TL;DR
The White House declared a national emergency over certain foreign-produced equipment in the U.S. bulk-power system, including risks from remote access, software, firmware and maintenance dependencies.
The order doesn’t prove hidden backdoors exist throughout the grid. It does show how hard remediation becomes after critical hardware is installed.
Supply-chain security starts with knowing what you own, how it communicates and what replacing it would actually take.
On August 26, the White House declared a national emergency over the foreign supply of equipment used in the U.S. bulk-power system.
The phrase that got the attention was “digital backdoors.” The order says some foreign-produced equipment might contain them and could allow remote foreign access. It doesn’t say investigators proved that hidden backdoors exist throughout the U.S. grid.
That distinction matters because a credible risk isn’t the same thing as a confirmed compromise.
The more useful word appears later in the order: inventory.
The Department of Energy is directed to identify risky equipment and recommend ways to identify, inventory, isolate, monitor or replace it. For equipment that is already installed, the Secretary can impose conditions that include securing, disconnecting, replacing or removing it.
That sequence should look familiar to every security leader. Before you can contain something, you have to know it’s there.
The Hardware Is Already There
The new order covers much more than transformers. It reaches grid-connected inverters, battery energy-storage systems, generators, protective relays, industrial control systems, programmable logic controllers, intelligent electronic devices and associated software, firmware, remote-access capabilities and lifecycle maintenance mechanisms.
Some of that equipment will be installed after the order. Some of it is already operating.
The latter category is harder.
Before the government directs isolation, disconnection, replacement or removal of existing equipment, the order requires Energy to consider reliability, safety, the availability of secure replacements and continuity of essential service. That’s not ceremonial caution. It’s the operating constraint.
You can’t treat a power transformer like a compromised laptop.
DOE’s 2024 report to Congress on large power transformers describes them as expensive, highly customized and difficult to transport. It says current manufacturing lead times can reach and exceed 36 months. DOE said again this month that critical grid equipment can carry lead times of two years or more.
So imagine the security answer is “replace it.” Fine. With what? How quickly? What does the grid do while you wait? Can the replacement be transported to the site? Is there another supplier that can meet the electrical and physical requirements?
The vulnerability may be technical. The remediation is constrained by physics, manufacturing capacity and procurement decisions made years earlier.
The Firewall Assumed the Hardware Was Telling the Truth
There’s another reason this story deserves more than a procurement-policy reading.
In May 2025, Reuters reported that U.S. experts had found undocumented communications equipment inside some Chinese-made solar inverters. One of its two anonymous sources also said undocumented communications devices, including cellular radios, had been found in some batteries from multiple Chinese suppliers.
The caveats are important. Reuters couldn’t determine how many inverters or batteries had been examined. The sources weren’t named. The report didn’t establish that every Chinese inverter contained undocumented hardware, that the devices had been used maliciously or that the U.S. grid had been broadly compromised.
Still, the mechanism matters.
Utilities can put firewalls around the communications paths they know about. An undocumented radio creates a path the network design may not know exists. The firewall didn’t suddenly fail. The inventory was incomplete.
That’s a different class of security problem. The documented interface may not be the complete interface.
A software vulnerability often gives you something concrete to hunt for: a version, a hash, a package, a CVE. Hardware and firmware supply-chain questions can be uglier. What is actually inside the device? Which components came from which suppliers? Which maintenance channel can reach it? What behavior is undocumented because nobody knew to ask?
The Reuters report isn’t proof of a hidden kill switch. It’s evidence that provenance and interface discovery deserve a place in the threat model.
Procurement Is Architecture
Security teams often inherit supply-chain risk after the consequential decisions have already been made.
The vendor was selected. The contract was signed. The equipment was ordered. The remote-support model was accepted. The update path was designed. The dependency on the manufacturer became part of operations.
Then security gets asked whether the system is safe.
NIST’s new July 2026 due-diligence guide for cybersecurity supply-chain risk management is useful here because it refuses to reduce the problem to a vendor questionnaire. Its assessment components include foreign ownership, control or influence, provenance, resilience, foundational cyber practices and supply-chain tiers.
FERC has been moving in the same direction for the bulk-power system. In September 2025 it approved new action on supply-chain risk-management reliability standards, building on requirements for entities to address risks in industrial-control-system hardware, software and services.
The common thread is visibility before dependence.
Procurement determines more of your eventual security architecture than most organizations admit. It can determine who can maintain the equipment remotely, how updates arrive, which supplier dependencies sit underneath the product and whether you have a realistic replacement path when the risk changes.
By the time an incident responder sees an alert, those choices may already be sunk costs.
The Flag on the Box Is Not a Control
The executive order explicitly pushes federal procurement toward U.S.-manufactured energy infrastructure. That can reduce some geopolitical and supply-disruption risks. It doesn’t turn country of origin into a complete security model.
NIST’s July guidance makes that clear without making a political argument. Foreign ownership, control or influence is one component of due diligence. So are provenance, resilience, basic cyber practices and the tiers behind the supplier you are directly buying from.
Domestic equipment can still have vulnerable firmware, weak remote access or fragile supplier dependencies. Foreign equipment isn’t one homogeneous risk category either.
So I’d resist the easy translation of this order into “buy American and the security problem goes away.” The government itself is building a more granular model. The order allows the Secretary of Energy to establish criteria for pre-qualified equipment and vendors, while also evaluating particular transactions and existing equipment based on risk.
The useful question isn’t which flag is printed on the shipping crate.
It’s whether you understand the equipment’s provenance, communications paths, update and maintenance mechanisms, supplier dependencies and replacement options well enough to make a decision when the threat model changes.
The grid makes this problem dramatic because the equipment is enormous, the service is essential and some replacements take years. The leadership lesson travels well beyond utilities.
Take the technology your organization can’t operate without and look at three things: remote-access or maintenance channels you don’t directly control, supplier or component tiers you can’t currently trace and replacements that would take months or years instead of days.
If the answer is “we don’t know,” that doesn’t mean the equipment is compromised.
It means you don’t know which options you have if a vulnerability, sanctions decision, supplier failure or incident suddenly changes the acceptable risk.
That’s why inventory belongs at the beginning of this story, not after the headline about backdoors.
In 2020, DOE was already restricting certain Chinese-supplied bulk-power equipment serving critical defense facilities. In 2025, FERC tightened the supply-chain conversation again. Now the federal government has declared a national emergency and is explicitly considering how to identify, inventory, isolate, monitor and replace risky equipment already in the field.
Two facts can sit next to each other without much editorial help: the risk has been on the government’s radar for years, and the installed base still matters enough to require a new emergency order.
Security debt isn’t always old code.
Sometimes it arrived on a pallet, passed procurement and became part of the infrastructure before anyone asked how hard it would be to remove.
If a critical system can’t be inventoried, isolated, monitored or replaced without threatening the business it supports, procurement already made part of your incident-response plan.
Security should know what it bought before the incident decides for you.
Resources
Executive Order 14421, Declaring a National Emergency to Secure the United States Bulk-Power System, August 26, 2026, published in the Federal Register August 31, 2026: https://www.govinfo.gov/content/pkg/FR-2026-08-31/pdf/2026-17843.pdf
The White House, Fact Sheet: President Donald J. Trump Declares a National Emergency to Secure America’s Bulk-Power System, August 26, 2026: https://www.whitehouse.gov/fact-sheets/2026/08/fact-sheet-president-donald-j-trump-declares-a-national-emergency-to-secure-americas-bulk-power-system/
U.S. Department of Energy, Large Power Transformer Resilience Report to Congress, July 2024: https://www.energy.gov/sites/default/files/2024-10/EXEC-2022-001242
U.S. Department of Energy, Strengthening America’s Grid Supply Chain, August 2026: https://www.energy.gov/oe/articles/strengthening-americas-grid-supply-chain
Reuters, Rogue communication devices found in Chinese solar power inverters, May 14, 2025, republished by Investing.com: https://www.investing.com/news/stock-market-news/ghost-in-the-machine-rogue-communication-devices-found-in-chinese-inverters-4043741
Federal Energy Regulatory Commission, FERC Takes Action to Enhance Reliability of the U.S. Electric Grid, September 18, 2025: https://www.ferc.gov/news-events/news/ferc-takes-action-enhance-reliability-us-electric-grid
National Institute of Standards and Technology, SP 1326, Cybersecurity Supply Chain Risk Management: Due Diligence Assessment Quick-Start Guide, July 8, 2026: https://csrc.nist.gov/pubs/sp/1326/final
U.S. Department of Energy, Secretary of Energy Signs Order to Mitigate Security Risks to the Nation’s Electric Grid, December 17, 2020: https://www.energy.gov/articles/secretary-energy-signs-order-mitigate-security-risks-nations-electric-grid
Source note: the Federal Register identifies the August 26 order as Executive Order 14421. The White House order page currently labels it 14420, which duplicates the number shown for an August 10 order on the White House executive-order index. I use the Federal Register number here and avoid relying on the White House page for the identifier.
Analytical note: the argument that procurement decisions become part of incident-response capability is my interpretation of the order, DOE replacement constraints, NIST due-diligence guidance and FERC supply-chain requirements. The Reuters findings are reported findings based on anonymous sources and an undisclosed sample size, not proof of broad grid compromise.


