Aerial view of a large utility-scale solar photovoltaic farm with rows of panels extending to the horizon

Introduction

Today, Europe has never produced so much solar energy. In the first quarter of 2025, solar electricity production across the European continent increased by 32% compared to the same period in 2024, reaching nearly 68 terawatt-hours.1 Over the full year 2025, solar accounted for a record 13% of the EU electricity mix, doubling its share since 2020, and for the first time in history, wind and solar together produced more electricity in Europe than fossil fuels.2 The scale of this transformation is unprecedented. But behind this industrial achievement lies a question that is becoming increasingly difficult to ignore: who controls the intelligence embedded in this system?

At the heart of this question sits the solar inverter, the device that converts direct current from photovoltaic panels into alternating current injected into the grid. Once a simple electrical component, the modern inverter has become a connected system, remotely manageable, cloud-integrated and capable of participating in grid balancing operations. With solar now accounting for 8.2% of European electricity in winter and over 20% in countries such as Spain or Greece in summer, the grid exposure created by these devices is no longer marginal but has become systemic.

The cybersecurity stakes of this exposure are real. To understand why the inverter debate has become so politically charged, one must first understand what cybersecurity means in an industrial context.

Unlike conventional IT security which protects data, Operational Technology (OT) systems control physical processes in the real world such as power grids and industrial platforms.3

Cybersecurity has become one of the defining strategic disciplines of the 21st century. At its core, it is the practice of protecting systems, networks and devices from attacks, damage or unauthorized access. But in the industrial world, it goes far beyond protecting a password or encrypting an email.It is about ensuring that the physical systems that keep our societies running (power grids, water treatment plants, transportation networks) continue to operate safely and without interruption. Over the past decade, cybersecurity has evolved from a niche technical concern into a matter of national security. Governments, military and intelligence agencies now treat it as a strategic priority on par with conventional defense. The reason is simple: a well-executed cyberattack on critical infrastructure can cause the same level of disruption as a physical attack, without a single soldier crossing a border. 

A compromised OT system can cut off a city’s electricity supply or paralyze national infrastructure. The consequences are physical, immediate and potentially irreversible.

The numbers speak for themselves. In the first half of 2025, over 3,000 cyberattacks targeted critical infrastructure worldwide.4 In the energy sector, 67% of organizations reported suffering a ransomware attack in 2024, with an average recovery cost of $3.12 million per incident 60% of these attacks are attributed to state-affiliated actors.5 In 2025, half of all ransomware attacks worldwide hit critical infrastructure sectors, up 34% year on year.6 The solar inverter, connected to the grid and remotely accessible from anywhere in the world, sits precisely at the heart of this reality.

It is in this context that the European debate has intensified. Approximately 80% of photovoltaic systems in Europe use inverters manufactured in China. In December 2025, the European Commission formally identified this concentration as a priority risk.7 In May 2026, it froze European funding for any energy project using inverters from countries designated as high-risk, including China, Russia, Iran and North Korea.8

These decisions reflect legitimate concerns. But the way in which they are being translated into policy raises a fundamental problem. There is a progressive shift from evidence-based technical assessment to geopolitical categorization, from measurable security controls to judgments based on country of origin. And this drift will have consequences far beyond the solar sector. It will define how tomorrow Europe will approach the security of connected vehicles, 6G networks and industrial automation.

When Cybersecurity Regulation Becomes Protectionism

The rise of technological sovereignty and strategic autonomy | How cybersecurity rules can become non-tariff trade barriers | The danger of country-of-origin assumptions

Technological sovereignty is a legitimate objective. Europe has experienced first-hand the consequences of strategic dependency, most notably through its reliance on Russian gas and the vulnerabilities exposed by the war in Ukraine. This experience made it clear that critical infrastructure cannot be managed by external actors whose interests may completely diverge from Europe’s own. This awareness has driven a shift toward supply chain diversification, industrial relocation and stronger oversight of sensitive technologies, including, in our context, the origin of the solar inverters that control the European electricity grid. This is not only understandable, it is necessary.

However, there is a fundamental difference between reducing a genuine strategic dependency and using cybersecurity as a tool to shield a national industry from international competition. Cybersecurity standards can become particularly effective non-tariff barriers: they are technically complex, difficult to challenge before the World Trade Organization, and allow foreign suppliers to be excluded without ever explicitly mentioning their price or competitiveness, creating a deeply uneven playing field. According to the Brookings Institution, the distinction between a legitimate cybersecurity measure and disguised protectionism is precisely what international trade rules struggle most to establish.9

On this specific point, a recent case in Europe provides a telling example of this ambiguity. When several European governments sought to exclude the Chinese telecoms equipment maker from their networks, some considered calibrating security requirements in such a way that the targeted vendor could not structurally meet them.10 Not because its equipment presented documented and proven vulnerabilities, but because the political will to exclude existed before the technical justification. China officially labelled the revision of the European Cybersecurity Act as pure protectionism, warning that it would act decisively if the EU continued down this path.11

Assessing a product based on the nationality of its manufacturer rather than its technical properties and verifiable security controls is the opposite of a rigorous and impartial risk assessment. It is also potentially inconsistent with the EU’s trade commitments: treating products from designated high-risk countries less favorably than others may violate WTO agreements if that designation is not grounded in objective and defensible technical criteria. The solar inverter debate risks reproducing exactly this logic, with the same legal grey areas and the same economic consequences.

Interior of the European Parliament hemicycle with MEPs seated in semicircular chamber, national flags displayed in background
The European Parliament chamber; the legislative arena where cybersecurity policy and trade regulation intersect in the ongoing inverter sovereignty debate.

The Solar Inverter Debate: A European Case Study

Cybersecurity concerns about foreign-manufactured inverters are not unfounded. A modern inverter is no longer a simple current converter. It is a permanently connected system, remotely updated via cloud servers, capable of modulating grid frequency and participating in what are known as virtual power plants. It communicates through industrial protocols such as IEC 61850, Modbus and SunSpec. When 80% of European solar capacity is remotely managed from servers outside the control of local operators, the question of who actually controls these systems is entirely legitimate.12

Recent facts confirm this. In May 2025, undocumented communication components were discovered in Chinese inverters in the United States. Components that, according to American authorities, could allow firewalls to be bypassed remotely.13 In December 2025, Poland suffered the first large-scale coordinated cyberattack on its distributed energy infrastructure: more than 30 solar and wind farms targeted simultaneously during a cold snap, affecting a heat plant supplying 500,000 people.14

But we should pause and examine the facts closely. Because the Polish attack did not exploit hidden backdoors in the Chinese inverters in use. The attack exploited unpatched vulnerabilities in American-made VPN appliances  and accounts without multi-factor authentication.15 Basic vulnerabilities will be present in any poorly secured infrastructure, regardless of the nationality of the equipment. The risk was architectural, not national.

This is precisely the point that the political debate tends to overlook. A European inverter with non-auditable firmware and no security updates is objectively more dangerous than a Chinese inverter certified under IEC 62443 and subject to regular independent audits. The nationality of the manufacturer says nothing about the quality of its security architecture.16 And confusing the two is exactly the mistake that was already made in the 5G debate : same argumentative pattern, same absence of published technical evidence at the time of the decisions, same drift toward political exclusion before technical justification.

A legitimate objection deserves to be raised: if a manufacturer hides a software killswitch inside its product, would a standard like IEC 62443 be able to detect it? This is the most serious question in the debate, and it deserves an honest answer. IEC 62443 alone does not guarantee the detection of a deliberately hidden backdoor. But that is precisely why a standards-based approach must be combined with independent firmware audits, source code analysis by accredited European laboratories, and a Zero Trust architecture that limits the potential impact of any malicious component.17 No approach can guarantee absolute security, including nationality-based exclusion. The question is not to find a perfect solution, but to put in place the most rigorous and verifiable controls possible, for all suppliers without exception. 

The Risks of Politicizing Cybersecurity

The most serious problem with politicizing cybersecurity is not money, it is credibility. When a “high-risk” designation is applied without published criteria and without any possibility of challenging it with technical evidence, it’s the entire objectivity of the risk assessment process that loses its meaning. And if it breaks down for Chinese inverters today, nothing prevents the same logic from being applied tomorrow to any other supplier, based on whatever is politically convenient at the time.

There is also a concrete problem that nobody talks about: the current restrictions only apply to new EU-funded projects. The 200 gigawatts of Chinese inverters already installed on European grids are not going anywhere. And by 2030, this figure is expected to exceed 400 gigawatts according to the European Solar Manufacturing Council, the equivalent of 150 to 200 nuclear power plants supposedly remotely manageable from China.18 If the threat is real, this restriction policy barely addresses it. If it is overstated, it creates costs for nothing. Either way, the response is not up to the challenge.

On the economic side, the numbers put the debate in perspective. Inverters account for approximately 5% of the total cost of a large-scale solar installation. The European Commission itself estimates that switching to alternative suppliers would increase total project costs by less than 2%. But questions remain unanswered regarding existing infrastructure that already relies on equipment from designated high-risk suppliers. European officials acknowledged the issue, stating that the current decision is only a “first step”, to be complemented by additional cybersecurity measures over time.19

Finally, there is a contradiction that Europe cannot ignore indefinitely. It wants energy independence, rapid decarbonization, and at the same time it is restricting the most competitive technologies available to achieve those goals. Ryan Davidson, senior grid consultant at DNV, said it clearly: this move improves energy sovereignty but does very little for actual cybersecurity. China already has enough inverters installed in Europe to cause disruption if it wanted to. Excluding new suppliers does not change that. It just gives the appearance of action.20

Technical Evidence: Security based on facts

The alternative to nationality-based exclusion is not a soft position. It is technically more demanding, legally more defensible and commercially neutral. And contrary to what the political debate suggests, the tools to implement it already exist.

The first pillar is certification and independent audits. Any equipment connected to the European electricity grid should be subject to firmware analysis, penetration testing and coordinated vulnerability disclosure for all manufacturers, without exception. Europe already has the regulatory tools to enforce this. The NIS2 Directive requires operators of critical infrastructure to implement robust cybersecurity risk management measures. DORA extends similar obligations to the financial sector, which indirectly funds much of Europe’s renewable energy infrastructure. The Cyber Resilience Act goes further, imposing security-by-design requirements on all connected product manufacturers selling in Europe. The IEC 62443 standard provides exactly this framework: it organizes industrial systems into security zones with defined requirement levels, and applies directly to solar inverters.21 With the Cyber Resilience Act, this standard will progressively become mandatory for any manufacturer selling connected products in Europe. The proof that it is achievable already exists: Sungrow, a Chinese manufacturer, was the first actor in the renewable energy sector to obtain IEC 62443-4-1 certification, issued by the independent body DEKRA.22 A supplier, regardless of origin, held to the same standards and meeting them is exactly what the principle of technical neutrality requires.

The second pillar is operational sovereignty. The real question around foreign inverters is not their origin, it is control. Can European operators isolate these devices in an emergency without depending on the manufacturer? Are firmware updates approved locally before being applied? Does data remain on European territory? These requirements must become mandatory contractual conditions for any supplier, whether Chinese, American or European.

The third pillar is Zero Trust architecture. Never assume trust, regardless of the origin of the supplier. Network segmentation, least privilege, strict IT/OT separation, real-time anomaly detection. CISA, in its advisory on Volt Typhoon, highlights that the best defense practices, MFA, patch management and OT monitoring, are completely independent of the nationality of the equipment.23 It is the architecture that protects, not the manufacturer’s passport.

These three pillars combined, form a governance framework that is both more rigorous and fairer than nationality-based exclusion. A supplier that meets these requirements is a safe supplier. A supplier that does not is a risky supplier, whether Chinese, American or European. That is the principle Europe must defend if it wants its cybersecurity governance to remain credible in the long term.

Fair Regulation: Avoiding regulation as an industrial policy tool

The solar inverter debate is about more than components, it is a test. A test of Europe’s ability to build cybersecurity governance grounded in technical rigor rather than geopolitical reflex.

If Europe passes this test, by imposing verifiable standards on all suppliers, by guaranteeing the operational sovereignty of its grid operators and by building architectures that resist threats regardless of their origin, it lays the foundation for a resilient digital infrastructure for decades to come. This model can be applied tomorrow to connected vehicles, 6G networks and industrial SCADA systems. 

If it fails on the other hand, by letting the “high-risk” label become a tool of disguised trade policy, it weakens precisely the instrument it needs most: trust in its own standards.24 And that loss of credibility will be difficult to rebuild.

The resilience of European critical infrastructure does not depend on the nationality of the equipment it is built with. It depends on transparent, auditable systems subject to real operational control. These requirements can and must apply to all suppliers. The development of a common security standard, open to operators, grid managers and industrial partners, is the logical next step. Not to close the market, but to secure it on solid and lasting foundations.

A concrete step in this direction is the emerging Cyber-Resilient Trusted Product Framework (CRTPF). This evidence-based initiative is designed to evaluate the trustworthiness of products with digital elements, offering a practical, neutral framework aligned with the EU Cyber Resilience Act (CRA). By focusing on organizational governance, engineering integrity, and independent technical validation, the CRTPF provides a verifiable path for securing the supply chain rather than relying on geopolitical criteria. We invite all energy stakeholders, including customers and partners, to join this effort, contributing to a collaborative and open approach to building a secure, resilient infrastructure ecosystem.

“In critical infrastructure security, the real danger is not globalization itself, but replacing engineering evidence with political assumption.”

  1. Energy Monitor, “Europe’s Solar Electricity Production Surged in Q1 2025,” Energy Monitor, 2025, https://www.energymonitor.ai/news/europes-solar-electricity-production-surged-q1-2025/. ↩︎
  2. pv magazine, “Solar Generates Record 13% of EU Electricity in 2025,” pv magazine, January 23, 2026, https://www.pv-magazine.com/2026/01/23/solar-generates-record-13-of-eu-electricity-in-2025/. ↩︎
  3. For comprehensive definitions and overviews of Operational Technology (OT) and its security distinctions from IT, see Darktrace, “OT (Operational Technology) Security,” Darktrace Cyber AI Glossary, accessed June 11, 2026, https://www.darktrace.com/cyber-ai-glossary/ot-operational-technology-security; Cisco, “What Is OT Security?,” Cisco, accessed June 11, 2026, https://www.cisco.com/site/us/en/learn/topics/security/what-is-ot-security.html; and Industrial Defender, “OT Cybersecurity: The Ultimate Guide,” Industrial Defender, accessed June 11, 2026, https://www.industrialdefender.com/blog/ot-cybersecurity-the-ultimate-guide. ↩︎
  4. Risk & Insurance, “Four Converging Threats Are Making Critical Infrastructure Increasingly Fragile,” Risk & Insurance, accessed June 11, 2026, https://riskandinsurance.com/four-converging-threats-are-making-critical-infrastructure-increasingly-fragile/. ↩︎
  5. EC-Council University, “Cyber Threat Landscape: Energy Sector,” EC-Council University Blog, accessed June 11, 2026, https://www.eccu.edu/blog/cyber-threat-landscape-energy-sector/. ↩︎
  6. Industrial Cyber, “Half of 2025 Ransomware Attacks Hit Critical Sectors as Manufacturing, Healthcare, and Energy Top Global Targets,” Industrial Cyber, 2026, https://industrialcyber.co/reports/half-of-2025-ransomware-attacks-hit-critical-sectors-as-manufacturing-healthcare-and-energy-top-global-targets/. ↩︎
  7. pv magazine, “EU Security Doctrine Highlights High-Risk Dependency on Chinese Solar Inverters,” pv magazine, December 16, 2025, https://www.pv-magazine.com/2025/12/16/eu-security-doctrine-highlights-high-risk-dependency-on-chinese-solar-inverters/. ↩︎
  8. Euronews, “EU Moves to Ban High-Risk Inverters from China Over Cybersecurity Threats,” Euronews, May 4, 2026, https://www.euronews.com/my-europe/2026/05/04/eu-moves-to-ban-high-risk-inverters-from-china-over-cybersecurity-threats.  ↩︎
  9. Brookings Institution, “Cybersecurity, Digital Trade, and Data Flows: Re-thinking a Role for International Trade Rules,” Brookings, accessed June 11, 2026, https://www.brookings.edu/articles/cybersecurity-digital-trade-and-data-flows-re-thinking-role-for-international-trade-rules/. ↩︎
  10. European Parliament, “Answer to Parliamentary Question E-10-2025-003060,” 2025, https://www.europarl.europa.eu/doceo/document/E-10-2025-003060-ASW_EN.html. ↩︎
  11. Light Reading, “Huawei and ZTE Bans in Europe Will Trigger Response, China Warns,” Light Reading, accessed June 11, 2026, https://www.lightreading.com/regulatory-politics/huawei-and-zte-bans-in-europe-will-trigger-response-china-warns. ↩︎
  12. European Union Institute for Security Studies (EUISS), “The Dragon in the Grid: Limiting China’s Influence in Europe’s Energy System,” January 15, 2026, https://www.iss.europa.eu/publications/briefs/dragon-grid-limiting-chinas-influence-europes-energy-system; Defense News, “Chinese Hold on Solar Power Tech Raises Fresh Sabotage Fears in Europe,” May 29, 2025, https://www.defensenews.com/global/europe/2025/05/29/chinese-hold-on-solar-power-tech-raises-fresh-sabotage-fears-in-europe/. ↩︎
  13. Utility Dive, “‘Rogue’ Communication Devices Found on Chinese-Made Solar Power Inverters,” May 15, 2025, https://www.utilitydive.com/news/rogue-communication-devices-found-on-chinese-made-solar-power-inverters/748242/. ↩︎
  14. Dragos, “Poland Power Grid Attack Targets Distributed Energy Facilities,” January 28, 2026, https://www.dragos.com/blog/poland-power-grid-attack-electrum-targets-distributed-energy-2025; Pierluigi Paganini, “Cyberattacks Disrupt Communications at Wind, Solar, and Heat Facilities in Poland,” Security Affairs, 2026, https://securityaffairs.com/187503/apt/cyberattacks-disrupt-communications-at-wind-solar-and-heat-facilities-in-poland.html. ↩︎
  15. Balkan Insight, “Who Was Behind the Largest Cyberattack on Polish Energy Infrastructure in Years?,” February 26, 2026, https://balkaninsight.com/2026/02/26/who-was-behind-the-largest-cyberattack-on-polish-energy-infrastructure-in-years/. ↩︎
  16. This distinction between country of origin and verifiable cybersecurity is further explored in EUISS, “The Dragon in the Grid.” ↩︎
  17. pv magazine, “Solar Inverters Can Detect Cyberattacks, But No One Sees the Signal,” May 1, 2026, https://www.pv-magazine.com/2026/05/01/solar-inverters-can-detect-cyberattacks-but-no-one-sees-the-signal/. ↩︎
  18. SolarQuarter, “ESMC Warns of Cybersecurity Risks in Europe’s Solar Infrastructure Due to Chinese Inverters,” SolarQuarter, May 1, 2025, https://solarquarter.com/2025/05/01/esmc-warns-of-cybersecurity-risks-in-europes-solar-infrastructure-due-to-chinese-inverters/. ↩︎
  19. Euronews, “EU Moves to Ban High-Risk Inverters from China Over Cybersecurity Threats,” Euronews, May 4, 2026, https://www.euronews.com/my-europe/2026/05/04/eu-moves-to-ban-high-risk-inverters-from-china-over-cybersecurity-threats. ↩︎
  20. PV Tech, “EU Bans Funding for Chinese Inverters Over Solar Cybersecurity Concerns,” PV Tech, accessed June 11, 2026, https://www.pv-tech.org/eu-bans-funding-for-chinese-inverters-solar-cybersecurity/. ↩︎
  21. Landis+Gyr, “Cyber Security According to IEC 62443 in the Energy Sector,” Landis+Gyr Blog, accessed June 11, 2026, https://eu.landisgyr.com/blog/cyber-security-according-to-iec-62443-in-the-energy-sector; see also Anern, “IEC 62443 Inverter Firmware Security: Ensuring Solar Energy Safety,” Anern Store DIY Solar Guides, accessed June 11, 2026, https://www.anernstore.com/blogs/diy-solar-guides/iec-62443-inverter-firmware-security. ↩︎
  22. Solar Power World, “Sungrow Inverters Receive International Cybersecurity Certification,” Solar Power World, May 21, 2021, https://www.solarpowerworldonline.com/2021/05/sungrow-inverters-international-cybersecurity-certification/. ↩︎
  23. Cybersecurity and Infrastructure Security Agency (CISA), “CISA and Partners Release Advisory on PRC-Sponsored Volt Typhoon Activity and Supplemental Living off the Land Guidance,” Joint Cybersecurity Advisory, February 7, 2024, https://www.cisa.gov/news-events/alerts/2024/02/07/cisa-and-partners-release-advisory-prc-sponsored-volt-typhoon-activity-and-supplemental-living-land. ↩︎
  24. pv magazine, “EU Security Doctrine Highlights High-Risk Dependency on Chinese Solar Inverters,” pv magazine, December 16, 2025, https://www.pv-magazine.com/2025/12/16/eu-security-doctrine-highlights-high-risk-dependency-on-chinese-solar-inverters/. ↩︎

Leave a Reply

I’m Trustforge.

Welcome to Trustforge.pub. Here, we collaborate with our ecosystem partners and are dedicated to sharing insights into European cybersecurity legislation, trends, and standards, and to sharing best practices in cybersecurity and digital trust from vendors and customers. We aim to inspire you through insights and practices, and we welcome your subscription and participation. Let’s get crafty!

Let’s connect

error: Content is protected !!

Discover more from TrustForge.pub

Subscribe now to keep reading and get access to the full archive.

Continue reading