Engineering Guide • Commissioning & Handover
Secure Commissioning for Grid-Scale Storage: FAT and SAT Verification Protocols
The most dangerous phase in the operational life of a battery energy storage facility is the transition between construction and commercial operation. During commissioning, dozens of contractors, equipment vendors, and engineering sub-suppliers connect laptops, flash firmware, and establish temporary network bridges. Without rigorous cyber verification at Factory Acceptance Testing (FAT) and Site Acceptance Testing (SAT), latent vulnerabilities become permanent operational liabilities.
The Commissioning Chaos Trap
Grid-scale BESS projects operate under severe commercial pressures. Delays in achieving Commercial Operation Date (COD) trigger massive liquidated damages (LDs) and forfeit lucrative utility capacity contracts.
In the rush to achieve COD, cybersecurity is frequently treated as an impediment. When an engineering technician cannot connect their diagnostic software through a firewalled switch, the common field response is to disable firewall rules, plug into an unmanaged bypass port, or leave a cellular dongle plugged into the cabinet.
When the EPC hands the keys to the permanent asset owner, the facility is riddled with temporary workarounds, default administrative credentials, and undocumented remote-access tunnels. Retrofitting security onto an energized, revenue-generating 100 MW facility is ten times more expensive and operationally hazardous than building security verification into the commissioning gates.
Stage 1: Factory Acceptance Testing (FAT) Protocols
Secure commissioning begins at the OEM manufacturing facility before containerized battery enclosures, inverter skids, and control panels are shipped to site.
FAT Verification Checklist:
- Cryptographic Firmware Verification: Verify that all microcontrollers (BMS master/slaves, inverter DSPs, switchgear protection relays) are running vendor-signed, known-good firmware builds. Record cryptographic SHA-256 hashes of all installed binaries.
- Hardware Interface Disablement: Physically and logically disable unused hardware debugging interfaces, including JTAG headers, UART serial ports, and exposed USB maintenance ports on enclosure exteriors.
- Default Credential Elimination: Eliminate all factory default credentials (e.g.,
admin/admin,root/root). Mandate individual, cryptographically secure credentials or certificate-based authentication for all listening services. - Unused Service Deactivation: Audit all controller network daemons. Permanently disable unencrypted and unnecessary services, such as Telnet, unencrypted HTTP, TFTP, and legacy SNMPv1/v2c agents.
Stage 2: Site Acceptance Testing (SAT) Protocols
Site Acceptance Testing validates the physical installation, field cabling, network segmentation, and external communication links at the project location.
SAT Verification Checklist:
- Layer 2/3 Segmentation & VLAN Auditing: Validate that physical managed switches enforce strict VLAN isolation according to the Purdue Enterprise Reference Architecture. Confirm that battery container VLANs cannot communicate peer-to-peer with adjacent containers.
- Industrial Firewall Rulebase Audit: Verify that all inter-zone firewall rulebases enforce explicit least privilege. Confirm the absolute absence of
ANY-ANYbypass rules or temporary test configurations. - Cellular & Satellite Gateway Boundary Inspection: Audit every cellular modem and satellite terminal installed on site. Ensure all outbound connections are restricted to authorized, customer-controlled mTLS endpoints and that public WAN inbound listen ports are completely closed.
- Pre-Energization Passive Traffic Baseline: Deploy passive network monitoring across switch SPAN ports for a minimum 72-hour burn-in period before high-voltage energization. Catalog every active MAC address, IP address, and industrial protocol flow to establish the site's initial operational baseline.
Stage 3: Golden Baseline & Handover
The culmination of secure commissioning is the generation of a verifiable Cryptographic Golden Baseline:
- PLC & Controller Logic Snapshots: Capture and cryptographically sign exact image snapshots of all programmable logic controller (PLC) ladder logic, EMS dispatch configurations, and inverter operating parameters.
- Remote Access Credential Revocation: Revoke all temporary commissioning credentials, vendor test accounts, and contractor VPN tokens. Transfer access governance into the permanent Just-In-Time (JIT) access framework.
- The As-Built Cyber Dossier: Deliver a comprehensive, verified technical package to the permanent asset owner, including physical network topology schematics, complete device inventories, verified firmware registers, and emergency cold-start recovery playbooks.
Conclusion
Achieving COD on schedule and maintaining rigorous operational cybersecurity are not mutually exclusive. By establishing clear FAT and SAT verification protocols and embedding cyber validation into the capital project delivery schedule, asset owners protect their multimillion-dollar investments before the first kilowatt-hour of energy enters the grid.
Embed cybersecurity into your next capital project
Battery Cyber provides turnkey Secure Commissioning services, including on-site FAT/SAT auditing and pre-energization verification for BESS and critical power projects.
Discuss an environment