Executive Order 14421: What Grid Asset Owners Need Before the December Rulemaking
Conventional grid compliance treats a patched, signed, CIP-013-compliant relay as a safe one. Executive Order 14421 asks who owns the company that wrote its firmware, and few utility records go that deep.

Doc McConnell
Head of Policy and Compliance
America's grid now runs on software as much as steel. Substations that once held electromechanical relays are full of microprocessor-based protection, remote terminal units, and network gear, and new solar and storage sites add inverters and battery controllers by the thousands. Each of those devices runs firmware assembled from code written across a global supply chain, and very little of it has ever been inventoried by the utility that operates it, let alone traced back to the companies that wrote it.
Executive Order 14421, signed on August 26, 2026, turns that tracing into a federal question. Picture a single protective relay in one of those substations. Its firmware is signed and the signature validates, the vendor answered every ownership question on your supply chain questionnaire, the device was patched in its last outage window, and a passive sensor watches its network segment. By every measure a CIP-013 program applies, it's in good order, and it could still fall within the order's prohibition. Under the order, what matters is who designed, developed, manufactured, or supplied the relay and its components, down to the firmware, and whether a covered foreign government owns, controls, or directs them. Most utility records stop at the vendor named on the purchase order.
Executive Order 14421 declares a national emergency over foreign-produced bulk-power system equipment. It authorizes the Secretary of Energy to prohibit or condition transactions in grid equipment and its software, firmware, and remote-access capabilities when a Covered Foreign Entity is involved and the risk is undue, and to impose conditions on equipment already in service.
DOE's implementing rules are due on or about December 24, 2026, and they'll settle definitions the order leaves open. What they're unlikely to change is the underlying question, so the preparatory work looks the same under any plausible version of the rules: for each device, a verified answer to who built it, what's inside it, and what it can reach.
IEEPA Puts the Secretary of Energy in Charge
If you've spent your career inside CIP, start with the legal authority. Executive Order 14421 rests on the International Emergency Economic Powers Act (IEEPA) instead of Section 215 of the Federal Power Act, so the Secretary of Energy administers it through prohibitions and licensing, outside FERC, NERC, and the Compliance Monitoring and Enforcement Program (CMEP). Violations carry IEEPA's civil and criminal penalties, and even the order's definitions stand apart from the NERC Glossary, so a familiar term may not carry its familiar meaning here.
As signed, the order names no vendor and prohibits no specific product, and DOE has said publicly that nothing is barred until the Secretary finds both a Covered Foreign Entity connection and an undue risk. For now, it establishes a framework and a deadline.
Ownership and Design Origin Decide What's Covered
Everything about the order's reach follows from its trigger language, which is worth reading in full. The prohibition reaches bulk-power system electric equipment, along with any critical component, software, firmware, digital service, maintenance service, or remote-access capability associated with it, that is designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of a Covered Foreign Entity.
Read closely, that wording sets a component-level test with no de minimis threshold. A finished device from a non-covered manufacturer falls within reach if a covered entity designed a critical component inside it, firmware included. Because ownership and design origin control the outcome, a covered entity's subsidiary assembling equipment in a third country sits squarely inside the test, and the country-of-origin representations most procurement contracts capture can't settle the question.
Anyone who followed Commerce's Connected Vehicles rulemaking will recognize the formula, which we cover in our Connected Vehicle Rule explainer. EO 14421 borrows the language but leaves behind that rule's firmware and legacy-software carve-outs. My advice is to plan for an ownership test that runs into the firmware and let December's rules trim the edges.
Executive Order 14421 Reaches Below the CIP Line
For the order's purposes, the bulk-power system means transmission facilities and control systems at 69 kV and above, plus generation needed for reliability. A 69 kV floor sits well beneath the 100 kV threshold that scopes most NERC CIP obligations, so a sub-100 kV transmission facility or a new battery site can fall outside CIP-002 and inside this order at once, and those are usually the assets with the thinnest provenance records.
Federal equipment lists have never been this specific about digital devices. Alongside transformers, breakers, and protective relaying, this one names grid-connected inverters, battery energy storage systems (BESS), uninterruptible power supplies, RTUs, PLCs, IEDs, and distributed control systems, each with its software, firmware, remote-access capabilities, and lifecycle update mechanisms attached. For energy and utility security teams, that last clause is what puts firmware analysis on the agenda.
Section 2(b) goes a step further and reaches equipment you already own, letting the Secretary impose conditions anywhere on a spectrum from identify, isolate, and monitor to disconnect, replace, and remove, after weighing reliability and replacement availability. Every one of those steps depends on the first. You can't isolate or replace what you haven't identified, and identifying covered equipment presumes a device-level provenance inventory most of the sector doesn't yet hold.
| Milestone | Timing |
|---|---|
| Order signed | August 26, 2026 |
| Written responses to DOE's request for information due | October 9, 2026 |
| Implementing rules due | On or about December 24, 2026 (120 days) |
| Recommendations to revise the Federal Acquisition Regulation | 180 days after signing |
| National emergency lapses absent renewal | One year after signing |
Supplier Attestation Can't Answer the Ownership Test
None of this means the sector is starting from scratch. Over roughly a decade, utilities have built a layered supply chain assurance practice, and each layer does what it was designed to do. What the layers share is a foundation: every one that scales relies on what a supplier says about itself, and none checks that account against the equipment as delivered.
CIP-013-2 shows the pattern most clearly. Nothing in it requires you to determine who owns or controls a manufacturer, and its applicability leaves out low-impact systems and most of the sub-100 kV population the order now sweeps in. Its one control that touches the artifact, R1.2.5, confirms that a firmware image came from the stated vendor and wasn't altered in transit. That's a valuable defense against tampering, yet it's silent on what the authentic image contains and who wrote it, so a correctly signed image from a covered-entity-owned manufacturer can pass R1.2.5 and still be exactly what the order targets. FERC has recognized the limits, too, though the revised standards it ordered in Order No. 912 aren't due until 2027.
Questionnaires, certifications, and network monitoring each run into the same wall from a different direction. On the 219-question Energy Sector Supply Chain Risk Questionnaire, suppliers answer ownership questions about themselves, so a covered entity's subsidiary selling through a U.S. reseller can respond truthfully and raise no flag. ISO/IEC 27001, SOC 2, and IEC 62443-4-1 attest to processes, and a covered-entity-owned manufacturer can hold all three in good standing. Passive OT monitoring reports the firmware version a device advertises without seeing what that firmware contains. Even DOE's CyTRICS program at Idaho National Laboratory, which does real firmware analysis, examines manufacturer-supplied models by consent at a pace of tens of components a year and was never meant to characterize your fleet.
Industry efforts to gather that evidence voluntarily have struggled for a simple reason: suppliers had no obligation to share it, and utilities had no mandate to ask. When Fortress Information Security analyzed the North American Energy Software Assurance Database in 2023, years of collection had produced just 224 supplier SBOMs. EO 14421 gives utilities the standing to ask for far more.
Evidence That Only Turned Up in the Hardware
Grid equipment has already produced findings that no paperwork predicted. In mid-2025, reporting described undocumented cellular radios discovered during teardowns of Chinese-manufactured inverters and batteries, hardware that appeared on no bill of materials and could open communication paths outside the owner's monitored network. Months earlier, in November 2024, deployed inverters had been remotely disabled, showing how far vendor-controlled update channels reach into equipment in service.
Forescout's SUN:DOWN research went on to disclose 46 vulnerabilities across Sungrow, Growatt, and SMA inverter platforms, including hardcoded credentials and cloud-mediated control paths, all since patched. Protection equipment hasn't been immune either: CISA advisory ICSA-21-075-02 disclosed hardcoded bootloader credentials across roughly 19 GE Multilin relay models.
Each of those findings came from direct analysis of hardware or firmware, and none would have surfaced on a questionnaire, a certificate, or a network sensor. They also arrive against a backdrop of documented adversary interest, with public reporting on Volt Typhoon describing extended dwell inside a U.S. electric utility's environment.
Each of the Order's Questions Needs Different Evidence
Who built a device, what's inside it, and what it can reach are separate analytical problems, each with its own evidence and its own ways of going wrong.
Composition comes first. A modern relay or inverter controller runs a firmware image that is really an assembled system: a bootloader, an embedded operating system such as VxWorks or embedded Linux, vendor binaries, and a substantial body of third-party code, from cryptographic libraries to DNP3 and IEC 61850 implementations. Because outage scheduling rarely allows synchronized updates, one relay model often runs several firmware trains across a fleet, each a distinct build. Binary software composition analysis lets you see inside each build without source code, and our firmware binary analysis guide walks through how it works.
Provenance is where the order turns, and where claims are most often overstated. Binary analysis yields strong signals about where code came from, such as statically linked components, toolchain and locale artifacts, and code lineage shared across unrelated products. Those signals tell you who wrote the code. Who controls the company behind it is a legal and factual question, settled through corporate-registry, beneficial-ownership, and sanctions research. A determination that will hold up fuses all three sources—supplier declarations for the claimed picture, corporate research for control, and binary signals to corroborate or contradict both—and records each classification with its basis and a stated confidence. When DOE, a state commission, or your own counsel reviews it, they should be able to see precisely where attestation ends and verification begins.
Reachable capability completes the picture. Sabotage and malicious remote action, the risks the order names, depend on what a device can do far more than on how many CVEs it carries. Answering for them means enumerating, from the firmware itself, the listening services, wireless and cellular interfaces, hardcoded credentials, and remote-access and update mechanisms, enabled or dormant, then weighing each against how the device is actually installed.
Getting the Firmware Is the Binding Constraint
Any honest program has to reckon with the step that stalls most of them: getting the firmware in the first place. Protection equipment increasingly ships signed, sometimes encrypted, images with secure boot, and an encrypted image may require chip-off methods worth reserving for a small, high-priority set. Inverter and BESS firmware often arrives over the air from the manufacturer's cloud, so you may never hold the image at all, which makes acquisition and the order's remote-access concern one and the same. Pulling firmware off an energized relay, meanwhile, means an outage, PRC-005 discipline, and CIP-010-4 change management, so it tends to happen only during failures, replacements, or commissioning.
So a fleet-scale program builds on firmware it can get without touching energized equipment. Start with the vendor-furnished images you already receive or can request under your support entitlements, which can be analyzed at a desk. For device classes with no image available, buy a representative unit and tear it down once, and the result carries across every installed unit running that build. Where neither path works, record the device as attested and not independently verified, an honest entry that will hold up far better under review than a gap papered over.
A Defensible Program Builds the Record in Stages
Each stage feeds the next, and together they build the provenance-and-disposition record that DOE, state commissions, and the eventual Section 2(e) pre-qualification process will each ask to see.
| Stage | What it does | What it produces |
|---|---|---|
| Collect | Gathers supplier SBOMs, hardware BOMs, and ownership representations; fuses asset, maintenance, and procurement data | A register keyed to make, model, and firmware version, risk-ranked by the order's logic |
| Resolve | Fuses supplier declarations, corporate and sanctions research, and binary-derived signals | Per-component ownership determinations with basis and confidence |
| Verify | Analyzes obtainable firmware and reconciles it against supplier evidence | Discrepancies between what was declared and what shipped |
| Analyze | Enumerates reachable interfaces and update mechanisms; assesses exploitability | Device-level risk in the order's terms |
| Mitigate | Maps findings to IEC 62443-3-2 and 62443-4-2, MITRE EMB3D, and ATT&CK for ICS | A disposition on the Section 2(b) spectrum |
| Sustain | Re-verifies each update; re-scores as designations and disclosures change | A record kept current for the next inquiry |
At the center of it all sits the register, which carries three fields most asset systems omit: country of manufacture, country of design or development, and controlling parent. Verification is where the program earns its credibility, because its discrepancies are its most valuable output: the component missing from the SBOM, the cellular interface absent from the hardware BOM, the update capability no document mentions. A ground truth software inventory built from the firmware is what brings those discrepancies to the surface, using the same discipline we recommend for verifying supplier SBOMs against the binary, with an ownership test layered on top.
For mitigation, I'd recommend a graduated posture: isolate and monitor the many, and reserve replacement for the consequential few. It preserves reliability, which the order asks the Secretary to weigh, and it's the cost-defensible path you'll need in front of your commission. Exploitability-based prioritization keeps scarce outage capacity aimed at exposures an adversary could actually use. Plan for the knock-on effects, too, since a forced relay replacement is also a CIP-010 change, a CIP-005 access revision, and a PRC-005 event.
Counsel Belongs in the Room Before the First Finding
Every verified finding adds to a documented record of what your organization knows. Whether that record develops under privilege depends on how the engagement is structured, and only your counsel can establish it. Keeping a covered-entity device energized for months on legitimate reliability grounds is a defensible decision, but it's also a documented one, so set finding-to-disposition timelines deliberately. Bringing counsel in early is a reason to structure the program carefully, not a reason to run it slowly.
Cost recovery deserves the same early attention. Costs arising from Section 2(b) directives fall on the equipment owner, and unlike FPA Section 215A, IEEPA carries no federal cost-recovery mechanism. A federal directive doesn't by itself establish prudence before a state commission, and telecom's rip-and-replace program, which began with a self-reported inventory and remains unfinished five years on, is a cautionary precedent. In a prudence proceeding, your strongest position is the rigor and independence of your own record. None of this is legal advice, only the questions your counsel will want to own from the outset.
What to Do Before DOE Publishes Its Rules
December's details are still unknown, but these steps hold up under any version of the rules.
Build the register first. Request SBOMs, hardware BOMs, and ownership representations from priority suppliers, and fuse your asset, maintenance, monitoring, and procurement data into a single register with the three provenance fields. It's the artifact DOE, your commission, and your board will each ask for first.
Verify your highest-consequence classes. Start with grid-connected inverters, BESS controllers, and foreign-linked RTUs and IEDs. Wherever firmware is obtainable, reconcile it against supplier evidence so your initial exposure picture is verified where it matters most.
Preserve procurement-initiation evidence. Since the prohibition applies to transactions initiated after August 26, 2026, and the order doesn't yet define "initiated," document the timing of pending procurements while records are fresh. Invoke the EEI country-of-origin and change-of-manufacture provisions on open agreements, too.
Engage counsel and regulatory affairs now. Open the prudence conversation with your commission and the definitional conversation with DOE, which is taking written responses to its request for information through October 9, 2026.
Your Own Record Is the Best Defense
IEEPA has no CMEP-style self-report credit schedule, but voluntary disclosure and remediation still carry weight with enforcers, which favors any asset owner able to show, from its own record, what it has, what it has verified, and what it's doing about it.
Producing the verified part of that record is where Finite State can help. Our platform analyzes delivered firmware, with no source code required, to establish what's inside each build, reconcile it against supplier SBOMs, and enumerate the interfaces and update mechanisms each device exposes. Our analysts pair those binary-derived signals with corporate-ownership and sanctions research, and device-level threat assessments are generated by the platform and validated by our experts before they reach you. Finite State is U.S.-owned and performs its analysis in the United States, and we wall off the work we do for equipment manufacturers, who will field these same questions from their utility customers. Whoever you choose to work with, judge them on the depth and independence of their verification.
December's rules will settle what the order's terms mean. Knowing what's running in your substations, and who wrote it, is work you can start well before then.
Bring us firmware from one of your highest-consequence device classes, and we'll show you what's inside it, where its components came from, what it can reach, and where any of that departs from what the supplier told you. Request a demo, or read the full technical and programmatic treatment in our guide, Bulk-Power System Supply Chain Assurance Under Executive Order 14421.
Frequently Asked Questions
When are the Executive Order 14421 implementing rules due?
The Department of Energy's implementing rules for Executive Order 14421 are due within 120 days of the August 26, 2026, signing, on or about December 24, 2026. Recommendations to revise the Federal Acquisition Regulation follow within 180 days, and the national emergency lapses after one year unless renewed. DOE has said the order doesn't immediately prohibit any transaction.
Does CIP-013 compliance satisfy Executive Order 14421?
Not on its own. CIP-013 doesn't require you to determine who owns or controls a manufacturer, excludes low-impact and most sub-100 kV assets, and its software integrity control, R1.2.5, confirms a firmware image is authentic without examining what it contains. A signed image from a covered-entity-owned manufacturer can pass CIP-013 and still fall within the order.
Does Executive Order 14421 apply below 100 kV?
Yes. Executive Order 14421 defines the bulk-power system as transmission facilities and control systems at 69 kV and above, plus generation needed for reliability. That reaches below the 100 kV Bulk Electric System threshold that scopes most NERC CIP obligations, so sub-100 kV transmission, inverters, and storage can sit inside the order while outside CIP-002.
Does Executive Order 14421 cover firmware?
Yes. The prohibition names firmware explicitly, alongside critical components, software, digital services, maintenance services, and remote-access capabilities. Its ownership formula matches the one in the Commerce Department's Connected Vehicles rule, but Executive Order 14421 doesn't import that rule's firmware or legacy-software carve-outs, so plan for an ownership test that extends into firmware.
Is a country-of-origin representation enough under Executive Order 14421?
No. Executive Order 14421 asks whether a component was designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of a Covered Foreign Entity. Country-of-manufacture representations don't answer that, and equipment assembled outside a covered country by a covered entity's subsidiary stays within scope.
Tags

Doc McConnell
Head of Policy and Compliance
Doc McConnell is a public policy and cybersecurity leader with over a decade of experience shaping national technology policy within the U.S. government. Prior to joining Finite State, he led strategic policy development for federal cybersecurity at the Cybersecurity and Infrastructure Security Agency and served as a policy advisor within the White House Office of Management and Budget.
Doc holds a Master of Information and Cybersecurity from the University of California, Berkeley, and a Master of Public Policy from the University of Virginia. He is a Certified Information Systems Security Professional (CISSP).


