Cybersecurity

U.S. Executive Order Expands Power Grid Security Review to Software and Supply Chains

The U.S. executive order issued on August 26, 2026, establishes an anticipated framework to restrict high-risk foreign equipment at electric facilities operating at 69 kilovolts or higher, with a focus on software, firmware, remote-access and update channels. The article argues that compliance will depend not only on the country of assembly, but also on the origin of components and the product’s operating mechanisms throughout the entire supply chain.

2026-10-01
5 min read
10 views
certi.news Editorial Team
U.S. Executive Order Expands Power Grid Security Review to Software and Supply Chains

On August 26, 2026, U.S. President Donald Trump signed an executive order declaring a national emergency with the aim of banning or restricting the procurement and installation of high-risk foreign-produced equipment within the U.S. electricity grid. The order is based on risks related to hidden cyber vulnerabilities, malware, and remote-access capabilities that foreign adversaries could exploit to disrupt critical infrastructure.

The framework covers equipment, software, and firmware used in generation, transmission, and control facilities operating at 69 kilovolts or higher, including large transformers, grid-connected inverters, circuit breakers, battery energy storage systems, SCADA software, and industrial control systems. Equipment used exclusively in low-voltage local distribution networks, such as standard residential solar inverters and commercial distribution below 69 kilovolts, is outside the scope described in the article.

Implementing Rules Will Define the Names and Restrictions

The executive order has not named specific suppliers so far. The current restrictions are limited to broad categories of equipment linked to country of origin, while the U.S. Department of Energy is expected to publish implementing rules by December 24, 2026. These rules may include a list of prohibited entities, a list of prequalified suppliers, or both.

The order broadly defines a “covered foreign entity” to include companies or subsidiaries owned or controlled by, or subject to the jurisdiction of, a country considered a foreign adversary. Countries subject to a U.S. arms embargo include Russia, Iran, and North Korea, while the article indicates that China is the greatest practical concern because of its presence in the energy-equipment sector.

Compliance Extends to Components and the Digital Layer

Manufacturing in the United States or Europe does not automatically ensure that a product falls outside the scope of review. The order traces the supply chain downward, which could weaken the position of a Western manufacturer that relies on chips, communications modules, or internal software sourced from a covered entity. Thus, proof of origin becomes necessary across multiple layers, not merely at the level of the outer casing or final assembly country.

The order also expands on a previous order issued in 2020, as it focuses not only on the source of physical equipment, but also on firmware, signing keys, cloud communications, and update and remote-access mechanisms. Transactions completed after August 26, 2026, may be restricted, and the Secretary of Energy may require entities to monitor, disconnect, replace, or remove equipment installed before that date.

Why Does This News Matter?

The article links cybersecurity with the risks of dependence on a single supplier or country. It cites the International Energy Agency as saying that China accounts for approximately 80% of global manufacturing capacity for batteries and solar inverters, while market analyses estimate that Chinese companies account for nearly half of solar inverters installed worldwide. This concentration may create availability risks because of sanctions, export controls, or trade disruptions, as well as safety risks if a single supplier has broad capacity to update or remotely control a large fleet of devices.

The article cites the SUN:DOWN report issued by Forescout Vedere Labs in March 2025, which identified 46 vulnerabilities in three of the ten largest inverter manufacturers globally: Sungrow, Growatt, and Germany’s SMA. The findings included capabilities for cloud takeover, remote execution, and full control of devices. These examples do not establish that the risk is confined to one country; rather, according to the source’s reading, they point to a broader problem in the quality of product-security engineering.

The article also invokes warnings from CISA, the FBI, and Five Eyes partners regarding the China-backed Volt Typhoon group, which infiltrated information-technology environments of critical infrastructure, including energy, and was assessed to be preparing to move into operational-technology assets and disrupt their functions. This remains evidence of network-intrusion risks, not of the insertion of components into the supply chain. Therefore, the two cases should not be equated, while remote-access channels remain a legitimate subject of review.

What Should Companies Prepare For?

  • Map the supply chain down to the component level instead of relying solely on declarations from the first-tier supplier.
  • Prepare certificates of origin, software bills of materials, and records of firmware provenance.
  • Document who holds the signing keys and who can push updates to deployed devices.
  • Inventory remote-access, telemetry, and support channels across every product line.
  • Review contracts related to disclosure, replacement, and continuity of support.

In practical terms, the implementation details and the entities that will be included on the lists remain unknown until the Department of Energy issues its rules. Equipment removal may also encounter constraints involving the availability of alternatives and grid reliability, considerations that the order itself indicated must be weighed before replacement decisions are issued. Accordingly, the change confirmed at present is the shift in review from the origin of the final device to the origin of its components and the behavior of its digital layer, not a definitive determination of the eligibility of any particular supplier or product.

News source
Semiconductor Engineering
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news