Automation Glossary • DCS hot cutover

What Is a DCS Hot Cutover During Migration?

Merobix Engineering • • 7 min read

Every distributed control system eventually reaches the end of its supported life, and replacing one is among the most daunting projects a plant can face because the plant depends on it to keep running. A hot cutover is the approach that avoids the alternative of a total shutdown: the new system is brought in while the old one keeps controlling, and the process is moved across in stages. This guide explains what a DCS hot cutover is, how loop-by-loop and marshalling-reuse strategies make it possible, the risks it carries and how they are controlled, and why operators choose it over stopping the plant.

Back to Blog

DCS hot cutover in one line: A DCS hot cutover is a migration in which an ageing or obsolete control system is replaced with a new one while the plant continues to operate, moving control from the old system to the new one in stages rather than during a full shutdown. Loops are typically transferred a few at a time, often reusing existing field wiring and marshalling, so that at any moment most of the plant is still under stable control and only a small, well-prepared slice is being switched over.

Migrating While the Plant Keeps Running

When a DCS becomes obsolete, spare parts grow scarce, support ends, and the risk of an unrecoverable failure climbs, so it must be replaced. The straightforward way to replace it would be to shut the plant down, remove the old system, install the new one, and start up again, but for many continuous processes a long shutdown is enormously costly or operationally unacceptable. A hot cutover exists to avoid that. The new system is installed alongside the old one, and control is handed over gradually while the process continues to run, so production is disrupted as little as possible.

The essence of a hot cutover is that the old and new systems coexist during the transition. The new controllers and I/O are installed, configured, and thoroughly tested offline, and then, section by section, the field signals and control are moved from the old system to the new. During this period part of the plant runs on the legacy system and part runs on the new one, and the two must interoperate cleanly, with careful attention to any loops or interlocks that span the boundary between them. The migration is choreographed so that the plant is never left without stable control of the parts that are running.

This makes a hot cutover as much an operations exercise as an engineering one. Each step is planned around the state of the process, executed at a chosen moment, and immediately verified, with the ability to fall back if something does not behave as expected. The pace is set by what the process can safely tolerate, not by how fast the wiring could be moved. Done well, the plant experiences a series of small, controlled transitions rather than one large, risky event, and keeps making product throughout.

Loop-by-Loop and Marshalling-Reuse Strategies

The most common way to keep a cutover manageable is to move it loop by loop, or in small groups of related loops, rather than all at once. A handful of signals are transferred to the new system, checked against the old readings, placed in control, and confirmed stable before the next group is touched. Working in small increments keeps the scope of any single step small, so that if something goes wrong it affects only that slice and can be corrected or reversed quickly. It also lets the team build confidence and refine their procedure as the migration proceeds.

A major enabler of a smooth cutover is reusing the existing field wiring and marshalling wherever possible. The field instruments and the cables running back to the control room are usually sound and expensive to replace, so migration designs often keep them and change only what sits behind the marshalling. Techniques such as installing new I/O that can accept the existing terminations, or providing interposing arrangements at the marshalling, let a signal be moved from the old system to the new by reterminating or reconfiguring at a single point rather than rewiring from the field. This shrinks both the work and the risk of each transfer.

These strategies work together. Reusing marshalling means each loop's move is a small, local operation at a known point; moving loop by loop means those small operations are sequenced so the plant is never broadly disturbed. Some migrations use specialised connection systems designed precisely to make signal-by-signal transfer fast and reversible. The overall aim is to make each cutover step as small, as quick, and as recoverable as it can be, so the accumulated risk of migrating an entire plant is broken into many low-risk pieces.

Managing Risk and the Supervisory Perspective

A hot cutover carries real risk precisely because it is done on a live plant, so risk control is the heart of the plan. The new system is proven out as far as possible before any live loop is moved, through offline testing, simulation, and staged commissioning, so that cutover day is executing a rehearsed procedure rather than discovering problems. Each step has clear success criteria, a defined fallback, and a moment chosen for a stable, quiet process state. Operators are briefed on what will change and how the plant should respond, and safety-critical interlocks get particular scrutiny wherever they cross the boundary between old and new.

Verification is continuous throughout. As each loop moves, its readings and behaviour on the new system are compared against expectations and against the old system's history, so that a discrepancy is caught immediately rather than discovered later. Keeping the old system available until the new one has proven itself gives a route back if a step misbehaves. The discipline is to advance only when the current step is confirmed good, so the migration is a chain of verified small transitions rather than a leap that must simply be trusted.

A supervisory or SCADA layer supports this verification strongly, because it holds the history and the live view that let a team judge whether a migrated loop is behaving. Trended data from before the move gives a baseline; the live values after the move show whether the new control matches it. For operations spread across sites, or for teams supporting a migration remotely, a cloud SCADA platform such as Merobix that collects and trends the process data provides a consistent, independent view of how each loop looks before and after cutover. That continuity of monitoring across the transition helps confirm that the process is under control at every step, whoever is doing the switching and wherever they are watching from.

Frequently Asked Questions

Why do a hot cutover instead of shutting the plant down?

A full shutdown to replace a DCS can be extremely costly for a continuous process and is sometimes operationally unacceptable, so a hot cutover moves control to the new system in stages while the plant keeps running. This avoids or greatly shortens lost production. The tradeoff is that the migration must be carefully choreographed on a live plant, with each step planned, verified, and reversible.

How does reusing marshalling help a hot cutover?

Field instruments and the cables running back to the control room are usually sound and costly to replace, so migrations reuse them and change only what sits behind the marshalling. Using new I/O that accepts existing terminations, or interposing at the marshalling, lets a signal move from the old system to the new by reterminating or reconfiguring at one point rather than rewiring from the field, which shrinks the work and risk of each transfer.

How is risk controlled during a live DCS migration?

The new system is tested and proven offline before any live loop moves, the migration is broken into small loop-by-loop steps each with success criteria and a fallback, and the old system stays available until the new one is proven. Each moved loop is verified against baseline history and live readings before the next step proceeds. Safety interlocks crossing the old-new boundary get special scrutiny, and steps are timed for stable process states.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
Controller loading  •  Distributed I/O node  •  ISA-88 unit procedure  •  ISA-88 equipment module  •  recipe phase  •  batch sequencer  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →