Saturday, October 10, 2026

R

Rainey Center to DOE: Verify grid risks, don’t just ban foreign gear

–

Comments on Executive Order 14421 urge independent testing, scrutiny of foreign access pathways, and security standards beyond country of origin.

WASHINGTON, DC, UNITED STATES, October 10, 2026 /EINPresswire.com/ — As the U.S. Department of Energy begins translating Executive Order 14421 into binding regulations, a key policy voice is pushing back against a simplistic, origin-based approach to securing the nation’s power grid. The Rainey Center Freedom Project filed formal comments today, arguing that the real test should be whether foreign actors can actually reach and manipulate critical equipment—not merely where that equipment was assembled.

The Freedom Project, while backing the President’s emergency declaration and the broader goal of confronting foreign threats to energy infrastructure, is urging DOE to adopt a practical framework. The group’s core argument: the rule must focus on demonstrable security risk—can it be independently verified and mitigated—rather than relying on assumptions baked into a product’s label.

“Foreign access to America’s electric grid is a serious national-security threat, and the Administration is right to act,” said Sarah E. Hunt, President of the Rainey Center Freedom Project. “But the strongest rule is one that measures the actual security risk. Meeting rigorous, independently verified security standards should matter more than country of origin alone.”

The comments emphasize that Executive Order 14421 itself avoids a blanket ban based solely on manufacturing location. Instead, the Order tasks DOE with proving both a Covered Foreign Entity nexus and an undue or unacceptable risk. The Freedom Project is asking DOE to keep that two-part test intact as it drafts the implementing regulations.

To that end, the group laid out a series of specific recommendations for DOE. First, equipment should be judged on whether it meets security standards, with country of origin used only to inform the level of scrutiny. The critical question, they argue, is whether the equipment’s access, software, communications, and control pathways can satisfy rigorous security requirements.

Second, DOE should zero in on whether a Covered Foreign Entity can actually reach the equipment—remotely accessing, monitoring, controlling, updating, diagnosing, or communicating with it without the asset owner’s authorization. Third, the regulations should recognize when that access pathway is closed, such as when update and diagnostic authority has been handed off to the owner or another non-covered party and that transfer has been independently verified.

The Freedom Project also recommends using existing NERC frameworks to assess system consequences, distinguishing between equipment based on the potential impact of its compromise rather than treating all devices as equally risky. Prequalification, they argue, should include independent testing by qualified labs covering access architecture, firmware controls, signing keys, and cybersecurity protections.

To avoid redundancy, the group suggests DOE allow a single security evidence package to serve both its own review and related federal Conditional Approval processes where the underlying security showing is the same. Where installed equipment poses a risk, the comments urge DOE to consider mitigation—network segmentation, monitoring, disabling vendor access, owner-controlled updates, and independent testing—before resorting to removal. And new rules should apply prospectively where appropriate, to avoid stranding contracted projects when secure alternatives aren’t yet available at scale.

The comments boil DOE’s review down to three guiding questions: Can a Covered Foreign Entity reach the equipment without the owner’s authorization? What would happen if the equipment were compromised? Where was the equipment manufactured, produced, or assembled?

Origin is a significant factor, the group concedes, but it should not replace the risk determination the Executive Order demands. A device made in the U.S. could still be vulnerable if a foreign actor retains control, while a foreign-built device with a closed and verified access pathway could present a wholly different risk profile.

The Freedom Project also pressed DOE to confront the realities of the U.S. supply chain. With more than 90 percent of photovoltaic inverters supplied to U.S. commercial, industrial, and utility-scale markets over the past decade being imported, domestic capacity simply cannot scale up overnight. The group argues DOE should secure the existing supply while domestic manufacturing ramps up, rather than making new domestic production the only route to keeping equipment on the grid.

“A clear standard gives manufacturers something they can design to and gives utilities something they can rely on,” Hunt said. “If a foreign actor can still reach the equipment and the consequence is unacceptable, DOE should restrict it. If that pathway has been closed and independently verified, DOE should recognize that security showing.”
The Rainey Center Freedom Project’s bottom line: DOE should restrict equipment where a Covered Foreign Entity retains an access pathway that creates undue or unacceptable risk, while allowing equipment to remain available where that pathway is closed and independently verified.

As the comments state: “Secure the pathway, and keep the capacity the country has contracted to build.”

Why it matters: The DOE’s final rule will determine whether the U.S. secures its grid by banning foreign-made components outright or by adopting a more nuanced, risk-based approach. The Rainey Center’s position highlights a tension between national security urgency and the practical limits of the domestic supply chain—a balance that will shape energy policy and project timelines for years to come.

About the Rainey Center Freedom Project
The Rainey Center Freedom Project advances freedom, security, and a reliable, affordable power grid through public-policy advocacy. Rainey Center Freedom Project.

Megan Sibley
Joseph Rainey Center for Public Policy
Visit us on social media:
LinkedIn
Instagram
Facebook
YouTube
X


David Hall

David Hall

David is the senior editor at TheCyberMag. He has a background in journalism and has worked with various media outlets, covering topics ranging from threat intelligence and data privacy to cybercrime and cloud security. When he is not writing, David enjoys reading, hiking, photography, and exploring new coffee shops.