The substation is a foreign country

The manufacturer's lead control engineer asks, perfectly reasonably, for the single-line diagram of the 220 kV substation. They want to understand the busbar arrangement, the transformer impedances, the protection scheme, the timing of the reclosers, the disturbance recorder configuration. They are designing a wind farm controller and want to model how the substation will respond to faults so the turbine controller can ride through them appropriately.

The asset owner's substation team declines.

Not impolitely. Not as an act of obstruction. They decline because the document the manufacturer has asked for sits inside a different engineering discipline, owned by different people, subject to different standards, regulated by a different authority, and shared on different terms — and because the manufacturer does not need it to do their job.

The substation is a foreign country. The wind or solar plant ends at a defined electrical and informational boundary, and beyond that boundary the engineering belongs to another discipline. The grid operator sets the rules through the connection agreement. The protection and control engineers set the configuration through the protection coordination study. The substation cybersecurity team — sometimes the asset owner's, sometimes the transmission system operator's, sometimes a third party — sets the security architecture inside the fence. The manufacturer specifies what comes across the boundary, in which protocol, with which data points, at what update rate. Everything beyond the boundary is opaque by design.

This applies whether the substation in question is the on-site collection substation built specifically for the project, or the transmission substation connecting the plant to the grid. The physical location does not determine the discipline. A 33 kV collection substation sitting fifty metres from the nearest wind turbine is still substation engineering, still governed by protection coordination, still subject to the grid code, still inside a different design authority than the turbines that feed it.

Why the substation is its own jurisdiction

Several reasons converge to make this separation non-negotiable.

Grid code compliance is national. The grid code is set by the national transmission system operator and the energy regulator. It defines how plants must behave at the point of connection — fault ride-through capability, frequency response, reactive power range, voltage regulation, harmonic emissions, communication and telemetry to the control centre. Compliance is demonstrated at the substation interface and witnessed by the grid operator. The manufacturer contributes to grid code compliance through the behaviour of the equipment they deliver, but the demonstration is conducted at, and on the substation side of, the boundary.

Protection coordination is a separate engineering discipline. Protection settings are calculated by P&C engineers who model the entire network — not only the plant, but upstream lines, neighbouring substations, and the grid behind them. Settings interact with reclosers, disturbance recorders, breaker failure protection and busbar protection schemes that have been engineered to coordinate across the whole grid section. A manufacturer who wants to alter, or even to fully understand, the protection scheme is reaching into engineering that is neither under the asset owner's contractual control nor under the grid operator's design authority.

Cybersecurity inside the substation is its own zoning problem. Substations operate under IEC 61850 station-bus and process-bus architectures, frequently with intelligent electronic devices from different vendors than the plant SCADA, their own time synchronisation infrastructure, and their own security framework under IEC 62351. The cybersecurity zoning inside a substation is a separate design exercise from the plant's IEC 62443 zoning, conducted by different engineers, with its own threat model and its own conformance evidence.

Physical and informational security is separately regulated. In many jurisdictions substations are protected under critical infrastructure or counter-terrorism legislation that imposes its own personnel vetting, physical access control and reporting obligations. The information that describes a substation — the single-line, the protection scheme, the physical layout, the list of personnel with access credentials — is regulated information. Who holds it, how it is transmitted, and on what authority it is shared, are matters governed by law rather than by contract.

What the manufacturer specifies at the boundary

At the boundary the manufacturer specifies a fairly precise set of things.

The protocol used to exchange data. For most modern projects this is IEC 60870-5-104 for telecontrol to and from the grid control centre, IEC 61850 MMS or GOOSE for higher-bandwidth integration with substation automation, occasionally DNP3 in markets where it remains dominant, and IEC 61400-25 for wind-specific monitoring extensions over the 61850 framework.

The data points exchanged — analogue measurements, status indications, control commands, sequence-of-events records, fault records — usually documented in an interface control document that lists every point, its data type, its scaling, its update logic, its quality flags, and the events that trigger it.

The performance envelope — update rate per point class, end-to-end latency targets, packet loss tolerance, jitter sensitivity for time-critical data.

The grid code obligations that the plant supports and the substation reports — fault ride-through behaviour, reactive power capability curves, frequency response characteristics, the events that constitute non-compliance and must be logged.

The security requirements for the link itself — IEC 62351-3 for transport-layer security on TCP/IP profiles, IEC 62351-5 for serial and derived protocols, IEC 62351-6 for the IEC 61850 protocols, certificate-based authentication, and the credential management lifecycle for the certificates and keys used at the boundary.

Time synchronisation deserves a short note because it is the one technical area where the plant and substation share an unavoidable dependency. The substation runs its own time infrastructure, typically a GNSS-disciplined master clock distributing IRIG-B over fibre or IEC 61588 (PTPv2) over Ethernet to the IEDs and the disturbance recorder. The plant runs its own time infrastructure for SCADA, historian, engineering workstations and turbine or inverter controllers. From the manufacturer's perspective, the requirement is straightforward: their equipment accepts time from an operator-provided source at the accuracy the application requires. The protocol, the source address, the path and the redundancy of that time source are operator decisions. The manufacturer states the accuracy required as a number — "synchronisation to better than 1 ms" — not as an architecture.

That is the contract at the boundary. What flows across it is bilaterally agreed and documented. What happens on either side of it is owned by the engineering discipline responsible for that side.

What the manufacturer does not get to see

The single-line diagram of the substation. The bay configurations. The protection coordination study and the relay settings. The busbar configuration and the breaker failure protection logic. The disturbance recorder configuration. The substation automation logic diagrams. The physical layout drawings of the switchyard. The list of personnel with access credentials. The substation's own cybersecurity zone and conduit diagram. The fibre infrastructure plan inside the substation. The auxiliary supply arrangement.

This is not an exhaustive list. The principle is that anything inside the substation fence — electrically or informationally — belongs to the substation engineering team and is shared on a need-to-know basis with parties whose contractual scope of work requires access to it. A wind turbine or solar inverter manufacturer's scope of work does not require it. The controller needs to ride through faults; the fault behaviour is specified at the boundary, through low-voltage ride-through curves, frequency response requirements and reactive power capability obligations expressed as parameters, without the manufacturer needing to see how those faults arise or how the substation responds to them.

There is a particular value in being clear about this with manufacturers accustomed to operating in markets where one engineering team designs the plant, the substation and the grid interface as a single integrated package. In an EU-financed project, none of those three is the manufacturer's. The plant is the asset owner's. The substation is the asset owner's substation team's, working under the connection agreement with the grid operator and under the supervision of the protection and control discipline. The grid is the grid operator's. The manufacturer is one supplier into one of those three engineering domains.

The single-line diagram example is worth lingering on because it crystallises the principle. A protection coordination study has been conducted on the assumption that the wind plant or solar plant injects current at the boundary with a defined fault behaviour. The boundary fault behaviour is what the manufacturer must deliver. The reasoning behind the protection scheme — why those particular relay settings, why that particular reclose logic, why the busbar protection is configured as it is — is the substation engineering team's working. The manufacturer does not need it to deliver the boundary behaviour, and providing it would expose engineering that is rightly held within a smaller circle of people.

At proposal stage

The principle holds in proposal documents the same way it holds in design. A bid that specifies the equipment, the boundary protocols, the boundary data points, the boundary performance, the grid code parameters supported by the equipment, and the security obligations the manufacturer will meet for the link itself — and stops there — is a bid the asset owner's substation team and the grid interface team can work with. A bid that includes a proposed single-line diagram for the substation, or that demands access to the protection coordination study for design verification, or that assumes specific relay settings, or that proposes substation cybersecurity controls beyond the boundary, is a bid that creates friction.

The friction in many early conversations is not about whether the manufacturer is competent. It is about whether they have understood that they are one engineering discipline among several, and that their authority ends at a boundary that has been deliberately drawn there. The substation team is not being unhelpful. They are being correct.

The next article moves from architectural questions to operational ones, beginning with the most consistent surprise of all: the persistent VPN tunnel from the manufacturer's office to the plant, which has been the industry's default for a decade, is no longer on the table.


This article reflects the regulatory and standards landscape at publication. References to IEC 61850, IEC 62351, IEC 61588 and IEC 60870-5-104 may be superseded by revisions of those standards; national grid codes evolve continually. If a citation has rotted or a clause has moved, LinkedIn is the way to flag it.