A new policy brief from the Joseph Rainey Center for Public Policy argues that the U.S. electric grid’s defenses should rely on independently verified security standards rather than simply excluding equipment based on its country of origin.
WASHINGTON, DC, UNITED STATES, October 10, 2026 /EINPresswire.com/ — As electricity demand surges and foreign-made components dominate the U.S. grid, a fresh policy paper from The Joseph Rainey Center for Public Policy is shifting the debate from where grid equipment is built to how its security can be proven. The report, titled Securing the Grid While Growing the Grid, tackles the challenge of protecting the nation’s power infrastructure from foreign threats while still allowing for the massive investment needed to keep up with rising electricity consumption.
At the heart of the brief is a straightforward proposition: the origin of equipment is a useful signal, but it shouldn’t be the sole test of trustworthiness. What matters more, the authors contend, is whether that equipment can meet demanding, independently verified security benchmarks.
“Where equipment is made matters, but it is not the same thing as knowing whether that equipment is secure,” said Sarah E. Hunt, President and CEO of the Joseph Rainey Center for Public Policy. “The stronger test is whether the equipment can meet demanding, independently verified standards governing who can access it, who controls its software and updates, and whether its communications can be trusted.”
Rather than calling for a brand-new cybersecurity regime, the brief points to existing frameworks. It notes that NERC, NIST, IEEE, UL, and IEC already offer measurable standards for supply-chain security, operational technology, software integrity, access controls, and industrial control systems. The federal government, the paper argues, can build on these rather than start from zero.
The Rainey Center’s recommendations for federal policymakers include:
Judge equipment by whether it meets rigorous security standards, not simply by where it was made. Country of origin is an important risk signal, but security ultimately depends on access, software integrity, communications, and control.
Require U.S.-controlled operation. Remote access and control should be disabled by default and remain under the asset owner’s control.
Require verified software. Firmware should be signed, updates should be subject to owner review, and software integrity should be independently verifiable.
Require independent testing. Equipment should undergo penetration testing and hardware review by accredited U.S. laboratories.
Keep operational data protected. Grid-related operational data should remain in the United States, with vendor access limited and logged.
Mitigate risk before removing installed equipment. Network segmentation, monitoring, access restrictions, and controlled software updates should be used where they can address the risk without unnecessarily disrupting grid operations.
Preserve exclusion as a tool. Equipment that cannot meet the standard, cannot be verified, or presents an unmitigable risk should not be allowed on the grid.
The paper takes direct aim at origin-based rules, arguing they fail to test the actual pathways through which cyber risk reaches the grid. A domestically assembled device with insecure remote access may still present a serious vulnerability, while a verifiable standard can evaluate remote access, software integrity, data handling, and control regardless of where equipment was manufactured.
Public opinion appears to align with this approach. In the Center’s September Policy Survey, 81 percent of registered voters said they were concerned that grid equipment could be remotely accessed or controlled by a foreign government or company. By 69 percent to 19 percent, voters said how equipment is built, tested, and controlled matters more than where it was made. Voters ranked preventing remote access from outside the United States and independent U.S. testing as the two most important elements of a federal security standard.
The policy debate comes as U.S. electricity demand is accelerating. NERC projects summer peak demand will increase by 224 gigawatts, or 24 percent, over the next decade, while about 80 percent of large transformers and more than 90 percent of power inverters installed over the past decade have been imported.
“America should build more energy infrastructure at home, and we should continue strengthening domestic supply chains,” Hunt said. “But domestic production is not, by itself, a cybersecurity standard. Every device connected to critical infrastructure should have to prove that its controls can be trusted.”
The brief concludes that a verifiable standard can strengthen national security while preserving the competition, reliability, and infrastructure investment needed to meet rising U.S. electricity demand.
About the Joseph Rainey Center for Public Policy
The Joseph Rainey Center for Public Policy advances market-oriented public policy solutions through research, public-opinion analysis, and engagement with policymakers.
Why it matters: As the U.S. grid leans increasingly on imported hardware to meet a 24 percent projected jump in peak demand, this policy shift could reshape how the federal government vets critical infrastructure. A standards-based approach would aim to close cyber vulnerabilities without stalling the equipment pipeline needed to keep pace with electrification and economic growth.
Megan Sibley
Rainey Center Freedom Project
megan.sibley@raineycenter.org
Visit us on social media:
LinkedIn
Instagram
Facebook


