linkedin

Cybersecurity for BESS & PV Inverters: 3 EU Regulatory Frameworks with an 80 % Market Share in China

NIS-2, the Cyber Resilience Act, and potential manufacturer restrictions are fundamentally changing the requirements for PV systems and battery storage. Our article explains which regulatory developments operators and investors should be aware of now.

According to the German government's assessment, 70 to 80 percent of the PV inverters used in Europe come from Chinese manufacturers. At the same time, regulatory initiatives at the global, EU, and federal levels are intensifying, classifying precisely this dependency as a security risk for critical energy infrastructure. The discussion surrounding the Cybersecurity for renewable energy plants has intensified massively.

The energy transition has fundamentally changed the structure of our power supply. Moving away from a few large, centralized power plants toward millions of decentralized, digitally connected players (such as wind farms, large-scale PV systems, and virtual power plants). Added to this are energy management systems (EMS) that are connected in real-time, AI-controlled, to grid operators, market platforms, and aggregators, directing a company's energy flows. From an IT security perspective, this creates a huge, difficult-to-control attack surface. This is increasingly coming into the focus of geopolitically motivated actors or criminal organizations.

For operators and investors of battery energy storage systems (BESS) and PV plants, this creates a new, three-pronged compliance field. The implementation of NIS-2 in the BSIG and EnWG, the EU Cyber Resilience Act (CRA), and the ongoing reform of the Cybersecurity Act (CSA) with a potential high-risk vendor list. This article classifies the current status and shows what is relevant for operators with immediate effect.

Why the issue is escalating now

The issue is escalating because inverters and battery management systems (BMS) are no longer passive components today, but networked, remote-maintainable components with cloud connectivity, firmware updates, and, in some cases, extensive remote control functions. It is precisely this connectivity that has brought them to the attention of security authorities—not the solar or storage technology itself, but control over the digital interfaces.

The current debate was sparked, among other things, by reports that Chinese inverters—as well as batteries from several Chinese suppliers— undocumented communication components were identified—according to press reports citing U.S. government officials Some include cellular modules. The information has not yet been independently verified, but it has led to an accelerated regulatory reassessment in both the U.S. and the EU.

The German government bases its risk assessment not only on technical criteria, but also explicitly on legal and geopolitical criteria: Chinese companies are subject to far-reaching legal obligations to cooperate with government agencies, which, from a German and European perspective, constitutes a structural risk regardless of the specific case.

The Three Key Areas of the Cybersecurity Debate

The “Regulatory Shock”: NIS-2 and the New IT Security Catalogs

Regulatory pressure regarding cybersecurity is noticeably increasing. Operators of renewable energy facilities are under immense pressure to implement new legal requirements:

  • NIS-2 Implementation: The European Cybersecurity Directive now also imposes obligations on many medium-sized operators and suppliers. Whereas previously only facilities with a capacity of 104 MW or more were considered “critical infrastructure” (KRITIS), the scope has now been expanded to include many more. In addition, the KRITIS umbrella law, effective January 2026, expands physical protection requirements for renewable energy facilities, mandates risk analyses, resilience measures, and crisis and emergency management, and establishes reporting obligations. The German Renewable Energy Federation (BEE) is therefore calling for a balanced approach to ensure that smaller operators are not overwhelmed by red tape.
  • Updating the IT Security Catalogs: The Federal Network Agency has tightened the requirements for power grid and facility operators. The focus is now much more on a Process Orientation – This means conducting ongoing risk analyses and maintaining an effective business continuity management (BCM) system to ensure the ability to continue operations in the event of an outage.

Technical Vulnerabilities and the “Cloud Dilemma”

The Federal Office for Information Security (BSI) and industry experts are warning of structural shortcomings in the cybersecurity of renewable energy systems in practice:

  • Direct Internet Access: In the past, many solar and wind power plants were quickly connected to the grid without giving priority to IT security. Open ports on routers or default passwords often make it easy for attackers.
  • Vendor lock-in: A major topic of discussion is the functional dependence of control systems on manufacturers’ clouds (often located outside Europe). If the cloud goes down or is hacked, the operator loses control of the system. The BSI therefore strongly recommends switching to local operation or using highly secure connections (such as VPNs).
  • Lack of segmentation: Unlike older fossil-fuel power plants, the networks in renewable energy facilities are often not clearly separated into administrative IT and operational technology (OT).

The Supply Chain as a Point of Entry (Supply Chain Risks)

An attacker does not need to hack every wind turbine or solar farm individually. If the manufacturer's software for the grid-connected inverter or if the remote maintenance service provider is compromised, thousands of systems can be manipulated all at once. This applies just as much to the digital infrastructure of C&I; Storage or utility-scale BESS. NIS-2 therefore explicitly includes the entire supply chain It is their responsibility. Operators must actively verify their service providers and the cybersecurity of the components they purchase.

Systemic risk: A single compromised wind turbine does not pose a threat to the power grid. However, if thousands of decentralized power generators are coordinated to be shut down or manipulated through poorly secured interfaces or botnets, this can jeopardize the stability of the entire power grid.

The regulatory triad for cybersecurity: NIS-2, CRA and CSA reform

Brussels and Berlin have responded to this complex interplay of technical vulnerabilities, market concentration, and geopolitical control. They have done so not with a single law, but with a multi-tier regulatory framework. It addresses cybersecurity separately for operators, manufacturers, and individual suppliers. These three sets of regulations overlap and are interrelated, and are relevant to operators of BESS and PV systems:

Quick Overview

NIS-2 (BSIG/EnWG)Cyber Resilience Act (CRA)CSA Reform / High-Risk Manufacturer List
Legal natureNational law (NIS-2 Implementation Act), implemented via the BSIG and EnWG (§ 5c et seq.)EU regulation, directly applicable, no national implementation requiredRevision of an existing EU regulation, currently in the legislative process
AddressedOperators (grid and plant operators, digital energy services/aggregators)Manufacturers, importers, and distributors of products with digital elementsManufacturer of critical ICT components; potential deployment bans for certain suppliers
RulesOrganizational IT security, risk management, reporting obligations, use of critical componentsSecurity-by-Design, vulnerability management, CE marking for digital productscertification schemes (e.g. EUCC/ECCF), potential manufacturer bans modeled after the 5G toolbox
Competent authoritiesBSI, BNetzA, BMI (for critical components), BBK (KRITIS Umbrella Act)National Market Surveillance Authority, ENISA, notified conformity assessment bodiesENISA (expanded powers planned), European Commission
Key deadlinesIn effect since December 5, 2025; registration within 3 months; proof of resilience within 3 yearsReporting obligations from September 11, 2026; full obligations including CE marking from December 11, 2027Proposal presented in January 2026; legislative process ongoing, schedule still open
sanctions frameworkFines between €100,000 and €20 million, partly based on turnovermarket access ban in case of non-compliance, finesPossible complete market exclusion of listed manufacturers
Relevance for BESS/PVOperators must prove risk management, attack detection and, if applicable, the exclusion of critical componentsInverter and BMS manufacturers must secure products throughout their entire lifecycle and report vulnerabilitiesDecide which manufacturers (e.g., from China) remain permitted at all for EU-funded or critical projects

Important for context: The three sets of rules work complementarily. NIS-2 obligates the Operator, CRA obligates the Manufacturer, the CSA reform potentially decides which manufacturers are even permitted anymore. An operator can be NIS-2-compliant and still use a product that is later affected by a high-risk list. Thus, while the issues are legally separate, they cannot be viewed in isolation in practice.

What is a „critical component” – and who is allowed to ban it?

The NIS-2 Implementation Act abolished the previous, complex obligation for manufacturers of critical components to provide a declaration of warranty and replaced it with a more flexible, risk-oriented review and prohibition procedure. The Federal Ministry of the Interior (BMI) can prohibit operators of critical systems from using critical components from a specific manufacturer or issue orders if this use is likely to impair public order or safety. During the review, the BMI takes into account, among other things, whether:

  • the manufacturer is directly or indirectly controlled by the government of a third country,
  • the manufacturer is or can be obliged to cooperate with state authorities or armed forces of a third country,
  • the manufacturer was involved in activities that could impair public policy or security of the Federal Republic or other EU/EFTA states.

In the energy sector, critical functions and components have been fundamentally defined since 2025; starting in 2026, they must be reported to the authorities as part of the registration as an operator of critical facilities. Concrete requirements for grid and system control functions already apply to transmission system operators; an expansion to other facility categories is foreseeable.

At the EU level, the debate is taking a step further: the European Investment Bank is already gradually phasing out new financing for projects involving inverters from high-risk countries (China, Russia, Iran, North Korea), with a transition period for ongoing projects until November 1, 2026, and a stricter phase starting in April 2027. According to the Commission, inverters account for around 5 percent of the costs of large solar plants; switching to lower-risk suppliers is expected to increase total project costs by an estimated less than 2 percent.

Component import instead of finished product import as a solution for cybersecurity?

The public usually simplifies the debate into a dichotomy of „Chinese manufacturers vs. European manufacturers.” In practice, at CUBE CONCEPTS we observe a third, increasingly widespread path that combines cybersecurity and economic efficiency. Manufacturers import individual components – solar cells or modules, battery cells, power semiconductors – directly from China, assemble the end products (module, inverter, Battery storage) in Europe and equip them here with European control, communication, and safety software.

This is relevant for regulatory classification because both NIS-2/BSIG and the debated high-risk vendor list focus primarily on the legal manufacturer and its control structures – not on the origin of individual components. The mentioned BMI evaluation criteria (control by a third-country government, mandatory cooperation with state agencies) are tailored to the manufacturer in the legal sense, not to the physical supply chain of preliminary products. This opens up a scope for interpretation that has not yet been conclusively clarified in the current legislative texts and consultations:

  • Does an inverter whose power semiconductors come from China, but which is finally manufactured by a European company with European firmware, count as a product from a high-risk manufacturer?
  • Is a European software and communication layer sufficient to address the remote access and backdoor concerns discussed in connection with Chinese manufacturers—or does a risk remain at the component level, for example in battery cells with factory-integrated BMS firmware?
  • How is such a hybrid manufacturing chain mapped within the scope of the CRA conformity assessment (Bill of Materials/SBOM, technical documentation according to Annex VII) when essential preliminary products originate from third-country suppliers?

For planners, operators, and investors, this means that merely checking the country of manufacture falls short. Anyone who wants to make reliable statements about the supply chain should also inquire about the origin of critical intermediate products (cell chemistry, power electronics, communication modules) as well as control over the software and firmware level – regardless of where final assembly takes place.

BESS versus PV Inverters: Different Risk Profiles

The public cybersecurity debate has so far focused heavily on PV inverters because their market concentration among Chinese manufacturers (including Huawei, Sungrow, Ginlong Solis) is particularly pronounced. For BESS operators, several points need to be considered separately:

  • Battery Management Systems (BMS) and Power Conversion Systems (PCS) are subject to the same fundamental connectivity risks as inverters – according to press reports, incidents involving undocumented communication modules affected not only inverters, but also battery components from several Chinese suppliers.
  • FTM large-scale storage system with grid service contracts (balancing energy, redispatch) are potentially more sensitive from a grid stability perspective than distributed small-scale systems, as they bundle concentrated capacity with direct systemic relevance—at the same time, they are generally already subject to stricter requirements today, such as through NIS-2 or the Federal Network Agency's IT security catalog, if they are classified as critical infrastructure.
  • Smaller, distributed systems (home storage, small C&I systems) tend to be more poorly regulated according to SolarPower Europe, even though they are also networked via manufacturer-owned clouds or installer backends and can therefore represent an aggregated risk.

For operators and investors, this means that the cybersecurity assessment of a project should not only consider the inverter level, but the entire digital chain – BMS, EMS, PCS, Communication modules and the respective backend connections.

Practical implications for operators & investors

  • Document supplier selection: Anyone who operates or might become an operator of a critical facility should already document the origin and legal control structure of inverter, BMS, and PCS manufacturers in a verifiable manner – not only when a prohibition order is imminent. This includes the component level: in the case of European final assembly with Chinese preliminary products, a look at the origin of the cell chemistry, semiconductors, and firmware is worthwhile.
  • Keep track of deadlines: The CRA reporting obligations for manufacturers take effect starting in September 2026, and the full requirements apply from December 2027. Operators should demand evidence of the CRA roadmap from their suppliers early on, even though the obligation formally lies with the manufacturer.
  • Check NIS-2 applicability: Operators that have not previously been classified as subject to KRITIS requirements (such as digital energy services/aggregators) may newly fall under the scope of the BSIG or EnWG due to the expansion of the addressed group.
  • Regulatory development is not yet complete: The CSA reform with the potential high-risk manufacturer list is still in the legislative process; an exclusion of certain manufacturers is likely, but the scope and timing are still open.

Timeline: The most important cybersecurity deadlines

blank

Frequently Asked Questions

Are Chinese inverters being banned in the EU?

As of July 2026, there is no general ban. However, the EIB is gradually phasing out new financing for projects involving inverters from high-risk countries, and the European Commission is discussing a high-risk manufacturer list modeled after the 5G toolbox as part of the CSA reform. Additionally, the German Federal Ministry of the Interior (BMI) can prohibit the use of critical components from individual manufacturers on a case-by-case basis.

When will the Cyber Resilience Act apply to BESS components?

Reporting obligations for actively exploited vulnerabilities apply to manufacturers from September 11, 2026. The full requirements, including CE marking for products with digital elements, apply from December 11, 2027.

Are BESS operators automatically subject to NIS-2?

No. NIS-2 obligations depend on plant size, sector, and classification as a critical facility pursuant to the BSI-KritisV or the thresholds for „important” and „essential” entities. A case-by-case assessment is required.

What distinguishes NIS-2 from the Cyber Resilience Act?

NIS-2 targets operators of facilities and networks and regulates organizational cybersecurity (risk management, reporting obligations). The CRA targets manufacturers of products with digital elements and regulates product safety over the entire lifecycle.

Free initial consultation

Analyze load profile & location — find the most cost-effective energy solution in 30 minutes.

We analyze your location, load profile, and procurement costs independently of manufacturers. You will find out immediately how PV and battery storage systems can reduce your grid costs and make optimal use of regulatory deadlines (EnWG, EPBD) – without technical risk or capital investment.

Keep an eye on regulations and deadlines · Incl. 250+ simulation variants · Free & without commitment

More interesting articles

PV Purem by Eberspeacher

More sustainability with 1.9 MWp: Purem by Eberspächer uses solar power

The new large-scale photovoltaic system covers a significant portion of the exhaust system production's self-consumption and strengthens the Eberspächer Group's global footprint. By collaborating with CUBE CONCEPTS, the company consistently continues its path toward sustainable energy supply and reduces emissions directly at the source.

Read more "
Solar carports - aerial view

Newsletter registration