OFICIAL PV Magazine

EU expert group urges curbs on high-risk solar suppliers

What happened
Based on PV Magazine · Oct 08, 2026

An EU advisory group recommends restricting high-risk solar suppliers, citing cybersecurity vulnerabilities in inverters and dependence on Chinese-origin equipment.

EU expert group urges curbs on high-risk solar suppliers
PV Magazine — pv magazine
Key points
·
EU advisory group recommends restricting high-risk solar suppliers across all PV market segments due to cybersecurity vulnerabilities in inverters
·
Report identifies risks from manufacturer cloud platforms, potential backdoors, and attacks on utility-scale plants through local networks
·
Experts propose classifying inverters as Class II important products under the Cyber Resilience Act requiring independent conformity assessments
Key numbers
·
Other recommendations include enforceable patching deadlines for manufacturer platforms, minimum security qualifications for installers, and a 1 MW threshold for applying the NIS2 directive and electricity cybersecurity network code to...

An expert group advising the European Commission has recommended restricting components and software from high-risk suppliers across all segments of the EU’s PV market, including residential, commercial, and utility-scale systems. The report, prepared by the cybersecurity working group of the European Commission’s Smart Energy Expert Group, reflects a consensus among 11 members, including representatives from SolarPower Europe, ENTSO-E, and Germany’s Federal Office for Information Security. The group highlights urgent risks due to vulnerabilities in inverters, geopolitical tensions, and the EU’s reliance on PV equipment of Chinese origin.

The report identifies three primary risks: attacks on manufacturer cloud platforms linked to large numbers of inverters, potential backdoors introduced by manufacturers on behalf of nation-states, and attacks on utility-scale plants through local networks. It notes that while a manufacturer backdoor attack has not yet occurred, its potential impact warrants serious consideration. The experts also flag a split operational architecture where monitoring dashboards are hosted in the EU, but firmware updates and remote control functions are managed from high-risk jurisdictions.

The recommendations propose restricting components and software from suppliers subject to the jurisdiction of third countries posing significant cybersecurity risks, drawing on criteria from the European Commission’s proposed revision of the Cybersecurity Act. The report cautions that such restrictions could disrupt the market if alternative supply is insufficient and should be based on thorough risk assessments. Under the CSA2 proposal, the Commission could designate high-risk third countries and prohibit components from suppliers established or controlled by them.

The report also calls for inverters to be classified as Class II important products under the Cyber Resilience Act, requiring independent conformity assessments, and for a harmonized cybersecurity standard for inverters. Other recommendations include enforceable patching deadlines for manufacturer platforms, minimum security qualifications for installers, and a 1 MW threshold for applying the NIS2 directive and electricity cybersecurity network code to solar plants.

Original source → Deals on Clipraptor.com →