves remain bound to the software OS requirement, not the ALM OS requirement.
USB Stick Content Verification Procedure
Perform the following steps on any PC with ALM installed. The procedure is non-destructive — it reads but does not alter the stick contents.
- Insert the Siemens USB stick into a USB 2.0 or USB 3.0 port. Allow Windows several seconds to enumerate the device. Do not open the stick in Windows Explorer; the hidden partition will not be visible anyway.
- Launch ALM as administrator. The left-hand navigation pane shows two top-level nodes: Local License Keys (the host PC) and Network License Keys (the license server, if installed).
- Click the + next to Local License Keys. A sub-node labelled USB Stick appears when a Siemens Class A stick is detected.
- Right-click the USB Stick node and choose Display License Keys. The right-hand pane populates with one row per license key on the stick.
- For each row, record the following fields into the IQ worksheet:
- Software Product — e.g. STEP 7 V5.5
- License Key ID — 32-character hexadecimal identifier
- License Type — Single, Floating, Upgrade, Power Pack
- Validity — start date and (if applicable) end date
- Status — Valid, Used, Defective, Returned
- Coexistence — the host PC on which the key is currently installed, if any
- Export the entire list via File → Export → License Key List. ALM produces a
.csvand an.alkbackup file. Save both into the IQ evidence folder. - Right-click the USB Stick node and choose Properties to read the stick's serial number and total/free key slots; record these against the delivery note.
Mapping ALM Output to the Order Documentation
Once ALM has produced the key list, compare it line by line against the order documentation. The matching procedure is:
- Pull every MLFB line from the delivery note or invoice.
- For each MLFB, derive the expected software title, license model, and (if floating) the user count from the Siemens Industry Mall or the printed product description.
- Build an expected key list: one row per MLFB, with the expected software title and license model.
- Build the ALM actual key list as exported in the previous procedure.
- Reconcile expected against actual. Acceptable differences:
- A single MLFB can yield one key (single license) or one key plus service keys (CoL, Certificate of License for floating licenses).
- Multiple MLFBs can be combined onto a single physical stick when ordered together as a bundle.
- Unacceptable differences requiring escalation:
- An expected software title is missing from the actual list.
- The license type in ALM does not match the order (e.g. ordered Floating, delivered Single).
- Any key has status Defective or Unknown.
- The number of concurrent users on a floating license is less than ordered.
Installation Qualification (IQ) Protocol Worksheet
For GAMP 5 / 21 CFR Part 11 environments, document the audit result in a structured IQ record. The recommended fields and their data sources are:
| IQ Field | Expected Value Source | Actual Value Source | Acceptance Criterion |
|---|---|---|---|
| USB Stick Serial Number | Delivery note | ALM > USB Stick > Properties | Exact match |
| Number of License Keys on Stick | Sum of MLFB line items (one per line, unless bundled) | ALM > License Key List row count | Equal to expected |
| Software Product per Key | MLFB description | ALM > Software Product column | Exact match |
| License Type per Key | MLFB descriptor (Single/Floating/Upgrade) | ALM > License Type column | Exact match |
| Language Pack per Key | MLFB descriptor language code | ALM > Properties > Language | Exact match (E+C if "2 languages" ordered) |
| Signature Verification | Siemens signed | ALM > right-click key > Verify Signature | Signature valid |
| Status per Key | Valid | ALM > Status column | Valid |
| Backup File Generated | Required |
.alk file path |
File present, checksum recorded |
Sign and date the worksheet. Store the worksheet, the ALM-exported .csv, and the .alk backup in the controlled IQ document set.
Working with Floating Licenses on the License Server
For a floating license such as the STEP 7 V5.5 Chinese 1-user entitlement in the source MLFB, the USB stick is delivered to the license server administrator and remains with the server for the lifetime of the installation. The procedure is:
- On the license server PC, install ALM (the same installer as the engineering station).
- Insert the USB stick. ALM detects it under USB Stick.
- Drag the floating key from USB Stick to Local License Keys on the server. The key is copied (not moved) to the server's license storage; the stick retains a copy for re-deployment.
- On each client engineering station, install ALM and point it to the license server via Options → License Server → Add Server, entering the server's hostname or IP address.
- When a client opens STEP 7, ALM checks out the floating key from the server. When the client closes STEP 7, the key is checked back in and made available to the next user.
A 1-user floating license supports exactly one concurrent checkout. If a second client attempts to open STEP 7 while the first client holds the key, the second client receives a "no license available" error. This is by design and is the correct behaviour for a 1-user floating entitlement.
Recovering Defective or Lost Licenses
Siemens retains a central license database keyed on the MLFB and the original proof of purchase. If a USB stick is lost, physically damaged, or its key database becomes corrupted, the entitlements are recoverable. The standard procedure is:
- Identify the original MLFB and the matching invoice or purchase order number.
- If a backup
.alkfile exists from a prior ALM export, attach it to the recovery request; this accelerates re-issuance. - Open a license management case through the Siemens Industry Online Support portal at support.industry.siemens.com, or contact the regional Siemens sales office that issued the original order.
- Provide the case with the MLFB, the original order number, the end customer name, and the licence holder details.
- Siemens issues a replacement USB stick containing the recovered keys, shipped to the registered end customer address.
Typical lead time for a standard recovery is 5–10 business days in EU/US regions. Recovery of a missing or never-received stick follows the same path, but the request must be raised within the warranty period of the original order for a no-charge replacement; outside the warranty period, a re-licensing fee may apply.
Troubleshooting Matrix
| Symptom | Most Likely Root Cause | Resolution |
|---|---|---|
| ALM does not list the USB stick at all | USB enumeration or power issue; ALM not run as administrator | Re-seat stick, try a different USB port (preferably rear-panel USB 2.0), re-launch ALM with elevated privileges |
| Key present on stick but setup rejects it as invalid | Version mismatch (e.g. V5.5 key presented to a V5.6 installer); wrong language pack | Match the installed software version exactly; check the ALM language field against the installed language |
| Key status shows "Defective" | Cryptographic signature mismatch, hidden partition corruption | Restore the key from a prior .alk backup; if no backup, request Siemens recovery |
| Floating key shows "Already in use" on a second client | First client did not return the key (crashed, network drop) | Wait for the ALM lease timeout (default 30 minutes), or manually return the key on the holding client via ALM |
| ALM reports a different number of keys than the delivery note suggests | Bundle was split across multiple sticks; multiple MLFBs aggregated to one stick | Reconcile every MLFB line item; check that no second stick is in the same delivery |
| Stick is detected but no keys appear | Hidden partition damaged by user attempting to format the stick | Do not attempt to format a Class A stick; escalate to Siemens recovery |
| Stick prompts for formatting in Windows | Windows sees only the public partition; user accepted the prompt and formatted the hidden partition | Stop using the stick immediately; the keys on the formatted partition are unrecoverable without Siemens intervention |
| License Manager service fails to start | Corrupted ALM install, Windows service account insufficient | Reinstall ALM with default service account (Local System); reboot |
Best Practices for License Key Audits
- Maintain a central license register indexed by MLFB, license key ID (the 32-character hex value from ALM), assigned PC or license server, and current status (Available, In Use, Returned, Defective).
- Export the ALM key list to
.csvand.alkfiles at every IQ event and every annual review. Store the exports in a controlled, write-once location (e.g. the document management system) and record the SHA-256 checksum to detect later tampering. - Store the physical USB sticks in ESD-safe containers in a fireproof media safe. The stick is the only physical token of the entitlement; if both the stick and the recovery backup are lost, recovery becomes a manual legal entitlement case.
- Never write non-license data to the USB stick. Windows may offer to format the stick if the public partition fills up; refusing the format and using a separate USB drive for data transfer is the correct procedure.
- For floating licenses, document the license server hostname, the server's MAC address, and the physical stick's serial number in the same register. If the server hardware is replaced, the floating key transfer is trivial; if the stick is also lost, recovery requires both pieces of evidence.
- For regulated environments, perform the ALM verification on a dedicated IQ workstation that is itself under change control. The verification PC should not be used for engineering work to avoid accidental key checkout during the audit.
- Periodically reconcile the ALM key inventory against the Siemens Industry Online Support entitlement report (downloadable by registered customers) to detect drift between the purchased entitlement and the deployed entitlement.
Compatibility Notes: STEP 7 V5.5 / TIA Portal Coexistence
A subtle audit point: a STEP 7 V5.5 license is not interchangeable with a TIA Portal STEP 7 Professional license, even though both are commonly referred to as "STEP 7". The MLFB structure differs:
-
Classic STEP 7 V5.x — MLFB family
6ES7810-4xx10-0KA5(the source example). Runs on Windows XP/7 only. -
TIA Portal STEP 7 Professional — MLFB family
6ES7822-1AExx-0YA5. Runs on Windows 7/10/11.
If a customer migrates from V5.5 to TIA Portal, the V5.5 floating key is reusable only as an upgrade entitlement for the TIA Portal equivalent; it does not directly authorise the new software. The upgrade requires a separate "Power Pack" MLFB to convert the entitlement. The IQ worksheet must capture which family the key belongs to, because the ALM column for "Software Product" shows the version string (V5.5 or V13/V14/V15/V16/V17/V18) and the audit team must verify this matches the installed software.
Backup and Restore with the .alk Format
ALM exports a backup in its native .alk (Automation License Key) format. The backup contains every key currently visible in the ALM tree (USB stick + local PC + license server). The format is encrypted and signed; it can be restored only on the same Windows installation or on another installation of the same Siemens software family, via File → Import → License Key Backup.
A robust IQ practice is to back up the entire ALM environment weekly, on a dedicated backup share with at least 30 days of retention. This is the fastest recovery path for a defective or corrupted local key store, and it reduces the dependency on Siemens' central recovery service for routine accidents.
FAQ
How do I list all license keys on a Siemens USB stick without installing the full SIMATIC software?
Install only the Automation License Manager component from any SIMATIC setup, launch it as administrator, insert the stick, and read the key list under Local License Keys > USB Stick > Display License Keys. Export to .csv for documentation.
How can I tell from the order which license keys should be on the stick?
Take each MLFB line from the delivery note or invoice and look up its description in the Siemens Industry Online Support portal. The descriptor (for example SIMATIC S7, STEP7 V5.5 CHINESE FLOATING LICENSE F.1 USER ... LICENSE KEY ON USB STICK KLASSE A) names the software title, language pack, license model, and class.
What should I do if a license key shows status "Defective" in ALM?
Stop using the key. Restore it from a prior .alk backup if available. If the key is unrecoverable from a backup, open a license recovery case with Siemens via the Industry Online Support portal, providing the MLFB, original invoice number, and the failing key ID.
Can a single Siemens USB stick hold multiple license keys?
Yes. Whenever a single order aggregates several software titles (for example STEP 7 base + S7-PLCSIM + S7-SCL, or a TIA Portal engineer bundle), Siemens ships one USB stick with the corresponding number of independent license keys in its hidden partition. Each key can be transferred independently.
Is a STEP 7 V5.5 license key usable with TIA Portal?
Not directly. A STEP 7 V5.5 floating license (MLFB family 6ES7810-4xx10-0KA5) covers the classic STEP 7 V5.x only. To run TIA Portal STEP 7 Professional, a separate TIA Portal MLFB (family 6ES7822) is required, or a Power Pack upgrade must be purchased to convert the V5.x entitlement.
What is the difference between Class A, Class B, and Class C license keys?
Class A is the modern USB stick delivery, used since around 2010. Class B was a USB stick plus legacy parallel port hardware key. Class C was a 3.5" floppy disk delivery used before 2010. All three classes are managed by the same Automation License Manager; the class only affects the physical media, not the way the key is consumed at runtime.