The New Bulk-Power Cyber Order: What Utilities and their Vendors Should Do Now

The order gives the Secretary of Energy broad authority over foreign-produced grid equipment and the software, firmware, maintenance and remote access that come with it. No implementing rules exist yet. That is precisely why the technical work should start now.

Tom Parker · Foridian · 2026-08-26

On 26 August 2026 the President signed Executive Order 14420, declaring a national emergency over the United States bulk-power system. It gives the Secretary of Energy authority over foreign-produced bulk-power equipment, and, more consequentially, over the software, firmware, digital services, maintenance arrangements and remote-access capabilities that arrive attached to it.

The instinct in most organisations will be to wait. Nothing is banned outright, no implementing rules have been published and there is no filing due. I understand that instinct. It is a behaviour we see repeatedly in cybersecurity across regulated industries. But inaction here is a mistake, not because enforcement is imminent, but because much of the work that will eventually matter takes months, possibly years, and some of it simply cannot be reconstructed after the fact.

There is precedent for what happens when national-security policy forces a rapid change in a country's infrastructure technology stack. In 2020, the United Kingdom decided that Huawei equipment would have to be removed from its 5G networks by the end of next year. The UK government estimated that the decision would delay the 5G rollout by two to three years and add up to £2 billion in costs. That was one vendor, operating within a comparatively bounded technology stack. The challenge contemplated by this order is potentially much broader: an energy system built over decades, containing equipment, firmware, software and critical components sourced through complex global supply chains, including from a country whose strategic relationship with the United States has become increasingly adversarial.

The important point is that the absence of a rule is not the absence of a problem. If DOE ultimately decides that parts of the bulk-power system cannot be trusted, the hard questions will not be legal ones. They will be practical: what is actually installed, where did it come from, what can it do, how confident are you in that answer, and how long would it take to replace?

What the order actually does

Issued under the International Emergency Economic Powers Act and the National Emergencies Act, it lets the Secretary of Energy prohibit the acquisition, importation, transfer or installation of foreign-produced bulk-power system electric equipment where a covered foreign entity has an interest and the Secretary determines the transaction poses undue risk.

The equipment definition is the part worth reading twice. It reaches transformers, inverters, battery storage systems, circuit breakers, protective relaying, generation turbines and industrial control systems (PLC's, RTU's etc), together with the associated software, firmware, digital service, maintenance service or remote-access capability. The order treats the maintenance contract and the remote-access path as part of the asset. That is the correct way to think about it, and it is not how most asset registers are structured in traditional IT environments.

One line is worth dwelling on because it determines how broadly DOE may ultimately act. The order does not require the government to examine every purchase or piece of equipment individually. It says the threat may arise from a single transaction or from an entire class of transactions. In practice, that means DOE could act against a particular acquisition, but it could also impose restrictions across a category of equipment, vendors or transactions that share the same risk characteristics. Section 2 reinforces this by allowing mitigation requirements to apply to individual transactions or whole classes of them, while also allowing the Secretary to pre-qualify particular equipment and vendors. Nothing in the order commits DOE to proceeding case by case.

For equipment already installed, the Secretary may impose conditions on continued use, operation, maintenance, servicing or updating, including requirements to identify, isolate, monitor, secure, disconnect, replace or remove effected kit. That authority is discretionary rather than automatic, and the order requires effects on reliability and safety, the availability of secure replacements and continuity of essential service to be weighed first, with phased compliance permitted.

What remains unknown

Almost all of the detail, which for an executive order, is not uncommon. This is the single most important thing to understand about the current moment, and the reason a compliance-led response is premature.

DOE has not identified any prohibited equipment, vendor or country. The order names none. It defines covered foreign entities generically, by reference to arms embargoes, sanctions regimes and conduct the Secretary determines is detrimental to national security, and leaves the identifying to implementing rules due within 120 days. Those rules could restrict individual transactions, classes of transactions, particular categories of equipment, particular vendors or particular jurisdictions. The order provides for all of them, and the class-level and vendor-level cases are the ones most likely to be underestimated.

One qualification on that first point, because it changes where to look. The order names no country, but the universe of covered jurisdictions is not entirely unknown. Section 5(e) defines a covered foreign entity partly by reference to countries subject to a United States arms embargo or sanctions regime under the International Traffic in Arms Regulations at 22 C.F.R. 126.1, and the policy-of-denial list at 126.1(d)(1) expressly includes China, alongside Belarus, Burma, Cuba, Iran, North Korea, Syria and Venezuela.7 That does not make Chinese-origin equipment automatically prohibited. DOE must still make the risk determination the order requires. But China is plainly within the population an operator should be examining now.

The rest of what is missing is procedural. The order applies prospectively, to transactions initiated after it was signed, so the immediate questions concern installed equipment and forward procurement rather than past purchases. No technical assessment framework has been published: there is no federal test an operator can put equipment through today, and no criteria defining what adequate evidence looks like. No pre-qualified vendor or equipment list exists yet either, though the order provides for one. On procurement specifically, recommendations for Federal Acquisition Regulation changes are due within 180 days, with the FAR Council considering amendments in the 90 days after that.

So there is no standard to comply with, and anyone offering certification against one is selling something that does not exist.

There is no standard yet, but there are clues.

That is worth saying plainly, because the gap between an executive order and its implementing rules is reliably where the compliance industry gets ahead of the facts. But DOE is not starting from a blank page, and the material it has already published is a reasonable guide to the questions it tends to ask.

Energy Cyber Sense is the most directly relevant. Established by Section 40122 of the Bipartisan Infrastructure Law and run by DOE's Office of Cybersecurity, Energy Security, and Emergency Response, it is a voluntary program to test the cybersecurity of energy products and technologies, including bulk-power systems.2 A program whose statutory purpose is testing bulk-power equipment is an obvious place for an implementing rule to look. The order does not say so, and neither has DOE.

Underneath it sits CyTRICS, which uses the national laboratory ecosystem (such as INL and Sandia) to test the software and firmware of energy-sector components, prioritized for impact, prevalence and national security interest. Its published shape is instructive: risk-based prioritization rather than testing everything, component enumeration, laboratory testing, and coordinated disclosure and mitigation with the manufacturer. That is a recognizable model of technical assurance and it maps closely onto what an operator would need to demonstrate. It is worth being careful here, because I have already seen CyTRICS discussed as though it were the standard. It is not. It is a voluntary testing program, it issues no certification, and nothing in the order designates it as anything.3

The Supply Chain Cybersecurity Principles, published by CESER with Idaho National Laboratory in June 2024, matter for a different reason: they run past the product and onto the relationship. Ten principles covering impact-driven risk management, secure development and implementation, transparency, lifecycle support and maintenance, proactive vulnerability management, incident response and operational resilience, with responsibilities distributed between supplier and end user. The order's own reach into maintenance, servicing and updating comes from the same instinct.

NIST SP 800-161 Rev. 1 is the general federal treatment of the same problem and is unusually on point. Its stated concern is products and services that may contain malicious functionality, are counterfeit, or are vulnerable through poor development practice in the supply chain. If a federal rule needs an existing vocabulary for this, that is the vocabulary that exists.

For registered entities, NERC CIP-013 is not a clue but a live obligation: documented supply-chain cyber security risk management plans for high and medium impact BES Cyber Systems, covering procurement processes, vendor-identified incidents, vendor remote access and software integrity and authenticity. Anyone who has built one already holds some of the raw material for this, and has probably also discovered how thin it is once you start asking about firmware provenance.

None of this tells us what the eventual test will be, and it would be wrong to present any of it as a preview. It does tell us the shape of the questions, which is enough to start producing evidence in a form that is likely to be useful whatever DOE publishes.

What you should start doing now

Know what you have

Most operators can produce an asset register. Far fewer can answer, for a given transformer or inverter, who actually manufactured it, who owns that manufacturer, whose firmware is running on it, which third parties can reach it remotely, and who performs the maintenance. That is the inventory this order implies: equipment, manufacturers, ownership and control, critical components, firmware and software, digital services, maintenance relationships, remote-access paths, update mechanisms and the supply-chain dependencies underneath them.

This is the long pole. It cannot be compressed once a deadline exists, and everything else on this list depends on it.

Find the transactions already in flight

The order applies to transactions initiated after 26 August 2026. That makes the open and planned procurement pipeline the most time-sensitive item here, and it is not where most people will look first, because the instinct is to worry about what is already in the ground.

Anything involving foreign-produced bulk-power system equipment that is out to tender, under negotiation, contracted but undelivered, or scheduled for the next capital cycle deserves attention this month. Some of those decisions can still be shaped, and a few probably should be. A transaction that closes in November under a rule published in December is a considerably harder conversation than one somebody looked at in September.

Decide what actually deserves scrutiny

Testing everything is not a plan. It is the most reliable way to spend a large budget and arrive with nothing more persuasive than a longer version of the same questions. Evaluate your threat model in the context of this EO, prioritize, and be able to explain the prioritization, because that explanation is itself part of the evidence.

Start with consequence, because it should dominate the rest: what happens to the system if this equipment is breached, becomes unavailable or is otherwise impacted. A small grid-connected inverter and a large substation transformer can carry identical provenance questions and entirely different answers about whether those questions are worth the money. Then ask who manufactured it, who owns that manufacturer, and which jurisdiction they ultimately answer to, since that is what the order itself turns on.

After that the questions become technical, and most of them are about software rather than bare metal. Where the firmware is developed, how updates are signed, and through what infrastructure they are delivered. What can reach the equipment remotely, by which path, and on whose account. And, as a separate question, what it actually communicates with externally, which is not the same as what the documentation says it communicates with. The gap between those two is where the interesting findings usually sit, and it closes only by observing the live environment.

Then the factors that constrain what you could do about any of it. Critical upstream components, where provenance stops being genuinely knowable at some depth, and it is worth establishing in advance where that depth is rather than discovering it under time pressure. Whether the equipment can be isolated at all, and what stops working when it is. And replacement lead time, which on large transformers runs to years and quietly decides which mitigations are real options and which are only rhetorical ones.

Start collecting evidence that will still be good in a year

Evidence collected now, with a documented methodology and chain of custody, gives an operator something that cannot easily be reconstructed later: a contemporaneous baseline of what was installed, how it behaved, and what was known about its provenance at the time. Credibility comes from method, provenance and reproducibility rather than from the date on the report, and a later assessment done well is worth more than an early one done badly. What starting early buys is not superiority but the baseline itself, which cannot be recovered retrospectively.

On priority products, that evidence might include independently obtained firmware images rather than whatever arrives on request, cryptographic hashes with a record of how and when they were taken, an enumeration of the software and firmware components present, architecture and interface documentation, observed network behaviour from the live environment, an inventory of remote-access mechanisms and who holds them, component provenance established as far up the chain as it can be, technical test results, and a written methodology stating what was examined and what was not.

That last item matters more than it looks. A finding is only as good as the scope statement attached to it, and the scope statement is what makes everything else defensible a year later, in front of somebody who was not there.

Ask your suppliers now

Most of what an operator needs is held by somebody else, and the moment to ask is before it becomes a regulatory request, while the answer is still a commercial courtesy rather than a disclosure with consequences. The questions are not exotic:

  1. Where is the firmware for this product actually developed, and by whom
  2. Who controls the signing keys, and where does the update infrastructure sit
  3. Who can reach this equipment remotely, through what path, and under whose account
  4. Which critical upstream components does it contain, and where do those originate
  5. Can remote access be technically disabled, and what capability is lost if it is

The answers are useful. So is a refusal to answer, or an inability to, which is information of a different kind and worth recording as carefully as any technical finding.

Plan against the order's own verbs

The order sets out what DOE may require for installed equipment: identify, isolate, monitor, secure, disconnect, replace, remove. That is a serviceable planning framework, and adopting DOE's vocabulary has the secondary benefit of making a mitigation proposal legible to the person who has to read it.

For each priority asset, work out which of those seven you could actually do, what each would cost in operational impact, capital and time, and what each would leave you unable to do. Mitigation is explicitly on the table as an alternative to prohibition, and the order requires reliability, safety, secure replacement availability and continuity of essential service to be weighed, with phased compliance permitted. That is room to negotiate, and it is only available to an operator who turns up with worked options. Someone who can price the answers is in a materially different position from someone who can only describe the problem.

Engage intelligently

The technical findings are inputs to decisions that are not technical: legal strategy, regulatory engagement, government-affairs positioning, board communication, procurement and capital planning. Analysis that stops at a findings report has not finished the job.

What technical assurance should actually mean here

What can be built is a body of evidence proportionate to the risk, drawing on architecture review, firmware analysis, hardware analysis, software or source review, supply-chain provenance work, network behavior analysis, remote-access assessment, examination of vendor controls, and the compensating controls already in place.

Not every engagement needs all of that, and treating the list as a menu to be worked through is how this becomes expensive without becoming more convincing. The judgment about which of these actually matter for a specific asset, in a specific configuration, against a specific concern is the valuable part.

The strategic issue

This is a larger problem than any technical assessment can settle. Executives will need to connect technical evidence to a regulatory position, that position to a mitigation plan, and the mitigation plan to capital and business decisions with consequences measured in years, with likely down-stream impacts to rate-paying customers and the broader economy. Each link is a different discipline, and the failure mode is a strong analysis in one that never reaches the others.

That is also why this sits awkwardly with a conventional security engagement. A basic penetration test, and certainly an AI red teaming agent, does not tell a board whether to replace a fleet of transformers (at least not yet).

In short

There is no standard to comply with yet, and there will be no prizes for having waited to find out what it says. The organizations that come through this well will be the ones that spent the intervening months understanding what they have, taking a risk based approach to targeted assessments, and what they can prove.

Primary material

  1. Executive Order 14420, "Declaring a National Emergency to Secure the United States Bulk-Power System" — The White House, 26 August 2026
  2. Energy Cyber Sense Program — U.S. Department of Energy, Office of Cybersecurity, Energy Security, and Emergency Response (CESER)
  3. Cyber Testing for Resilient Industrial Control Systems (CyTRICS) — U.S. Department of Energy, CESER
  4. Supply Chain Cybersecurity Principles — U.S. Department of Energy, CESER, June 2024
  5. NIST SP 800-161 Rev. 1, "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations" — NIST, May 2022
  6. NERC Reliability Standard CIP-013-2, "Cyber Security - Supply Chain Risk Management" — North American Electric Reliability Corporation
  7. 22 C.F.R. 126.1, "Prohibited exports, imports, and sales to or from certain countries" — International Traffic in Arms Regulations, current through eCFR