30
votes
US Federal Communications Commission bans foreign-produced solar inverters
Link information
This data is scraped automatically and may be incorrect.
- Title
- FCC bans foreign-produced solar inverters, grid lockout begins today - pv magazine USA
- Authors
- Ryan Kennedy
- Published
- Jul 28 2026
- Word count
- 570 words
While I doubt the sincerity of this (and the Chinese humanoid robot ban) action, it does reveal the deeper issue of everything being internet-connected all the time: Devices can be remotely compromised and shut down at any moment with nearly zero warning. It used to be that you could check an item during procurement, and then occasionally during a (manually installed) update. Now everything is operating on the public internet and hypervigilance is required in the cyber domain.
Thank you for posting.
Is this blanket ban just an attack on renewable energy? I need someone with more technical expertise to weigh in, but my intuition says there should have been less disruptive ways to achieve the same result.
The concern, as written, is about widespread malicious firmware updates. Would there be large obstacles (e.g., IP boundaries) to having foreign hardware run U.S. firmware maintained by U.S. software companies? Could you block network access to the inverters and still rely on them to work properly?
I’m used to assuming the worst combination of malice, corruption, and incompetence from this administration. I would still like to make sure my total lack of experience with this kind of hardware isn’t leading me to make bad assumptions.
So, these parts are correct and have been known for a while. This same website published an article about these vulnerabilities in April. And there is a precedent, as the Chinese company Deye remotely shut down inverters in the US, UK, and Pakistan in 2024. Now, these were apparently improperly sold in the US, but the point still stands: they could have also done it maliciously, had they wanted.
The fact that there was no intentional malware discovered could easily be neither here not there. If the devices can have new firmware remotely pushed, then the "malware" can simply be introduced at a later time. This, of course, is also true for US-made devices, but US-companies are unlikely to trigger such an attack for the same reasons as a foreign country.
I won't speculate on motivations, but after a few minutes of thinking about it, I can imagine some less chaotic ways to achieve equivalent outcomes. First, the mandate could have compelled all devices to be placed under the control and supervision of wholly US-owned companies. So that other countries can still make and sell them, but only US companies can access and operate them. They could do this right now and all the companies would have to start handing over the keys to US firms.
Second, the mandate could require foreign-devices sold to have all telecommunication capability disabled prior to interconnect. They could have relaxed what US-made means.
It makes me glad that we already have our solar system set up, but I guess my dreams of low cost battery storage will remain just that.
There are companies making these components in the U.S. Victron is one example. And apparently existing companies that manufacture in China have some sort of workaround.
Probably greasing the palms of the president or his cronies.
It not entirely coming out of nowhere, cybersecurity on the grid in general is a big concern for defense agencies, as currently there isnt really much effort put into securing infrastructure.
More relevantly, there was some chatter last year about some chinese inverters being flagged as having remote shutdown capacity built in. I found an old article from last year about it.
There have been a number of small incidents throughout the years that have laid the foundations for conspiracy theories about grid attacks, but I dont think there has ever been any conclusive evidence that anyone is planning to try anything like that.
From the article: