European Parliament Committee Amended Cybersecurity Act
Proposed changes to the Cybersecurity Act 2 would evaluate solar inverter suppliers on an individual basis.
Updated on Sept. 28, 2026 in Cybersecurity

Live Poll
Should government cybersecurity rules restrict specific companies rather than imposing broad bans on foreign countries?
The European Parliament Committee on Industry, Research and Energy has drafted amendments to the proposed Cybersecurity Act 2. The update suggests moving away from country-based restrictions for solar inverter suppliers in favor of individual assessments.
Why it matters
The legislation seeks to bolster digital supply chain security across the European Union by modernizing existing cybersecurity frameworks. It specifically addresses concerns regarding the use of components from high-risk countries in critical infrastructure.
The amendments target Articles 100 to 104 of the proposed Cybersecurity Act 2, focusing on the technical validation of solar inverter suppliers. This shift aims to replace blanket bans on specific nations with a granular evaluation of ICT asset security.
The players
European Parliament Committee on Industry, Research and Energy
This body is responsible for shaping EU policy regarding industrial, research, and energy matters, including digital security legislation.
European Commission
This is the executive branch of the European Union responsible for proposing new legislation and implementing EU law.
Chinese Ministry of Commerce
This government department manages foreign trade and international economic cooperation for the People's Republic of China.
The details
The European Commission, which initially proposed the Act in early 2026, had previously implemented funding restrictions for projects utilizing inverters from China, Russia, Iran, and North Korea. Amendment 28 seeks to modify this approach by assessing supplier risk individually, a move that follows criticism from the Chinese Ministry of Commerce regarding earlier exclusionary policies.
Timeline
2019: Original cybersecurity rules were established.
January 2026: The European Commission proposed the Cybersecurity Act 2.
April 2026: The Commission restricted funding for projects using inverters from specific nations.
September 2026: The Parliament committee drafted amendments to the proposed legislation.
The Tech Race
This move represents a significant evolution in digital sovereignty compared to the 2019 cybersecurity rules, shifting from broad jurisdictional blocks to targeted supplier scrutiny. It positions the EU to balance supply chain security with its dependency on global tech partners.
Users and developers of solar technology may see a shift in the compliance requirements for hardware installation in key ICT assets. These rules will determine which components are eligible for EU-funded projects, directly influencing supply chain choices for energy firms.
The takeaway
The EU's transition toward individual supplier evaluation reflects an effort to maintain security without completely isolating specific international markets. Future project planners should prepare for a vetting process that focuses more on technical component verification than regional origin.
Further reading
For more background, visit our Cybersecurity section.
Live Poll
Should government cybersecurity rules restrict specific companies rather than imposing broad bans on foreign countries?







