A national emergency declaration signed this week does something the security industry has been asking Washington to do for years: it puts a legal backbone under the assumption that foreign-built hardware sitting inside the US power grid cannot be fully trusted. On August 26, President Trump signed Executive Order 14420, “Declaring a National Emergency to Secure the United States Bulk-Power System,” restricting the acquisition and installation of foreign-made transformers, inverters, battery storage, and industrial control systems tied to a list of adversary nations. The order does not name a single breach or a single vendor. It names a category of risk that the security industry has documented for years: equipment with remote-access paths its buyer never authorized.
What the order actually does
Executive Order 14420 invokes the International Emergency Economic Powers Act and the National Emergencies Act to declare a national emergency over “foreign-produced bulk-power system electric equipment.” The order text, published on WhiteHouse.gov, states the rationale directly. “During my first term, I found that the bulk-power system could be a target of those seeking to commit malicious acts against the United States, including malicious cyber activities, because of the significant risks that a successful attack would have on our economy, human health and safety, and national defense,” the order reads. It goes on to declare that the current situation “constitutes an unusual and extraordinary threat, which has its source in whole or substantial part outside the United States, to the national security, foreign policy, and economy of the United States.”
Section 2 of the order prohibits any acquisition, importation, transfer, or installation of foreign-produced bulk-power system equipment, “or any critical component, software, firmware, digital service, maintenance service, or remote-access capability associated with such equipment,” where the Secretary of Energy determines the transaction involves a Covered Foreign Entity and poses an “undue risk of sabotage, subversion, unauthorized access, malicious remote action, or supply disruption.” The Secretary, working with the Office of Management and Budget and in consultation with the Secretaries of War, Commerce, and Homeland Security and the Director of National Intelligence, can also impose conditions on equipment already installed before the order, including requirements to identify, isolate, monitor, disconnect, or replace it.
The scope is deliberately narrow at the top end and deliberately broad underneath. It covers the bulk-power system, defined as transmission facilities rated 69 kilovolts or higher and the generation needed to keep them reliable, explicitly excluding local electricity distribution. Underneath that line, the order’s list of covered equipment is long: substation components, transformers, inverters, battery energy storage systems, circuit breakers, turbines, and industrial control systems, plus the software, firmware, and remote-access tooling that ships with them. According to the accompanying White House fact sheet, the entities covered by the order include suppliers and service providers tied to 24 countries: China, Russia, North Korea, Iran, and 20 others under existing US arms embargoes or sanctions programs, including Afghanistan, Belarus, Cuba, Myanmar, Syria, and Venezuela.
Why now, and why this framing
The order’s own text supplies the escalation logic. It points to the same vulnerability the administration flagged during Trump’s first term, in a 2020 order that covered similar ground before being suspended by the incoming Biden administration in January 2021 and left to expire that spring. What has changed since then, the order argues, is scale: “The rapid growth of advanced manufacturing, data centers, artificial intelligence, and defense production has increased the Nation’s dependence on abundant, reliable electricity and magnified the consequences of a successful attack or supply disruption on the bulk-power system.” The order is explicit about the mechanism it is worried about: equipment “might have digital backdoors built into their systems that allow a foreign country to access that equipment remotely.”
That is not a hypothetical drawn from a think tank paper. It is the same concern a Senate bill aimed at the grid’s cryptography has been built around, and the same pattern security teams have been tracking since a UK power plant and US water utilities were hit by the same nation-state campaign earlier this year. A smaller, narrower version of this policy already landed in July, when the Federal Communications Commission barred new equipment certifications for foreign-made “connected” solar inverters, those with cellular, Wi-Fi, or Bluetooth links back to a vendor, citing the same class of national-security concern. Executive Order 14420 is that same logic applied to the rest of the grid’s hardware stack, backed by emergency powers instead of a single agency’s certification process.
What happens next, on paper
The order does not itself ban any specific piece of equipment. It hands the Secretary of Energy 120 days, until late December, to publish rules operationalizing the prohibition: defining which transactions require review, which entities count as “covered,” and what a compliant replacement or mitigation plan looks like. A separate, longer clock, 180 to 190 days, applies to a second workstream: revisions to the Federal Acquisition Regulation that would prioritize US-manufactured energy infrastructure in federal procurement. Until those rules exist, utilities operating equipment that might fall under the order are working from a national emergency declaration with real legal teeth and no published list of who, specifically, is on the wrong side of it.
That gap is already shaping the early reaction. In a statement, the North American Electric Reliability Corporation, the industry’s federally designated reliability watchdog, described the order as an initiative that “will help support activities already underway in NERC’s supply chain standards and other work,” positioning its existing supply-chain risk-management standards as the operational layer the new order will eventually plug into rather than replace.
The order’s Section 3 spells out how the Secretary is meant to fill that gap. Rules issued under the order can designate specific countries or persons as a Covered Foreign Entity “exclusively for the purposes of this order,” flag particular equipment categories or countries that “warrant particular scrutiny,” and, notably, “establish procedures to license transactions otherwise prohibited.” That licensing mechanism is the release valve utilities will be watching most closely: it is the difference between a blanket ban and a case-by-case review process, and its design will determine whether a utility mid-procurement on a multi-year transformer order can finish that purchase or has to restart it. Separately, the Secretary is directed to identify equipment already installed that meets the order’s risk criteria and, working through the National Security Council process, recommend to the President “ways” to address it, a step that keeps the disposition of already-deployed foreign equipment a live political decision rather than a fixed rule.
What it means for the security leader
For a CISO or security engineering lead who does not work in utilities, this order is not really about the grid. It is a preview of how the government intends to regulate hardware trust going forward, and the mechanics are worth studying regardless of sector.
The pattern to watch: emergency powers before evidence, then a list
The order declares a national emergency and grants broad discretionary authority before any public list of covered entities exists. That sequencing, legal authority first, specifics later, mirrors how export-control and entity-list regimes have worked in other domains. Security and procurement teams in any regulated infrastructure sector, not just energy, should expect the same pattern to repeat: a declaration establishing the government’s authority to act, followed months later by the operational detail that turns it into a compliance obligation.
The remote-access clause is the real story
Buried in the order’s definition of covered equipment is language that extends the prohibition to “software, firmware, digital service, maintenance service, or remote-access capability” tied to foreign-made hardware, not just the physical unit itself. That is the clause security teams should read most carefully. A domestically assembled device that still phones home to a foreign vendor’s cloud for updates, telemetry, or remote diagnostics is squarely inside the concern this order is written to address, even if the hardware itself clears a “made in the USA” bar. Vendor risk assessments that stop at country-of-manufacture and skip the maintenance and telemetry supply chain will miss exactly the exposure this order targets.
The licensing process will decide who this actually hits
Because the order authorizes a licensing process for transactions that would otherwise be prohibited, the practical bite of Executive Order 14420 will not be visible in the order’s text at all. It will be visible in how the Department of Energy uses that licensing authority over the next several rulemaking cycles: which vendors get a case-by-case exception, which get a blanket designation, and how fast an application moves. Security and procurement leaders evaluating a foreign-tied vendor relationship right now should treat “wait for the covered-entity list” as a plan to be surprised. A more defensible posture is to document, today, the business justification and risk mitigation for any foreign-vendor dependency in bulk-power-adjacent infrastructure, so that a license application, if one becomes necessary, starts from an existing file rather than a cold one.
What to do before the rules land
Waiting for the Department of Energy’s 120-day rulemaking before acting is the wrong call for any organization operating bulk-power-adjacent infrastructure, or watching this as a bellwether for how hardware-trust regulation will spread to other critical-infrastructure sectors. Four steps are worth starting now:
- Inventory equipment at or above the 69kV threshold, and separately, any lower-voltage gear whose vendor also supplies transmission-tier equipment to the same utility, since replacement obligations upstream can still affect service contracts downstream.
- Map country of manufacture and country of software/firmware maintenance separately. The order treats them as distinct risks. A transformer built domestically but serviced through a foreign vendor’s remote-access tooling is still in scope.
- Audit remote-access and maintenance contracts for any vendor tied to the 24 countries named in the order’s fact sheet, and flag which of those contracts include always-on connectivity versus on-demand, logged access.
- Track NERC’s supply-chain standards work directly rather than waiting for DOE’s rulemaking alone; NERC has signaled its existing standards will be the operational layer this order builds on, which means compliance groundwork done against those standards now is unlikely to be wasted effort.
The order gives the industry a deadline without giving it a rulebook. For security leaders, the right response to that gap is not to wait for the rulebook. It is to make sure the inventory and the vendor-risk map exist before the Secretary of Energy asks for them.
Source: Declaring a National Emergency to Secure the United States Bulk-Power System, The White House

