SCADA and Automation SAT: A Practical End-to-End Verification Checklist

A risk-based site acceptance checklist covering point-to-point, reports, controls, automation, timing, redundancy, security and energization hold points.

SCADA/automation SAT proves the installed system from physical input and breaker mechanism to station HMI and control center under real wiring, networks, time, authority and operating procedures. It is not a repeat of vendor FAT and not a point-list checkbox exercise: site-specific interfaces, failures, latency, redundancy, cybersecurity and restoration must be demonstrated.

This checklist covers IEC 61850 station systems with IEC 60870-5-104/DNP3/Modbus integration. Adapt test scope to risk and approved switching conditions; never bypass electrical safety to obtain a “pass.”

1. SAT entry criteria

  • Approved architecture, SLD, cause/effect, point list, SCD, gateway/HMI/control-center database and network/time/cyber drawings.
  • FAT complete with defects closed or formally accepted with site action.
  • Installed wiring/termination/labels and panel checks complete.
  • IED/gateway/server/switch/clock firmware, settings and licenses frozen.
  • Primary equipment and control DC ready; approved switching/test permits.
  • Calibrated test equipment, simulators, packet capture and synchronized timing tools.
  • Defined responsibilities, stop criteria, rollback and operations handback.

2. Configuration baseline

  • Record hardware serials, firmware/software/tool/library versions.
  • Export/read back IED settings, logic, SCD/ICD/CID as applicable, gateway map and HMI/control-center build.
  • Verify IP/MAC/VLAN/PRP-HSR/time/certificate identities against drawings.
  • Compare installed/live configuration to the approved release; no unexplained local edits.
  • Hash/archive the pre-test baseline and tested rollback/restore package.
  • Confirm removable temporary commissioning routes/accounts are controlled.

3. Physical and auxiliary checks

  • DC polarity/voltage, fuse/MCB discrimination, dual supplies and alarms.
  • Panel earth, shield/segregation, fiber/copper/serial patching and connector condition.
  • 52a/52b, truck/disconnector/earthing, local/remote and mechanism/coil supervision wiring.
  • Trip/close circuit continuity and output/interposing relay ratings.
  • Time/reference input cabling and GNSS/clock distribution.
  • Cabinet environment, temperature/fans/heaters and door/security contacts.
  • Network A/B and redundant DC paths are physically independent as designed.

4. Point-to-point monitoring

Point classTest statesVerify end-to-end
Single/double status0/1; open/closed/intermediate/invalidIdentity, state, quality, time, text/alarm
Protection eventStart/operate/reset/test/blockSource time, priority, SOE and no false trip
AnalogZero, nominal, sign, upper/over rangeRatio, unit, scale, deadband and quality
Counter/energyIncrement, rollover/reset/retainDirection, value and restart behavior
HealthIED/DC/communication/time failuresCorrect layer/root cause and child quality
Mode/bypassAll valid/invalid combinationsEvaluated authority, alarm and audit

5. IEC 61850 reporting and GOOSE

  • Validate server model/SCD, data sets, BRCB/URCB instances, triggers, optional fields and client ownership.
  • Disconnect/reconnect clients and IEDs; verify buffer replay, entry/sequence continuity and overflow alarm.
  • Change quality without value and verify qchg reporting.
  • Test GOOSE publisher/subscriber identity, timing, message supervision, test/simulation and timeout fail-safe.
  • Fail network A/B, switches and paths; verify PRP/HSR or other recovery as specified.
  • Generate event storms with integrity scans/file transfer while measuring critical traffic.
  • Capture packets and reconcile with SCD/expected flows.

6. Gateway and telecontrol

  • Verify every IEC 104/DNP3/Modbus address/type/profile against the controlled map.
  • Preserve source value, quality, timestamp, cause/class and current/backfill distinction.
  • Test general interrogation/integrity, spontaneous/unsolicited, counter and deadband behavior.
  • Interrupt WAN/gateway/IED links independently; verify layered quality and recovery.
  • Overflow buffers deliberately and prove visible evidence of loss.
  • Measure normal, event-storm and reconnect/backfill capacity.
  • Confirm unsupported semantic losses are documented and operationally mitigated.

7. Remote-control tests

  • Trace exact control-center object to gateway, IED, output, coil and independent 52a/52b feedback.
  • Test direct/SBO, select timeout/cancel, normal/enhanced termination and precise rejection causes.
  • Prove local/station/remote/automatic authority and simultaneous-command priority.
  • Test every interlock/synchrocheck/lockout/mechanism/DC/quality block.
  • Lose link/restart/fail over after select and after physical execution before response.
  • Verify no blind repeat, latent queue or duplicate output.
  • Measure command-to-output, breaker feedback and total HMI round trip under load.

8. Automation sequences

  • Use a scenario matrix for transfer, load shedding/restoration, interlocking or FLISR states.
  • Test every initiation, block, timeout, abort and manual-takeover path.
  • Vary measurements around thresholds/hysteresis and inject stale/invalid data.
  • Fail breaker operation and contradictory/intermediate feedback.
  • Restart/fail over logic host in every sequence state.
  • Verify protection/reclose/breaker-failure priority and no unsafe close.
  • Confirm final electrical state, loading and event/audit record.

9. Time and SOE

  • Measure IED/server/gateway offsets and physical-event-to-source-timestamp error.
  • Inject simultaneous events at multiple IEDs and verify ordering uncertainty.
  • Fail primary/backup PTP/SNTP/IRIG-B source/path and measure switchover/holdover.
  • Verify unsynchronized/time-quality propagation through control center.
  • Correlate SOE, command audit and COMTRADE disturbance record.
  • Test daylight-saving/local display while retaining UTC internally.
  • Alarm unexpected master/time step/path delay as designed.

10. Redundancy and performance

  • Fail one DC feed, server, gateway, service/process, NIC, LAN, switch, router, WAN and clock.
  • Partition redundant peers to prove split-brain prevention.
  • Measure failover/failback interruption, data age and state synchronization.
  • Verify no missing/duplicate events and zero unintended/duplicate commands.
  • Fail standby silently, then active, to prove latent-path alarms.
  • Repeat maximum event/backfill/file/logging load with one component/path failed.
  • Restore a node/spare from controlled backup and compare live state.

11. Alarm/HMI and operator workflow

  • Single-line/topology matches labels/physical equipment and shows invalid/intermediate state.
  • Alarm text, priority, cause/action, acknowledgment, return, shelving/suppression and audit follow philosophy.
  • Generate bus/DC/communication floods and confirm usable operator response.
  • Verify test/substitution/bypass/local modes are prominent.
  • Exercise operating procedures for WAN/HMI/gateway/time/cyber outage.
  • Use representative operators and record human-factor defects.

12. Cybersecurity SAT

  • Compare actual assets, zones/conduits, ports/services and firewall/ACL rules with approval.
  • Test permitted flows and representative denied origin/direction/protocol.
  • Verify roles/accounts/default removal, privileged/remote access and audit.
  • Test certificates/keys, time dependency and safe security-service failure.
  • Check hardening, unused ports/services, backups and vulnerability/patch baseline.
  • Attempt controlled unauthorized command/configuration/publisher/time source.
  • Test incident isolation and recovery while local protection/control remains.

13. Defect, regression and handover

  1. Record test ID, preconditions, stimulus, expected/actual, evidence, tester/witness and result.
  2. Classify defect consequence and block energization/remote control where required.
  3. Change only through approved release; determine cross-system regression scope.
  4. Retest defect plus affected reports, mappings, logic, redundancy and cyber controls.
  5. Remove simulations/jumpers/test flags/temporary accounts/routes.
  6. Restore protection/reclose/automation/modes and verify final topology.
  7. Archive as-built configurations/hashes, captures, results and known limitations.
  8. Hand over spares, restore instructions, licenses, training and periodic regression tests.

14. Energization and remote-control hold points

  • No primary energization until protection trip chain, interlocks, DC, breaker position and unsafe defects are closed.
  • No remote close enable until point-to-point identity, authority, quality, negative cases and physical feedback are proven.
  • No automatic scheme enable until studies, all state/failure paths and manual abort/recovery are witnessed.
  • No cyber remote access until zones/conduits, accounts, allowlists, logging and emergency isolation are accepted.
  • Record who releases each hold point, the exact configuration revision and any time-limited condition.
  • After energization, perform a controlled post-energization review of alarms, loading, time, communications and unexpected events.

References and further reading

Engineering note: SAT acceptance means the installed system remains correct and safe under realistic failure and restoration—not merely that every normal point once changed color.

LearnSwitchgear

Search the engineering library