TL;DR
The European Commission’s move to restrict funding for projects using high-risk Chinese-made inverters marks a significant policy shift. However, cybersecurity experts warn that hardware bans alone won’t solve the sector’s vulnerabilities. The debate is evolving into a broader discussion about systemic security issues.
The European Commission has announced plans to restrict funding for solar projects that use high-risk inverter vendors, primarily targeting Chinese-made inverters, signaling a major policy shift. However, cybersecurity specialists warn that banning Chinese hardware alone will not eliminate the sector’s vulnerabilities, as the real cybersecurity issues are more complex and systemic.
Earlier this year, the European Commission implemented funding restrictions affecting an estimated 10-20% of solar project financing in Europe, with plans to extend similar measures to wind and battery storage systems. These restrictions are part of a broader effort to reduce reliance on foreign, high-risk vendors, especially Chinese manufacturers, amid growing cybersecurity concerns.
Despite these measures, industry experts like Uri Sadot, founder of SolarDefend, emphasize that the core cybersecurity risks extend beyond hardware origin. The rapid integration of wind, solar, and storage assets—many of which are remotely operated and interconnected—creates multiple attack vectors. Inverters, while often highlighted, are just one component in a complex ecosystem vulnerable to cyber threats.
Recent incidents, such as VPN vulnerabilities exploited in Poland and network gateway breaches in Denmark, demonstrate that attackers do not need to target hardware directly. Instead, they often exploit human errors, stolen credentials, or software vulnerabilities in networking equipment from Western vendors. These cases underscore that focusing solely on Chinese inverters ignores the broader threat landscape.
Implications of Hardware Bans for European Solar Security
The move to restrict Chinese inverter use aims to bolster Europe’s energy independence and reduce supply chain risks. However, cybersecurity experts warn that hardware bans are insufficient alone, as most vulnerabilities stem from software, network, and human factors. Addressing these systemic issues is crucial for genuine security improvements, making the debate about Chinese inverters a broader discussion about holistic cybersecurity strategies.
Shophubio Solar Grid Tie Inverter 1600W, Inverter with MPPTs, IP65 Waterproof, Wireless APP Monitoring for Home Balcony Power Station System(1600w)

1600W solar grid-tie inverter with MPPT, waterproof design, and wireless app monitoring for efficient home power systems.
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
European Policy Shift and Growing Cybersecurity Concerns
The European Commission’s recent policy changes reflect a strategic effort to diversify supply chains and reduce dependence on Chinese technology, driven by concerns over both security and industrial sovereignty. This follows the publication of the draft Cyber Security Act 2, which explicitly identified solar and other energy sectors for increased scrutiny. Industry insiders note that restrictions on Chinese inverters are only one part of a larger effort to improve energy infrastructure resilience amid rising geopolitical tensions.
While the policy aims to mitigate supply chain risks, experts highlight that over 300 GW of Chinese-made inverter capacity is already installed across Europe and will remain operational for years. Additionally, many Western inverters depend on Chinese components, blurring the lines between ‘trusted’ and ‘risky’ hardware. The policy’s effectiveness in cybersecurity terms remains uncertain, given the complexity of interconnected energy systems.
“Banning Chinese inverters won’t eliminate cybersecurity risks because the core vulnerabilities are systemic and involve software, human factors, and supply chain complexities.”
— Uri Sadot, SolarDefend founder
Unresolved Questions About Long-term Security Impact
It remains unclear whether restricting Chinese inverter imports will significantly reduce cyber threats in Europe’s energy infrastructure, given the widespread use of Chinese components in Western-made inverters and the ability of attackers to target other system elements. The overall effectiveness of these policies in improving cybersecurity is still under assessment, and the evolving threat landscape may require more comprehensive approaches.
Next Steps in European Solar Cybersecurity Policy
Policy discussions in Brussels are ongoing, with industry stakeholders and policymakers debating the scope and implementation of restrictions. Further regulatory measures, including technical standards and asset visibility requirements, are expected to be introduced. Monitoring of real-world cyber incidents will inform whether these policies effectively address systemic vulnerabilities or if additional measures are needed to secure Europe’s energy infrastructure.
Key Questions
Will banning Chinese inverters eliminate cybersecurity risks?
No, experts warn that most cybersecurity risks are systemic and involve software vulnerabilities, human errors, and supply chain complexities that go beyond hardware origin.
How many Chinese-made inverters are currently installed in Europe?
Over 300 GW of Chinese-made inverter capacity is already installed across Europe and will likely remain operational for years.
Are Western inverters free from cybersecurity vulnerabilities?
No, many Western inverters rely on Chinese components and are vulnerable to similar cyber threats, especially through connected network devices and software vulnerabilities.
What other cybersecurity measures are being considered?
European policymakers are discussing technical standards, asset visibility requirements, and stronger enforcement of existing cybersecurity regulations to address systemic risks.
Source: PV Magazine