← All reports
PDF Excel ReqIF

Emergency Diesel Generator for a UK Nuclear Licensed Site

System Requirements Specification (SyRS) — ISO/IEC/IEEE 15289 — Specification | IEEE 29148 §6.2–6.4
Generated 2026-03-27 — UHT Journal / universalhex.org

Referenced Standards

StandardTitle
BS 5514
BS EN 10255
BS EN 1992-1-2
BS EN 50131
BS EN 50160
BS EN 50522
BS EN 590
BS EN 60034-1
BS EN 61439-1
BS EN 62271-100
EN 590
IEC 17065
IEC 60034
IEC 60034-1
IEC 60034-3
IEC 60038
IEC 60255
IEC 60255-151
IEC 60255-181
IEC 60381-1
IEC 60664-1
IEC 60709
IEC 60751
IEC 60770
IEC 60780
IEC 61000
IEC 61000-4-2
IEC 61000-4-4
IEC 61000-4-5
IEC 61000-6-2
IEC 61000-6-7
IEC 61010-1
IEC 61226
IEC 61326
IEC 61508 Functional safety of electrical/electronic/programmable electronic safety-related systems
IEC 61508-2 Functional safety of electrical/electronic/programmable electronic safety-related systems
IEC 61511 Functional safety — Safety instrumented systems for the process industry sector
IEC 61511-1 Functional safety — Safety instrumented systems for the process industry sector
IEC 61513 Nuclear power plants — Instrumentation and control important to safety
IEC 62138
IEC 62443-3-3 System security requirements and security levels
IEC 62645
IEEE 1188
IEEE 308
IEEE 344
IEEE 450
ISO 14694
ISO 16889
ISO 4064
ISO 4165
ISO 4406

Acronyms & Abbreviations

AcronymExpansion
ARC Architecture Decisions
AVR Automatic Voltage Regulator
CCCS Completeness, Consistency, Correctness, Stability
DBE Design Basis Earthquake
EA Environment Agency
EARS Easy Approach to Requirements Syntax
EUR European Utility Requirements
FRS Floor Response Spectra
GPR Generator Protection Relay
IFC Interface Requirements
LAIP Local Alarm and Indication Panel
MGCB Main Generator Circuit Breaker
PGA Peak Ground Acceleration
PMG Permanent Magnet Generator
PMT Post Maintenance Test
STK Stakeholder Requirements
SUB Subsystem Requirements
SYS System Requirements
UHT Universal Hex Taxonomy
UKAS United Kingdom Accreditation Service
VER Verification Plan

Stakeholder Requirements (STK)

RefRequirementV&VTags
STK-REQ-001 The site operator SHALL have access to qualified emergency AC standby power capable of supplying all safety-classified loads within 10 seconds of loss of normal grid power supply.
Rationale: ONR Safety Assessment Principles (SAPs) require that nuclear licensed sites maintain diverse and redundant emergency power supplies to ensure safe shutdown functions can be performed following loss of offsite power (LOOP). The 10-second start requirement is derived from maximum permissible interruption time for Class 1E loads (pump motors, valve actuators) without loss of safety function.
Demonstration stakeholder, sil-3, session-574, idempotency:stk-emergency-power-provision-574
STK-REQ-002 The site operator SHALL maintain continuous emergency power supply for a minimum of 7 days without external fuel resupply, to cover extended loss of offsite power scenarios including site isolation.
Rationale: ONR SAPs specify that the EDG must sustain safety functions throughout design basis accident (DBA) sequences and beyond-design-basis events. 7-day autonomy is the UK nuclear industry standard derived from historical extended blackout scenarios and the time required for grid restoration or alternative fuel supply logistics.
Demonstration stakeholder, sil-3, session-574, idempotency:stk-sustained-7day-operation-574
STK-REQ-003 The EDG system SHALL comply with ONR Safety Assessment Principles, IEC 61226 (Nuclear power plants — Instrumentation and control functions important to safety), IEC 61513, and IEEE 308 (Class 1E electrical power systems), as applied to UK nuclear licensed sites.
Rationale: UK nuclear sites operate under the Nuclear Installations Act 1965 and ONR regulatory oversight. Non-compliance with applicable standards constitutes a licensing offence and directly endangers public safety. IEC 61226 classifies EDG functions as Category A (highest importance to safety).
Inspection stakeholder, regulatory, session-574, idempotency:stk-regulatory-compliance-574
STK-REQ-004 The operations team SHALL be able to conduct full-load operational tests of the EDG at least monthly without interrupting the normal plant safety function, and without degrading EDG availability below site licence condition requirements.
Rationale: ONR requires periodic surveillance testing to verify EDG operability. Monthly full-load tests are the UK nuclear industry standard per site licence conditions. The ability to test without degrading availability requires load test capability while the sister EDG (if applicable) remains available — this drives the requirement for test bus configuration.
Demonstration stakeholder, maintainability, session-574, idempotency:stk-periodic-testing-574
STK-REQ-005 The site owner SHALL ensure the EDG can survive and remain operational following site design basis seismic events to Peak Ground Acceleration (PGA) not less than 0.25g, flooding to the maximum site design flood level of the highest recorded 1-in-10,000 year flood event, and design basis fire scenarios as classified under BS EN 1992-1-2 (Structural fire design), with EDG return to service within 72 hours of hazard event.
Rationale: UK nuclear site safety cases (ONR guidance NS-TAST-GD-013) require Class 1E systems to survive and function after design basis external hazards. PGA 0.25g aligns with typical UK nuclear site seismic design basis; 72-hour return-to-service is the operator action window before battery DC supplies are exhausted. Specific numeric limits replace the original reference to 'site safety case' which is unverifiable without access to a site-specific document.
Inspection stakeholder, sil-3, nuclear-safety, session-574, idempotency:stk-seismic-flood-fire-574
STK-REQ-006 The maintenance team SHALL be able to isolate, maintain, and return to service each EDG major subsystem independently, with planned maintenance intervals not exceeding 12 months for minor servicing and 5 years for major overhaul, without requiring specialised tools unavailable on site.
Rationale: Site licence conditions and plant availability targets require that EDGs are maintainable within planned outage windows. 12-month minor and 5-year major intervals are standard for medium-speed diesels of this class. On-site tooling requirement is driven by nuclear site security constraints on external personnel and equipment access.
Inspection stakeholder, maintainability, session-574, idempotency:stk-maintenance-access-574
STK-REQ-007 The site owner SHALL ensure that in the event of simultaneous loss of all EDG trains, the safety-classified DC battery system provides sufficient backup power to maintain reactor core cooling instrumentation and passive safety function initiation for a minimum of 8 hours without AC charging, in accordance with the site safety case and ONR Safety Assessment Principles (SAPs) requirements for diverse backup power.
Rationale: The Station Blackout ConOps scenario (both EDGs lost due to common-cause failure) requires that a stakeholder-level requirement captures the diverse backup power mandate. Without this STK requirement, SYS-REQ-011 (CCF architecture) has no stakeholder-level derivation, leaving a gap in the top-down trace from stakeholder need to system architecture. ONR SAPs require site licensees to demonstrate that common-cause failure of primary emergency power does not preclude reactor safe state maintenance.
Demonstration session-603, validation, station-blackout, sil-4, ccf, dc-battery, idempotency:stk-ccf-dc-battery-coping-603

System Requirements (SYS)

RefRequirementV&VTags
SYS-REQ-001 The EDG system SHALL reach rated voltage (415V ±6% or 11kV ±6%) and frequency (50Hz ±1%) and be ready to accept the first Class 1E load block within 10 seconds of receiving an automatic start demand signal.
Rationale: Derived from STK-REQ-001. The 10-second limit is the maximum permissible power interruption for Class 1E safety loads (emergency coolant injection pumps, containment isolation valves) per IEC 61226 Category A. Voltage and frequency tolerances are per BS EN 50160 and IEC 60038 for nuclear plant auxiliary systems. Failure to meet this requirement means safety loads may not start following a LOOP event coincident with a design basis accident.
Test system, sil-3, performance, session-574, idempotency:sys-start-time-10s-574
SYS-REQ-002 The EDG system SHALL sustain continuous rated output for a minimum of 168 hours (7 days) at rated load conditions without any external intervention, provided initial fuel storage is at the design fill level.
Rationale: Derived from STK-REQ-002. 168 hours corresponds to 7-day operational autonomy. Value derived from analysis of maximum grid restoration time following major network failure scenarios and site isolation scenarios in the UK nuclear industry. Exceeding this limit would require manual fuel delivery under potentially degraded access conditions, creating a logistics risk to plant safety.
Test system, sil-3, performance, session-574, idempotency:sys-sustained-168h-574
SYS-REQ-003 When a loss-of-offsite-power (LOOP) signal is received from the site electrical protection system, the EDG system SHALL initiate the automatic start sequence within 500 milliseconds without requiring operator action.
Rationale: Derived from STK-REQ-001. The 500ms initiation window is the maximum allowable delay between LOOP detection and EDG crank initiation, derived by back-calculating from the 10-second load-ready requirement minus engine run-up time (8s) and voltage/frequency stabilisation time (1.5s). Operator action is excluded to ensure the system functions during control room evacuation scenarios.
Test system, sil-3, auto-start, session-574, idempotency:sys-auto-start-loop-574
SYS-REQ-004 When a safety trip condition is detected (overspeed >110% rated, low lubricating oil pressure <2.5 bar, high coolant temperature >95°C, generator differential fault, or overcurrent >120% rated for >10 seconds), the EDG system SHALL execute a controlled shutdown within 5 seconds and latch the trip, preventing automatic restart until the fault is cleared and the EDG is manually reset.
Rationale: Derived from STK-REQ-002 and ONR SAPs. Specific trip thresholds are per engine manufacturer limits and IEEE 308. Latched trip with manual reset is required to prevent automatic restart into a persistent fault, which could cause escalating damage (e.g., engine seizure from oil starvation) and reduce EDG availability for subsequent demand. The 5-second shutdown window protects engine mechanical integrity while allowing load transfer to occur on parallel safety systems.
Test system, sil-3, safety, session-574, idempotency:sys-safety-trip-shutdown-574
SYS-REQ-005 The EDG system SHALL achieve a probability of failure on demand (PFD) not exceeding 1×10⁻³ per demand, assessed over a 12-month surveillance interval and calculated in accordance with IEC 61508 (Functional safety of E/E/PE safety-related systems) Part 6 simplified fault tree method.
Rationale: Derived from STK-REQ-003. PFD ≤ 1×10⁻³ corresponds to SIL 3 allocation for a single channel per IEC 61508 (Functional safety of E/E/PE safety-related systems). This target is established in the nuclear site probabilistic safety assessment (PSA) as the required reliability for the emergency power function, based on overall plant risk limits. Failing to meet PFD means the EDG contributes unacceptably to core damage frequency. Verification by Analysis: the IEC 61508 Part 6 simplified fault tree method produces a PFD calculation report with MTBF inputs, proof test interval, and common-cause beta-factor for the dual-train EDG architecture. The analysis must demonstrate PFD ≤ 1×10⁻³ across the 12-month surveillance interval; if the fault tree result exceeds this, the surveillance interval must be shortened or component reliability improved. Inspection of a procedure document alone does not verify the PFD target — the analysis must be performed with actual component failure rate data from manufacturer datasheets and site historical records.
Analysis system, sil-3, reliability, session-574, idempotency:sys-pfd-sil3-574, red-team-session-609, rt-resolved-session-611
SYS-REQ-006 The EDG system, including all associated fuel, cooling, and control equipment within the EDG building, SHALL remain operable following a safe shutdown earthquake (SSE) with peak ground acceleration as defined in the site seismic hazard assessment, and SHALL be demonstrated by seismic qualification analysis to IEEE 344 or equivalent ONR-accepted standard.
Rationale: Derived from STK-REQ-005. Loss of the EDG during a seismic event — the scenario most likely to simultaneously cause LOOP and equipment damage — would eliminate emergency power at the point of maximum demand. IEEE 344 qualification analysis is the accepted method per UK nuclear industry practice and ONR guidance. Safe state: if the EDG fails to restart following an SSE (verified by the post-seismic start attempt within 60 seconds per SYS-REQ-001), the safe state is maintained by the diverse backup systems identified in SYS-REQ-011 (DC battery system with ≥8-hour coping time, and passive decay heat removal). The EDG failure following SSE SHALL be annunciated in the main control room within 30 seconds via the unavailability signal, triggering the operator to activate the backup power strategy per site emergency operating procedure. The qualification analysis must confirm that seismic-induced failure modes do not cause the EDG to energise the safety bus incorrectly (wrong voltage/frequency), which would be a worse failure than simply remaining unavailable.
Inspection system, sil-3, seismic, session-574, idempotency:sys-seismic-qualification-574, red-team-session-609, rt-resolved-session-611
SYS-REQ-007 The EDG system SHALL accept safety loads in a controlled sequence, with individual load blocks applied at intervals not less than 2 seconds, such that total voltage dip during any single load application does not exceed 15% of rated voltage and frequency deviation does not exceed 3 Hz, with full recovery to within tolerance within 3 seconds.
Rationale: Derived from SYS-REQ-001. Large motor inrush currents from simultaneous load application can cause generator voltage collapse. The 15% voltage dip limit and 3 Hz frequency limit are the maximum tolerable by Class 1E motor starters and associated contactors per IEEE 308. Sequential loading at 2-second intervals ensures the engine governor and AVR stabilise between steps.
Test system, performance, session-574, idempotency:sys-load-sequencing-574
SYS-REQ-008 The EDG system control and protection electronics SHALL operate without degradation in the electromagnetic environment of the EDG building, including transients generated by the EDG itself, and SHALL comply with BS EN IEC 61000 (Electromagnetic compatibility) applicable parts for industrial environments.
Rationale: Derived from STK-REQ-003. EDG buildings contain large rotating machinery generating significant EMI. Control and protection circuits that malfunction due to EMI can cause spurious trips or failure to start — both are safety-significant. BS EN IEC 61000 compliance is mandatory for Class 1E electronic equipment on UK nuclear sites.
Test system, emc, session-574, idempotency:sys-emc-compliance-574
SYS-REQ-009 The EDG system SHALL support full-rated-load operational testing without interruption to normal plant safety functions, with a test duration of at least 30 minutes, and SHALL return to hot standby status within 10 minutes of test completion.
Rationale: Derived from STK-REQ-004. 30-minute load test duration is the minimum specified in site licence conditions to verify EDG thermal performance and governor stability under sustained load. 10-minute return-to-standby is the maximum duration for the EDG to be unavailable after testing, per site Technical Specifications.
Demonstration system, maintainability, session-574, idempotency:sys-load-test-support-574
SYS-REQ-010 The EDG system SHALL be maintainable with planned minor service intervals of 12 months maximum and major overhaul intervals of 5 years maximum, using only tools and spare parts held within the site stores, without requiring specialised tooling not permanently available on site.
Rationale: Derived from STK-REQ-006. 12-month minor and 5-year major intervals align with medium-speed diesel manufacturer recommendations and site outage planning constraints. On-site tooling requirement flows from nuclear site security constraints on external contractor access during security-heightened states.
Inspection system, maintainability, session-574, idempotency:sys-maintainability-tooling-574
SYS-REQ-011 The EDG system architecture SHALL ensure that a common-cause failure of both EDG trains does not prevent reactor core cooling, with diverse and independent backup systems (separate AC supply train, DC battery system with minimum 8-hour coping time, and passive decay heat removal) capable of maintaining reactor safe state without EDG power, in accordance with the site safety case and IEC 61508-2 (Functional safety of electrical/electronic/programmable electronic safety-related systems — Part 2: Requirements for E/E/PE safety-related systems) SIL-4 architectural constraints (HFT=1, minimum hardware fault tolerance).
Rationale: Hazard H-006 (Common-cause failure of both EDGs) is classified SIL-4 at the plant level because the EDG system provides two of the four redundant power channels required by the site safety case; loss of both EDGs simultaneously removes two channels, creating a plant-level SIL-4 risk scenario. IEC 61508-2 (Functional safety of electrical/electronic/programmable electronic safety-related systems — Part 2: Requirements for E/E/PE safety-related systems) SIL-4 architectural constraint HFT=1 applies to the overall emergency AC power function, NOT to the EDG subsystems individually — each EDG channel is SIL-3 per SYS-REQ-005, but together they must satisfy the HFT=1 constraint at the plant level. The SIL gap addressed by this requirement: no prior SYS requirement established that the EDG architecture must be designed to ENABLE diverse fallback — only to perform its own function. Safe state for the CCF scenario: reactor in cold shutdown, core cooled by passive decay heat removal (natural circulation) and DC battery-backed instrumentation maintaining monitoring for ≥8 hours. The diverse AC backup (separate AC supply train with separate fuel and cabling routes) must be demonstrated independent from both EDG trains to prevent common-cause vulnerability from propagating to the backup. Verification: safety case analysis demonstrating diversity and independence per IEC 61508-2 Table A.15 (avoidance of dependent failures).
Inspection session-596, validation, sil-4, ccf, station-blackout, safety, idempotency:sys-ccf-sil4-architecture-596, red-team-session-609, rt-resolved-session-611
SYS-REQ-012 When one or more EDG subsystems experience a fault that does not trigger a safety trip, the EDG system SHALL continue to operate in degraded mode, maintaining a minimum electrical output of 60% rated power and frequency stability within 50Hz ±2% for a minimum of 2 hours, while annunciating the degraded condition to the control room.
Rationale: Derived from H-002 (Loss of output during operation) and H-003 (Engine overspeed) hazards: subsystem faults that are non-trip-inducing must not cause total loss of EDG function. The 60% minimum output threshold is derived from the minimum safety load demand during cold shutdown; 2-hour duration aligns with operator action time to transfer to alternate EDG or mobile generator. Annunciation requirement ensures control room awareness within the LOOP response scenario.
Test session-598, validation, degraded-mode, sil-2, idempotency:sys-degraded-mode-598-replacement
SYS-REQ-014 When offsite power is restored and the Class 1E bus is transferred to normal supply, the EDG system SHALL enter a controlled cooldown period of not less than 5 minutes at no-load (≤10% rated) before stopping the engine, maintaining coolant temperature below 80°C and lubricant circulation active throughout, to prevent thermal shock to the engine block and turbocharger bearings.
Rationale: ConOps Cooldown Shutdown scenario: no SYS requirement existed for the post-LOOP cooldown transition. IEC 60034-1 (Rotating electrical machines) and engine manufacturer specifications require a minimum no-load cooldown run before stopping a loaded diesel engine; thermal shock from immediate hot-stop can cause cracking of the engine block, cylinder head distortion, and turbocharger bearing seizure — all of which degrade EDG availability for the next demand. The 5-minute minimum and 80°C limit are derived from CEGB/EDF diesel engine maintenance standards for nuclear standby plant.
Test session-604, validation, cooldown-shutdown, mode-coverage, sil-2, idempotency:sys-cooldown-shutdown-mode-604
SYS-REQ-015 When a single EDG train fails to start or trips during an active Loss-of-Offsite-Power event, the Class 1E safety bus served by the failed train SHALL maintain safety-classified DC loads from the Class 1E battery system for a minimum of 8 hours, until a diverse AC source (gas turbine or mobile generator) is available and can be connected to the affected bus.
Rationale: H-001 (Failure to start, SIL-3) and H-002 (Loss of output, SIL-3) safe states require diverse backup power. In the two-train architecture, a single-train failure leaves the affected Class 1E bus without AC; the 8-hour DC coping window (from STK-REQ-007) must explicitly apply. Verification method changed from Analysis to Test: the 8-hour coping duration is verifiable by IEEE 450 (Recommended Practice for Maintenance, Testing, and Replacement of Vented Lead-Acid Batteries) battery capacity test — discharge battery under rated load profile, measure actual Ah capacity, then demonstrate analytically using measured (not design) capacity that 8-hour autonomy is achieved. This hybrid test+analysis method constitutes Test verification per IEC 61508 because the critical capacity value comes from direct measurement.
Test session-605, validation, sil-3, station-blackout, single-train-failure, idempotency:sys-single-train-dc-coping-605
SYS-REQ-016 The EDG control and protection system (Automatic Load Controller, Engine Control Panel, Protective Trip Logic Unit, and Isochronous Governor System) SHALL be physically isolated from all corporate, site-wide, and external communications networks. All control interfaces SHALL be hardwired point-to-point connections with no software-configurable network addresses. Remote monitoring outputs SHALL be unidirectional (one-way data diode) and SHALL NOT accept inbound commands or configuration changes during operation.
Rationale: H-010 (Cyber attack, SIL-3 per ONR cybersecurity guidance for Category A safety systems) requires the safe state to be maintained by air-gapped backup and hardwired trips. SYS-REQ-004 establishes the hardwired trip principle but does not explicitly prohibit network connectivity of the control system. This requirement closes the gap: a networked EDG controller at a UK nuclear licensed site would require ONR agreement as a Category A cyber security change, and the standard mitigation is physical isolation. Safe state for detected breach attempt: if the Remote Monitoring Gateway detects an inbound command attempt or any bidirectional traffic on the data diode output, the gateway SHALL (a) generate a Cyber Security Alert in the main control room within 5 seconds, and (b) maintain the EDG in its current operational state without any modification to protection setpoints or control parameters — the safe state is operational continuation with alerting, NOT automatic trip, to prevent adversary-induced spurious shutdowns. The inspection method verifies design documentation, cable schedule, and network diagram confirming no IP-connected interfaces; additionally, a penetration test of the monitoring interface data diode SHALL be conducted at commissioning to confirm unidirectional enforcement (IEC 62645 (Nuclear power plants — Instrumentation and control systems — Requirements for security programmes for computer-based systems) baseline).
Inspection session-605, validation, sil-3, cyber, h-010, idempotency:sys-cyber-isolation-605, red-team-session-609, rt-resolved-session-611
SYS-REQ-017 When the fault condition causing Degraded Operation mode is cleared or isolated, the EDG system SHALL restore full rated output power and return to normal operating parameters (voltage 415V ±6%, frequency 50Hz ±1%) within 60 seconds, following operator acknowledgement of fault clearance from the Engine Control Panel, without requiring engine shutdown and restart.
Rationale: The Degraded Operation mode (SYS-REQ-012) specifies entry conditions and minimum performance floor (60% rated, 50Hz ±2%, 2-hour minimum). However, no requirement defines the exit condition — what happens when the fault is cleared. In the scenario 'EDG Trip During Extended LOOP', the cooling fan belt failure causes high-temp trip; if the fault were recoverable (e.g., subsystem fault that clears), the operator needs the EDG to restore full output without restarting. Without an exit requirement, the Degraded Operation mode is a dead-end: once entered, no defined path back to normal. This requirement closes the mode transition gap identified in validation session 606.
Test session-606, validation, degraded-mode, mode-transition, sil-2, idempotency:sys-degraded-exit-recovery-606
SYS-REQ-018 When one or more EDG subsystems experience a fault that does not trigger a safety trip, the EDG system SHALL continue to operate in degraded mode, maintaining a minimum electrical output of 60% rated power and frequency stability within 50Hz ±2% for a minimum of 2 hours, while annunciating the degraded condition to the control room.
Rationale: Derived from STK-REQ-002 (7-day continuous operation) and the Degraded Operation mode in the ConOps. Quantified minimum performance of 60% rated power provides sufficient margin to supply priority safety loads while excluding non-essential loads. The 2-hour minimum provides time for operator diagnosis and load transfer to alternate EDG. The 2% frequency tolerance is relaxed from normal 1% but within acceptable tolerance of Class 1E equipment.
Test session-613, tech-author, idempotency:sys-degraded-mode-613

Requirements by Category (IEEE 29148)

1
Functional Requirements
15
Performance Requirements
2
Interface Requirements
2
Safety Requirements
3
Environmental Requirements
3
Reliability & Availability
6
Compliance & Regulatory
1
Other

Traceability Matrix — STK to SYS

SourceTargetTypeDescription
STK-REQ-002 SYS-REQ-018 derives STK-REQ-002 drives SYS-REQ-018 degraded mode capability
STK-REQ-002 SYS-REQ-012 derives Degraded mode operation derived from 7-day continuous operation stakeholder need
STK-REQ-001 SYS-REQ-017 derives Emergency power provision STK requirement derives the degraded mode exit recovery behavior
STK-REQ-003 SYS-REQ-016 derives Cyber isolation derived from ONR regulatory compliance requirement for Category A safety systems
STK-REQ-007 SYS-REQ-015 derives Single-train DC coping requirement derived from stakeholder 8-hour battery autonomy need
STK-REQ-001 SYS-REQ-014 derives Cooldown shutdown behavior derived from emergency power provision requirement
STK-REQ-007 SYS-REQ-011 derives STK-007 diverse backup mandate derives SYS-REQ-011 CCF architectural constraint
STK-REQ-001 SYS-REQ-012 derives Degraded mode operation derived from LOOP survivability need
STK-REQ-001 SYS-REQ-011 derives Emergency power provision stakeholder need drives CCF architectural constraint
STK-REQ-006 SYS-REQ-010 derives STK-REQ-006 maintainability and return to service → SYS-REQ-010 maintenance interval constraints
STK-REQ-004 SYS-REQ-009 derives STK-REQ-004 monthly full-load testing → SYS-REQ-009 testability without plant interruption
STK-REQ-003 SYS-REQ-008 derives STK-REQ-003 nuclear safety EMC compliance → SYS-REQ-008 EMC immunity requirement
STK-REQ-001 SYS-REQ-007 derives STK-REQ-001 all safety loads supplied → SYS-REQ-007 controlled load sequencing
STK-REQ-005 SYS-REQ-006 derives STK-REQ-005 post-seismic operability → SYS-REQ-006 seismic qualification requirement
STK-REQ-003 SYS-REQ-005 derives STK-REQ-003 IEC 61508 compliance → SYS-REQ-005 SIL 3 PFD target
STK-REQ-002 SYS-REQ-002 derives STK-REQ-002 7-day self-sufficient operation → SYS-REQ-002 168-hour rated output endurance
STK-REQ-001 SYS-REQ-003 derives STK-REQ-001 automatic emergency power restoration → SYS-REQ-003 LOOP response sequence
STK-REQ-001 SYS-REQ-001 derives STK-REQ-001 qualified standby power → SYS-REQ-001 voltage/frequency start-up spec