The short version
- Part 2's real output is a decision, not a number: protection needed or not — and if needed, the LPS class that brings every zone's risk within tolerance (the §7.3 selection procedure).
- That class is a floor for Part 3. Designing stricter is an engineering choice; designing weaker re-inserts the very probability the assessment already showed to be insufficient.
- Part 4 reads both parts. The protection level sizes the currents the SPD schedule must carry, and the services and event counts come from the risk model, not from a fresh survey.
- The chain also runs backwards. Change the building, recompute the risk, and the floor can move under a finished design — and nothing in a folder of PDFs says so on its own.
- Every handoff is a value one document establishes and another consumes. Done by hand, each one is a retype, and retypes are where a dossier learns to state two different protection levels for one building.
1. Part 2 decides whether — and how much
The sequence starts with the risk assessment, because everything after it is conditional. IEC 62305-2 assembles the risk R for each risk zone of the structure and compares it, zone by zone, against the tolerable risk RT. Where every zone is already within tolerance, the procedure ends there: no LPS is required, and there is nothing for Part 3 to do. Where any zone exceeds it, §7.3's procedure (Figure 1 of the standard) selects protection measures and re-evaluates until every zone passes.
An LPS enters that loop as a probability, not as hardware: installing a class of LPS steps the probability PB — that a dangerous flash to the structure causes physical damage — down the ladder of Table B.3, and the loop escalates the class until the risk comes within tolerance. So the class is an output of the assessment. It is the answer to "how much protection does this building need", produced by the same arithmetic that decided protection was needed at all.
Note the procedure has three outcomes, not two: no LPS required, required at a stated class — and not reachable by an LPS alone, when even the strictest class with its accompanying measures leaves a zone above tolerance. A tool or a workflow that can only say "class X" flattens the third outcome into the second, which reads as an answer when it is actually a problem. Whatever runs your Part 2 needs a way to say all three, because Part 3 must not begin from the third one as though it were the second.
2. What Part 2 hands Part 3: the floor
The required class arrives in Part 3 through the equivalence of lightning protection levels and LPS classes — LPL I to IV correspond to class I to IV (IEC 62305-3, Table 1) — and from there one choice fans out into most of the external design. The class fixes the rolling-sphere radius and the mesh size of the air termination (IEC 62305-3, Table 2), the typical spacing between down conductors (Table 4), the minimum earth-electrode length the earthing arrangement must reach (5.4.2), and the induction factor ki in the separation-distance formula of 6.3. Change the class and all of them move together.
The direction of the handoff matters. An engineer may design stricter than the assessment requires — a class II system on a building assessed at class III is a design decision, and a document should print it as one, with its reason. Designing weaker is different in kind: the risk was brought within tolerance using the required class's PB, so building to a lower class re-inserts the probability the assessment already showed insufficient. The result is not a more economical design; it is a design whose own risk assessment says the building is unprotected. That is why the required class behaves as a floor, and why a workflow should refuse to cross it rather than politely warn.
One value flows the other way at this boundary, from design back to record: the separation distance s computed in 6.3 — how far conductive parts must stand from the LPS to rule out dangerous sparking — is established by the Part 3 design and belongs in the shared record of the building, because the people who route pipes and cables later are not the people who computed it. We walked that calculation through separately.
3. What both hand Part 4
IEC 62305-4 designs the protection of the electrical and electronic systems inside the structure, and it opens by consuming both earlier parts. From Part 2 it takes the protection level, and the level sets the lightning current parameters everything else is sized from: the impulse current Iimp each incoming-service SPD must carry comes from the LPL via the simplified current-sharing model of D.3.2 and the ratings of Table C.3, and the corresponding figures for telecommunication and signal lines come from Part 2's own Table B.8, read across through C.2.2. A class III/IV design and a class I design are buying different SPDs at the service entrance, and the difference traces back to the risk assessment's decision.
Part 4 also re-reads the risk model rather than re-surveying the building: the number of dangerous events feeding its assessment is Part 2's N figures (C.2.2, NOTE 1), and the services whose entries need coordinated SPDs are the services the risk assessment modelled (C.2.6). This is a seam worth watching in any workflow, because both parts enumerate the same incoming services and nothing in a paper process compares the two lists. A telecom line that exists in the Part 2 model and is missing from the Part 4 schedule is an unprotected entry wearing a completed study's cover page.
From Part 3, Part 4 takes the fact and the shape of the external LPS: whether one exists changes where the lightning current flows — the simplified model assumes half the current of a flash to the structure goes to the earthing system and half returns through the equipotential-bonding SPDs (D.3.2) — and the bonding network it specifies (cross-sections per its Table 1) joins the same conductors, of the same chosen material (IEC 62305-3, Table 6), that the LPS design placed.
4. The chain runs backwards too
Everything above describes the forward direction, which is the direction the documents are written in. Buildings do not cooperate. The plan grows a wing, a server room moves floors, a second power feed arrives — and the risk assessment that set the floor is recomputed. If the required class moves, every value that fanned out from it in §2 and §3 is now derived from a premise that no longer holds: the mesh, the down-conductor spacing, the separation distances, the SPD schedule.
On paper this is invisible. The LPS design report does not know the risk assessment was re-run; it states a class, a date and a result, all of which were true. The failure mode is not a wrong calculation anywhere — it is three individually correct documents that describe two different buildings. The only defence a folder of PDFs offers is someone remembering to re-open all of them, in order, every time any input changes.
5. The same values, retyped — or one model
Count the handoffs in this article: the required class, the protection level, the presence and geometry of the LPS, the separation distance, the service list, the event counts, the conductor material. In a per-part workflow every one of them is read off one document and typed into another tool's form, usually under a slightly different name. Each retype is a place where two studies of one building can silently diverge — and the divergence surfaces at the worst time, when a reviewer puts the documents side by side.
This is the problem Voltbench is built around, so here is how it looks when the three studies run against one model instead. A project is one building, described once. When a study computes, what it establishes is published into a shared basis — with its source study and its clause — and the downstream study reads it there rather than asking you to retype it. These are real rows from the sample dossier's basis table:
| Established | Value | By | Reference |
|---|---|---|---|
| Does the risk assessment require an LPS? | Yes | Lightning Risk | IEC 62305-2:2024, 7.3 (Figure 1) |
| LPS class required by the risk assessment | III | Lightning Risk | IEC 62305-2:2024, Table B.3, 7.3 |
| LPS class / lightning protection level | III | LPS Design | IEC 62305-3:2024, Table 2; IEC 62305-1:2024, Table 3 |
| The structure has an external LPS | Yes | LPS Design | IEC 62305-3:2024 |
| Required separation distance s (m) | 0.2296 | LPS Design | IEC 62305-3:2024, 6.3 |
| Dangerous events N_D + N_L + N_DJ (1/yr) | 0.2241 | Lightning Risk | IEC 62305-2:2024, Annex A; read by IEC 62305-4 C.2.2 NOTE 1 |
| Metallic services modelled by the risk assessment | 2 | Lightning Risk | IEC 62305-2:2024, A.4; read by IEC 62305-4 C.2.6 |
The floor from §2 is enforced, not advised: the LPS design prefills the required class and refuses a weaker one. A stricter choice is allowed and printed as a departure, with the inherited value beside it. And the problem of §4 is handled by the model rather than by memory — an input changed after a study computed flags that study stale, on screen and in the combined document, until it is recomputed. The sample dossier shows the end state: all three chapters, the shared basis stated once, on one fixed example building.
Run the sequence on your building
Describe the building once, then run the risk assessment, the LPS design and the surge protection design against the same model — free on screen, in order.
This guide describes method in the authors' own words for practising engineers; it is not a reproduction of IEC 62305 and does not restate its tables. Clause and table references are to IEC 62305-1 through -4, Ed. 3.0:2024. Always work from a current licensed copy of the standard. Voltbench is a calculation aid and does not replace the judgement of a licensed engineer of record.