Back to Blog

The kill switch is already on your roof: what the US inverter ban tells us

·6 min read
Industrial building with solar panels and an inverter connected to a remote cloud — representation of the remote-control risk

On 28 July 2026 the US Federal Communications Commission added to its Covered List — the blacklist of devices deemed a threat to national security, the same one that hosts Huawei and ZTE — two product categories that until yesterday nobody associated with cybersecurity: advanced robots (humanoids and quadrupeds) and connected power inverters, the devices that convert the direct current of solar panels and batteries into alternating current for the grid.

The headlines all went to the humanoid robots, which make better news. But the part of the announcement that directly concerns European companies — and Italian ones in particular — is the other one: the inverters.

Why inverters, of all things

The FCC's decision does not come out of nowhere. In May 2025 Reuters revealed that US experts, tearing down Chinese-made solar inverters connected to the US grid, had found undocumented communication devices — including cellular radios — absent from the product specifications. Similar components had also surfaced in storage batteries from several Chinese suppliers.

An undeclared communication channel is, by definition, a channel that bypasses firewalls: a network operator protects the connections it knows about, not the ones it doesn't know it has.

In justifying the measure, the FCC explicitly cites three risks: the possibility that a foreign actor could remotely switch off the devices, data theft, and the use of the devices as beachheads for remote access and surveillance.

An honest distinction is needed here, because there is a lot of loose talk on this subject:

  • It is a fact that undocumented communication devices have been found in Chinese inverters and batteries (Reuters, confirmed by several trade publications).
  • It is a fact that connected inverters have remote management channels to the manufacturer's cloud: it is a declared feature, used for monitoring and firmware updates.
  • No real attack conducted through these devices against a Western power grid has been publicly documented to date.

The risk, in other words, is not an ongoing attack: it is structural. Whoever manufactures the inverter retains privileged, legitimate access to the device for its entire operational life. If that manufacturer operates in a jurisdiction that can compel it to cooperate with its intelligence agencies, that access becomes a matter of national security — or, at a smaller scale, corporate security.

"It's just the electrical system": the SME blind spot

And this is where the news stops being geopolitics and becomes operational.

Thousands of European SMEs have a solar installation on their warehouse roof. In the vast majority of cases the inverter is connected to the internet — to the manufacturer's cloud, for production monitoring — through the company network or a dedicated SIM. And in the vast majority of cases that device does not appear in any IT inventory: it is not a server, not a PC, not "IT stuff". It is the electrical system; the electrician takes care of it.

The result is a device with these characteristics:

  • it is permanently connected to a non-EU cloud,
  • it receives firmware updates decided by third parties,
  • it has physical actuation capability (it can cut off a power source),
  • and nobody in the company is watching it.

In any risk analysis done seriously, an object like this cannot sit outside the perimeter. It is connected operational technology, and must be treated as such.

The European approach: no blacklists, but obligations for everyone

The United States chose the path of banning by geographic origin. The European Union took a different — and in some ways more demanding — road: it does not ban by flag, but imposes security requirements on anyone selling connected products in the single market.

Two instruments, with different timelines.

NIS2 (Directive 2022/2555): for in-scope entities, Article 21 expressly requires measures on supply chain security, including assessing the vulnerabilities of direct suppliers. An inverter connected to the company network is, for all intents and purposes, a supplier in your technology supply chain.

Cyber Resilience Act (Regulation 2024/2847): it applies to products with digital elements sold in the EU, inverters included. The dates to mark:

  • from 11 September 2026 — a few weeks away — manufacturers must notify ENISA and national CSIRTs of actively exploited vulnerabilities and severe incidents, including for products already on the market;
  • from 11 December 2027 the full security-by-design obligations kick in for new products placed on the market.

Translated: from September, if your inverter has an actively exploited vulnerability, the manufacturer is legally required to disclose it. A manufacturer that does not respond, does not publish advisories, or has no disclosure channel is already a red flag today — and from December 2027 will be out of the market.

Five things to do (before an auditor asks)

  1. Inventory — the inverter (and the batteries, and the charging stations) goes into the connected-asset inventory, with make, model, firmware version and connectivity type.
  2. Segment — the inverter must not sit on the same network as your business systems. A dedicated VLAN or a separate SIM costs little; lateral movement from the OT network to the IT network costs a lot.
  3. Ask your supplier — where does the telemetry data go? Are firmware updates signed? Is there a remote shutdown function and who can invoke it? Is there a vulnerability disclosure policy? These are procurement questions, not paranoia.
  4. Check the contract — if monitoring goes through the manufacturer's cloud, data processing and incident liability must be in writing.
  5. Bring OT into the risk analysis — solar, HVAC, access control, video surveillance: everything that is connected and actuates something in the physical world belongs to the perimeter, even if IT did not install it.

The lesson

The FCC has just told the world that an inverter is network equipment in every respect. Europe has been saying it for a while, with less noise and more deadlines: NIS2 for those who buy, CRA for those who manufacture.

There is no need to wait for geopolitical risk to become news. The point is not the manufacturer's flag: it is knowing which connected devices you have, what they can do, and who else can make them do it. If the answer to any of these three questions is "I don't know", the right place to start is not the roof — it is the risk analysis.

Sources

Do you know which connected devices your company really has?

Tomato helps SMEs bring operational technology — rooftop solar included — into their risk analysis and NIS2 compliance, with concrete contractual requirements towards suppliers.

Talk to us →