The new expert report under the European Commission’s Smart Energy Expert Group (SEEG) calls for stronger cybersecurity requirements for solar PV, including restrictions on the use of high-risk suppliers.
The report, “Recommendations to address cybersecurity risk in photovoltaic generation”, was presented on 1 October and has been developed by experts from the electricity sector, solar industry, regulators, cybersecurity organisations and academia. The report addresses the growing cybersecurity risks associated with Europe’s increasing deployment of digitally connected PV systems. Vulnerabilities in inverters and other connected equipment could potentially be exploited to cause power outages, disruptions and grid instability.
One of its most important recommendations is that the EU should “restrict the use of high-risk suppliers”. The experts conclude that existing legislation does not adequately address the risk of intentional backdoors in supply chains, particularly where manufacturers are subject to the jurisdiction of countries considered to pose significant cybersecurity risks. The report recommends that such risks should be addressed through the revised Cybersecurity Act (CSA) and the Industrial Accelerator Act (IAA). Importantly, the restrictions should not be limited to large-scale installations but should also cover residential PV systems, including plug-in equipment.
The experts also recommend restrictions on components and software from high-risk suppliers across all four categories examined in the report: plug-in residential, residential, commercial and industrial, and utility-scale PV installations.
Other recommendations include stronger control of communications from utility-scale inverters and classifying PV inverters as Class II important products under the Cyber Resilience Act, requiring independent conformity assessment.
For ESMC, the report is an important step forward towards stronger cybersecurity standards for solar PV in Europe. We now expect its recommendations to be reflected in EU and Member State policymaking – not least in the ongoing revision of the Cybersecurity Act (CSA2).
As solar PV becomes an increasingly important part of Europe’s electricity system, cybersecurity and security of supply must become integral parts of European energy and industrial policy.
Jens Holm (Policy Director, ESMC) and Thomas Rührlinger (Head of Public & Regulatory Affairs, Fronius) represented the European Solar Manufacturing Council (ESMC) in the expert group that developed the report.
