Why Protecting America's Power Grid Requires Testing Equipment Security, Not Just Country of Origin

Why Protecting America's Power Grid Requires Testing Equipment Security, Not Just Country of Origin

2026-10-11 politics

Washington, D.C., Saturday, 10 October 2026.
The Rainey Center urged the Department of Energy to secure the power grid by enforcing independent cybersecurity testing rather than relying on blanket bans based on manufacturing origin.

Regulatory Shift Toward Verifiable Risk Standards

On October 10, 2026, the Rainey Center Freedom Project formally submitted comments to the U.S. Department of Energy (DOE) regarding the implementation of Executive Order 14421, which addresses national security threats to the bulk-power system [1]. The advocacy group urged federal regulators to implement independent security testing and rigorous evaluation of foreign access pathways rather than relying exclusively on country-of-origin restrictions [2]. This policy recommendation follows the signing of Executive Order 14421 on August 26, 2026, which mandates that the DOE evaluate transactions involving Covered Foreign Entities based on whether they pose an undue or unacceptable risk to infrastructure [4]. The Rainey Center argues that meeting rigorous, independently verified security standards should matter more than country of origin alone to ensure grid reliability [3]. Sarah E. Hunt, President of the Rainey Center Freedom Project, stated that foreign access to America’s electric grid is a serious national-security threat, but the strongest rule is one that measures the actual security risk [1]. The organization emphasizes that secure pathways should be maintained while keeping the capacity the country has contracted to build [2].

Supply Chain Vulnerabilities and Import Reliance

Industry data indicates that over 90 percent of photovoltaic inverters supplied to U.S. commercial, industrial, and utility-scale markets between 2016 and 2026 were imported, highlighting capacity constraints for domestic manufacturing [1]. In 2025, analysts identified undocumented cellular radios in Chinese-manufactured solar inverters, and federal agencies have documented unauthorized state-sponsored access within U.S. critical infrastructure [4]. Large power transformer imports to the U.S. increased from $0.97 billion in 2019 to $4.15 billion in 2025, representing a significant rise in dependency 327.835 [7]. Replacing a major power transformer requires approximately 128 weeks, or roughly 2.5 years, due to current supply chain lead times [7]. Furthermore, Chinese-headquartered companies have delivered more than 70 GW of inverters to America’s commercial and utility solar plants, while each U.S. grid is designed to ride through the sudden loss of roughly 2.8 to 3.9 GW [7]. The Foundation for Defense of Democracies notes that China has been prepositioning capabilities within United States critical energy infrastructure to enable future operational disruption for at least the past five years [5].

Public Opinion and Implementation Timeline

In the Rainey Center’s September 2026 Policy Survey, 81 percent of registered voters expressed concern regarding the possibility of grid equipment being remotely accessed or controlled by foreign entities [3]. The survey further found that 69 percent of voters favored building, testing, and control standards over manufacturing origin, compared to 19 percent who prioritized origin [4]. The deadline for public comments on the Department of Energy’s Request for Information regarding the implementation of Executive Order 14421 was October 9, 2026, though the Rainey Center submission was dated October 10, 2026 [4]. Implementing rules for the executive order are scheduled for release by December 24, 2026 [4]. The DOE is expected to release policy rules in December 2026 and procurement recommendations in February 2027, which the Rainey Center advises should prioritize testable risk criteria [4]. To maintain grid reliability, the center recommends utilizing existing North American Electric Reliability Corporation frameworks for risk assessment and mandating independent laboratory testing of firmware and access architecture [2].

Sources


Energy Policy Grid Security