Industry guide · Project Management

Nuclear Refueling Outage Software: Why the Schedule Slips at 2am on Day Nine

Nuclear Outage Management software visual showing atom, project timeline, and shield alert.
The short answer

$120,000 to $250,000 and 16 to 24 weeks is the honest first release for a station building outage software, and it belongs in the non-safety-related space: a constraint-aware sequencing layer over your existing work management system, clearance order and radiation work permit awareness, emergent work triage, and a field-facing view that is current rather than printed. A full platform adding qualification and access checking for a contract workforce, live critical path recalculation, milestone and window management, and post-outage schedule forensics runs $350,000 to $800,000 across 12 to 18 months in our delivery experience. Anything touching the licensing basis or a safety-related function is a different conversation with your quality assurance and licensing organisations, and it is theirs to decide, not a vendor's.

Why the outage schedule is not really a schedule

Day nine of a refueling outage, 2am. The published schedule says a valve overhaul in a contaminated area starts now. In practice it cannot, because the clearance order that isolates it has a conflicting tag from another job that ran long, the radiation work permit for the area was written for a different scope than the one that actually got discovered when the insulation came off, and two of the four craft qualified for that specific procedure are three hours into a shift on a different job in another building. None of that is in the schedule. All of it is in four people's heads, and they resolve it in the 5am meeting.

The tooling is usually a scheduling product holding tens of thousands of activities, a work management system of record holding the work orders, a clearance and tagging system, a radiation protection system holding permits and dose tracking, an access and qualification system for the contract workforce, and a printed schedule that goes stale the moment it leaves the printer. Each system is doing its job. What no system holds is the actual constraint graph, which is the reason the schedule and reality diverge from about day three onward.

The financial shape of this is brutally simple. Every day the unit is offline costs seven figures in replacement power, and the outage duration is decided by the accumulation of small sequencing failures rather than by any single event. A station that recovers half a day per outage through better sequencing has paid for a software program several times over, and everyone in the room knows it, which is why outage software conversations happen at director level.

Problem 1: the scheduler levels resources, the plant obeys the licensing basis

Oracle Primavera P6 is a serious scheduling tool and most stations use it well. What it models is activities, durations, logic and resources. What governs a nuclear outage is a different set of objects: technical specification limiting conditions with allowed completion times, shutdown safety function availability, clearance orders and their tag conflicts, contamination and radiation zone access, fire protection compensatory measures, and configuration control on systems that are partly disassembled. Those constraints do not exist in the scheduling model, so they are enforced by experienced people in meetings.

Hitachi Energy Asset Suite is the work management backbone at many stations and it holds the work orders properly, but work management and constraint-aware sequencing are separate concerns and it was built for the first. IBM Maximo is a strong maintenance management system with an asset and work order constraint model rather than a licensing basis one. None of these products is deficient. They were simply built for a world where the binding constraint is resources, and in a refueling outage the binding constraint is permission.

A custom layer makes the constraint graph explicit alongside the schedule. A work order carries the clearance it requires, the radiation work permit scope it falls under, the zone it occupies, the qualifications the craft need, and the plant configuration state it depends on. Then the sequencing engine can answer, at 2am, which of the fourteen ready jobs can actually start right now, in what order, and which single clearance release unlocks the most downstream work. That question is currently answered by the best-informed person awake.

Problem 2: emergent work reorders everything and the field is reading yesterday's print

Insulation comes off and the scope changes. A valve that was a repack becomes a replacement. An inspection finds indications that add a work package nobody planned. In a large outage this happens continuously, and each occurrence ripples through the sequence in ways the daily republished schedule captures partially and late.

The consequence is not that the schedule is wrong, everyone expects that. The consequence is that the field is working from a document that was true at 4am, so craft arrive at jobs that cannot start, wait for clearances that were reassigned, and burn hours in a radiological area for no product. Those hours are also dose, which makes it a radiation protection issue and not only a productivity one.

A custom layer treats emergent work as a first class event with a triage path: scope captured where it was found, constraint requirements identified immediately, impact on the critical path computed rather than estimated, and the affected crews notified on a device rather than in the next meeting. The measurable win in the stations we have worked with is not schedule optimisation, it is the reduction in crews standing at a job they cannot start. That is the cheapest half day a station will ever recover.

Problem 3: thousands of contract workers, and the constraint is qualification, not headcount

An outage brings in a temporary workforce many times the size of the permanent staff. Each person has a set of qualifications, medical and respiratory clearances, radiation worker training with expiry dates, unescorted access authorisation, and site-specific procedure qualifications. The schedule shows craft counts. The reality is that a specific job needs a specific qualification combination and there may be six people on site who hold it.

When schedulers plan against headcount and the field discovers a qualification gap at shift turnover, the job slips, and it slips at the worst possible time because everything downstream was planned around it. Qualification and access data lives in a separate system, so the scheduler simply cannot see the constraint they are violating.

A custom layer joins qualification and access state to the sequencing model, so a job cannot be scheduled into a window where no qualified and cleared person is available, and so an expiring training qualification surfaces as a schedule risk days before it becomes a stoppage. It also makes shift turnover a data handoff rather than a verbal one, which matters when the incoming shift supervisor has to reconstruct why the previous twelve hours went the way they did.

What a custom outage build has to include

  • A constraint model per work order covering clearances, radiation work permit scope, zone access, required qualifications and plant configuration dependencies, sourced from the systems that own each.
  • Read integration with the work management system of record and the scheduling product, with the custom layer sequencing rather than replacing them.
  • A ready-to-work engine answering which jobs can start now and which single constraint release unlocks the most downstream work.
  • Emergent work capture in the field, with constraint identification and critical path impact computed at the point of discovery.
  • A field-facing current view on a device, replacing the printed schedule, designed for a plant environment with poor connectivity and gloved hands.
  • Qualification, training expiry and access state joined to the sequencing model for the full contract workforce.
  • Post-outage forensics: an immutable record of what was planned, what changed, when and why, so the next outage plan is built from evidence rather than recollection.

What it costs and how long it takes

From the industrial scheduling and asset work Digital Heroes has delivered, this is the shape. A first release covering the constraint model, integration with work management and scheduling, the ready-to-work engine and a field view runs $120,000 to $250,000 and ships in 16 to 24 weeks. A full platform adding workforce qualification integration, live critical path recalculation, milestone and window management and post-outage forensics runs $350,000 to $800,000 phased over 12 to 18 months.

Nuclear specific cost drivers, and these are larger than in any adjacent industry. Software quality assurance expectations, because a station applies controls that commercial software projects do not, and even non-safety-related applications carry documentation, verification and configuration management obligations your quality organisation will define. Cyber security and network segmentation, since anything reading plant systems has an architecture review with real duration. Integration access, because the clearance, radiation protection and access authorisation systems are each owned by a different organisation with its own change process. And the licensing question, which is not ours to answer: whether any part of the scope touches the licensing basis is a determination your licensing organisation makes, and it changes the project fundamentally if the answer is yes.

What keeps cost down: scoping strictly to the non-safety-related sequencing and information layer, reading from systems of record rather than writing to them in the first release, and piloting on one outage window with one department before station-wide rollout.

Build versus buy, and where the line sits

Do not build if your station runs short outages with a stable, largely permanent workforce and your existing scheduling discipline is producing outcomes you are satisfied with. Do not build a replacement for your work management system of record under any circumstances, and be sceptical of anyone who suggests it. Asset Suite and Maximo hold the work order record for good reasons and the migration risk is disproportionate to any benefit.

Build the layer when two or more of these are true. Your outages routinely lose time to crews arriving at jobs that cannot start. Emergent work reordering is managed verbally and the field is working from printed schedules. Qualification and access constraints are discovered at shift turnover rather than during planning. Nobody can explain, after an outage, where the duration actually went, so each outage plan is built from the last one plus optimism. Or you are a multi-unit fleet and cannot compare outage performance across stations on a common basis.

Our position: in nuclear, the value is in the information layer and the constraint model, not in replacing anything. The systems of record stay. What gets built is the thing that answers, continuously and correctly, what can start right now.

How to choose a developer for outage management software

Ask them what they would do if a clearance order and a radiation work permit disagree about a job's readiness. A developer who has worked in this environment will say the system surfaces the conflict to a named human and does not resolve it automatically. A developer who describes an automatic resolution rule has not understood where authority sits in a nuclear station.

Ask how they will work with your quality assurance organisation. The right answer includes asking, early and directly, what software quality requirements apply to a non-safety-related application at your station and building the documentation and verification approach around that answer rather than discovering it in month six.

Ask what they will read and what they will write. In a first release the answer should be read-heavy: read the work orders, read the clearances, read the permits, write only within the custom layer. A vendor eager to write back into plant systems on day one is optimising for a demo, not for your change control process.

Ask who owns the code, the infrastructure and the integration configurations, and settle it in writing before kickoff. At Digital Heroes the client owns the repository from the first commit, and in a regulated environment that ownership is what allows your own organisation to audit and control what is running. A concrete first step: take the last outage and count the crew hours spent at jobs that could not start when the schedule said they could. Most stations have never measured it, and the number is the business case.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. McKinsey argues software developer productivity can be measured by combining system-level metrics (DORA and SPACE) with its own outcome-oriented approach, which it reports deploying across nearly 20 tech, finance, and pharmaceutical companies - a claim that sparked significant debate in the engineering community. Source: McKinsey & Company (2023) →
  2. Across 1,471 IT projects the average cost overrun was 27%, but one in six projects was a 'black swan' with an average cost overrun of 200% and a schedule overrun of nearly 70%. Source: Harvard Business Review (Bent Flyvbjerg & Alexander Budzier, University of Oxford) (2011) →
  3. Only 22% of firms are 'future ready' having significantly transformed digitally; these companies show average revenue growth 17.3 percentage points and net margins 14.0 percentage points above their industry average. Source: MIT Center for Information Systems Research (MIT Sloan) (2022) →
  4. Digital Champions expect to achieve about 16% in cost savings and around 15% in revenue gains from digital operations over five years; the study surveyed 1,155 manufacturing executives across 26 countries. Source: PwC / Strategy& (2018) →
Ben H. · Account Manager · UK B2B · London

Ben handles business to business accounts, where the buyer is rarely the end user and sign off involves several people who want different things. He writes about running a software project through a committee: gathering requirements that conflict, and getting a decision before the quarter closes.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

How much does custom nuclear outage management software cost?
A first release covering the constraint model, integration with work management and scheduling, a ready-to-work engine and a field view runs $120,000 to $250,000 and ships in 16 to 24 weeks, based on Digital Heroes delivery experience. A full platform with workforce qualification integration, live critical path recalculation and post-outage forensics runs $350,000 to $800,000 over 12 to 18 months. Nuclear specific quality assurance, cyber security review and multi-organisation integration access drive the cost above comparable industrial projects.
Can custom software replace Primavera P6 for outage scheduling?
It should not, and we would advise against it. P6 models activities, durations, logic and resources competently, and a station's scheduling discipline is built around it. What P6 does not model is the constraint set that actually governs a refueling outage: clearance orders and tag conflicts, radiation work permit scope, zone access, qualification requirements and plant configuration state. The productive build is a constraint-aware layer that reads from P6 and the work management system rather than replacing either.
Does building outage software trigger a licensing or quality assurance issue?
That determination belongs to your licensing and quality assurance organisations, not to a software vendor, and it should be answered before scoping. In practice most stations scope this work strictly in the non-safety-related space, reading from systems of record and writing only within the custom layer. Even then, expect software quality documentation, verification and configuration management obligations your quality organisation defines, and build the project plan around that answer rather than discovering it late.
How do we stop crews arriving at jobs that cannot start?
Model the constraints the schedule does not carry, then answer the ready-to-work question continuously rather than at the morning meeting. A job carries its clearance requirement, permit scope, zone access, qualification needs and configuration dependencies, and the engine reports which of the ready jobs can actually start now. The second half is delivery: the field needs a current view on a device rather than a printed schedule that was true at 4am.
How is emergent work handled without wrecking the sequence?
Capture it where it is discovered, identify its constraint requirements immediately, and compute critical path impact rather than estimating it at the next meeting. The affected crews get notified directly. Most stations manage emergent work well in terms of decision quality and poorly in terms of decision speed, and the recoverable time sits in the delay between the discovery and the field knowing about it.
How long does a nuclear outage software build take?
A first release ships in 16 to 24 weeks of development, but the calendar is usually longer because of parallel activities that do not compress: quality assurance requirement definition, cyber security architecture review, and obtaining read access from the clearance, radiation protection and access authorisation system owners. Starting those three conversations in week one, before design is complete, is the single most effective schedule decision available to a station.
Can it track qualifications for a large contract workforce?
Yes, and it is usually where the quickest wins appear. Joining qualification, training expiry and unescorted access state to the sequencing model means a job cannot be planned into a window where no qualified and cleared person is available, and an expiring qualification surfaces as a schedule risk days ahead. Planning against craft headcount rather than qualification combinations is a common cause of slips discovered at shift turnover.
What does post-outage forensics actually give us?
An immutable record of what was planned, what changed, when and on whose decision, so the next outage plan is built from evidence rather than recollection. Stations routinely finish an outage without being able to explain where the duration went, which means each plan inherits the previous plan's assumptions plus optimism. Multi-unit fleets get a second benefit: outage performance becomes comparable across stations on a common basis.
Who owns the code if a vendor builds this for our station?
You should own the repository, the infrastructure and the integration configurations, agreed in writing before kickoff. In a regulated environment that ownership is what lets your own organisation audit, control and verify what is running, which is not optional. At Digital Heroes the client owns everything from the first commit. A vendor who wants to host the system on their accounts is creating a configuration control problem your quality organisation will eventually have to solve.
Who owns the code when an agency builds my software?
You should, completely, through a written intellectual property assignment that transfers everything on final payment; without that clause, copyright stays with whoever wrote the code by default. Insist that the repository lives in your own GitHub organization from day one and that hosting, domains, and third-party accounts are registered to you. Also check for licenses to the agency's proprietary frameworks buried in the contract, because those can make switching vendors practically impossible even when you own your own code.
Should I hire a freelancer or an agency for my software project?
A skilled freelancer is the right call for a single-discipline scope under roughly $15,000, like a website, a plugin, or one integration. Above that, projects need design, backend, testing, and project management at once, and a solo builder becomes the single point of failure: if they get sick or take a bigger client, your project simply stops. Agencies bill 20-40% more per hour but carry continuity, code review, and someone to escalate to, which is what you are actually buying.
Can I build my product on a no-code tool like Bubble instead of hiring developers?
For testing whether anyone wants the product, yes, and Bubble's paid plans start at $29 a month, which is the cheapest validation you will ever buy. The ceiling arrives with complex data relationships, heavy integrations, performance at a few thousand users, and the fact that you cannot export a Bubble app to servers you control. A path many Digital Heroes clients take: prove demand on no-code, then rebuild custom once revenue justifies it, treating the no-code version as a paid prototype rather than a foundation.
What happens if the agency that built our project management tool shuts down?
Nothing fatal, if you set things up correctly from day one: code in your own GitHub organization, infrastructure in your own cloud account, and written deployment documentation as a contract deliverable. With those in place, any competent team can take over a standard-stack codebase in one to two weeks. Takeover disasters happen when the vendor hosted everything in accounts they owned, so verify account ownership before the first sprint, not after the relationship sours.
How do I calculate whether custom software will pay for itself?
Divide the build cost by the monthly benefit, where benefit is hours saved times loaded hourly cost, plus subscription fees replaced, plus any revenue the software unlocks. Three staff saving 10 hours a week each at a $40 loaded rate is about $62,000 a year, which pays back a $60,000 build in roughly 12 months. Across Digital Heroes internal-tool projects, 12 to 24 months is the normal payback range, and anything projecting under 6 months usually means the spreadsheet is hiding costs.
How do I vet a software development agency before signing a contract?
Ask to speak with two past clients whose projects resemble yours in size and industry, and ask exactly who will write your code, since some agencies sell senior faces and deliver junior or subcontracted hands. Demand a written specification with acceptance criteria before any fixed price, and check that their portfolio links to products that are actually live. An instant quote given without questions about your workflows is the clearest warning sign there is.
Can a custom project management tool double as a client portal?
Yes, and this is one of the strongest reasons to build. Guest access is where Asana, Monday, and ClickUp frustrate agencies: permissions are coarse, client editing rights can require paid seats, and the whole experience carries the vendor's branding. A custom portal shows each client only their projects, under your brand, with approval buttons wired to your real workflow, and unlimited client logins cost you nothing per seat.
How do I vet a software agency before hiring them to build a PM tool?
Ask to click through a workflow tool they shipped, live rather than in screenshots, and get a reference from a client whose system has been in production for over a year. Then ask two questions that expose weak vendors: how they migrate data out of your current tool, and what their maintenance retainer covered for that reference client last quarter. An agency that has genuinely shipped project management software answers both in specifics.
Who can build a custom project management software system?

Digital Heroes builds custom project management software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other project management software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?