Blog

What the New US Bulk-Power Emergency Order Actually Does

The new national emergency is a supply-chain intervention, not an immediate cyber-response to recent attacks on US water utilities or the reported UK generating-plant incident.

On 26 August 2026, President Donald Trump declared a national emergency concerning foreign-produced equipment used in the US bulk-power system. Despite the timing, the order does not mention Iran, the recent disruption of US water utilities or the reported four-day shutdown of a small UK generator. Its structure instead follows the supply-chain model established by an earlier bulk-power executive order in 2020. On the public evidence, the proximity of these events appears coincidental rather than causal.

DOE can now intervene in grid procurement

The order gives the Department of Energy significant authority over the acquisition, importation, transfer and installation of certain foreign-produced grid equipment.

It is not an automatic ban on all equipment manufactured outside the United States. DOE must determine that the equipment—or its software, firmware, maintenance, digital services or remote-access capability—is connected to a “Covered Foreign Entity” and presents an undue or unacceptable security risk. Covered Foreign Entities include governments and persons connected to countries subject to specified US arms embargoes or sanctions, such as China, Iran, North Korea and Russia, as well as additional entities that may later be designated.

A Chinese-manufactured or Chinese-supplied RTU, substation gateway, SCADA platform, relay, plant controller or DCS used to operate the covered bulk-power system could therefore be subject to prohibition or mitigation. But it is not automatically illegal today. DOE must connect it to a Covered Foreign Entity and make the required risk determination, unless the forthcoming rules establish a relevant country, vendor or product-class determination.

This is broader than a restriction on transformers and switchgear. The definition also includes industrial control systems, RTUs, PLCs, intelligent electronic devices, protective relays, metering, distributed control systems, safety instrumented systems, grid-connected inverters and battery storage. Associated software, firmware, remote access, maintenance and update mechanisms may also be examined.

 

Installed equipment may be the next focus

DOE can impose conditions on equipment installed before the order was issued. Those conditions may require an owner to identify, isolate, monitor, secure, disconnect, replace or remove equipment.

The order also directs DOE and other federal agencies to identify potentially risky equipment and recommend ways to identify, inventory, isolate, monitor or replace it. Utilities are not yet expressly required to submit equipment inventories or remediation plans, but the direction of travel is clear. Future DOE rules are likely to require substantially more visibility into equipment provenance, firmware, vendor access, maintenance arrangements and foreign supply-chain dependencies. DOE has 120 days to issue implementing rules as needed.

 

Prediction: mitigation will be more common than replacement

For most installed equipment, mitigation is more practical than complete replacement.

The order requires DOE to consider reliability, safety, replacement availability and continuity of essential service before requiring disconnection or removal. It also permits phased compliance and negotiated mitigation.

In practice, remediation may involve:

  • removing permanent vendor remote access;
  • isolating equipment from external networks;
  • monitoring communications and outbound traffic;
  • replacing gateways, controllers or communications modules;
  • moving maintenance and firmware management to an approved provider; or
  • separating covered equipment from critical operational functions.
  • a 115 kV or higher interconnection substation;
  • grid-connected battery storage or inverters;
  • equipment providing electricity or reliability services to the grid; or
  • certain uninterruptible-power systems supporting critical infrastructure.

Complete replacement is more likely where remote influence cannot be removed, firmware cannot be trusted or verified, or compensating controls cannot reduce the residual risk sufficiently. For large transformers, turbines and other long-lead-time assets, replacing a digital component or surrounding control architecture will usually be less disruptive than replacing the primary equipment.

 

What this means for OT cyber risk quantification

The order creates a practical OT cyber risk quantification question. The decision is unlikely to be a simple choice between accepting an asset and replacing it. Owners will need to compare the risk reduction achieved by removing remote access, improving monitoring, isolating equipment, replacing a digital component or replacing the complete system.

OT CRQ can quantify cyber-physical loss exposure before and after each treatment, while also accounting for the operational consequences of remediation itself: outage time, engineering and recommissioning costs, temporary equipment, emergency procurement, lost production and long replacement lead times. It does not determine whether equipment is legally prohibited; it supports the economic and operational decisions that follow.

The analysis should also extend across the portfolio. A common inverter, relay, gateway, firmware family or remote-service provider may create correlated exposure across multiple substations, generating facilities, battery systems or renewable projects. This is especially relevant where the same technology is deployed at Category 2 resources or 69–99 kV transmission facilities outside the conventional NERC CIP boundary.

The useful output is therefore not a binary compliant-or-non-compliant result. It is an evidence-based comparison of which treatment produces the greatest reduction in expected loss and tail risk for the cost, while preserving safe and reliable operations. When combined with equipment-inventory and supply-chain data, DeRISK CRQ can support this comparison and help identify concentrations associated with common vendors, technologies and operational dependencies.

 

A subtle but important voltage difference

The order expressly includes transmission lines rated at 69 kV or above, while excluding facilities used for local electricity distribution.

By comparison, NERC’s Bulk Electric System definition generally starts with transmission elements operated at 100 kV or above, subject to inclusions and exclusions. That BES boundary strongly shapes the ordinary perimeter of NERC CIP. The new order may therefore reach equipment at 69–99 kV transmission facilities that has often fallen outside the normal BES and CIP boundary.

This does not bring those facilities into NERC CIP. It creates a separate DOE-led supply-chain regime that can apply even where CIP does not.

For OT CRQ, the implication is important: NERC CIP applicability should not be used as a proxy for cyber-physical exposure. Assets outside the conventional CIP perimeter may still create material operational loss and may now fall within DOE’s supply-chain scrutiny.

 

Category 2 solar, wind and battery resources

NERC Category 2 includes certain non-BES inverter-based resources with aggregate nameplate capacity of at least 20 MVA and a common point of connection at 60 kV or above. This population includes many solar, wind and battery-storage projects that were historically outside the BES definition.

Many Category 2 projects connected at 69 kV or above could also fall within the new order’s intended scope. The order expressly includes grid-connected inverters, battery energy storage systems, generating equipment and associated control systems.

Projects connected between 60 and 68.9 kV present a less certain boundary. They meet the Category 2 registration threshold, but fall below the order’s express 69 kV transmission-line threshold. DOE will need to clarify whether their generation and control systems can nevertheless be covered because they are needed to maintain wider system reliability.

That creates a portfolio-level OT CRQ concern: common inverter, plant-controller, gateway, firmware and remote-service dependencies may concentrate exposure across many renewable or storage sites.

 

What it means for AI and hyperscale data centres

AI and data centres are part of the order’s rationale, not its primary regulatory target. The White House argues that their growing electricity demand has increased US dependence on reliable power and magnified the consequences of supply disruption.

The order does not regulate servers, AI models or ordinary data-centre IT systems. A hyperscale operator could, however, be affected where it owns or procures covered energy infrastructure, such as:

Distribution-only and ordinary behind-the-meter equipment is not automatically covered. The more likely commercial effect is that vendor prequalification, equipment-origin requirements and foreign-component restrictions affect the cost, availability and delivery time of the electrical infrastructure needed to connect major data-centre campuses.

 

The present text is only the starting point

The order took effect immediately for transactions initiated after 26 August, but leaves much of its practical scope to DOE.

The implementing rules may identify particular countries, companies, persons or equipment classes for scrutiny. DOE may also establish licensing procedures and lists of prequalified vendors and equipment. The President can subsequently amend or revoke the order, while DOE can revise its implementing rules within the authority delegated to it.

There is already precedent for rapid policy change. The 2020 bulk-power order was suspended in January 2021, and DOE revoked its associated prohibition order in April 2021.

Utilities, generators, renewable developers and hyperscale data-centre operators should therefore treat the current order as a framework—not the final scope of the programme.

The immediate question is not whether every foreign-made asset must be replaced. It is whether owners know what equipment they have, who ultimately controls its software and maintenance, how it communicates, and whether foreign access or influence can be removed without replacing the asset itself.

From an OT CRQ perspective, unknown equipment origin, undocumented vendor access or an unverified maintenance pathway should not be treated as evidence of no exposure. It is uncertainty that lowers confidence in the risk estimate and increases the priority for further investigation.


 

Quantify the treatment, not just the exposure. Removing remote access, isolating equipment, replacing a gateway, replacing the full system — each carries a different cost and a different reduction in expected loss. DeRISK CRQ models cyber-physical loss exposure before and after each treatment, accounting for the operational consequences of remediation itself: outage time, recommissioning, emergency procurement and replacement lead times. Combined with equipment-inventory and supply-chain data, it surfaces the concentrations a single vendor, firmware family or remote-service provider creates across a portfolio. The output is Annual Expected Loss and Value at Risk, facility by facility and rolled up.

Explore the DeRISK Platform → https://www.denexus.io/derisk-platform