Overview
If you have ever had a 3500 monitor module fail on a running machine, you will know the feeling. There is a dead slot in the rack, a turbine that is either offline or running without protection, and someone upstairs asking for a date. Meanwhile you are typing a part number into a search bar for a card that was first specified in the late nineties.
The difficult part is not finding a module. Search hard enough and plenty of people will sell you something with "3500" printed on the front. The difficult part is knowing whether what arrives in the box is the real thing, whether it will talk to your rack, and whether it will still be doing its job in five years.
This guide covers how the system is put together, how its protection logic actually works, where the 3500 now sits in its lifecycle, and the checks worth making before you raise a purchase order.
Bently Nevada 3500 Series
Bently Nevada launched the 3500 Machinery Protection System in 1996, and it went on to become the default rack-based protection platform for critical rotating machinery. By Bently Nevada's own figures, tens of thousands of systems are in service worldwide.
It is a continuous, online system rather than a periodic survey tool. In practical terms it does four things:
- Measures vibration, shaft position, speed, phase and temperature from transducers mounted on the machine
- Compares those measurements against configured alarm setpoints, continuously and in real time
- Passes data to plant systems like DCS, PLC, historian, or System 1 for condition monitoring
- Drives relays that alarm or trip the machine when limits are exceeded
The system is designed to meet API 670, the American Petroleum Institute standard for machinery protection systems. That is a large part of why it appears in so many oil, gas and petrochemical specifications by name.
The 3500 is not a diagnostic tool that happens to raise alarms. It is a protection system that happens to produce useful data.
That distinction matters when you are sourcing spares. A card that is nearly right is fine in a monitoring application and unacceptable in a protection one.
How a 3500 rack is put together
The system follows a modular 19-inch rack architecture. Understanding the layers makes it much easier to work out what you actually need to order.
The rack and power layer
The 3500/05 rack provides the mechanical housing, the backplane that carries communication between modules, and the slots themselves. The full-size 19-inch version has 14 slots. Panel, bulkhead and weatherproof variants exist for installations that cannot take a standard cabinet.
One or two 3500/15 power supplies sit at the left-hand end. Two is common on critical duty, one AC and one DC, so the rack survives a loss of either supply.
The interface layer
The 3500/22M Transient Data Interface, or the older 3500/20 Rack Interface Module on legacy racks, is the brain of the system. It holds the rack configuration, runs system-level diagnostics, and provides the path out to System 1 and to plant networks.
This is also the module that determines what the rest of the rack can do. Firmware revision here governs which monitor cards will configure and which features are available which is why it is the first thing to check when a replacement card refuses to come online.
The measurement layer
Monitor modules occupy the middle of the rack. Each takes inputs from field transducers like Proximitor sensors, seismic transducers, accelerometers, RTDs, thermocouples that conditions the signal, derives the measurement, and compares it against setpoints.
Most are four-channel. A single rack can therefore cover a full turbine train, with radial vibration, thrust position, differential expansion, speed and bearing temperatures all monitored from one frame.
The output layer
Relay modules convert alarm states into contacts the plant can act on. Communication gateways pass measurements and statuses to the DCS over Modbus RTU or TCP, or to OPC clients.
The protection path and the data path are deliberately separate. A network fault or a failed gateway does not stop the rack tripping the machine.
Bently Nevada 3500 Series Modules
| Function | Common modules | What they do |
|---|---|---|
| Rack & power | 3500/05 3500/15 |
The 14-slot frame and backplane, available as 19-inch, panel, bulkhead and weatherproof variants, plus single or redundant AC/DC power. |
| Rack interface | 3500/22M TDI 3500/20 RIM |
Holds the configuration, runs diagnostics, and acts as the gateway through to System 1. The 3500/20 appears on older racks. |
| Vibration & position | 3500/40M 3500/42M 3500/45 |
Four-channel monitoring for radial vibration, thrust position, differential expansion, eccentricity, acceleration and velocity. |
| Specialist machines | 3500/44M 3500/46M 3500/64M |
Tailored channel types for aeroderivative gas turbines, hydro sets, and combustion pulsation ("humming") monitoring. |
| Reciprocating | 3500/72M 3500/77M |
Rod position and cylinder pressure monitoring on reciprocating compressors. |
| Speed & phase | 3500/25 3500/50 3500/53 |
Phase reference, speed, zero speed, reverse rotation and electronic overspeed detection. |
| Temperature | 3500/60 · 3500/61 3500/62 · 3500/65 |
RTD and thermocouple inputs for radial and thrust bearing metal temperature and differentials. |
| Relays | 3500/32 3500/33 3500/34 TMR |
Alarm and trip outputs four-channel, sixteen-channel and triple modular redundant with voting and AND/OR logic. |
| Comms & display | 3500/91 · 3500/92 3500/93 · 3500/94M · 3500/95 |
Modbus and OPC connectivity through to the DCS, plus local rack display options. |
Table 1: 3500 module families by function. Part numbers carry a dash suffix that identifies the specific variant.
This detail catches people out more often than any other: every monitor module needs its matching rear I/O module. They are separate part numbers.
Ordering a 3500/42M on its own and assuming the I/O card comes with it is one of the most common reasons a spare arrives on site and still does not get the machine back into service. If you are quoting a spare, quote the pair.
How the protection logic actually works
Understanding this is what separates ordering the right card from ordering something that fits the slot.
Alert and Danger
Each channel carries two setpoint levels. Alert is the early warning, the machine is drifting away from its baseline and someone should look at it. Danger is the trip level, where continuing to run risks damage.
Both are configured in software rather than set with potentiometers, which is one of the significant advances the 3500 brought over the systems it replaced.
Voting logic
A single channel exceeding Danger is not always enough to justify tripping a large machine. The relay modules support voting arrangements, commonly two channels out of two on the same bearing, or two out of three where triple redundancy is specified.
This is the balance every protection engineer works to: trip too readily and you lose production to spurious events; trip too reluctantly and the protection has not done its job. Voting logic is how the 3500 lets you tune that trade-off.
Channel self-diagnostics and the OK circuit
Each channel continuously checks that the transducer loop itself is healthy. For a proximity probe system, the monitor watches the bias voltage coming back from the Proximitor, typically around −10 V DC when the probe is correctly gapped.
If that voltage drifts outside its expected window, the channel goes Not OK. That single feature catches a broken probe, a damaged extension cable, a failed Proximitor, and a short or open circuit in the field wiring.
It matters more than it sounds. The classic failure mode in older protection systems was not a false trip, it was a dead channel reading a comfortable zero while the machine quietly destroyed a bearing.
What happens when a machine goes out of limits
- The monitor detects a measurement crossing its configured setpoint.
- Channel diagnostics confirm the transducer loop is healthy, so the reading is trusted.
- Alert is raised, and the condition is passed to the DCS and to System 1.
- If the measurement continues into Danger and the voting condition is satisfied, the relay module drives its output.
- The trip signal reaches the machine's shutdown system through hardwired contacts, independent of any network.
Where 3500 racks are running in the UK
If you work in any of these sectors, there is a good chance you are within a few miles of one.
Oil and gas
- North Sea platform compression trains
- Gas terminal and pipeline compressor stations
- Refinery turbine and compressor trains
Power generation
- CCGT steam and gas turbine sets
- Biomass and energy-from-waste plant
- Hydro and pumped-storage units
Chemicals and Petrochemicals
Passes data to plant systems- Process and reactor feed compressors
- Boiler feed and cooling water pumps
- Air separation plant
3500 versus the 3300
Plenty of UK sites still run 3300 racks, and the question of whether to keep patching one or move to a 3500 comes up regularly. The practical differences:
3300 Series
Predecessor- Lower channel density per rack
- Analogue signal processing
- Setpoints adjusted by hand on the card
- Limited diagnostic reporting
- No native path to System 1
3500 Series
Current platform- Higher channel density, fewer racks
- Digital signal processing
- Software configuration, with keylock protection
- Per-channel self-diagnostics
- Ethernet and System 1 connectivity
Sourcing tends to settle the argument on its own. 3300 spares are genuinely scarce now, and the gap between "hard to find" and "not available" closes faster than most maintenance budgets move.
Is the 3500 obsolete?
This question comes up in almost every conversation, and it deserves a straight answer.
No, the 3500 is not obsolete. Bently Nevada has never announced a forced obsolescence programme for it, and the platform remains supported.
What has changed is where it sits in the manufacturer's five-phase lifecycle. The 3500 is now described as a mature product in Phase 2: still supported, still repairable, still available as spares, but with no new features or functionality in development. The Orbit 60 Series is what Bently Nevada recommends for new installations and major system refreshes.
For anyone running a 3500 today, the practical implications are worth thinking about now rather than during an outage:
- There is no urgent need to rip out a working rack. If it protects the machine and satisfies your safety case, it is doing its job.
- Spares strategy matters more than it used to. Phase 2 is the stage at which it makes sense to review your critical spares holding, not the stage at which you leave it to chance.
- Cards that were once ordered off the shelf may now carry longer lead times which is exactly the gap the grey market moves into.
Why "genuine" matters more here than almost anywhere else
Plenty of industries tolerate a pattern part. Machinery protection is not one of them.
A counterfeit or misrepresented card does not usually announce itself by failing outright. It sits in the rack, shows green LEDs, reports plausible numbers, and quietly does not trip when it should. That is worse than having no protection at all, because it removes the one thing protection is meant to provide confidence.
- Counterfeits and relabelled parts
- Cards refinished and sold as new, or lower-spec variants relabelled with a higher part number. Both circulate.
- Firmware and revision mismatches
- A physically correct module with the wrong firmware revision may refuse to configure, may not communicate with your TDI, or may behave differently from the card it replaced. Rack Configuration Software compatibility is not optional detail.
- Traceability gaps in your safety case
- If your protection system forms part of an API 670 specification, an insurance requirement or an audited safety case, a module you cannot trace is a hole in the documentation. That tends to be discovered at the worst possible time.
Then there is the simple arithmetic. A monitor module costs a few thousand pounds. An unplanned trip, a damaged bearing or a failed protection event on a large machine costs a great deal more than that, before anyone counts the lost production.
Eight checks before you commit to a 3500 purchase
These checks are worth running through.
- Get the full part number, including the dash suffix. 3500/42M is a family. 3500/42M 176449-02 is a part.
- Confirm the rear I/O module is included, with its own part number, and that the connector type matches your existing wiring.
- Ask for the firmware revision and confirm it is compatible with your rack interface module and your version of Rack Configuration Software.
- Ask for photographs of the actual unit, not a catalogue image. Front label, serial number, board condition.
- Establish the condition honestly. New, factory-refurbished and used-tested are three different things at three different prices. A supplier who blurs the line is telling you something.
- Ask what testing was done. Powered up and channel-tested is meaningful. Visually inspected is not.
- Get the warranty in writing, along with the returns position if the card does not configure on site.
- Check delivery to site, not to depot. A module sitting in customs on the Friday of a shutdown window is no use to anyone.
How British Instruments can help
British Instruments is a trusted UK and US supplier of genuine Bently Nevada machinery protection equipment. When a monitor module fails, you do not need a lecture on the 3500 architecture, you need the right card, at a fair price, on site before the outage window closes. That is what we built the business around.
We supply Bently Nevada 3500 hardware across the full range racks, power supplies, TDI and rack interface modules, monitor cards, relay modules, Keyphasor and tachometer modules, communication gateways, and the matching rear I/O modules.
What we try to do differently is the part before the quote. Send us the part number from the card you are replacing, or a photograph of the rack if you are not sure what you are looking at, and we will confirm the correct module and I/O combination before anything is priced. We will tell you plainly whether a part is new, refurbished or used-tested, what warranty applies, and what the realistic delivery date to your site is.
If a module is genuinely hard to find, we will say so, rather than let a purchase order sit open while you assume it is on its way.
If you are also sourcing the transducers that feed this rack, our guide to Bently Nevada proximity probes covers the probe, extension cable and Proximitor side of the same system.
Ready to Source Genuine Bently Nevada Products?
Get competitive pricing, fast delivery in the UK (EU) & US, and dedicated technical support on every order. Reach out now and receive a tailored quote within 24 hours.
Frequently asked questions
Yes. It is a mature product in Phase 2 of Bently Nevada's lifecycle programme, meaning it is still supported and still available as spares, but no new features are in development. Orbit 60 is the recommended platform for new installations.
Almost always, yes. They are separate part numbers and the monitor will not function without the correct I/O card behind it. Always check before ordering.
Both are four-channel modules. The 3500/42M is the more flexible Proximitor/Seismic monitor, accepting input from both Proximitor sensors and seismic transducers, and covering a wider range of measurement types including thrust position, differential expansion and shaft absolute.
The full-size 19-inch 3500/05 rack has 14 slots. Two are typically taken by power supplies and one by the rack interface module, leaving eleven for monitor, relay and communication cards.
Often, but not always. Compatibility depends on the rack interface module, firmware revisions and the version of Rack Configuration Software you are running. Send us your rack details and we will check rather than guess.
Yes. 3500 systems can be specified with intrinsic safety barriers or galvanic isolators, either internal or external. Let us know the area classification when you inquire.
Ideally the full part number including the dash suffix. If you do not have it, a clear photograph of the module's front label and of the rack is usually enough for us to identify it.
Send us a part number.
Tell us the module, the machine it protects and when you need it on site. We will come back with availability, condition, warranty and a realistic delivery date.