Governed grid and customer workflows for municipal and regional utilities, beside your billing system
For Stadtwerke and regional utilities that run grid, supply, metering, heat and water on one IT team: build connection request handling, §14a device processes, market-process clearing and compliance evidence as production software with review points, traceability and code ownership.
Modernise around IS-U, Schleupen, Wilken, S/4HANA Utilities, GIS and your market communication system while the migration runs. Nothing we build lands in your billing system's change backlog.
Where it runs
Nuclicore-managed single tenant on Hetzner in Germany or Azure in the EU, or your own cloud (BYOC) and on-premise on Enterprise.
What it connects to
Billing and CRM (SAP IS-U and S/4HANA Utilities, Schleupen, Wilken, powercloud and others), GIS, meter data management and your market communication system via APIs, exports and database views.
What we do not touch
Grid control systems, SCADA, smart meter gateways and the market messages themselves. Your control room and your MaKo system stay as they are.
Who owns the code
You do. Each app is a standard React and Node repository with its own backend, running on a managed, encrypted Postgres database. Export it at any time, including for a public tender.
What utility teams evaluate first
These are the questions grid operations, the IT lead, the information security officer and the works council ask before a pilot gets a budget line.
Hosting in Germany
Nuclicore-managed on Hetzner in Germany or Azure in the EU, with BYOC or on-premise on Enterprise. No data leaves the EU unless you decide otherwise.
No access to grid control or OT
We do not connect to SCADA, grid control systems, RTUs or smart meter gateways. Apps consume exports and interfaces on the IT side that you approve.
Beside IS-U, not inside it
Workflows run as side-by-side applications against the billing system's interfaces. Your S/4HANA Utilities programme keeps its scope, its freeze and its cutover date.
Unbundling-safe, above and below the de minimis threshold
Informational unbundling applies even where legal unbundling does not. RBAC keeps grid data invisible to sales and sales data invisible to grid, and the separation is documented for your compliance officer.
Audit trail for regulators and auditors
Who raised, who reviewed, who approved, when, with what evidence. Exportable per case for regulator inquiries, KRITIS audits, internal audit and the supervisory board.
Evidence for NIS2 and KRITIS
Dependency scanning, secrets handling, CVE patching and a nightly ZAP scan run on every app. Release gates and logs give you documented technical measures for the applications you build.
Exit path for public procurement
Standard code, standard database, documented interfaces. The exit path is in place before the award, which is what your procurement rules ask for.
Built for how a municipal utility actually runs
Align scope, workflow ownership and governance per division, on one platform, with the separation the law requires.
Grid company (electricity and gas)
- Connection requests answered inside the 8-week window
- §14a devices registered with the reduction applied
- Every capacity decision with an approver on record
- Connection request intake, review and response
- §14a controllable device registration
- Installer portal and commissioning records
Supply and customer service
- Supplier switch exceptions cleared before the 24-hour window closes
- Tariff and dynamic tariff onboarding without manual rework
- Funding programmes with a payout record per application
- Market-process clearing and exception cases
- Tariff change and dynamic tariff onboarding
- Municipal funding and subsidy applications
Metering point operation
- Rollout notices, appointments and device changes tracked per metering point
- Rollout quota progress visible per grid area
- Access failures handled through a documented exception path
- Smart meter rollout appointment and change handling
- Device change and exception records
- Rollout progress reporting
Heat, water and further divisions
- Heat network connection requests handled like grid requests
- Inspection and maintenance rounds with evidence per asset
- Contractor work permits with the approver on record
- Heat network and water connection intake
- Asset inspection and maintenance rounds
- Work permits and contractor safety
Why delivery models are changing for municipal utilities
The utilities that ship fastest keep the billing core clean, move exceptions out of mail and treat compliance as running software.
Common Reality
One IT team, six divisions, and the billing clock runs out in 2027
Mainstream maintenance for SAP IS-U on ECC ends in December 2027 and the migration to S/4HANA Utilities takes 18 to 36 months. Meanwhile the regulator changes market communication formats twice a year. Every business request outside the migration waits.
Common Reality
Connection requests arrive faster than the grid team can answer
PV, heat pumps, wallboxes and storage generate hundreds of connection requests per month even at a mid-sized utility. The law expects an answer within eight weeks, and the Netzpaket makes digital connection portals mandatory for every request type. Mail and spreadsheets do not scale to that.
Common Reality
Resilience is now a documented obligation
KRITIS-Dachgesetz has applied since March 2026, and the federal states can set lower thresholds that bring regional utilities into scope. NIS2 treats energy as an essential sector with 24-hour incident reporting. Both ask for evidence that can be produced on request, not for a binder.
What you can build across grid, customer, metering and compliance
Deliver governed software around your systems of record, with review points, traceability and code ownership.
Grid and connection
Connection request intake and 8-week tracking
One digital intake for generators, storage and consumers, completeness check, acknowledgement, review by the grid planner and a response with the deadline visible on every case.
- Deadline tracking
- Completeness check
- Audit trail per request
Installer portal and commissioning
Registered installers submit commissioning records, protocols and photos; the grid team reviews and confirms; metering point operation is notified.
- Installer directory
- Document upload
- Status per case
§14a controllable device registration
Register heat pumps, wallboxes and storage above the threshold, assign the control module, apply the grid fee reduction and keep the record per metering point.
- Threshold check
- Grid fee reduction record
- Metering point link
Capacity information and reservation
Non-binding capacity information per grid area, reservation requests with expiry, and a decision record per capacity decision.
- Reservation expiry
- Decision record
- Per grid area
Customer and metering
Market-process clearing cases
Exceptions from the supplier switch, master data changes and meter readings land in one queue with the deadline, the owner and the fix, instead of in three mailboxes.
- Deadline per case
- Owner assignment
- Link to MaKo reference
Guided change of tariff, eligibility check for dynamic tariffs based on the metering system, consent and confirmation with a record per contract.
- Eligibility check
- Consent recorded
- Write-back to billing
Smart meter rollout appointments and device changes
Three-month notices, appointment booking, technician confirmation, device change record and the exception path when access fails.
- Notice tracking
- Appointment booking
- Exception handling
Applications for municipal or utility funding programmes with document checks, eligibility rules, approval and payout record.
- Eligibility rules
- Two-step approval
- Payout record
Compliance, heat and field
KRITIS risk analysis and resilience evidence
Structured risk analysis per critical asset, measures with owners and due dates, and the evidence file that can be produced for the authority or an on-site inspection.
- Per critical asset
- Measures with owners
- Export on request
NIS2 incident reporting workflow
Incident intake, classification, the 24-hour, 72-hour and final report steps with the responsible person on record and the submitted content archived.
- Reporting deadlines
- Classification
- Archived submissions
Work permits and switching requests
Contractor and crew work permits, switching requests to the control room as a documented request, approvals with time windows and closure with evidence.
- Time-windowed approval
- Contractor records
- Closure evidence
Heat planning data and heat network connection intake
Collect building and consumption data for municipal heat planning in a structured form, and handle heat network connection requests with the same intake, review and response pattern as grid requests.
- Structured data collection
- Per building or street
- Response with deadline
Fits your systems of record
Most ROI comes from removing manual handoffs between grid planning, customer service, metering and compliance, and from connecting to the billing system with clear ownership of every interface.
We build governed workflows around billing, CRM, GIS, meter data management, document management and your market communication system. We read what these systems expose and write back through their supported interfaces. We do not generate or process market messages, and we do not touch grid control or smart meter gateways.
What we need from you
- Interface specs or sandbox access for the billing system (APIs, exports or database views)
- Sample exports from GIS, meter data management or the market communication system
- One named owner per workflow on the business side and one on the IT side, per market role where unbundling applies
- The approval matrix: who may approve what, per division and per value
Integration patterns supported
- APIs and exports of your billing, CRM and GIS systems
- File exchange via SFTP (CSV, XML and the formats your systems already produce) with validation and error queue
- Read-only database views and scheduled extracts from meter data and asset systems
- Webhooks and events for status changes into billing, ticketing and mail
- Document handover to DMS and archive systems with retention metadata
Governed releases, stable production
- Scope is clarified and acceptance criteria are defined before implementation.
- Every change is a task with a reviewer, a preview and an approval record.
- Releases move through Preview, Test and Production, and any earlier release can be redeployed from the history.
- Division-specific configuration is data, not code, so one release serves all divisions.
- Market-role separation is enforced in the access model and documented for the compliance officer.
- Audit trail per case and per release, exportable for regulators, internal audit and the supervisory board.
Security and data controls for utilities
Each application runs its own backend, with a managed, encrypted Postgres per environment. Single-tenant infrastructure, BYOC and on-premise on Enterprise. Hosting in Germany or the EU by default.
RBAC, audit logs and monitoring keep access controlled per market role, division and function. Dependency scanning, secrets handling, CVE patching and a nightly ZAP scan run on every app, which gives you documented technical measures for NIS2 and for your ISMS. Your workspace content is not used to train models.
Security controls in practice
- Own backend per application, managed Postgres per environment with each application on its own table suffix, dedicated or single tenant databases on Enterprise.
- RBAC with market role, division and function scopes; SSO on Enterprise
- Audit log of every write action and sensitive read, exportable
- Dependency scanning, CVE patching and nightly ZAP scan on every app
- No OT or grid control access; integration only through IT-side interfaces you approve
What a first pilot at a municipal utility looks like
We align on one approval-heavy workflow and deliver reviewable increments with clear governance.
Scope, acceptance criteria, architecture outline
Pick one workflow (for example connection request intake, §14a registration or market-process clearing). Define market role, approval matrix, the billing fields to read and the records to write back.
First working version in Preview
Forms, routing, deadlines, approvals and the read integration to your billing or GIS exports. Grid and customer service users click through and comment in the task.
Test environment with real roles and real data
Division and market-role permissions, SSO if applicable, write-back to billing or DMS, audit trail export. Your IT and your information security officer review interface and access concept.
Production release and handover
Approval, release to Production, redeploy of an earlier version verified. Documentation for IT, the compliance officer and the works council. Decision on the next workflow.
Success criteria examples
- Every case in the pilot workflow closed with a complete approval chain and the deadline visible
- Audit trail export accepted by internal audit or the information security officer
- Billing interface documented and signed off by the system owner
- Zero changes to the billing system change backlog
Energy & Utilities FAQ
Answers for grid operations, IT, information security and customer service at municipal and regional utilities.
What does "governed" mean for grid and customer workflows?
Work is organised into reviewable tasks with acceptance criteria. Releases move through Preview, Test and Production with approval, and any earlier release can be redeployed. Every case carries who raised, reviewed and approved it, with timestamps and evidence. That is the trail regulators, KRITIS auditors, internal audit and the supervisory board ask for.
We are migrating from IS-U to S/4HANA Utilities. Can we still build?
Yes, and that is the typical starting point. Apps run beside the billing system against stable interfaces, not inside it. Nothing lands in the migration backlog, and when the cutover switches interfaces the app is repointed, not rebuilt.
Do you connect to grid control, SCADA or smart meter gateways?
No. We do not touch the control room, RTUs, SCADA or the smart meter gateway infrastructure. Apps consume IT-side exports and interfaces you approve. Your control system security concept stays untouched.
Do you handle market communication?
No. Market messages are generated and processed by your market communication system. We build the workflows around it: intake, clearing of exceptions, deadlines, approvals and the record of what was decided. The message itself stays where it is.
We have fewer than 100,000 connected customers. Does unbundling still matter?
Below the de minimis threshold you are exempt from legal and operational unbundling, but informational and accounting unbundling still apply. We build one app per market role where separation is required, with RBAC that keeps grid data invisible to sales and vice versa. The access model is documented so your compliance officer can sign it off.
Does this help with KRITIS-Dachgesetz and NIS2?
In two ways. The apps themselves run with dependency scanning, secrets handling, CVE patching, nightly ZAP scans and audit logs, which gives you documented technical measures for the applications you build. And the risk analysis, resilience plan evidence and incident reporting workflows are among the first things utilities build.
Can it run on-premise or in your own tenant?
Yes. BYOC and on-premise deployment are available on Enterprise. The default is Nuclicore-managed single tenant on Hetzner in Germany or Azure in the EU.
We run electricity, gas, heat, water and a pool. One app or five?
One app, one codebase, one release, unless unbundling requires a separate app for a market role. Division-specific fields, approvers and thresholds are configuration, not code. Deployment labels let you release per division or legal entity.
We are subject to public procurement rules. How does code ownership work?
Each app is a standard React and Node repository with its own backend, running on a managed, encrypted Postgres database, exportable at any time. You own the code and the data, and the exit path exists before the award. That is usually what the procurement office needs to see.
Who maintains the app after the pilot?
Your team, through the same platform: describe the change, review the task, approve the release. Security patches to dependencies are applied by the platform. If you want to take the code and maintain it in-house, you can.
What is not a fit?
Grid control, real-time operations, market message processing, billing itself and anything on the OT network. Nuclicore builds the governed workflows around these systems, not the systems.
Move grid and customer workflows out of mail and into governed software.
Ship beside your billing migration, unbundling-safe, with audit trail and code you own.