How to Select and Specify a Protection Relay for Medium-Voltage Switchgear: A 30-Point Engineering Checklist

A procurement-ready IEC 60255/61850 and IEEE C37 framework for exact hardware, firmware, licenses, evidence, bid scoring and acceptance.

Selecting an MV protection relay is not a feature-count contest. The correct device must implement the protection study securely, accept the actual CT/VT or digital process interface, energise the breaker trip path, survive the substation environment, integrate with station automation, remain testable and be supported through the plant lifecycle.

This 30-point engineering checklist turns those needs into a procurement specification and technical bid evaluation. Apply each point to the exact model, hardware option, firmware and licensed feature—not the vendor family brochure.

Executive rules

  • Freeze primary topology, protection philosophy and studies before comparing relay models.
  • Separate mandatory, preferred and future functions; require evidence for every mandatory claim.
  • Evaluate the complete scheme—sensor, IED, communications, DC/output, breaker, engineering tools and support.
  • Use current applicable IEC/IEEE editions and declare project deviations/profile options.
  • Check guaranteed performance and hardware common groups, not only menu screenshots.
  • Bid the exact bill of material, firmware, licenses, accessories, test tools, files and lifecycle services.
  • Use weighted technical compliance plus fatal noncompliance gates; lowest price cannot cure a wrong trip output or process interface.

1. Standards framework

ReferenceSelection relevance
IEC 60255-1:2022Common requirements; explicitly includes merging units/communications, binary outputs, LPIT and environmental conditions
IEC 60255-26:2023EMC emission/immunity for protection schemes and interfaces
IEC 60255-27:2023Product safety; not functional performance
IEC 60255-1xx functional standardsFunction-specific performance/characteristics/tests where applicable
IEC TS 60255-216-1:2025Digital-interface SV/GOOSE/time input/output protection functions and interoperability tests
IEC 61850-3/5/6/7/8/9 seriesEnvironment, communication requirements, SCL, data models and mappings
IEEE C37.2-2022Device functions, acronyms and contact designations
IEEE C37.90.1-2024 / C37.90.2-2024Current specialised surge/EFT and radiated-EMI withstand tests for IEEE projects

Do not write “IEC 60255 compliant” without listing relevant parts/editions and requested function/performance. A safety certificate under IEC 60255-27 does not demonstrate overcurrent or differential performance.

2. Prepare the application data sheet

  • system nominal/max voltage, frequency, grounding and fault levels;
  • one-line, source/transformer/motor/generator/feeder/capacitor data;
  • CT/VT/LPIT/MU ratings, classes, ratios, burden and connections;
  • protection functions, zones, settings ranges and clearing times;
  • breaker mechanism, trip coils, DC voltage envelope and TCS;
  • I/O, SCADA/alarm, interlocking and transfer requirements;
  • IEC 61850/protocol/network/time/cyber architecture;
  • environment, panel arrangement, EMC and auxiliary supplies;
  • redundancy, maintenance/test, lifecycle and documentation needs.

3. The 30-point engineering checklist

  1. Application and protected object. State whether the IED protects an incomer, feeder, transformer, motor, generator, capacitor, bus coupler or busbar zone. Confirm source direction, network grounding, island/parallel states and operating modes. Reject a generic “feeder relay” assumption when the topology needs transformer inrush restraint, motor thermal/start logic, directional earth-fault polarisation or synchronism.
  2. Applicable standards and editions. List IEC 60255 common, EMC, safety and function parts; IEC 61850 profile; IEEE requirements where contractually used; environmental/cyber and utility specifications. Require a compliance matrix distinguishing certified/type-tested, designed-to-comply and exception. Review the exact test-report model, hardware, firmware and port configuration.
  3. Protection-function coverage. Map every required ANSI/IEC function to the relay’s implemented element and licensed option: phase/earth overcurrent, directional, voltage/frequency, thermal, negative sequence, differential, REF, breaker failure, arc input, synchronism and others. Include element quantity, stages, characteristic choices, blocking/restraint, starts/trips and independent setting ranges.
  4. Study-derived sensitivity and setting range. Confirm minimum pickup, maximum setting, step/resolution, curve/time range and measurement accuracy can realise the approved study with margin. Check high-resistance earth fault, minimum generation/island fault and maximum load/inrush. A wide advertised range is useless if accuracy, dropout or dynamic performance at the chosen point is unsuitable.
  5. Dynamic and transient performance. Obtain guaranteed/documented performance for DC-offset faults, CT saturation, transformer inrush/overexcitation, motor starting/reacceleration, frequency variation, CVT/VT transients, power swings or intermittent earth faults as applicable. Require COMTRADE/real-time test evidence for critical algorithms, not only steady-state ramp accuracy.
  6. Conventional current inputs. Specify 1 A/5 A rating, continuous/short-time withstand, input burden, linear/dynamic range, isolation and terminal safety. Verify calculated CT burden/class/knee/transient performance with relay inputs. Check phase/residual connections, dual earth-current inputs, sensitive CBCT range and whether input switching/taps are hardware or configuration controlled.
  7. Voltage and frequency inputs. Specify phase-to-neutral/phase-to-phase nominal range, continuous/overvoltage withstand, burden, accuracy, frequency range and connection (3/4 wire, broken delta/residual). Confirm synchronism-check uses independent line/bus inputs and handles VT fuse failure, source selection and dead-bus logic securely.
  8. LPIT, merging-unit and sampled-value capability. If digital process interface is used, specify IEC 61869/61850 compatibility, supported sample rates/stream count, ratio/scaling, quality/time handling, redundancy and loss/fallback. Require IEC TS 60255-216-1:2025 functional-interoperability evidence where applicable; “SV supported” without exact profile/subscription limits is inadequate.
  9. Measurement, metering and recording accuracy. Define protection measurement versus operational metering/PQ needs, primary scaling, RMS/phasor method, energy/demand accuracy and frequency/phase resolution. A protection IED value is not automatically revenue grade. Specify overrange, bad-quality behaviour and calibration/traceability expectations.
  10. Binary-input electrical characteristics. Match nominal/min/max DC/AC voltage, pickup/dropout thresholds, hysteresis, current/wetting, polarity, isolation and shared commons. Analyse contact film, cable leakage/capacitance and long-run induced voltage. Specify debounce/SOE timestamp separately; slow filtering can compromise breaker-failure or transfer logic.
  11. Binary-output duty. Inventory high-speed, standard, changeover, latching and watchdog outputs. Check actual DC inductive make/carry/break or L/R duty at trip/close/interposing coils, not a general “8 A” rating. Confirm contact isolation/commons, output operate/release time, pulse/continuous capability, suppression effects and weld/open failure response.
  12. Auxiliary power and DC envelope. Match nominal/minimum/maximum station DC, power/inrush, interruption/dip/ripple, polarity and earthing. Check start-up and brownout/reset behaviour, output states, retained latches and restoration alarms. Include dual power-supply options and independence if required; calculate shared DC load during disturbances.
  13. I/O quantity, card topology and spares. Allocate every signal before ordering. Map card slots, terminals, internal commons, isolation groups and power dependencies; reserve spares by required type/common/location, not total percentage. Verify expansion can be installed/configured without replacing the chassis or invalidating environmental/type-test assumptions.
  14. Redundancy and common-mode independence. Define Protection 1/2 separation through CT cores or MUs, IED power, network, outputs, terminals, cables, breaker coils and settings/tool common modes. Two identical relays improve some failures but share systematic firmware/configuration risks; diversity may add complexity. Require a documented failure-domain diagram.
  15. Breaker and trip-circuit interface. Verify dual trip coils, TCS coverage in breaker open/closed/test/service states, 52a/52b logic, close circuit, anti-pumping, spring/pressure ready and breaker-failure initiation/retrip. Ensure the relay can supervise the actual circuit without leakage operating the coil or auxiliary inputs.
  16. Programmable logic capability and governance. Check logic gates, timers, latches, edge/pulse functions, equation size, execution cycle, priority/order and online diagnostics. Require readable logic diagrams/reports, version/checksum, independent review and simulation. Avoid embedding safety interlocks in opaque vendor scripting with no deterministic test or fallback.
  17. Setting groups and adaptive logic. Specify number of groups, what parameters change, selection authority, changeover atomicity/time and active-group indication. Validate group selection on topology/source changes and failure response. Prevent remote/cyber or lost input from selecting an unsafe group; record group changes in SOE/audit.
  18. Event, disturbance and fault records. Define SOE resolution/source timestamp, event depth, oscillography channels/sample rate/pre-fault/post-fault length, trigger logic, file format and storage overwrite. Require COMTRADE export, record quality/time flags, automated retrieval where needed and buffer capacity for a mass trip/communications outage.
  19. Local HMI and human factors. Require clear mimic/measurements, trip targets, first-out, active settings, I/O/GOOSE/SV/time/DC health and blocked/bypass indication. Check language, access roles, LED quantity/colour/labels and safe reset authority. The front panel must aid emergency diagnosis without exposing uncontrolled configuration.
  20. IEC 61850 data model and SCL engineering. Specify edition, logical nodes/data objects, server limits, reports/logs, controls, GOOSE/SV, test/simulation and SCL workflow (ICD/IID/CID/SCD). Confirm configurable datasets/control blocks, naming limits and tool interoperability. Require the exact as-built SCL and reports, not only a vendor-private database.
  21. GOOSE and communication performance. Define application transfer-time class/maximum, publisher retransmission, subscriber supervision, stale/quality behaviour, VLAN/priority and simultaneous traffic. Check the complete IED input-to-output time, not network transit alone. Test loss, duplicate, delay, sequence, reboot and recovery under representative load.
  22. Protocols, gateway and SCADA interfaces. List required IEC 61850 MMS, IEC 60870-5-103/104, DNP3, Modbus or other profiles only where needed. Specify point capacity, time/quality mapping, command control model, simultaneous clients and redundancy. Avoid protocol quantity becoming a substitute for semantic interoperability and cyber control.
  23. Station network and time synchronisation. Specify port count/media, PRP/HSR support and edition, VLAN/QoS, link supervision, PTP IEC/IEEE 61850-9-3, IRIG-B or NTP. Define required time accuracy/holdover and function behaviour on loss. Check network switch/clock common modes and fibre transceiver compatibility.
  24. Cybersecurity and access control. Define role-based local/remote privileges, authentication, secure protocols/management, unused-service disablement, logging, firmware/setting authenticity, key/certificate lifecycle, ports and vulnerability response. Protection must continue safely if remote security services or SCADA are unavailable. Require supplier secure-development/support commitments appropriate to project risk.
  25. EMC, safety and environmental suitability. Require IEC 60255-26:2023 and IEC 60255-27:2023 evidence for the exact configuration plus temperature, humidity, altitude, vibration/shock/seismic, enclosure/IP and pollution/overvoltage context. For IEEE projects assess current C37.90.x tests. Check derating, ventilation, heat and panel mounting, not just a catalogue temperature range.
  26. Mechanical form, terminals and installation. Confirm rack/flush dimensions, panel cut-out, depth, weight, terminal access, removable plugs/CT shorting safety, wire sizes, connector coding, PE, optical connectors and minimum bend radius. Ensure replacement can occur without disturbing adjacent CT/trip circuits and that the LV compartment maintains separation/access requirements.
  27. Self-supervision and maintainability. Define watchdog output, processor/memory/I/O/ADC/power/network/time/SV/GOOSE diagnostics and alarm granularity. Identify failures not covered by self-test and periodic test interval. Check hot/warm/cold replacement, configuration restore, calibration policy, operation counters and health data export.
  28. Engineering tools, licenses and data ownership. Price all software, cables/adapters, dongles/licenses, drivers and future-seat/upgrade costs. Require offline logic/settings review, comparison, audit, batch management, COMTRADE/SCL import/export and documented file formats. The owner needs editable native files plus human-readable reports and a reproducible restore workflow.
  29. Lifecycle, firmware, obsolescence and support. Obtain product support horizon, spare/repair turnaround, firmware/security patch policy, backward configuration compatibility, notification and migration path. Define approval/regression tests before upgrades. Evaluate local technical competence, training, manuals, language, factory support and installed-base experience for the exact application.
  30. Verification, deliverables and contractual acceptance. Require type/conformance/interoperability reports, detailed compliance matrix, exact BOM, datasheets/manuals, FAT/SAT procedures, settings/logic/SCL, cybersecurity/lifecycle documents and training. Contractually define dynamic/end-to-end/failure tests, defect closure, as-built extraction/checksum, warranty and performance guarantees; unresolved “comply” statements are not acceptance evidence.

4. Bid-evaluation method

ClassTreatment
Fatal/mandatoryReject or formally redesign: protection function/performance, CT/VT/SV compatibility, trip duty, DC, safety/EMC, critical interoperability
Weighted technicalScore functionality, evidence, testability, engineering, lifecycle, cyber, support and maintainability
Commercial/lifecycleExact BOM, licenses/tools, spares, training, support, upgrades, warranty and total ownership cost
Risk adjustmentPenalise unproven firmware/application, exceptions, proprietary lock-in and missing test evidence

Require vendors to answer each clause with Comply / Partial / Exception / Not applicable, exact document/page evidence and proposed deviation. A blank or “noted” response is not compliance. Evaluate a representative configured sample or factory demonstration before final award for high-risk applications.

5. FAT acceptance package

  • serial/model/hardware/firmware/license and module/terminal verification;
  • as-loaded settings/logic/checksum and independent settings report comparison;
  • analogue/current/voltage and binary input/output checks;
  • dynamic function tests at security/dependability boundaries;
  • DC min/max/dip/power-cycle and output-state tests;
  • trip/close/TCS/breaker-failure end-to-end interface tests;
  • IEC 61850 SCL, GOOSE/SV/MMS, quality/test/time and network-failure tests;
  • SCADA commands/status/measurements/alarms and protocol mapping;
  • self-supervision, watchdog, user roles/cyber settings and record retrieval;
  • complete native/readable as-built files, manuals, certificates and issue closure.

6. Common procurement errors

ErrorWhy it failsCorrection
Specify only ANSI function numbersPerformance, stages and logic undefinedFunctional characteristics/settings/tests
“IEC 60255 compliant”Parts/editions/evidence ambiguousExact standards compliance matrix
Count I/O onlyCommons/duty/isolation ignoredChannel allocation and electrical profiles
Select by family brochureOption/firmware/license differsExact configured BOM
Protocol tick-boxSemantic/profile interoperability unprovenSCL/data/control/performance tests
Tools/support excludedLifecycle cost/lock-in appears laterTotal ownership deliverables
FAT only secondary rampsDynamic/logic/network/failure defects latentEnd-to-end risk-based acceptance

References and further reading

Engineering note: The checklist is a specification framework. Final requirements must be derived from the actual network studies, breaker/DC/sensor interfaces, operating policy and owner cybersecurity/lifecycle standards.

LearnSwitchgear

Search the engineering library