Skip to content
World clockEU--:--UK--:--USA--:--CN--:--PLDEFRIT中文EN

portal about AI and technologyevents · analysis · interviews · technical background

Search
LIVE
›

US Order Pushes Grid Supply Chain Scrutiny Into Software Layer

US utilities are pausing procurement and pressing vendors for provenance answers during active bids, weeks before the Department of Energy publishes implementing rules for an executive order signed on August 26, 2026, according to SemiEngineering.

EconomyAnalysisDr. Amara PatelPublished: 2 October 20267 min readSources 9
US Order Pushes Grid Supply Chain Scrutiny Into Software Layer

US utilities are pausing procurement and pressing vendors for provenance answers during active bids, weeks before the Department of Energy publishes implementing rules for an executive order signed on August 26, 2026, according to SemiEngineering. The order declares a national emergency to ban or restrict high-risk foreign-produced equipment in the US electric grid, and it reaches equipment used in generation, transmission or control facilities operating at 69 kilovolts or above.

The story of the week is not the grid order itself. It is the supply chain. On 1 October, EE Times reported from the Pretzl Connect 2026 event in Budapest that Kate Underhill, future space transportation propulsion architect at the European Space Agency, said Europe's strategic space independence depends on semiconductor supply chains, satellite networks and 6G communications as much as on propulsion. Her remarks point at the same nerve the US order touches: who controls the components inside critical systems.

What the order actually covers

The order affects large transformers, grid-tied inverters, circuit breakers, battery energy storage systems, SCADA software and industrial control systems. Equipment used only in local low-voltage distribution falls outside it, including standard residential solar inverters and commercial distribution below 69 kV. No vendor has been named yet. Restrictions are limited to broad equipment categories combined with country of origin, and the specifics do not exist until the Department of Energy publishes implementing rules, due December 24, 2026. Those rules may take the form of a prohibited-entity list, a pre-qualified vendor white list, or both, according to SemiEngineering.

The definition of a covered foreign entity is broad: any company, national or subsidiary owned by, controlled by, or subject to the jurisdiction of a foreign adversary. The order applies to countries under US arms embargoes, including Russia, Iran and North Korea. China is the real concern, since the others do not supply much to the power sector. Vendors headquartered in, owned from, or substantially dependent on manufacturing in those jurisdictions are directly affected.

"We are very conservative in space, and we have a very specific environment for electronics," Underhill said, observing that space systems typically operate "at least 10 years behind consumer electronics."

Western and US vendors are not automatically clear. Because the order follows the supply chain downward, a US or European manufacturer that sources critical sub-components, chips, communications modules or internal software from a covered jurisdiction may still find its finished product restricted. Provenance has to be established across every tier, not just claimed at the enclosure. Transactions after August 26, 2026 can be restricted, and the Secretary of Energy can require equipment installed before that date to be monitored, disconnected, replaced or removed.

This is where the 2026 order differs from a predecessor issued in 2020 under the first Trump administration. That order covered broadly similar ground and produced a single prohibition action before being suspended and then rescinded in 2021. Where the 2020 order focused on hardware provenance, meaning who built the transformer and where, the 2026 order extends into the digital layer, naming inverters, battery storage, control systems and industrial control components alongside their software, firmware, remote-access capabilities and update mechanisms. Compliance is no longer about proving where a device was built. The concern now is how the product works: its firmware, signing keys, cloud connections and update paths. Moving assembly to another country no longer solves the problem.

Space procurement shows the same squeeze

Underhill's comments at Pretzl Connect 2026 give a concrete picture of what constrained supply chains look like for buyers of small volumes. She described an attempt by ESA to order just 20 laser diodes from a German company, where the supplier required a minimum order of 10,000 units. Low satellite launch volumes prevent space component buyers from securing favorable pricing, she said, and ESA is pursuing "spin-in" strategies that adapt high-volume commercial off-the-shelf electronics for spaceflight, while seeking "spin-out" opportunities where space-tested designs can enter commercial terrestrial markets.

Export controls complicate that effort. Underhill said European satellite developers often face compliance challenges tied to US International Traffic in Arms Regulations. "If there is any U.S. component on your satellite, then you have to comply with U.S. regulations," she said. In her keynote, she cited efforts by European manufacturers to construct ITAR-free satellites, which have faced persistent hurdles because certain specialized parts remain available only from foreign suppliers. "We need to identify the components we are still buying from the U.S. or from China and see what we can do in Europe so that we can have control over" those supplies, she said, according to EE Times.

The component problem is not confined to orbit. The same week, security advisories landed across enterprise and industrial gear that sits inside or beside critical infrastructure. On Thursday, Fortinet warned customers about a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices, BleepingComputer reported. The flaw is rated critical with a CVSS score of 9.8 and affects FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9, according to Fortinet's advisory. Gwendal Guégniaud of Fortinet's Product Security team discovered it internally. Security updates were not yet available for affected 7.4, 7.6 and 8.0 installations at the time of the advisory.

On 30 September, Cisco said attackers were exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage Cisco SD-WAN networks, The Hacker News reported. The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager's API as the admin user. It carries a CVSS score of 9.8 out of 10 and sits in the part of the API that handles login sessions. Fixed releases are available and there is no workaround. Cisco said its Product Security Incident Response Team "became aware of active exploitation of this vulnerability" in September 2026, and the flaw was found while its Technical Assistance Center handled a support case. The advisory does not say how many customers were attacked, when the attacks began, who carried them out, or what the attackers did with the access.

Two days earlier, CISA added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities catalog following reports of active exploitation, according to The Hacker News. CVE-2026-88771, with a CVSS score of 9.5, is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772, also 9.5, could allow remote code execution or denial-of-service and requires the DTLS configuration to be enabled, an option turned on by default on VPN virtual servers. CISA said it had received reports and partner threat intelligence confirming that threat actors are actively exploiting the vulnerabilities globally, and gave federal civilian executive branch agencies until September 30, 2026 to apply fixes.

The verification layer

Underneath the policy and the patches sits a measurement problem. A paper submitted to arXiv on 25 September by Paul Trust describes adapting large language models for economic monitoring in the public sector, to determine automatically whether an article discusses Economic Policy Uncertainty and to identify its specific type. The author argues that previous studies either rely on keywords, which often result in a high count of false positives, or use machine learning approaches that require large amounts of quality human labeled data that is costly and time consuming to acquire. The proposed approach uses weak supervision, with generative LLMs creating synthetic labels through prompting, plus methods for multi-label and hierarchical classification of articles related to EPU.

For anyone trying to track how supply chain policy actually lands, that distinction matters. The grid order's own text does not name a single vendor, and the categories it covers are wide. The implementing rules due on December 24, 2026 will decide whether compliance becomes a prohibited-entity list, a pre-qualified vendor white list, or both. Until then, utilities and their suppliers are left reading categories and country of origin, and asking their own vendors where the firmware, signing keys and update paths come from.

Comments 0

Sources

9
  1. 01US Executive Order On Energy Grid Supply Chain SecurityEN
  2. 02Europe's Space Industry Seeks Greater Supply Chain ControlEN
  3. 03Fortinet warns of critical FortiMail flaw exploited in zero-day attacksEN
  4. 04Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN ManagerEN
  5. 05CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws GloballyEN
  6. 06CISA warns of critical pre-auth RCE flaw in MikroTik RouterOSEN
  7. 07Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary ShutdownEN
  8. 08Beyond Keywords: Leveraging Generative LLMs and Label Aggregation to Classify Economic Policy Uncertainty in News ArticlesEN
  9. 09REM sleep paradox: Dreaming may drain the brain's energy even as fuel supply risesEN

All figures and quotations in this text come from the sources listed below.

Content prepared by the editorial team with AI assistance.

Dr. Amara Patel

Dr. Amara Patel

Economy, business and world

Dr. Amara Patel covers business, world affairs and the economy for FLASH24, working from filings, central bank statements and trade data rather than press releases, and she does not let company spin stand in for numbers. She checks revenue recognition, debt covenants and currency effects line by line against audited reports and regulatory disclosures. Her week includes calls with analysts, logistics operators and trade lawyers, and she watches the calendar for rate decisions, earnings dates and port and freight updates, comparing each against prior quarters. Outside the desk she tracks tech-company accounts and rides cargo bikes, which keeps her close to both the balance sheets she reads and the supply chains she covers. She does not publish a figure she cannot trace to a primary document.

Newsroom →

Comments

0
  1. No comments yet — be the first.

Write a comment

Comments are public. We do not publish abuse, spam or advertising.