Skip to content
§
§ · build vs buy

SCADA Alarm Management Software: Custom Build vs Off the Shelf

Single vendor sites should buy. If your estate is Honeywell end to end, DynAMo is already native inside Experion and will beat anything commissioned from scratch. The decision flips on estate mix and licensing model, not on site size.

Custom Software Development code editor and API illustration for Scada Alarm Management Software Build vs Buy Guide.
The short answer

Single vendor sites should buy. If your estate is Honeywell end to end, DynAMo is already native inside Experion and will beat anything commissioned from scratch. The decision flips on estate mix and licensing model, not on site size. Build when alarms arrive from three or more control system vendors, or when per tag pricing on a distribution network has made a packaged suite absurd at your point count.

What the off the shelf products actually do well

This category has mature products and it is worth being precise about their strengths, because two of them will genuinely beat a build for a large share of readers.

Hexagon PAS PlantState Suite is the most capable product here and nobody should pretend otherwise. It carries a master alarm database, management of change workflow and multi vendor configuration reading across a very wide list of control systems. For a refinery or chemical site with dedicated alarm management staff and the budget, it is a defensible purchase and we would not compete for that work.

Honeywell DynAMo Alarm Suite is genuinely good and genuinely native inside Experion. If your distributed control system is Honeywell throughout, buy it and stop reading. It reads configuration more faithfully than any outside team can, because it is the same company that wrote the configuration format.

TiPS has been doing alarm analytics longer than most and the mathematics are sound. Yokogawa, Emerson and AVEVA all ship analysis tools that read their own systems well. Every one of these implements the ISA 18.2 and IEC 62682 lifecycle competently, and none needs writing again.

Buy also if you cannot name the engineer whose job includes owning the master alarm database. Software does not rationalise alarms, people do. A platform with nobody accountable for the record becomes another dashboard on the wall of a control room that already ignores several. Fix the accountability before spending anything, because that is free and it is the actual constraint.

Where they stop: a mixed estate with your own asset hierarchy

Walk into a utility control room at shift change and look at the alarm summary. Sixty or seventy entries are standing and the incoming operator scrolls past every one without reading, because they were standing yesterday too. Half are communications failures on remote sites unreachable since a storm. A dozen are low level analogue alarms on a pump station where somebody set a deadband too tight a decade ago. Three come from a unit that was decommissioned and never removed from configuration.

ISA 18.2 defines a flood as more than ten alarms in ten minutes for one operator. EEMUA 191 puts a manageable steady state at roughly one alarm per operator every ten minutes. Most operations that have never measured come out many times above that and believed their alarm system was basically fine, because operators had learned to work around it.

The specific workflow packaged products model badly is not the analysis. It is the join between a rationalisation record and your own estate. Your alarms arrive from an OSI, a Survalent, a GE and a Schneider system, each with a proprietary schema. Your rationalisation has to tie back to your substation and station naming, your switching orders, your maintenance records and your operating procedures, not to a generic plant model built for a process unit.

Then there is drift. Everyone has done a rationalisation workshop: three weeks in a room agreeing cause, consequence of no operator action, the operator action, time available to respond, and a priority. It comes out as a spreadsheet, and it dies, because the control system keeps changing through capital projects, vendor upgrades and one engineer typing a setpoint at two in the morning during a trip. Six months later nobody can say which live alarms still match the approved record.

The arithmetic: per tag licensing versus a build at your point count

Run this with your own quote, because per tag pricing is where this decision is actually made and it is rarely on the first page of a proposal.

An illustrative shape. Suppose a packaged alarm management suite prices at $3 per monitored tag per year with a platform fee on top. A single process unit at 8,000 tags is $24,000 a year and you should pay it happily. A distribution utility with 250,000 points across substations, pump stations and remote terminal units is $750,000 a year, and it grows every time you commission an asset, which is the thing your capital programme exists to do.

Put the build beside that. A full programme platform at $180,000 to $450,000, with year two support at 15 to 20 percent annually, is roughly a single year of that subscription and considerably less thereafter. The crossover in this category is a tag count, and on the shape above it sits somewhere near sixty to eighty thousand tags. Below that, buy. Above it, the commercial model rather than the capability is what pushes utilities toward a build, and vendors know it.

The other number worth computing is not financial. Count consoles, then count control system vendors. At one vendor and two consoles, buy. At four vendors you need four answers plus a consolidation layer, and the consolidated view you actually wanted never appears no matter which product you choose.

What a custom build actually costs

From Digital Heroes delivery experience, a first release with alarm and event ingestion from your primary control system, normalisation, a metrics engine and a master alarm database holding the rationalisation record runs $60,000 to $140,000 and ships in 12 to 16 weeks. That is enough to publish real numbers per console and start killing bad actors. The full programme platform adding management of change, drift detection against live configuration, a shelving and suppression register with expiry enforcement, and conformance reporting against the ISA 18.2 lifecycle runs $180,000 to $450,000 across 6 to 12 months.

Data migration is 10 to 25 percent here and most of it is not alarm history. It is your existing rationalisation spreadsheets, which have to be reconciled against live configuration before they can become an authoritative record, and that reconciliation is where teams discover how far things drifted. Year two runs 15 to 20 percent of build cost annually, spent on control system upgrades that change export formats and on the new sites your capital programme adds.

Cost drivers specific here: the number of distinct control system vendors, since each is a separate extraction path with its own schema and quirks. Historian volume if you want years rather than a rolling window. Console and operator modelling, because alarm rate per operator requires knowing which points belonged to which console on which shift, and that mapping is rarely documented anywhere. And remote sites with no reliable network back to the control centre, which turn collection into a store and forward problem.

The four situations where building wins

Regulatory fit. Conformance evidence has to be shaped the way your regulator, your insurer or an incident investigator asks for it, not the way a vendor reports it. After an event the first question is what the operator was shown and when. If the answer is a screen with four hundred standing entries, your alarm system becomes the story, and the record you produce needs to sit inside your own asset hierarchy to mean anything.

Scale economics. Per tag commercial models were designed for process plants with tens of thousands of points, not for distribution networks with hundreds of thousands. When the licence scales with asset commissioning, it prices your capital programme.

A workflow that is your advantage. Write back is the case here, and the correct design is conservative. The platform proposes a change set from the master alarm database, routes it through your management of change with your approvals, generates the configuration artifact in the vendor's own import format, and verifies after an engineer applies it. It never writes to a live control system. That boundary is your operating discipline, and it is not configurable in a product.

Integration sprawl. Alarm and event data through OPC subscriptions here, a sequence of events file export there, a direct historian read somewhere else, plus a work management system and an asset register. Four or more sources and no consolidated view is the defining condition of an electric, water or gas utility, and it is the gap every product in this category shares.

How to decide in a week

This test is close to free and it settles the argument. Export one month of alarm and event history from your busiest console. Compute four numbers: activations per tag ranked descending, alarm rate per operator per ten minute interval, the count of periods exceeding the ISA 18.2 flood threshold, and the number of alarms standing beyond twenty four hours.

The top twenty tags will be roughly the same twenty a year from now unless somebody acts on them. That list is your business case, and it costs one afternoon of an engineer's time to produce. Take it to whoever controls the budget alongside the priority distribution, which in most control rooms is nothing like the roughly eighty percent low, fifteen percent high and five percent emergency shape EEMUA 191 suggests.

If those numbers are close to benchmark, you have a configuration job and no software will help. If they are far away, you have a programme, and now you can size it honestly.

Then buy a paid discovery phase. Digital Heroes writes a signed product requirements document before any code exists, covering the extraction path per control system, the master alarm database model, the change workflow and acceptance criteria. The specification is yours whether you build with us, build elsewhere or buy a product, and it is what keeps a fixed quote fixed.

We are the wrong firm if you want control system engineering, distributed control system configuration or people in your control room daily. We build the layer above the control systems and we do not touch them. Digital Heroes operates as an India LLP, a US LLC and a UK LTD so intellectual property assigns under your own law, and you meet the named engineers before signing. More than 2,000 delivered projects, over fifty specialists, our own products ShopScore, HeroCheckout and Section Vault, verifiable on Clutch, Trustpilot, Fiverr Vetted Pro and our D-U-N-S listing.

Book a 30-minute call with Digital Heroes and get a written plan and a fixed quote within 48 hours.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. Standish's 2015 CHAOS research found roughly a third of software projects (about 36% by the Modern definition) fully succeed on time, on budget, and on scope, with top success drivers including executive support, user involvement, and clear requirements/business objectives. Source: Standish Group (CHAOS Report) (2015) →
  2. Only 16% of respondents said their organizations' digital transformations had successfully improved performance and equipped them to sustain gains over the long term; even in digitally savvy industries such as high tech, media, and telecom, self-reported success rates did not exceed 26%. Source: McKinsey & Company (2018) →
  3. Qualtrics research (Q3 2023 survey of ~28,400 consumers across 26 countries) estimated bad customer experiences put roughly $3.7 trillion in global revenue at risk annually, a 19% jump from the prior year's $3.1 trillion; 64% of customers say they will switch companies over poor service regardless of how much they like the product. Source: Qualtrics XM Institute (via Forbes) (2024) →
  4. An earlier SHRM benchmarking report (reflecting fiscal year 2015, published 2016) established a widely cited baseline average cost-per-hire of $4,129, illustrating how recruiting costs have climbed over time (SHRM's separate 2025 Benchmarking Report shows $5,475 for nonexecutive roles). Note: the $5,475 figure is not on this linked page; it comes from SHRM's 2025 report. Source: SHRM (Society for Human Resource Management) (2016) →
FAQ

Frequently asked questions

How much does custom alarm rationalisation software cost for a utility?

A first release with alarm and event ingestion, normalisation, a metrics engine and a master alarm database holding rationalisation records runs $60,000 to $140,000 over 12 to 16 weeks in Digital Heroes delivery experience. A full programme platform adding management of change, drift detection, a suppression register and conformance reporting runs $180,000 to $450,000 across 6 to 12 months, plus migration at 10 to 25 percent.

What is an acceptable alarm rate per operator?

EEMUA 191 puts a manageable steady state at roughly one alarm per operator every ten minutes, and ISA 18.2 defines a flood as more than ten alarms in ten minutes for a single operator. Those are the benchmarks control rooms measure against. Compute your own from one month of alarm and event history before believing anything a vendor tells you about your current position.

Who owns the master alarm database if an agency builds the system?

You own the software, and one of your engineers owns the content. Both matter. Put code and infrastructure ownership in the contract before kickoff, and name the person accountable for the rationalisation record before the project starts. At Digital Heroes the client owns the repository and cloud accounts from the first commit, but no contract clause can supply the internal owner, and without one the record drifts again.

What is the difference between alarm monitoring and alarm management?

Monitoring shows an operator what is alarming now and records it. Management is the lifecycle around that: deciding which alarms should exist, agreeing cause, consequence, operator action and priority for each, holding those decisions in an authoritative record, detecting when live configuration drifts away from it, and measuring whether the result is workable. ISA 18.2 describes the second, and most sites only own the first.

Can software automatically fix nuisance alarms in the control system?

It should not, and any developer who treats that casually should be removed from the project. Changing configuration on a live control system carries warranty and safety consequences, and a deadband change on the wrong tag suppresses something doing its job. The correct pattern is propose, approve through management of change, generate an artifact in the vendor import format, then verify after an engineer applies it.

How long before operators notice a difference?

Measurement changes behaviour before configuration does. Publishing six honest numbers per console monthly, activations by tag, flood periods, chattering and stale counts, priority distribution and response times, shifts attention within weeks. Actual relief arrives once the top bad actors are corrected, which is typically one to three months after first release depending on how quickly your change board moves and how many need field work.

Does alarm management work across several SCADA and DCS vendors?

That is precisely the case for a custom build. Each vendor is a separate extraction path with its own schema, and the consolidated view is the deliverable. Ask any developer how they will get alarm and event data out of each of your systems by name, expecting specifics such as an OPC subscription here and a sequence of events export there. Vague talk of connectors means they have not looked.

What data do we need before starting an alarm management project?

One month of alarm and event history from your busiest console, the alarm configuration export from each control system, your existing rationalisation spreadsheets however stale, and a console to point mapping showing which alarms reached which operator on which shift. That last one is usually undocumented and is the common reason a project stalls in week three, so start reconstructing it now.

Is Hexagon PAS worth it for a small single vendor site?

For a single vendor process site with dedicated alarm staff and a matching budget, PAS PlantState Suite is a strong purchase and the integrated product will read your configuration more faithfully than an outside team can. Where it strains for utilities is commercial structure, since pricing scales with tag counts that get uncomfortable across a distribution estate, and organisational weight it assumes you have.

What happens if we do nothing about a standing alarm list?

Nothing measurable, until an incident. Operators keep acknowledging in batches, the genuinely important alarm arrives inside the noise, and the practice is invisible on any report you currently produce. The exposure only becomes visible afterwards, when an investigator asks what the operator was shown and when, and the answer is a screen nobody had read since the previous shift change.

What are the biggest mistakes first-time software buyers make?

Choosing the lowest bid, paying more than 30-40% upfront instead of on milestones, skipping a written specification, and having no maintenance plan for after launch. The most expensive of the four in Digital Heroes rescue projects is the missing spec: without written acceptance criteria, done becomes an argument instead of a checklist, and every disagreement resolves in the vendor's favor. Fix those four and you have avoided most of the ways these projects fail.

How long does it take from first call to software my team can actually use?

Plan for four to six months: two to three weeks of discovery, two to four weeks of design, then a 10 to 16 week build with testing. In Digital Heroes delivery experience the schedule killer is not engineering speed but decision lag; a client who takes two weeks to approve wireframes adds two weeks to launch. Book a weekly 30-minute decision slot before kickoff and most of that risk disappears.

Should we build an MVP first or go straight to the full system?

MVP first, for almost everyone: ship the single workflow that carries the business value in 10 to 16 weeks, learn from real users, then fund phase two from evidence instead of guesses. The caveat is that an MVP is a small version of a well-built system, not a badly built version of a big one; the data model must already support what comes next. An agency that cannot tell you what they deliberately left out of your MVP has not designed one.

Couldn't I just build my app in Bubble or another no-code tool instead of hiring an agency?

For validating an idea with real users, yes, and we tell clients that honestly. The walls come later: Bubble apps cannot be exported as code to run anywhere else, performance drops on complex data operations, and usage-based pricing climbs as you grow. A meaningful share of Digital Heroes custom builds are rebuilds of no-code MVPs that proved the business worked, which is the system operating as intended: validate cheap, then build the version that scales.

What should I prepare before contacting a software development agency?

A one-page brief beats a 40-page requirements document: the business problem in plain words, who will use the system, the 5 to 10 workflows it must handle, the tools it must connect to, and your budget range and deadline driver. You do not need wireframes, a specification, or technical vocabulary; producing those is the agency's job during discovery. Stating a budget range up front is the single best move, because it gets you honest scoping instead of a quote engineered to win the meeting.

Does it matter which tech stack the agency wants to use?

Yes, but not in the way most buyers expect: the goal is boring, popular technology such as React, Node.js or Python, and PostgreSQL, because any future team can maintain it and hiring a replacement developer takes days, not months. The red flag is an agency-proprietary framework or an unusual language, which welds you to that one vendor no matter what your contract says about code ownership. A useful test: could you find three freelancers fluent in this stack within a week? If not, push back.

What is a discovery phase, and is it worth paying for separately?

Pay for it, and treat the output as yours. A discovery phase runs two to three weeks, typically 5 to 10% of the eventual build budget, and produces a written scope, wireframes, and a fixed quote you can take to any vendor, including a competitor of the agency that wrote it. Skipping it is how projects end up quoted from a two-paragraph email and delivered at twice the price.

Who owns the code when an agency builds my software?

You should, completely, through a written intellectual property assignment that transfers everything on final payment; without that clause, copyright stays with whoever wrote the code by default. Insist that the repository lives in your own GitHub organization from day one and that hosting, domains, and third-party accounts are registered to you. Also check for licenses to the agency's proprietary frameworks buried in the contract, because those can make switching vendors practically impossible even when you own your own code.

How do I work out whether custom software will pay for itself?

Do the arithmetic on hours before anything else: if the system saves three staff eight hours a week at a $35 loaded hourly cost, that is about $43,700 a year against, say, a $70,000 build plus 15 to 20% annual maintenance, a payback around two years. Add revenue effects only if you can name them specifically, like faster quotes or fewer abandoned orders, not as vague growth. In our delivery experience the businesses that see payback inside 24 months are the ones automating a process they already measure.

How much should a small business budget for its first custom app or website?

For a focused first build, most small businesses land between $8,000 and $60,000: roughly $8,000 to $45,000 for a custom website and $25,000 to $60,000 for an internal tool or simple web app, based on Digital Heroes delivery across 2,000+ projects. Customer-facing products with payments, logins, or a mobile app start around $40,000. Quotes far below these bands usually mean a template with your logo on it, not software shaped around your workflow.

Who can build a custom software system?

Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading

Published · Last updated .

Online now

Hi there. How can we help you today?

Reply