<?xml version="1.0" encoding="utf-8"?>
<Spec id="301" path="\9\b\9bb3c10ce55546b33cc0b7b700b5d11a.pdf"><Text id="45969" page="6">The purpose of this document is to describe the technical and functional requirements for the Automation system for the MFW . The content of this document describes the requirements for the</Text><Text id="45970" page="6">This document provides the overall design criteria for the Industrial Automation and Control System (IACS) and shall form the basis for the functional design specifications for IACS sub-systems, including Supervisory Control and Data Acquisition (SCADA) systems, with the required interfaces to all other related systems and external interfaces. Fiscal metering and TSO communication needs to be clarified and agreed with TSO</Text><Text id="45971" page="6">Reference is made to Design basis MFW – PM735-PMS-050-001</Text><Text id="45972" page="6">The design and operation of the entire Wind Power Plant (WPP) shall be demonstrated to be in accordance with all applicable laws, rules and regulations as required by the regulatory authorities, including but not limited to, Contract Appendix E document.</Text><Text id="45973" page="6">It is the Contractor’s responsibility to ensure that the design, material, and equipment provided meets all relevant requirements.</Text><Text id="45974" page="6">Contractor shall indicate in their proposal if any part of this specification deviates from Contractor’s usual design so that a significant increase in the cost is expected without providing a corresponding increase in quality; or if Contractor’s usual design will provide better quality than the design required by this specification.</Text><Text id="45975" page="6">Contractor shall ensure that the design incorporates HSE best practices and gained experiences so that construction, testing, installation, maintenance, and normal production activities can be carried out in an efficient manner, and without risk to people, environment, or the asset.</Text><Text id="45976" page="6">All engineering, design and construction covered by this specification shall be in line with relevant Polish Laws and Regulations and practices applicable for the offshore wind sector.</Text><Text id="45977" page="6">For roject specific design requirements towards Polish Transmission System Operator (TSO) is defined in the Grid Connection Agreements between TSO and , Technical Conditions for the Connection to the Telecommunication Network of PSE S.A., Grid Code and any other relevant TSO requirements for Telecommuncation systems.</Text><Text id="45978" page="7">Contractor shall be responsible to ensure and document that its products are designed in accordance with applicable laws, regulations, standards given in App E of the Contract.</Text><Text id="45979" page="7">If there are inconsistencies between the various requirements given within the regulations, requirements, and standards, reference is made to the contractual Order of Precedence.</Text><Text id="45980" page="7">The wind power plant shall be built for unmanned operation. This shall include the Onshore Substation (ONS), Offshore Substation (OSS) and Wind Turbine Generators (WTGs). It shall be possible to control and monitor the Wind Power Plant (WPP) from remote sites, including e.g. utility systems.</Text><Text id="45981" page="7">The WPP shall have an integrated automation system for supervision, control and monitoring of the Wind Farm including ONS, OSS, WTGs and cable monitoring. The automation system shall control utilities, or interface third party utility control systems supplied by package suppliers such as HVAC, UPS, etc. The overall automation system for is denoted Industrial Automation and Control System (IACS), see section 3 for further details.</Text><Text id="45982" page="7">The control system and electrical HV Control &amp; Protection system/ equipment, MV, LV equipment/systems and utility equipment/systems for ONS / OSS and the WTGs shall be remotely operated and controlled from the Multi wind farm Central Control Room (CCR), located at the O&amp;M base.</Text><Text id="45983" page="7">The IACS system in the wind farm shall be designed with three levels of control.</Text><Text id="46009" page="9">All systems on shall have a uniform, consistent and standardized design. This applies to all aspects of system design, including both hardware (cabinet design, cabling etc), software (user interfaces etc), condition monitoring capabilities and so on.</Text><Text id="46010" page="9">All relevant real-time data shall be made available to the Company IMS/Wind Farm Management System. This shall include both raw and analysed data from all SCADA systems. Raw data shall be available without any filtering or compression, via agreed interface protocols. Definition of “all relevant real-time data” shall be detailed during the detail engineering phase and agreed with Company.</Text><Text id="46011" page="9">Both raw and analysed data shall include historical records, plus data from SCADA and Control and Protection systems, monitoring systems, database system, Conditioning Monitoring systems (CMS) Metering Systems, etc. Data shall flow from the source systems directly to the company IMS buffer servers on the company network without leaving and re-entering the Company network. Data transfers should, unless agreed with Company, occur continuously and with minimal delay.</Text><Text id="46012" page="9">The automation systems, including ESI SCADA, WTG SCADA and SUS SCADA (if not integrated part of ESI SCADA) shall have OPC UA interface to a future Top Level/Common SCADA in the CCR for operation of the windfarm. The WTG SCADA for could be combined, the ESI SCADA for could be combined and the SUS SCADA (if not integrated part of ESI SCADA) could be combined for . Top Level/Common SCADA will probably not be made until B is built. This to be clarified with Company during FEED.</Text><Text id="46013" page="10">Doc. No. C256-EQ-J-SP-OOOO2 Rev. no. 01 Valid from: 12.12.2022</Text><Text id="46014" page="10">Multi Wind Farm Central Control Room (CCR) Multi Wind Farm CCR SCADA System</Text><Text id="46016" page="10">Windfarm Automation System ESI Automation System Wind Turbine Automation System</Text><Text id="46019" page="10">Safety &amp; UtMtty System Sutotatlon Automaton Electrtcal System WTG System</Text><Text id="46024" page="10">The interface shall support OPC UA companion specification OPC 10040 - UA for IEC 61850 for monitoring and operation of the lED&apos;s exposing the information models to the above systems. In addition, the interface shall support other relevant OPC UA companion standards for non-IED equipment in the ESI systems exposing the information models to the above systems. The information model shall be inclusive of alarms and events.</Text><Text id="46025" page="10">The OPC UA interface should as a minimum support the following features:</Text><Text id="46026" page="10">A. OPC UA clients shall support the &quot;Standard UA Client 2017 Profile&quot; (http://opcfoundation.org/UA- Profile/Client/Standard2017).</Text><Text id="46027" page="10">B. OPC UA clients shall support the &quot;Documentation - Client&quot; profile (http://opcfoundation.org/UA-Profile/Client/Documentation).</Text><Text id="46028" page="10">C. OPC UA clients shall support the &quot;Base Client Behaviour Facet&quot; profile (http://opcfoundation.org/UA- Profile/Client/Behaviour)</Text><Text id="46029" page="10">D. OPC UA clients shall support the &quot;Reverse Connect Client Facet&quot; profile (http://opcfoundation.org/UA- Profile/CIient/ReverseConnect)</Text><Text id="46030" page="10">E. OPC UA servers shall support the &quot;Standard UA Server 2017&quot; profile&quot; (http://opcfoundation.org/UA- ProfiIe/Server/Sta ndardUA 2017).</Text><Text id="46031" page="10">F. OPC UA servers shall support the &quot;Data Access Server Facet” profile (http://opcfoundation.org/UA- Profile/Server/DataAccess)</Text><Text id="46032" page="10">G. OPC UA servers shall support the &quot;Documentation - Server&quot; profile (http://opcfoundation.org/UA- Profile/Server/Documentation).</Text><Text id="46033" page="10">H. OPC UA servers shall support the &quot;Base Server Behaviour Facet&quot; profile (http://opcfoundation.org/UA- Profile/Server/Behaviour).</Text><Text id="46034" page="10">I. OPC UA servers shall support the &quot;Reverse Connect Server Facet&quot; profile (http://opcfoundation.org/UA- Profile/Server/ReverseConnect) K</Text><Text id="46035" page="11">J. OPC UA client shall support the “Alarm &amp; Condition Server Facet” profile http://opcfoundation.org/UA-Profile/Client/ACBaseCondition</Text><Text id="46036" page="11">K. OPC UA server shall support the “Alarm &amp; Condition Server Facet” profile http://opcfoundation.org/UA-Profile/Server/ACBaseCondition2021</Text><Text id="46037" page="11">The OPC UA interface should support the following feature: OPC UA clients should support the “Pub/Sub facet” OPC UA servers should support the “Pub/Sub facet”</Text><Text id="46038" page="11">An overall Automation and Control System shall be installed for monitoring and control of the wind farm. For the IACS shall comprise one or more of the following components: Industrial control systems, including but not limited to distributed control systems (DCSs), programmable logic controllers (PLCs), remote terminal units (RTUs), Intelligent Electronic Devices (IEDs), Supervisory Control and Data Acquisition (SCADA) systems, network components, networked electronic sensing and control, and monitoring and diagnostic systems. All systems designated for operational use shall be compliant for real-time monitoring and control. The ESI SCADA shall therefore be designed with complete functionality for real-time monitoring, and for control of all electrical and utility equipment on the ONS/OSS. The control system shall be compliant with the IEC 61850 standard for substation automation and support other standard communication protocols as listed in chapter 6.1.6.</Text><Text id="46039" page="11">Figure 1 - IACS General Architecture gives a general overview of the IACS and does also indicate main interfaces towards systems and parties external to IACS. Please note that the outline of the IACS is only functional, hence not necessarily reflecting location or the Automation network topology correctly.</Text><Text id="46040" page="11">The objective of the IACS is to control and monitor the power generation, the electrical power distribution network, and auxiliary systems.</Text><Text id="46041" page="11">The IACS shall control and monitor the 400/220 kV switchboards, HV, MV and LV and all auxiliary equipment on the ONS, and controlling the 220/66 kV switchboards, HV, MV and LV and all auxiliary equipment on OSS including 66kV inter array cable incomers from the WTGs, with required signals and set point to/from the WTG SCADA Plant Control/Wind Farm Power Control (WFPC) system.</Text><Text id="46042" page="11">The ESI SCADA shall also control and monitor the WTG 66 kV switchgear in the WTGs via the IEC 61850 network.</Text><Text id="46043" page="11">The IACS shall in basis consist of the following systems:</Text><Text id="46044" page="11">• ESI SCADA performing Supervisory control and monitoring of the high voltage distribution, medium voltages and low voltage distribution system and transmission system from the high voltage connections in the WTGs.</Text><Text id="46045" page="11">• High Voltage Control &amp; Protection system including control equipment for:</Text><Text id="46046" page="12">Doc. No. C256-EQ-J-SP-00002 Rev.no. 01 Valid from: 12.12.2022</Text><Text id="46047" page="12">o Onshore 400/220 kV high voltage substation switchgear and other high voltage components, transformers, reactors etc. o Offshore 220 kV /66 kV high voltage substation switchgears and other high voltage components, transformers, reactors etc. o 66 kV inter array cable distribution system, including 66 kV WTG switchgear and the 66/0,690kV WTG transformer.</Text><Text id="46048" page="12">• ONS auxiliary system/equipment including but not limited to Low Voltage switchgears/distribution system, power supplies, battery systems, UPS, fire detection, HVAC systems as needed to obtain remote capabilities to the SCADA system</Text><Text id="46049" page="12">• OSS Safety and Utility automation system (SUS SCADA), including, but not limited to: o Shutdown System o Fire (and Gas) detection o Protection systems o Auxiliary and Utility systems o Low Voltage switchgears/distribution system and UPS&apos;s o HVAC control system o Intruder system</Text><Text id="46050" page="12">• WTG SCADA performing Supervisory control, monitoring of the WTGs, and controlling Active Power (MW) and Reactive Power (MVAr) from the WTGs.</Text><Text id="46051" page="12">• Interface between ESI SCADA and WTG SCADA/WFPC for power control of the WTGs in the Wind Farm.</Text><Text id="46052" page="12">• ESI SCADA HMI systems including operator and engineering workstation remote monitoring and control of the wind farm electrical system infrastructure, including remote monitoring and control of OSS SUS.</Text><Text id="46053" page="12">• WTG SCADA HMI systems including operator and engineering workstation for remote monitoring and control of the WTGs including remotely controlled medium voltage breaker at 690V side of WTG transformer, if poss. This to be further detailed in FEED.</Text><Text id="46054" page="12">• Interface to Information Management System (IMS) for data acquisition from the above systems.</Text><Text id="46055" page="12">• Interface to TSO for inter-tripping, monitoring and metering.</Text><Text id="46057" page="12">• Interface to Condition Monitoring System (CMS), including WTG Main Bearing CMS system.</Text><Text id="46058" page="12">• Interface to cable monitoring systems, such as Distributed Temperature Sensing (DTS) and similar.</Text><Text id="46059" page="12">• Interface to telecommunication systems (WTG WAN, Wifi, Telephony system, TMS, CCTV, Met-Ocean, GPS Clock system, Access Control, Intruder system, PVTS, radio and /radar systems).</Text><Text id="46061" page="12">• TCP/IP based interface to WTG Contractors Navigation and aviation aid system (Sabik)</Text><Text id="46062" page="12">• Interface to WTG Contractors Fleet leader systems (SiDAC in Baltyk) on two WTGs.</Text><Text id="46063" page="12">A dedicated and redundant PRP control and protection network utilizing the IEC 61850 protocol for the control &amp; protection shall be established. IEDs for control and monitoring function shall be implemented. Control &amp; Protection systems and related equipment&apos;s shall support PRP network, IEC61850 MMS and GOOSE communication.</Text><Text id="46064" page="12">400/220/66kV switchboard and LV transformer incomers shall be connected to the IEC61850 network for control and protection. The local control units (LCU) and protection relays/IE Os shall be integrated to the SCADA system via agreed interface/communication protocol. IEC 61850 GOOSE shall be used for intertrip and permissive signals, hardwired interlocks/intertrips shall be limited to what is strictly necessary.</Text><Text id="46065" page="12">Local Control Units (LCU) shall provide fully integrated monitoring functions of all 400/220/66 kV switchgear within the wind farm, e.g., circuit breaker, disconnector, earth switch, 3-pos-switch, etc. The LCU shall allow the operator to control switchgear locally at the relay or remotely from the SCADA.</Text><Text id="46066" page="13">Protection relays provide fully integrated protection functions of all 400/220/66 kV circuits within the wind farm. The protection relays also provide monitoring and control functionality for all the WTG 66 kV switchgear. These shall be controlled from the ESI SCADA system.</Text><Text id="46067" page="13">Required inter tripping signals shall be included for tripping of the circuit breakers for stop of the production and protection of equipment and export cable including soft stop and/or Hard stop of the WTG’s/400kV grid circuit breakers in compliance with TSO Operational Tripping Schemes (OTS).</Text><Text id="46068" page="13">Arming, disarming and reset functions shall be included from the ESI SCADA HMI, according to TSO.</Text><Text id="46069" page="13">All required HW, SW and functions shall be included for local and remote maintenance access, diagnostic, trouble shooting and SW updating via the Company secure access solution. The foregoing is applicable for all programmable and configurable equipment. Contractor to ensure all Sub Suppliers meet this requirement.</Text><Text id="46070" page="13">The three main parts of the “power supply chain” in are;</Text><Text id="46071" page="13">• The WTGs – the offshore wind turbines and the cables between the WTGs and the OSS.</Text><Text id="46072" page="13">• The transmission system - consisting of the OSS, ONS, HV cables between the two, and the interconnection to the grid</Text><Text id="46073" page="13">• The grid – TSO receiving the power from . This is owned by an external party; Company does therefore not have any control over the grid. The IACS shall comply with the TSO Manuals, such that grid-related control and status signals can be sent and received. Fiscal metering must also be incorporated.</Text><Text id="46074" page="13">For these three parties to work efficiently together, it is necessary to exchange some crucial information and act in a timely manner based on the information. The main objectives are to</Text><Text id="46076" page="13">2) Handle de-loading and inter-tripping efficiently and reliably, and finally,</Text><Text id="46077" page="13">3) Ensure the technical integrity of the wind farm is not compromised. The power control requirements will be described in the Power System Philosophy and shall be basis for the Power Control philosophy and design.</Text><Text id="46078" page="13">Power Control From the grid there is a requirement to not provide more active power (MW) at any given time than the grid can handle. Normally the grid can handle full production, but during maintenance of power lines onshore and high amount of wind a need to limit the active power produced may be informed by the TSO. To ensure grid compliance the reactive power control shall use voltage and reactive power reference at POI. The reactive power support requirement is specified in the grid code and the system shall be designed accordingly. TSO may, in special operation scenarios, specify how reactive power shall be controlled, by providing a reference value for voltage, reactive power or power factor at POI. The Power Control system shall be suited for different power control modes to enable input from TSO and manual input of set points. The concept for reactive power control shall be in line with the Projects Grid Connection Conditions and shall be agreed with the TSO.</Text><Text id="46079" page="13">De-load and inter-tripping; Under certain operational scenarios the grid owner may need to rapidly reduce the power production from the wind farm. In this situation the wind farm must be able to efficiently and reliably de-load as required by the grid owner. Should the required de-loading not be executed sufficiently fast, a trip shall be initiated according to a pre- defined inter-tripping scheme agreed with TSO.</Text><Text id="46080" page="13">1) Technical integrity; During operation of the wind farm there will be a limited number of pre-defined operational scenarios, sometimes referred to as Configurations and Topologies. Configuration means a clearly defined combination of open and closed HV breakers, and thereby a defined set of transformers, reactors, and WTGs in operation. Different Configurations may require different needs of support from the WFPC units. Topology is a term used by the WTG Contractor for identifying scenarios where a sub-set of WTGs may be controlled by another WFPC</Text><Text id="46081" page="14">than then normal one. If for instance a transformer on the OSS is inoperable and a bus-tie breaker is closed to reroute power towards the grid on-shore, the power generated by a set of WTGs may now be routed in such a way that it is measured by another WFPC module than before. Such change of Topology required a Topology change sequency to be performed before resuming operation to inform the WFPC about the change in WTGs under its measurement and control.</Text><Text id="46082" page="14">For some pre-defined scenarios there can be limitations to permitted power production to prevent overloading components (e.g., cables &amp; transformers). Rerouting power by opening and closing of HV breakers in the system often means changing from one Topology or Configuration to another. A Topology Change procedure must be developed for the project since it involves informing the WFPC system about which WTGs are under which WFPC units&apos; control. The procedure shall define the necessary steps to be performed by operators in ESI Scada HMI, and for a given topology the system may be permitted only to change to a few other topologies, e.g., if the operator attempts to change to a topology for which there is insufficient capacity in transformers or export cables, they will be warned that this is an invalid topology.</Text><Text id="46083" page="14">These three functions are implemented in a common interface where the ESI Power Controller (EPC) and the Wind Farm Power Controllers (WFPC) are the main units at the side. The number and location of the EPCs and WFPCs necessary to implement reliable, maintainable, and safe solutions shall be assessed as part of the overall system design.</Text><Text id="46084" page="14">Figure 2 gives a high-level overview of the functional split between the different controllers, as well as the signals exchanged between them.</Text><Text id="46085" page="14">Assess topology and limitations based on all inputs</Text><Text id="46086" page="14">■ Decide Wind park set points (MW, Mvar)</Text><Text id="46088" page="14">Functions: Optimize WTG usage based on Wind Park set point Calculate set point for each WTG</Text><Text id="46091" page="14">Functions: Run each WTG as per received set point</Text><Text id="46092" page="14">Figure 2 Power Control, Interlocks and Grid Compliance. ESI Power control to be delivered by ESI contractor. WFPC and WTG controllers are WTG delivery.</Text><Text id="46093" page="14">The purpose of EPC is to receive external information from the TSO, in addition to information from within the Wind Farm. The information is typically MW, MVAr references, de-load/intertrip requests and so on from the TSO, as well as HV breaker status, transformer/reactor status, power production and export cable temperature from within the Wind Farm. Based on this information the EPC shall determine the optimized power production. The other main task for the EPC is to maintain an overview of the current topology based on the current status of all relevant equipment.</Text><Text id="46094" page="15">The purpose of the WFPC is to adjust the Wind Farm power production according to the demand dictated by TSO, and within the limits dictated by the ESI Power Controller. Based on the set points received from the ESI Power Controller, the WFPC shall give set points to each WTG in operation to meet the overall requirement for MW and MVAr while still adhering to the limitations.</Text><Text id="46095" page="15">Further details of the different controllers and interfaces are described in the following sections.</Text><Text id="46096" page="15">A separate Power Control system philosophy describing the required topologies, tripping schemes and interfaces between the ESI SCADA, the WFPC and TSO for Grid Compliance shall be developed. Also, Power Control functional drawing and equipment scope drawing showing the entire windfarm shall be made, by collecting input from TSO, WTG and OSS.</Text><Text id="46097" page="15">The Wind Farm Power Controller (WFPC) shall be installed by the WTG supplier for control of the reactive and active power from the WTG’s. For SGRE WFPC is normally referred to as High Performance Park Pilot (HPPP).</Text><Text id="46098" page="15">The WFPC shall be able to receive various active power limiting “runback signals” from the Wind Farm Electrical System Infrastructure, e.g., bus tie circuit breaker position indication, external run back signals from grid operator, fault indications on transformer breakers etc. and take action by reducing total wind farm power output according to the new condition in the wind farm. The runback signal with the lowest power limiting shall have priority over runback signals with less reduction in allowable power production.</Text><Text id="46099" page="15">The intertrip/ run back signals from TSO control centre shall have duplicated communication routes between the POI and ONS. TSO intertrip shall have priority above all other intertrip signals, as long as the isolation of a fault is according to relevant electrical system studies, to ensure the safest intertrip scheme for every fault cause and location. This will be specified in the Power System Philosophy.</Text><Text id="46100" page="15">To perform required power control the interface signals per WFPC /Balancing mechanism units (BMU) must be included, such as: MW and MVAr references, MW measurements, MW and MVAr Set point, MW production, MW at Grid entry point, De- load request, Breaker configuration/constellation, and voltage measurements to be included and presented on the ESI SCADA HMI.</Text><Text id="46101" page="15">Required Trip and De-load signals shall be included as defined by TSO requirements.</Text><Text id="46102" page="15">It is the responsibility of the Contractor to coordinate the WFPC settings with the ESI system so that the overall integrity of the power system is not degraded. The WFPC shall have functionality supporting the different possible operating modes of the WTGs</Text><Text id="46103" page="15">A Function design document, equipment scope and cause and effect scheme shall be developed showing all exchanging signals with ESI SCADA.</Text><Text id="46104" page="15">The wind farm shall be designed to operate and be energized under different operation scenarios without overloading the plant.</Text><Text id="46105" page="15">Required functions, logic, interlocks, control of the different breaker positions/constellation, topologies and operation limits shall be included to maintain the active power and reactive power needed within defined limits to ensure the primary plant is not overloaded and the compliance to the grid code is met.</Text><Text id="46106" page="15">To fulfil this requirement a dedicated ESI Power Controller (EPC), for single point of contact with the WTG WFPC, shall be included for handling automatic verification of different topologies for the “Grid Code” Compliance towards TSO. Required</Text><Text id="46107" page="16">topologies/logic, trip, and de-load signals (Soft stop), breakers status and control signals (MW, MVAr setpoints) shall be implemented between the EPC and the WFPC. Alternatives to a PLC-based implementation may be accepted by Company provided it can be documented that reliability, maintainability and uptime is comparable to the PLC.</Text><Text id="46108" page="16">The purpose of the EPC is to automate the response regarding power flow in each export cable dependent on a set of operational modes, scenarios (contingencies) and topologies/breaker constellations for the ONS and OSS.</Text><Text id="46109" page="16">• The functionality to be implemented in the EPC for grid code compliance will be described in the Power System</Text><Text id="46110" page="16">Philosophy, and shall be followed. The main functionality shall be: o Power limitation dependent of operating scenario and a defined set of power limitation inputs (onshore/offshore) o Reactive power setpoint as a function of active power output and operational scenario.</Text><Text id="46111" page="16">The wind farm may be energized to operate under any of the above configurations by the operating personnel.</Text><Text id="46112" page="16">Depending on the configuration, the active power and reactive power needs to be maintained within defined limits to ensure the primary plant and component limits are not exceeded and the agreed compliance for the specific scenario to the grid code is met. To meet this functionality the required topologies and logic shall be implemented in dedicated controllers – the EPC and WFPC.</Text><Text id="46113" page="16">The ESI Power Controller shall include all relevant functionality to comply with the Power System Philosophy. It will include, but not limited to, the following:</Text><Text id="46114" page="16">• Receive WTG 66kV switchgear configuration information from the IEDs monitoring the WTG 66kV switchgears.</Text><Text id="46115" page="16">• Receive offshore 66 kV switchgear configuration information from the IEDs monitoring the switchgear.</Text><Text id="46116" page="16">• Receive onshore 220 kV switchgear status information, receive necessary measurements from WTG and ESI SCADA.</Text><Text id="46117" page="16">• Use reactive power controller at POI to give feedback to STATCOM to ensure the voltage and reactive power delivered is within the given limits in the Grid Code.</Text><Text id="46118" page="16">• Use active power controller at POI to give feedback to the WTG production to ensure the frequency and active power delivered is within the given limits in the Grid Code.</Text><Text id="46119" page="16">• Use the WTG and offshore 66 kV circuit breaker configuration and onshore 220 kV switchgear status information and measurements to provide the MW and MVAr set points to WFPC to ensure optimized compensation of the 220kV export cables.</Text><Text id="46120" page="16">• Utilise the CTS/DRS/DTS information to reduce the loading on the export cable when required.</Text><Text id="46121" page="16">• Detect and prevent invalid topologies and fault operation.</Text><Text id="46122" page="16">• Raise an alarm and/or initiate interlocks if the operator prepares to run the wind farm into a configuration which is not permitted.</Text><Text id="46123" page="16">Modes of operation and limitation scenarios shall be included. The below table indicate some examples, based on previous experience. It is the responsibility of the Contractor to develop the required modes for operation and limitations scenarios applicable to according to the project specific Power System Philosophy.</Text><Text id="46124" page="17">• Raise alarm and suggest a safe reconfiguration of the network in case an EAT (including 66kV earth reference point) at OSS is lost</Text><Text id="46125" page="17">• Either automatically and/or manually from the O&amp;M Base CCR execute de-loading of the wind farm, based on instruction from TSO.</Text><Text id="46126" page="17">• Either automatically and/or manually curtail the MW output of the wind farm if required.</Text><Text id="46127" page="17">• Raise an alarm, de-load and/or trip if the overall control interface fails.</Text><Text id="46128" page="17">• One push button energization sequence for the wind farm (ONS-OSS-WTG), including relevant time delay for the sequence to energizing the WTG transformers.</Text><Text id="46129" page="17">The wind farm MW and MVAr at the 66 kV or 220kV side offshore is handled via WFPCs which shall be interfaced to the EPC by means of a WFPC PLC to achieve the above aims of the overall control interface. The number and electrical placement of the WFPC controllers shall be evaluated during ESON FEED based on Grid code requirements, regulations related to need Balancing Mechanism Units (as in the United Kingdom or Polish equivalent) and subsidy CfD rules.</Text><Text id="46130" page="17">The need and method for de-load and tripping signals or requests shall be agreed with the TSO through workshops. The functionality must be in accordance with all grid code requirements for different operating modes and with the Power System Philosophy. TSO requirements to signal interfaces must be clarified through FEED.</Text><Text id="46131" page="17">Redundancy and Failure A fault function will need to be included to detect any problems caused by the program logic execution or interface/communication fault.</Text><Text id="46132" page="17">• Failure of EPC shall raise an alarm to the ESI SCADA.</Text><Text id="46133" page="17">• Failure of WFPC shall raise an alarm to the ESI SCADA.</Text><Text id="46134" page="17">• Communication error between the EPC and WFPC shall raise an alarm to the ESI SCADA</Text><Text id="46135" page="17">Redundancy of the interface between ESI Power Control and WFPC shall be included.</Text><Text id="46136" page="17">The EPC and ESI SCADA shall receive breaker status information from the POI connection point, ONS, OSS and WTG 66kV switch gear. The short circuit levels are high in the WTG system. LV breakers on 690 V will most likely not be allowed manual operation of. Status and possible operation of all 690 V breaker is mandatory in WPS/ESI scada</Text><Text id="46137" page="17">The DTS for both IAC and EC shall be integrated to the EPC for cable monitoring and power control to ensure cable integrity in all operational scenarios/configurations/topologies.</Text><Text id="46138" page="17">For all information and interface signals described above, it shall be ensured that information is exchanged as direct as possible if the units communicating are connected to the same network. Firewall crossings shall be done at the lowest possible level. Communication and available network architecture shall be thoroughly assessed when hardware for implementation of EPC and WFPC functionality is considered. Horizontal communication shall be limited to the extent necessary.</Text><Text id="46139" page="18">The IACS test facility shall accommodate testing of all changes to applications, configurations, and settings prior to implementation on the live system. Testing shall be performed without relying on any part of the operating IACS. Software simulators shall be utilized to emulate IACS components to the extent possible, hardware components shall be delivered for units where this is not possible. The test facility shall have necessary network connections to permit download of security patches and other software updates for test and connected to the company secure access solution for remote activities.</Text><Text id="46140" page="18">The test facility functionality shall include but not be limited to;</Text><Text id="46143" page="18">IACS networks shall be designed according to reference standards and requirements document as described in Appendix E, which gives the framework for the design and specific requirements to the proposed solution. This design and requirements are based on IEC62443. This includes, but are not limited to, zoning and conduits, firewall requirements, OS patching, malware, and antivirus protection. All systems delivered (including subsystems) shall be assessed, designed, implemented, and documented according to the requirements and guidance in these frameworks and requirements, including (dependent on project phase):</Text><Text id="46144" page="18">• Network, Security Zones and Conduit drawings shall be made by Contractor. The template for the drawing shall be provided by Employer.</Text><Text id="46145" page="18">• The Zones and Conduit drawing shall contain Security Level-Targets substantively following the processes as set out by IEC62443-3-3:2019. The SL-Ts will be based on the Reference Architecture Model in IEC62443-3-3:2019 and the SL-Ts shown therein and documented as a part of the topology drawing agreed between Company and Contractors/Suppliers</Text><Text id="46146" page="18">• Cyber Security tests shall be a part of the Contractors and Suppliers’ FAT procedure and report</Text><Text id="46147" page="18">• The Contractor shall conduct a detailed Cyber Security Risk and Vulnerability Assessment. A Detailed Risk and Vulnerability Assessment report shall be provided to Company. The assessment should follow the processes defined in IEC 62443-3-2</Text><Text id="46148" page="18">• Create backups and test the backup and recovery procedures.</Text><Text id="46149" page="18">• Antivirus and patch management procedures shall be described. All systems, servers and clients shall be tested to ensure that required antivirus and security OS patches are installed.</Text><Text id="46150" page="18">• The Contractor shall make procedures and strategies for hardware, OS and software upgrades for all systems.</Text><Text id="46151" page="18">Each computer and Server on the technical and process network shall be kept up to date with security patches and virus protection software during project execution and at handover to Company. The system shall also be designed to enable patching and malware protection during normal operation.</Text><Text id="46152" page="19">All hardware and software shall when commissioning is complete have at least 10 years left before End of Life, i.e., before Support is no longer officially available from the Manufacturer. This shall be from the date when Contractor has completed his commissioning scope, as well as all assistance to Company during offshore commissioning.</Text><Text id="46153" page="19">The systems on the technical network shall have local access to a recovery backup. Recovery backup shall be performed after all software changes. The automated backup solution shall be able to hold minimum 10 previous backups.</Text><Text id="46154" page="19">The arrangement and configuration of servers and communication equipment shall be based on a redundancy philosophy. If any of the substation SCADA server / communication equipment fails, then a standby server shall take over, or communication shall be routed through another channel. Performance of the backup channel shall be equal to that of the primary communication channel.</Text><Text id="46155" page="19">The SCADA Logic Solvers/logic controllers shall be based on a true real-time operating system to achieve the necessary degree of security, reliability, and reduced maintenance, i.e., operating systems like Microsoft Windows are not allowed for Logic Solvers.</Text><Text id="46156" page="19">Process values shall be in engineering units throughout the system (engineering tools and run-time system).</Text><Text id="46157" page="19">When powered up after being powered down, the total IACS shall automatically restart, including all internal system communication mechanisms, without manual intervention. Power-up shall not cause spurious activation of outputs. Restart shall take less than 10 minutes.</Text><Text id="46158" page="19">Configuration changes to the logic solvers/IEDs shall be persistent, such that the configuration is not affected by power loss and restart.</Text><Text id="46159" page="19">All system software changes shall be recorded in defined system for logging changes visible (auditable and unalterable log) to Company.</Text><Text id="46160" page="19">There shall be facilities for read-out of current versions of all system software and firmware, including logic solvers, control and protection devices, I/O cards, servers, and operator stations.</Text><Text id="46161" page="19">The IACS software tools shall be available through Company Secure access solution.</Text><Text id="46162" page="19">The software tools shall be available from a central management server and/or from the engineering-/maintenance workplace.</Text><Text id="46163" page="19">Software should allow for a central management server to apply all updates, modifications, patches, etc from a single location. This should be accessible via Company Secure access solution.</Text><Text id="46164" page="19">If several engineering stations are used, then the SCADA shall have means of preventing online configuration conflicts. SCADA applications and system performance shall not be influenced by utilization of engineering tools.</Text><Text id="46165" page="19">The system shall be self-documenting including both suppliers’ standard application blocks and project specified application blocks. The documentation shall be &quot;as programmed&quot; in the executing SCADA logic solvers, servers, and Control and protection unit/devices.</Text><Text id="46166" page="19">It shall be possible to document the application program directly from the system including utility systems, Control and Protection devices and IED’s and make it available as a graphical report. In special cases, program listings can be accepted based on Company preapproval. An automatic cross reference between graphical report interconnections shall be included.</Text><Text id="46167" page="19">There shall be a tool for automatic read-back of the current online parameters and comparison with the engineering master. It shall be possible to perform an update of the master configuration files for all or for selected parameters. This tool shall</Text><Text id="46168" page="20">provide a report showing the parameter differences. In the case of deviations these shall be reported as maintenance alarms/advisories, not to the main operator alarm list.</Text><Text id="46169" page="20">There shall be admin/management tools for remote monitoring and management for the system. The system shall send diagnostic information in case of failure. The information shall be available in the admin/management tools to address problems rapidly and take corrective actions.</Text><Text id="46170" page="20">Servers / clients shall all be supplied with both Administrator and Operator logins</Text><Text id="46171" page="20">The system shall have role-based security to prevent unauthorized access to functionality. Any thick client Application shall support 64-bit client Operating System, e.g., Windows 10.</Text><Text id="46172" page="20">The system server application shall support Windows Server 2019 or newer. Unless system servers have need for special interfaces that prevents virtualization, servers shall be provided with VMWare Workstation Pro 14 (or newer) Virtualization software.</Text><Text id="46173" page="20">Required back-up solution shall be provided to be able to perform automatic and regular back-up of the SCADA and subsystems software including Network, HMI, and engineering workstation.</Text><Text id="46174" page="20">For any backup media used by the backup / recovery solution, it shall be possible to store the backup media in a separate location (either on a physical backup media, or by file transfer to a Company server).</Text><Text id="46175" page="20">A backup and recovery solution shall be included, covering all equipment with software, configuration settings and other data needed to recover the system to resume normal operation.</Text><Text id="46176" page="20">The IACS shall be distributed and designed to be self-contained (autonomous)</Text><Text id="46177" page="20">SCADA servers and Logic devices/Logic Solvers hardware shall be unified, i.e., a limited number of hardware types shall be used to ease maintenance and spare part handling. It shall be possible to replace redundant components in SCADA during normal operation of the system, without any loss of functionality or production.</Text><Text id="46178" page="20">Any SCADA unit shall be able to survive loss of power for an indefinite period without irrecoverable loss of application programs, configuration or parameters which have been set by the user/operator.</Text><Text id="46179" page="20">Approximate recovery time for each SCADA unit shall be documented and verified.</Text><Text id="46180" page="20">Electrically powered devices shall comply with relevant test limits and performance criteria in EN 61326 or IEC 61000-6-2 and IEC 61000-6-4 with respect to electromagnetic emission and immunity in an industrial environment.</Text><Text id="46181" page="20">Company assigned IP addresses shall be used for all systems. Note that IP addresses shall not be openly displayed on the HMI or in system documentation.</Text><Text id="46182" page="21">To ensure network time synchronization and provide coordinated time stamping for alarms and events, between all IACS system units, electrical, instrumentation and telecommunications systems, a common and reliable NTP, or better, time server (real-time clock) shall be used. The time server shall receive Network Time Protocol (NTP) coordinated universal time (Universal Time Coordinated (UTC)) or better from the telecommunication system real-time clock (RTC) and distribute the time to other system equipment including networked field devices. If possible, the RTC shall be a common clock used for telecom, IACS, electro and Control &amp; Protection equipment, to avoid multiple sets of GPS antennas on the facility.</Text><Text id="46183" page="21">Contractor shall ensure all relevant components receive the UTC time and maintain correct time. This is applicable to all components connected to a network.</Text><Text id="46184" page="21">The time server shall be equipped with 10/100Mbit/s outputs, in an RJ45 format, for direct connection to the SCADA backbone, technical network and other consumers. Instrumentation, telecommunication systems shall request NTP (Network Time Protocol) (or better) information from the time server for time synchronization.</Text><Text id="46185" page="21">The SCADA shall be capable of providing a time synchronization signal to IEDs via IEC 61850 protocol to ensure all events are time stamped.</Text><Text id="46186" page="21">The HMI shall have the possibility of enabling daylight saving summertime (Wintertime + 1 hour) including alarm list.</Text><Text id="46187" page="21">All events, process and system alarms shall be time stamped in order to identify the correct sequence of events. Time stamping should be performed by the SCADA units, and the accuracy of the time stamping shall be according to the defined cycle time. Timestamps shall use UTC.</Text><Text id="46188" page="21">Independent of configuration and number SCADA control devices/units, the protection alarms in SCADA, control and protection equipment and all sub-systems shall be time stamped with the accuracy of 10 ms, or better, relative to when they physically appear.</Text><Text id="46189" page="21">All IO values in the system shall include Quality and Timestamp (VQT). VQT shall be propagated throughout the system, from the IO device (e.g., IED or PLC) through to the HMI and IMS.</Text><Text id="46190" page="21">Timestamps shall be in UTC. The quality code shall be an industry standard. Company’s preference is the OPC UA quality codes.</Text><Text id="46191" page="21">All SCADA hardware modules shall have been tested in accordance with recognised industrial standards regarding susceptibility to environmental conditions such as:</Text><Text id="46194" page="22">IACS failure shall in general not cause a production loss. This includes all components in the SCADA system.</Text><Text id="46195" page="22">In addition, Mean Time Between Failure (MTBF) and Mean Time to Repair (MTTR) figures shall be documented and calculations of overall IACS availability shall be performed. The overall system availability requirement is set to 99,5%, the IACS shall be designed such as it will not contribute to a lower total availability than 99,5%. No single IACS failure shall have the effect to disrupt the process.</Text><Text id="46196" page="22">Design of safety instrumented functions shall be based on the Safety Requirement Specification developed on basis of the Hazard and Risk analysis.</Text><Text id="46197" page="22">Redundancy shall be evaluated based on the following:</Text><Text id="46211" page="23">Short time data shall be possible to store for at least 30 days. Database storage with RAID 0+1 striping is preferred.</Text><Text id="46212" page="23">The different database servers such as OPC, ODBC etc shall have required direct interface to Company IMS.</Text><Text id="46213" page="23">All units on the IACS network, including network components and IEDs shall be monitored and detected fault or malfunction shall be alarmed. IACS unit, fault type and card (if relevant) shall as a minimum be referenced in the alarm text.</Text><Text id="46214" page="23">Programming for logic solvers shall comply with IEC 61131-3 Function Block Diagram, Sequential Function Chart and Structured Text. Structured Text shall be used for function block coding only.</Text><Text id="46215" page="23">It shall be possible to configure SCADA and Logic Solver applications semi automatically, as well as manually, utilising different configuration levels and libraries of function blocks and templates (ref. section 9.5) to maintain the consistent use and quality throughout the configuration. The use of a central management server shall be considered for maintenance of SCADA software and libraries.</Text><Text id="46216" page="23">SCADA and Logic Solver functionality shall support application configuration on the following levels:</Text><Text id="46221" page="23">TR4036 “SCADA Operator Station HMI” should be the basis for development of an HMI philosophy. The Project will have two SCADA systems, one dedicated to the WTGs, referred to as WTG SCADA, and one dedicated to the ESI (power distribution systems and utilities) referred to as the ESI SCADA. There shall be some exchange of information between the two, but they will not be fully integrated. The ESI SCADA and WTG SCADA system shall include all necessary HMI, operator, engineering, and service workstations for remote monitoring and control. The SCADA operator station represents the main HMI between the operator and the electrical distribution and utility facilities.</Text><Text id="46222" page="24">The HMI solution shall include equipment and functionality for Large Screen solution. Dedicated mimics shall be developed for the Large Screen Display solution to ensure correct information as well as level of detail and readability is ensured.</Text><Text id="46223" page="24">An HMI philosophy detailing the HMI functionality shall be developed during detail design. The philosophy shall cover HMI solutions, alarm, and trend solutions as well as the Large Screen Display solution, and any other functionality foreseen to be covered from the Operator Stations.</Text><Text id="46224" page="24">The HMI (Human Machine Interface) for all systems in the control room shall be built to a common standard/philosophy, as agreed with Company. This HMI standard shall include:</Text><Text id="46225" page="24">• Consistent use of colours, layout, and sounds</Text><Text id="46226" page="24">• Consistent screen navigation and functions, for example:</Text><Text id="46227" page="24">‣ One-click navigation from alarm summary to associated HMI display</Text><Text id="46228" page="24">• Clear indication of the relevant wind farm and plant area/system</Text><Text id="46229" page="24">Required HMI/Operator Workstations shall be available at the CCR in O&amp;M Base situated in Leba, on the OSS and ONS.</Text><Text id="46230" page="24">Engineering workstations shall be installed at ONS/OSS and remotely accessed from CCR and Company secure access solution.</Text><Text id="46231" page="24">From the engineering workstation, it shall be possible to perform maintenance, troubleshooting, without any interference with the monitoring and control of the process.</Text><Text id="46232" page="24">Use of symbols and colours for operator interface shall be consistent throughout. Tagging of alarms and events for the local operator interfaces, shall be consistent and harmonized with the WTG Supplier Wind Power workstation.</Text><Text id="46233" page="24">In line with the agreed HMI philosophy, the IACS and SCADA HMI shall have required functionality and interface for viewing and selection of all SCADA HMI mimics, alarm and events, IMS information, CCTV (Closed circuit television) information/mimics, Intruder information/mimics.</Text><Text id="46234" page="24">The layout of the HMI displays shall be function-oriented and based on Single Line Diagrams, Key Line diagram, SCADA Topology Drawings, Fire Detection Layouts, Area Layout drawings, P&amp;ID, etc. The display shall enable the operator to monitor and control ESI electrical and utility section functions. Where interfaces and interaction with TSO is needed, the symbols and naming shall be the same as TSO to avoid misunderstandings.</Text><Text id="46235" page="24">WTG displays shall enable monitoring and control of relevant WTG functions.</Text><Text id="46236" page="24">The electrical and utility detail display shall contain all electrical process-related variables and control functions for each section.</Text><Text id="46237" page="24">The HMI display for the electrical system shall be split into different HV and LV electrical main and sub levels, including but not limited to Generator, UPS system, and utility process sub level displays. In addition, there shall be separate displays for all utility systems, including but not limited to;</Text><Text id="46238" page="25">The use of colours shall be fully based on applicable standard for similar offshore wind projects and agreed with Company. TR4036 should be used as guideline. There shall be a clear distinction between dynamic symbols and static symbols on the displays.</Text><Text id="46239" page="25">The operator shall be able to select the corresponding trend displays from the process detail display. All signals shall have trend facility with adjustable time and range span.</Text><Text id="46240" page="25">The HMI system shall be object based. From the object faceplate, it shall be possible to:</Text><Text id="46241" page="25">• Operate the equipment. All commands that will change the state of the equipment (e.g., Open, Close) shall require confirmation. No more than one level of confirmation is required.</Text><Text id="46242" page="25">• View any current interlocks on the equipment, and the origin of these interlocks</Text><Text id="46243" page="25">• View any current alarms on the equipment</Text><Text id="46244" page="25">• View the current quality and timestamps, including timestamp of last good value</Text><Text id="46246" page="25">The HMI system shall include the following functionality:</Text><Text id="46247" page="25">• Operator notes/comments. It shall be possible to associate operator notes with any HMI object (e.g. circuit breaker, disconnector, earth switch). A symbol next to the object shall indicate that there is an active operator note. Operator notes shall be timestamped and shall record the name of the operator as well as the actual text entered. The contents of the operator notes shall be logged on the SCADA server and retrievable via the report system.</Text><Text id="46248" page="25">The HMI displays shall be based on recognized standards, such as the following:</Text><Text id="46249" page="25">The use of static text shall be minimized. Branding (the inclusion of the supplier’s name or logo within the HMI) is not permitted.</Text><Text id="46250" page="25">Bad-value representation: HMI displays shall normally display the current value of the IO tag. In the event of bad or uncertain quality, this shall be clearly indicated on the HMI. The last good value shall be shown on the HMI. It shall be possible to see the timestamp of the last good value, for example in the object faceplate.</Text><Text id="46251" page="25">Control and monitoring of OSS systems at the CCR shall be through the ESI SCADA, not a separate OSS HMI. OSS SUS shall be integrated in the ESI SCADA to allow supervisory control, monitoring and alarm handling of OSS SUS and the related sub- systems noted in Section 3.2.1.</Text><Text id="46252" page="25">HMI summary screens from the OSS SUS shall be reproduced in the ESI SCADA including supervisory control functionality. Alarm and event handling shall be per Section 5.2.5. Remote troubleshooting of OSS SUS or subsystems shall be possible using engineering workstations at the CCR; Contractor and OSS Contractor shall coordinate on automation and telecoms system design to allow this remote accessibility.</Text><Text id="46253" page="25">ESI SCADA integration with OSS systems and end devices shall include: - Hardwired interfaces to OSS lighting controls as noted in OSS Specification.</Text><Text id="46254" page="26">- Hardwired interfaces to LV switchgear and Standby Diesel Generator (SDG) for trip commands: main and generator breaker trips, diesel generator unit trip.</Text><Text id="46255" page="26">- Hardwired interfaces to LV switchgear, UPS, and SDG for key status points: main and generator breaker status, UPS common alarm contact, other key status points at ~4-5 per device.</Text><Text id="46256" page="26">- Hardwired interfaces for any OSS safety-related functions executed by ESI-SCADA. Above-noted LV main breaker and SDG trips are examples of this.</Text><Text id="46257" page="26">- Hardwired or soft interfaces to Motor MCB’s that are controllable directly by ESI SCADA. Interface method is to be agreed with OSS Contractor.</Text><Text id="46258" page="26">- Soft interfaces to LV switchgear, MCC’s, UPS and SDG for the remainder of SCADA functionality for electrical systems. This could be a combination of direct interfaces with the end devices or through the OSS SUS. - Soft interfaces to protective relays for integration into P&amp;C networks (e.g., IEC 61850). - Hardwired interfaces to sub-panel breaker status as noted in OSS specification. - ESI SCADA interfacing with non-electrical OSS systems, e.g., HVAC and F&amp;G, shall be through soft link with OSS SUS except as noted above.</Text><Text id="46259" page="26">Hardwired interface method including typical loop configurations are to be agreed with OSS Contractor. Interposing relays, where required, shall be provided by OSS Contractor.</Text><Text id="46260" page="26">To ease the workload for the operators in CCR, several HMI components from WTG SCADA shall be displayed in ESI SCADA as a minimum the following functionality and information shall be induced:</Text><Text id="46273" page="27">Alarms shall be prioritized according to the severity of consequences that could be avoided by corrective actions and the time available for successful corrective operator action.</Text><Text id="46274" page="27">Alarm management capabilities (e.g., the ability to filter, block, suppress, handle nuisance alarms, sort or re-prioritize) shall be provided.</Text><Text id="46275" page="27">A common alarm prioritisation scheme shall be used, approved by Company prior to implementation. At least 4 priorities shall be supported. It shall be possible to direct certain alarm priorities to different users.</Text><Text id="46276" page="27">The alarms shall be presented with text, colours, symbols, and sound, clearly differentiated from other information. Alarm description shall be understandable and self-explanatory for the operation.</Text><Text id="46277" page="27">The operator shall be alerted by means of audible and visual indication. The alarm shall present information defining the problem e.g., descriptive alarm text in alarm lists and change in graphic displays on operator stations.</Text><Text id="46278" page="27">Each tag/alarm should have an associated free-text comment field available for use by the operator. The operator shall be allowed to sort and filter lists. Alarm and event shall be in separate lists on SCADA HMI.</Text><Text id="46279" page="27">The system shall include the following alarm/event categories:</Text><Text id="46281" page="27">Alarm implies an audible alarm requiring acknowledgement by the operator. Before acknowledgement, the object shall be flashing. When acknowledged, the object is shown with steady light. An acknowledged alarm shall reflect the abnormal process condition until the process variable has returned to normal state.</Text><Text id="46282" page="27">A common sounder system shall be implemented to avoid multiple sounders simultaneously sounding and causing confusion.</Text><Text id="46283" page="27">Event requires neither audible alarm nor acknowledgement by the operator. When applicable, events shall result in a visual change of state on the associated dynamic symbol.</Text><Text id="46284" page="27">Alarms and events shall be reported on separate summaries and recorded on disk. Options shall exist to recall alarms/events on search criteria like time, tag, process section, event type, etc. Suppressed alarms are not logged.</Text><Text id="46285" page="27">Alarm list The following information shall be available for each alarm / status:</Text><Text id="46309" page="29">SCADA shall provide a facility for real time and historical trending for all binary and analogue variables, independent of the IMS. Real time trending shall be with the same time resolution as the cycle time of the application in the Logic solver.</Text><Text id="46310" page="29">Historical trending shall have user selectable sampling time, normally 1 second. Sampling time for selected values shall be possible from 100 ms. SCADA shall store relevant values for a minimum of 35 days for trending purposes.</Text><Text id="46311" page="29">Print server functionality on the SCADA servers shall be included for printing of alarm and event list/reports, HMI mimic from all the Operator workstation via DMZ print server via Company secure access solution to a printer on the office network and to a SCADA local printer.</Text><Text id="46312" page="29">Failure of one operator station shall not prevent printer access. Silent type of colour printers shall be used.</Text><Text id="46313" page="29">A printer shall be available at the CCR. It shall be possible to generate printouts, e.g., screen dumps, list, reports from the SCADA engineering station. Required printers shall be installed on the O&amp;M Base CCR and ONS.</Text><Text id="46314" page="29">A Safety system shall be installed for detection of abnormal conditions and to perform necessary action. Reference is made to safety strategies in Appendix E.</Text><Text id="46316" page="29">Control &amp; Protection system shall shut down necessary equipment during an fault situation, automatically or manually and remotely from the CCR.</Text><Text id="46317" page="29">The Fire Detection and Fire Fighting systems shall be integrated in the ESI SCADA system via agreed interface protocol.</Text><Text id="46318" page="29">The purpose of the shutdown system is to prevent escalation of abnormal conditions into a major hazardous event and to limit the extent and duration of any such events that do occur.</Text><Text id="46319" page="29">The shutdown logic shall be implemented by use of Logic Solvers.</Text><Text id="46320" page="29">The probability of single defects / failures causing inadvertent trip actions shall be as low as reasonably possible, e.g., provide fault tolerance by means of automatic diagnostic features and redundancy according to cost-benefit assessment.</Text><Text id="46321" page="30">Safety system shall have facilities to allow for testing and maintenance without interrupting production or operation. Safety system shall be in compliance with DNVGL-ST-0145.</Text><Text id="46322" page="30">Manual initiating of the different shutdown levels shall be possible from CCR via reliable connection to the ESD/Fire/safety logic solver.</Text><Text id="46323" page="30">A Fire detection system for continuously monitoring of the fire status and execute safety related functions upon fire detection shall be installed. The fire detection system shall comply to applicable Polish standards as defined in appendix E requirements.</Text><Text id="46324" page="30">Aspiration smoke detection shall be used for areas not accessible in normal operation.</Text><Text id="46325" page="30">The control logic/Cause &amp; effect for the ONS shall preferably be included by use of separate Logic Solvers but may also be included locally in the fire detection panel. Solution to be agreed upon.</Text><Text id="46326" page="30">The safety related parts of HVAC, such as closing of fire dampers and trip of fans and heaters, shall be part of the Fire Fighting system.</Text><Text id="46327" page="30">The Fire Detection system shall have the capability to handle addressable detectors either directly or interfaced through dedicated Fire detector panels via agreed interface protocol.</Text><Text id="46328" page="30">Silent testing shall be possible, i.e., for the functions being tested it shall be possible to disable audible alarm annunciation and also inhibit release of Fire Fighting agent.</Text><Text id="46329" page="30">All safety critical loops for the Fire Detection System shall be line monitored, enabling detection of abnormalities (e.g., earth fault detection, short circuit detection, open circuit detection in the entire circuits, etc.).</Text><Text id="46330" page="30">When powered up after being powered down, the total Fire system shall automatically restart itself, including all internal system communication mechanisms, without manual intervention. This also includes F detector interface centrals. Power-up shall not cause spurious activation of outputs.</Text><Text id="46331" page="30">All fire Detection Systems/Panels shall be powered from two independent UPS electrical sources.</Text><Text id="46332" page="30">The UPS shall offer 100 percent redundancy, such that loss of one power source shall not cause any malfunction within the system.</Text><Text id="46333" page="30">Gas detection may be provided in battery rooms for Hydrogen, and in switchgear rooms for SF6 leakage. Gas alarms shall be enunciated locally both inside and at the entrance to the electrical rooms. Gas alarms shall also be sent to the ESI SCADA system via robust industry standard protocol, to be decided during detailed design.</Text><Text id="46334" page="30">A control system for monitoring and control of HVAC system on ONS and OSS shall be implemented. The HVAC Control System shall be fully integrated in ESI SCADA for operation and monitoring. For chilled water system, supplier&apos;s local control system shall be used. System status and operation signals shall be transferred to ESI SCADA system for information.</Text><Text id="46335" page="31">Fire dampers shall be initiated from the Fire Detection system with damper position limit switches also connected to the Fire Detection system. The HVAC system including fire dampers, fans, instrumentation shall be shown on a separate HVAC HMI picture. Fire dampers shall be redundant to allow for periodic testing. Failure of a fire damper in closed position during testing shall not be critical for power production/affect platform operations. Design of fire dampers and control systems shall allow for remote testing, monitoring and recording of opening and closing times. If maximum limits for opening/closing times are exceeded, alarm shall be given.</Text><Text id="46336" page="31">The HVAC logical programmable logic devices/Logic Solvers should preferably be connected to the ESI SCADA system via OPC UA, IEC-104 protocol or by Profibus protocol. Use of Profibus shall be agreed upon.</Text><Text id="46337" page="31">All data from the HVAC control and monitoring system shall be available in the SCADA system servers/HMI. All real time values, analogue data from the HVAC system shall be available to the IMS via agreed interface.</Text><Text id="46338" page="31">It shall be possible for remote connection to the HVAC Control system for diagnostic, troubleshooting and SW updating via Company Secure Access solution.</Text><Text id="46339" page="31">Communication line between ONS and Company administrative network, O&amp;M Base CCR and TSO operator, and between OSS and ONS, shall be redundant and through Multi-Protocol Label Switch with Transport Profile (MPLS-TP) infrastructure and it shall support routable communication protocols such as IEC104 and OPC UA. Interface requirements and capacity shall be as described in the Telecom Technical and functional requirements document C256-EQ-T-SP-00001.</Text><Text id="46340" page="31">A fiber optic network based on the fiber cores in electrical cables shall be established for control/monitoring and telecommunication purposes both for all WTGs and the OSS. The WTGs shall be connected to the OSS via fibers in the inter array subsea electrical cables.</Text><Text id="46341" page="31">Communication to shore shall be via redundant single mode fiber optics, G.652, as part of the subsea export cable. All communication to shore shall be equipment redundant i.e., if one link goes down, the communication shall automatically switch over to the other link. Communication between ONS and OSS as well as internal communications on substations shall be done by standard protocols e.g., TCP/IP, IEC104 and IEC 61850 through the MPLS-TP infrastructure.</Text><Text id="46342" page="31">All networks shall be monitored, and an alarm shall be raised in the ESI SCADA if any part of the network does not perform as expected to permit the first line maintenance to action the problem. In addition, the networks will be monitored by Company’s specialist service during the operational phase, therefore some central network components shall be Company Provided Items to ensure monitoring systems already established can be used. Furthermore, to ensure the IACS networks are fully transparent to the monitoring system, also some network components further “down” in the system require Company approval. Close cooperation with Company’s network specialist is required.</Text><Text id="46343" page="31">Some signalling may require full redundancy/different routing between ONS and OSS, according to Grid Connection Agreement, Grid Code and Technical Conditions for The Connection to The Telecommunication Network of PSE S.A. Agreement with TSO (App E), and the required communication systems shall be installed to fulfil this requirement.</Text><Text id="46344" page="31">A typical Architecture model of Integrated Automation and Control system is shown in figure 1. Based on this an overall SCADA network hierarchy/topology drawing including all SCADA process network, technical network, and Company Wide Area Network (WAN) network structure shall be developed and detailed during detail engineering phase, including input from OSS, WTG, IT, TSO or others where relevant.</Text><Text id="46345" page="32">Each SCADA network (ESI and WTG) shall be fully redundant, and a fail-safe philosophy shall be evaluated for critical signals. In case of communication failure, the system shall move to predefined state with regards to the severity of the failure, where the predefined state shall be defined in the fail-safe philosophy. The SCADA systems shall have robust and fault tolerant protocols for the dual redundant communication network and shall have intuitive alarms and diagnostics tools for the communication network.</Text><Text id="46346" page="32">The network shall include RSTP (Rapid Spanning Tree Protocol) functionality, with high priorities on the backbone switches to ensure an uninterruptible changeover if one part of the network fails</Text><Text id="46347" page="32">There shall be a separate process critical data network for the control and monitoring system (process technical network) of all SCADA monitoring and control system. All equipment that needs to communicate together or to remote systems shall be connected via dedicated firewalls to technical network.</Text><Text id="46361" page="33">New data shall only need to be defined once, with one single engineering tool. The interface between SCADA gateway and IMS shall be one of the following protocols:</Text><Text id="46363" page="33">Plant data export shall not have a negative influence on SCADA primary functions, i.e., safeguarding, control and monitoring. The SCADA gateway shall have the buffer capacity to store all SCADA real time data and selected parameters for 7 days. Status information of the interface shall be available in SCADA.</Text><Text id="46364" page="33">The I/O list shall clearly define what is an alarm and what is an event.</Text><Text id="46365" page="33">Communication to TSO (monitoring of electrical Infrastructure at TSO control centre) and settlement metering/trading agency shall also be established, communication protocols to be used to be agreed and approved by TSO.</Text><Text id="46366" page="33">Communication between TSO and ONS should go through a dedicated and redundant link including firewall and malware protection. Secure IT solution and access control shall be established.</Text><Text id="46367" page="33">Signals to be transferred to / from TSO shall be agreed as part of Detail design</Text><Text id="46368" page="33">IEC60870-5-101 and/or IEC60870-5-104 is the preferred standard for data exchange between TSO and ONS on the application layer of the communication link. Alternatively, the DNP3 protocol could be used. Signals sent from TSO to substation control system shall also be available in the SCADA system.</Text><Text id="46369" page="33">Telephone interconnection will be based on VoIp. All telephone communications initiated/received by TSO to be recorded. Retention time of recordings according to local regulations.</Text><Text id="46370" page="33">Handling of inter-trip signals and installation of Dynamic System Monitoring and Ancillary Service Monitoring Equipment must be provided in accordance with TSO requirements.</Text><Text id="46371" page="33">For data exchange of signals for monitoring and control between/to the ESI/WTG SCADA systems, the following communication interfaces may be used:</Text><Text id="46372" page="34">Doc. No. C256-EQ-J-SP-OOOO2 Rev. no. 01 Valid from: 12.12.2022</Text><Text id="46373" page="34">For data exchange of signals for monitoring and control to TSO, workshops need to be done with TSO. Also see &quot;Technical Conditions for the Connection to the Telecommunication Network of PSE S.A&quot;, l.e.:</Text><Text id="46375" page="34">• ARNE/ARST automatic voltage and reactive power control system - communication</Text><Text id="46376" page="34">• The communication between ONS and TSO should be established through a multiplexing system based on Optical Transport Network (layer 1), MPLS-TP with resiliency-robustness, traversal time, network latency, synchronization (time/phase) as needed by selected Tele-protection and SCADA protocols.</Text><Text id="46377" page="34">The primary revenue metering for the WPP will be at Slupsk Substation, delivered and installed by TSO, The back-up revenue metering for the WPP will be at Sfupsk Substation, delivered by contractor but installed by TSO. In order to mitigate the risk of change of ownership of Slupsk substation and export cable to PSE / there will be established 0,2 class (revenue grade) VT&apos;s &amp; CT&apos;s in 220 kV GIS bus bar at OSS. This is to safeguard always to have a correct fiscal metering independent of ownership boundaries.</Text><Text id="46378" page="34">At the Sfupsk, check metering shall be provided at the 400kV circuits at POI, for operational and verification purposes. Check metering shall use revenue grade current and voltage measurements, but these measurements may be shared with other functions, e.g., PQ metering. Check metering values shall be transmitted to TSO via a Remote Intelligence Gateway (RIG).</Text><Text id="46379" page="34">Permanently PQ measurement system, including PQ server to continuously monitor and report on the electrical system power quality parameters with the ability to provide remote reporting and feed this information to the SCADA system and PQ Server shall be installed at POI, at ONS 400 kV side of transformers, at 220kV ONS and 66kV OSS.</Text><Text id="46380" page="34">The PQ measurement system shall include necessary PQ meters, sensors, PQ server, network, and interfaces for connection of the PQ meters to PQ servers and to SCADA network, and with required interface to Company IMS server.</Text><Text id="46381" page="34">The PQ meters shall be type Class A meters as defined in IEC 61000-4-30, and the system shall be able to obtain an evaluate up to the 100 th harmonics data. Alternative standards for PQM metering shall be approved by Company.</Text><Text id="46382" page="34">Typical data shall be available, but not limit to:</Text><Text id="46383" page="35">PQ data shall be transferred via IEC-61850, IEC-60970-5-101/104, DNP3 or OPC-UA. Type of protocol to be agreed upon.</Text><Text id="46384" page="35">For locations other than 400kV, the ESI SCADA shall gather non-metering grade P and Q measurements from throughout the system, for HMI viewing of system power flow, and ability to approximate system losses. This includes P and Q to auxiliary systems, O&amp;M base, and both ends of the export cables. These P and Q values may be through P&amp;C relays using protection class instruments, i.e., standalone hardware is not required.</Text><Text id="46385" page="35">All PQM data to be stored for long time storage in the PQM server such as.</Text><Text id="46386" page="35">• Current, phase voltage, frequency, active/reactive power, import/export for all PQMs in system</Text><Text id="46388" page="35">• PQMs shall be installed for all voltages levels (66kV, 220kV onshore and 400kV ONS/TSO). Sampling interval, time-average and how high frequencies shall be according to grid code and Polish requirements and shall be grid compliant</Text><Text id="46389" page="35">• The data shall be shown in a clear and correct way where the planning levels from Engineering Recommendation G5/4 is shown in the figure as threshold values</Text><Text id="46390" page="35">• Flag in system, timestamp and save applicable data for long term storage when crossing thresholds</Text><Text id="46392" page="35">• If not derived from any of the other items here, it must be set up with thresholds, so the PQM record the data and store it during an event.</Text><Text id="46393" page="35">• The same values as TSO can see through the DSM onshore and offshore shall be included on the PQM server.</Text><Text id="46394" page="35">• As per TSO requirements, the same data shall be gathered and presented so it is easy to see if we are within or outside the bounds</Text><Text id="46395" page="35">• Flag in system, timestamp and save applicable data for long term storage when crossing thresholds</Text><Text id="46396" page="35">• Same as for DSM, as per TSO requirements</Text><Text id="46398" page="35">Required SW for monitoring and analysing of all required data shall be included/installed on the PQM server.</Text><Text id="46399" page="35">All available and collected data, measurements, real time data, raw data, historical and analysed data and stored in the PQM server shall be available and transferred to Company IMS server via agreed interface protocol</Text><Text id="46400" page="35">Web interface for remote access to the PQM server and PQM meters for retrieving of required data and data analysing shall be included and shall be based on Company’s secure access solution.</Text><Text id="46401" page="35">The PQM solution shall store all PQM data for a pre-defined time, at least 3 months, before transfer to Company’s long-term storage solution. No data shall be lost, redundant data shall be removed.</Text><Text id="46402" page="35">PQM measurements shall be transmitted to TSO via a RIG. Data shall also include: - gross MW and MVAR quantities at the generator terminals, - generator terminal voltage and current magnitudes and angles; - generator terminal frequency and frequency rate of change;</Text><Text id="46403" page="36">- generator field voltage and current, where available; - breaker status, if available.</Text><Text id="46404" page="36">Above noted data relating to WTG measurements shall be transmitted from WTG SCADA to ESI SCADA. ESI SCADA shall transmit data to TSO. There is not a separate data link from the WTG SCADA to TSO, ESI SCADA shall act as a pass-through / data concentrator.</Text><Text id="46405" page="36">Condition monitoring shall be included for equipment on ONS, OSS, cables and WTG with the following goals:</Text><Text id="46406" page="36">• Solutions to reduce maintenance need or requirement for facility visits (e.g., online monitoring rather than physical readings)</Text><Text id="46407" page="36">• Solutions to monitor asset condition by data collection and analysis to review asset health and future maintenance need</Text><Text id="46408" page="36">Condition monitoring solutions may perform “dual roles” by also being used in other applications. For example, a Distributed Temperature Sensing (DTS) system on export cable can be used for condition monitoring, but also used in conjunction with Dynamic cable Rating System (DRS) engine to perform dynamic power set point analysis and control. Also, Depth of Burial (DoB) Monitoring shall be included.</Text><Text id="46409" page="36">Required equipment, interfaces, protocols, signals, and instrumentation shall be included for transfer of required signals into SCADA and to Company IMS for Conditioning Based maintenance and monitoring and analysing of electrical, mechanical and instrument equipment to reduce lifetime cost and reduce time for offshore maintenance.</Text><Text id="46410" page="36">Equipment that shall have online condition monitoring system, including but not limited to are:</Text><Text id="46423" page="37">Doc. No. C256-EQ-J-SP-OOOO2 Rev. no. 01 Valid from: 12.12.2022</Text><Text id="46436" page="38">Doc. No. C256-EQ-J-SP-OOOO2 Rev. no. 01 Valid from: 12.12.2022</Text><Text id="46437" page="38">Required software/application for remote connection for remote support, maintenance, trouble shooting, diagnostics, software updates and fil transfer shall be included.</Text><Text id="46438" page="38">If TSO requires phasor measurement unit, this shall be included forthe400kV circuit.</Text><Text id="46439" page="38">Location and segregation shall be assessed for all IACS components for which a redundant design is chosen for reliability or availability reasons. This applies to cable routing, segregation of power feeds, physical location of components in panels, and so on. The main principle is to ensure a redundant system or function is not rendered inoperable because of a single failure.</Text><Text id="46440" page="38">All equipment shall be fully functional in the environmental conditions in which it is installed, ref is made to C218-ST-Z -SP-00001.</Text><Text id="46441" page="38">The requirements in this section shall apply to all IACS cabinets, including but not limited to server cabinets, Network panels. Field Termination Cabinets (FTCs) and RIO cabinets.</Text><Text id="46443" page="39">The IACS cabinets including panels for protection relays shall be segregated from the telecom panels. Cabinet layout, sizes and material shall be standardized.</Text><Text id="46444" page="39">All cabinets design shall consider passive thermal cooling techniques to maintain operating conditions, and all cabinets, except server cabinets should be designed to avoid need for cabinet cooling fans. Special considerations, such as perforation of cabinet/doors and enforced cooling, shall be taken for server cabinets.</Text><Text id="46445" page="39">All cabinets shall be equipped with door locks, and it shall be possible to connect lifting lugs easily.</Text><Text id="46446" page="39">For cabinets installed in rooms with computer raised access floor, cable entry shall be in the bottom of the cabinets.</Text><Text id="46447" page="39">Equipment inside cabinets shall be easily accessible with door(s) open, and cabinet doors shall self-lock in the fully opened position.</Text><Text id="46448" page="39">Cabinets shall have sufficient space to permit cables to be installed without going below the minimum bend radius given by the cable manufacturer. Special attention shall be paid to arrangements for fiber optical and network cables to ensure installation in line with manufacturers recommendation is achievable for all cables. These requirements are applicable also to future cables not installed at the time of handover to Company.</Text><Text id="46449" page="39">It shall be possible to isolate field signals from the SCADA units without disconnecting the cable cores from the terminals. This applies to all field signal terminations, including those in RIO units and field junction boxes. Field termination blocks shall be spring-loaded. It shall be possible to disconnect the termination part of the logic solvers without affecting the possibilities for application program testing. Reconnection facilities shall be pluggable. C&amp;P circuits (e.g., CT and PT terminations) shall incorporate the necessary test switches to perform the tests required in Grid Connection Agreement and Grid Codes. The required test switches shall be placed such that they allow relay and overall protection circuit testing, including operation of lockout relays, while preventing breaker failure schemes from operating and causing unnecessary breaker operations and/or the tripping of the Facility.</Text><Text id="46450" page="39">The field topology design shall be based on proven standard products in the offshore environment.</Text><Text id="46451" page="39">Advanced diagnostics with use of smart/intelligent field instruments/devices with field bus/HART protocol should be used to reduce maintenance and unscheduled stops in production. Field transmitters and final control elements should have configuration and self-diagnostic capabilities to enhance safety and support maintenance planning.</Text><Text id="46452" page="39">Industrial network for signal transfer based on fieldbus protocols may be used. This shall be in accordance with IEC 61158. The preferred choices are Profibus PA and Foundation Fieldbus.</Text><Text id="46453" page="39">Field transmitters and final control elements using Foundation Fieldbus or Profibus PA shall have documented interoperability, e.g., tick marked.</Text><Text id="46454" page="39">Analogue instruments shall be used instead of mechanical switches.</Text><Text id="46455" page="40">IEC 60529/ NEMA 250: Minimum degree of protection provided by local control panels, enclosures, instrument housing (i.e., transmitter housing) and junction boxes shall be as follows:</Text><Text id="46456" page="40">All equipment and materials shall as a minimum be flame retardant (fire retardant) and with preferably no halogen content (e.g., no fluoride, chloride, bromide, or iodide).</Text><Text id="46457" page="40">Equipment enclosures located outdoors in naturally ventilated areas and wash down areas shall be made of proven sea water resistant material. Alternatively, the enclosures shall be a protected by an approved coating system according to Appendix E material requirements.</Text><Text id="46458" page="40">Operating temperatures for 316 Stainless Steel shall be limited to 60 Deg C to limit the risk of chloride stress cracking in a saliferous environment.</Text><Text id="46459" page="40">Precautions against galvanic corrosion shall be made when considering the use of dissimilar materials and applying insulating layers where required.</Text><Text id="46460" page="40">Sensor materials shall be suitable for the application, with respect to process parameters, measurement uncertainty and repeatability.</Text><Text id="46461" page="40">The material requirements in Table 5 shall be applied wherever possible.</Text><Text id="46473" page="42">Winterization shall be accomplished by first considering indoor installation, then outdoor installation with suitable instruments and heated enclosure and heat tracing of instruments and process tubing.</Text><Text id="46474" page="42">When thermowell is used, the temperature transmitter should be mounted directly on top of the thermowell and in such a manner that the element can be installed and removed from the thermowell for maintenance, without disconnecting the cable.</Text><Text id="46475" page="42">Level gauges and transmitters shall be physically accessible, removable, and capable of isolation from the tank, without having to drain down inventory. This is to facilitate calibration and maintenance.</Text><Text id="46476" page="42">GIS shall be provided with intelligent circuit breaker monitoring solution based on the Supplier’s standard instruments cabled to the applicable controller. Functionality shall include monitoring and alarming of SF6 pressure, temperature, and leakage rate. The ESI SCADA shall monitor the SF6 status and provide alarms. No manual registration shall be necessary. The signal sent to SCADA shall be an analogue value, and not based on level switching, to be able to monitor and register small SF6 leakages over time or other operating point deviations.</Text><Text id="46477" page="42">The following spare capacity that shall be provided at the time of plant start-up.</Text><Text id="46478" page="42">• Spare space in panels/cabinets (for equipment and internal wiring): 15%</Text><Text id="46479" page="42">• Spare in installed multicore cables and terminations (shall be terminated at both ends) excluding Cat cables: 25%</Text><Text id="46480" page="42">• Spare space in main cable ladders/trays and Multi cable transits for (MCTs) for telecom and instrument cabling: 10%</Text><Text id="46481" page="42">• Spare space in equipment rooms for future panels/cabinets, 10% based on final number of panels/cabinets installed</Text><Text id="46482" page="42">All tagged instruments shall be delivered with a 316 Stainless Steel tag plate of minimum size 50mm x 20mm, with etched or embossed characters of minimum 5 mm high. This tag plate shall contain the tag number only. The plate shall either be affixed to the instrument with Stainless Steel screws or Stainless-Steel wire.</Text><Text id="46483" page="42">Field instrument nameplates shall as a minimum contain the following information:</Text><Text id="46484" page="42">• Explosion protection category and ingress protection rating (if applicable).</Text><Text id="46485" page="43">Electrical power shall be provided at 220 VDC and 230 VAC, 50 Hz.</Text><Text id="46486" page="43">All IACS cabinets, instrumentation, OWSs (Operator Workstations), EWSs (Engineering Workstations), plus SCADA backbone and Instrument Technical Network equipment shall remain operable following a main power failure. This shall be accomplished by installation of an Uninterruptable Power Supply (UPS).</Text><Text id="46487" page="43">All IACS panels shall be powered from two independent sources, one being via the UPS. All IACS equipment is to be served from one common UPS.</Text><Text id="46488" page="43">The IACS panels shall be equipped with redundant AC/DC power supplies in an N+1 arrangement, for provision of DC power to electronics equipment such as logic controllers, I/O cards, network components etc. Electrical isolators shall be installed such that replacement of an individual power supply unit shall be possible without interrupting normal operations.</Text><Text id="46489" page="43">A common alarm shall be provided for each system cabinet, to alert the operator of a power supply unit failure.</Text><Text id="46490" page="43">All IACS components shall be designed for continuous dual electrical power feed inputs. Where this proves impractical a changeover unit with dual power inputs shall be provided.</Text><Text id="46491" page="43">Galvanic isolation shall be used within the AC/DC power supplies to ensure that cable borne electrical interference does not adversely impact operation of either logic controllers, I/O cards, or field instruments.</Text><Text id="46492" page="43">The UPS shall interface to the ESI SCADA system via a serial data interface, for performance monitoring and power failure, as defined for Class 2 equipment. Trip signals shall be hardwired.</Text><Text id="46493" page="43">Required protection earth (PE), instrument earth (IE) and equipotential bonding shall be included. The IE shall be the common earth reference for instrumentation and telecommunication 0 V references and earthing of cable screen.</Text><Text id="46494" page="43">For OSS, see C256-EQ-Z-SP-00009 chapter 6.10 for details.</Text><Text id="46495" page="43">The maximum cycle time for the logic solver shall be 100ms. Individual applications may require shorter cycle times. Where required, selected logic solvers shall be able to handle applications with cycle times down to 10 ms.</Text><Text id="46496" page="43">HMI response time is how fast the system responds to user interaction, that is how fast the response is after the user gives information to the system or demands information from the system. The speed of computer response to user entries should be appropriate to the transaction involved. In general, the response should be faster for those transactions perceived by a user to be simple.</Text><Text id="46497" page="43">Required response time shall be defined such as:</Text><Text id="46498" page="44">The following are requirements for some key interactions and shall be satisfied for pages containing typically up to 1000 dynamic data points (See Note 1 below Table 2):</Text><Text id="46507" page="45">SCADA component types Lifetime requirements (Years) SCADA servers 10 SCADA operation station 10 Programable Logic Controllers 20 I/O cards 20 Logic solver power supply 20 SCADA network components 20 SCADA applications and tools Life cycle support through version upgrades.</Text><Text id="46508" page="45">Contractor shall provide lifecycle plan for delivered equipment.</Text><Text id="46509" page="45">Equipment shall as a minimum be certified for operation under the following conditions.</Text><Text id="46524" page="46">The FAT shall include HMI equipment for testing of all interfaces at the Contractor’s site. All communication interface signals and protocols shall be fully tested during the FAT.</Text><Text id="46525" page="46">All communications interface equipment shall be fully tested against telecom and relevant HMI operator station(s) for remote and local operation and monitoring.</Text><Text id="46526" page="46">All systems, servers and clients shall be tested to ensure that required antivirus and security OS patches are installed. In addition, testing shall ensure that OS and other software is correctly password protected and that all Universal Serial Bus ports are disabled. Verification of enabling for remote access shall also be performed.</Text><Text id="46527" page="46">Additional FAT testing to be performed shall include the following:</Text><Text id="46528" page="46">• Remote connection/Remote Desktop function for all equipment.</Text><Text id="46531" page="46">Test equipment for simulating all types of connected equipment and signals shall be supplied with the system. Test programs simulating values on equipment and signals shall also be supplied. These programs shall be equipped with an appropriate operator interface.</Text><Text id="46532" page="46">LCI documentation shall be delivered as described in LCI requirement in Appendix E documents.</Text><Text id="46533" page="48">CCR standard system for access and services to technical systems. The solution provides two factor login, user access management, and services like WSUS, antivirus, backup etc.</Text><Text id="46534" page="48">All control and monitoring are fully integrated in the SCADA, utilizing standard software and unit hardware Central Control Room (CCR) shall have the capability to control multiple farms from a single location, each with a predefined set of control, monitoring and communication services. CCR is located at the O&amp;M base.</Text><Text id="46535" page="49">Backup CCR The Control Room on the ONS shall serve as a backup for the CCR and the ONS Station control must therefore be designed with necessary facilities to accommodate this.</Text><Text id="46536" page="49">ESI Electrical System Infrastructure for offshore-onshore power transmission, including performing control and supervision of all functions and installations at Onshore Substation and Offshore Substation. Hereunder all infrastructure elements such as switchgears, transformers, back-up generators, reactive power components and auxiliaries.</Text><Text id="46537" page="49">GMS (Grid measurement system) performing the control of the WTGs power at the Grid Connection Point in the wind farm power network to achieve grid code compliance.</Text><Text id="46538" page="49">IACS Industrial control systems, including distributed control systems (DCSs), programmable logic controllers (PLCs), remote terminal units (RTUs), intelligent electronic devices, supervisory control, and data acquisition (SCADA), networked electronic sensing and control, and monitoring and diagnostic systems.</Text><Text id="46539" page="49">OSS SUS Offshore substation Plant Automation System. Automation, SCADA, safety, and condition monitoring system with interfaces to other systems.</Text><Text id="46540" page="49">SCADA Integrated Automation Control System is the overall integrated system for Electrical Power control system including ESI SCADA and WTG SCADA, Shutdown system, fire and gas detection system which included the basic control system, power distribution control limited to Control Class 1 systems. SCADA comprises the main HMI for the facility.</Text><Text id="46541" page="49">Logic Solver That portion of the IACS that performs one or more logic function(s). Examples are electronic systems, programmable electronic systems, pneumatic systems, hydraulic systems. Sensors and final elements are NOT part of the Logic Solver</Text><Text id="46542" page="49">Operator Workplace All the equipment that the operator has for his disposal to do the monitoring and control of his facility area. Consists of one or more operator stations.</Text><Text id="46543" page="49">Part of Old Text Part of New Text</Text><Text id="46548" page="16">Configuration Scenario A Normal operation B Loss of one 66kV WTG string/feeder C Loss of one 66 kV SWB D Loss of one OSS 220/66 kV transformer E Loss of one 220 kV export cable F Loss of one ONS 400/220 kV transformer G Loss of any reactive compensation or filter unit</Text><Text id="46549" page="34">Signal Description Analogue Units 1 Current IA Amps 2 Current IB Amps 3 Current IC Amps 4 Voltage VAB KV 5 Voltage VBC KV 6 Voltage VCA KV 7 Frequency Hz 8 Active Power MW 9 Reactive Power MVAr 10 Power Factor % 11 Voltage Unbalance: &amp;</Text><Text id="46550" page="37">Unit From SCADA to DTSParameter Current Export Cable 1 A Voltage Export Cable 1 kV</Text><Text id="46551" page="37">Parameter Unit Max Measured Temperature Cable 1 °C Max Calculated Temperature Cable 1 °C Max Actual Current Cable 1 A Max Measured Temperature Cable 2 °C Max Calculated Temperature Cable 2 °C Max Actual Current Cable 2 A Alarm on Export Cable 1 - Zone n 0/1 Alarm on Export Cable 2 - Zone n 0/1 System Status o/i System Fault o/i</Text><Text id="46552" page="38">Parameter Unit Max Measured Temperature Export Cable 1 °C Max Calculated Temperature Export Cable 1 °C A Max Actual Current Export Cable 1 Max Load Export Cable 1 MW Max Measured Temperature Export Cable 2 °C Max Calculated Temperature Export Cable 2 °C Max Actual Current Export Cable 2 A Max Load Export Cable 2 MW System Status 0/1 System Fault 0/1 Alarm on Export Cable 1 - Zone n 0/1 Alarm on Export Cable 2 - Zone n 0/1</Text><Text id="46553" page="38">Active Power Export Cable 1 MW MVAr Reactive Power Export Cable 1 Current Export Cable 2 A Voltage Export Cable 2 kV Active Power Export Cable 2 MW Reactive Power Export Cable 2 MVAr</Text><Text id="46554" page="40">Location IEC 60529 NEMA250 IP 56 4X Outdoor areas, naturally ventilated areas and wash down areas Dry indoor areas IP 20 12 Other areas 13/3S IP 44 (IP 54 for indoor areas with water mist)</Text><Text id="46555" page="41">Enclosures Atmosphere/ field environment Instrument housing Fire&amp;Gas detectors Protective shades Local Control Panels SSType AISI 316 SS or Fire retardant plastic (Note 1) Indoor and dry atmosphere or external non-saliferous atmosphere External and saliferous atmosphere</Text><Text id="46557" page="46">Abbreviation Explanation ASMU Ancillary Service Monitoring System AVPF Anti-virus protection functions BCA Bilateral Connection Agreement BMU Balancing Mechanism Unit BW Black and White C&amp;P Control and Protection CAP Critical Action Panel CB Circuit Breaker CCTV Closed Circuit Television CCR Central Control Room CMS Condition Monitoring System CoP Code of Practice</Text><Text id="46558" page="47">CPMS Condition and Performance Monitoring System CPU Central Processing Unit CT Current Transformer DMS Dynamic Monitoring System DMZ Demilitarized Zone DRS Dynamic Rating System DSM Dynamic System Monitoring DTS Distributed temperature sensing DTR Dynamic cable Thermal Rating EPC ESI Power Controller ESD Emergency Shutdown System ESI Electrical System Infrastructure ESON Electrical system design and onshore substation contractor EWS Engineering Work Station FAT Factory Acceptance Test FEED Front End Engineering and Design FDS Functional Design Specification FTC Field Termination Cabinets F&amp;G Fire and Gas GEP Grid Entry Point GIS Gas Insulated Switchgear GMS Grid Measurement System GPS Global positioning system HART Highway Addressable Remote Transducer protocol HMI Human Machine Interface HPPP High performance park pilot HVAC High Voltage Alternating Current HV High Voltage Industrial Automation and Control System. Note: Industrial control systems, including distributed control systems (DCSs), programmable logic controllers (PLCs), remote terminal units (RTUs), intelligent electronic devices, supervisory control, and data acquisition (SCADA), networked electronic sensing and control, and monitoring and diagnostic systems IEC International Electro Technical Commission IED Intelligent Electronic Device IMS Information Management System I/O Input/Output KVM Keyboard Video Mouse switch/extender LAN Local Area Network LCI Life Cycle Information LCU Local Control Unit LOGIC SOLVER Programmable Control Unit (PLC and similar devices) LV Low Voltage LVAC Low Voltage Alternating Current MCT Multi Cable Transit MPLS Multiprotocol Label Switching NG National Grid NTP Network Time Protocol TSO Polish Transmission System Operator ODBC Open Database Connectivity</Text><Text id="46559" page="48">OMS Operating Metering Summator ONS Onshore Sub Station OPC OLE for Process Control OS Operating System OSS Offshore Sub Station OTS Operational Tripping Scheme OWS Operator Workstation O&amp;M Operation and Maintenance PCC Plant Control Center PDCS Power Distribution Control System PFO Prepare for Operation PLC Programmable Logic Controller PQ Power Quality PQM Power Quality Monitoring RIO Remote Input/Output RSTP Rapid Spanning Tree Protocol RTTR Real Time Thermal Rating SCADA Supervisory Control and Data Acquisition SD Shutdown SNMP Simple Network Management Protocol SOV Service Operation Vessel SoW Scope of Work SVC Static VAr Compensator SW Soft Ware TCM Turbine Condition Monitoring TCP/IP Transmission Control Protocol/Internet Protocol TP Transition Piece TSO Polish Transmission System Operator UPS Uninterruptable Power Supply UTC Coordinated Universal Time VDU Video Display Unit VT Voltage Transformer WAN Wide Area Network WFMS Wind Farm Management System WFPC Wind Farm Power Controller WTC Wind Turbine Controller WTG Wind Turbine Generator</Text></Spec>