Proteção e controle de subestações: como funciona um SPCS e quando modernizar
Um sistema de proteção e controle precisa reconhecer condições anormais, tomar decisões seletivas, comandar a interrupção da falta e entregar à operação informações confiáveis sobre o que aconteceu. Em uma subestação existente, modernizar essa cadeia exige mais do que substituir relés: exige compreender funções, circuitos, interfaces, comunicação, riscos e restrições operacionais.
- Conteúdo:
- Engenharia POWER
- Atualizado em
- setembro de 2026
- Leitura técnica:
- aproximadamente 25 minutos
Proteção · Controle · Automação · Supervisão · IEC 61850 · Retrofit
In summary
Protection is a chain
The relay is one part of the system. Measurement, DC power supply, logic, trip circuits, breakers, communication, synchronization, and documentation all need to work together coherently.
Retrofit is an engineering decision
The age of the equipment is only one factor. Support, spare parts, performance, expansion capacity, security, records, and operational risk also determine the need for modernization.
Migration is part of the design
Between the existing system and the future architecture there is a critical stage: planning outages, temporary interfaces, tests, contingencies, and the entry into operation without losing essential functions.
What is a substation's protection and control system?
A substation must transfer energy, transform voltage levels, connect or isolate circuits, and keep the system within safe operating conditions. The equipment that physically performs these functions — power transformers, circuit breakers, disconnect switches, busbars, lines, cables, reactors, and capacitor banks — makes up the primary system.
The protection and control system is part of the secondary system. It monitors the electrical and operational behavior of the facility, processes information, identifies abnormal situations, executes commands, coordinates interlocks, records events, and makes data available to the operator.
In the context of this guide, SPCS means Protection, Control, and Supervision System. Depending on the standard adopted by the facility's owner, the acronym and the exact scope may vary. The concept, however, remains the same: bringing together the functions that make it possible to protect, command, automate, supervise, and analyze the substation's operation.
Four different functions, one single system
| Camada | Pergunta que responde | Função principal | Exemplos |
|---|---|---|---|
| Proteção | Existe uma condição anormal que precisa ser isolada? | Detectar faltas e condições inadmissíveis e iniciar a ação adequada | Sobrecorrente, distância, diferencial, falha de disjuntor |
| Controle | A manobra pode ser executada e por quem? | Processar comandos, permissivos, bloqueios e intertravamentos | Abrir, fechar, selecionar local/remoto, bloquear uma manobra |
| Automação | Qual sequência deve ocorrer sem depender de cada comando manual? | Coordenar lógicas, sequências e respostas automáticas | Transferências, recomposição, alívio de carga e automatismos locais |
| Supervisão | O que está acontecendo e o que aconteceu? | Apresentar estados, medições, alarmes, eventos e históricos | SCADA, IHM, SOE, tendências e telecomando |
These layers have different objectives, but they share signals, devices, networks, documents, and test criteria. A seemingly localized change can affect permissives, alarms, remote commands, event records, and other functions that are not visible on the replaced panel.
How does a protection operation work?
A protection operation begins before the relay and ends after the breaker opens. Between the occurrence of the fault and the information presented to the operator there is a physical and logical chain that must remain intact.
O sistema elétrico muda de condição
Um curto-circuito, uma falta à terra, uma sobrecarga, uma perda de sincronismo ou outra condição anormal altera correntes, tensões, frequência, impedância ou estados do sistema.
As grandezas são medidas
Transformadores de corrente e de potencial — TCs e TPs — fornecem sinais compatíveis com os dispositivos de proteção. Em arquiteturas com barramento de processo, unidades de aquisição podem digitalizar essas grandezas e transmiti-las pela rede.
O IED processa a informação
O relé ou dispositivo eletrônico inteligente aplica algoritmos, ajustes, temporizações, critérios direcionais, restrições e lógicas definidos pela filosofia de proteção.
A proteção decide se deve atuar
A decisão deve distinguir uma falta interna de uma condição externa, uma perturbação transitória ou uma situação operacional admissível. Dependendo da função, essa decisão pode ocorrer em milissegundos ou incluir uma temporização intencional para coordenação.
O comando de trip percorre a cadeia
A saída do IED atua sobre a matriz de trip, relés auxiliares ou mensagens de comunicação previstas no projeto. O circuito de corrente contínua energiza a bobina de abertura do disjuntor correspondente.
O disjuntor interrompe a corrente
O equipamento primário abre seus contatos e isola a parte defeituosa. Se ele não interromper a corrente dentro do tempo esperado, a função de falha de disjuntor pode comandar a abertura de disjuntores de retaguarda.
O sistema registra e comunica
Eventos, alarmes, oscilografias, medições e estados são registrados e enviados ao sistema supervisório ou ao centro de operação. Esses dados permitem reconstruir a ocorrência, verificar o desempenho da proteção e orientar ações corretivas.
Reliability depends on the most vulnerable link
Select a link to see the consequence of its unavailability.
Medição
O que precisa estar assegurado — Relação, polaridade, classe, integridade dos circuitos e adequação dos TCs/TPs
Consequência de indisponibilidade — O IED recebe grandezas incorretas ou insuficientes
Alimentação CC
O que precisa estar assegurado — Tensão, autonomia, proteção e continuidade dos circuitos
Consequência de indisponibilidade — O comando de abertura pode não chegar à bobina de trip
IED
O que precisa estar assegurado — Hardware, firmware, ajustes, lógica e configuração
Consequência de indisponibilidade — A função pode não reconhecer a condição ou atuar indevidamente
Lógica de trip
O que precisa estar assegurado — Matriz, contatos, mensagens e relés auxiliares
Consequência de indisponibilidade — A decisão correta não alcança o disjuntor correto
Disjuntor
O que precisa estar assegurado — Capacidade de interrupção, mecanismo e bobinas
Consequência de indisponibilidade — A falta permanece alimentada apesar do comando
Registro e supervisão
O que precisa estar assegurado — Tempo, eventos, oscilografia e comunicação
Consequência de indisponibilidade — A operação perde visibilidade e capacidade de diagnóstico
That is why replacing only the relay without validating the rest of the chain can renew a component while leaving the systemic risk in place.
What are the layers of an SPCS?

The architecture varies with the size of the facility, the voltage level, the criticality of the assets, the client's philosophy, and the technology applied. A useful way to understand it is to divide the system into functional levels.
Nível de processo
É onde o sistema secundário encontra os equipamentos primários. Inclui grandezas de corrente e tensão, posições, contatos, comandos, bobinas de abertura e fechamento, além das interfaces com disjuntores, seccionadores, transformadores e outros ativos. Em projetos digitais, pode incluir merging units e comunicação de valores amostrados.
Nível de bay ou vão
Concentra funções associadas a uma posição elétrica: proteção, controle, medição, intertravamentos, sincronismo, religamento, registro e comunicação. Relés de proteção e controladores de bay são dispositivos típicos desse nível.
Nível de estação
Integra os bays e reúne funções comuns, como servidores, IHM, gateways, concentradores, supervisão local, registros, engenharia, sincronismo e interfaces com sistemas superiores.
Nível de operação
Conecta a subestação ao centro de operação e a outros sistemas corporativos ou operacionais. Nele estão o telecomando, a consolidação de alarmes e eventos, a visualização remota e os dados utilizados para análise e manutenção.
Physical architecture and functional architecture are not the same thing
Two systems can use similar equipment and behave very differently. The placement of functions, network segregation, redundancies, trip paths, control hierarchy, and interfaces with existing systems define the real architecture.
In a retrofit, it is essential to map both views:
- Physical: panels, devices, terminals, cables, fibers, switches, power supplies, and circuits.
- Functional: protections, logic, commands, interlocks, data, dependencies, and expected responses.
What makes protection technically reliable?
Effective protection is not simply fast. It must combine criteria that, in certain situations, compete with each other.
Selectivity
Isolate the smallest necessary part of the system, keeping unaffected areas in service. Selectivity depends on the philosophy, zone boundaries, studies, and coordination between main and backup protections.
Sensitivity
Recognize fault conditions within the protected zone, even when the available quantities are reduced or influenced by the system configuration.
Speed
Clear the fault in a time compatible with system stability, equipment withstand capability, and safety. The fastest operation is not always the most selective; the design determines where speed is essential and where coordination requires a time delay.
Dependability
Atuar quando a condição prevista realmente ocorre. Isso depende do conjunto formado por medição, lógica, alimentação, circuitos de trip e equipamento de interrupção.
Security against incorrect operation
Remain stable in the presence of external faults, transients, CT saturation, transformer energization, power swings, and other conditions that should not result in a trip.
Redundancy and independence
Critical facilities may require independent main protections, power sources, CT cores, trip circuits, communication channels, or redundant networks. Redundancy does not mean duplicating components without criteria: it is necessary to reduce common failure causes and verify the behavior when each element is lost.
Protection functions: the code identifies the function, it does not define the design
Function numbers are an established language for identifying devices and functions in electrical power systems. They help organize documents, diagrams, and logic, but they do not replace the application study.
| Código | Função | O que observa | Aplicações frequentes |
|---|---|---|---|
| 21 | Distância | Impedância aparente e direção da falta | Linhas de transmissão e circuitos onde a proteção por corrente não oferece seletividade suficiente |
| 24 | Sobre-excitação | Relação tensão/frequência | Transformadores e geradores sujeitos a fluxo magnético excessivo |
| 25 | Verificação de sincronismo | Diferença de tensão, frequência e ângulo | Fechamento de disjuntores entre fontes ou partes energizadas do sistema |
| 27 / 59 | Subtensão / sobretensão | Tensão abaixo ou acima dos limites | Barramentos, máquinas, cargas e esquemas de controle ou proteção |
| 32 | Potência direcional | Magnitude e sentido da potência ativa | Geradores, motores e controle de intercâmbio ou fluxo |
| 40 | Perda de excitação | Condição de subexcitação ou perda de campo | Geradores síncronos |
| 46 | Sequência negativa ou desequilíbrio de corrente | Componente de sequência negativa | Motores, geradores e situações de desequilíbrio entre fases |
| 48 / 51LR | Partida prolongada / rotor bloqueado | Corrente e tempo durante partida ou bloqueio | Motores |
| 49 | Proteção térmica | Modelo ou medição da condição térmica | Transformadores, motores, geradores e cabos |
| 50 / 51 | Sobrecorrente instantânea / temporizada | Corrente de fase | Alimentadores, transformadores e proteção de retaguarda |
| 50N / 51N | Sobrecorrente de neutro ou residual | Corrente residual ou de neutro | Faltas à terra, conforme o aterramento e a forma de medição |
| 50BF | Falha de disjuntor | Persistência de corrente e/ou estados após o trip | Retaguarda local para abertura de disjuntores adjacentes |
| 63 | Pressão, gás ou fluxo | Condição de dispositivos mecânicos associados ao equipamento | Transformadores e outros equipamentos com dispositivos próprios de detecção |
| 67 / 67N | Sobrecorrente direcional | Corrente e referência de polarização | Sistemas em anel, malhados ou com fluxo de falta bidirecional |
| 79 | Religamento automático | Sequência de abertura e restabelecimento | Linhas e alimentadores, conforme política operacional |
| 81 | Frequência | Subfrequência, sobrefrequência ou taxa de variação | Geração, ilhamento, estabilidade e esquemas sistêmicos |
| 85 | Canal de teleproteção | Sinais de permissivo, bloqueio ou transferência entre terminais | Esquemas de proteção de linhas com comunicação |
| 86 | Bloqueio | Comando de bloqueio mantido após determinada atuação | Falhas que exigem inspeção antes da recomposição |
| 87 | Diferencial | Comparação vetorial das correntes que delimitam uma zona | Transformadores, barramentos, geradores, motores e linhas |
The application changes according to the protected asset
| Ativo | Funções frequentemente consideradas | Questões de engenharia que influenciam a escolha |
|---|---|---|
| Linha ou alimentador | 21, 50/51, 50N/51N, 67/67N, 79, 85 | Topologia, fontes, aterramento, teleproteção, seletividade e estabilidade |
| Transformador | 87T, 50/51, 50N/51N, 49, 63, 24, 86 | Relação, grupo vetorial, corrente de magnetização, aterramento e proteções próprias |
| Barramento | 87B, 50BF, 86 | Zonas, posição de seccionadores, saturação de TCs, velocidade e estabilidade |
| Gerador | 87G, 32, 40, 46, 49, 59, 81 | Aterramento, potência, excitação, estabilidade, limites térmicos e integração à planta |
| Motor | 49, 46, 48/51LR, 50/51, 50N/51N, 27 | Partida, tempo de rotor bloqueado, carga, processo e regime de operação |
| Banco de capacitores ou reator | 50/51, 50N/51N, 59, 87, desequilíbrio | Configuração, energização, harmônicos, unidades internas e forma de aterramento |
The relationships above are for guidance only. The selection, setting, and coordination of the functions depend on the electrical studies, the topology, the equipment data, the owner's requirements, and the rules applicable to the project.
Control, automation, and supervision: operation must be predictable
While protection responds to abnormal conditions, control organizes how the facility must be operated. It establishes who can issue commands, under what conditions, and with what confirmations.
Command hierarchy
A piece of equipment can be commanded from the yard, from the panel, from the local HMI, or from the control center. The philosophy must define priorities, local/remote modes, blocks, and the conditions for transferring control between levels.
Interlocks
Interlocks prevent switching operations that are incompatible with the state of the system. They can combine breaker and disconnect-switch positions, presence of voltage, grounding, operating permissives, and other conditions. In a retrofit, simply reproducing inputs and outputs is not enough: the intent of the logic must be reconstructed.
Permissives and blocks
A command may depend on synchronism, spring charge condition, pressure, absence of a block, circuit availability, or authorization from another system. These signals need to be documented, tested, and presented to the operator in a way that is easy to understand.
Automation schemes
Transfers, restoration, reclosing, voltage control, starting sequences, and special schemes require a clear definition of initial states, advance conditions, timers, failure handling, and return to a safe condition.
Supervision and recording
The supervisory system organizes states, measurements, alarms, events, and commands. A well-designed screen does not compensate for an inconsistent database; quality starts at the signal source, passes through naming and alarm priority, and ends with the presentation to the operator.
The sequence-of-events record — SOE — and oscillography make it possible to reconstruct occurrences. For the analysis to be reliable, clocks, time zones, time quality, and record resolution need to be consistent throughout the architecture.
See how automation integrates IEDs, networks, SCADA, and operation in the guide dedicated to substation automation architecture.
IEC 61850: interoperability requires engineering
IEC 61850 should not be treated as just a protocol. The series structures data models, communication services, and a system description language, making it possible to represent functions and exchange information between devices and engineering tools.
MMS
It is used in client-server communication to make states, measurements, alarms, commands, and other data available between IEDs and supervision or control systems.
GOOSE
It enables fast exchange of events and states between devices. It can be applied to interlocks, permissives, blocks, transfers, and protection-related signals, depending on the architecture. Its use requires publish/subscribe engineering, supervision, testing, and configuration management.
Sampled Values
Sampled Values make it possible to digitally transmit current and voltage quantities. They are associated with process-bus architectures and require specific network, timing, availability, testing, and maintenance requirements. Not every IEC 61850 installation uses Sampled Values.
SCL
The SCL language describes devices, capabilities, communication, and the system configuration. Files such as ICD, CID, and SCD are part of the engineering cycle and need to be controlled as technical documents, with version, origin, ownership, and correspondence with the system in operation.
Compatibility is not a guarantee of interoperability
Two pieces of equipment declared compatible with IEC 61850 do not automatically form an integrated system. Data models, standard editions, service implementation, naming, datasets, messages, tools, and client requirements need to be reconciled and tested.
Networks, availability, and timing
Topology, segregation, capacity, latency, synchronism, and redundancy must result from the functional requirements. Protocols such as PRP and HSR can provide seamless recovery from certain network failures when planned and correctly implemented. They do not eliminate the need to analyze power sources, switches, links, configurations, and common failure causes.
Integration with legacy systems
Modernizations often require different generations to coexist. Gateways, converters, physical contacts, and legacy protocols may remain during one stage or throughout the system's entire life cycle. The solution must preserve the meaning of the data, command security, time quality, and diagnostic capability.
Learn about POWER's approach to IEC 61850 integration.
Without DC power, there is no reliable trip chain
The DC system keeps relays, controllers, communication, signaling, and command circuits available even when the facility's AC supply is lost. It also provides the energy needed for the breakers' opening and closing coils, depending on the architecture.
Rectifiers, battery banks, distribution panels, protection devices, cables, and supervision form another critical system. Rated voltage, autonomy, selectivity, charger capacity, steady-state current, transient loads, and battery condition need to be considered together.
In a protection and control retrofit, the following must be verified:
- available capacity of the DC system;
- minimum voltage at the terminals of critical loads;
- voltage drops in the trip circuits;
- required autonomy;
- circuit distribution and protection;
- ground-fault supervision and alarms;
- impact of new loads;
- condition, age, and documentation of the battery bank;
- strategy for maintaining power supply during the migration.
POWER integrates this need into SPCS projects and, when the scope requires power-conversion solutions, works with technology from NPT Energia, a MACH Capital group company specialized in DC systems for critical applications.
When does a protection and control system need a retrofit?
There is no universal age at which every SPCS must be replaced. An older system can remain adequate if it is supported, documented, testable, and compatible with the facility's needs. Likewise, a relatively new system can present a risk if its architecture, configuration, or maintenance are inadequate.
The decision must combine life cycle, condition, performance, and operational exposure.
Ciclo de vida e suporte
- Relés, controladores, servidores ou switches fora de linha.
- Ausência de peças de reposição confiáveis.
- Ferramentas de engenharia incompatíveis com computadores atuais.
- Dependência de cabos, portas ou sistemas operacionais difíceis de manter.
- Firmware sem suporte ou sem possibilidade de correções necessárias.
Desempenho e confiabilidade
- Atuações indevidas ou recusas de atuação.
- Falhas intermitentes de comunicação.
- Reinicializações ou defeitos recorrentes.
- Registros de eventos insuficientes para esclarecer ocorrências.
- Indisponibilidades que aumentam com o envelhecimento da base instalada.
Manutenibilidade
- Configurações não localizadas ou sem controle de versão.
- Diagramas e listas de sinais diferentes da instalação real.
- Conhecimento concentrado em poucas pessoas.
- Equipamentos que não podem ser testados com os recursos disponíveis.
- Tempo de recuperação incompatível com a criticidade do ativo.
Integração e expansão
- Falta de capacidade para novos bays, sinais ou funções.
- Protocolos proprietários que limitam integração.
- Supervisão sem informações necessárias à operação.
- Dificuldade para padronizar IEDs ou incorporar novos sistemas.
- Arquitetura que não atende aos requisitos futuros do empreendimento.
Segurança e risco operacional
- Sistemas operacionais descontinuados.
- Contas compartilhadas ou acesso sem rastreabilidade.
- Ausência de backups validados e procedimento de recuperação.
- Redes sem segregação coerente com a criticidade da instalação.
- Intervenções frequentes em circuitos antigos e pouco documentados.
Matriz orientativa de decisão
| Condição | Tendência de decisão |
|---|---|
| Equipamento suportado, documentação íntegra, desempenho satisfatório e capacidade de expansão | Manter, testar e monitorar |
| Pontos isolados de obsolescência, arquitetura geral saudável | Substituição pontual ou atualização dirigida |
| Uma família de IEDs ou uma camada do sistema no fim do ciclo de vida | Retrofit por sistema ou por função |
| Bays com diferentes níveis de criticidade e janelas limitadas | Modernização progressiva por bay |
| Obsolescência ampla, documentação frágil e limitações sistêmicas | Reengenharia e retrofit integral planejado |
A tabela é orientativa. A decisão final depende de levantamento de campo, documentos, criticidade, requisitos de operação e estudos aplicáveis. A decisão exige avaliação da instalação e dos requisitos do empreendimento.
Partial, by-bay, or full retrofit?
Retrofit does not necessarily mean replacing the entire system. The right scope is the one that reduces the relevant risk without creating an architecture that is difficult to maintain.
Targeted replacement
Recommended when a component is clearly obsolete or faulty and the rest of the architecture remains adequate. It requires checking electrical, functional, mechanical, logic, and communication compatibility.
Vantagem: smaller immediate intervention.
Attention: may transfer the obsolescence to the interfaces and keep systemic limitations in place.
Retrofit by bay
Modernizes one electrical position at a time, keeping the others in operation. It is a common alternative when outage windows are short or when the investment needs to be spread out.
Vantagem: progressive implementation.
Attention: requires managing interfaces between new and old bays throughout the entire transition.
Retrofit by layer or system
Replaces a cross-cutting function, such as supervision, communication, synchronization, or a specific family of IEDs.
Vantagem: standardizes a common limitation.
Attention: may require adaptations across a large number of retained devices.
Full retrofit
Redesigns protection, control, automation, supervision, and communication when obsolescence and limitations are extensive or when the facility will undergo significant expansion.
Vantagem: coherent architecture, ready for the next cycle.
Attention: demands more extensive migration engineering, testing, and outage planning.
Legacy, transition, and future architecture
Um sistema mais antigo pode continuar adequado se estiver suportado, documentado, testável e compatível com as necessidades da instalação.
Durante uma modernização progressiva, o sistema temporário é um estado real de operação. Ele pode reunir equipamentos de diferentes gerações, sinais físicos e digitais, redes novas e antigas e bases de supervisão parcialmente migradas.
Esse estado deve possuir:
- diagramas próprios
- lista de interfaces
- lógica validada
- limites claros de responsabilidade
- plano de testes
- procedimento de retorno ou contingência
- documentação de cada etapa concluída
Redesenha proteção, controle, automação, supervisão e comunicação quando a obsolescência e as limitações são amplas ou quando o empreendimento passará por expansão relevante — arquitetura coerente e preparada para o ciclo futuro.
How is an SPCS retrofit carried out?

A safe modernization starts with the system that is actually in operation, not just the set of available drawings.
Levantamento e reconstrução do estado atual
Inspeção da base instalada, painéis, IEDs, circuitos, bornes, redes, versões, sinais, lógicas, arquivos, documentação, condições ambientais e restrições de acesso ou desligamento. O resultado deve ser uma representação confiável do as-is: o sistema como ele existe e opera.
Diagnóstico de criticidade e obsolescência
Classificação dos ativos e funções conforme consequência de falha, condição, suporte, sobressalentes, manutenção, exposição cibernética, capacidade de recuperação e necessidade de expansão.
Definição da filosofia e da arquitetura futura
Definição das zonas de proteção, funções, redundâncias, hierarquia de controle, redes, sincronismo, supervisão, interfaces, alimentação, requisitos de desempenho e critérios de teste.
Engenharia de detalhe
Desenvolvimento ou revisão de diagramas funcionais e construtivos, listas de sinais, lógicas, matrizes de trip, intertravamentos, bases de dados, parametrizações, configurações, telas, redes e documentação de migração.
Configuração, integração e testes de fábrica
Configuração de IEDs, controladores, switches, gateways e supervisório. Validação individual e integrada das funções antes da intervenção em campo, conforme o escopo e a possibilidade de simulação.
Migração e comissionamento
Execução por etapas, identificação dos circuitos, bloqueios, transferência de sinais, testes ponto a ponto, testes funcionais, validação de comandos, energização e acompanhamento da entrada em operação.
Documentação final e sustentação
Consolidação do as-built, arquivos nativos, backups, relatórios de teste, registros de versão, treinamento e informações necessárias para operação, manutenção e futuras alterações.
Critical points of the migration
Current circuits
CT secondaries require specific handling and safe procedures. Changes, tests, and isolation must consider the risk of inadvertently opening the circuit and the correspondence between polarities, ratios, cores, and functions.
Trip circuits
Each path must be traced from the IED to the breaker coil, including contacts, auxiliary relays, test switches, blocks, supervision, and power supply. Testing only the relay's logic output does not validate the full chain.
Interlocks and permissives
Existing logic may be distributed across wiring, auxiliary relays, IEDs, controllers, and the supervisory system. The migration must preserve the intended behavior, eliminating improper dependencies and documenting approved changes.
Temporary interfaces
Each signal between the new system and the retained system must have a defined origin, destination, safe state, quality, failure handling, and test criteria.
Rollback plan
Before starting a critical outage window, it is necessary to define how far the implementation can be reverted, which conditions allow progress, and which evidence authorizes release for operation.
See how POWER structures engineering, configuration, integration, and field services.
What can go wrong in a poorly planned retrofit?
The most significant risks are usually found in the interfaces and in the functions that were not explicitly reconstructed.
Equivalent swap only on paper
A new IED can have the same ANSI functions and still differ in inputs, outputs, logic, timing, filtering, supervision, communication, and behavior during transient conditions.
Incomplete documentation treated as ground truth
Outdated diagrams can omit changes made in the field. An implementation based solely on the document can remove an existing function or create an incorrect interface.
Focus on the relay and lack of a systemic view
Measurement, DC power supply, trip circuit, breaker, supervision, and remote control can remain unvalidated even when the new IED is correctly configured.
Interlock rebuilt without operational context
Converting contacts into digital logic without understanding the intent of the switching operation can produce unnecessary blocks or allow improper commands.
Communication validated only by connectivity
A device responding on the network does not prove the meaning, quality, timeliness, or behavior of the data during failures.
Fragmented testing
Equipment approved in isolation can fail when integrated. Validation needs to include the complete paths and the relevant operating and contingency scenarios.
Configuration without governance
Files without identification, version, an owner, and correspondence with what is installed make future maintenance slow and risky.
What tests are needed before entering operation?

The test plan must be developed together with the architecture and the philosophy. It needs to demonstrate that requirements and functions have been met, not just that each piece of equipment powers up or communicates.
| Grupo de teste | O que deve ser verificado |
|---|---|
| Inspeção e documentação | Identificação, montagem, bornes, cabos, fibras, versões, desenhos e correspondência com o projeto |
| Alimentação e circuitos CC | Polaridade, proteção, supervisão, quedas de tensão, comandos e continuidade dos circuitos críticos |
| Entradas e saídas | Estados, polaridades, escalas, contatos, comandos, alarmes e retorno de posição |
| Proteções | Grandezas de partida, temporizações, direção, restrições, zonas, bloqueios e sinais associados |
| Lógicas | Matrizes de trip, intertravamentos, permissivos, automatismos, falhas e estados de retorno |
| Comunicação | Datasets, reportes, comandos, GOOSE, protocolos, qualidade, perda e recuperação de enlaces |
| Sincronismo | Fonte de tempo, qualidade, distribuição, perda de referência e coerência dos registros |
| Supervisão | Telas, nomenclatura, alarmes, prioridades, medições, SOE, históricos e telecomando |
| Redundância | Comportamento diante da perda de fonte, servidor, switch, enlace ou outro elemento previsto |
| Ponto a ponto | Correspondência entre cada origem física ou lógica e seu destino |
| Funcional integrado | Resposta completa do sistema para cenários de proteção, controle, falha e contingência |
| End-to-end | Desempenho do caminho entre terminais ou sistemas quando a função depende de comunicação remota |
FAT, SAT, and field tests
The FAT makes it possible to anticipate problems before installation, especially in logic, communication, databases, and integration. The SAT confirms the solution in the real environment. Field tests validate circuits, polarities, interfaces with primary equipment, and conditions that cannot be fully reproduced in the factory.
The distribution between these stages depends on the scope, the architecture, and the client's requirements. What matters is maintaining traceability between requirement, function, procedure, result, and open item.
What must remain after commissioning
- test report and evidence;
- list of closed or formally addressed open items;
- as-built drawings;
- native files and backups;
- firmware and software version list;
- system configuration files;
- approved parameters and settings;
- communication matrix;
- logic documentation;
- recovery procedures;
- record of changes made in the field;
The actual deliverables must follow the limits and responsibilities defined in each contract.
How do you assess whether your SPCS is ready to keep operating?
Before deciding on maintenance, an upgrade, or a retrofit, gather evidence. This checklist does not replace an engineering assessment, but it helps identify gaps.
Checklist de avaliação
Checklist de avaliação do sistema de proteção e controle
POWER — Proteção, Controle e Automação de Subestações · bepower.com.br
Frequently asked questions about substation protection, control, and retrofit
O que significa SPCS?
SPCS é uma sigla usada para Sistema de Proteção, Controle e Supervisão. Ela representa o conjunto de dispositivos, circuitos, redes, lógicas, softwares e documentos que permitem proteger, comandar, automatizar e supervisionar uma instalação elétrica. A denominação e os limites exatos podem variar conforme o padrão do proprietário.
Qual é a diferença entre relé de proteção e IED?
Relé de proteção é o equipamento dedicado a executar funções de proteção. IED, ou dispositivo eletrônico inteligente, é uma designação mais ampla para equipamentos digitais capazes de medir, processar, comunicar e executar funções de proteção, controle ou automação. Muitos relés numéricos atuais são também IEDs.
Qual é a diferença entre proteção e controle?
A proteção identifica condições anormais e inicia ações para limitar seus efeitos, normalmente isolando a parte defeituosa. O controle processa comandos, permissivos, bloqueios e intertravamentos para que os equipamentos sejam operados nas condições previstas. As duas funções são integradas, mas possuem objetivos e critérios diferentes.
O que é retrofit de SPCS?
É a modernização planejada do sistema de proteção, controle e supervisão de uma instalação existente. Pode incluir relés, controladores, painéis, circuitos, comunicação, SCADA, sincronismo, alimentação e documentação. O retrofit pode ser pontual, por bay, por camada ou integral.
Retrofit é apenas trocar relés antigos por relés digitais?
Não. A troca do relé pode fazer parte do escopo, mas o retrofit precisa considerar medição, circuitos de trip, lógicas, intertravamentos, supervisão, comunicação, alimentação em corrente contínua, equipamentos primários, testes e estratégia de migração.
Quando um relé de proteção deve ser substituído?
Não existe uma idade única aplicável a todos os equipamentos. A decisão deve considerar suporte do fabricante, disponibilidade de sobressalentes e ferramentas, condição, desempenho, registros de falha, capacidade de expansão, compatibilidade com a arquitetura e consequência de uma indisponibilidade.
É possível fazer retrofit sem substituir todos os painéis?
Sim. Em muitos projetos é possível preservar painéis, fiação ou parte da base instalada, desde que sua condição e adequação sejam verificadas. A decisão deve avaliar espaço, bornes, circuitos, isolamento, alimentação, interfaces, documentação e a vida útil esperada do conjunto.
É possível integrar IEDs novos com equipamentos legados?
Sim, desde que as interfaces sejam tecnicamente compatíveis e testadas. A integração pode usar contatos físicos, protocolos, gateways ou soluções híbridas. É necessário preservar o significado dos sinais, os requisitos de tempo, a segurança dos comandos e a capacidade de diagnóstico.
IEC 61850 elimina toda a fiação convencional?
Não. A norma permite arquiteturas com diferentes graus de digitalização. Uma subestação pode usar IEC 61850 no barramento de estação e manter circuitos convencionais no processo. A redução de fiação depende da arquitetura adotada, do uso de GOOSE, Sampled Values, merging units e das exigências do projeto.
Equipamentos IEC 61850 são automaticamente interoperáveis?
Não automaticamente. A norma cria uma base comum, mas a interoperabilidade efetiva depende de modelos, serviços, edições, ferramentas, configuração, arquitetura e testes. A declaração de conformidade de cada dispositivo não substitui o teste do sistema integrado.
Um retrofit exige desligar toda a subestação?
Nem sempre. O desligamento depende da arquitetura, dos circuitos compartilhados, da estratégia de implantação e das condições operacionais. Modernizações por bay ou por etapas podem limitar a extensão das indisponibilidades, mas as interfaces temporárias e as janelas precisam ser planejadas.
Quais são os principais documentos de um retrofit?
O conjunto varia conforme o contrato, mas normalmente inclui levantamento do sistema existente, arquitetura, filosofia, diagramas, listas de sinais, lógicas, matriz de trip, rede e comunicação, parametrizações, procedimentos de teste e migração, relatórios e documentação as-built.
Como iniciar uma modernização de proteção e controle?
Comece pelo diagnóstico da instalação existente. Reúna documentos e arquivos, faça o levantamento de campo, identifique obsolescências, classifique funções críticas e defina requisitos operacionais. A seleção de tecnologia deve vir depois da definição da arquitetura e da estratégia de migração.
Antes de escolher o novo equipamento, entenda o sistema que continuará operando ao redor dele.
A POWER diagnostica, projeta, configura, integra e implanta sistemas de proteção, controle, supervisão e automação, considerando a base instalada, as funções críticas e as condições reais de migração.
Technical note
This content presents general engineering concepts and does not replace electrical studies, owner requirements, risk analysis, safety procedures, or project-specific documentation. Functions, settings, architectures, tests, and implementation strategies must be defined by qualified professionals and in accordance with applicable standards and requirements.
Technical basis and references
- 1.IEC 61850 Series — Communication networks and systems for power utility automation. International Electrotechnical Commission.
- 2.IEC 60255-1:2022 — Measuring relays and protection equipment — Common requirements. International Electrotechnical Commission.
- 3.IEEE C37.2-2022 — Electrical Power System Device Function Numbers, Acronyms, and Contact Designations. IEEE Standards Association.
- 4.IEC 62439-3:2021 — High-availability automation networks — PRP and HSR. International Electrotechnical Commission.
- 5.IEC 62351 Series — Data and communications security for power systems. International Electrotechnical Commission.
- 6.Applicable Grid Procedures — Operador Nacional do Sistema Elétrico and Agência Nacional de Energia Elétrica, Brazil, according to the project's regulatory classification.
- 7.Requirements, standards, and specifications of the facility owner, applicable to each project.
We do not reproduce extensive excerpts from the standards. The references indicate the technical basis; application should consider the editions contractually required for each project.