Selecting an MV protection relay is not a feature-count contest. The correct device must implement the protection study securely, accept the actual CT/VT or digital process interface, energise the breaker trip path, survive the substation environment, integrate with station automation, remain testable and be supported through the plant lifecycle.
This 30-point engineering checklist turns those needs into a procurement specification and technical bid evaluation. Apply each point to the exact model, hardware option, firmware and licensed feature—not the vendor family brochure.
Executive rules
- Freeze primary topology, protection philosophy and studies before comparing relay models.
- Separate mandatory, preferred and future functions; require evidence for every mandatory claim.
- Evaluate the complete scheme—sensor, IED, communications, DC/output, breaker, engineering tools and support.
- Use current applicable IEC/IEEE editions and declare project deviations/profile options.
- Check guaranteed performance and hardware common groups, not only menu screenshots.
- Bid the exact bill of material, firmware, licenses, accessories, test tools, files and lifecycle services.
- Use weighted technical compliance plus fatal noncompliance gates; lowest price cannot cure a wrong trip output or process interface.
1. Standards framework
| Reference | Selection relevance |
|---|---|
| IEC 60255-1:2022 | Common requirements; explicitly includes merging units/communications, binary outputs, LPIT and environmental conditions |
| IEC 60255-26:2023 | EMC emission/immunity for protection schemes and interfaces |
| IEC 60255-27:2023 | Product safety; not functional performance |
| IEC 60255-1xx functional standards | Function-specific performance/characteristics/tests where applicable |
| IEC TS 60255-216-1:2025 | Digital-interface SV/GOOSE/time input/output protection functions and interoperability tests |
| IEC 61850-3/5/6/7/8/9 series | Environment, communication requirements, SCL, data models and mappings |
| IEEE C37.2-2022 | Device functions, acronyms and contact designations |
| IEEE C37.90.1-2024 / C37.90.2-2024 | Current specialised surge/EFT and radiated-EMI withstand tests for IEEE projects |
Do not write “IEC 60255 compliant” without listing relevant parts/editions and requested function/performance. A safety certificate under IEC 60255-27 does not demonstrate overcurrent or differential performance.
2. Prepare the application data sheet
- system nominal/max voltage, frequency, grounding and fault levels;
- one-line, source/transformer/motor/generator/feeder/capacitor data;
- CT/VT/LPIT/MU ratings, classes, ratios, burden and connections;
- protection functions, zones, settings ranges and clearing times;
- breaker mechanism, trip coils, DC voltage envelope and TCS;
- I/O, SCADA/alarm, interlocking and transfer requirements;
- IEC 61850/protocol/network/time/cyber architecture;
- environment, panel arrangement, EMC and auxiliary supplies;
- redundancy, maintenance/test, lifecycle and documentation needs.
3. The 30-point engineering checklist
- Application and protected object. State whether the IED protects an incomer, feeder, transformer, motor, generator, capacitor, bus coupler or busbar zone. Confirm source direction, network grounding, island/parallel states and operating modes. Reject a generic “feeder relay” assumption when the topology needs transformer inrush restraint, motor thermal/start logic, directional earth-fault polarisation or synchronism.
- Applicable standards and editions. List IEC 60255 common, EMC, safety and function parts; IEC 61850 profile; IEEE requirements where contractually used; environmental/cyber and utility specifications. Require a compliance matrix distinguishing certified/type-tested, designed-to-comply and exception. Review the exact test-report model, hardware, firmware and port configuration.
- Protection-function coverage. Map every required ANSI/IEC function to the relay’s implemented element and licensed option: phase/earth overcurrent, directional, voltage/frequency, thermal, negative sequence, differential, REF, breaker failure, arc input, synchronism and others. Include element quantity, stages, characteristic choices, blocking/restraint, starts/trips and independent setting ranges.
- Study-derived sensitivity and setting range. Confirm minimum pickup, maximum setting, step/resolution, curve/time range and measurement accuracy can realise the approved study with margin. Check high-resistance earth fault, minimum generation/island fault and maximum load/inrush. A wide advertised range is useless if accuracy, dropout or dynamic performance at the chosen point is unsuitable.
- Dynamic and transient performance. Obtain guaranteed/documented performance for DC-offset faults, CT saturation, transformer inrush/overexcitation, motor starting/reacceleration, frequency variation, CVT/VT transients, power swings or intermittent earth faults as applicable. Require COMTRADE/real-time test evidence for critical algorithms, not only steady-state ramp accuracy.
- Conventional current inputs. Specify 1 A/5 A rating, continuous/short-time withstand, input burden, linear/dynamic range, isolation and terminal safety. Verify calculated CT burden/class/knee/transient performance with relay inputs. Check phase/residual connections, dual earth-current inputs, sensitive CBCT range and whether input switching/taps are hardware or configuration controlled.
- Voltage and frequency inputs. Specify phase-to-neutral/phase-to-phase nominal range, continuous/overvoltage withstand, burden, accuracy, frequency range and connection (3/4 wire, broken delta/residual). Confirm synchronism-check uses independent line/bus inputs and handles VT fuse failure, source selection and dead-bus logic securely.
- LPIT, merging-unit and sampled-value capability. If digital process interface is used, specify IEC 61869/61850 compatibility, supported sample rates/stream count, ratio/scaling, quality/time handling, redundancy and loss/fallback. Require IEC TS 60255-216-1:2025 functional-interoperability evidence where applicable; “SV supported” without exact profile/subscription limits is inadequate.
- Measurement, metering and recording accuracy. Define protection measurement versus operational metering/PQ needs, primary scaling, RMS/phasor method, energy/demand accuracy and frequency/phase resolution. A protection IED value is not automatically revenue grade. Specify overrange, bad-quality behaviour and calibration/traceability expectations.
- Binary-input electrical characteristics. Match nominal/min/max DC/AC voltage, pickup/dropout thresholds, hysteresis, current/wetting, polarity, isolation and shared commons. Analyse contact film, cable leakage/capacitance and long-run induced voltage. Specify debounce/SOE timestamp separately; slow filtering can compromise breaker-failure or transfer logic.
- Binary-output duty. Inventory high-speed, standard, changeover, latching and watchdog outputs. Check actual DC inductive make/carry/break or L/R duty at trip/close/interposing coils, not a general “8 A” rating. Confirm contact isolation/commons, output operate/release time, pulse/continuous capability, suppression effects and weld/open failure response.
- Auxiliary power and DC envelope. Match nominal/minimum/maximum station DC, power/inrush, interruption/dip/ripple, polarity and earthing. Check start-up and brownout/reset behaviour, output states, retained latches and restoration alarms. Include dual power-supply options and independence if required; calculate shared DC load during disturbances.
- I/O quantity, card topology and spares. Allocate every signal before ordering. Map card slots, terminals, internal commons, isolation groups and power dependencies; reserve spares by required type/common/location, not total percentage. Verify expansion can be installed/configured without replacing the chassis or invalidating environmental/type-test assumptions.
- Redundancy and common-mode independence. Define Protection 1/2 separation through CT cores or MUs, IED power, network, outputs, terminals, cables, breaker coils and settings/tool common modes. Two identical relays improve some failures but share systematic firmware/configuration risks; diversity may add complexity. Require a documented failure-domain diagram.
- Breaker and trip-circuit interface. Verify dual trip coils, TCS coverage in breaker open/closed/test/service states, 52a/52b logic, close circuit, anti-pumping, spring/pressure ready and breaker-failure initiation/retrip. Ensure the relay can supervise the actual circuit without leakage operating the coil or auxiliary inputs.
- Programmable logic capability and governance. Check logic gates, timers, latches, edge/pulse functions, equation size, execution cycle, priority/order and online diagnostics. Require readable logic diagrams/reports, version/checksum, independent review and simulation. Avoid embedding safety interlocks in opaque vendor scripting with no deterministic test or fallback.
- Setting groups and adaptive logic. Specify number of groups, what parameters change, selection authority, changeover atomicity/time and active-group indication. Validate group selection on topology/source changes and failure response. Prevent remote/cyber or lost input from selecting an unsafe group; record group changes in SOE/audit.
- Event, disturbance and fault records. Define SOE resolution/source timestamp, event depth, oscillography channels/sample rate/pre-fault/post-fault length, trigger logic, file format and storage overwrite. Require COMTRADE export, record quality/time flags, automated retrieval where needed and buffer capacity for a mass trip/communications outage.
- Local HMI and human factors. Require clear mimic/measurements, trip targets, first-out, active settings, I/O/GOOSE/SV/time/DC health and blocked/bypass indication. Check language, access roles, LED quantity/colour/labels and safe reset authority. The front panel must aid emergency diagnosis without exposing uncontrolled configuration.
- IEC 61850 data model and SCL engineering. Specify edition, logical nodes/data objects, server limits, reports/logs, controls, GOOSE/SV, test/simulation and SCL workflow (ICD/IID/CID/SCD). Confirm configurable datasets/control blocks, naming limits and tool interoperability. Require the exact as-built SCL and reports, not only a vendor-private database.
- GOOSE and communication performance. Define application transfer-time class/maximum, publisher retransmission, subscriber supervision, stale/quality behaviour, VLAN/priority and simultaneous traffic. Check the complete IED input-to-output time, not network transit alone. Test loss, duplicate, delay, sequence, reboot and recovery under representative load.
- Protocols, gateway and SCADA interfaces. List required IEC 61850 MMS, IEC 60870-5-103/104, DNP3, Modbus or other profiles only where needed. Specify point capacity, time/quality mapping, command control model, simultaneous clients and redundancy. Avoid protocol quantity becoming a substitute for semantic interoperability and cyber control.
- Station network and time synchronisation. Specify port count/media, PRP/HSR support and edition, VLAN/QoS, link supervision, PTP IEC/IEEE 61850-9-3, IRIG-B or NTP. Define required time accuracy/holdover and function behaviour on loss. Check network switch/clock common modes and fibre transceiver compatibility.
- Cybersecurity and access control. Define role-based local/remote privileges, authentication, secure protocols/management, unused-service disablement, logging, firmware/setting authenticity, key/certificate lifecycle, ports and vulnerability response. Protection must continue safely if remote security services or SCADA are unavailable. Require supplier secure-development/support commitments appropriate to project risk.
- EMC, safety and environmental suitability. Require IEC 60255-26:2023 and IEC 60255-27:2023 evidence for the exact configuration plus temperature, humidity, altitude, vibration/shock/seismic, enclosure/IP and pollution/overvoltage context. For IEEE projects assess current C37.90.x tests. Check derating, ventilation, heat and panel mounting, not just a catalogue temperature range.
- Mechanical form, terminals and installation. Confirm rack/flush dimensions, panel cut-out, depth, weight, terminal access, removable plugs/CT shorting safety, wire sizes, connector coding, PE, optical connectors and minimum bend radius. Ensure replacement can occur without disturbing adjacent CT/trip circuits and that the LV compartment maintains separation/access requirements.
- Self-supervision and maintainability. Define watchdog output, processor/memory/I/O/ADC/power/network/time/SV/GOOSE diagnostics and alarm granularity. Identify failures not covered by self-test and periodic test interval. Check hot/warm/cold replacement, configuration restore, calibration policy, operation counters and health data export.
- Engineering tools, licenses and data ownership. Price all software, cables/adapters, dongles/licenses, drivers and future-seat/upgrade costs. Require offline logic/settings review, comparison, audit, batch management, COMTRADE/SCL import/export and documented file formats. The owner needs editable native files plus human-readable reports and a reproducible restore workflow.
- Lifecycle, firmware, obsolescence and support. Obtain product support horizon, spare/repair turnaround, firmware/security patch policy, backward configuration compatibility, notification and migration path. Define approval/regression tests before upgrades. Evaluate local technical competence, training, manuals, language, factory support and installed-base experience for the exact application.
- Verification, deliverables and contractual acceptance. Require type/conformance/interoperability reports, detailed compliance matrix, exact BOM, datasheets/manuals, FAT/SAT procedures, settings/logic/SCL, cybersecurity/lifecycle documents and training. Contractually define dynamic/end-to-end/failure tests, defect closure, as-built extraction/checksum, warranty and performance guarantees; unresolved “comply” statements are not acceptance evidence.
4. Bid-evaluation method
| Class | Treatment |
|---|---|
| Fatal/mandatory | Reject or formally redesign: protection function/performance, CT/VT/SV compatibility, trip duty, DC, safety/EMC, critical interoperability |
| Weighted technical | Score functionality, evidence, testability, engineering, lifecycle, cyber, support and maintainability |
| Commercial/lifecycle | Exact BOM, licenses/tools, spares, training, support, upgrades, warranty and total ownership cost |
| Risk adjustment | Penalise unproven firmware/application, exceptions, proprietary lock-in and missing test evidence |
Require vendors to answer each clause with Comply / Partial / Exception / Not applicable, exact document/page evidence and proposed deviation. A blank or “noted” response is not compliance. Evaluate a representative configured sample or factory demonstration before final award for high-risk applications.
5. FAT acceptance package
- serial/model/hardware/firmware/license and module/terminal verification;
- as-loaded settings/logic/checksum and independent settings report comparison;
- analogue/current/voltage and binary input/output checks;
- dynamic function tests at security/dependability boundaries;
- DC min/max/dip/power-cycle and output-state tests;
- trip/close/TCS/breaker-failure end-to-end interface tests;
- IEC 61850 SCL, GOOSE/SV/MMS, quality/test/time and network-failure tests;
- SCADA commands/status/measurements/alarms and protocol mapping;
- self-supervision, watchdog, user roles/cyber settings and record retrieval;
- complete native/readable as-built files, manuals, certificates and issue closure.
6. Common procurement errors
| Error | Why it fails | Correction |
|---|---|---|
| Specify only ANSI function numbers | Performance, stages and logic undefined | Functional characteristics/settings/tests |
| “IEC 60255 compliant” | Parts/editions/evidence ambiguous | Exact standards compliance matrix |
| Count I/O only | Commons/duty/isolation ignored | Channel allocation and electrical profiles |
| Select by family brochure | Option/firmware/license differs | Exact configured BOM |
| Protocol tick-box | Semantic/profile interoperability unproven | SCL/data/control/performance tests |
| Tools/support excluded | Lifecycle cost/lock-in appears later | Total ownership deliverables |
| FAT only secondary ramps | Dynamic/logic/network/failure defects latent | End-to-end risk-based acceptance |
References and further reading
- IEC 60255-1:2022 — Common requirements
- IEC 60255-26:2023 — EMC requirements
- IEC 60255-27:2023 — Product safety
- IEC TS 60255-216-1:2025 — Digital-interface protection functions
- IEC 61850-3:2013 — Utility IED general requirements
- IEC 61850-6:2009+A1:2018+A2:2024 — SCL configuration language
- IEEE C37.2-2022 — Device functions and acronyms
- IEEE C37.90.1-2024 — SWC/EFT tests
- IEEE C37.90.2-2024 — Radiated-EMI tests
Engineering note: The checklist is a specification framework. Final requirements must be derived from the actual network studies, breaker/DC/sensor interfaces, operating policy and owner cybersecurity/lifecycle standards.