EU Advisory Group Flags Solar Inverters as Cyber Risk, Urges Procurement Curbs
An advisory body to the European Commission has recommended tightening regulatory oversight of the solar sector over cybersecurity concerns, identifying inverters and their software as potential vulnerabilities in the power grid.
The Solar Energy Expert Group (SEEG) published a report outlining measures to limit exposure to equipment sourced from suppliers under risk-country jurisdictions. The document does not name any specific country or company, and it does not represent an official Commission position — but it signals growing EU-level concern about grid security as solar capacity has expanded dramatically. Installed capacity across the bloc stood at 406 GW in 2025, compared with 86 GW ten years prior.
The group put forward three concrete proposals:
- Restrict components and software from suppliers under third-country risk jurisdiction, applying criteria defined under the CSA2 project.
- Replace automatic firmware updates with controlled manual processes for commercial and industrial (C&I) facilities.
- Assign inverters Security Class II status under the Cyber Resilience Act, requiring independent compliance assessment, and establish a shared 1 MW threshold under the NIS2 directive.
The authors themselves flag a key tension: imposing restrictions without sufficient alternative supply could seriously harm the market, so any such steps must be grounded in thorough risk assessment. Even if the recommendations are adopted, new Cyber Resilience Act requirements would apply only to products released after 11 December 2027 and would not affect equipment already installed.
Source: PV Magazine
Become a member of 100 RE UA
Switching to 100% renewable energy in Ukraine is possible!
