Chinese PV Inverters as a Security Risk
An inverter is an unremarkable component until you see who can reach it from a distance. Europe depends on Chinese devices for four fifths of its fleet, and they sit on the internet for updates. For grid operators and utilities this is no longer a geopolitical footnote, but a concrete question about their own grid: which devices can be switched off, and whose cloud does that access run through.
About 80% of the solar inverters installed in Europe come from China, dominated by Huawei and Sungrow. The EU security doctrine of December 2025 classifies this dependence as high-risk. Because the devices sit on the internet for updates, control over roughly 10 gigawatts of simultaneously switched capacity is enough, on paper, to disrupt the grid on a large scale. In January 2026 the Commission proposed a high-risk vendor list modelled on the 5G toolbox, and on 23 April 2026 it stopped EU funding for projects with devices from four risk countries. The BSI rejects grid-supportive remote control via the manufacturers and recommends the local path through the smart meter gateway under Section 14a. For grid operators, defence begins with a device inventory that knows the manufacturer and remote access channel of every inverter.
Why an inverter became a security topic
An inverter turns the direct current from the roof into alternating current for the grid. That is the everyday function. The second, quieter function is the interesting one: almost every modern device sits on the internet so the manufacturer can update software, read out faults and adjust feed-in. It is exactly this remote access that turns a component into a security topic.
The European Commission wrote the dependence into its security doctrine on economic security in December 2025. Solar inverters count there as a high-risk dependence. The reason is not a single act of sabotage, but the sheer number of identical devices behind the same remote access. What holds for one holds for hundreds of thousands at once. The fast build-out of wind and solar from China created this concentration in just a few years.
The doctrine names the four risks clearly: the concentration on few suppliers, the danger of cyber manipulation, access to grid-relevant operational data and the possibility that foreign actors infiltrate the supply chain. Two manufacturers, Huawei and Sungrow, dominate the European as well as the global market.
The problem is not a single malicious device, but the sheer number of identical devices behind the same remote access.
Why concentration is the real riskHow a coordinated remote shutdown hits the grid
The decisive number is smaller than you would think. It does not take a majority of installations to unsettle the grid, it takes a single-digit gigawatt block switched at the same moment. And inverters are almost ideally built for it, because they already work in step with the grid.
These figures come from a risk assessment by SolarPower Europe and DNV from April 2025. On top of that is the concrete finding: in 2025 Reuters reported undocumented radio modules that US investigators discovered in imported inverters. Such modules are not in the product documentation and can bypass firewalls. Forescout additionally documented vulnerabilities in the radio dongles of several manufacturers in March 2025, reachable through the manufacturer cloud.
The next build-out is not the problem, the existing fleet is. More than 200 gigawatts of Chinese inverter capacity already sit in Europe's grids and are covered by no funding ban.
The high-risk vendor list on the 5G model
The EU reaches for a tool it already knows. For 5G networks there was a list of critical vendors that member states were meant to follow. Exactly this pattern is now to be transferred to inverters, with all the strengths and weaknesses of the model.
In January 2026 the Commission proposed a list of high-risk manufacturers as part of a revision of the Cybersecurity Act. Being placed on the list bars access to the EU market. The model is the voluntary 5G toolbox of 2020. Its record is mixed: some states excluded Huawei and ZTE entirely, others left them in the network under conditions. Voluntariness produces a patchwork.
The European Solar Manufacturing Council proposes anchoring a whitelist of trustworthy vendors in NIS2 and allowing member states to deny grid connection to high-risk manufacturers.
For utilities this means the list will help decide which devices may be procured and connected at all. Procurement becomes a security decision, not just a price question. Anyone tendering today should already carry the origin of the devices as a criterion, so an award does not turn into a teardown a year later.
The EU funding ban from 23 April 2026
The analysis has become a first hard measure. It does not hit the private roof owner, but the big money: EU-financed energy projects. Anyone who wants public funds has to disclose the origin of their devices.
The ban affects financing from the European Investment Bank and the European Investment Fund. The Investment Bank carried roughly one fifth of EU solar projects in 2025, mostly with Chinese devices. New projects are excluded immediately. For ongoing projects there are reporting obligations and, where feasible, retrofitting. Advanced projects can use transitional exemptions.
Financial institutions had to report their ongoing project pipelines in early May 2026. The funding ban is therefore also an inventory obligation on a tight timeline, and it covers only the funded new build, not the existing fleet in the grid.
Why the BSI rejects control via the manufacturers
In Germany the European debate meets a concrete technical decision. With the Solar Peak Law and PV controllability, the controllability of small installations became mandatory. The only question is which path that control runs through, and here the BSI has a clear opinion.
The BSI views grid-supportive remote control of inverters via the manufacturers very critically. It would give a manufacturer direct access to a systemically important part of the power supply. The second concern is the detour: even without intent on the manufacturer's part, vulnerabilities in the product or in the manufacturer cloud could open access to third parties.
The BSI recommends handling control locally through the smart metering system with a control box under Section 14a EnWG. The control command then runs via the smart meter gateway, not through a cloud abroad. The BDEW supports this path and calls for an economic framework that carries the decentralised solution. The dispute is therefore also one about the architecture of control, not only about the origin of the devices.
Two legal frameworks on one device
The inverter ends up under several sets of rules that overlap but do not coincide. Anyone who keeps only one in view misses the gaps. For a utility's architecture it matters which framework demands what.
| Framework | What it governs for the inverter |
|---|---|
| NIS2 and the BSI Act | supply chain risk management and the legal frame for a possible vendor list |
| Cyber Resilience Act | security properties and certification of the product over its lifecycle, including update duties |
| Radio equipment requirements | apply to the communication modules, cybersecurity becomes a product property |
| Network code on cybersecurity | graded operational duties depending on how critical an asset is for grid stability |
Anyone who has already worked on OT security under IEC 62443 knows this way of thinking. The debate over high-risk AI in energy infrastructure shows the same pattern: several frameworks on the same system, each with its own evidence. The data question in turn is governed by the Data Act for energy utilities and IoT manufacturers.
Evidence under one framework does not automatically satisfy another. Plan the frameworks together and you save double work, work through them separately and you collect gaps.
What grid operators and utilities should do now
The build-up begins not with a ban, but with visibility. Without knowing which devices are reachable through which channel, none of the new duties can be met. The rest follows from that list.
Five steps to defence
-
Build a device inventory
Record every inverter and storage unit in the grid by manufacturer, firmware, communication module and remote access channel. For each device, clarify whether control runs via the manufacturer cloud or locally. Without this list, any further assessment is patchwork.
-
Assess remote access
Mark the devices that can be remotely switched off or have their set-points altered, and estimate the bundled capacity per manufacturer. The 10-gigawatt benchmark is the measure of systemic relevance, not the single installation.
-
Review the control architecture
Move grid-supportive control to the smart meter gateway under Section 14a where possible, instead of routing it through the manufacturer cloud. That follows the BSI recommendation and closes an access path you otherwise do not control.
-
Tie procurement to the list
Factor the future high-risk vendor list and the funding ban into ongoing tenders. Origin and update responsibility belong in the award criteria, not just price.
-
Plan the frameworks together
Use the existing asset inventory from the NIS2 rollout as a base and add the product and radio-related evidence from the Cyber Resilience Act and the network code. Two separate projects cost double, one shared project saves half.
In the end it is not the origin of a single device that counts, but the sum of the access paths that lead from your own grid to the outside. Anyone who knows these paths and keeps the critical ones local has already contained most of the risk. That is work, but it starts with a list, not with a billion-euro budget.
Further reading
Frequently asked questions
About 80% of the inverters installed in Europe come from China, dominated by Huawei and Sungrow. Inverters are internet-connected devices reachable remotely for maintenance and updates. The EU security doctrine of December 2025 classifies this dependence as high-risk and names four risks: supplier concentration, cyber manipulation, access to grid-relevant operational data and infiltration of the supply chain.
In January 2026 the European Commission proposed a list of high-risk manufacturers as part of a revision of the Cybersecurity Act. Being placed on the list bars access to the EU market. The model follows the voluntary 5G toolbox of 2020, which let member states exclude or restrict Huawei and ZTE in critical networks.
On 23 April 2026 the European Commission decided to stop EU funding for energy projects that contain inverters from four high-risk countries: China, Russia, Iran and North Korea. It affects European Investment Bank and Investment Fund financing. New projects are excluded immediately, ongoing ones must be reported and, where feasible, retrofitted. Private rooftop systems under 30 kilowatts are unaffected.
A risk assessment by SolarPower Europe and DNV from April 2025 names roughly 10 gigawatts of simultaneously switched capacity as the threshold for a large-scale disruption. Seven manufacturer groups each control more than 10 gigawatts across Europe. Because inverters work in millisecond control loops with the grid, simultaneous manipulation of their set-points can tip frequency and voltage faster than protective relays react.
The BSI views grid-supportive remote control of inverters via the manufacturers very critically, because a manufacturer would gain direct access to a systemically important part of the power supply. It recommends handling control locally through the smart metering system with a control box under Section 14a EnWG, so the control command runs via the smart meter gateway rather than a manufacturer cloud abroad.
The first step is a device inventory by manufacturer, firmware, communication module and remote access channel. Next comes assessing remote access against the 10-gigawatt benchmark, moving grid-supportive control to the smart meter gateway, tying procurement to the future high-risk list, and planning NIS2, the Cyber Resilience Act and the network code on cybersecurity together.