9.1 Capacity, Availability, Heat Load, Power, and Environment
Key Takeaways
- Wired spare I/O is usable spare; empty slots still need a module, a download, and often a shutdown window.
- A redundant CPU pair does not fix shared UPS, shared heat, or a shared network switch—those remain common-cause.
- Cabinet heat is module watts plus power-supply inefficiency plus solar, checked at the hottest ambient against the electronics rating.
- UPS sizing is qualitative first: critical load times required runtime for generator start or orderly shutdown, with inrush at transfer.
- Purge type (NFPA 496 X/Y/Z) sets both the classification reduction and whether loss of pressure alarms or de-energizes.
The PE Control Systems exam treats implementation as a matching problem: the installed system must meet the process requirement inside real limits of capacity, availability, heat load, power, and environment, at a cost the project can defend. The 2027 outline (knowledge area 2.E remainder) is not asking you to pick the largest controller on a datasheet. It is asking which constraint is binding, which spare is actually usable during an outage, and which redundancy is theater because both redundant nodes share the same failure.
Capacity is more than CPU percentage
Capacity is the ability to add the last loop, the last sequence, and the last historian tag without saturating the platform. A healthy design leaves headroom in several places at once:
- Controller CPU and memory at the peak scan—including sequences, communication, and diagnostic tasks, not the idle shop-floor load.
- Network loading on control, I/O, and information networks. A historian that solicits every analog at 100 ms can starve control traffic even when the CPU looks fine.
- I/O count versus installed hardware, including the marshaling and barrier real estate that actually lands the wires.
- Operator-workstation and server graphics and alarm performance when the unit is in a trip and every display is alive.
Vendor numbers are specific, but the professional pattern is the same: design so that normal operation sits well below a hard ceiling, and prove the peak (unit trip, sequence start, redundancy failover) during factory testing—not after first feed. Cost shows up here as a temptation. One large controller is cheaper than two until you cannot download, cannot add a package-PLC interface, or cannot keep scan time inside the process's need.
I/O spare philosophy
Empty slots in a rack are not the same as wired spare. A wired spare analog input, already fused and landed on a marshaling terminal, can accept a new transmitter during a short outage. An empty slot still needs a module, a configuration download, and often a shutdown window. Typical practice is on the order of 10–20% spare installed I/O plus spare slot or backplane capacity for growth—but spare that you cannot cool or power is not spare. Over-filling a cabinet to save a second enclosure is how heat and UPS problems are born. Spare CPU licenses with no spare I/O, and spare floor space with no spare power feed, fail the same honesty test.
Availability: simplex versus a redundant pair
Availability is not two CPUs, so twice as good. For a simplex node, availability is roughly MTBF divided by (MTBF plus MTTR). Shortening MTTR—spare module on site, labeled fuse, documented restore, someone who has actually restored a controller—often buys more than a second CPU that nobody can fail over. A redundant pair only helps failures that are independent. If both CPUs sit in the same overheated cabinet, on the same instrument UPS, behind the same pair of switches, the pair does not protect you from the failures that actually take the unit down.
Worked thought process — simplex versus redundant pair. Suppose a controller module is highly reliable and an eight-hour replacement is realistic if a spare is on the shelf and the restore is rehearsed. Simplex unavailability is then dominated by that repair time: on the order of hours per year, not minutes. Adding a hot-standby CPU in the same cabinet, fed from the same UPS, sharing one network, leaves the UPS, the heat, and the switch as common-cause. The pair is still the right choice for a CPU or backplane fault. It is the wrong story if the last two outages were a battery cabinet that cooked both processors and an HVAC loss that did the same. Independent power feeds, diverse network paths, and a room that stays inside temperature limits are part of availability, not accessories. Cost again: a second CPU is visible on the bid tab; a second UPS and a working HVAC interlock are what actually keep the pair honest.
Heat load and the marshaling cabinet
Heat load is a watt budget, then a temperature rise, then a life and listing problem. Sum dissipation of I/O modules at expected load, controllers, switches, intrinsic-safety barriers, and the power-supply loss implied by efficiency. A 24 VDC load of 80 W on an 85% efficient supply dumps about 14 W as heat in the supply itself, on top of the module watts. Add solar load for outdoor cabinets (dark paint, no shade, sun on a steel box). Compare the total to what the enclosure can reject—vents, listed fans, vortex coolers, or room HVAC—at the hottest ambient, not the average day. Electronics life falls as temperature rises; vendor ratings often sit in a 40–50 °C internal-air band that a sealed outdoor box can breach.
Worked thought process — marshaling cabinet. A sealed outdoor marshaling box holds eight analog-input cards, four analog-output cards, digital I/O, a 24 VDC supply, a small Ethernet switch, and a row of IS isolators. Nameplate module heat might land near 50–70 W; the supply and switch push the internal load toward 90–110 W. In a sealed painted steel box in 40 °C sun, that is enough to drive internal air toward vendor limits unless you add shade, increase surface area, provide HVAC, or split the I/O into a second enclosure. The design sequence is:
- Sum watts at expected load, not idle.
- Add supply losses and solar.
- Check enclosure dissipation or room cooling at the hottest ambient.
- Derate because life and drift worsen as temperature rises.
- If the area is classified, you cannot punch a muffin-fan hole through a listed enclosure—you relocate, purge, or use listed cooling.
Power, UPS, and environment
Separate the instrument UPS from lighting and convenience receptacles. Size the UPS qualitatively from critical load (controllers, critical I/O, control network, and whatever operator interface is required for orderly shutdown) times required runtime: often on the order of 15–30 minutes of battery if a generator will start, longer if there is no generator and you must shut the unit down on battery. Account for power-supply inrush that can look like an overload at transfer. Dual-fed redundant controllers should not share a single UPS as their only story. Noncritical historian servers and office-style PCs that happen to sit in the rack room are the first loads to drop off the instrument UPS when runtime is short.
Environment includes temperature, humidity, classification, and purge. Rack rooms and control rooms are typically held in a comfort band (about 18–27 °C, roughly 30–70% RH, non-condensing) so cabinets can reject heat and terminals do not sweat after a cold night. Field cabinets see the process: dust, hydrogen sulfide, washdown, vibration from a compressor deck. Classification of the room decides whether ordinary electronics are legal. If marshaling must live in a classified location, options are relocate to an unclassified room, use intrinsically safe apparatus, use explosion-proof equipment, or use a purged/pressurized enclosure. NFPA 496 Type Z reduces a Division 2 interior toward unclassified (loss of pressure typically alarms). Type Y reduces Division 1 to Division 2. Type X reduces Division 1 toward unclassified and generally requires de-energizing on loss of pressure. Purge air is a utility: the pressure switch, alarm, and interlock have to match the type. Lighting and rear access are maintainability constraints—if you cannot change a card without a vessel-entry permit, the spare you bought is fiction.
| Constraint | Typical mitigation |
|---|---|
| I/O capacity | Wired spare plus spare slots; add a remote I/O cabinet instead of stuffing one box |
| CPU loading | Split by unit or criticality; keep peak-scan headroom; do not slow a loop the process cannot tolerate |
| Network loading | Separate control from information; limit historian scan rates; QoS on shared uplinks |
| Cabinet heat | Shade, HVAC, split cabinets, efficient supplies; do not seal high-watt gear |
| UPS / power | Dual independent feeds for redundant nodes; critical versus noncritical load; runtime for shutdown |
| Hazardous area | Relocate; intrinsic safety; explosion-proof; Type X/Y/Z purge with listed pressure switches |
| Humidity / condensation | Room HVAC with reheat; cabinet heaters on outdoor enclosures |
| Common-cause availability | Diverse power and network; temperature control; spare parts that actually cut MTTR |
Exam traps for 2.E: treating empty slots as commissioned spare, treating redundant CPUs as independent of shared UPS and heat, and treating a sealed outdoor cabinet as if it had infinite dissipation.
A project proposes adding four analog-output cards to a sealed outdoor marshaling cabinet that already runs warm in 40 °C sun. The I/O list still has spare addresses. What is the first binding check?
A simplex controller's last two outages were a shared instrument UPS failure and a rack-room HVAC loss. Management wants a redundant CPU in the same cabinet, same UPS, and same switches. Which statement is most accurate?
Which spare is most likely to let operations add one analog transmitter during a short outage without buying a new I/O module?