EU’s revised cybersecurity law targets ‘high risk’ suppliers

Facebook
Twitter
LinkedIn
Reddit
Email
The proposal outlines measures to identify high-risk companies supplying digital equipment to the EU and exclude them from key digital infrastructure. Image: Flickr.

The European Commission has released its proposal to revise its Cybersecurity Act (CSA), which includes provisions to exclude “high-risk” companies and components from European supply chains.

The proposal was expected last week (14 January) after a months-long review process, but was delayed, reportedly due to disagreements between officials and member states over the scope of the changes to the CSA.

This article requires Premium SubscriptionBasic (FREE) Subscription

Try Premium for just $1

  • Full premium access for the first month at only $1
  • Converts to an annual rate after 30 days unless cancelled
  • Cancel anytime during the trial period

Premium Benefits

  • Expert industry analysis and interviews
  • Digital access to PV Tech Power journal
  • Exclusive event discounts

Or get the full Premium subscription right away

Or continue reading this article for free

The proposal outlines measures to identify high-risk “third countries” and companies supplying digital equipment or components to the EU and exclude them from key digital infrastructure.

The Commission said the proposal aims to enable “the EU and Member States to jointly identify and mitigate risks across the EU’s 18 critical sectors”, which includes energy. Though a press statement by the Commission only outlines the “mandatory derisking” of the telecommunications sector.

For renewable energy, particularly solar PV and energy storage, the major “third country” of risk is China, though the Commission’s proposal does not mention the country at all. Chinese companies have supplied the majority of the EU’s solar inverters in recent months, which has raised cybersecurity concerns in the industry and in Brussels. The EU has already identified solar inverters as a “high-risk” supply dependency in its Economic Security Doctrine published late last year.

For example, data from European PV wholesaler sun.store says that Huawei has been a leading supplier of solar inverters—many of which are digital and connected to cloud servers—despite the fact that the company has been restricted from the EU’s 5G network on security grounds.

The proposal includes provisions to potentially recall and phase out products that are already deployed in EU infrastructure if the supplier is found to be high-risk. PV Tech Premium analysed the implications of a phaseout of Chinese technology for the solar sector last week.

The supply chain restrictions focus on “non-technical” risks, which the Commission says refers to the risk that a supplier is “subject to influence by a third country” that could disrupt an essential service or “the exfiltration of data, including for the purposes of espionage or revenue generation”.

“Cybersecurity threats are not just technical challenges. They are strategic risks to our democracy, economy, and way of life,” said Henna Virkkunen, the Commission’s executive vice-president for tech sovereignty, security and democracy.

“With the new Cybersecurity Package, we will have the means in place to better protect our critical ICT supply chains but also to combat cyber attacks decisively. This is an important step in securing our European technological sovereignty and ensuring a greater safety for all.”

The proposal also introduced clarifications for the European Cybersecurity Certification Framework (ECCF) which it said would “bring more clarity and simpler procedures” and allow some certifications to be “developed within 12 months”. Businesses will also be able to voluntarily submit to ECCF compliance, which it said would be a “competitive asset for EU businesses”. This seems to avoid a mandatory certification process, which was discussed during the CSA review process.

It also brought in measures to bolster the EU’s Agency for Cybersecurity (ENISA), which was introduced with the first passage of the CSA in 2019.

In response to the proposal, Dries Acke, deputy CEO of SolarPower Europe, said: “It is very good that the European Commission takes cybersecurity topics seriously.

“The key remains to have robust EU-wide standards and protocols for cybersecurity that apply to all digital components and companies active on the European energy market. Europe needs to be resilient to all types of attacks from all sides. 

“As the solar-specific risk and impact assessment on cybersecurity is ongoing, we look forward to continuing the constructive cooperation with the Commission, and engage with the renewed mandate of ENISA, as well as through the streamlined European Cybersecurity Certification Framework.”

PV Tech has contacted the Commission for clarification on the Act’s implications for renewable energy.  

3 November 2026
Málaga, Spain
Understanding technology and supplier selection for Europe’s utility-scale PV market in 2027. PV ModuleTech Europe 2026 is a two-day conference that tackles these challenges directly, with an agenda that addresses all aspects of PV module, inverter and battery supplier selection; product availability, technology offerings, supply chain traceability, quality assurance, factory auditing, system reliability, and supplier bankability.
2 February 2027
London, UK
Returning in 2027 for its 14th edition, Solar & Storage Finance Europe will bring together the brightest minds representing funds, banks, developers, utilities, government and industry across Europe and the UK on a programme that is solutions-focused from top to tail. The event is designed to enable leaders at the forefront of solar and storage investment and deployment in Europe to scale, learn and land themselves industry defining partnerships.

Read Next

Premium
September 11, 2026
The financial difficulties of one of Europe’s best-known downstream solar companies highlight the faultlines running through the continent’s PV and energy storage business.
September 11, 2026
Plans for the US’ “first end-to-end” solar PV critical materials recovery and recycling facility have been announced.
September 11, 2026
Italian power utility Enel has bought two solar PV projects in the US with a combined 625MW of generation capacity.
September 11, 2026
Georgia Power has secured Georgia Public Service Commission (PSC) approval for seven solar PPAs totalling 1,137MW under its CARES programmes.
September 11, 2026
European Energy Australia has completed the installation of all 200,172 solar modules at its Winton North solar plant in northeast Victoria.
September 11, 2026
Mint Renewables has referred a solar-plus-storage site with a capacity of up to 375MW, paired with a 3,000MWh BESS, to Australia's EPBC Act.

Upcoming Events

Solar Media Events
October 13, 2026
San Francisco Bay Area, USA
Solar Media Events
November 3, 2026
Málaga, Spain
Solar Media Events
November 24, 2026
Warsaw, Poland
Solar Media Events
February 2, 2027
London, UK