C&I ESS Design Freeze Checklist: BOM, Firmware and Change Approval

Oct.08.26

A custom commercial and industrial energy storage order can change after the purchase order is signed. A cooling unit becomes unavailable, an EMS interface is revised, or a site engineer requests a different cable entry. The important question is not simply whether the replacement works. It is whether the delivered system still matches the approved requirements, test evidence and handover documents.

A C&I ESS design freeze establishes a controlled project baseline: the agreed hardware, drawings, software, settings and acceptance criteria. Changes remain possible, but they need traceable review before implementation. This checklist helps importers, EPC contractors and distributors define that process without treating a supplier's general product brochure as a project-specific engineering release.

1. Define what the design freeze actually approves

Design freeze is not a promise that no engineering question will arise. It is an agreement about which configuration can enter purchasing, manufacture or testing, and which unresolved items prevent the next release. Record the project identifier, baseline revision, approval date, included documents and authorized signatories.

Separate confirmed requirements from assumptions. Grid voltage, frequency, usable energy definition, operating modes, ambient conditions, site interfaces and contractual acceptance criteria should not remain scattered across quotations and email attachments. If site information is incomplete, identify the open item, its owner, its deadline and the activities it blocks.

Begin with the requirements established in the custom solar energy storage configuration checklist. This article addresses the next step: controlling departures from the approved configuration. General configuration-management principles are described in NASA's configuration management guidance; it is a useful process reference, not an ESS certification requirement.

2. Build one baseline register for hardware and documents

Use a single register that points to controlled files rather than collecting several folders all called “final.” Each item needs an identifier, revision, status, owner and approval reference. State whether an approval authorizes procurement, assembly, factory testing or shipment: these are different gates.

The following register is a starting point. Add project-specific items where the scope includes a transformer, switchgear, PV inverter, generator interface or site controller.

Controlled item Freeze evidence Change-review question
Battery and protection BOM Approved part numbers, quantities and permitted alternatives Does the replacement alter electrical limits, protection coordination or supporting evidence?
PCS and cooling equipment Model, ratings, interfaces and relevant options Are thermal duty, controls, auxiliary power and maintenance needs still compatible?
Drawings and site interfaces Released single-line diagram, layout and terminal schedules Must installation drawings or site equipment be revised?
BMS, PCS and EMS software Version matrix, approved parameter export and interface revision Are compatibility checks and regression tests required?
Safety and test plan Applicable evidence register, FAT procedures and acceptance limits Does the change affect evidence coverage or agreed testing?
Release and handover pack As-built document index and equipment identity records Can the owner identify the actual delivered configuration?

Link the register to the manufacturing quality plan and hold points. The quality plan controls inspection activities; the baseline register identifies the configuration those inspections must assess.

3. Name the approval authority before a change occurs

Do not rely on “approved by the customer” without naming the authorized role. The buyer's purchasing representative may approve a price adjustment but not a protection-setting change. A supplier's production planner may propose an alternative part but should not be assumed to approve its engineering compatibility.

Separate technical approval from commercial authorization

Define who proposes the change, who evaluates it, who authorizes implementation and who verifies completion. Depending on the contract, reviewers may include the supplier's engineering team, EPC electrical engineer, controls integrator, owner and a relevant assessment body. Buyer sign-off does not replace competent engineering review or an authority's approval where required.

Use impact-based approval levels. A corrected document typo may need document-control review. A change to a safety function, battery model, power rating or grid interface needs broader assessment. Establish escalation criteria and response times before procurement starts. Silence, a read receipt or a verbal conversation should not count as approval unless the contract explicitly defines a valid authorization method.

4. Control BOM substitutions by part number, not resemblance

“Equivalent component” is a proposal, not a conclusion. Request the original and proposed manufacturer, exact part number, revision, relevant ratings, dimensions and interface details. Compare the characteristics that matter to the system, including environmental suitability, electrical protection, control behavior, service access and spare-part availability.

A cooling-module substitution, for example, may change auxiliary consumption, heat-rejection behavior, alarms, noise or maintenance procedures even when it fits the same opening. A fuse, contactor or sensor replacement can affect coordination, switching behavior or the measurement chain. The necessary review depends on the actual design; this checklist does not approve any specific substitution.

AI illustration of an engineer checking the identity of a cooling module beside a closed energy storage cabinet
AI-generated component-review illustration; a replacement still needs project-specific compatibility and approval checks.

Identify which serial numbers, cabinets or production lots receive the change. Keep the original configuration visible in the revision history. If a proposed part is rejected, ensure purchasing and production cannot mistake the proposal for the released BOM. Record approved alternatives explicitly, including any conditions that limit their use.

5. Review physical and electrical interfaces together

A component-level change can become a site-level problem. Recheck cable entries, terminal locations, protective earthing connections, conductor requirements, lifting arrangements, enclosure dimensions, service clearances and auxiliary supplies wherever the change could affect them. Ask the responsible engineer to assess fault levels and protection coordination when relevant.

Issue an interface change notice with marked-up drawings, not just a new datasheet. The EPC team needs to know whether foundations, cable trays, switchgear, communications equipment or installation sequencing are affected. A drawing that looks almost identical can still move a connection to an inaccessible location.

For a cabinet project, compare the approved scope against the C&I energy storage product information and the project-specific documents supplied with the order. Product-page specifications are a starting point; they are not a substitute for the released site-interface package.

6. Freeze firmware, control settings and the compatibility matrix

Record BMS, PCS, EMS and gateway software identifiers separately. Include the relevant hardware revision and protocol or point-list revision, because a version number alone may not identify a compatible system. Define the approved parameter set and distinguish factory defaults from project-specific settings.

Store a controlled settings export where supported, plus its date and file identifier or checksum. Include limits, alarms, operating modes, communications mappings and relevant access permissions. Keep passwords and private keys out of general handover folders; provide them through an agreed secure channel.

Any update after testing needs a change record. State the reason, compatibility evidence, affected functions, regression-test plan and recovery method. A rollback may be unavailable or unsafe for some versions, so verify the supplier-supported procedure before relying on it. Use the EMS integration checklist for detailed point-list and control testing; the design-freeze register should reference its approved revision rather than duplicate it.

7. Require a complete engineering change request

Give each engineering change request a unique identifier. Describe the current baseline, proposed revision, reason for change and affected equipment. Attach evidence rather than asking reviewers to accept statements such as “no impact” without explanation. Identify whether the request applies to one order or future orders as well.

  • Technical impact: ratings, interfaces, operating limits, safety functions and maintainability.
  • Evidence impact: drawings, instructions, assessment scope and test records requiring review.
  • Commercial impact: price, rework, spares, warranty terms and delivery milestones.
  • Implementation plan: affected serial numbers, work instructions, responsibility and verification.

Track each request through proposed, reviewed, approved or rejected, implemented and verified states. “Approved” does not mean the factory has installed it; “installed” does not mean it passed the required checks. Make the state visible to purchasing, manufacturing and the buyer so production cannot move ahead using an unapproved revision.

8. Assess safety and supporting evidence before release

Ask which existing reports, declarations or installation requirements cover the revised configuration. A report for a similar model does not automatically cover a changed battery, enclosure, control function or suppression arrangement. Obtain a documented applicability assessment from the responsible supplier, engineer or assessment body where needed.

NFPA 855 addresses minimum requirements for mitigating hazards associated with stationary energy storage installations. Its applicability, adopted edition and local approval requirements depend on the project jurisdiction. Referencing it does not prove that equipment is certified, that a modification is acceptable or that the site is approved.

Use a change-impact review to identify questions for the qualified project team. Fire detection, ventilation, shutdown logic, separation distances and emergency procedures may need reconsideration when relevant. Coordinate the review with the BESS fire-safety document checklist. Do not close the change solely because the revised part has its own certificate.

9. Agree the retest scope and acceptance evidence

Testing should follow the change's impact, not an automatic rule that every change requires either a complete FAT or no testing. Ask engineering to identify affected requirements, functions and interfaces, then specify the checks and acceptance limits. Record why previously completed tests remain applicable where they are retained.

A communications revision may require point mapping, command response, alarm and loss-of-communication checks. A cooling change may require verification of thermal behavior and relevant alarms. A protection-related change can require a broader engineer-defined assessment. Test methods and safe conditions must be selected by qualified personnel; this guide is not an energization procedure.

Update the test document revision and identify the actual configuration under test. Keep failed results and corrective actions traceable instead of replacing them with an unexplained “pass.” The BESS quality assessment checklist provides the broader evidence framework, while the change record explains why a particular test was repeated.

10. Resolve cost, schedule and deviation terms explicitly

Technical approval should not conceal a delivery or commercial dispute. Record the agreed cost adjustment, who pays for additional tests, revised procurement dates and effects on shipment or site commissioning. Include impacts on spare parts, training and warranty support where the change introduces them.

If the buyer accepts a limited deviation, define its scope and expiry: one identified cabinet, one batch or a specified operating condition. Do not treat a one-time concession as a permanent design change. Where safety or mandatory compliance is affected, a commercial concession cannot replace the necessary technical or regulatory acceptance.

For an urgent shortage, ask for a written interim plan showing what work can continue and what remains on hold. This makes schedule recovery visible without quietly converting an unavailable original component into an approved substitute. The exporter and wholesaler buyer checklist can help organize the related delivery and warranty responsibilities.

11. Release the as-built configuration and close the change log

Before shipment, reconcile the released design with what was actually built. The as-built package should identify relevant BOM and drawing revisions, equipment serial numbers, software versions, parameter records, completed test references and approved deviations. A file index helps the owner find the right document without opening every attachment.

AI illustration of two engineers reviewing configuration and test records beside commercial energy storage cabinets
AI-generated illustration of a configuration release review, not an actual FAT result or project acceptance record.

Confirm that approved changes were implemented on the intended units and that rejected proposals were excluded. Keep superseded documents clearly marked and preserve the audit trail. Any remaining open item needs an owner and an agreed release decision; avoid using shipment as evidence that an engineering issue was closed.

Carry the baseline into the commissioning and warranty handover checklist. Later site updates should create a new traceable revision rather than erase the factory record. When discussing a custom system with SolarStorageHub, provide the site requirements and request a project-specific baseline, change-approval route and document deliverable list before placing the order.

12. Frequently asked questions

Does design freeze mean no further changes are allowed?

No. Design freeze establishes an approved baseline. Later changes need an identified request, impact review, authorized approval, implementation record and verification before the revised configuration is released.

Can an equivalent component be substituted without buyer approval?

Only if the contract and approved baseline explicitly permit that alternative and its conditions are met. Otherwise, the supplier should submit the proposed substitution for the required technical and commercial approvals before implementation.

Does a firmware update always require a complete FAT?

Not necessarily. Qualified reviewers should define testing from the affected functions and risks. Record the software change, compatibility assessment, required regression tests and reasons for retaining any earlier test evidence.

What should a buyer receive with the final configuration?

Request an as-built document index, relevant BOM and drawing revisions, equipment identities, software and parameter records, test references, approved deviations and the closed change log, with any remaining obligations clearly assigned.


Related SolarStorageHub Resources

If you are turning this article into a buying decision, compare the relevant product families and send your inverter model, target capacity, installation country, and quantity plan for confirmation.

Start a new green zero-carbon life today

For additional specifications, please get in touch with us. We are committed to providing comprehensive service