Comments on Executive Order 14421 urge independent testing, scrutiny of foreign access pathways, and security standards beyond country of origin.
WASHINGTON, DC, UNITED STATES, October 10, 2026 /EINPresswire.com/ — The debate over securing America’s bulk-power system is shifting from blanket bans to nuanced, verifiable security standards, and The Rainey Center Freedom Project is making the case for that shift in formal comments submitted to the U.S. Department of Energy on the implementation of Executive Order 14421, which declares a national emergency to secure the nation’s bulk-power system.
While the Rainey Center Freedom Project backs the President’s emergency declaration and the Administration’s broader push to counter foreign threats to critical energy infrastructure, its recommendations urge DOE to build the Order’s implementation around a clear and administrable framework. The central question, the group argues, should be whether equipment poses a genuine security risk and whether that risk can be independently verified and mitigated — not simply where the hardware was manufactured.
“Foreign access to America’s electric grid is a serious national-security threat, and the Administration is right to act,” said Sarah E. Hunt, President of the Rainey Center Freedom Project. “But the strongest rule is one that measures the actual security risk. Meeting rigorous, independently verified security standards should matter more than country of origin alone.”
The Order itself does not impose a self-executing ban based purely on manufacturing location. Instead, it tasks DOE with determining both that a transaction involves a Covered Foreign Entity and that it presents an undue or unacceptable risk. The Rainey Center Freedom Project is pressing DOE to maintain that two-part structure in the implementing regulations, avoiding any drift toward a de facto origin-based prohibition.
The comments lay out a series of concrete recommendations for DOE, starting with the principle that equipment should be judged on whether it meets security standards rather than where it was made. Country of origin should inform how closely regulators look, but the decisive factor should be whether the equipment’s access, software, communications, and control pathways can satisfy rigorous security requirements.
A second recommendation focuses on whether a Covered Foreign Entity can actually reach the equipment. DOE should examine whether a manufacturer or vendor can remotely access, monitor, control, update, diagnose, or communicate with equipment without the asset owner’s authorization — a key distinction between theoretical risk and operational exposure.
The comments also call on DOE to recognize when the access pathway has been closed. Equipment should receive different treatment where update, diagnostic, and commissioning authority has been transferred to the asset owner or another non-covered party, provided that handoff has been independently verified.
On system-level impact, the Rainey Center Freedom Project recommends DOE leverage existing NERC frameworks to distinguish among equipment based on how its compromise could affect the bulk-power system, rather than treating every device as presenting the same level of risk. Independent testing should be a prerequisite for prequalification, including verification of access architecture, firmware controls, signing keys, and cybersecurity protections by qualified laboratories.
To avoid redundant federal processes, the comments suggest DOE allow a single security evidence package to support both DOE review and related federal Conditional Approval processes where the underlying security showing is the same. Where installed equipment poses a risk, DOE should prioritize mitigation over removal — using network segmentation, monitoring, disabling vendor access, owner-controlled updates, and independent testing to close the risk pathway without unnecessarily taking equipment offline.
Finally, the comments urge DOE to apply new requirements prospectively where appropriate, avoiding stranded contracted projects where secure alternatives are not yet available at scale, and considering reliability and replacement timelines before requiring removal.
The Rainey Center Freedom Project’s comments distill the review process into three guiding questions: Can a Covered Foreign Entity reach the equipment without the owner’s authorization? What would happen if the equipment were compromised? Where was the equipment manufactured, produced, or assembled?
The group argues that origin is an important factor but should not substitute for the risk determination required by the Executive Order. Equipment manufactured in the United States can still present a cybersecurity vulnerability if a foreign entity retains access or control, while foreign-produced equipment may present a different risk profile where that access pathway has been closed and independently verified.
The comments also acknowledge the practical realities of the U.S. energy supply chain. More than 90 percent of photovoltaic inverters supplied to U.S. commercial, industrial, and utility-scale markets over the past decade were imported, and domestic capacity cannot expand overnight. The Rainey Center Freedom Project argues that DOE should secure existing supply while domestic manufacturing expands, rather than making new domestic production the only pathway for equipment to remain available.
“A clear standard gives manufacturers something they can design to and gives utilities something they can rely on,” Hunt said. “If a foreign actor can still reach the equipment and the consequence is unacceptable, DOE should restrict it. If that pathway has been closed and independently verified, DOE should recognize that security showing.”
The Rainey Center Freedom Project concludes that DOE should restrict equipment where a Covered Foreign Entity retains an access pathway that creates an undue or unacceptable risk, while allowing equipment to remain available where that pathway has been closed and independently verified.
As the comments state: “Secure the pathway, and keep the capacity the country has contracted to build.”
Why it matters: This rulemaking will determine how the U.S. balances urgent national-security concerns against the practical need to keep the grid running. If DOE adopts a risk-based, verifiable approach, it could set a precedent for how critical infrastructure is secured without crippling supply chains — a template other sectors may follow.
About the Rainey Center Freedom Project
The Rainey Center Freedom Project advances freedom, security, and a reliable, affordable power grid through public-policy advocacy. Rainey Center Freedom Project.
Megan Sibley
Joseph Rainey Center for Public Policy
Visit us on social media:
LinkedIn
Instagram
Facebook
YouTube
X



