Data centre electrical redundancy — Tier classification and EN 50600 availability classes
Data centre electrical redundancy — Tier classification and EN 50600 availability classes
The guides on [4-pole ATS switching](/guides/nen-1010/noodstroomaggregaat-vierpolige-omschakeling-neutraalgeleider) and UPS parallel operation and N+1 redundancy cover individual redundant building blocks of a backup power supply. For a data centre, those building blocks are assembled according to an overall redundancy classification that determines how much downtime the facility is designed to tolerate. This article covers the two classification systems in common use — the industry-standard Uptime Institute Tier system and the formally standardised NEN-EN 50600 availability classes — and the electrical design consequences that follow from each.
Uptime Institute Tier I–IV
The Uptime Institute Tier system is an industry de facto standard (not an IEC/NEN standard) widely used as shorthand in the data-centre sector:
| Tier | Description | Approximate design availability |
|---|---|---|
| I | Single distribution path, no redundancy | ≈ 99.67 % |
| II | Single path, with redundant components (N+1) | ≈ 99.74 % |
| III | Multiple distribution paths, only one active at a time, concurrently maintainable | ≈ 99.98 % |
| IV | Multiple simultaneously active distribution paths, fault tolerant | ≈ 99.995 % |
NEN-EN 50600 — the formally standardised counterpart
The NEN-EN 50600 series is the formal European standard for data centre facilities and infrastructures, with NEN-EN 50600-2-2 specifically covering power distribution. It defines four Availability Classes that are conceptually comparable to the Uptime Tiers (Class 1 ≈ single path/no redundancy, up to Class 4 ≈ fault tolerant), while being a normative European standard rather than a proprietary industry scheme — relevant where a design must reference a formal standard rather than a commercial certification body's own criteria.
N, N+1, 2N and 2N+1: two different kinds of redundancy
These notations describe fundamentally different protections and are often confused with one another:
- N — the minimum capacity actually required to serve the load, with no spare margin.
- N+1 — component-level redundancy: one extra unit (for example one spare UPS module in a parallel bank) beyond what N requires, so a single component failure does not interrupt supply. This does not protect against failure of a shared distribution path itself.
- 2N — path-level redundancy: two entirely separate, independently routed distribution systems, each individually sized for the full N load, so an entire path (including its own switchgear, UPS, and distribution) can fail or be taken out of service without affecting the load.
- 2N+1 — a 2N path-level architecture with additional N+1 component margin on top of each path.
N+1 protects against a single component failure; 2N protects against loss of an entire path, including planned maintenance of that path. A design can have generous N+1 component redundancy and still be vulnerable to a single point of failure at the distribution-path level if it is not also 2N.
Concurrent maintainability versus fault tolerance
These are the two properties that actually separate Tier III/Class 3 from Tier IV/Class 4:
- Concurrent maintainability (Tier III / Class 3): any single component or distribution path can be taken out of service for planned maintenance without impacting the IT load — this requires a maintenance bypass and isolation point on every element of the distribution chain, not just redundant capacity.
- Fault tolerance (Tier IV / Class 4): the facility automatically continues to serve the load through an unplanned failure of any single component or distribution path, without operator intervention — this requires genuinely independent, simultaneously active paths (2N or better) with automatic failover, not a manual transfer procedure.
A facility can be concurrently maintainable (safe to service on purpose) without being fault tolerant (safe against a sudden, unplanned failure); the two capabilities require different design decisions and are not automatically implied by one another.
Consequences at IT-equipment level
The redundancy claimed upstream at Tier III/IV or Class 3/4 is only useful if it is preserved all the way to the IT equipment itself:
- Dual-corded IT equipment — a server or switch with two independent power supply units, each fed from a different path (commonly labelled "A feed" and "B feed"), can lose one entire path without losing power.
- Static transfer switch (STS) — for single-corded equipment that cannot accept two independent feeds directly, an STS automatically switches between the A and B feed within a few milliseconds on loss of the active feed, without the equipment itself noticing an interruption.
Without one of these two measures at the rack, upstream path redundancy is effectively wasted: the equipment still has only a single point of failure at its own power inlet.
Interaction with existing NEN 1010 requirements
Several requirements already covered elsewhere apply directly when assembling a Tier III/IV or Class 3/4 architecture:
- 4-pole ATS switching is required at each point where the neutral conductor of two independent TN-S sources is switched, to avoid a double N-PE bond between the two paths.
- Distribution board selectivity must be verified so a fault on one downstream circuit trips only the closest protective device, not a shared upstream device that would take out an entire redundant path along with the faulted circuit.
- The generator's own power rating classification determines whether backup generation can actually sustain the facility at the claimed availability class under real load, not just at nameplate rating.
Practical relevance
Selecting a target Tier or Availability Class is primarily a business decision balancing downtime cost against capital and operating cost, but once that target is set, the physical electrical design — separate risers, separate PDUs per rack, dual-corded equipment or STS units, selective protection coordination, and 4-pole switching between independent sources — must actually deliver the claimed level, and that delivery should be verified operationally (a live maintenance-bypass test, a real feed-transfer test) rather than assumed from the design documents alone.
Common mistakes
- Specifying Tier III/IV upstream while installing single-corded IT equipment without a static transfer switch — the redundant A/B feeds are then useless at the point that actually matters.
- Confusing N+1 component redundancy with 2N path redundancy — an N+1 UPS bank does not protect against a fault or planned maintenance on the shared distribution path feeding that bank.
- Claiming concurrent maintainability without an operational test of the maintenance bypass before commissioning — a design that looks concurrently maintainable on paper can still interrupt load the first time the bypass is actually used.
- Overlooking a shared upstream point (a single medium-voltage substation, or a PEN conductor shared before the point where the two "independent" paths split) that quietly negates the path independence claimed at Tier III/IV.
Related
Further reading
- §8-1 / IEC 60364-8-1NEN 1010 Part 8-1 — Energy efficiency of electrical installations (IEC 60364-8-1)
- §413.3Electrical separation (§413.3) — an isolating transformer as a protective measure without earthing
- §526 (IEC 60364-5-52)§526 — Electrical connections: why a loose terminal is the most common cause of electrical fire
- §721Electrical installations in caravans and motor caravans (§721)
- §753Electric floor and ceiling heating — NEN 1010 §753
- §444EMC — separation of power and data cables (§444)