Washington Asks Which Grid Equipment Counts as Covered
The US Department of Energy has opened a request for information implementing Executive Order 14421, asking industry to define covered equipment and foreign entities across inverters, storage, UPS and industrial control systems.

The US Department of Energy's Office of Cybersecurity, Energy Security and Emergency Response has opened a request for information implementing Executive Order 14421, "Declaring a National Emergency to Secure the United States Bulk-Power System", issued on 26 August. The RFI was published in the Federal Register on 9 September at 91 FR 57322, document 2026-18370, with comments due by 9 October under docket DOE-HQ-2026-1123 and a public webinar scheduled for 16 September. DOE is asking industry to help define covered equipment, covered foreign entities and risk thresholds. The equipment categories referenced are bulk-power system electric equipment, grid-connected inverters, battery energy storage systems, uninterruptible power supplies, generators and backup power systems, and industrial control systems — with scope explicitly extending to associated software, firmware and digital services rather than hardware alone. Comment topics include scope definitions, foreign entity identification, supply chain risk management, equipment evaluation and mitigation, licensing procedures, domestic manufacturing capacity, federal procurement and economic impacts.
The category list is the part with consequences well beyond utilities. Grid-connected inverters, battery storage, uninterruptible power supplies and industrial control systems are not transmission assets; they are equipment that sits on ordinary industrial and commercial sites. A definition of "covered equipment" that reaches the inverter on a factory roof, the UPS in a plant's control room or the controller in a battery container would extend a bulk-power rule into general industrial procurement, and where the line is drawn is precisely what this RFI is asking.
The inclusion of software, firmware and digital services is the second point to register. A restriction framed around hardware origin is answerable by knowing where a box was assembled. One that includes firmware and remote services asks harder questions: who wrote the firmware, who can push an update, where does the monitoring platform run, and who holds the credentials for the vendor's remote access. Most industrial buyers cannot currently answer those about their installed equipment, and the answers are not in the purchase order.
The practical response is the same whether or not a given site ends up in scope, and it is worth starting now rather than after a rule appears. Build an inventory of grid-connected power electronics and control equipment that records not just make and model but firmware origin, update mechanism, remote access path and the jurisdiction of any cloud service it depends on. That inventory is the thing every version of this rule will require, it takes months to assemble honestly, and it is independently useful — it is the same document needed for the Cyber Resilience Act, for NIS2 supplier obligations, and for answering a customer's own supply chain questionnaire. Organisations with a view on where the threshold should sit have until 9 October to say so.