Architect & specify
Architect & Specify: Vendor-Neutral System Design for Bankable, Secure Digital Infrastructure
We translate prioritised use-cases into a complete technical architecture — system topology, data models, OT/IT cybersecurity design, and tender-ready specifications. This step de-risks procurement by giving you vendor-agnostic documentation that any credible EPC or system integrator can bid against, with clear acceptance criteria and cybersecurity compliance built in from day one.
Typical duration · 8-12 weeks depending on system complexity and number of interfaces
Samples generated 07 Sept 2026, 02:06 am ISTWhat happens in this step
- 01Define target system architecture: SCADA/EMS/DERMS layers, historian, data lake, and integration middleware
- 02Develop data models and tag/point lists mapping field devices to control room and analytics layers
- 03Design OT/IT network segmentation, firewall zones, and remote access architecture per IEC 62443 / CEA cybersecurity guidelines
- 04Specify communication protocols (IEC 61850, DNP3, Modbus TCP) and interoperability requirements across vendors
- 05Draft functional and technical specifications for control systems, protection interfaces, and cybersecurity controls
- 06Prepare tender documentation package: technical specs, evaluation criteria, compliance matrices, and draft SLAs
- 07Support client through vendor Q&A, technical bid evaluation, and clarification rounds
What we need from you
- Approved use-case shortlist and prioritisation matrix from Step 02
- Single-line diagrams and protection philosophy documents
- Existing SCADA/DCS architecture (if brownfield) and asset inventory
- Site network topology and any existing cybersecurity policy documents
- Regulatory and DISCOM interconnection/communication requirements
- Procurement timeline and preferred contracting structure (EPC/turnkey vs multi-package)
Worked example (anonymised, illustrative)
400 MW / 800 MWh Standalone BESS · 400 MW / 800 MWh, LFP chemistry · Western India, DISCOM-connected at 220 kV
Following baseline audit and use-case prioritisation (frequency regulation + peak shifting), the client required a vendor-neutral architecture and tender package to run a competitive EPC bid across four shortlisted integrators.
Sample deliverables from this step
Every sample below is analyst-written and anonymised for illustration — structure and depth mirror our real deliverables; figures and names are not from any client engagement.
System Architecture & Data Model Report
Complete architecture covering SCADA/EMS layers, historian design, data flow diagrams, and point-list schema aligned to IEC 61850 object models.
Sample excerpt · Data Point Summary (Extract) — illustrative figures
| System | Signal Type | Protocol | Update Rate | Criticality |
| PCS Skid Controller | Active Power Setpoint | Modbus TCP | 1 s | High |
| BMS Rack | Cell Temperature | IEC 61850 GOOSE | 1 s | High |
| Site EMS | SOC Aggregate | DNP3 | 2 s | Medium |
| Fire Suppression | Alarm Status | Hardwired + Modbus | Event-based | High |
| Weather Station | Ambient Temp/Humidity | Modbus RTU | 60 s | Low |
- Point list forms basis for FAT/SAT test scripts
- Data model designed for future DERMS integration without rework
OT/IT Cybersecurity Design Memo
Network segmentation architecture, zone/conduit model per IEC 62443, remote access controls, and compliance mapping to CEA cybersecurity guidelines for BESS assets.
Sample excerpt · Zone & Conduit Summary (Extract) — illustrative figures
| Zone | Assets | Trust Level | Conduit Control |
| Level 0 - Field I/O | PCS, BMS sensors | Untrusted | Unidirectional gateway |
| Level 1 - Control | Local controllers | Restricted | Firewall + VLAN |
| Level 2 - Supervisory | Site SCADA/EMS | Restricted | IDS monitored |
| Level 3 - Site DMZ | Historian, remote access | Semi-trusted | Jump server + MFA |
| Level 4 - Corporate/Cloud | Analytics platform | Trusted | VPN + encryption |
- Aligned with CEA (Cyber Security in Power Sector) draft guidelines
- Remote access restricted to whitelisted vendor IPs with session recording
Technical Specification & Tender Package
Vendor-neutral functional specifications, compliance matrix, evaluation criteria, and draft SLA terms ready for release to shortlisted EPC/integrator bidders.
Sample excerpt · Tender Compliance Matrix (Extract) — illustrative figures
| Clause Ref | Requirement | Mandatory/Desirable | Bidder Compliance |
| 4.2 | IEC 61850 protocol support | Mandatory | Yes/No |
| 5.1 | 99.5% SCADA uptime SLA | Mandatory | Yes/No |
| 6.3 | Cybersecurity audit within 6 months | Mandatory | Yes/No |
| 7.4 | Local O&M training program | Desirable | Yes/No |
| 8.1 | 5-year spares availability guarantee | Mandatory | Yes/No |
- Compliance matrix used directly in technical bid evaluation scoring
- Package structured for multi-package or single EPC contracting
Outcomes
- Vendor-neutral, bankable technical package ready for competitive tendering
- Reduced integration risk through pre-validated data models and protocol specifications
- Cybersecurity architecture aligned with CEA and IEC 62443 requirements from design stage
- Faster, more comparable bid evaluation through standardised compliance matrices
Questions clients ask
Do you recommend specific vendors or products?
No. Our specifications are written to be technology and vendor-neutral, defining performance, interoperability, and compliance requirements so any credible bidder can propose their solution on equal footing.
How does this step handle cybersecurity compliance for regulated utility assets?
We design network segmentation, access controls, and monitoring architecture aligned with IEC 62443 and applicable CEA cybersecurity guidelines, then document compliance mapping directly into the tender specification.
Can this package be used for a multi-package procurement instead of single EPC?
Yes. The specification and compliance matrix are structured so packages can be split by discipline (e.g., BESS supply, SCADA integration, network infrastructure) or issued as a single turnkey scope.


