Technical guide · Automation · SCADA · IEC 61850

Substation automation: how field devices, IEDs, SCADA, and operations work as a single system

An automated substation must do more than carry signals. It has to preserve the meaning of each piece of information, recognize its quality, record when the event occurred, control who can issue commands, and respond predictably when part of the architecture fails. This guide follows the path of data and commands — from the primary equipment to the operations center — and shows what needs to be specified, integrated, tested, and maintained.

Walk through the architecture
ProcessBayStationNetworkSCADAOperations
Content:
POWER Engineering
Updated on
September 2026
Technical reading:
approximately 24 minutes

Automation · SCADA · IEC 61850 · GOOSE · Networks · Synchronism · Retrofit

In summary

Automation is a chain

Sensors, contacts, IEDs, controllers, network, servers, gateways, HMI, and operations centers only form a system when data, commands, and responsibilities are coordinated.

Connecting is not integrating

Available communication does not prove that names, states, quality, timing, logic, interlocks, and fault responses are correct.

Going digital changes how you test

When functions depend on shared messages and configurations, integrated testing, version management, and documentation become part of operational availability.

Chapter 1

What is substation automation?

Substation automation is the coordinated set of functions, equipment, networks, software, and procedures that makes it possible to observe the electrical process, execute controls, record events, exchange information, and support operation safely.

It can range from an architecture with hardwired signals, a remote terminal unit, and a local SCADA to a system based on IEDs, IEC 61850 data models, device-to-device communication, and a process bus. Between these extremes there is a wide variety of hybrid solutions — and many real installations will remain hybrid for years.

For this reason, automation should not be defined by the presence of a protocol, a server, or a screen. The more useful question is another:

Technician working on control wiring beside a row of substation cubicles
Wiring integration of a SCADA panel in a power substation in Queens, New York. Field record by the MTA, 2019.Foto: MTA Capital Construction Mega Projects · CC BY 2.0

A substation automation system, also called SAS in many projects, can bring together:

  • aquisição de estados, grandezas e alarmes;
  • comandos locais e remotos;
  • intertravamentos e sequências;
  • registro cronológico de eventos;
  • supervisão por IHM/SCADA;
  • comunicação com centros de operação;
  • integração de relés de proteção, controladores e sistemas auxiliares;
  • sincronização de tempo;
  • armazenamento de eventos, históricos e diagnósticos;
  • engenharia, manutenção e gestão de configurações.

Not all functions need to be centralized. Critical protection and interlocks can remain distributed across the IEDs; supervision can be redundant; communication with the center can go through gateways; and legacy equipment can remain connected through contacts or different protocols. The appropriate architecture arises from the operational requirements, the risk, and the life cycle — not from an isolated preference for technology.

To understand the chain that detects electrical conditions and produces protection operations, see the substation protection and control guide .

Chapter 2

A jornada do dado — e o caminho de volta do comando

A value on the screen looks simple: “breaker open”, “current of 412 A”, “protection operated”. But before it reaches the operator, this information travels through a physical and logical chain.

Consider the position of a circuit breaker. Auxiliary contacts represent its state. The information is acquired by an input, interpreted by an IED or controller, and associated with a model. The device assigns state, quality, and time. The network transports the update. The server or gateway processes and distributes the point. The HMI presents the result. If there is remote integration, the operation center also receives it.

The visible value is only the last step. To trust it, engineering needs to answer:

  • qual é a origem do dado?
  • o estado é simples ou usa dupla indicação?
  • o valor está válido, antigo, bloqueado, substituído ou em teste?
  • qual equipamento produziu o timestamp?
  • o relógio desse equipamento estava sincronizado?
  • o que ocorre se um contato ficar inconsistente?
  • como o sistema registra uma mudança durante falha de comunicação?

O comando percorre o caminho inverso, mas exige salvaguardas adicionais. Uma ordem de abertura ou fechamento pode envolver:

  1. 1.identification of the user and the command origin;
  2. 2.definition of authority — local, station, or remote;
  3. 3.object selection and operation confirmation, according to the adopted model;
  4. 4.verification of blocks, permissives, and interlocks;
  5. 5.transmission to the responsible device;
  6. 6.activation of the output circuit;
  7. 7.time supervision and position feedback;
  8. 8.registro da tentativa, do resultado e de eventuais falhas.

Not every project uses the same command model. What matters is that the sequence is specified, applied consistently, and tested end to end.

Sentido da supervisão — do processo ao operador
  1. Equipamento primário
  2. Interface de processo
  3. IED / controlador de bay
  4. Rede da estação
  5. SCADA / gateway
  6. Centro de operação
O dado carrega:valor / estadoqualidadetimestamporigem
Sentido do comando — do operador ao processo
  1. Centro / operador
  2. Autoridade
  3. Seleção / validação
  4. Intertravamento
  5. Execução
  6. Retorno de posição

The minimum context package

A piece of operational information should be treated as something larger than an isolated value:

The minimum context package that accompanies a piece of operational information
ElementoPergunta que responde
Valor ou estadoO que está acontecendo?
Identification / originEm qual equipamento e ponto?
QualityPosso confiar neste dado agora?
TimestampQuando a condição ocorreu?
Causa ou contextoFoi espontâneo, comandado, bloqueado ou colocado em teste?

Without these elements, the system can remain “online” and still lead to a wrong interpretation.

Chapter 3

As quatro camadas da arquitetura

Dividing automation into layers helps to locate functions, interfaces, and responsibilities. The boundaries are not rigid, but the model is useful for specification and fault analysis.

Nível de processo

Sensores, TCs e TPs, disjuntores, seccionadoras e unidades de interface. É o ponto em que a automação encontra o sistema elétrico — e onde erro de polaridade, relação, fiação, mapeamento, tempo ou atuação pode virar informação incorreta ou operação indevida.

Nível de bay ou vão

IEDs de proteção, controladores de bay, medidores, registradores e lógicas locais associados a uma posição funcional. Reúne aquisição, medição, proteção, intertravamento, sequências, execução de comandos e concentração de diagnósticos.

Nível de estação

Rede, servidores de automação e SCADA, estações de operação e engenharia, gateways, sincronismo, históricos, alarmes e registro de eventos. É a camada de coordenação local, onde muitos dados ganham uma representação operacional consolidada.

Nível de operação

Centros locais ou remotos de controle, sistemas corporativos autorizados e canais de acesso remoto controlado. Não deve ser confundido com acesso irrestrito à rede de estação: exige limites, responsabilidades, monitoramento e critérios de segurança.

Os limites não são rígidos: proteções e intertravamentos críticos podem permanecer distribuídos nos IEDs, a supervisão pode ser redundante e equipamentos legados podem continuar conectados por contatos ou protocolos distintos. O diagrama não representa um fornecedor ou produto específico.

Process level

This is where automation meets the electrical system. It includes circuit breakers, disconnectors, transformers, sensors, CTs and VTs, contacts, actuators, and, when adopted, process interface units or merging units. In conventional architectures, currents, voltages, and states reach the panels through copper cables. In process-bus architectures, part of these quantities and states can be digitized closer to the primary equipment and transported over the network.

The process level is not “just the field”. It is the point where an error of polarity, ratio, wiring, mapping, time, or operation can turn into incorrect information or improper operation.

Bay level

It brings together devices associated with a functional position of the substation: protection relays, bay controllers, meters, recorders, and local logic. At this level there can be acquisition and validation of states, metering, protection, interlocking, local sequences, command execution, publishing and subscribing of messages, and concentration of the equipment’s own diagnostics.

Distributing functions by bay can reduce dependence on a central server, but it requires consistency between devices, files, and versions.

Station level

It is the local coordination layer. It can include automation and SCADA servers, operation and engineering workstations, telecontrol gateways, switches and network infrastructure, synchronism services, historical data, alarms, and event logging, in addition to controllers for functions common to the substation. It is at this level that much of the data gains a consolidated operational representation — and where inconsistencies in naming, alarm priority, screens, permissions, and communication become most visible.

Operation level

It includes local or remote control centers, authorized corporate systems, analysis applications, and controlled remote-access channels. Communication can use protocols and gateways defined by the utility or the project. The operation level must not be confused with unrestricted access to the station network. Integration requires clearly defined limits, responsibilities, monitoring, and security criteria.

Chapter 4

Who does what within the system

Siemens SIPROTEC 7SA612 digital relay installed in a panel, with display, status indicators, and configuration keypad
Digital distance protection relay installed in a panel: local functions, signaling, and configuration interface on a real IED.Foto: Bad-reg · CC BY-SA 3.0

Terms such as IED, RTU, gateway, and SCADA sometimes appear as if they were equivalent. They are not. The exact function varies by project, but the separation below helps to build a consistent scope.

Typical roles and the engineering question associated with each component
ComponentePapel típicoQuestão de engenharia
IED de proteçãomede, executa funções de proteção, registra e pode controlarQuais funções permanecem autônomas durante perda da estação?
Controlador de bayaquisição, comando, intertravamento e sequências do vãoOnde reside a autoridade e como são tratados estados inconsistentes?
UTR/RTUaquisição, concentração e telecontroleQuais pontos, tempos, qualidades e comandos são disponibilizados?
Gatewayconversão, concentração e fronteira entre sistemas/protocolosComo evitar perda de semântica e rastrear cada mapeamento?
Servidor SCADAprocessa dados, alarmes, eventos, históricos e comandosO que acontece na perda do servidor principal?
IHMapresenta o processo e recebe ações do operadorA tela revela qualidade, autoridade e consequência da ação?
Switch gerenciávelencaminha tráfego e aplica recursos de redeA configuração, supervisão e redundância foram documentadas e testadas?
Fonte de tempodistribui referência temporalQue precisão as funções realmente exigem e como a perda é indicada?
Estação de engenhariaconfigura, diagnostica e mantém dispositivos/sistemaComo acesso, versões, backups e alterações são controlados?
Centro de operaçãosupervisão e controle remoto de instalaçõesQuais responsabilidades pertencem à subestação e quais ao centro?

A single piece of equipment can accumulate roles. This does not remove the need to describe them. When different functions reside in the same device, a common failure can affect all of them; when they are distributed, dependencies on network, time, and coordination arise.

The functional inventory comes before the catalog

Selecting equipment without consolidating functions usually produces gaps or overlap. Before choosing models, it is best to map:

  • dados que devem ser adquiridos;
  • comandos e origens permitidas;
  • lógicas e intertravamentos;
  • eventos que exigem timestamp na origem;
  • disponibilidade e modos degradados;
  • interfaces com proteção, medição, serviços auxiliares e telecomunicações;
  • requisitos do centro de operação;
  • manutenção, acesso e recuperação;
  • expansão futura.
Chapter 5

Control, authority, and interlocks

The most dangerous command is the one that reaches the correct equipment without the system having verified the correct context. A control architecture must make clear:

  • quem pode comandar;
  • de onde pode comandar;
  • qual origem tem prioridade;
  • como ocorre a transferência entre local, estação e remoto;
  • quais permissivos e intertravamentos são avaliados;
  • como bloqueios de manutenção são aplicados e apresentados;
  • como a execução e o retorno são supervisionados;
  • o que é registrado para análise posterior.

Local, station, and remote

“Local/remote” cannot be just a label on the HMI. The position of selector switches, equipment states, user permissions, and internal logic must result in an unambiguous authority model.

If two sources can act simultaneously without a defined rule, automation creates conflict instead of coordination. If the transfer of authority is not recorded, the investigation of an event loses context.

An interlock is not just a screen message

An interlock prevents or conditions an operation based on the state of the process. Its implementation can be electrical, logical, mechanical, or a combination. The choice depends on criticality, requirements, and the project’s philosophy. For each command, document:

  • condições permissivas;
  • condições impeditivas;
  • origem de cada estado utilizado;
  • comportamento diante de dado inválido ou comunicação perdida;
  • possibilidade e governança de bypass;
  • mensagem apresentada ao operador;
  • evidência registrada no evento;
  • testes positivos e negativos.

Testing only the “happy path” proves little. It is necessary to verify the block when a condition is not met, when a data point is invalid, and when a dependency disappears.

Confirmation and feedback

Issuing an output does not mean the equipment changed position. Automation must distinguish, where applicable: command accepted; command sent; output activated; movement started; final position reached; time exceeded; inconsistent position; circuit failure or unavailability. This distinction reduces ambiguity for operation and improves field diagnostics.

Chapter 6

SCADA: more than screens and symbols

SCADA turns distributed data into an operational view. Its quality depends as much on screen design as on the engineering behind it. Functions can include acquisition, processing, alarms, events, historical data, commands, calculations, reports, data exchange, and supervision of the infrastructure itself. In installations subject to ONS requirements, the applicable scope must be verified directly in the Grid Procedures and in the project documents.

Qualidade do dado

A value needs to indicate when it should not be interpreted as normal. Depending on the system and protocol, the quality can reflect situations such as:

  • dado inválido;
  • comunicação interrompida;
  • valor antigo;
  • ponto bloqueado;
  • valor substituído;
  • ponto em teste;
  • transbordo ou fora de faixa;
  • origem não sincronizada.

Hiding quality or indiscriminately converting it to “zero” creates false certainty. On the HMI, invalid states must be perceptible without visually competing with real alarms.

Eventos, alarmes e SOE

An event is a recorded change. An alarm is a condition that requires attention or a response from the operator. Not every event should become an alarm. A good alarm design seeks to avoid:

  • avalanches que encobrem a causa inicial;
  • mensagens duplicadas para a mesma condição;
  • alarmes permanentes sem ação possível;
  • prioridades definidas apenas pela categoria do equipamento;
  • texto vago, sem indicação da condição ou consequência;
  • ausência de registro de reconhecimento e normalização.

The sequence-of-events record, often called SOE, helps to reconstruct the order of an event. Its usefulness depends on the timestamp at the source, synchronism, time resolution, and preservation during communication outages.

A situation-oriented HMI

The screen must help the operator perceive the state and act safely. This means:

  • hierarquia clara entre visão geral e detalhe;
  • uso contido de cor;
  • destaque reservado a anomalias e estados que exigem atenção;
  • apresentação de autoridade, bloqueios e qualidade;
  • navegação consistente;
  • nomes que correspondam à documentação e ao centro de operação;
  • confirmação compatível com a consequência do comando.
Operator in an energy control room with a synoptic panel and SCADA supervision stations in Yokosuka
Operation of electrical loads in the SCADA room in Yokosuka, Japan, in 2011. A real example of coexistence between a mimic panel and computerized supervision.Foto: Joe Schmitt / U.S. Navy · Domínio público

A visually sophisticated screen, but without quality, origin, or block information, is still an incomplete interface.

Chapter 7

Protocolos: cada um resolve uma parte do problema

There is no “best protocol” apart from the use case. The design must define which information needs to flow, between which participants, and with what performance, semantics, availability, and security.

Communication technologies, typical use, and main engineering focus
TecnologiaUso típicoAtenção principal
IEC 61850 MMScomunicação cliente-servidor, relatórios, dados e controles no ambiente da estaçãomodelo de dados, datasets, reports, qualidade e comportamento de comando
IEC 61850 GOOSEtroca rápida de eventos e estados entre dispositivos por publicação/assinaturamatriz de mensagens, desempenho, supervisão, VLAN/prioridade e testes de perda/recuperação
IEC 61850 Sampled Valuespublicação de amostras de correntes e tensões, especialmente em barramento de processosincronismo, desempenho de rede, engenharia de streams e comportamento degradado
IEC 60870-5-104telecontrole sobre redes IP, comum na integração com centros de operaçãomapeamento, causas de transmissão, qualidade, comandos, tempos e disponibilidade do canal
DNP3 / IEEE 1815telecontrole e integração entre RTUs, IEDs e sistemas mestresclasses/eventos, variações, timestamps, qualidade, controles e perfil aplicado
Modbusintegração de equipamentos e sistemas auxiliares com modelo de registradoressemântica documentada, escala, polling, qualidade e limitações do equipamento
Contatos físicosestados e atuações cabeadassupervisão de circuito, quantidade de cabos, documentação e testes físicos

GOOSE

Station / process bus

Fast events and states between functions and IEDs, via publish/subscribe.

MMS

Station environment

Data, reports, commands, and client-server services of IEC 61850.

Sampled Values

Process bus

Current and voltage samples close to the primary equipment, when adopted.

IEC 60870-5-104

Integration with the center

Telecontrol over IP networks, according to the project standard.

DNP3 / IEEE 1815

Telecontrole e RTUs

Integration between RTUs, IEDs, and master systems, according to the applied profile.

Modbus

Auxiliary systems

Integration of equipment and auxiliary services through a register model.

Contatos físicos

Interfaces cabeadas

States and operations that can remain due to requirement, legacy, or segregation.

MMS, GOOSE, and Sampled Values are not synonyms

In IEC 61850, different services meet different needs. MMS is associated with client-server communication and structured access to data and services. GOOSE uses publish/subscribe to distribute events and states with performance suited to fast functions, as defined by engineering. Sampled Values publishes samples of electrical quantities and is tied to the use of a process bus.

An installation can use MMS and GOOSE without adopting Sampled Values. It can also integrate legacy equipment through other protocols. Saying that a substation “has IEC 61850” does not yet describe its architecture.

Protocol conversion is not automatic conversion of meaning

A gateway can transform representations, but engineering needs to decide:

  • como o ponto é nomeado;
  • qual unidade e escala serão usadas;
  • como estados e qualidades correspondem;
  • qual timestamp será preservado;
  • como eventos espontâneos são tratados;
  • como comandos e retornos são mapeados;
  • o que ocorrerá quando um lado perder comunicação.

When this equivalence table is not controlled, the integration becomes dependent on the tacit knowledge of whoever configured it.

Chapter 8

IEC 61850: model, services, and engineering

Treating IEC 61850 as merely “another Ethernet protocol” hides an important part of its value. The series establishes a common structure to represent functions and data of the electrical domain, communication services, and a system configuration language.

Semantics before the address

In traditional integrations, much of the meaning resides in external lists of registers or points. In IEC 61850, data is organized into standardized models, with classes and attributes that help tools and systems understand what is being represented. This does not remove the engineering. It increases the possibility of consistency — provided that naming, model extensions, datasets, controls, and files are treated as system deliverables.

SCL: the system described in files

The SCL language, defined in IEC 61850-6, allows describing IED capabilities, functions, topology, and communication configuration for exchange between tools. Files found in the engineering cycle include, depending on the edition, tool, and adopted process:

  • ICD: IED capability description;
  • SSD: system specification;
  • SCD: configured description of the substation as a whole;
  • CID: configuration intended for an IED;
  • IID: instantiated description of an IED for engineering exchange.

The SCD file deserves special attention because it coordinates relationships between multiple participants. It should not exist only as an occasional export. It is necessary to define its official source, owner, version, validation, and update process.

Interoperabilidade precisa ser demonstrada

Standard conformance and declared service support are important foundations, but they do not replace application validation. Differences in edition, model, interpretation, options, tools, and behavior can affect the integration. A multi-brand FAT must verify, among other things:

  • importação e exportação SCL;
  • associação e comunicação cliente-servidor;
  • datasets e report control blocks;
  • publicações e assinaturas GOOSE;
  • atributos de qualidade e tempo;
  • modelos de comando;
  • reinício e reconexão;
  • diagnósticos e alarmes de comunicação;
  • comportamento após alteração de configuração.

Station bus and process bus

The station bus connects devices and systems at the bay and station levels. The process bus brings digitalization and communication closer to the primary equipment, and can transport states, commands, and sampled values.

A process bus can reduce wiring and expand supervision possibilities, but it also changes the nature of the dependencies. Network, synchronism, configuration, testing, and maintenance become even more decisive. The decision must consider the full life cycle, the available competence, and the expected behavior under faults — not just the reduction of cables.

Chapter 9

Networks, topologies, and redundancy

Technician preparing fiber-optic connections beside a control cabinet at B11 substation
Splicing and identification of optical fibers in a control cabinet of substation B11, on the MTA’s East Side Access project, 2018.Foto: MTA Capital Construction Mega Projects · CC BY 2.0

The automation network is a functional part of the system. Its design must consider traffic, latency, availability, maintenance, segregation, expansion, and diagnostics.

Estrela

Dispositivos conectados a switches centrais ou de acesso. Arquitetura clara e fácil de segmentar; a disponibilidade depende de como switches, uplinks, fontes e caminhos são distribuídos.

Anel

Com protocolos de recuperação, existe caminho alternativo após certas falhas. O tempo de recuperação e o efeito sobre as funções dependem do protocolo, da configuração e do tamanho da rede.

PRP

Duas LANs independentes recebem os mesmos quadros; o destino aceita o primeiro e descarta a duplicata. Definido na IEC 62439-3.

HSR

Quadros enviados nas duas direções de um anel; os nós processam o primeiro recebido e tratam duplicatas. Definido na IEC 62439-3.

Estrela e anel

In a star topology, devices connect to central or access switches. The architecture is clear and can be easily segmented, but availability depends on how switches, uplinks, power sources, and paths are distributed. In rings with recovery protocols, there is an alternative path after certain failures. The recovery time and the effect on the functions depend on the protocol, the configuration, the size of the network, and the equipment. Do not assume instantaneous recovery without measurement.

PRP e HSR

PRP and HSR, defined in IEC 62439-3, are high-availability redundancy mechanisms. Under conditions and failures foreseen by the design, they can offer switchover with no recovery time perceived by the protected traffic.

  • PRP: envia quadros por duas LANs independentes; o destino aceita o primeiro e descarta a duplicata.
  • HSR: sends frames in both directions of a ring; nodes process the first one received and handle duplicates.

This does not make the entire installation immune to failures. If the two networks share a power source, physical route, incorrect configuration, or another common point, the benefit can be reduced. Servers, gateways, clocks, switches, IEDs, and final circuits must be analyzed within the architecture.

VLAN, prioridade e multicast

Logical segmentation and prioritization help to control domains and traffic. In IEC 61850 environments, multicast messages require conscious configuration and supervision. VLAN and priority do not compensate for a network without a traffic budget, documentation, or diagnostics. The network design must record at least:

  • topologia física e lógica;
  • portas, enlaces e velocidades;
  • endereços e redes;
  • VLANs e prioridades;
  • multicast e assinaturas;
  • redundância e modos de falha;
  • fontes e alimentação dos equipamentos;
  • supervisão, logs e acesso de manutenção;
  • capacidade atual e reserva para expansão;
  • configuraç��es as-built.
Chapter 10

Time: the invisible infrastructure of analysis

Misaligned clocks can make a correct sequence appear contradictory. In distributed systems, time influences events, oscillography, sampled values, correlation between devices, and event investigation. The design must define:

  • quais funções precisam de sincronismo;
  • qual precisão cada função exige;
  • qual é a fonte de referência;
  • como o tempo é distribuído;
  • quais dispositivos atuam como mestre, transparente ou cliente;
  • como a perda, degradação ou salto de tempo é indicado;
  • quanto tempo cada equipamento mantém a precisão sem referência;
  • como o sincronismo é testado de ponta a ponta.

Common technologies include NTP, IRIG-B, and PTP. NTP serves many general functions, but it should not be assumed to be a solution for high-accuracy requirements. IRIG-B remains present in conventional architectures. PTP, including the IEC/IEEE 61850-9-3 profile, serves precise synchronism applications in automation networks, when the entire chain is compatible and correctly designed. GPS or another GNSS source can provide the primary reference, but the antenna alone does not solve distribution, redundancy, supervision, and holdover behavior.

Um teste frequentemente esquecido

Deliberately disconnecting the time source during commissioning helps to verify which alarms appear, which devices remain synchronized and for how long, how the time quality changes, how recovery occurs, and whether jumps or incoherent sequences appear.

Chapter 11

Conventional, automated, and digital: what is the difference?

The terms describe architecture choices and degree of integration. They do not represent an automatic scale of reliability.

Comparison between conventional, automated, and digital architectures
AspectoConvencionalAutomatizadaDigital
Aquisiçãopredominância de sinais e medições cabeadosIEDs e sistemas integrados, com combinações de cabeamento e redemaior digitalização próxima ao processo
Comunicaçãopontos concentrados e protocolos diversosrede de estação e integração entre dispositivos/sistemasuso ampliado de modelos e serviços digitais, inclusive no processo quando aplicável
Controlepainéis, chaves e lógicas cabeadascontrole local/remoto coordenado por dispositivos e supervisóriofunções distribuídas e integradas digitalmente
Engenhariadiagramas e listas predominantemente documentaisconfiguração de dispositivos, bancos de dados e gatewaysforte dependência de modelos, arquivos, rede, tempo e gestão integrada
Testescontinuidade, injeção, comando e sinais físicostestes físicos + comunicação e ponta a pontatestes físicos, lógicos, de rede, tempo, mensagens e simulação integrada
Principal desafiovolume de fiação e diagnósticoconsistência entre múltiplos sistemasgovernança de dados, configuração, interoperabilidade e ciclo de vida
01Convencional
  • Predominância de sinais e medições cabeados.
  • Pontos concentrados e protocolos diversos.
  • Painéis, chaves e lógicas cabeadas.
  • Principal desafio: volume de fiação e diagnóstico.
02Automatizada
  • IEDs e sistemas integrados, com cabeamento e rede.
  • Rede de estação e integração entre dispositivos.
  • Controle local e remoto coordenado por supervisório.
  • Principal desafio: consistência entre múltiplos sistemas.
03Digital
  • Maior digitalização próxima ao processo.
  • Uso ampliado de modelos e serviços digitais.
  • Funções distribuídas e integradas digitalmente.
  • Principal desafio: governança de dados, configuração e ciclo de vida.

A well-designed and well-maintained conventional architecture can be more reliable than a poorly specified digital architecture. Likewise, a mature digital solution can increase observability, flexibility, and standardization. The benefit comes from fitness to the requirement and from the execution of the engineering.

Digitalization does not have to happen all at once

Retrofit projects may be implemented in stages:

  • integrar IEDs existentes ao supervisório;
  • substituir UTR ou gateway mantendo parte dos sinais cabeados;
  • modernizar um bay por vez;
  • introduzir IEC 61850 no barramento de estação;
  • preparar rede e sincronismo para expansões futuras;
  • manter interfaces físicas onde a transição ou o requisito justificarem.

A hybrid architecture is not necessarily improvised. It can be a planned stage — provided that interfaces, limitations, and final condition are documented.

Chapter 12

Cybersecurity: part of the architecture, not a later layer

Automation increases connectivity and dependence on software. This requires defense in depth and governance throughout the life cycle. Controls to consider, according to risk and project requirements:

  • segmentação entre zonas e fluxos autorizados;
  • menor privilégio e contas individuais;
  • autenticação e gestão de credenciais;
  • acesso remoto controlado, temporário quando apropriado e auditável;
  • hardening de servidores, estações, switches e IEDs;
  • inventário de ativos, firmware, software e versões;
  • gestão de vulnerabilidades e de atualizações compatível com disponibilidade;
  • backups verificados e restauração ensaiada;
  • proteção e rastreabilidade de arquivos de configuração;
  • logs, monitoramento e resposta a incidentes;
  • controle de mídias removíveis e estações de engenharia;
  • gestão de fornecedores e suporte remoto.

The IEC 62351 series addresses security of communications and data in power-sector protocols, including parts related to IEC 61850. It is an important reference, but it does not replace network architecture, processes, people, and operational controls.

Availability and security need to be reconciled

Indiscriminately updating a critical system can introduce unavailability. Leaving software vulnerable indefinitely is also a risk. Engineering needs to combine impact assessment, homologation, window, rollback, and test evidence. Likewise, an “emergency” remote access without traceability can become permanent. Every exception needs an owner, a deadline, and a closing condition.

Chapter 13

Automation retrofit: modernize without losing the existing system

In operating installations, the challenge is rarely to design only the future architecture. It is to understand what exists, define transition states, and carry out the change without creating hidden risks.

O as-is real

Old documents are a starting point, not proof of the current state. The survey must confront drawings and field:

  • equipamentos e versões em serviço;
  • pontos efetivamente conectados;
  • lógicas e intertravamentos ativos;
  • origens de comando;
  • protocolos, conversores e links;
  • sincronismo;
  • endereçamento e topologia;
  • telas, alarmes e históricos;
  • interfaces com proteção e serviços auxiliares;
  • alterações não refletidas na documentação;
  • peças, licenças, ferramentas e conhecimento disponíveis.

Do not replicate the error in a new format

Migrating an old point list without validating names, quality, alarms, and usefulness only transfers liabilities to the new platform. The retrofit is an opportunity to rationalize:

  • pontos duplicados ou nunca utilizados;
  • alarmes sem ação;
  • escalas e unidades inconsistentes;
  • textos diferentes entre campo, IHM e centro;
  • comandos sem retorno adequado;
  • lógicas sem narrativa funcional;
  • dependências de equipamentos obsoletos.

Transition states

Between the current system and the future one there is a period in which new and old parts need to coexist. Engineering must explicitly represent:

  • arquitetura de cada etapa;
  • funções disponíveis e indisponíveis;
  • caminhos temporários de dados e comandos;
  • responsabilidade operacional;
  • bloqueios e medidas provisórias;
  • testes antes, durante e depois do corte;
  • critérios de abortar e retornar;
  • duração máxima da condição temporária.

Possible strategies

  • migração por bay;
  • substituição por camada — rede, servidores, gateway ou campo;
  • operação paralela controlada;
  • gateway temporário entre legado e futuro;
  • janela concentrada de corte;
  • implantação de infraestrutura comum antes dos dispositivos finais.

There is no universal strategy. Required availability, access to the process, existing documentation, testing capacity, and the risk of each transition guide the choice.

Signs that a retrofit deserves evaluation

  • falhas recorrentes ou diagnósticos insuficientes;
  • equipamentos sem suporte, peças ou ferramentas;
  • conhecimento concentrado em poucas pessoas;
  • alterações impossíveis de testar fora da instalação;
  • eventos sem sequência temporal confiável;
  • incompatibilidade com novos centros ou padrões;
  • redes sem segregação, supervisão ou documentação;
  • servidores e sistemas operacionais fora do ciclo de suporte;
  • divergência entre desenhos, banco de dados e campo;
  • expansão bloqueada por limites da arquitetura.

These signs do not by themselves determine replacement. They indicate the need for a structured technical diagnosis.

Chapter 14

Engineering: the system must exist before it is configured

Configuring too early usually turns architecture decisions into parameters scattered across the tools. Engineering must establish a source of truth and a sequence of deliverables.

  1. 01

    Requisitos

    Funcionais, operacionais e de disponibilidade.

  2. 02

    Arquitetura

    Arquitetura e critérios de falha do sistema.

  3. 03

    Dados e lógicas

    Inventário de funções, dados, comandos e intertravamentos.

  4. 04

    Configuração

    IEDs, servidores, gateways, switches e IHM.

  5. 05

    FAT

    Validação individual e integrada em fábrica.

  6. 06

    Integração / SAT

    Validação da instalação real no local.

  7. 07

    Comissionamento

    Testes ponta a ponta e entrada em operação.

  8. 08

    As-built e mudanças

    Documentação, backups e gestão de mudanças na operação.

Lições, pendências e correções encontradas no FAT, no SAT e no comissionamento retornam aos entregáveis anteriores — requisitos, arquitetura, dados e configuração. O ciclo é iterativo, não uma linha reta do requisito à energização.

From requirement to configuration

Um processo robusto inclui:

  1. 1.requisitos funcionais, operacionais e de disponibilidade;
  2. 2.architecture and failure criteria;
  3. 3.inventory of functions, data, and commands;
  4. 4.control philosophy, authority, and interlocks;
  5. 5.network and time-synchronization engineering;
  6. 6.modelo de dados, listas de pontos e interfaces;
  7. 7.configuration of IEDs, servers, gateways, switches, and HMI;
  8. 8.progressive and integrated testing;
  9. 9.as-built documentation, backups, and training;
  10. 10.change management during operation.

Deliverables that cannot disappear inside the tools

  • arquitetura funcional e física;
  • diagramas de rede e alimentação;
  • lista de pontos e I/O;
  • matriz de comandos e autoridade;
  • narrativas de lógica e intertravamento;
  • matriz de causa e efeito;
  • endereçamento, VLANs, portas e multicast;
  • modelo de dados e mapeamentos de protocolo;
  • datasets, reports e mensagens GOOSE;
  • arquivos SCL e configurações nativas;
  • telas e filosofia de alarmes;
  • requisitos de tempo;
  • procedimentos e casos de teste;
  • registros de resultados e pendências;
  • plano de migração e rollback;
  • backups testados;
  • documentação as-built e registro de versões.

A fonte oficial

Complex projects fail silently when divergent copies of the same file exist. Define:

  • qual repositório contém a versão válida;
  • quem pode alterar;
  • como uma mudança é solicitada, revisada, testada e aprovada;
  • como versões instaladas em campo são identificadas;
  • como recuperar a configuração anterior;
  • como garantir que documentos e arquivos correspondam.
Chapter 15

FAT, SAT, and commissioning: testing relationships, not just parts

Open cubicles with accessible control wiring during SCADA system testing at a Queens substation
Substation in Queens during tests of the MTA’s SCADA system, in 2019. Field validation confronts signals, equipment, and configuration.Foto: MTA Capital Construction Mega Projects · CC BY 2.0

An IED can pass an individual test and still fail as a participant in the system. The greater the integration, the more necessary it becomes to test relationships between devices, networks, servers, time, operation center, and process.

FAT — Factory Acceptance Test

FAT should be performed in an environment sufficiently representative to anticipate problems before field deployment. Depending on the scope, verify:

  • configuração e versões;
  • pontos, estados, escalas, unidades e qualidade;
  • comandos, permissivos e intertravamentos;
  • eventos e timestamps;
  • telas, alarmes e históricos;
  • comunicação entre dispositivos e sistemas;
  • GOOSE, MMS, reports e arquivos SCL;
  • integração por IEC 104, DNP3, Modbus ou interfaces aplicáveis;
  • redundância de servidores e rede;
  • perda e retorno de enlaces;
  • perda e retorno da fonte de tempo;
  • reinício a frio e a quente;
  • backups e restauração;
  • desempenho sob cenários representativos;
  • lista de pendências, responsáveis e critérios de encerramento.

The FAT does not fully reproduce the field. Simulation limitations must be recorded and converted into mandatory SAT or commissioning cases.

SAT — Site Acceptance Test

On site, validate the actual installation:

  • correspondência entre equipamento, desenho e configuração;
  • cabeamento, portas, fibras e rotas;
  • alimentação, aterramento e redundâncias;
  • integração com equipamentos primários;
  • aquisição e comando ponto a ponto;
  • atuação, retorno e supervisão de circuitos;
  • comunicação real com o centro de operação;
  • sincronismo distribuído;
  • failover com a topologia final;
  • recuperação após perda de energia ou reinício;
  • acessos, perfis e trilhas de auditoria;
  • procedimento de operação em modo degradado.

Teste ponta a ponta

The end-to-end test follows a complete function. Examples:

  • mudar um estado real ou simulado no campo e confirmar valor, qualidade, tempo, alarme e registro no centro;
  • emitir um comando autorizado e verificar seleção, intertravamento, saída, posição final e registro;
  • interromper um enlace e confirmar continuidade prevista, alarmes, reconexão e ausência de estados enganosos;
  • perder o sincronismo e verificar indicação, holdover e recuperação;
  • restaurar um backup em ambiente controlado e comprovar que ele é utilizável.

Measurable acceptance criteria

“Communication OK” is not a sufficient criterion. Each case must contain:

  • condição inicial;
  • estímulo;
  • resultado esperado;
  • tolerância ou tempo aplicável;
  • evidência;
  • responsável;
  • resultado obtido;
  • desvio e tratamento.

A communication path of the automation network is interrupted.

The three questions the design needs to answer

  1. What continues operating locally?
  2. How is the condition signaled and recorded?
  3. What is the recovery path validated in testing?
Chapter 16

Operation and maintenance: delivery does not end at energization

After entering operation, automation keeps changing. There are replacements, updates, new points, screen revisions, bay expansions, equipment changes, and changes at the control center. Without life-cycle management, the as-built loses validity and the next diagnosis starts over from scratch.

Recommended minimum routine

  • inventário atualizado de hardware, firmware, software e licenças;
  • monitoramento de rede, servidores, sincronismo e comunicações;
  • análise de alarmes recorrentes e eventos de infraestrutura;
  • backups periódicos com teste de restauração;
  • revisão de contas e acessos;
  • avaliação controlada de patches e vulnerabilidades;
  • registro de toda mudança de lógica, ponto, tela ou configuração;
  • comparação entre versão aprovada e instalada;
  • testes após mudanças;
  • treinamento e exercícios de condição degradada;
  • preservação de ferramentas, cabos, adaptadores e ambientes necessários à manutenção.

Useful indicators

  • disponibilidade das funções, não apenas dos equipamentos;
  • falhas e perdas de comunicação por origem;
  • dispositivos fora de sincronismo;
  • alarmes mais frequentes e tempo até resposta;
  • quantidade de pontos inválidos ou forçados;
  • mudanças pendentes de as-built;
  • sucesso de backup e restauração;
  • tempo de recuperação em falhas ensaiadas;
  • obsolescência e suporte por ativo.
Chapter 17

Checklist para especificar ou revisar um SAS

Use the questions below as an initial guide. They do not replace the analysis of the project.

Specification checklist

Functions and operation
  • Which functions must remain available without a server or without remote communication?
  • What are the command origins and their priority?
  • How are blocks, permissives, and bypass governed?
  • What condition must be recorded at the source?
  • What is the degraded operating mode?
Data and integration
  • Is there a single, versioned, and traceable point list?
  • Are unit, scale, quality, and timestamp defined?
  • O mapeamento entre protocolos preserva significado?
  • Has the operation center validated points and commands?
  • Are there criteria for stale, invalid, or inconsistent states?
Rede e tempo
  • Is the physical and logical topology documented?
  • Modos de falha e pontos comuns foram analisados?
  • Was redundancy tested with the final architecture?
  • Do multicast, VLAN, and priority have controlled configuration?
  • Was time accuracy defined per function?
  • Is the loss of the time reference alarmed and rehearsed?
Engenharia e testes
  • Is there an official source for SCL and configurations?
  • Does the FAT represent the critical integrations?
  • Were the FAT limitations carried over to the SAT?
  • Are negative and recovery tests foreseen?
  • Backups foram restaurados em teste?
  • Do the evidence and pending items have owners?
Life cycle and cybersecurity
  • Is there an inventory of versions, licenses, and support?
  • Is remote access controlled and auditable?
  • Do accounts and privileges follow real responsibilities?
  • Do changes require review, testing, approval, and as-built?
  • Does the team have the tools and knowledge required to recover the system?
Chapter 18

Frequently asked questions

Are substation automation and SCADA the same thing?

No. SCADA is one part of automation, focused on acquisition, processing, supervision, alarms, events, historical data, and controls. Automation also involves process interfaces, IEDs, controllers, networks, time, logic, interlocks, gateways, engineering, and procedures.

What does SAS mean in a substation?

SAS is an acronym for Substation Automation System. The exact scope varies: in some projects it covers IEDs, network, servers, HMI, gateway, and synchronism; in others, the term is used more narrowly. The contract and the architecture need to make the boundaries explicit.

Is IEC 61850 a protocol?

It is broader than that. The IEC 61850 series includes data models, communication services, mappings, and a system configuration language. MMS, GOOSE, and Sampled Values serve distinct functions within this ecosystem.

What is the difference between GOOSE and MMS?

GOOSE is associated with publish/subscribe distribution of events and states between participants, including for fast functions when the design so defines. MMS is associated with client-server communication, data reading, reports, commands, and other services. They can coexist in the same system.

Does every IEC 61850 automation use a process bus?

No. Many installations use IEC 61850 on the station bus and keep currents, voltages, states, and operations hardwired. A process bus is an additional architecture choice and requires its own network, time, testing, and maintenance engineering.

Do PRP or HSR eliminate any interruption?

They provide redundancy mechanisms for communication in defined scenarios, but they do not eliminate all the system’s points of failure. Power sources, common routes, servers, gateways, clocks, devices, and final circuits must also be analyzed and tested.

Which protocol should connect the substation to the operation center?

It depends on the standard of the utility and the project. IEC 60870-5-104 and DNP3/IEEE 1815 are frequent examples. The protocol alone does not define the quality of the integration: point list, events, quality, time, commands, availability, and cybersecurity need to be specified.

What should be tested beyond the supervision points?

Commands, authority, interlocks, quality, timestamps, alarms, SOE, redundancy, loss of time, loss of server, restart, reconnection, degraded behavior, communication with the center, and restoration of backups. Negative tests are as important as normal operation.

When to modernize the existing automation?

When operational risk, obsolescence, lack of support, insufficient diagnostics, documentation inconsistency, expansion limitations, or incompatibility with new requirements exceed the safe capacity for maintenance. The decision must start from an as-is diagnosis and a risk analysis, not just from the age of the equipment.

Is it possible to modernize in stages?

Yes. Migration by bay, by layer, or with temporary coexistence can reduce operational impact. However, each transition state needs its own architecture, tests, responsibilities, blocks, and rollback.

What is the main deliverable of an IEC 61850 project?

There is no single sufficient file. The system needs architecture, requirements, models, lists, logic, SCL files, native configurations, network documentation, test cases and evidence, backups, and a coherent as-built. The value lies in the consistency of the whole.

Conclusion

Coherence is what turns equipment into a system

An automated substation is a distributed system applied to a critical electrical process. Its performance does not depend only on the speed of the network, the brand of the IED, or the appearance of the HMI. It depends on the coherence between what the field reports, what the devices interpret, what the network transports, what SCADA presents, what the operator can command, and what remains available when something fails.

This coherence is built through engineering: clear requirements, defined responsibilities, data with semantics and quality, reliable time, network architecture, controlled configurations, end-to-end tests, and documentation that remains valid after energization.

When these disciplines come together, automation ceases to be a set of connected equipment and begins to fulfill its role: expanding observability, reducing ambiguity, supporting decisions, and operating the system with predictability.

Glossary

Essential glossary

Bay ou vão

Posição funcional da subestação associada, por exemplo, a uma linha, transformador, alimentador, barramento ou acoplamento.

Gateway

Equipamento ou software que concentra, encaminha ou converte informações entre sistemas e protocolos.

GOOSE

Serviço de publicação/assinatura da IEC 61850 para distribuição de eventos e estados entre participantes.

HSR

Protocolo de redundância em anel com transmissão em ambas as direções, definido na IEC 62439-3.

IED

Dispositivo eletrônico inteligente que executa funções como proteção, controle, medição, aquisição ou registro.

IHM

Interface homem-máquina usada para apresentar o processo e receber ações do operador.

MMS

Conjunto de serviços/mapeamento cliente-servidor utilizado no ecossistema IEC 61850 para acesso a dados, relatórios e controles.

PRP

Protocolo de redundância com duas LANs paralelas, definido na IEC 62439-3.

SAS

Sistema de automação de subestação.

SCL

Linguagem de configuração de subestações da IEC 61850, usada para descrever capacidades, funções e comunicação do sistema.

SCADA

Sistema de controle supervisório e aquisição de dados.

SOE

Sequência de eventos registrada com referência temporal para apoiar a análise de ocorrências.

Sampled Values

Serviço/mapeamento para publicação de valores amostrados, como correntes e tensões, em arquiteturas aplicáveis.

UTR/RTU

Unidade terminal remota que adquire, concentra e troca informações e comandos com sistemas superiores.

References

Technical references

Standards, procedures, and contractual requirements evolve. The applicable version must be confirmed for the date, the utility, and the project.

  1. 1.IEC 61850 — official overview of the series
  2. 2.IEC 61850-6 — configuration description language (SCL)
  3. 3.IEC 61850-7-2 — abstract communication services
  4. 4.IEC 61850-9-2 — mapeamento de Sampled Values
  5. 5.IEC/IEEE 61850-9-3 — PTP profile for power system automation
  6. 6.IEC 62439-3 — redes de alta disponibilidade, PRP e HSR
  7. 7.IEC 62351-6 — security for IEC 61850 protocols
  8. 8.IEC 60870-5-104 — acesso de rede para telecontrole
  9. 9.DNP Users Group — overview of DNP3 (IEEE 1815)
  10. 10.Modbus Organization — Modbus application protocol specification
  11. 11.ONS — Submodule 2.12 of the Grid Procedures: supervision and control for operation
  12. 12.IEC 62682 — management of alarm systems
  13. 13.CIGRE — WG B5.90: commissioning and testing of fully digital PACS

References consulted in September 2026. For the IEC standards, the applicable edition and year must be confirmed; for the ONS Grid Procedures, the current revision must be verified per project.

Does your automation deliver information — or context to decide?

POWER works on the engineering, integration, configuration, testing, implementation, and modernization of substation automation systems. We assess the existing architecture, the operating requirements, and the transition risks to build a technically consistent and verifiable solution.

Explore the automation solutions