Draft article / HMI / Display / en
Firmware and project backups for an HMI
The panel boots today, and that is the moment to capture its project and firmware, because those two files decide what service can do later.
The question this guide answers
Which HMI files should be preserved before service?
1. The two records that decide your options
Two records decide almost everything a service partner can do with your panel: the application project and the firmware version. The project is the master record of what the panel does, meaning the screens, the buttons, and the data connections to the controller. Firmware is the software inside the panel that runs the hardware. Neither alone is enough, which is why they travel together through this guide.

Diagram unavailable.
The project file is what lets a different unit take over. A Siemens Comfort Panel project lives inside a TIA Portal project, a Basic Panel project may sit in an older WinCC flexible project, and a PanelView Plus terminal loads from a FactoryTalk View Machine Edition application, usually archived as a single .apa file. Weintek panels carry an EasyBuilder project file. Whichever one you have, know its format and its tool.
Panel firmware is the second half of the pair. A runtime project generally needs a firmware version the engineering tool supports, and a replacement that ships with a newer or older revision may need a firmware update before your project loads. Record the version shown in the panel control panel or diagnostics screen, together with the order number that fixes the hardware generation.
Proof of what the panel runs right now is evidence too. Photograph the project or application name shown at runtime, the firmware version page, and any password or user administration state the machine depends on. If the project file cannot be found later, these images are often the only starting point for a rebuild.
2. What the firmware version changes
Firmware sounds like a detail until a replacement refuses the project. The runtime project is compiled against what the engineering tool supports, and the panel executes it only on firmware versions that match the hardware generation and the tool release. Record the version exactly as the panel shows it, because families release several firmware lines in parallel.

Diagram unavailable.
The pairing works in both directions. A replacement running newer firmware may need a downgrade or a project recompile. A replacement running older firmware may need an update before the engineering tool accepts it. Either way the step sits between the unit and the project, and knowing it in advance turns a surprise into a line in the plan.
A concrete case makes this real. Two Comfort Panels with the same screen and the same family name can differ in the trailing order number block, and that block can mean different hardware revisions with different firmware expectations. The panel that looks identical on the wall is not identical to the engineering tool.
Keep the limit in view. A recorded firmware version shows whether an update step exists, and it does not promise the update succeeds. Update availability for the exact reference, and license needs on the engineering station, are checks the manufacturer documentation and the provider perform.
Sources and scope (1)
- Rockwell Automation: PanelView Plus Terminals User Manual, publication 2711P-UM001. Documents application transfer and firmware context for the PanelView Plus range. It covers one family, not a cross brand procedure.
3. How to capture the backup while the panel runs
Take the backup while the panel still runs, not after the fault spreads. Most HMIs offer a service or transfer mode that stops the runtime and exposes the storage over Ethernet or a memory card. The exact path depends on the family, so write down the menu path you used. If the panel already fails to boot, note that as well, because it changes whether an on site backup is possible at all.

Diagram unavailable.
Do it before the weekend shift, not after, and treat the running panel as the opportunity it is. A panel that boots today is a panel you can interrogate: the project name, the firmware page, the transfer menu. None of that is available from a dead unit, and none of it gets easier with waiting.
The capture itself is usually one command or one wizard, but the surroundings decide whether it counts. A laptop on the wrong VLAN, a cable swapped with the office network, or a full memory card each stop the transfer halfway. Prepare the path first, then start the transfer, and watch it finish rather than assuming it did.
One boundary belongs here. These are generic steps that every family implements differently, and the exact menu names, tools, and card types come from the manufacturer documentation for your reference. Do not improvise a transfer procedure from memory on a panel that is the only copy of the machine project.
4. How to name, copy, and verify the backup
A backup only counts when it survives the next year, so treat the file like evidence. Name it after the machine and the date, not after the panel, because several panels can share a machine over the years. Copy it to at least two places. A backup that lives only on your laptop is one crash away from repeating the whole exercise.

Diagram unavailable.
If the file is encrypted or password protected, record who holds the password. An unreadable archive is a common dead end, and it usually surfaces at the worst moment, when the panel is already out of the machine. The password is part of the backup, and it needs an owner.
Verify the backup instead of trusting the file size. Where the tool offers a restore or consistency check that leaves the running panel alone, use it. Record the tool name and version that produced the file too, since a project saved by a much newer tool version may refuse to load on an older engineering station. Five minutes of checking now is cheap.
The limit is honesty about what verification proves. A consistent archive confirms the file is intact and loadable by that tool version. It does not prove the project compiles on today's licenses, and it does not capture passwords, recipes stored on the controller, or data that lives outside the panel.
5. What removable media add
Some families back up to removable media, and that route matters when the network is locked down. A Siemens panel can store its project and firmware on a SIMATIC memory card, and a Weintek panel can copy to USB storage. Where the Ethernet path needs approvals that take weeks, a card or a stick can be the difference between a backup today and a backup never.

Diagram unavailable.
The media carries its own rules. Cards are often family specific, and a card formatted by one panel generation may not be accepted by another. Write down which slot the card came from and which panel wrote it, because a card that lives in the panel is part of the backup story, not an accessory.
Treat the card as a copy, not as the backup. It stays inside a machine that floods, shakes, and runs hot, next to the panel it protects. Copy its contents to the same two places as the main file, and date the copy. A card plus a verified archive covers most of the storage risks at once.
Keep the limit visible: removable media shortcuts do not change what needs recording. Tool version, firmware version, and password owner belong to the card route exactly as they belong to the Ethernet route, because a restore always ends on the engineering station.
6. How backup status steers the route
With a verified project backup, your options widen. A replacement of the same reference accepts the project, a repair swap can be preloaded, and machine downtime shrinks to the transfer. The evidence to send is the project file, the firmware version, and the exact order number of the failed unit. That single file can turn a week of downtime into an afternoon.

Diagram unavailable.
Without a backup, the options narrow fast. The panel storage then holds the only copy of the machine project, so a repair that preserves the storage, or an exchange that keeps the original board, becomes preferable to a blank replacement. Say clearly in the request whether a backup exists. A service partner plans very differently in each case, and this single line saves a whole round of questions.
Put the status in writing, not in tone. Write backup verified, backup exists but unverified, or no backup, and add the tool version next to it. Each phrase triggers a different plan on the bench, and each one is honest in its own way. Partial knowledge labeled as partial is exactly what a reviewer can work with.
Backup status still has limits. It does not prove the project compiles today, that the engineering licenses are available, or that a replacement will be stocked at a given price. Those are separate checks, and the linked intake guides show which evidence carries them. Start the capture now, while the panel still talks to you. Ten minutes now beats ten days later.
How the flow works
Key takeaways
- Know the project format: TIA Portal, WinCC flexible, FactoryTalk .apa, or EasyBuilder.
- Record firmware version and order number next to the project file.
- Back up while the panel runs, verify the archive, and store it in two places.
- No backup means prefer a repair that preserves the panel storage.
Related pages
Editorial notes and sources
This preview is a bounded brief, not a reviewed technical article or a compatibility, stock, price, service, or safety claim.
Source ledger
Version: /how-it-works/#request-checklist|Technical evidence required
- /how-it-works/#request-checklist
- Technical evidence required
Workflow state
Status: draft / noindex
Unresolved: technical and commercial claims need attributable evidence; exact transfer menus, memory card types, and firmware update availability need the manufacturer documentation for the exact reference
