EU expert group urges curbs on high-risk solar suppliers

An expert group advising the European Commission has recommended restricting components and software from high-risk suppliers in every segment of the European Union’s PV market, from plug-in systems to utility-scale plants.

The report, “Recommendations to address cybersecurity risk in photovoltaic generation,” was prepared by the cybersecurity working group of the European Commission’s Smart Energy Expert Group (SEEG). It reflects a consensus among the group’s experts and “does not represent the opinion of the European Commission,” according to the document.

An 11-member subgroup carried out the analysis. It included representatives of SolarPower Europe, ENTSO-E, Eurelectric, Germany’s Federal Office for Information Security (BSI) and the Council of European Energy Regulators (CEER), as well as two members from the European Solar Manufacturing Council (ESMC).

The experts said the European Union’s installed PV capacity grew from 86 GW in 2015 to 406 GW in 2025. They said the risk has become more urgent because of serious vulnerabilities found in inverters, rising geopolitical tensions and “the EU’s heavy dependence on PV equipment of Chinese origin.” The report does not designate any country or company as a high-risk supplier.

Threat scenarios

The report assessed risks across four segments: plug-in residential, residential, commercial and industrial (C&I), and utility-scale. It measured impact by the amount of generation an attacker could control, compared with the continental European grid’s 3,000 MW of frequency containment reserves.

It identified three high risks: attacks on manufacturer cloud platforms connected to large numbers of inverters; backdoors introduced by manufacturers on behalf of a nation-state, which it said applies to all segments; and attacks on utility-scale plants through local networks.

The experts said a manufacturer backdoor attack has not yet occurred in practice, but must be taken seriously because of its potential impact.

The report also flagged a “split operational architecture” in which monitoring dashboards are hosted in the European Union, while firmware updates, signing and remote control functions are operated from countries identified as posing significant cybersecurity risks.

Supplier restrictions

The experts recommended restricting components and software from suppliers subject to the jurisdiction of third countries posing significant cybersecurity risks, drawing on criteria in the European Commission’s proposed revision of the Cybersecurity Act (CSA2). That covers suppliers of components and software to inverter makers, as well as inverter makers themselves.

They added a caveat. “Restricting the use of high-risk suppliers can seriously impact the market if there is not sufficient alternative supply. So, it should only be done based on a thorough risk assessment,” the report said. The experts said they did not carry out such an assessment.

Under the CSA2 proposal, which the European Commission published in January and which has yet to be adopted, the commission could designate third countries as posing cybersecurity concerns and then prohibit components from suppliers established in or controlled by them. Those measures would apply only to entities covered by the NIS2 directive, so the experts said a prohibition should also extend to sales of inverters from high-risk suppliers to consumers.

The report also cites the European Commission’s proposed Industrial Accelerator Act. Its recitals say high-risk suppliers identified under CSA2 should be prevented from supplying critical components to bidders in renewable energy auctions, to public procurement tenderers and to products supported by government intervention.

Other measures

For utility-scale plants, the experts recommended documenting, encrypting and authenticating all inverter internet traffic, limiting outbound connections to approved servers in the European Union or equivalent jurisdictions, and blocking inbound communications from outside the local network.

For C&I and utility-scale installations, they said manufacturer-triggered automatic firmware updates should be replaced with controlled manual updates by qualified maintenance providers, in part to reduce risks at installations already using equipment from high-risk suppliers.

The report also calls for PV inverters to be classified as Class II important products under the Cyber Resilience Act (CRA), which would require independent conformity assessment by a notified body, and for a harmonized cybersecurity standard for inverters. Inverters currently fall into the CRA’s default category, which allows manufacturers to self-assess.

The report noted that CRA product requirements apply only to products placed on the market from Dec. 11, 2027, and not to the installed base.

Other recommendations include enforceable patching deadlines for manufacturer platforms, minimum security qualifications for installers under the Requirements for Generators network code, and a common 1 MW threshold for applying the NIS2 directive and the electricity cybersecurity network code to solar plants.

Manufacturer view

ESMC, which promotes European-made solar manufacturing and represents about 70 companies and research organizations, was represented in the subgroup by policy director Jens Holm and Thomas Rührlinger, head of public and regulatory affairs at Austrian inverter maker Fronius.

“The report is an important step forward towards stronger cybersecurity standards for solar PV in Europe,” said ESMC Secretary General Christoph Podewils. “We now expect its recommendations to be reflected in EU and Member State policymaking – not least in the ongoing revision of the Cybersecurity Act (CSA2).”

The report’s recommendation that web and SSH services on inverters should not be directly exposed to the internet follows research published this week by Dutch firm Modat and the Dutch National Cyber Security Centre, which found 7,942 internet-facing systems at solar parks in 34 European countries that should not have been reachable online.

In April, the European Commission issued guidance restricting EU funding for PV projects using inverters from high-risk suppliers, with a transition period for projects already in the pipeline. Lithuania banned remote access by Chinese companies to solar, wind and storage installations above 100 kW in November 2024, and Czechia’s cybersecurity agency warned in September 2025 that Chinese inverters in small solar plants pose a potential security threat.

The post appeared first on pv magazine Global.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论