Commercial BESS Safety Checklist: What Buyers and EPC Contractors Must Verify Before Purchase and Commissioning

I Would Not Start This Review at the Fire-Suppression Cylinder

A commercial BESS safety review should verify the complete protection chain: cell and battery evidence, BMS protection, electrical isolation, thermal management, off-gas/fire detection, propagation control, enclosure and site design, emergency response, and commissioning tests. A certificate is evidence for a defined scope; it is not proof that the installed project is safe under every site condition.

That last distinction matters.

IEC 62619:2022 covers safety requirements and tests for secondary lithium cells and batteries used in industrial applications, including stationary electrical energy storage. In North American projects, UL Solutions distinguishes UL 9540 system certification from UL 9540A testing of thermal-runaway and fire-propagation behavior.

Different evidence. Different questions.

When I receive a BESS safety package, I do not ask:

"Is it certified?"

I ask:

"Certified as what, to which edition, for which model, and under which configuration?"

The Model Number Is My First Safety Check

Imagine an EPC is buying ten 215 kWh Outdoor Cabinet s.

The supplier provides an IEC 62619 report.

Good.

Now compare the report with the purchase BOM.

Cell manufacturer: same?

Cell model: same?

Module: same?

Battery configuration: same?

Factory: covered?

BMS: same version where relevant?

This is where safety due diligence starts becoming less glamorous.

IEC states that IEC 62619:2022 applies to industrial secondary lithium cells and batteries, including stationary ESS applications. That does not mean one battery certificate automatically covers every PCS, cabinet, HVAC arrangement, fire system, or later component substitution.

A buyer should build a simple evidence chain:

Safety Layer What I Want to Verify
Cell/battery Model, chemistry, test/certificate scope
Module/rack Configuration and protection
BMS Voltage, temperature, current and fault logic
Complete ESS Applicable system-level evidence
Fire behavior Propagation/fire test evidence where required
Installation Site-specific code and authority requirements

If the model numbers do not connect, I stop there.

A thick certificate folder with the wrong SKU is still the wrong folder.

I Want to Know What Happens Before There Is Fire

A lot of BESS safety presentations begin with suppression.

I begin earlier.

Thermal runaway rarely starts as a dramatic container fire. The protection architecture should identify abnormal conditions while intervention is still possible.

I want to understand:

cell overvoltage and undervoltage limits

overtemperature protection

overcurrent protection

insulation monitoring

contactor and pre-charge behavior

temperature-sensor coverage

cooling alarms

off-gas detection where used

rack isolation logic

Then I ask the uncomfortable question:

What happens if one of those protections fails?

A temperature sensor can drift.

A cooling pump can stop.

A contactor can weld.

Communication between BMS and PCS can disappear.

Safety design becomes interesting when the first protection layer is no longer assumed to work perfectly.

"LiFePO4 Is Safer" Is Not My Risk Assessment

LiFePO4 chemistry is widely selected for stationary storage partly because of its thermal characteristics.

That does not make an LFP cabinet non-combustible or eliminate thermal-runaway risk.

The relevant question is what the actual system does after a cell enters failure.

UL 9540A evaluates thermal-runaway behavior progressively through cell, module and larger ESS configurations. UL explains that testing examines issues including propagation, heat and gas release, ignition, deflagration and the effectiveness of protection measures. UL Solutions

For current U.S. projects, edition matters too. UL reports that the 6th Edition of UL 9540A was published in March 2026 and revised installation-level large-scale fire testing, including scenarios involving ignited vent gases. UL Solutions

So I would not accept:

UL 9540A tested

as the end of the conversation.

I want:

test edition

tested configuration

test level

cell/module/system identity

separation arrangement

test results

and whether the proposed installation matches the conditions supported by that evidence.

The Safety Drawing I Read After the Test Report

Now move outside the cabinet.

Where is the BESS actually going?

Suppose a Ruibit/Dawnice commercial cabinet passes its applicable factory safety checks and arrives at site exactly as specified.

Then the EPC places it:

next to an emergency exit;

inside a flood-prone low point;

against an air intake;

without adequate maintenance clearance;

or where firefighters cannot practically approach it.

The product did not change.

The risk did.

For U.S. installations, NFPA 855 addresses stationary ESS installation requirements, while UL notes that current requirements increasingly use representative fire and large-scale fire testing to support decisions around separation and fire behavior. UL Solutions

For other markets, the applicable codes and approval route can be different.

This is a knowledge boundary I would keep explicit:

I cannot approve BESS separation distance from the cabinet datasheet alone.

It is a site and jurisdiction question.

The Drainage Drawing Belongs in the Safety File

This is the kind of detail procurement often leaves for civil engineering.

I don't.

For an outdoor BESS, I want to know:

finished site elevation

surface-water route

flood level

cabinet plinth/foundation height

cable-entry location

water accumulation points

fire-water management where applicable

Then:

vehicle impact protection

emergency access

equipment clearance

ventilation/exhaust direction

nearby combustible exposures

Safety is not a component installed inside the battery cabinet.

It is partly geography.

A perfectly good cabinet installed in the wrong two square metres can become a bad project.

Before Shipment, I Want the Faults Tested—Not Just the Functions

A FAT that proves the system can charge and discharge is a performance test.

I also want deliberate fault simulation.

Depending on system design and agreed test scope, I may ask the factory to demonstrate:

emergency stop

BMS high-temperature alarm

loss of BMS–PCS communication

HVAC/cooling fault

smoke/off-gas/fire alarm input

contactor opening

insulation alarm

door/access interlock where applicable

remote alarm transmission

power-loss and restart behavior

event logging and timestamps

The U.S. Department of Energy's BESS Procurement Checklist similarly treats safety and technical requirements as procurement-stage questions rather than issues to discover only after installation.

That is the right timing.

A fault found during FAT is paperwork and rework.

A fault found after energization can become an incident.

Then SAT Tries to Break the Assumptions We Made at the Factory

This is where I separate product safety from project safety .

At the factory, the cabinet knows its own wiring.

At site, it meets:

transformer

switchgear

grounding system

utility

SCADA

fire alarm

EMS

building management system

emergency procedures

The interfaces are where commissioning earns its money.

Before commercial operation, I would expect the EPC and supplier to verify the project-specific functions that apply, including grounding/bonding, protection settings, insulation condition, emergency stop behavior, alarm communication, cooling operation, BMS–PCS–EMS coordination, and remote monitoring.

I would also check whether the emergency response documentation matches the system that was actually installed.

Not the previous firmware.

Not the tender drawing.

Not a generic container.

This system. This site. This software.

One Change After Certification Can Reopen the Safety Question

This is probably the procurement issue I worry about most.

The approved design uses Cell A.

Six months later, purchasing proposes Cell B.

"Same capacity."

Or the supplier changes:

BMS

contactor

coolant

HVAC

fire detector

module arrangement

firmware

The change may be perfectly acceptable.

But "equivalent" is not a safety argument by itself.

UL's testing framework emphasizes representative ESS configurations because fire behavior is evaluated at defined cell, module and installation configurations. UL Solutions

For a Ruibit/Dawnice project, I would therefore freeze safety-critical components in the approved BOM and require formal engineering review before substitution.

The review should answer:

Does this change affect certification, test evidence, thermal behavior, protection settings, drawings, warranty, or commissioning?

Sometimes the answer is no.

Write that down too.

The Checklist I Would Sign Before Energization

Verification Purchase Stage FAT Site / SAT
Battery model and safety evidence ✓ ✓
Approved safety-critical BOM ✓ ✓ ✓
BMS protection functions ✓ ✓ ✓
Thermal-management alarms ✓ ✓ ✓
Fire/off-gas detection architecture ✓ ✓ ✓
Propagation/fire evidence where required ✓
E-stop and isolation logic ✓ ✓
Grounding / insulation protection ✓ ✓ ✓
Site separation and emergency access ✓ ✓
Flood/drainage/site hazards ✓ ✓
Alarm communication ✓ ✓
BMS–PCS–EMS fault response ✓ ✓
Emergency response documentation ✓ ✓
Operator training ✓
Final as-built drawings ✓

The exact checklist must change with system size, architecture, country, code edition and authority requirements.

That variation is not an inconvenience.

It is the reason the checklist exists.

I Don't Want a "Safe BESS"

That phrase is too absolute for me.

I want a system where the hazards have been identified, credible failures have protection layers, test evidence matches the supplied configuration, the site respects the installation assumptions, and operators know what to do when an alarm arrives at 02:17.

There is one more thing I want.

Traceability.

If an alarm identifies Rack 3, Module 7, I want the project team to know which cells are there, which production batch they came from, what firmware was running, what temperature history preceded the event, and which changes were made after commissioning.

That information does not stop the first fault.

It can stop the second one.

So before a buyer asks Ruibit/Dawnice—or any commercial BESS supplier—whether the system is "safe," I would change the question:

Show me the protection layers, show me the evidence for this exact configuration, and show me how we will prove they still work after the system reaches the site.

FAQs

1. What should buyers verify before purchasing a commercial BESS?

Verify the battery configuration, BMS protection, thermal management, fire detection, electrical isolation, safety test evidence, site requirements, emergency response, and applicable certifications for the exact system being purchased.

2. Is IEC 62619 certification enough to prove a complete BESS is safe?

No. IEC 62619 addresses industrial lithium cells and batteries within its defined scope. Complete BESS safety also depends on system integration, PCS, thermal management, fire protection, installation conditions, and local regulations.

3. What is the difference between UL 9540 and UL 9540A?

UL 9540 addresses energy storage system and equipment safety certification, while UL 9540A is a test method used to evaluate thermal runaway, fire propagation, gas release, and related fire behavior.

4. What BESS safety functions should be tested during FAT?

Depending on the system, FAT may verify E-stop, BMS protection, high-temperature alarms, cooling faults, communication loss, insulation alarms, contactor operation, fire/off-gas alarms, remote alarms, and event logging .

5. Why must BESS safety be checked again during commissioning?

Factory testing cannot verify every site interface. SAT and commissioning should confirm grounding, protection settings, emergency stops, alarm communication, cooling, BMS–PCS–EMS coordination, and site-specific emergency procedures .

Ready to Find Your Perfect BESS Solution?

Contact Ruibit BESS for a free consultation and custom BESS solution tailored to your commercial and industrial energy storage needs.