SCADA/automation SAT proves the installed system from physical input and breaker mechanism to station HMI and control center under real wiring, networks, time, authority and operating procedures. It is not a repeat of vendor FAT and not a point-list checkbox exercise: site-specific interfaces, failures, latency, redundancy, cybersecurity and restoration must be demonstrated.
This checklist covers IEC 61850 station systems with IEC 60870-5-104/DNP3/Modbus integration. Adapt test scope to risk and approved switching conditions; never bypass electrical safety to obtain a “pass.”
1. SAT entry criteria
- Approved architecture, SLD, cause/effect, point list, SCD, gateway/HMI/control-center database and network/time/cyber drawings.
- FAT complete with defects closed or formally accepted with site action.
- Installed wiring/termination/labels and panel checks complete.
- IED/gateway/server/switch/clock firmware, settings and licenses frozen.
- Primary equipment and control DC ready; approved switching/test permits.
- Calibrated test equipment, simulators, packet capture and synchronized timing tools.
- Defined responsibilities, stop criteria, rollback and operations handback.
2. Configuration baseline
- Record hardware serials, firmware/software/tool/library versions.
- Export/read back IED settings, logic, SCD/ICD/CID as applicable, gateway map and HMI/control-center build.
- Verify IP/MAC/VLAN/PRP-HSR/time/certificate identities against drawings.
- Compare installed/live configuration to the approved release; no unexplained local edits.
- Hash/archive the pre-test baseline and tested rollback/restore package.
- Confirm removable temporary commissioning routes/accounts are controlled.
3. Physical and auxiliary checks
- DC polarity/voltage, fuse/MCB discrimination, dual supplies and alarms.
- Panel earth, shield/segregation, fiber/copper/serial patching and connector condition.
- 52a/52b, truck/disconnector/earthing, local/remote and mechanism/coil supervision wiring.
- Trip/close circuit continuity and output/interposing relay ratings.
- Time/reference input cabling and GNSS/clock distribution.
- Cabinet environment, temperature/fans/heaters and door/security contacts.
- Network A/B and redundant DC paths are physically independent as designed.
4. Point-to-point monitoring
| Point class | Test states | Verify end-to-end |
|---|---|---|
| Single/double status | 0/1; open/closed/intermediate/invalid | Identity, state, quality, time, text/alarm |
| Protection event | Start/operate/reset/test/block | Source time, priority, SOE and no false trip |
| Analog | Zero, nominal, sign, upper/over range | Ratio, unit, scale, deadband and quality |
| Counter/energy | Increment, rollover/reset/retain | Direction, value and restart behavior |
| Health | IED/DC/communication/time failures | Correct layer/root cause and child quality |
| Mode/bypass | All valid/invalid combinations | Evaluated authority, alarm and audit |
5. IEC 61850 reporting and GOOSE
- Validate server model/SCD, data sets, BRCB/URCB instances, triggers, optional fields and client ownership.
- Disconnect/reconnect clients and IEDs; verify buffer replay, entry/sequence continuity and overflow alarm.
- Change quality without value and verify qchg reporting.
- Test GOOSE publisher/subscriber identity, timing, message supervision, test/simulation and timeout fail-safe.
- Fail network A/B, switches and paths; verify PRP/HSR or other recovery as specified.
- Generate event storms with integrity scans/file transfer while measuring critical traffic.
- Capture packets and reconcile with SCD/expected flows.
6. Gateway and telecontrol
- Verify every IEC 104/DNP3/Modbus address/type/profile against the controlled map.
- Preserve source value, quality, timestamp, cause/class and current/backfill distinction.
- Test general interrogation/integrity, spontaneous/unsolicited, counter and deadband behavior.
- Interrupt WAN/gateway/IED links independently; verify layered quality and recovery.
- Overflow buffers deliberately and prove visible evidence of loss.
- Measure normal, event-storm and reconnect/backfill capacity.
- Confirm unsupported semantic losses are documented and operationally mitigated.
7. Remote-control tests
- Trace exact control-center object to gateway, IED, output, coil and independent 52a/52b feedback.
- Test direct/SBO, select timeout/cancel, normal/enhanced termination and precise rejection causes.
- Prove local/station/remote/automatic authority and simultaneous-command priority.
- Test every interlock/synchrocheck/lockout/mechanism/DC/quality block.
- Lose link/restart/fail over after select and after physical execution before response.
- Verify no blind repeat, latent queue or duplicate output.
- Measure command-to-output, breaker feedback and total HMI round trip under load.
8. Automation sequences
- Use a scenario matrix for transfer, load shedding/restoration, interlocking or FLISR states.
- Test every initiation, block, timeout, abort and manual-takeover path.
- Vary measurements around thresholds/hysteresis and inject stale/invalid data.
- Fail breaker operation and contradictory/intermediate feedback.
- Restart/fail over logic host in every sequence state.
- Verify protection/reclose/breaker-failure priority and no unsafe close.
- Confirm final electrical state, loading and event/audit record.
9. Time and SOE
- Measure IED/server/gateway offsets and physical-event-to-source-timestamp error.
- Inject simultaneous events at multiple IEDs and verify ordering uncertainty.
- Fail primary/backup PTP/SNTP/IRIG-B source/path and measure switchover/holdover.
- Verify unsynchronized/time-quality propagation through control center.
- Correlate SOE, command audit and COMTRADE disturbance record.
- Test daylight-saving/local display while retaining UTC internally.
- Alarm unexpected master/time step/path delay as designed.
10. Redundancy and performance
- Fail one DC feed, server, gateway, service/process, NIC, LAN, switch, router, WAN and clock.
- Partition redundant peers to prove split-brain prevention.
- Measure failover/failback interruption, data age and state synchronization.
- Verify no missing/duplicate events and zero unintended/duplicate commands.
- Fail standby silently, then active, to prove latent-path alarms.
- Repeat maximum event/backfill/file/logging load with one component/path failed.
- Restore a node/spare from controlled backup and compare live state.
11. Alarm/HMI and operator workflow
- Single-line/topology matches labels/physical equipment and shows invalid/intermediate state.
- Alarm text, priority, cause/action, acknowledgment, return, shelving/suppression and audit follow philosophy.
- Generate bus/DC/communication floods and confirm usable operator response.
- Verify test/substitution/bypass/local modes are prominent.
- Exercise operating procedures for WAN/HMI/gateway/time/cyber outage.
- Use representative operators and record human-factor defects.
12. Cybersecurity SAT
- Compare actual assets, zones/conduits, ports/services and firewall/ACL rules with approval.
- Test permitted flows and representative denied origin/direction/protocol.
- Verify roles/accounts/default removal, privileged/remote access and audit.
- Test certificates/keys, time dependency and safe security-service failure.
- Check hardening, unused ports/services, backups and vulnerability/patch baseline.
- Attempt controlled unauthorized command/configuration/publisher/time source.
- Test incident isolation and recovery while local protection/control remains.
13. Defect, regression and handover
- Record test ID, preconditions, stimulus, expected/actual, evidence, tester/witness and result.
- Classify defect consequence and block energization/remote control where required.
- Change only through approved release; determine cross-system regression scope.
- Retest defect plus affected reports, mappings, logic, redundancy and cyber controls.
- Remove simulations/jumpers/test flags/temporary accounts/routes.
- Restore protection/reclose/automation/modes and verify final topology.
- Archive as-built configurations/hashes, captures, results and known limitations.
- Hand over spares, restore instructions, licenses, training and periodic regression tests.
14. Energization and remote-control hold points
- No primary energization until protection trip chain, interlocks, DC, breaker position and unsafe defects are closed.
- No remote close enable until point-to-point identity, authority, quality, negative cases and physical feedback are proven.
- No automatic scheme enable until studies, all state/failure paths and manual abort/recovery are witnessed.
- No cyber remote access until zones/conduits, accounts, allowlists, logging and emergency isolation are accepted.
- Record who releases each hold point, the exact configuration revision and any time-limited condition.
- After energization, perform a controlled post-energization review of alarms, loading, time, communications and unexpected events.
References and further reading
- IEC 61850-10 edition 2.1 — Conformance/performance testing
- IEC TR 61850-10-3:2022 — Functional testing
- IEC 61850-8-1 consolidated edition — MMS/GOOSE mapping
- IEC TS 60870-5-604:2016 — IEC 104 conformance tests
- IEC TR 61850-90-4:2020 — Network engineering/testing
- IEC 62682:2022 — Alarm-management lifecycle principles
- IEC 62443-3-3:2013 — System security requirements
Engineering note: SAT acceptance means the installed system remains correct and safe under realistic failure and restoration—not merely that every normal point once changed color.