Grid Brief ENDE

EU expert group: restrict high-risk solar suppliers in every market segment

A cybersecurity working group of the European Commission's Smart Energy Expert Group (SEEG) has recommended restricting components and software from high-risk third-country suppliers across the whole EU photovoltaic market — from plug-in balcony systems to utility-scale plants — pv magazine reported on 8 October. The report states it reflects a consensus of the experts and "does not represent the opinion of the European Commission", and it names no country or company as high-risk.

Who wrote it. An 11-member subgroup including SolarPower Europe, ENTSO-E, Eurelectric, Germany's BSI, the regulators' council CEER and two members from the European Solar Manufacturing Council (ESMC). The experts note EU solar capacity grew from 86 GW in 2015 to 406 GW in 2025, and cite serious inverter vulnerabilities, geopolitical tension and "the EU's heavy dependence on PV equipment of Chinese origin".

How they measured risk. Impact was judged by how much generation an attacker could control, compared with the 3,000 MW of frequency containment reserve of the continental European grid. Three risks were rated high: attacks on manufacturers' cloud platforms that reach large numbers of inverters; manufacturer backdoors on behalf of a state, which applies to all segments; and attacks on utility-scale plants via local networks. The experts concede a manufacturer backdoor attack has not yet occurred but say its impact warrants taking it seriously. They also flag a "split architecture" in which dashboards are hosted in the EU while firmware signing, updates and remote control run from high-risk countries.

EU expert group: restrict high-risk solar suppliers in every market segment
EU expert group: restrict high-risk solar suppliers in every market segment — Grid Brief

What they propose.

  • Restrict high-risk suppliers using criteria from the Commission's proposed revised Cybersecurity Act (CSA2) — and extend it to inverter sales to consumers, since CSA2 measures would only bind NIS2 entities.
  • Classify inverters as Class II important products under the Cyber Resilience Act, requiring third-party conformity assessment instead of self-assessment.
  • For utility-scale plants: encrypted, authenticated inverter traffic, outbound connections only to approved servers in the EU or equivalent jurisdictions, no inbound access from outside the local network.
  • Replace automatic manufacturer firmware pushes with controlled manual updates for C&I and utility plants; a common 1 MW threshold for NIS2 and the electricity cybersecurity code.

The caveat in the report itself. Restricting suppliers "can seriously impact the market if there is not sufficient alternative supply", so it should follow a thorough risk assessment — which the experts say they did not carry out. CRA product rules apply only from 11 December 2027 and not to the installed base, which is why the manual-update and network measures matter for plants already running.

Source: pv magazine, "EU expert group urges curbs on high-risk solar suppliers", 8 October 2026 — https://www.pv-magazine.com/2026/10/08/eu-expert-group-urges-curbs-on-high-risk-solar-suppliers/

Written by Victoria Shinder.