Growthifyegrowthifye
Utility Digitalisation & Automation
Step 03 of 4 · Utility Digitalisation & Automation

Architect & specify

Architect & Specify: Vendor-Neutral System Design for Bankable, Secure Digital Infrastructure

We translate prioritised use-cases into a complete technical architecture — system topology, data models, OT/IT cybersecurity design, and tender-ready specifications. This step de-risks procurement by giving you vendor-agnostic documentation that any credible EPC or system integrator can bid against, with clear acceptance criteria and cybersecurity compliance built in from day one.

Typical duration · 8-12 weeks depending on system complexity and number of interfaces

Samples generated 07 Sept 2026, 02:06 am IST

What happens in this step

  1. 01Define target system architecture: SCADA/EMS/DERMS layers, historian, data lake, and integration middleware
  2. 02Develop data models and tag/point lists mapping field devices to control room and analytics layers
  3. 03Design OT/IT network segmentation, firewall zones, and remote access architecture per IEC 62443 / CEA cybersecurity guidelines
  4. 04Specify communication protocols (IEC 61850, DNP3, Modbus TCP) and interoperability requirements across vendors
  5. 05Draft functional and technical specifications for control systems, protection interfaces, and cybersecurity controls
  6. 06Prepare tender documentation package: technical specs, evaluation criteria, compliance matrices, and draft SLAs
  7. 07Support client through vendor Q&A, technical bid evaluation, and clarification rounds
Footage

Architect & specify · on the ground

Video · ANTONI SHKRABA production / Pexels

What we need from you

  • Approved use-case shortlist and prioritisation matrix from Step 02
  • Single-line diagrams and protection philosophy documents
  • Existing SCADA/DCS architecture (if brownfield) and asset inventory
  • Site network topology and any existing cybersecurity policy documents
  • Regulatory and DISCOM interconnection/communication requirements
  • Procurement timeline and preferred contracting structure (EPC/turnkey vs multi-package)
Close-up of person using a calculator with financial documents in an office.
Image

Your inputs, our engineering

Photo · Mikhail Nilov / Pexels

Worked example (anonymised, illustrative)

400 MW / 800 MWh Standalone BESS · 400 MW / 800 MWh, LFP chemistry · Western India, DISCOM-connected at 220 kV

Following baseline audit and use-case prioritisation (frequency regulation + peak shifting), the client required a vendor-neutral architecture and tender package to run a competitive EPC bid across four shortlisted integrators.

What you receive

Sample deliverables from this step

Every sample below is analyst-written and anonymised for illustration — structure and depth mirror our real deliverables; figures and names are not from any client engagement.

Illustrative — System Architecture & Data Model ReportIllustrative · Growthifye-prepared
report

System Architecture & Data Model Report

Complete architecture covering SCADA/EMS layers, historian design, data flow diagrams, and point-list schema aligned to IEC 61850 object models.

Sample excerpt · Data Point Summary (Extract) — illustrative figures

SystemSignal TypeProtocolUpdate RateCriticality
PCS Skid ControllerActive Power SetpointModbus TCP1 sHigh
BMS RackCell TemperatureIEC 61850 GOOSE1 sHigh
Site EMSSOC AggregateDNP32 sMedium
Fire SuppressionAlarm StatusHardwired + ModbusEvent-basedHigh
Weather StationAmbient Temp/HumidityModbus RTU60 sLow
  • Point list forms basis for FAT/SAT test scripts
  • Data model designed for future DERMS integration without rework
Download illustrative sample (PDF)
Illustrative — OT/IT Cybersecurity Design MemoIllustrative · Growthifye-prepared
memo

OT/IT Cybersecurity Design Memo

Network segmentation architecture, zone/conduit model per IEC 62443, remote access controls, and compliance mapping to CEA cybersecurity guidelines for BESS assets.

Sample excerpt · Zone & Conduit Summary (Extract) — illustrative figures

ZoneAssetsTrust LevelConduit Control
Level 0 - Field I/OPCS, BMS sensorsUntrustedUnidirectional gateway
Level 1 - ControlLocal controllersRestrictedFirewall + VLAN
Level 2 - SupervisorySite SCADA/EMSRestrictedIDS monitored
Level 3 - Site DMZHistorian, remote accessSemi-trustedJump server + MFA
Level 4 - Corporate/CloudAnalytics platformTrustedVPN + encryption
  • Aligned with CEA (Cyber Security in Power Sector) draft guidelines
  • Remote access restricted to whitelisted vendor IPs with session recording
Download illustrative sample (PDF)
schedule

Technical Specification & Tender Package

Vendor-neutral functional specifications, compliance matrix, evaluation criteria, and draft SLA terms ready for release to shortlisted EPC/integrator bidders.

Sample excerpt · Tender Compliance Matrix (Extract) — illustrative figures

Clause RefRequirementMandatory/DesirableBidder Compliance
4.2IEC 61850 protocol supportMandatoryYes/No
5.199.5% SCADA uptime SLAMandatoryYes/No
6.3Cybersecurity audit within 6 monthsMandatoryYes/No
7.4Local O&M training programDesirableYes/No
8.15-year spares availability guaranteeMandatoryYes/No
  • Compliance matrix used directly in technical bid evaluation scoring
  • Package structured for multi-package or single EPC contracting
Download illustrative sample (PDF)

Outcomes

  • Vendor-neutral, bankable technical package ready for competitive tendering
  • Reduced integration risk through pre-validated data models and protocol specifications
  • Cybersecurity architecture aligned with CEA and IEC 62443 requirements from design stage
  • Faster, more comparable bid evaluation through standardised compliance matrices
Footage

Outcomes that reach COD

Video · invisiblepower / Pexels

Questions clients ask

Do you recommend specific vendors or products?

No. Our specifications are written to be technology and vendor-neutral, defining performance, interoperability, and compliance requirements so any credible bidder can propose their solution on equal footing.

How does this step handle cybersecurity compliance for regulated utility assets?

We design network segmentation, access controls, and monitoring architecture aligned with IEC 62443 and applicable CEA cybersecurity guidelines, then document compliance mapping directly into the tender specification.

Can this package be used for a multi-package procurement instead of single EPC?

Yes. The specification and compliance matrix are structured so packages can be split by discipline (e.g., BESS supply, SCADA integration, network infrastructure) or issued as a single turnkey scope.

A diverse group of professionals in a business consulting office setting.
Image

Questions we answer every week

Photo · Tran Nhu Tuan / Pexels

We use essential cookies to run the site and, with your consent, track your activity to personalise your learning and recommendations. See our Privacy Policy.