President Trump issued Executive Order 14420 on Wednesday, declaring a national emergency to mitigate vulnerabilities in the United States’ bulk power system arising from foreign-supplied electrical equipment.
The order attributes the heightened emergency status to rapid growth across data centers, AI, advanced manufacturing, and defense production.
Officials noted that dependence on grid reliability magnifies the impact of foreign supply chain disruptions or targeted attacks that exploit built-in backdoors for remote access.
The order covers critical infrastructure operating bulk-power system transmission lines rated at 69 kilovolts or higher, while explicitly excluding local electricity distribution facilities.
Targeted technologies include transformers, inverters, energy storage systems, and industrial control systems (ICS), such as remote terminal units (RTUs), programmable logic controllers (PLCs), and safety systems. The order also covers associated firmware, software, and remote access capabilities.
Under the new directives, any acquisition, import, transfer, or installation of foreign-produced bulk-power equipment initiated after August 26, 2026, is prohibited if the transaction involves designated entities. Restrictions apply to hardware or software deemed to pose risks of sabotage, unauthorized access, malicious remote operation, or supply disruption.
The order does not name any country. However, its structure closely mirrors a 2020 Trump-era bulk-power order that led to a DOE prohibition order explicitly targeting entities associated with China — though that prohibition was later revoked following a Biden administration review.
While the focus is often on state-sponsored Chinese actors targeting US power grid networks through active intrusions, these directives signal a shift toward mitigating upstream supply chain risks and embedded hardware backdoors.
For equipment installed prior to the new executive order, the Energy Department can mandate security controls. Following consultation with defense and intelligence leaders, it can require grid operators to identify, isolate, monitor, secure, disconnect, or replace certain components to neutralize operational threats, while ensuring service continuity and safety.
To support ongoing grid operations, energy authorities may negotiate mitigation agreements or publish an official list of pre-qualified equipment and vendors exempt from the baseline prohibitions.
Related: Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility
Related: Origin Energy Data Breach Affects 900,000 Australians
Related: New Wiper Malware Targeted Venezuelan Energy Sector Prior to US Intervention
