Commissioning and acceptance
Collect acceptance evidence from the installed system. Include normal operation, denied requests, degraded conditions and recovery after failures.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
Research and static guidance only; product and deployment specific behaviour requires controlled environment validation and authoritative product evidence.
On this page
Overview#
Commissioning proves that the installed, configured and integrated system matches the versioned design and behaves predictably in normal, denied, degraded and recovery scenarios.
Commissioning authority comes from the system owner and applicable local authority. High impact and regulated functions also require manufacturer procedures, qualified personnel, local approvals, and an isolated or controlled acceptance window.
Commissioning sequence#
- Verify asset identity, provenance, hardware, firmware, licences and physical installation records.
- Establish isolated ownership and remove defaults using the secure onboarding state model.
- Apply and record approved protocol, network, identity, certificate, time, logging, storage and update baselines.
- Confirm only designed flows and roles are enabled.
- Validate each integration with synthetic or non actuating cases first.
- Validate authorisation denials, malformed input handling, timeouts, retries, duplicate/replay behaviour and safe failure.
- Validate failover, offline operation, queue/storage limits, reconnection and state reconciliation.
- Validate monitoring, audit correlation, backup and recovery.
- Resolve deviations or document explicit accepted limitations.
- Capture the system owner approved acceptance record and handover material.
Protocol acceptance record#
For every interface record client/server/device roles, standard/API revision, optional features, secure mode, certificate identities, accounts/roles, addresses/ports, discovery, timeouts, retries, event ordering, scale, error cases, evidence location, exact validation endpoints, and observed environment result.
Safety separation#
Validate software integration without bypassing independent hardware interlocks or certified local control. Don't generate dispatchable monitoring events, unlock occupied site doors, move gates/elevators, alter fire interfaces, silence alarms, or energise outputs as a generic documentation test. Use manufacturer approved simulated/test modes and site procedures.
Handover package#
- as built architecture, inventories and schedules;
- configuration and approved deviation records;
- credential, certificate and key custody without secret disclosure;
- support and escalation contacts;
- update, backup, restore and decommissioning procedures;
- monitoring and runbooks;
- environment validation scope, results, approval, and limitations;
- outstanding defects, risks and review dates.
Sources#
- NIST 800 82, NIST SP 800-82 Rev. 3, lifecycle, architecture, testing and safety considerations, accessed 25 August 2026.