Flexibility and grid codes

Dutch Realtime Interface (RTI) for generation above 1 MW

Dutch RTI connections: customer endpoint duties, setpoints, lost-link behaviour and the boundary with plant control and site monitoring.

Above 1 MW, a Dutch system operator can cap the active power that a generating site delivers at its connection point, in real time, over a dedicated IEC 61850 link. The Realtime Interface (RTI) is the national specification for that link. The operator sends a maximum active power setpoint and the site sends back its measurements. When the link fails, the site falls to a safe-mode limit that the operator has set in advance.

The legal basis is Article 14(2) of the EU Requirements for Generators code, Regulation 2016/631. It requires a type B power-generating module to have an input port that reduces active power output on instruction, and it gives the system operator the right to specify further equipment for remote operation. The Dutch system operators started the RTI project through Netbeheer Nederland in 2020. Version 1.0 of the technical specification was released on 20 February 2024. Version 1.1, dated 1 July 2025 and published in July 2025, adds mutual Transport Layer Security (TLS).

Which connections need an RTI

The RTI targets type B power-generating modules. In the Netherlands, the Netcode elektriciteit sets type B at 1 MW to less than 50 MW. Type C starts at 50 MW, and type D starts at 60 MW or at a connection of 110 kV or higher. The specification is written so that it can also apply to larger connections and to connections with both generation and consumption. Netbeheer Nederland plans to extend it to smaller installations; its RTI page gives no threshold or date.

Each operator decides in its connection conditions whether the RTI applies. This article uses Enexis as the worked example. Enexis requires power control through RTI for every new generation connection above 1 MW. For an existing connection, the RTI is required only when the customer applies to increase a generation connection above 1 MW. Liander and Stedin publish their own RTI pages, which are linked from the Netbeheer Nederland RTI page. When TenneT needs to restrict a site in a distribution grid, it asks that distribution operator's control centre, and the distribution operator sends the setpoint over its own RTI.

The RTI exists because of congestion. Since November 2022, the Netcode elektriciteit has let operators apply capacity management actively, and since April 2024 the framework requires operators to connect generation up to 150% of rated network capacity. The RTI is the operational tool that makes this safe. It carries no market data: prices, volumes, GOPACS bids and congestion service contracts are out of its scope.

How the RTI works

The operator installs its endpoint in the medium-voltage compartment that it already uses at the customer's substation, or in another secure area that only the operator can access. The customer provides that space and a power supply. The demarcation point is the RJ-45 port on the operator's endpoint. Everything after that port is the customer's responsibility, including the cable.

The cable is a dedicated link with exactly two hosts. The customer end must terminate on a network interface of the customer endpoint itself, not on a switch. Fibre-to-Ethernet converters are allowed only if they serve this link and nothing else. The operator supplies the IP address, subnet and gateway for the customer endpoint.

The protocol is IEC 61850 MMS, with the data model from IEC 61850-7-4 Ed. 2 and IEC 61850-7-420 Ed. 2. The operator's endpoint is the client and connects to the customer endpoint, which is the server. The specification, the Protocol Implementation Document and the SCL file together define the interface, and both endpoints are built from that SCL file. The customer endpoint can be a park controller, an energy management system or a separate device, if it meets the specification.

Logical nodeWhat it carriesDirection
DWMXMaximum active power setpoint as a percentage of maximum capacity (WMaxSptPct) or in MW (WMaxSpt); reason code (SptReas); safe-mode setpoint (WMaxSetPct or WMaxSet); safe-mode time-out (WMaxFto)Operator to site
MMXUTotal P (TotW) in MW, total Q (TotVAr) in MVAr, three phase currents, phase-neutral and phase-phase voltages in kV, and 15-minute average, maximum and minimum of TotWSite to operator
DGENOperating state of the site (DEROpSt)Site to operator
LLN0, LPHDRTI version (configRev, for example "1.1.0"), endpoint firmware (swRev), device healthSite to operator

Version 1.1 controls active power only. It has no reactive power or voltage setpoint. A positive setpoint limits generation and a negative setpoint limits consumption; percentage setpoints apply to generation only. Only one setpoint is active at a time. The percentage is a percentage of the accumulated maximum capacity in the site's Power Generating Module Document (PGMD) forms, not of inverter nameplate.

Every setpoint needs a reason code, and the rules are strict. The operator sends the reason first, as a separate message. The endpoint accepts a setpoint only if it arrives within 10 seconds of the reason. A reason applies to one setpoint only. If the reason is frequency stability, the site must reach the limit by reducing generation. For every other reason, the site may also increase consumption to reduce net export.

Timing and accuracy

RequirementValue in v1.1
Acknowledgement between the endpointsLess than 4 seconds
Time for the plant to reach the setpointSet by the application framework for the use case, not by the specification
Measurement update interval5 seconds or faster
Measurement accuracy at the connection pointClass 1, as described in IEC 61869
Measurement voltage levelThe same level as the utility meters, so medium voltage if the billing meters are on medium voltage
ClockWithin 10 seconds of UTC
Link restored after power restoration or an endpoint restartLess than 3 minutes
Link availability99.00% over at least 6 months (IEC 60870-4 class A1)

The measurements can come from a meter behind the connection point, but they must still meet class 1 referred to the connection point. Each value carries a quality flag that is either good or invalid. If the endpoint loses its measurement source, it must set the quality to invalid.

Safe mode and start-up

The customer endpoint supervises the IEC 61850 connection. When the connection drops, the endpoint starts the WMaxFto timer. If the connection returns before the time-out, nothing changes. If the time-out expires, the endpoint enters safe operating mode and the site must hold the safe-mode setpoint until the operator sends a new, valid reason and setpoint. The operator sets both the safe-mode value and the time-out, and it can read them back.

At first energisation, with no stored safe-mode settings, the site may not deliver power until three things are true: the IEC 61850 connection is up, a valid reason and setpoint have arrived, and the safe-mode setpoint and time-out have arrived. This affects commissioning. A new site cannot export until the operator's endpoint is live and configured.

After a restart with stored settings, for example after an outage or a firmware update, the endpoint enters reboot mode and holds the safe-mode setpoint until the operator sends a new reason and setpoint. A planned firmware update therefore limits the site to the safe-mode value for a short period.

When the link returns, the endpoint must push buffered 15-minute average, maximum and minimum values of TotW for up to the last 8 hours, and the changes in its operating state during that time. The endpoint reports state 6 when every generating unit can follow a setpoint and state 98 when one or more units cannot, for example when one inverter of many is offline.

What the customer must integrate

The endpoint receives the limit. The plant must act on it. Define these items for each installation.

  1. The controller that holds the connection point at the limit: a power plant controller, the inverter fleet's controller or a battery management system.
  2. The signal path from the endpoint to that controller, and the plant's response time against the application framework that applies to the site.
  3. The measurement source for MMXU, its voltage level and its accuracy class.
  4. The safe-mode behaviour, and a test that shows the plant follows it after the WMaxFto time-out and after a reboot.
  5. How the controller reports partial unavailability, so that the endpoint can send state 98.
  6. The version of every component in the chain. The specification requires a retest after a change that affects RTI behaviour, such as a firmware or software update.

Worked example: 5 MW PV with a battery

A PV site has 5.0 MW of maximum capacity in its PGMD forms, a 1 MW battery and 0.4 MW of auxiliary and process load behind the connection point.

The operator sends a reason code for congestion, then, within 10 seconds, WMaxSptPct = 40%. The endpoint accepts the pair and sets WMaxSpt to 2.0 MW, so that the percentage and absolute values agree. The park controller must now hold TotW at the connection point at or below 2.0 MW. With the 0.4 MW load, the PV can still generate 2.4 MW. If the battery charges at 1 MW, the PV can generate 3.4 MW. Both are allowed for a congestion reason. For a frequency stability reason, the controller must reach the limit by reducing generation, and it may not start charging the battery to do so.

Two common integration errors show up here. First, if the controller sends 40% to every inverter instead of closing the loop on the connection point, the result depends on the inverter base and site load. With 5.5 MW of inverter AC nameplate, 40% per inverter is 2.2 MW of generation. At the stated 0.4 MW load, net export is 1.8 MW, below the 2.0 MW limit; if that load falls to zero while generation remains at 2.2 MW, export breaches the limit by 0.2 MW. Second, if the controller ignores the site load, it curtails 0.4 MW more than it must.

Then the RTI link fails. Assume the operator has set WMaxFto to 60 seconds and WMaxSetPct to 30%. For the first 60 seconds the endpoint stays in operational mode and the 2.0 MW limit still applies. After the time-out, the site must drop to 1.5 MW and hold that until the operator sends a new reason and setpoint. The operator decides both values; these are for illustration only.

Security and approval

Version 1.1 protects the MMS session with mutual TLS. The endpoint must support TLS 1.2 as described in IEC 62351-3:2023 and IEC 62351-4. A subsequent Netbeheer Nederland add-on removed the original NULL-cipher requirement and postponed mandatory TLS 1.3 compliance until one year after publication of the IEC 62351-100-3 conformance document named in that add-on. Confirm the effective TLS 1.3 date and permitted cipher suites with the operator before commissioning. Only the TLS version and cipher suites agreed with the operator may be enabled. The endpoint generates its private key internally. The key never leaves the endpoint, and the endpoint must refuse to import one. The customer sends its endpoint certificate to the operator, which pins it on the operator's endpoint. The operator gives the customer its root certificate for validation. The operator sets the certificate validity, and the specification advises no more than 15 years. Certificate events must be exportable in RFC 5424 syslog format.

The contract adds site obligations. The customer endpoint may not be reachable directly from the Internet; remote access goes through a VPN or a jump server, and the solution should require multi-factor authentication. Default passwords must be replaced on the endpoint and on every device in its local network. The customer must patch at least once a year, and the administrator needs basic security training.

A new endpoint product needs a conformance test against the Protocol Implementation Document and IEC 62351 before its first use. DNV runs the laboratory tests. Netbeheer Nederland publishes the list of operator and customer endpoints that have passed, per specification version, on its RTI page. The operator can also require a commissioning test on site.

RTI and site monitoring

The RTI gives the operator 5-second totals at the connection point, and 15-minute buffered values after an outage. It gives the owner nothing. To check that the plant followed a limit, and to quantify generation lost during it, the owner needs its own record: the limit in force, the output of each inverter and battery, the site load and the export at the connection point, all on one clock. Curtailed energy is the difference between available and delivered power, so also record an availability signal, such as the inverters' available active power, if the plant controller publishes it.

ZEM electricity monitors can measure the low-voltage side: inverter outputs, battery feeders and site loads. At a site metered on medium voltage, they do not replace the RTI measurement source, which must measure at the utility meter's voltage level. Edge on the Gateway stores the data locally and sends it to the owner's platform. If the park controller publishes its active limit and operating state over Modbus TCP, Edge can read them as a client on the controller's site network interface. Edge never connects to the RTI cable and does not take part in the control path.

Project checklist

  • Confirm with the system operator that the connection is in scope, which specification version applies and which application framework sets the response time.
  • Choose an endpoint that has passed conformance testing for that version, and agree who integrates it with the plant controls.
  • Provide the space, power supply and dedicated cable for the operator's endpoint, and terminate the cable on the customer endpoint's own network interface.
  • Close the control loop on the measured export at the connection point, not on per-inverter percentages.
  • Test a setpoint step at commissioning: record the time the reason and setpoint arrive, the time the plant settles, and the export at the connection point against the setpoint.
  • Test safe mode: disconnect the link, confirm the plant falls to the safe-mode setpoint after WMaxFto, and confirm the 8-hour buffered values arrive when the link returns.
  • Record the firmware and software version of each component, and retest after a change that affects RTI behaviour.
  • Keep an independent record of limits, plant output and connection point export for the owner.

Common questions

Does the RTI replace the plant controller?

No. The customer endpoint receives the operator's active power limit. The plant controller, the inverters or the battery management system apply it. The endpoint can run inside the park controller, but the control loop that holds the connection point at the limit is still the customer's responsibility.

Is RTI the same as a monitoring feed?

No. The site reports measurements at the connection point every 5 seconds or faster, but the purpose is control: the operator sends a limit on active power and the installation applies it. The owner's own record of plant behaviour is a separate system and must not share the RTI cable.