A 600-megawatt coal turbine weighs hundreds of tonnes, and when it spins at 3,000 revolutions per minute, that mass becomes a stabilizer the control room never has to ask for. Lose a generator somewhere on the system, and for the first few hundred milliseconds the stored rotational energy in every other machine pushes back against the frequency drop automatically. No signal, no dispatch, no software. The physics simply holds the line while operators and markets catch up.

That floor is eroding. As coal and gas plants retire and solar, wind, and batteries take their place, the spinning mass that used to absorb the first shock of any disturbance is leaving the system. Grid stability stops being a property the hardware provides for free and becomes something operators have to procure, configure, and prove. For a system operator, that is a different job than the one the control room was built for, and the renewables-heavy grids of Iberia, Australia, and Texas are already living it.

What grid stability meant when the machines were synchronous

For most of the last century, electric grid stability was an inheritance rather than a design choice. Synchronous generators, the coal, gas, hydro, and nuclear machines that anchored every large network, are physically locked to grid frequency. Their rotors turn in step with the alternating current, and that synchronism gives the power system three gifts at once.

The first is inertia. The rotating mass resists any change in frequency, buying milliseconds to seconds of breathing room after a fault. The second is a strong voltage reference: a synchronous machine actively forms the voltage waveform, holding it steady at the point of connection. The third is fault current and reactive power on demand, the short, heavy current surges that let protection systems detect and isolate faults cleanly. Operators rarely had to think about any of this. Power grid stability was a side effect of how electricity had always been generated.

Inverter-based resources behave differently. A conventional solar or battery inverter is a grid-following device: it measures the grid’s existing voltage and frequency, then injects current in step with what it sees. It is a fast, precise follower, and on a grid still dominated by synchronous machines that arrangement works well. The problem arrives when the followers become the majority. A system made mostly of devices that wait to be told what the voltage and frequency are has no one left setting the reference, which is why the choice between grid-forming and grid-following control has become a product decision rather than a configuration detail. The inherited stabilizer is gone, and nothing has automatically replaced it.

This is the structural reason renewable energy puts grid stability under pressure, and it runs deeper than the familiar story about solar and wind being intermittent across the day. The dominant way of connecting them to the grid removed the physical mechanisms that used to hold voltage and frequency steady in the critical first moments of a disturbance, which is why grid resilience is now largely a controls-software problem. Recognizing that shift is the starting point for every operator now planning a high-renewables system.

The three stabilities now under pressure

When the spinning mass thins out, instability does not arrive as one problem. It arrives as three, and the recent blackout post-mortems show all three converging.

Grid frequency stability is the most familiar. With less inertia on the system, frequency falls faster and further after the loss of a generator or a large load. The rate of change of frequency, the metric operators track as RoCoF, climbs steeply. Protection relays that were tuned for a high-inertia world can trip on that steep slope, disconnecting resources that the grid badly needs to keep, and turning a single fault into a cascade.

Grid voltage stability is the quieter and, on recent evidence, more dangerous of the three. Reactive power is what holds voltage within limits across a network, and synchronous machines supply or absorb it continuously without being asked. Strip them out, and voltage control becomes an active task that something has to perform deliberately. Voltage excursions that a synchronous fleet would have damped on their own can instead run away.

Oscillatory stability is the least intuitive. Large numbers of fast inverters, each running its own control loop, can interact with the network and with one another in ways that set off sustained or growing oscillations. These are not slow swings that operators can watch and manage. They build in fractions of a second, faster than a human or a market can respond.

Diagram titled Three Stabilities Under Pressure, showing how one trigger splits into three converging failure modes rather than a single problem. The shared trigger is synchronous mass leaving the system: coal, gas, hydro and nuclear machines retire, and grid-following inverters take their place while setting no voltage or frequency reference. That trigger splits into three failure modes. Mode one is frequency stability, tracked by the metric RoCoF, the rate of change of frequency: with less inertia, frequency falls faster and further after a generator trip, RoCoF climbs steeply, and protection relays tuned for a high-inertia world trip on the slope, turning one fault into a cascade. Mode two is voltage stability, driven by reactive-power control becoming an active task: synchronous machines supply or absorb reactive power continuously and unasked, so stripping them out means voltage control must be performed deliberately, and excursions a synchronous fleet would have damped can run away. Mode three is oscillatory stability, which builds in fractions of a second: large numbers of fast inverters, each running its own control loop, interact with the network and with one another to set off sustained or growing oscillations faster than a human or a market can respond.
One trigger, three failure modes. The blackout post-mortems show them converging rather than arriving one at a time.

The Iberian blackout of 28 April 2025 is the case study the whole sector is now studying. ENTSO-E’s analysis frames it as a multi-factor event, and the framing matters: there was no single cause, and it would be wrong to claim any one technology would have prevented it. ENTSO-E’s factual report from October 2025 documented that a population of grid-following inverters tripped offline on overvoltage as conditions deteriorated, withdrawing support at the worst possible moment. The final report from March 2026 placed the systemic weight on oscillatory behavior and inadequate voltage and reactive-power control, and concluded that even substantially higher system inertia, on its own, would not have prevented the loss of synchronism. That last finding is the one operators should sit with. More spinning mass alone was not the missing ingredient. The missing ingredient was active, fast voltage and frequency forming that the inverter fleet was not configured to provide.

The table below maps how each stability mechanism shifts as the generation mix flips from synchronous machines to inverter-based resources.

Stability mechanism Synchronous machines Grid-following inverters What must now supply it
Inertia / frequency response Rotating mass resists frequency change automatically, buying milliseconds to seconds after a fault No inherent inertia; output follows the frequency it measures Synthetic (virtual) inertia and fast frequency response from grid-forming storage
Voltage reference Actively forms the voltage waveform and holds it at the point of connection Measures existing voltage and injects current in step; sets no reference of its own Grid-forming control software that establishes and holds a voltage reference
Reactive power / voltage support Supplied or absorbed continuously, without being asked Provided only within configured limits, on command Deliberate reactive-power control, specified, dispatched, and verified
Fault current Short, heavy current surges let protection detect and isolate faults cleanly Current-limited by the power electronics Protection schemes retuned for inverter fault behavior
Oscillation damping Physical damping through mass and machine coupling Fast control loops can interact with the network and one another and excite oscillations Damping designed into control, tuned coordinately across the fleet
Table 1. Every mechanism that used to arrive free with rotating mass now has to be specified, configured, and proven.

Where stability services come from once the spinning stops

If the grid can no longer get stability for free from rotating mass, the obvious question for an operator is where it comes from instead. The reassuring answer is that the replacements exist, they are commercially available, and they are running at scale today in real markets. The harder answer is that they are capabilities to be specified, procured, and integrated, not a default that arrives with the hardware.

The central replacement is the grid-forming inverter. Where a grid-following inverter waits to be told the voltage and frequency, a grid-forming device behaves like a synchronous machine’s electronic cousin: it actively establishes a voltage and frequency reference and holds it, and it can do so even on a weak grid with little surrounding synchronous generation. Crucially, grid-forming behavior is governed by the inverter’s control software and configuration, which is why the same physical hardware can be a follower or a former depending on how it is programmed and tuned for the specific grid it sits on.

Batteries are the natural host. A battery energy storage system, or BESS, has fast, dispatchable power in both directions, which makes it the ideal platform for grid-forming control and for the fast frequency response that compensates for missing inertia. The synthetic inertia, sometimes called virtual inertia, that a grid-forming BESS provides is a software emulation of what a spinning rotor did mechanically: it injects or absorbs power in the first instants of a frequency event to slow the rate of change and hold the system together. Whether that capability is actually reachable depends on the dispatch software above it, and the gap between contracted storage and dispatchable storage is where the value tends to leak away.

This is no longer theoretical. AEMO, the operator of Australia’s National Electricity Market and one of the most renewables-stressed grids on earth, reported in December 2025 that it had ten grid-forming BESS sites in operation, totaling roughly 1,070 megawatts. That is the strongest available proof that grid-forming stability services are a deployable reality at utility scale, in a real market, under real operating conditions, rather than a research roadmap. The technology is ready. The question that determines whether an operator can actually rely on it is a software-and-integration question, and that is where the difficulty concentrates.

What system operators are actually procuring

The instinct, when stability becomes a procurement problem, is to procure megawatts: contract enough grid-forming BESS capacity, and the stability follows. Capacity is necessary. It is nowhere near sufficient. What an operator is really buying is the ability to command, coordinate, validate, and observe a fleet of fast inverter-based resources, and almost all of that lives in the software layer that sits above the hardware.

Consider what stands between a contracted grid-forming BESS and an actual stability service the operator can dispatch and defend. The plant controller and energy management system have to translate a system need into coordinated commands across many inverters, each with its own control loops, without those loops fighting one another. Those assets have to be integrated into the DERMS and the TSO-DSO signaling fabric so a transmission-level frequency event can reach distribution-connected resources fast enough to matter, and the distinction between a DERMS, a VPP, and an ADMS stops being academic the moment that dispatch path has to be built. The whole arrangement has to interoperate with the SCADA and ADMS systems the control room already runs, because reliability is the operating floor and no operator will bolt on a stability layer that compromises the systems they trust. And the telemetry has to be fast and trustworthy enough that an operator can see what the fleet is doing in something close to real time, the exact data-and-coordination gap the blackout post-mortems flagged as missing.

Diagram titled The Stability-Service Software Stack, showing what sits between a contracted grid-forming battery and a stability service an operator can actually dispatch, validate, and prove. At the top is the system need from the control room: a frequency, voltage, or oscillation event, a transmission-level disturbance that must reach fast inverter-based resources in fractions of a second. Below it sit two Codibly software layers. The first is the plant controller and energy management system, which translates one system need into coordinated commands across many inverters without their control loops fighting one another. The second is the DERMS and TSO-DSO signaling fabric, which routes a transmission-level event to distribution-connected resources fast enough to matter. Beneath those is the reliability floor: SCADA and ADMS interoperability, integrating with the control-room systems the operator already trusts, because the stability layer must not compromise them. At the base is the grid-forming inverter fleet itself, providing synthetic inertia and fast frequency response, dispatchable in both directions, configured as a former rather than a follower, with many control loops coordinated as one stability resource. Closing the loop upward is the telemetry and data layer: fast, trustworthy feedback so the operator can see what the fleet is doing in near real time, the exact data-and-coordination gap the Iberian blackout post-mortems flagged as missing.
Contracted megawatts sit at the bottom of this stack, not the top. Everything above them is what turns capacity into a service an operator can command and prove.

This is the layer Codibly builds, and it is the layer operators consistently underestimate. We do not manufacture inverters, and we do not write the power-electronics control law that lives inside an OEM’s firmware. We build the software around it: the plant-controller and EMS logic that commands grid-forming fleets, the integration into DERMS and the DSO and TSO signaling infrastructure that carries those instructions, and the telemetry and data layer that turns a collection of contracted assets into a stability resource an operator can actually depend on. The credibility behind that work is grounded in delivery. Codibly built a custom DERMS platform for the retail energy provider APG&E, with real-time telemetry, event scheduling, and rollback across multiple market territories, and consolidated a single source of truth across dozens of databases and seventy-plus data sets for a major US utility that needed one trustworthy operational view of its assets. Those are the unglamorous integration disciplines that decide whether a stability service is real.

Read through the ancillary-services lens, the picture sharpens further. Frequency regulation, fast frequency response, and reactive-power support are products an operator procures and an asset owner sells, and each one has to be measured, settled, and proven against a market or a regulator. Frequency regulation for grid stability is therefore both a control problem and a data and verification problem, which is precisely why the grid stability solutions that hold up are software-led. The hardware sets the ceiling on what is physically possible. The software determines how much of that ceiling an operator can reach, command, and prove.

The table below sets out the stability services an operator procures, the asset class that delivers each, and where the controlling software layer sits.

Stability service procured Delivering asset class Where the controlling software sits
Synthetic (virtual) inertia Grid-forming battery storage Inverter control mode plus plant-controller configuration
Fast frequency response Battery storage; responsive DER fleets Plant-controller and EMS dispatch logic
Frequency regulation (ancillary market) Battery storage; aggregated flexible load EMS plus the market-settlement and telemetry layer
Dynamic voltage and reactive-power support Grid-forming inverters; STATCOM; synchronous condensers Plant-controller voltage-control logic; DERMS coordination
Oscillation damping Grid-forming inverter fleet Control-loop tuning coordinated across the whole fleet
Blackstart and islanded operation Grid-forming battery storage Plant controller plus SCADA and ADMS integration
Table 2. The hardware column is the shortest one. Almost every service an operator procures is defined by the software layer that commands and proves it.

The operator’s move now

There is a version of this transition that waits. Run the synchronous fleet as long as the economics and the retirement schedule allow, lean on the inertia that remains, and treat grid-forming procurement and the software integration behind it as a problem for the year the mandate forces the issue. It is an understandable posture in a world of long, RFP-driven utility cycles. It is also the higher-risk path.

The mandates are arriving on dates that are already set. In the United States, NERC’s PRC-029 ride-through standard, approved through FERC Order 909, takes effect on 1 October 2026, and the EU’s network code for new generators is finalizing a grid-forming obligation for new plants above one megawatt. Meeting them is its own discipline, because grid-code compliance has itself become a software deliverable with a validation burden attached. The direction is no longer in question, and that turns the deadline risk in a single direction: every operator that waits is buying integration work into a narrower window, against a compliance clock, alongside everyone else who waited.

The system operators who start now get to build, integrate, and validate their stability software layer at a deliberate pace, prove it against their own SCADA and reliability standards before they are forced to, and meet the renewables-heavy grid on their own schedule. That is the load-balancing and energy-optimization work Codibly delivers with operators today. When the spinning stops, stability is whatever an operator has already built the software to command. The earlier that work begins, the more of the grid stays under control.

Grid resilience and grid-forming whitepaper promo - Codibly