\n\n

On August 26, 2026, President Trump issued Executive Order 14421, Declaring a National Emergency to Secure the United States Bulk-Power System. The Order establishes a new national security regulatory framework for a broad range of equipment, software, services, and supply chain relationships associated with the U.S. electric grid. Although the Order is framed as a grid security measure, its implications extend well beyond utilities.

Equipment manufacturers, project developers, utilities, contractors, lenders, investors, data center operators, and others participating in the energy sector may all be affected. The Order introduces new restrictions and uncertainty into energy infrastructure procurement and supply chains and, critically, it represents a fundamental shift in how the federal government approaches security risks in the energy sector.

This is not the federal government’s first attempt to establish national security regulations for bulk-power system supply chains. In 2020, President Trump issued Executive Order 13920, which similarly established a framework for reviewing certain acquisitions of bulk-power system electric equipment associated with foreign adversaries. The new EO revives and significantly expands that framework.

Why This Executive Order Is Different – and Why It Matters Now

Like its 2020 predecessor, the Order is based on the same broad legal authority and modeled on the same framework as another national security regulatory authority administered by the Department of Commerce, which addresses the risks posed in the information and communications technology and services (“ICTS”) supply chain. That authority and framework are scalable, allowing the Department of Energy (“DOE”) (like Commerce) the flexibility to conduct case-by-case reviews of specific equipment or companies, regulate entire classes of equipment, or use a combination of approaches to address national security risks. The bulk-power Order highlights the risks of sabotage, unauthorized access, remote access, and supply disruption that can result from certain foreign-produced bulk-power system electric equipment—the same kinds of risks underlying Commerce’s ICTS program, the Federal Communications Commission (“FCC”)’s Covered List, and other national security authorities.

These national security risks are not new but instead have been steadily growing for years. We have seen the Committee on Foreign Investment in the United States (“CFIUS”) increasingly scrutinize transactions in the energy sector that present such risks with respect to Chinese equipment and services, including through commitments involving equipment and vendor screening, supply chain integrity, and software-development security.

Like Commerce’s ICTS program and the FCC’s Covered List, the Order marks yet another standalone national security authority that has grown out of risks addressed through CFIUS and concerns about the limits of its case-by-case reviews. The Order thus marks a shift from scrutinizing foreign ownership and control of companies involved in critical infrastructure to scrutinizing the equipment, software, services, and supply chain relationships that support that infrastructure. Rather than focusing principally on foreign investment reviews or transaction-specific approvals, the Order creates the potential for broadly applicable restrictions on certain products and suppliers regardless of who owns the underlying asset.

The direction of travel is clear: energy equipment, software, and services increasingly will be evaluated through a national security lens. Companies that have never viewed themselves as potential subjects of a national security review process may nonetheless find themselves confronting unfamiliar national security considerations and questions regarding ownership, control, sourcing, and supply chain risk.

Consider a few scenarios that illustrate the potential reach:

  • A U.S. solar developer sources inverters from a manufacturer with partial Chinese ownership. Even if the finished product is assembled domestically, the Order could subject the transaction to DOE review based on the manufacturer’s ownership structure and the software embedded in the equipment.
  • A utility enters into a long-term maintenance contract that gives a foreign vendor remote access to grid control systems. The Order expressly contemplates scrutiny of remote-access capabilities and lifecycle maintenance arrangements—meaning the service relationship itself, not just the hardware, could trigger review.
  • A data center operator contracts for a battery energy storage system from a supplier whose firmware is developed by a subsidiary in a covered jurisdiction. Even if the operator has no direct relationship with the subsidiary, the supply chain dependency may be enough to draw scrutiny.

These examples are not hypothetical outliers. They reflect common commercial arrangements in today’s energy sector.

What the Executive Order Covers

The Order prohibits certain acquisitions, importations, transfers, or installations of foreign-produced bulk-power system electric equipment where the Secretary of Energy determines that the transaction involves equipment connected to a “Covered Foreign Entity” and that it presents an unacceptable national security or critical infrastructure risk.

Importantly, the Order extends well beyond physical equipment. The Secretary may examine not only transformers, generators, inverters, battery energy storage systems, industrial control systems, and turbines, but also associated software, firmware, remote-access capabilities, maintenance services, digital services, and other supply chain dependencies.

The definition of “Covered Foreign Entity” is similarly broad. It incorporates countries subject to U.S. arms embargoes or sanctions restrictions and reaches persons owned by, controlled by, or subject to the jurisdiction or direction of those countries. Although the list includes China, Russia, Iran, North Korea, Venezuela, Cuba, Belarus, and numerous other jurisdictions identified in ITAR section 126.1, the most prominent national security focus and practical implications surround China, followed by Russia.

The Order also authorizes DOE to:

  • Impose mitigation measures on covered transactions;
  • Develop a prequalification process for vendors and equipment;
  • Establish approved-equipment and approved-vendor lists; and
  • Require the identification, monitoring, isolation, disconnection, replacement, or removal of certain equipment already deployed on the grid, subject to reliability considerations.

The practical consequence is that companies will need to look far deeper into their supply chains than simply identifying the country of origin of finished products. The Order expressly contemplates scrutiny of software, firmware, remote-access capabilities, lifecycle maintenance arrangements, and other supply chain dependencies, raising difficult diligence questions:

  • If a project developer signed an equipment supply agreement before August 26, does the Order give DOE authority to block delivery or impose conditions on installation?
  • How far down the supply chain must companies investigate?
  • Can DOE require a utility to disconnect or replace installed equipment based on a post-installation determination that the supplier’s software or firmware poses unacceptable risk?
  • How will DOE assess ongoing software updates, remote-access arrangements, or lifecycle maintenance by foreign-connected service providers?
  • Will mitigation measures, such as third-party monitoring or code escrow, be available as alternatives to outright prohibition?

The Executive Order leaves these questions largely unanswered for now.

The Coming Rulemaking Will Matter More Than the Executive Order

The most important practical takeaway may be that the Executive Order establishes a framework, not a final regulatory program. Much remains to be determined through future DOE action.

The Secretary of Energy has 120 days to issue implementing rules and regulations, which places the current deadline in late December 2026. DOE must also identify covered equipment, develop recommendations for further implementation, and work with the Federal Acquisition Regulation (“FAR”) Council on potential procurement-related changes affecting energy infrastructure.

Among the most significant questions for rulemaking are:

  • Whether DOE will implement prohibitions and mitigation conditions through case-by-case reviews and determinations with respect to specific equipment (like Commerce’s ICTS program prohibited Kaspersky cybersecurity software and like the FCC’s Covered List prohibited certain services and equipment from specific Chinese telecom companies), class-wide regulations (as Commerce did), or a combination;
  • Whether DOE will establish a licensing or authorization process, and whether such a process will include onshoring requirements similar to the conditional approval process for the FCC’s Covered List;
  • Whether DOE will establish meaningful safe harbors or mitigation pathways;
  • How aggressively DOE will scrutinize existing equipment and projects;
  • Whether prequalification mechanisms become practical tools for reducing compliance burdens;
  • How broadly DOE interprets concepts such as software, firmware, remote access, and supply chain dependencies;
  • Whether DOE will identify specific categories of equipment or services that warrant heightened, or reduced, scrutiny;
  • How the new framework interacts with existing FERC reliability requirements; and
  • How federal procurement requirements evolve in response to the Order.

Existing Projects and Contracts May Face New Risks

Companies should not assume that the 120-day rulemaking period provides a temporary safe harbor. Although DOE’s implementing regulations remain to be written, the Executive Order took effect immediately upon issuance and applies to covered transactions initiated after August 26, 2026. The Order also authorizes DOE to make transaction-specific determinations before generally applicable regulations are issued.

Consequently, the most immediate consequence of the Executive Order may be uncertainty rather than enforcement. Project owners, utilities, suppliers, contractors, lenders, and investors must continue making procurement and financing decisions before DOE identifies the countries, entities, equipment, software, services, and supply chain relationships that will receive the greatest scrutiny under the new framework.

That uncertainty is particularly acute for projects already under development or under contract. Several categories of contractual provisions are likely to be tested:

  • Change-in-law clauses may be invoked by parties seeking to reallocate costs or excuse performance if DOE imposes new requirements on equipment already under contract. The scope and drafting of these provisions, including whether they cover executive orders, agency determinations, or only formal rulemakings, could prove decisive.
  • Force majeure provisions may be implicated if DOE action renders performance impracticable, though many standard force majeure clauses may not clearly cover regulatory restrictions of this nature.
  • Termination for regulatory change provisions in Engineering, Procurement, and Construction (“EPC”) contracts and equipment supply agreements could be triggered, raising questions about breakage costs, liability caps, and the availability of substitute equipment.
  • Representations and warranties regarding compliance with applicable law, regulatory approvals, and supply chain integrity may need to be revisited in light of the new framework.
  • Financing documents, including loan agreements, security instruments, and investment agreements, may contain covenants, material adverse change provisions, or regulatory compliance requirements that are implicated by the Order.

If DOE later imposes mitigation requirements or determines that certain equipment presents unacceptable risks, disputes may arise regarding who bears the resulting costs, delays, redesign obligations, or replacement requirements.

The Executive Order also reaches beyond future transactions. Under certain circumstances, DOE may impose conditions on the continued use, operation, maintenance, servicing, or updating of covered equipment already acquired or installed before August 26, 2026. Depending on DOE’s findings, those measures could include monitoring, isolation, disconnection, replacement, or removal, subject to reliability, safety, and replacement-availability considerations.

What Companies at All Levels of the Supply Chain Should Do Now

Companies buying, developing, financing, investing in, importing, constructing, or supplying bulk-power infrastructure should begin assessing potential exposure now, rather than waiting for the rulemaking to conclude. The period before DOE issues implementing regulations presents an opportunity to evaluate supply chains, review procurement and contracting strategies, and identify equipment, software, and service relationships that could draw scrutiny under the new framework. Specifically, companies should consider:

  • Evaluating and mapping current and planned supply chains for covered equipment and services, with particular attention to suppliers, software, and equipment with connections to covered jurisdictions.
  • Reviewing existing procurement, EPC, and equipment supply contracts for change-in-law, force majeure, termination, and regulatory compliance provisions that may be triggered by DOE action.
  • Assessing whether critical equipment may involve suppliers connected to covered jurisdictions, including through software, firmware, remote-access, or maintenance relationships that may not be apparent from the face of the equipment itself.
  • Considering new contractual provisions to allocate risks related to future development, and evaluating existing financing documents and investment agreements for covenants or conditions that may be implicated by new regulatory requirements.
  • Monitoring DOE’s implementation process and identifying opportunities for stakeholder engagement during the rulemaking.

The Executive Order may ultimately advance important cybersecurity and national security objectives. At the same time, broader supply chain reviews, equipment restrictions, and potential replacement requirements could increase project costs, complicate procurement decisions, and lengthen development timelines, particularly at a time when utilities, generators, and data center operators are already facing significant supply chain constraints. Companies that begin preparing now will be better positioned to manage the risks and uncertainties that lie ahead.