EN · FR
Guides  ›  Redundancy

RedundancyUPS Redundancy: N, N+1 and 2N

Redundancy is how a UPS system survives a failure or a service window without dropping the load. Here is what N, N+1 and 2N actually mean for three-phase critical power, and where the hidden single points of failure live.

What is an N+1 redundant UPS configuration?

N+1 means installing one more UPS module than the load actually requires. If your critical load needs three 20 kW modules to run, an N+1 system installs four. The extra module carries no additional load in normal operation. It exists so that any single module can fail, or be pulled for service, while the remaining modules still carry the full load without transferring the load to raw utility power.

When do you need N+1?

You need N+1 when an unplanned outage costs more than the spare module does, and when you cannot take the load down for routine UPS service. In practice that covers most data centres, hospitals, telecom sites and process control. You do not need it when the load tolerates a planned shutdown and one well-maintained unit with a maintenance bypass is enough.

The test is arithmetic rather than fashion. Multiply the cost of an hour of downtime by the hours you would lose to a module failure or a service visit, then compare that to the price of one additional module spread over the life of the system. If downtime is cheap and you can schedule it, N is a defensible answer and nobody should talk you out of it.

Start with N: the capacity you need

Before you can talk about redundancy you have to fix N. N is the capacity required to carry the load with nothing to spare, if the load is 300 kW, N is one 300 kW UPS, or three 100 kW units, or six 50 kW modules. Size N properly first; everything else is built on top of it. Get the load wrong and no amount of redundancy saves you, so the sizing step comes before the redundancy decision, not after.

An N system has no margin. Lose one module, take one unit out for service, or have a single component fail, and the load drops. That is fine for non-critical equipment, but it is rarely acceptable once a load is on three-phase power for a reason. Redundancy is what you add to N so a single fault, or planned maintenance, does not become an outage.

How N+1 works inside a modular frame

N+1 adds a single redundant unit or module to whatever N requires. If the load needs three 100 kW units, N+1 is four; if a modular frame needs five 50 kW power modules, N+1 is six. The load shares across all of them, so any one can fail or be pulled for service and the survivors carry the full load without a transfer.

That single spare buys two things. It survives one module failure, and it lets you service one module, replace fans, swap a power module, do firmware work, while the system stays online. It is the most common redundancy level we see in three-phase systems because it covers the failure mode that actually happens most: one thing breaks, or one thing needs attention. What it does not cover is a fault in the parts the units share, or a second failure during a service window. N+1 protects the modules, not the whole path.

2N: two independent systems

2N is two complete, independent systems, each able to carry the full load on its own, a full A side and a full B side, fed from separate inputs, with separate batteries, and ideally in separate rooms. The load is dual-corded: every critical device draws from both the A path and the B path at once. Lose an entire side, a UPS fault, an upstream breaker, a feeder, or a whole side down for maintenance, and the other side carries everything with no interruption.

This is the topology behind the most demanding facilities, where you must be able to take an entire electrical side out for work and never put the load at risk. It is also the safest answer to the single-point-of-failure problem below: with two genuinely separate paths there is no shared component whose failure can take down both sides. The price is the obvious one, you are buying and powering roughly twice the equipment.

Beyond 2N: 2N+1 and distributed redundancy

Two refinements sit past 2N. 2N+1 is 2N with a spare module added inside each side, so a side can lose a module during maintenance and still carry its share, it removes the “second failure during a service window” risk that plain 2N still carries. You see it only where the cost of downtime justifies it.

Distributed or “catcher” redundancy is a more efficient middle ground than full 2N. Several systems share the load, and one spare system stands ready to “catch” the load of any unit that fails, usually through static transfer switches. It reaches toward 2N availability while running the equipment closer to its rated capacity, so utilization is higher and stranded capacity is lower. It is more complex to design and operate, which is the trade.

The trade-off, in plain terms

The three levels line up on a simple curve. N is the cheapest and smallest, with the least equipment to buy, power and cool, and the highest risk, because any single fault drops the load. N+1 adds one unit of cost and footprint and removes the most common failure mode; for most three-phase sites it is the sensible balance of availability against spend. 2N roughly doubles capital, footprint, and energy overhead, and in return gives the highest availability and full concurrent maintainability, you can work on an entire side with the load fully protected. These broadly track the way data-centre availability is tiered, from basic capacity up to fully fault-tolerant, but the exact tier definitions and witnessed-test requirements are set by the relevant standard, not by the redundancy label alone.

One more distinction matters: module-level versus system-level redundancy. In a modular UPS, N+1 can live inside a single frame, one extra power module among several. That is neat and space-efficient, but the frame, its controls and its bypass are still shared, so a frame-level fault can affect every module in it. With standalone units, redundancy is at the unit and system level: separate cabinets, separate batteries, and with a paralleling tie or dual paths, no single shared frame. Module-level redundancy is convenient; system-level redundancy is more thorough. Which you need depends on how much shared hardware you are willing to live with. See modular vs monolithic for that decision in full.

The single points of failure people forget

It is easy to buy redundant UPS modules and still leave a single point of failure in the path. The usual culprits: a shared static bypass that both the A and B paths route through; downstream switchgear, a single output board or breaker that everything passes through after the UPS; and a single utility feeder serving both sides, so a problem upstream of the building takes out your “independent” systems at once. N+1 on the modules does nothing for any of these.

The fix is to make the path redundant, not just the boxes. True 2N gives every critical load two independent cords from two independent paths, all the way from separate feeders to separate output distribution. For the many devices that have only a single power supply, a static transfer switch (STS) sits in front of them, fed from both the A and B paths, and switches between sources fast enough that the device never sees the gap. Dual-cord plus an STS is what turns redundant equipment into a genuinely redundant supply. If you tell us the load, how critical it is, and whether the building can give you two feeders, we will spec the right level, from N+1 modules up to a full 2N data hall, from any major brand. Browse systems by application on the data-centre page, or talk it through with an engineer.

Frequently asked questions

What is the difference between N+1 and 2N redundancy?

N+1 adds one spare unit or module to the pool that carries the load, so the system survives a single failure or lets you service one module. 2N is two complete independent systems, each able to carry the full load alone, so an entire side can fail or be maintained with no interruption. N+1 protects the modules; 2N protects the whole path.

Is N+1 redundancy enough for a data centre?

It depends on the load. N+1 covers the most common failure, one module breaking or needing service, and suits many three-phase sites. For a facility that must take an entire electrical side out for work without risk, or that cannot tolerate a second failure during a service window, 2N or 2N+1 is the conservative choice.

Does redundant UPS mean there is no single point of failure?

Not by itself. Redundant modules still leave single points of failure if the A and B paths share a static bypass, a downstream output board, or a single utility feeder. Removing single points of failure needs independent paths end to end, true 2N with dual-cord loads, and a static transfer switch in front of any single-corded device.

What is the difference between module-level and system-level redundancy?

Module-level redundancy lives inside one modular UPS frame, an extra power module among several, which is space-efficient but shares the frame, controls and bypass. System-level redundancy uses separate standalone units with separate batteries and paths, so there is no shared frame to fail. Module-level is convenient; system-level is more thorough.

When do I need N+1 redundancy instead of a single UPS?

When you cannot schedule the load down for UPS service, or when an hour of unplanned downtime costs more than the spare module amortised over the life of the system. Data centres, hospitals, telecom and process control almost always qualify. A load that tolerates a planned shutdown usually does not.

Related guides and systems

Request a system quote

Tell us the application and we will come back within one business day, sizing, the right system, install and a price. Three-phase installs usually need a licensed electrician, so let us know if you have one.

Do you have your own electrician?
Yearly preventive maintenance?

Or email [email protected] · 1 (438) 881-3363

Need the replacement battery only? Shop matched three-phase batteries →
Already have a fleet to maintain? Canada-wide UPS maintenance and repair →
Image credits