A battery energy storage system (BESS) told to discharge 100 kW can deliver 60 kW and still report success, because the request passed through three control layers and each owns different decisions. An integration that writes to the wrong layer, or reads the wrong value, reports power the battery never delivered. Here BMS means battery management system, not building management system. This guide is part of the flexibility series.
Three layers
| Layer | Job | Owns |
|---|---|---|
| BMS | Measure cell voltages, currents and temperatures; estimate state of charge (SoC) and state of health (SoH); protect the cells | Charge and discharge current limits, protective trips, the DC contactors |
| PCS | Convert DC to AC and back; follow active and reactive power set points; meet the grid connection rules | Actual AC power, ramp rates, grid protection and ride-through settings |
| EMS | Choose when to charge and discharge: tariffs, peak shaving, grid services | The active power set point, the schedule, the SoC reserve |
One cabinet may hold all three. A utility-scale site may have a BMS per rack, several PCS units and a site EMS or power plant controller from a third supplier. That top layer usually also enforces the import and export limits at the connection point. An aggregator or virtual power plant sends its requests to the top layer, not to the PCS or the BMS.
Each layer answers to its own standards. IEC 62619:2022 sets the safety requirements for industrial lithium cells and batteries, including electrical energy storage systems. It covers the battery system and its management, not only the cells, and its second edition added requirements for battery system design and EMC. The PCS must meet the connection rules for generating plant: EN 50549-1 (low voltage) and EN 50549-2 (medium voltage) in Europe, which include storage, and the network operator's own conditions, such as EREC G99 in Great Britain. Those rules fix the protection settings, the frequency and voltage ride-through and the reactive power behaviour. The EMS works inside them.
Limits, requests and delivered power
The BMS reports how much current the cells can take or give now. The PCS, or the EMS above it, clamps the set point to that limit. If the EMS asks for 100 kW of discharge and the BMS allows 60 kW at the present SoC and cell temperature, the battery delivers 60 kW or less.
The allowed power changes during operation. It falls when cell temperature leaves the manufacturer's window, and it tapers as SoC approaches the lower limit on discharge or the upper limit on charge. Read it at least as often as you write the set point. A limit read five minutes ago does not tell you what the battery can deliver now.
Keep three values apart:
| Value | Example |
|---|---|
| Requested power | 100 kW discharge |
| Allowed power now | 60 kW, from the BMS limits |
| Actual power | 58 kW, measured at the PCS or a meter |
Report the actual power as the delivery. A dashboard that shows the request as the delivery passes every internal test, then fails the first settlement check against the meter data.
Data to read
| Data | Why |
|---|---|
| Operating state and alarms | Whether the battery is available at all |
| SoC, and the minimum and maximum SoC | How much energy is left above the floor |
| SoH and the energy rating | How much energy a full battery now holds |
| Maximum charge and discharge power or current allowed now | What can be offered |
| Actual AC power, active and reactive | What is being delivered |
| Set point in force, and its source | Which system is in control |
| Timestamp and quality of each value | Whether the data is current |
Some products publish these values through the SunSpec Modbus models. Model 802 (battery base) carries SoC, SoH, the nameplate SoCMin and SoCMax, and the instantaneous DC limits AChaMax and ADisChaMax. Model 713 (DER storage capacity) carries the energy rating WHRtg and the energy available WHAvail. Model 701 (DER AC measurement) carries the AC active power W, and model 704 (DER AC controls) carries the set point WSet. Many commercial and utility BESS products use a proprietary Modbus map or IEC 61850 instead. Get the supplier's register map before you design the integration.
SunSpec stores most values as an integer and a separate scale factor, and the value is the register multiplied by 10 to the power of the scale factor. A W register of 5800 with W_SF of 1 is 58 kW. Ignore the scale factor and the dashboard shows 5.8 kW. A value exactly 10, 100 or 1,000 times too large or too small is almost always a scale factor error.
Record the units and the sign convention of every value. Model 701 reports active power as positive for generation, so discharge is positive. A meter on the battery feeder that counts import as positive shows the same discharge as negative. A sign mixed up in one mapping turns a discharge into a charge on the dashboard. At commissioning, run a small known discharge, such as 20 kW, and check that the PCS, the meter and the dashboard all move the way you expect.
Power, energy and runtime
Do not take usable energy as SoC multiplied by the nameplate. Take a 500 kW, 1 MWh battery at 30% SoC, with SoC reported against the energy rating and a minimum SoC of 10%:
| Step | Energy |
|---|---|
| Nameplate multiplied by SoC | 300 kWh |
| Less the energy below the 10% minimum SoC | 200 kWh DC |
| Less about 8% conversion loss on discharge | about 184 kWh AC |
| Runtime at 500 kW | about 22 minutes |
The 8% loss follows from the 85% round-trip efficiency that the Annual Technology Baseline (ATB) from the US National Laboratory of the Rockies, formerly NREL, assumes for utility-scale lithium-ion storage, which is about 92% each way. The headline figures suggest 36 minutes; the battery gives about 22, and often less. The BMS may taper discharge power near the SoC floor, so the last minutes run below 500 kW. The HVAC and other auxiliary loads draw from the same connection, so the site meter sees less export than the PCS reports, and the gap is largest on hot days. Any reserve that the EMS holds for another service also comes off the top.
Check how the product defines SoC. Model 802 expresses SoC as a percentage of the energy rating. Other BMSs report SoC across the usable window, where 0% is already the floor. The same reading of 30% gives 300 kWh on one and 200 kWh on the other.
SoC is an estimate. Lithium iron phosphate (LFP) cells have a flat voltage curve across most of their range, so the BMS counts charge in and out, and the error grows until the BMS sees a full charge and recalibrates. A battery that sits around 50% for weeks, for example on a frequency response service, can report an SoC several percentage points wrong. SoH reduces the energy as well: at 90% SoH, a 1 MWh battery holds about 900 kWh when full.
Authority, expiry and failure
Name the one system that owns the active power set point at any time. Normally that is the site EMS. During a grid service event it may be the aggregator's request, passed through the EMS, or a local frequency response controller. All other systems read and do not write. Publish the current owner as a status value, so that a manual or local override shows as an override, not as a failed response.
Every external set point needs an expiry. SunSpec model 704 provides one: the writer sets a reversion value (WSetRvrt) and a reversion time in seconds (WSetRvrtTms). When the reversion time runs out without a new write, the PCS applies the reversion value. Products without SunSpec usually have a heartbeat or watchdog register that does the same job. Set the reversion time to a few write intervals. With a set point written every 10 s, a reversion time of 30 to 60 s survives one lost write without holding a stale command for long. Also give each command a sequence number or timestamp, so that a request delayed in a queue is dropped, not executed. A discharge request that arrives ten minutes late is a new, unrequested discharge.
Decide the link-failure behaviour at design time. For most sites the safe default is to revert to 0 kW, ramping at the PCS's configured rate. Holding the last set point is the risky choice. A battery that holds a 500 kW discharge with no supervisor runs down to its SoC floor, and if the site load falls it can export past the connection limit unless the site controller enforces that limit separately. A return to a local schedule works only if the schedule and the service contract agree on what the battery is committed to.
After a restart of any layer, no external set point should be in force until the owner writes a new one. Check whether the PCS stores the last set point in non-volatile memory and applies it at power-up.
Test each case under the equipment owner's approved test plan. For the link failure case, start a 100 kW discharge, disconnect the network cable between the EMS and the PCS, and measure at the meter the time until the power reaches 0 kW. The test passes if that time is no longer than the reversion time plus the ramp time. The local control guide gives a structure for the full matrix.
Modbus TCP has no authentication. Any host that can reach the PCS on port 502 can write a set point. Put the control network on its own segment, apart from the office and internet-facing networks, and let only the owning system reach the write port, as NIST SP 800-82 describes for operational technology networks.
Evidence for each command
For each command, record the identifier, the source, the request, the acceptance, the allowed power at the time, the actual power, the meter that measured it and the configuration version. For the example above, one record could read:
2026-09-18T14:02:10Z cmd=4812 src=EMS req=100kW discharge accepted=yes allowed=60kW actual=58kW meter=battery-feeder cfg=v14A successful write proves only that the command arrived. The BESS command verification guide describes the full sequence.
Batteries with EpiSensor
The ZDR-22 demand response controller meters the supply, follows grid frequency and sends a changing power set point to a battery or UPS over Modbus. It reacts to a frequency event within 100 ms, without waiting for a remote platform. That makes it a set point writer, so give it its own row in the authority matrix and agree with the EMS supplier which one wins during an event. A Gateway running Edge reads the battery's own Modbus data alongside the site meters, keeps the history on site and forwards it over MQTTS or HTTPS to the platform that the service uses. Confirm the register map of the battery's EMS or PCS before commissioning, and run the link failure test above.
Common questions
What is the difference between a BMS and an EMS in a battery system?
The battery management system (BMS) monitors the cells and protects them: it measures voltage, current and temperature, estimates the state of charge and sets the limits for charging and discharging. The energy management system (EMS) decides how to use the battery, for example to shave peaks or answer a grid service, and sends power requests within those limits.
What is a PCS in a BESS?
The power conversion system: the bidirectional inverter that converts the battery's DC to AC to discharge, and AC to DC to charge. It takes active and reactive power set points from the EMS, applies the grid connection protection settings and reports the actual power.
What data should I read from a battery system?
Operating state, alarms, state of charge, the maximum charge and discharge power allowed now, the actual AC power, and the set point in force, each with a timestamp. Record the sign convention of each value.