UL, NREL unveil DERs cybersecurity report, call for industry standards to protect against threats

March 8, 2022
Facebook
Twitter
LinkedIn
Reddit
Email
The report noted how the market shift towards DERs in the US was increasing the need for industry cybersecurity standards. Image: UL.

Safety and certification company UL and the US Department of Energy’s (DOE) National Renewable Energy Laboratory (NREL) have released a report into the cybersecurity of US interconnected grid edge devices and inverter-based resources that calls for security standards to be established to counter potential threats.

The report pointed to a “market shift from utility-scale to distributed generation”, meaning greater protection of distributed energy resources (DERs) is required to ensure the security of those assets and the wider US grid system from cyberattacks.

This article requires Premium SubscriptionBasic (FREE) Subscription

Try Premium for just $1

  • Full premium access for the first month at only $1
  • Converts to an annual rate after 30 days unless cancelled
  • Cancel anytime during the trial period

Premium Benefits

  • Expert industry analysis and interviews
  • Digital access to PV Tech Power journal
  • Exclusive event discounts

Or get the full Premium subscription right away

Or continue reading this article for free

It said DERs depend on advanced computer systems in both the information technology (IT) and operational technology (OT) space, which could be potentially infiltrated by common cyberattacks, such as eavesdropping, replay, man-in-the-middle (MITM) attacks, denial-of-service (DoS) attacks and more.

“To mitigate the effect of these potential attacks, cybersecurity certification standards and programs need to be established,” said the report, adding that a security standard would support “DER adoption into the grid without risk of compromising grid security.”

While the report will be used to create a “voluntary UL cybersecurity certification standard for DER stakeholders”, there are also plans to develop a future equipment standard and create a market value for cybersecurity certification to motivate industry stakeholders to adopt more secure systems.

A range of DERs are susceptible to cyberattacks, such as electric vehicles (EVs) and wind plants, but solar PV is exposed because of the increasing progression of smart inverter technologies that communicate directly with the grid network. The report said the most common attack vector for solar PV was through monitoring and control capabilities followed by sensor measurements which can be altered to manipulate voltage.  

UL and NREL performed two certification tests on solar PV inverters. The first was performed on industry standard PVs, while the second test was performed on PVs running an intrusion detection communication device (“bump-in-the-wire”) solution called DERCyST.

The tests, which assessed 10 different cybersecurity functionalities, found that “attacks can be mitigated by incorporating software and services, such as DERCyST in Test 2, which enable DERs to pass the certification recommendations into the DER environment”, while Test 1 exposed vulnerabilities in the average industry PV inverter.

The report calls for a ‘defence-in-depth’ approach to cybersecurity that has long been used to secure sophisticated and sensitive IT systems. Under the approach, if an attack were to breach one layer of defence, it would be stopped by a subsequent layer. Each of the 10 layers is described in depth in the report.

UL has reviewed and approved the recommended functionalities, validating their practicality, integrity and use for industry. “UL’s support for this report will accelerate the adoption of the certification recommendation features to a UL certification program and a cybersecurity standard for DERs,” said the report.

“Currently, there are no cybersecurity certification requirements to which manufacturers and vendors can certify their DER and IBR devices against an established and widely adopted cybersecurity certification program,” said Kenneth Boyce, senior director for Principal Engineering, Industrial, group at UL.

“The development of these new cybersecurity certification requirements will provide a single unified approach that can be taken as a reference for performing the testing and certification of DERs before being deployed and while in the field.”

The cybersecurity certification recommendations were informed through working group collaborations among NREL, Sandia National Laboratories, the SunSpec Alliance and “industry partners”.  

PV Tech has written about the importance of cybersecurity to the solar industry in Volume 24 of PV Tech Power. The full article can be read here.

16 June 2026
Napa, USA
PV Tech has been running PV ModuleTech Conferences since 2017. PV ModuleTech USA, on 16-17 June 2026, will be our fifth PV ModulelTech conference dedicated to the U.S. utility scale solar sector. The event will gather the key stakeholders from solar developers, solar asset owners and investors, PV manufacturing, policy-making and and all interested downstream channels and third-party entities. The goal is simple: to map out the PV module supply channels to the U.S. out to 2028 and beyond.
13 October 2026
San Francisco Bay Area, USA
PV Tech has been running an annual PV CellTech Conference since 2016. PV CellTech USA, on 13-14 October 2026 is our third PV CellTech conference dedicated to the U.S. manufacturing sector. The events in 2023, 2024 and 2025 were a sell out success and 2026 will once again gather the key stakeholders from PV manufacturing, equipment/materials, policy-making and strategy, capital equipment investment and all interested downstream channels and third-party entities. The goal is simple: to map out PV manufacturing in the U.S. out to 2030 and beyond.

Read Next

March 24, 2026
Sunraycer has signed long-term power purchase agreements with Google for its Lupinus and Lupinus 2 solar projects in Texas.
Premium
March 24, 2026
The rejection of a 94MW solar PV project in Ohio stems from 'a small group of anti-solar activists', according to the project’s developer.
March 24, 2026
The 'new shape of solar' in the US residential sector is one driven by flexible private financing, according to Aurora Solar.
March 23, 2026
The Ohio Power Siting Board (OPSB) has denied the development of a 94MW solar project following “substantial” opposition from local residents.
March 23, 2026
Terabase Energy has completed testing work at its Terafab version 2 solar module installation process, which is set for commercial shipments.
March 19, 2026
The California Senate Energy, Utilities and Communications Committee has unanimously voted 14-0 (and 3 abstentions) in favour of a bill for balcony solar.

Upcoming Events

Solar Media Events
April 15, 2026
Milan, Italy
Solar Media Events
June 16, 2026
Napa, USA
Solar Media Events
October 13, 2026
San Francisco Bay Area, USA
Solar Media Events
November 3, 2026
Málaga, Spain
Solar Media Events
November 24, 2026
Warsaw, Poland