Energy digitalisation: the GB stack
By the end of this module you will be able to:
- Describe the GB energy digitalisation governance stack and say which organisation owns each layer
- Apply the presumed-open default and the five Open Data Triage sensitivities to a real dataset
- Assess a Digitalisation Strategy and Action Plan against the guidance that requires it
- Describe the Data Sharing Infrastructure, its peer-to-peer design, and its published delivery window
- Read market-wide half hourly settlement as an industry-wide data migration rather than a system release
- Connect digital twins, flexibility, and the security questions now being asked of open energy data
Five instruments, five owners, and only one of them carries a consequence.
On 23 March 2026 the Department for Energy Security and Net Zero and Ofgem published the Energy Digitalisation Framework. The GOV.UK publication page says the framework provides clarity, coherence and direction to an energy digitalisation landscape characterised by high levels of activity but limited system-wide alignment. That sentence is a diagnosis, and it is unusually candid. Great Britain has never been short of energy digitalisation projects. What it has been short of is a shared picture of who is responsible for which part of the result.
The framework answers that with two devices. It introduces a digitalisation coordination function to provide and maintain system-wide architectural coherence, common standards and alignment across the sector, and it establishes a data domain model that groups digitalisation activity into four functional domains, each with clear responsibilities. Neither device is a licence condition. Both sit above the layer where a regulator can act.
The layer where a regulator can act is Ofgem's Data Best Practice Guidance. Its publication date is 01 April 2026, and the document states that its requirements must be complied with by companies whose licences are subject to the RIIO-GD3, RIIO-T3 and RIIO-ED2 price controls. A framework sets direction. A licence-linked requirement sets consequence. Everything that follows depends on knowing which of the two you are holding.
When a network company says it is committed to open data, which document did it sign, and what happens if the data never appears?
Five organisations issue five different kinds of instrument about the same subject. The first job is to sort them by what happens when they are ignored.
19.1 Who owns what
, the National Energy System Operator, launched on 1 October 2024 with broad strategic oversight of both the electricity and gas systems, and stands operationally independent of Government and industry. That whole-system remit is the reason NESO now appears in three different roles in this stack: as a licensee with its own data duties, as the body coordinating shared data infrastructure for the sector, and as the author of a sector-wide digitalisation plan.
Ofgem sits above the licensees as the regulator. It issues two guidance documents that carry licence weight rather than advisory weight: the Data Best Practice Guidance, which governs how licensees handle energy system data, and the Digitalisation Strategy and Action Plan Guidance, which governs what they must publish about their own digitalisation. Both carry a publication date of 01 April 2026 and both bind companies whose licences are subject to the RIIO-GD3, RIIO-T3 and RIIO-ED2 price controls. Data Best Practice names its audience directly: gas distribution network companies, gas and electricity transmission network companies, electricity distribution network companies, and the electricity system operator.
Above Ofgem, the Department for Energy Security and Net Zero co-owns policy. The is the joint DESNZ and Ofgem statement of what a digitalised energy system should look like and how it should be governed over the long term. Alongside it, NESO published a Sector Digitalisation Plan in 2025, developed in partnership with Energy Systems Catapult and supported by Digital Catapult, Connected Places Catapult and the Royal Academy of Engineering. NESO states that the plan was developed in close collaboration with Ofgem and DESNZ and identified and mapped the digitalisation requirements essential to reach clean power by 2030.
At the market end sits , which Ofgem appointed to act as senior responsible owner and implementation manager for market-wide half hourly settlement. That appointment matters practically: a question about settlement data goes to the code body running the programme, not to the regulator that commissioned it. Getting the addressee right is most of the work in this sector.
The GB energy digitalisation governance stack
Five layers each name an owner and an instrument, and the reading note puts layer two first because regulation is the layer a regulator can act on, so the policy layer above it sets direction without placing an obligation on its own.
The GB stack runs policy, regulation, licensee duty, shared infrastructure, market delivery. Only the middle band is enforceable: Ofgem Data Best Practice and DSAP Guidance bind companies under the RIIO-GD3, RIIO-T3 and RIIO-ED2 price controls.
The licensee layer carries one rule that reverses the normal burden of proof about data, and one process that decides when the reversal does not hold.
19.2 Presumed open, and the triage that qualifies it
sets eleven principles. Ten of them describe how to make data usable: identify the roles of stakeholders, use common terms, describe data accurately using industry standard , provide supporting information, make assets discoverable, learn from data users, prioritise quality against user needs, keep assets interoperable, protect them, and store them so access is sustained. The eleventh changes the default position of the whole sector.
“Treat all Data Assets, their associated Metadata and Software Scripts used to process Data Assets as Presumed Open.”
Ofgem, Data Best Practice Guidance, principle 11 - Version V3.3, publication date 01 April 2026
The scope of the principle is wider than most people expect on first reading. It is not only the dataset. It is the metadata that describes the dataset and the software scripts that process it, which means a licensee that publishes a feeder loading extract but keeps the transformation script closed has not met the principle. The guidance defines Presumed Open as the treatment of those three things as Open Data, subject to Open Data Triage, so the qualifier is built into the principle rather than bolted on afterwards.
reverses the burden of proof. A data user does not have to justify a request. The data custodian has to produce evidence that an asset should be withheld or its availability reduced. The evidence has to come from a defined list, and this is where most practitioners go wrong: Open Data Triage is not an open-ended assessment. The guidance limits the sensitivities to five. They are sensitivities that relate to people's rights to personal privacy, security needs, obligations from legislation or regulation, commercial requirements that if not protected will have a negative impact on products and services for end-consumers, and anything that would have a negative impact on the Public Interest.
Finding a sensitivity does not end the process, and this is the second common error. Where a sensitivity is identified, triage also determines how the custodian can mitigate the risk associated with it while still making the asset, its metadata and its scripts as open to stakeholders as possible. The guidance names two levers: processing the data, and providing different levels of access to different types of stakeholder. A yes on one of the five tests is an instruction to redesign the release, not permission to close the file.
Take a worked example. A distribution licensee holds half hourly loading data for low-voltage feeders, joined to the count of connected customers per feeder. Test one bites in the tail of the distribution, because a feeder serving three properties makes the consumption of a household identifiable. Test two is arguable, because feeder-level loading maps the network. Tests three, four and five do not obviously apply. The triage output is therefore not withdrawal. It is a minimum-count threshold below which feeders are aggregated, a published release above the threshold, and a controlled route for researchers who need the tail. Two levers, one dataset, one decision recorded.
The status of presumed open is now itself in question. Ofgem published a consultation on 29 May 2026 titled Securing open data in energy, which asks for views on three models for triaging data before publication: a centralised model, a hybrid model and an educational model. Its stated reason is that hostile state actors and terrorists have targeted energy infrastructure, and that the increased use of AI has changed how open data might be used. That consultation closed on 15 July 2026 and the page records it as awaiting decision, so the triage arrangements described above are the current ones and the model that replaces them has not been settled.
Common misconception
“Presumed open means a network company must publish everything it holds.”
It means the opposite of a request-driven regime, not the absence of judgement. The default is open, and the custodian carries the burden of evidence, but the guidance supplies five named sensitivities that can qualify the default. What it does not supply is a route to a simple no. Where a sensitivity is found, triage moves on to how the risk can be mitigated while keeping the asset as open as possible, using processing or tiered access. A licensee whose triage record ends at the word withheld has stopped halfway through the process.
Open Data Triage and the presumed-open default
The burden of proof sits with the data custodian and the five tests look for sensitivity, but neither outcome is to withhold, because a sensitivity found by any test sets the mitigation and the level of access rather than closing the asset.
Presumed open is a default with an escape route, not a publishing rule. Ofgem Data Best Practice Guidance limits Open Data Triage to five sensitivities, and a sensitivity means mitigate and open as far as possible, not withhold.
Data Best Practice governs the data itself. A second Ofgem document governs what a licensee has to say in public about its own digitalisation, and how often.
19.3 Digitalisation strategies and action plans
A is a combination of two separate artefacts. The Digitalisation Strategy is the licensee's strategic approach to digitalising its products and services. The Digitalisation Action Plan is the plan to do it. Ofgem's guidance describes their purposes as distinct rather than overlapping: the strategy shares the licensee's understanding of stakeholder needs and what is required to meet them, with the goal of creating consumer and public interest benefits.
“The purpose of a Digitalisation Action Plan is to show that a licensee is making progress towards delivering the work required to fulfil its Digitalisation Strategy.”
Ofgem, Digitalisation Strategy and Action Plan Guidance, paragraph 2.2 - Version V3.3, publication date 01 April 2026
Read the verb. The action plan exists to show progress, which is why the guidance sets a publication schedule rather than a content template alone. An action plan republished unchanged is evidence of no progress, and it is public evidence, which is what makes DSAPs the cheapest available intelligence on what a network company has actually committed to build.
The schedule is asymmetric by design, because the two artefacts change at different rates. For RIIO-3 licensees, the guidance requires the Digitalisation Strategy update to be published on or before 31 March 2028 and at least every two years after that date, and the Digitalisation Action Plan update on or before 30 June 2026 and at least every six months after that date, meaning each subsequent 31 December and 30 June. For RIIO-ED2 licensees the same shape applies on earlier anchors: the strategy on or before 1 April 2023 and at least every two years, and the action plan on or before 30 June 2023 and at least every six months.
Assessing a published DSAP is therefore a two-part job. The first part is the calendar. Find the publication date on the current action plan and check it against the anchor and the six-month cadence for that licensee's price control. A plan that is more than six months old is a compliance question before it is a quality question.
The second part is the seven principles the guidance sets. A DSAP should prioritise benefits to the stakeholders who pay for the products and services as well as benefits in the public interest; ensure products and services work towards a defined vision; take advantage of opportunities to deliver benefits early and iterate; enable stakeholders to understand the products and services, the status of their delivery and how to access them; ensure visibility about the nature and status of actions in the action plan; ensure shared understanding of how success and performance are measured; and coordinate with the wider ecosystem of products and services.
Principle five is the one that separates a plan from a brochure. The guidance requires visibility about the nature and status of the actions, so an action list with no status column fails the test on its face. Principle one is the one that separates a plan from an IT roadmap: for each product, service or action, the licensee must be clear about which stakeholder need it meets and what benefits it will deliver to end-consumers or the public interest, and must include a summary of stakeholder feedback and how it is responding to it.
Published plans and published datasets solve the problem of finding data. They do not solve the problem of moving it between organisations that do not trust each other with a copy.
19.4 The Data Sharing Infrastructure
The is described by NESO as a socio-technical solution that makes it easier for the energy sector to share data and models in a scalable, secure and resilient way by bringing together common processes, governance and technology. The phrase socio-technical is carrying weight. Most of the DSI is agreement about identity, permission and meaning; the software is the part that follows.
Two design decisions define it. The first is ownership: each participating organisation retains full ownership, responsibility and control over the data it shares, including how and under what conditions it is made available. The second is topology: all transactions are peer to peer, with no data passing through the Data Sharing Mechanism, which NESO describes as the control plane or broker at the centre of the DSI ecosystem and which holds a central metadata catalogue for data discovery. Together they sidestep the question that has stalled most sector data platforms, which is not technical but political, and is simply who gets to hold everyone else's data.
That topology also changes what an analyst can do. If data never lands in one place, cross-organisation analysis has to run where the data already sits, which is the pattern behind . The trade is real: no central copy to leak, but far harder joins, and a much greater dependence on the parties agreeing what a field means before anyone queries it.
NESO is accountable for developing and operating the DSI and holds the role of interim DSI coordinator, providing governance, oversight and coordination on behalf of the sector. The published delivery path runs through discovery, alpha, private and public beta, and live, with a minimum viable product phase focused on the regulated networks and open to other organisations able to deploy at pace. Public beta and full live releases are planned for 2028 to 2030. That window is worth holding on to when a supplier promises DSI-based delivery inside the current price control period.
A peer-to-peer design moves the hard problem rather than removing it. Nobody has to surrender custody of their data, so nobody can be blamed for holding it. In exchange, every participant now has to agree on identity, permission and vocabulary before a single query runs, and there is no central team that can quietly fix a mismatch.
The DSI is the sector learning to move data it already has. The next programme is the sector moving every metering point in Great Britain onto a different settlement basis.
19.5 Half hourly settlement as a data migration
Ofgem describes the electricity settlement process as placing incentives on suppliers to buy energy to meet their customers' demand in each half hour of the day. That half hour is the , and it is the unit every commercial consequence in the GB electricity market is eventually expressed in. Consumers without half hourly capable meters have been settled using estimates of consumption for each half hour, which means the market has been trading against a model of demand rather than a measurement of it.
replaces the estimate with the meter reading. Stated that way it sounds like a system change. It is not. It is a migration of every metering point in the market onto new arrangements, running while the market continues to settle, which is why the programme milestones are expressed in what has moved rather than in what has shipped.
The published milestone ladder makes the distinction visible. The MHHS Programme records milestone 10, central systems ready to migrate meter point administration numbers, as approved on 24 September 2025, and milestone 13, the load shaping system switched on, on the same date. Milestones 11 and 12, both approved on 21 October 2025, are described as the commencement of an 18-month migration, first for unmetered supplies and advanced metered points and then for smart and non-smart metered points. Milestone 14, all suppliers must be able to access meter point administration numbers under the new target operating model, is dated 28 October 2026. Milestone 15, full transition complete, is dated 7 May 2027. Milestone 16, cutover to the new settlement timetable, is dated 2 July 2027.
Read those as a data engineer would. There is a readiness gate before any record moves. There is a long dual-running period in which two populations of metering points are settled under two sets of rules at once, and reconciliation between them is the actual risk. There is a completion milestone for the population, and only then, months later, a cutover milestone for the timetable the whole market runs on. The sequencing is the standard shape of a large migration, and the 56 days between milestone 15 and milestone 16 are a stabilisation period rather than slack.
Market-wide half hourly settlement milestone ladder
The rows run from central systems ready to migrate MPANs, through an eighteen-month migration for unmetered, advanced, smart and non-smart MPANs, to full transition and cutover, counting progress in metering points moved rather than in releases delivered.
MHHS milestones move metering points, not releases. The MHHS Programme records M11 and M12 approved on 21 October 2025 opening an 18-month migration, full transition complete on 7 May 2027, and cutover to the new settlement timetable on 2 July 2027.
Settlement data at half hourly granularity is what makes flexibility saleable. It is also what makes the sector a more attractive target, and both consequences are now being legislated for.
19.6 Twins, flexibility, and the security question
A in this sector is not a visualisation exercise. What separates a twin from a model is the live connection to the physical thing it represents and the feedback it enables into that thing. In the GB context that connection is exactly what the DSI is being built to carry, which is why NESO houses the DSI inside its virtual energy system work rather than treating it as a standalone data platform.
The commercial pull comes from flexibility. The , published jointly and updated on 13 July 2026, defines clean flexibility as the ability to shift in time or location the demand or supply of electricity, over hours, days or seasons, while reducing emissions. It sets an increase to 51 to 66 GW of clean flexibility by 2030, from 24 GW in 2023. Shifting demand only pays if the shift is measured in the half hour it happened in, which is the direct line from settlement reform to a flexibility market.
The roadmap's data commitments are the ones to track. It states that by the end of 2026 DESNZ will amend electricity suppliers' licence conditions to require them to make tariff data available to domestic consumers in a standardised format, that government will consult by early 2026 on approaches to enable open data communication between electric vehicles, chargepoints, energy suppliers and aggregators, and that government will explore whether enhanced data sharing through a could create a trusted environment for new products. It also states that DESNZ will introduce new consumer protections and cyber security measures for load controllers and flexibility service providers by the end of 2027, through a new licensing scheme administered by Ofgem. The early 2026 consultation date has already passed, which makes it the first of the roadmap commitments an analyst can test against what has actually been published rather than against what has been promised.
Running alongside that is the , introduced to Parliament on 12 November 2025. GOV.UK factsheets updated on 30 June 2026 set out its intended effect on this sector: data centres would be classed as essential services and data infrastructure as a network and information systems sector, medium and large managed service providers would be brought into scope, large load controllers would be brought into scope to reduce the risk of grid disruption, and regulators would be able to designate critical suppliers to essential services. On reporting, the factsheets describe an initial notification within 24 hours and a fuller report within 72 hours. On penalties they say the maximum financial penalty will be amended to enable potentially higher penalties where appropriate and proportionate, and they state no figure. The factsheets describe phased commencement, with future-proofing and post-implementation review provisions from day one, the statement of strategic priorities and information sharing at month two, and most substantive measures brought in through secondary legislation.
The two instruments pull against each other on the same data. One pushes energy data out by default. The other prepares to pull load-controlling organisations into a security regime with a 24-hour reporting clock. Ofgem's 2026 triage consultation is the place where the two meet, which is why its outcome will matter more to a practitioner than any of the strategy documents above it.
A distribution licensee holds a dataset of half hourly substation loading joined to the number of connected customers per feeder. Its data team concludes that feeders with fewer than five connected customers make individual household consumption identifiable. Under Ofgem's Data Best Practice Guidance, what is the correct outcome of Open Data Triage?
A RIIO-3 network licensee published its Digitalisation Action Plan on 30 June 2026 and has not republished since. In February 2027 an analyst reviews it. Which statement is accurate under Ofgem's Digitalisation Strategy and Action Plan Guidance?
A supplier proposes an architecture in which every network company sends a nightly copy of its asset and loading data to a central sector data lake, which then serves all cross-organisation analysis. How does this compare with the Data Sharing Infrastructure as NESO describes it, and what follows for the analysis it supports?
Core distinctions
- The GB stack has five layers with five owners. Only the Ofgem guidance layer is licence-linked: Data Best Practice Guidance and Digitalisation Strategy and Action Plan Guidance, both carrying a publication date of 01 April 2026, bind companies whose licences are subject to the RIIO-GD3, RIIO-T3 and RIIO-ED2 price controls.
- Presumed open covers the data asset, its metadata and the software scripts that process it. Open Data Triage is limited to five sensitivities, and finding one is an instruction to mitigate through processing or tiered access, not permission to withhold.
- Ofgem consulted on centralised, hybrid and educational triage models on 29 May 2026, citing hostile state actors and the effect of AI on how open data might be used. That consultation closed on 15 July 2026, so the triage arrangements to teach are the current ones.
- A DSAP is two artefacts on two clocks. For RIIO-3 licensees the strategy update is due on or before 31 March 2028 and at least every two years, and the action plan on or before 30 June 2026 and at least every six months. Check the calendar before the content.
- The Data Sharing Infrastructure keeps every organisation in full ownership and control of what it shares and moves data peer to peer with nothing passing through the Data Sharing Mechanism at its centre. NESO plans public beta and full live releases for 2028 to 2030.
- Market-wide half hourly settlement is an industry-wide data migration. The MHHS Programme publishes milestone 15, full transition complete, on 7 May 2027, and milestone 16, cutover to the new settlement timetable, on 2 July 2027.
- Flexibility and security pull in opposite directions on the same data. The Clean Flexibility Roadmap of 13 July 2026 commits to opening tariff data, while the Cyber Security and Resilience Bill introduced on 12 November 2025 would bring large load controllers into a regime with a 24-hour initial notification.
Standards and sources cited in this module
Ofgem, Data Best Practice Guidance
Version V3.3, publication date 01 April 2026
Source for the eleven principles, the presumed-open definition, the five Open Data Triage sensitivities and the mitigation duty, and for the statement that its requirements bind companies under the RIIO-GD3, RIIO-T3 and RIIO-ED2 price controls. Quoted in Section 19.2.
Ofgem, Digitalisation Strategy and Action Plan Guidance
Version V3.3, publication date 01 April 2026
Source for the purpose of a strategy and an action plan, the seven DSAP principles, and the publication schedules for RIIO-3 and RIIO-ED2 licensees used in Section 19.3.
Ofgem, Securing open data in energy: triage in Data Best Practice guidance
Consultation published 29 May 2026, closed 15 July 2026
Source for the three proposed triage models and for Ofgem's stated reasons for reopening the question, cited in Section 19.2.
DESNZ and Ofgem, Energy Digitalisation Framework
Published 23 March 2026, GOV.UK
Source for the coordination function, the four-domain data model, and the description of a landscape of high activity but limited system-wide alignment used in the opening and in Section 19.1.
NESO, Data Sharing Infrastructure
Virtual Energy System programme page
Source for the socio-technical description, the ownership and peer-to-peer statements, the interim coordinator role, and the 2028 to 2030 public beta and live window used in Section 19.4.
MHHS Programme, Key Programme Milestones
mhhsprogramme.co.uk
Source for every milestone date used in Section 19.5 and in the sequencing exercise, including M14 on 28 October 2026, M15 on 7 May 2027 and M16 on 2 July 2027.
DESNZ, Ofgem and NESO, Clean Flexibility Roadmap
Updated 13 July 2026, GOV.UK
Source for the definition of clean flexibility, the 51 to 66 GW by 2030 figure against 24 GW in 2023, and the tariff data, smart data and licensing commitments cited in Section 19.6.
GOV.UK, Cyber Security and Resilience (Network and Information Systems) Bill factsheets
Summary of the Bill, updated 30 June 2026
Source for the scope expansions including large load controllers, the 24-hour and 72-hour reporting description, the phased commencement, and the statement that the maximum financial penalty will be amended without a figure being given. Used in Section 19.6.
Published 12 November 2025, last updated 30 June 2026
Source for the statement in Section 19.6 that the Bill was introduced to Parliament on 12 November 2025, which the summary factsheet itself does not carry.
NESO, Sector Digitalisation Plan
Project page, plan published 2025
Source for the partnership with Energy Systems Catapult, the support from Digital Catapult, Connected Places Catapult and the Royal Academy of Engineering, and the collaboration with Ofgem and DESNZ on the requirements for clean power by 2030, cited in Section 19.1.
NESO, National Energy System Operator launches today
1 October 2024
Source for the NESO launch date, its strategic oversight of both the electricity and gas systems, and its operational independence, cited in Section 19.1.
Ofgem, Electricity settlement: moving to half hourly settlement
ofgem.gov.uk guidance
Source for the description of settlement incentives in each half hour and for settlement on estimates where meters are not half hourly capable, used in Section 19.5.
The GB energy sector is the clearest available worked example of digitalisation under regulation: published duties, dated plans, a shared infrastructure with a delivery window, and a security review running against an openness default. Every judgement made here has a document behind it, which is the standard worth carrying into any sector. Telling a framework from a licence-linked requirement, and mitigation from withdrawal, is the same close reading the two papers reward, where one qualifying word usually separates two defensible options. The course revision guide gathers those distinctions stage by stage and sets out how each paper is marked.
Module 23 of 28 · Strategy, trust and sector