Three Deadlines Reshaping Grid Cybersecurity

New regulatory milestones are moving cybersecurity from a final compliance check to a design, sourcing, validation, and operations requirement.

Power inverters rarely make national-security headlines. That changed on July 28, 2026, when the U.S. Federal Communications Commission (FCC) added foreign-produced power inverters to its Covered List. The action generally prevents newly covered equipment from receiving FCC authorization unless conditional approval is granted through the applicable federal process. It does not constitute a blanket shutdown of equipment already operating in the field, but it signals that the cyber integrity of grid-connected devices is now a supply-chain and national-security issue.

Three milestones now put that signal into operational context:

Figure 1. Deadlines converge across supply chains, product lifecycles, and utility operations.

These dates are not one common compliance regime. Together, however, they reinforce a practical principle: security evidence and controls must be established before procurement and deployment, then maintained throughout the asset lifecycle.

Inverters move into the security spotlight

Solar and battery energy-storage systems depend on inverters to connect direct-current resources to the alternating-current grid. Modern inverters also contain communications, firmware, monitoring, and remote-control functions. Those capabilities support a flexible grid, but each connected function can create another path for manipulation, disruption, or data exfiltration.

The FCC action affects more than inverter manufacturers. Developers may need to revisit approved-vendor lists and project pipelines. Integrators will need clearer evidence of product provenance, software control, and update practices. Utilities and asset owners may place greater weight on remote-access governance and long-term vendor support. The FCC has published a conditional-approval process, while previously authorized equipment and certain risk-reducing software or firmware changes receive separate treatment. The immediate procurement lesson is to verify a product’s exact authorization status rather than relying on a broad label such as “foreign-made”.

September 2026: Europe puts product response on the clock

The EU CRA shifts attention from where a product was manufactured to how securely it is managed throughout its useful life. From September 11, 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting products with digital elements. The European Commission’s reporting guidance specifies an early warning within 24 hours, a complete notification within 72 hours and a final report after remediation or within the timelines defined for severe incidents. The Act’s principal product-security and conformity obligations apply from December 11, 2027.

For grid modernization, this can reach smart meters, gateways, controllers, monitoring platforms, grid-management software, and other connected equipment placed on the EU market. Manufacturers will need repeatable vulnerability intake, triage, reporting, remediation, and update processes. Utility customers will increasingly expect evidence such as software inventories, secure-update commitments, disclosure channels, support periods, and a clear division of incident responsibilities.

The CRA applies directly to manufacturers and other economic operators, not simply to a utility because it operates a grid. Its practical impact will travel through procurement. Product cybersecurity will become harder to separate from interoperability, performance, cost, and deployment time.

October 2028: visibility moves inside the grid network

NERC CIP-015-1 focuses on operational cybersecurity for relevant bulk power system entities in the U.S. and parts of Canada. Perimeter controls remain necessary, but an attacker or compromised account that gets through them can operate inside a trusted environment. NERC CIP-015-1 requires internal network security monitoring (INSM) within electronic security perimeters to improve the detection, evaluation, and investigation of anomalous or unauthorized network activity.

The first implementation milestone, October 1, 2028, covers high-impact bulk electric system (BES) cyber systems and medium impact BES cyber systems with external routable connectivity located at primary and backup control centers. The second phase, due October 1, 2030, extends the requirement to the remaining applicable medium-impact BES cyber systems with external routable connectivity. The phased dates are defined in the official NERC CIP-015-1 Implementation Plan.

Two years can appear generous, but operational-technology monitoring is not a plug-and-play exercise. Teams must map communications, establish normal behavior, place sensors without disrupting deterministic operations, integrate alerts with response workflows, and validate the system under realistic traffic and failure conditions. Mapping and monitoring these steps during procurement and design gives organizations time to build evidence and test the monitoring architecture before the deadline turns the program into a retrofit.

Figure 2. Build security evidence early, then maintain it throughout grid operations.

One ecosystem, three pressure points

The FCC action, EU CRA, and CIP-015-1 are not interchangeable regulations. One changes equipment authorization and supply-chain decisions; one establishes lifecycle obligations for digital products sold in Europe; and one requires internal visibility within defined bulk-power environments. What connects them is the direction of travel: trust must be demonstrated, monitored, and maintained.

For manufacturers, that means secure-by-design engineering and response readiness. For developers and integrators, it means stronger sourcing controls and acceptance criteria. For utilities, it means asset and communications visibility, tested monitoring, and coordinated response. For laboratories and test teams, it means validating electrical performance alongside protocols, interfaces, update paths, failure behavior, and evidence that can support procurement and compliance.

Grid modernization is creating a more complex, interconnected energy system that requires power, communications, cybersecurity, and network technologies to operate together reliably. Cybersecurity should therefore be built into sourcing, architecture, validation, deployment, and operations, and not added only at the end. Organizations best prepared for these milestones will establish requirements early, verify them before deployment, and continue testing, monitoring, and improving after assets enter service.

Keysight connects design, emulation, and test, helping utilities and their partners validate system behavior earlier, reduce risk, and accelerate readiness before deployment. Explore how Keysight supports grid cybersecurity for modern energy infrastructure, from device and protocol testing to network visibility and operational resilience.

Useful References:

Explore Keysight’s grid cybersecurity and other resources for modernizing the energy infrastructure:

Grid Cybersecurity for Modern Energy Infrastructure

Contact us for expert advice on grid modernization.

www.keysight.com/find/grid

limit
3