Back Semiengineering US Executive Order On Energy Grid Supply Chain Security
Compliance with trade restrictions is no longer proving where a device was built, but how the product works.
On August 26, 2026, President Trump signed an executive order declaring a national emergency to ban or restrict the acquisition and installation of high-risk foreign-produced equipment in the U.S. electric grid. It cites hidden cybersecurity vulnerabilities, malware and remote-access risks that foreign adversaries could exploit to disrupt critical infrastructure.
The order affects equipment, hardware, software and firmware used in generation, transmission or control facilities operating at 69 kilovolts or above: large transformers, grid-tied inverters, circuit breakers, battery energy storage systems, SCADA software and industrial control systems among them. Equipment used exclusively in local low-voltage distribution falls outside it, such as standard residential solar inverters and commercial distribution below 69 kV.
No vendor has been named yet — restrictions are currently limited to broad equipment categories combined with country of origin, and the specifics do not exist until the Department of Energy publishes implementing rules, due December 24, 2026. Those rules may take the form of a prohibited-entity list, a pre-qualified vendor white list, or both.
A “Covered Foreign Entity” is defined broadly: any company, national or subsidiary owned by, controlled by, or subject to the jurisdiction of a foreign adversary. It applies to countries under U.S. arms embargoes, including Russia, Iran and North Korea, but China is the real concern, since the others don’t supply much to the power sector. Vendors headquartered in, owned from, or substantially dependent on manufacturing in those jurisdictions are directly affected.
Western and U.S. vendors are not automatically clear. Because the order follows the supply chain downward, a U.S. or European manufacturer that sources critical sub-components — chips, communications modules, internal software — from a covered jurisdiction may still find its finished product restricted. Provenance now has to be established across every tier, not just claimed at the enclosure.
Transactions after August 26, 2026 can be restricted, and the Secretary of Energy can require equipment installed before that date to be monitored, disconnected, replaced or removed. U.S. utilities are already pausing procurement with foreign-linked supply chains and pressing vendors for provenance answers during active bids, well before any rule exists.
A predecessor order was issued in 2020 under the first Trump administration, covering broadly similar ground. It produced a single prohibition action before being suspended and then rescinded in 2021.
Where the 2020 order focused on hardware provenance (who built the transformer and where), the 2026 order extends into the digital layer, naming inverters, battery storage, control systems and industrial control components alongside their software, firmware, remote-access capabilities and update mechanisms. Compliance is no longer proving where a device was built. The concern now is how the product works: its firmware, signing keys, cloud connections and update paths. Moving assembly to another country no longer solves the problem.
The dependency underneath the security argument
The International Energy Agency puts China at roughly 80% of world manufacturing capacity for batteries and solar inverters, and market analysts have placed Chinese firms at around half of all solar inverters installed globally. The United States has also imported large power transformers from China at scale over the past decade.
Two distinct risks follow from that.
The first is availability . A supply base concentrated in one jurisdiction is exposed to trade disruption, export controls, sanctions and single-country industrial shocks, none of which require anyone to act maliciously. Large power transformers already carry multi-year lead times in normal conditions; the alternative supplier base for several categories is thin and cannot be built on a crisis timeline. A restriction regime that outpaces domestic and allied manufacturing capacity creates its own reliability problem, which is why the order requires reliability, safety and replacement availability to be weighed before any removal is ordered.
The second is integrity . Fleet concentration means a single vendor’s remote-update and remote-control authority can span enough installed capacity to matter for grid stability. This is a structural property of the market, independent of the intentions of any particular manufacturer. It is also the argument that most directly justifies the order’s focus on update mechanisms rather than on hardware alone.
Security research has shown that operational technology can contain vulnerabilities enabling scalable, destabilizing attacks on the grid, regardless of country of origin.
Forescout Vedere Labs’ SUN:DOWN report of March 2025 disclosed 46 vulnerabilities across three of the world’s ten leading inverter makers — Sungrow, Growatt and Germany’s SMA — from cloud-based takeover of Growatt units to the hijacking of Sungrow inverters through insecure direct object references and hard-coded credentials that led to remote code execution and full device takeover. Exploited at scale, the researchers warned, such flaws could let an attacker manipulate power generation and stage coordinated load-changing attacks capable of destabilizing the grid. Roughly 80% of the vulnerabilities disclosed across the sector over three years were rated high or critical. The pattern points not to any one country but to a sector-wide problem of engineering quality. More scrutiny is clearly called for, but standards alone don’t settle who can reach that access once a device is in the field.
Chinese companies operate under statutory obligations to assist state intelligence services. This is a documented feature of law , not an allegation conduct, and it quietly converts a vendor’s routine remote-access capability into one a state can compel. No hidden backdoor is required; the maintenance channel designed in for support simply answers to a jurisdiction that can direct its use.
The concern is not hypothetical. In a joint advisory with the NSA, FBI and Five Eyes partners, CISA confirmed that the PRC state- group Volt Typhoon had compromised critical-infrastructure IT environments, energy among them, and assessed with high confidence that the intruders were pre-positioning to move into operational-technology assets and disrupt functions. The agencies judged that behavior inconsistent with conventional espionage, and found access persisting undetected for years in some cases. The campaign points to a deliberate effort to hold grid functions at risk.
Even though the Volt Typhoon findings concern network intrusion rather than supply-chain implantation, the case for treating a vendor’s remote-access authority as a controlled risk doesn’t depend on them — capability, concentration and jurisdiction are enough. That is why the order focuses on remote-access and update mechanisms rather than country of assembly.
Vendors don’t need to wait for the December rules to act, and the essentials hold regardless of how DOE defines them.
Map the supply chain down to component level rather than relying on first-tier attestations. Get ahead of active bids by disclosing manufacturing footprint and component origin to U.S. utility customers before they ask. Assemble the compliance file now: origin certificates, SBOMs, firmware provenance, and update governance that shows who holds signing keys and who can push an update to a deployed fleet. Inventory every remote-access, telemetry and support channel in each product line, and review existing contracts for replacement, disclosure and continuity-of-support obligations.
Similarly, European regulators are moving toward comparable outcomes through different instruments: product-security and operator obligations under NIS2 and the Cyber Resilience Act , and restrictions on certain foreign-made inverters in publicly funded projects. While the mechanisms differ, vendors will largely face the same questions.
If you need to know how your own products would hold up, Keysight’s device security lab can test them, identify vulnerabilities, and help you build the provenance and update-governance evidence buyers are starting to demand.
Impact of Cu Microstructure On The TSV-Induced Residual Stress Within Silicon (Purdue, UCLA) September 28, 2026 by Technical Paper Link
Comparing A7 CFET and A10 Nanosheet FETs From Parasitics to Chip Reliability (TUM, UNIMORE, Applied Materials) September 25, 2026 by Technical Paper Link
Wafer-Scale Sub-5nm Channel Monolayer MoS2 Transistors (CMU, UF, MIT et al.) September 22, 2026 by Technical Paper Link
Designing Multi-kW Power Delivery In 3D Heterogeneously Integrated Systems (U. of Minnesota) September 22, 2026 by Technical Paper Link
High-Intensity Rowhammer Attack On GPUs Leveraging Non-uniform Hammering (U. of Toronto) September 22, 2026 by Technical Paper Link
Knowledge Centers Entities, people and technologies explored
Self-Driving Cars Have An Aging Problem
AI Agent Orchestration For ASIC Autonomy
Startup Funding: Q2 2026
Chip Industry Week In Review
Chip Industry Week In Review
Chip Industry Week In Review
Copper’s Grip On AI Scaling Is Starting To Slip
Chip Industry Week In Review
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
