Battery energy storage systems concentrate electrical and chemical energy into equipment that must remain safe through normal operation, faults, maintenance, emergencies, and eventual decommissioning. For that reason, effective BESS safety cannot be reduced to a fire suppression system, a battery chemistry choice, or a certificate on a data sheet.
A defensible safety strategy is layered. It begins with cell quality and system architecture, continues through battery management, electrical protection and thermal control, and extends to detection, propagation control, fire and explosion protection, site layout, emergency planning, commissioning, operations, maintenance, and change control. Teams that need a refresher on how these subsystems fit together can first review the core components of a battery energy storage system.
The practical question is not simply, "How do we extinguish a battery fire?" A better question is: How do we prevent a credible failure from escalating into an uncontrolled site-level event?
Important: Codes and standards change, and local jurisdictions do not always adopt the newest edition immediately. Before design or procurement decisions are finalized, confirm the editions, amendments, permits, and interpretations enforced by the authority having jurisdiction (AHJ).

Why BESS Safety Is a System-Level Problem
A lithium-ion BESS contains many interacting layers: cells, modules, racks, power electronics, conductors, protective devices, controls, cooling equipment, ventilation, enclosures, communications, fire protection, and site infrastructure. A fault can originate in one layer and create conditions that challenge several others.
That is why safety analysis should follow the possible escalation path rather than focusing only on the initiating component:
cell failure → module involvement → rack or unit involvement → adjacent unit exposure → installation-level consequences
The engineering objective is to interrupt that sequence as early and as reliably as practical.
Thermal Runaway and Propagation
Thermal runaway occurs when heat generation within a cell accelerates beyond the cell's ability to dissipate that heat. Internal defects, overcharge, external heating, electrical faults, mechanical damage, manufacturing problems, or other abnormal conditions can initiate the process.
Once thermal runaway begins, an affected cell can release heat, hot particles, vapor, and gases. The safety problem then changes from preventing the first failure to controlling propagation. Neighboring cells, modules, wiring, enclosure materials, and adjacent energy storage units may be exposed to elevated temperature, flames, or combustible gases.
This is one reason large-scale fire testing matters. Cell-level behavior alone cannot fully represent the interactions among thousands of cells, enclosure geometry, ventilation, barriers, cooling systems, suppression, spacing, and adjacent equipment. UL Solutions describes UL 9540A as a test method that evaluates thermal runaway and fire propagation behavior at multiple levels of a battery energy storage system.

Off-Gassing, Fire, and Deflagration Are Related but Different Hazards
A BESS incident does not always begin with visible flame. Cells under abnormal conditions may vent electrolyte vapor and other gases before or during thermal runaway. If flammable gases accumulate inside an enclosure and encounter an ignition source, the event can involve deflagration and damaging overpressure in addition to fire.
This creates three separate engineering questions:
- Can the abnormal condition be prevented or detected early?
- Can heat and fire propagation be limited after a cell fails?
- Can released gases be detected, managed, diluted, vented, or otherwise addressed before they create an explosive atmosphere?
Early warning can be valuable, but it should not be treated as guaranteed. In controlled FM testing, off-gas detectors provided warning before thermal runaway in certain scenarios, with the available interval depending on the battery and test conditions. FM reports test intervals of roughly five to 20 minutes in those scenarios, which illustrates both the potential value and the limits of early detection. See FM's discussion of lithium-ion off-gas detection.
Fire Is Not the Only Hazard
A complete BESS hazard assessment can also need to address overvoltage, overcurrent, short circuits, ground faults, insulation failure, electric shock, arc flash, loss of cooling, water intrusion, flooding, mechanical impact, extreme ambient temperature, seismic or wind loads, control-system failure, communication loss, aging batteries, and unauthorized or poorly controlled modifications.
Not every project has the same exposure. A utility-scale container yard, an indoor commercial installation, and an outdoor cabinet have different layouts, access conditions, environmental stresses, and emergency-response constraints. The safety case therefore has to match the actual installation.
BESS Safety Standards: What UL 9540, UL 9540A, NFPA 855, IFC, and IEC Actually Do
One recurring compliance mistake is treating every standard as if it answers the same question. It does not. Product certification, fire testing, installation requirements, and local code adoption perform different roles.
| Standard or Code | Primary Role | Practical Question |
|---|---|---|
| UL 9540 | Safety standard for energy storage systems and equipment | Has the complete ESS been evaluated as a system? |
| UL 9540A | Thermal runaway fire propagation test method | How does the tested configuration behave when thermal runaway or a severe fire condition is initiated? |
| NFPA 855 | Installation standard for stationary energy storage systems | How should the ESS be installed, commissioned, operated, maintained, protected, and decommissioned? |
| 2024 IFC Section 1207 | Fire-code provisions for electrical energy storage systems | What fire-code requirements apply where the 2024 IFC has been adopted? |
| IEC 62619:2022 | Safety requirements for industrial secondary lithium cells and batteries | What cell- and battery-level requirements apply to industrial and stationary applications? |
| IEC 62933-5-2:2025 | Safety requirements for grid-integrated electrochemical energy storage systems | How should system safety be addressed over the BESS lifecycle? |
UL 9540: System-Level Product Safety
UL 9540 addresses energy storage systems and equipment as an integrated product. This distinction matters because individual cells or battery modules do not operate in isolation. They interact with power conversion equipment, controls, wiring, protection, thermal systems, enclosures, and communications.
UL Solutions' energy storage system testing and certification overview identifies UL 9540 as the safety standard for energy storage systems and equipment. For additional site-specific reading, see the discussion of why UL certification matters for BESS projects.
UL 9540A: Fire and Thermal Runaway Test Evidence
UL 9540A is a test method, not a substitute name for UL 9540 certification. The method is used to characterize thermal runaway, propagation, gas release, heat release, fire behavior, deflagration potential, re-ignition, and the performance of protection features under defined test conditions.
As of 2026, UL Solutions supports the fifth and sixth editions of UL 9540A. UL states that the sixth edition was published on March 13, 2026 and updates installation-level large-scale fire testing. The key lesson for project teams is not merely to ask whether a report exists. They need to understand what was actually tested and whether the proposed installation remains represented by that evidence.
NFPA 855: Installation and Lifecycle Safety
NFPA 855, 2026 edition, is the Standard for the Installation of Stationary Energy Storage Systems. Its structure makes the lifecycle scope clear: Chapter 6 addresses commissioning, Chapter 7 operation and maintenance, Chapter 8 decommissioning, and Chapter 9 electrochemical energy storage systems.
NFPA 855 connects product information, fire-test evidence, installation design, separation, fire and explosion protection, emergency planning, commissioning, and ongoing operation. It should be used together with the adopted fire, building, electrical, and other applicable codes rather than treated as a stand-alone project checklist.
2024 IFC Section 1207 and Local Adoption
The 2024 International Fire Code energy-storage provisions are located in Section 1207. The code addresses stationary, portable, and mobile electrical energy storage systems and links installation requirements to NFPA 855, required listings, and manufacturer instructions.
Publication does not equal local adoption. A jurisdiction may enforce an earlier code edition, local amendments, additional fire-department conditions, or project-specific requirements. Confirm the adopted code set before finalizing spacing, fire protection, site access, or emergency-response assumptions.
IEC Standards for International Projects
IEC 62619:2022 specifies safety requirements and tests for secondary lithium cells and batteries used in industrial applications, including stationary electrical energy storage.
IEC 62933-5-2:2025 addresses safety requirements for grid-integrated electrochemical energy storage systems and explicitly covers the lifecycle from design through end-of-service-life management.
The practical approach is to build a compliance matrix around the technology, project location, application, product configuration, adopted codes, owner requirements, insurer expectations, and AHJ-not around a generic internet list of standards.
BESS Safety Design: Seven Protection Layers
A resilient BESS safety case assumes that individual devices can fail. Protection is stronger when independent or complementary layers prevent one fault from immediately escalating to the next level.

1. Cell Quality and Chemistry
Battery chemistry affects thermal behavior, voltage, energy density, state-of-charge response, and failure characteristics, but chemistry is only one part of the safety case. Manufacturing consistency, cell design, module construction, thermal interfaces, electrical protection, BMS logic, enclosure design, and operating limits can be equally important in determining real-world risk.
LFP is widely used in stationary storage and is often selected in part for its thermal characteristics. NMC can offer higher energy density. Neither chemistry should be described as risk-free, and neither label can replace configuration-specific safety testing and engineering controls.
When defining operating limits, ambient conditions, and cooling requirements, it is also useful to understand the broader temperature limits that affect lithium battery performance and safety.
2. Battery Management and Electrical Protection
The battery management system is an early active line of defense. Depending on the architecture, it may monitor cell and module voltage, current, temperature, state of charge, state of health, insulation conditions, and other abnormal operating signals.
The important question is not how many values are displayed on a dashboard. It is what the system does when a value becomes unsafe. Protective thresholds, time delays, contactor logic, inverter commands, alarms, trips, isolation, remote notifications, and emergency shutdown functions need to be coordinated.
Failure modes also matter. A robust design asks what happens if a temperature sensor fails low, a communications link is lost, a controller reboots, an auxiliary power supply disappears, or a protective command is not acknowledged. Safety logic should fail in a defined and tested manner.
3. Thermal Management and Hotspot Control
Thermal management serves both performance and safety. Average enclosure temperature is not enough. Engineers also need to control local hotspots and excessive temperature gradients between cells, modules, and racks.
Cooling architecture may use forced air, liquid cooling, refrigerant-based systems, immersion, or other approaches. Selection should be based on heat load, environmental conditions, redundancy, maintainability, failure response, and validated performance rather than marketing claims about one "best" cooling method.
Outdoor installations add solar loading, dust, humidity, rain, and seasonal temperature swings to the design problem. For that context, see this overview of thermal management for outdoor cabinet BESS.
4. Isolation, Compartmentation, and Propagation Control
A practical design review should assume that one cell, module, cable, contactor, cooling circuit, or control function can fail and then ask: what keeps the failure from reaching the next layer?
Depending on the product and site, useful measures may include:
- electrical isolation and appropriately coordinated protective devices;
- module or rack separation;
- thermal barriers and fire-resistive construction;
- compartmentation and enclosure design;
- controlled venting;
- spacing between energy storage units;
- shutdown and de-energization logic; and
- site layout that limits exposure to buildings, equipment, property lines, and responder access routes.
The right combination should be justified by the tested configuration and site-specific hazard analysis. A separate overview of container energy storage system safety considerations can help when evaluating containerized installations.
5. Early Detection and Actionable Alarms
Detection is most valuable when it creates enough time for a useful protective action. A layered system can combine operational data with dedicated safety sensors.
- Abnormal voltage or current may identify an electrical problem.
- Rapid temperature rise can indicate a developing thermal event.
- Cooling-system alarms can reveal the loss of a critical support system.
- Off-gas sensors may detect electrolyte vapor before visible fire in some scenarios.
- Smoke, heat, flame, or radiant-energy detection can provide confirmation as an event develops.
Sensor selection is only half of the design. The alarm must connect to clear logic: who receives it, what is automatically shut down, what equipment remains energized, what the operator is expected to do, and when emergency responders are notified.
6. Fire and Explosion Protection
Fire protection has several different objectives that should not be collapsed into one:
- suppress visible flame;
- cool affected batteries;
- prevent propagation to neighboring cells or units;
- protect adjacent exposures;
- manage combustible gases;
- control overpressure; and
- support safe responder operations.
A suppression system that extinguishes an external flame has not necessarily stopped the electrochemical reactions inside a cell already in thermal runaway. Protection should therefore be selected from test evidence and hazard analysis rather than from a universal claim about the "best" extinguishing agent.
7. Site Design and Emergency Preparedness
Emergency response should influence design before construction is complete. Access roads, gates, unit spacing, isolation points, shutdown controls, water supply, drainage, ventilation, signage, responder staging areas, and safe approach routes are difficult or expensive to correct after commissioning.
This is where BESS fire safety becomes a site problem rather than a battery problem. The facility has to remain understandable and manageable under abnormal conditions, including loss of normal power or communications.
How to Turn a UL 9540A Report Into a Site-Specific Safety Decision
Possessing a UL 9540A report is not the same as proving that a proposed installation is safe. The report is evidence. The project team still has to connect that evidence to the equipment being purchased, the configuration being installed, and the protection features being relied upon.
A useful review sequence is:
- Identify the exact tested configuration. Confirm cell model, module arrangement, rack or unit design, enclosure, state of charge, and any active systems used during the test.
- Check propagation results. Determine whether thermal runaway propagated within a module, between modules, between racks, or between units under the tested conditions.
- Review heat and gas data. Understand heat release, gas production, ignition behavior, deflagration observations, re-ignition, and any limitations in the test report.
- Identify credited protection features. Note barriers, spacing, cooling, ventilation, detection, suppression, deflagration protection, or other features that were part of the tested configuration.
- Compare the test to the project. Check whether site spacing, enclosure geometry, ventilation, firmware, module design, suppression, and product revision remain representative.
- Resolve deviations. If the proposed installation differs from the test configuration, determine what additional engineering evaluation, testing, documentation, or AHJ approval is needed.
This process catches a common failure mode: using a valid report to support an installation that has materially changed from what was tested. A later substitution, firmware revision, module change, ventilation change, capacity augmentation, or altered spacing can affect the safety assumptions even when the product name remains familiar.
BESS Fire Protection: Suppression, Cooling, and Gas Management
Suppressing Flame Is Not the Same as Stopping Thermal Runaway
Once a cell is in thermal runaway, internal heat generation can continue even if an external flame is reduced. This is why BESS fire protection must distinguish between flame suppression, battery cooling, propagation control, exposure protection, gas management, and post-event monitoring.
The right strategy depends on the battery architecture, enclosure, fire-test results, ventilation, expected gas release, spacing, occupancy, neighboring exposures, water availability, environmental controls, and applicable code requirements.
Water-Based Response and Exposure Protection
Water can be valuable because it absorbs heat and can protect neighboring equipment or structures. The U.S. EPA's current BESS installation and incident-response guidance emphasizes preventing fire spread and describes the use of water to protect neighboring batteries or structures while research continues on application strategies.
Water use also creates design questions that should be resolved before an incident: where runoff will go, whether it can be contained or redirected, how electrical hazards will be managed, how responders can reach the exposure safely, and what environmental monitoring may be needed.
Gaseous Agents, Aerosols, Water Mist, and Other Systems
Other suppression technologies may be appropriate in certain enclosures. Their role should be defined precisely. A system may suppress an incipient fire, protect auxiliary equipment, reduce flame spread, or support enclosure protection without necessarily preventing thermal runaway propagation in every battery configuration.
Protection decisions should therefore be tied to representative test data, the enclosure geometry, ventilation design, battery chemistry, expected gas release, ignition risk, and the failure scenarios established by the hazard analysis.
Deflagration and Vent-Gas Management
Combustible gas accumulation creates a separate design challenge from open flame. Depending on the enclosure and hazard analysis, mitigation may involve gas detection, ventilation, shutdown logic, deflagration venting, explosion prevention, or other engineered measures.
UL 9540A gas data can be important in this analysis because the type, quantity, and flammability of released gases influence whether an enclosure can reach a hazardous concentration. The most defensible design connects the gas data, enclosure volume, ventilation assumptions, ignition sources, and mitigation strategy instead of treating "ventilation" as a generic checkbox.
BESS Emergency Response Planning
An emergency response plan should be developed before commissioning and tested before the site is placed into normal operation. A plan written after a major alarm is too late to influence access, isolation, water supply, drainage, signage, ventilation, or responder approach.

Coordinate With First Responders Before Energization
Local responders should know what is on the site and how it behaves before an emergency. Pre-incident coordination can cover:
- site access and staging areas;
- equipment layout and stored-energy locations;
- battery chemistry and safety data;
- electrical isolation and emergency shutdown points;
- expected fire, gas, and explosion hazards;
- water supply and drainage considerations;
- remote monitoring and alarm contacts;
- areas that should not be entered during an incident; and
- owner, operator, manufacturer, utility, environmental, and emergency contacts.
EPA guidance specifically recommends communication with local first responders during BESS planning and includes incident-response considerations such as isolation, air monitoring, fire-spread prevention, runoff management, and safe transport and disposal of damaged batteries.
Define Shutdown, Isolation, and Notification Logic
The plan should state who is authorized to act and what conditions trigger alarms, automatic shutdown, manual shutdown, isolation, evacuation, fire-department notification, utility notification, or escalation to hazardous-material and environmental response.
Procedures also need to work under degraded conditions. If normal communications, site power, remote monitoring, or access control is lost, personnel should still know how to identify the affected equipment and place the site in the safest practicable state.
Plan for Air Monitoring, Runoff, and Re-Ignition
Battery fires can release hazardous gases and combustion products. EPA guidance recommends assessing hazardous air emissions during a BESS incident and minimizing, containing, or redirecting runoff from water application where practicable.
Recovery planning is equally important. Damaged batteries can remain unstable and may re-ignite after visible flames have disappeared. Post-incident work can involve extended monitoring, controlled de-energization, isolation, packaging, transport, cleanup, and disposal. The emergency plan should continue through this recovery phase instead of ending at "fire out."
Commissioning, Operations, Maintenance, and Change Management
A design can look complete on paper and still fail if interfaces are never commissioned or safety-critical equipment is not maintained. NFPA 855's separate chapters for commissioning, operation and maintenance, and decommissioning reflect this lifecycle reality.
Commission the Safety Functions as a System
Commissioning should verify not only individual components but also the interactions among them. Depending on the project, tests may include:
- BMS alarms, warnings, trips, and contactor logic;
- temperature and gas sensors;
- cooling and ventilation equipment;
- fire detection and suppression controls;
- emergency stops and remote shutdown;
- communications between BMS, PCS, EMS, fire systems, and remote monitoring;
- backup or auxiliary power for critical safety functions; and
- notification and escalation paths.
A sensor test is incomplete if the team never confirms what the controller, PCS, operator, and fire system do when that sensor reaches an alarm threshold.
Monitor Trends, Not Only Hard Alarms
Many deteriorating conditions are more visible as trends than as single threshold crossings. Useful indicators can include recurring temperature imbalance, increasing cell imbalance, cooling performance changes, repeated communication faults, insulation abnormalities, unexplained state-of-charge differences, or health indicators supported by the battery system.
The operating team should define which trends require inspection or diagnostic review before they become hard alarms.
Maintain Safety-Critical Equipment
Cooling equipment, ventilation, gas sensors, fire detectors, suppression systems, emergency power supplies, protective relays, shutdown circuits, and communications all require inspection and testing. A protective feature that has not been verified for years should not be assumed to work on demand.
For a broader operations perspective, see the site's guide to BESS maintenance requirements.
Treat Modifications as Safety-Case Changes
Software updates, firmware revisions, replacement modules, altered alarm thresholds, cooling-component substitutions, capacity augmentation, enclosure changes, or revised spacing can change the relationship between the installed system and its original certification, fire-test evidence, hazard analysis, and emergency plan.
A formal management-of-change process should ask:
Does this modification change any assumption used in certification, UL 9540A testing, fire or explosion analysis, code approval, commissioning, maintenance, or emergency response?
If the answer is yes-or cannot be demonstrated to be no-the change deserves technical review before implementation.
Common BESS Safety Mistakes
"We use LFP, so thermal runaway is no longer a concern."
LFP can have favorable thermal characteristics, but it is still a lithium-ion chemistry and can fail under sufficiently severe conditions. Chemistry should reduce or reshape parts of the risk profile, not replace the rest of the safety layers.
"The system passed UL 9540A, so it is UL 9540A certified."
This wording confuses two different concepts. UL 9540A is a standardized fire-test method. UL 9540 is the system-level product safety standard. The project should describe exactly what testing, listing, certification, and installation evidence is available.
"We have suppression, so the fire problem is solved."
Suppression may address one consequence while leaving thermal runaway, propagation, gas accumulation, overpressure, exposure protection, re-ignition, and recovery to other layers. Fire protection should be evaluated as a coordinated strategy.
"The newest standard online must be the one our project follows."
Not necessarily. Model codes and standards can be published before a state, city, county, or other jurisdiction adopts them. Always verify the enforceable code edition and local amendments.
"Emergency planning can wait until after commissioning."
By that point, site access, isolation, water supply, drainage, spacing, signage, ventilation, and responder approach may already be fixed. Emergency planning should influence design.
"A small product change cannot affect the safety case."
Small changes can alter airflow, thermal behavior, control logic, fault response, spacing, or the relationship between the product and its tested configuration. Use formal change control rather than relying on the apparent size of the modification.
Frequently Asked Questions About BESS Safety
What is BESS safety?
BESS safety is the combination of product design, testing, installation controls, electrical and thermal protection, fire and explosion protection, monitoring, commissioning, maintenance, emergency preparedness, and change management used to reduce both the likelihood and consequences of failures in battery energy storage systems.
What causes BESS fires?
Potential initiating conditions include internal cell defects, electrical faults, overcharge, overheating, cooling failure, mechanical damage, external fire exposure, manufacturing defects, water intrusion, and other abnormal conditions. In lithium-ion batteries, some of these conditions can initiate thermal runaway.
Is LFP safer than NMC for BESS?
LFP is often selected for stationary storage partly because of its thermal characteristics, while NMC can offer higher energy density. However, a complete BESS safety assessment cannot be made from chemistry alone. Cell quality, state of charge, module design, BMS protection, cooling, electrical protection, enclosure design, propagation controls, installation conditions, and operations all matter.
Is UL 9540A a certification?
No. UL 9540A is a standardized test method for evaluating thermal runaway fire propagation behavior in battery energy storage systems. UL 9540 is the system-level safety standard for energy storage systems and equipment.
What is NFPA 855?
NFPA 855 is the Standard for the Installation of Stationary Energy Storage Systems. The 2026 edition includes requirements and guidance covering commissioning, operation and maintenance, decommissioning, electrochemical energy storage systems, and related fire-safety topics. Always confirm which edition is enforced by the project AHJ.
Can a lithium-ion BESS fire be extinguished?
The answer depends on the battery configuration, stage of the event, protection systems, and incident conditions. Controlling visible flame does not necessarily mean thermal runaway inside affected cells has stopped. Response may need to prioritize cooling, prevention of propagation, exposure protection, gas monitoring, site isolation, and re-ignition monitoring in addition to flame suppression.
Does every BESS need the same fire suppression system?
No. The appropriate approach depends on battery chemistry, architecture, enclosure design, fire-test evidence, installation conditions, gas and explosion hazards, adopted codes, and AHJ requirements. Protection should be justified for the specific installation rather than selected from a universal rule.
What should a BESS emergency response plan include?
At minimum, it should address responsibilities, notification, site access, shutdown and isolation, electrical and battery hazards, coordination with first responders, evacuation or isolation considerations, air monitoring where appropriate, water and runoff management, emergency contacts, post-incident monitoring, re-ignition risk, recovery, and disposal.
Final Takeaway
The strongest BESS safety programs do not rely on one device, one chemistry, one test, or one code provision. They build a chain of defenses:
cell quality → battery management and electrical protection → thermal control → early detection → isolation and propagation control → fire and explosion protection → emergency response → commissioning and maintenance → disciplined change management
Standards such as UL 9540, UL 9540A, NFPA 855, the applicable fire code, and relevant IEC requirements provide the framework and evidence. The project team still has to translate them into the exact product, site, operating environment, emergency plan, and lifecycle procedures being used.

