America Declared a Power-Grid Emergency Over Hardware It Does Not Trust
The White House has declared a national emergency over risks from foreign involvement in equipment used by the US bulk-power system. The order reaches beyond transformers and breakers. It also covers critical components, software, firmware, digital services, maintenance and remote access.
The policy treats energy security as a supply-chain and continuing-access problem. A product can remain dependent on a foreign vendor long after it is installed through updates, diagnostics, support accounts and cloud-connected management.
What the order authorises
Executive Order 14420 allows the Secretary of Energy to prohibit or impose conditions on the acquisition, import, transfer or installation of covered bulk-power equipment where a foreign interest creates an unacceptable national-security risk.
Covered transactions can include the equipment itself and the critical components, software, firmware, digital services, maintenance and remote-access arrangements associated with it. That language recognises that ownership of hardware is not the same as control over its full operating lifecycle.
The order is broader than a country label
The emergency declaration is designed to address foreign-produced equipment and foreign interests in the supply chain. It does not establish that every product made outside the United States contains a backdoor or has been maliciously altered.
Risk depends on architecture, access, update authority, component provenance, vendor control and the consequences of failure. A domestically assembled device can still depend on foreign firmware or remote support, while a foreign-manufactured component may be operated without continuing external access.
Procurement becomes a security control
The order directs the government to develop Federal Acquisition Regulation recommendations within 180 days. It also prioritises US-manufactured energy infrastructure.
That can change how utilities and suppliers document provenance. A bill of materials is not enough if it lists parts without identifying who can sign firmware, operate update servers, access diagnostic channels or approve maintenance changes.
Remote access is part of the product
Energy equipment often has a service life measured in decades. Vendors may support it through remote diagnostics, proprietary software and specialist accounts. Those capabilities can improve reliability, but they also create trust that survives mergers, contract changes and geopolitical shifts.
Utilities need to know whether remote access can be disabled, independently monitored and revoked without making the equipment unusable. They also need recovery plans for updates or replacement components if a supplier becomes prohibited.
What operators should do now
- Inventory bulk-power equipment together with software, firmware, update services and remote-support paths.
- Record the legal entity and infrastructure that controls code signing, updates and diagnostics.
- Identify systems that cannot operate or be maintained if a vendor connection is removed.
- Restrict vendor access to time-bound, approved sessions with independent logging.
- Preserve known-good firmware and configuration backups where licensing and safety requirements permit.
- Add provenance, update authority and remote-access terms to procurement and renewal reviews.
- Map replacement lead times for components that may become restricted.
- Separate evidence-based product risk from assumptions based only on country of origin.
The strategic trade-off
Domestic manufacturing can reduce certain dependencies, but rushed substitution can create new reliability and concentration risks. The grid cannot replace long-lived equipment at software speed.
Implementation therefore needs prioritisation. Equipment with privileged remote access, opaque firmware or high consequence of failure deserves earlier scrutiny than a component whose behaviour can be independently verified and isolated.
The BlackTree view
The most consequential phrase in the order may be remote-access services. Hardware is visible. Continuing control through maintenance software and vendor infrastructure is easier to overlook.
The order moves the security boundary from the substation fence into procurement, firmware signing and support contracts. That is where much of the grid’s long-term trust is actually stored.
Source
- White House: Declaring a National Emergency to Secure the United States Bulk-Power System, Executive Order 14420, published 26 August 2026. The primary page provides a date but no publication time.


