Executive Order 14420 and the Bulk-Power System Supply Chain
By Patrick Miller
An executive order signed August 26, 2026 declares a national emergency over foreign-produced bulk-power system electric equipment. It reaches 69 kV and above, adds software, firmware, a list of OT/ICS gear, and vendor remote access to scope, and creates authority to condition or remove equipment already installed. Here is what changed since the 2020 order, where it meets CIP-003-9 and CIP-013-2, and what to do before December 24.
Overview
On August 26, 2026, the White House signed Executive Order 14420, declaring a national emergency with respect to the foreign supply of bulk-power system electric equipment. We've been here before, more or less. Executive Order 13920, signed May 1, 2020, declared an emergency on nearly the same subject and gave the Secretary of Energy nearly the same job. That one didn’t get far. Executive Order 13990 suspended it in January 2021, the Department of Energy (DOE) revoked its December 2020 Prohibition Order that April, and by DOE's own account the revocation was timed ahead of the 13920 emergency declaration expiring on May 1, 2021. No implementing rules were published in the meantime, and the pre-qualified vendor list the order authorized was never built.
The important thing to understand up front is that this is a new emergency declaration rather than a revival of the old one. It doesn't cite 13920 by number anywhere. The new text is meaningfully broader in four places that matter to anyone running a compliance program.
What the Order Does
Section 2(a) prohibits the acquisition, importation, transfer, or installation of foreign-produced bulk-power system electric equipment where the Secretary of Energy determines two things.
First, that the equipment, or any critical component, software, firmware, digital service, maintenance service, or remote-access capability associated with it, comes from a person owned by, controlled by, or subject to the jurisdiction or direction of a Covered Foreign Entity.
Second, that the transaction poses an undue risk of sabotage, subversion, unauthorized access, malicious remote action, or supply disruption, or an undue risk of catastrophic effects on critical infrastructure or the economy, or otherwise an unacceptable risk to national security or to the safety of United States persons. Those determinations are made in coordination with the Office of Management and Budget and in consultation with the Secretary of War/Defense, the Secretary of Commerce, the Secretary of Homeland Security, and the Director of National Intelligence.
The prohibition reaches transactions initiated after the date of the order, and it applies notwithstanding any contract entered into or permit granted before that date. There's a separate authority over equipment already in the ground, which I'll come back to. Rules or regulations are due within 120 days, so December 24, 2026, though the text says the Secretary shall publish them "as needed," which is probably (in reality) softer than it appears. Recommended revisions to the Federal Acquisition Regulation are due within 180 days, so February 22, 2027, with the Federal Acquisition Regulatory Council given 90 days after that to consider proposing amendments for comment. There's one more date worth keeping in view. An emergency declared under the National Emergencies Act terminates at its one-year anniversary unless a continuation notice is published, which is how the 2020 declaration ended.
What Changed Since 2020
| Provision | EO 13920 (2020) | EO 14420 (2026) |
|---|---|---|
| Covered supplier test | "Foreign adversary," defined by pattern of conduct, requiring DOE designation | "Covered Foreign Entity," defined by reference to ITAR 22 C.F.R. 126.1, plus a residual Secretary determination |
| Software and services | Not addressed | Critical components, software, firmware, digital service, maintenance service, and remote-access capability all in scope |
| Equipment already installed | No authority | Sec. 2(b) permits conditions including identify, isolate, monitor, secure, disconnect, replace, or remove |
| Risk triggers | Sabotage or subversion, catastrophic effects, unacceptable risk | Adds unauthorized access, malicious remote action, and supply disruption |
| Equipment list | Baseline list of substation, control room, and generating station items | Adds grid-connected inverters, battery energy storage, UPS supporting critical infrastructure, and small generators, and names RTUs, PLCs, and IEDs |
| Rules deadline | 150 days, "shall publish" | 120 days, "shall publish ... as needed" |
| Anti-evasion | None | Sec. 2(f) prohibits evasion, attempt, and conspiracy |
| Industry structure | Standing Task Force, consultation with the Electricity Subsector Coordinating Council, engagement with distribution groups | None of the above, with recommendations routed to the President through the National Security Advisor |
Who Counts as a Covered Foreign Entity
The 2020 definition of "foreign adversary" was a description rather than a list, and DOE never turned it into one. The 2026 definition points at 22 C.F.R. 126.1, the International Traffic in Arms Regulations (ITAR) provision covering countries subject to a United States arms embargo or sanctions regime. That list already exists. Its first table carries a flat policy of denial for Belarus, Burma, China, Cuba, Iran, North Korea, Syria, and Venezuela. A second table adds sixteen more with country-specific conditions, Russia among them. So the country question is largely answered on day one, which is a real difference from 2020.
That list moves on its own schedule. Cyprus is currently on it, but its policy of denial and its status as a proscribed destination are suspended from October 1, 2025 through September 30, 2026. A country can come off and go back on for reasons that have nothing to do with grid equipment, and if your vendor screening is built on a snapshot, it will drift so you’ll need to pay attention.
The harder question moved rather than disappeared. Once you know the countries, you still have to decide whether a given manufacturer is "owned by, controlled by, or subject to the jurisdiction or direction of" one of those governments. For a company headquartered in a covered country, with a plant in a third country and a sales entity in Delaware, that phrase is doing all of the work and the order doesn't define it. I'd expect that to be the substance of whatever DOE publishes in December.
Below the CIP Line
There's a question I've been asked multiple times already, so it's probably worth answering plainly. The order defines bulk-power system to include transmission lines rated at 69,000 volts (69 kV) or more, and people want to know how an executive order can move a line they understand to be set at 100 kV, with federal authority above it and state authority below.
It can't move that line, and the line isn't quite where most of us have rationalized. The 100 kV threshold isn't statutory and it isn't jurisdictional. It lives in NERC's Glossary definition of Bulk Electric System, and FERC made it a bright line in Order No. 773 in December 2012, approving NERC's revised definition to cover everything operated at or above 100 kV and to strip out the regional discretion the older definition allowed. That was the answer to Orders 743 and 743-A. It's an applicability threshold for reliability standards and it has no life outside Section 215 of the Federal Power Act.
Section 215 itself defines bulk-power system with no voltage in it at all. Facilities and control systems necessary for operating an interconnected electric energy transmission network, plus electric energy from generating facilities needed to maintain transmission system reliability, and not facilities used in local distribution. That's the whole definition.
The federal and state divide sits somewhere else, and it's functional rather than electrical. Section 201(b) gives FERC transmission in interstate commerce and wholesale sales, and reserves to the states facilities used in local distribution along with transmission that stays inside one state. The test for which is which comes from Order No. 888 and it runs to seven factors: proximity to retail customers, radial character, whether power ever flows out as well as in, whether power entering gets reconsigned to another market, whether it's consumed in a restricted geographic area, where the metering sits, and reduced voltage. Voltage is the seventh one, and it works as an indicator rather than a threshold.
That has real consequences in both directions. FERC has applied the seven-factor test to find that roughly 2,500 circuit miles of one utility's 115 kV facilities were used in local distribution, which put them outside the Bulk Electric System and outside mandatory reliability standards. Those facilities served something like 19 percent of that utility's peak load and had 685 MW of generation connected to them. The Commission granted the request in substantial part, holding back certain protection systems and transmission elements. Running the other way, Order 888 holds that a utility's facilities used to deliver energy to a wholesale purchaser sit inside FERC's exclusive jurisdiction whether you label them transmission, distribution, or local distribution. So above 100 kV can be state-side, below 100 kV can be federal, and what's printed on the one-line diagram doesn't always settle it.
What we have now is three lines rather than two, built at different times for different reasons. Section 201 draws a functional line for rates and service. Section 215 draws a reliability line, with the Bulk Electric System definition doing the applicability work inside it. This order draws a third one at 69 kV, for its own purposes, under a statute that has nothing to do with the Federal Power Act. Nothing in it changes CIP applicability, so your Bulk Electric System footprint tomorrow is the same as it was yesterday. What changed is that a wider line now sits alongside the one you've been managing to, and the two don't align. The space between them is larger than the voltage numbers suggest. By one estimate carried in Carnegie Mellon's Electrotech Moneyball paper, only 10 to 20 percent of the US electricity system falls under federal cybersecurity oversight at all, and the fastest-growing parts of the grid's digital architecture sit outside it.
The equipment list is what makes that concrete. Alongside the transformers, breakers, relays, and turbines that were in the 2020 list, the 2026 version adds utility-scale and other grid-connected inverters, battery energy storage systems, uninterruptible power supply systems supporting critical infrastructure, and small generators. It also breaks out remote terminal units (RTUs), programmable logic controllers (PLCs), and intelligent electronic devices (IEDs) explicitly under industrial control systems.
| Dimension | EO 14420 | CIP-013-2 | CIP-003-9, Attachment 1 Section 6 |
|---|---|---|---|
| Threshold | 69 kV and above, local distribution excluded | High and medium impact BES Cyber Systems, plus EACMS and PACS | Assets containing low impact BES Cyber Systems |
| What it covers | Physical equipment, components, software, firmware, digital and maintenance services, remote-access capability | Procurement and installation planning for vendor products and services | Vendor electronic remote access established under Section 3.1 |
| What it requires | Prohibition, or conditions imposed by the Secretary | A documented plan, with risk identification and assessment | Processes to determine access, disable it, and detect malicious communications |
| Trigger | Covered Foreign Entity nexus plus a risk finding | Procurement of applicable systems and services | Presence of vendor electronic remote access |
Neither CIP regime contains the order, and the order contains neither of them. An entity in full compliance with CIP-013-2 hasn't necessarily done anything this order will ask for, and the reverse holds as well.
Where the States Come In
The next question after the voltage one is usually whether states will object, and I think they will, though possibly not where people expect.
The order doesn't assert authority over facilities. IEEPA regulates transactions involving property in which a foreign country or a national of one holds an interest, and it rests on foreign commerce and a declared emergency rather than the interstate transmission construct FERC works from. So the Section 201(b) reservation to the states isn't really the constraint people will reach for first, and the order carves out local distribution on its own terms anyway. The 69 kV floor isn't so much a federal push into state territory as a different line in a domain where the state and federal line was never drawn at a voltage to begin with.
Cost recovery will get argued first and the mechanics are further down. The short version is that state commissions will be asked to find prudent the cost of replacements compelled by a federal order their state had no part in, with no federal recovery mechanism standing behind it. I'd expect that conversation to start at the state level and in the trade associations well before it reaches a court.
An entity holding a FERC determination that its 115 kV facilities are used in local distribution, and therefore exempt from reliability standards, may still find those same facilities inside this order's scope. The order defines bulk-power system for its own purposes, sets its own floor at 69 kV, and carries its own local distribution exclusion. Nothing obligates the Department to honor a determination FERC made under a different statute for a different reason, and while Order 888 says FERC will give deference to state commission determinations on the transmission and distribution question, nothing here creates a comparable obligation. So an asset can sit outside CIP and inside this order at the same time. If you went through an Order 773 exception process, it’s worth a look.
Municipals and cooperatives land in a similar spot for a different reason. They aren't public utilities under Section 201, they're creatures of state law answering to local boards, and plenty of them sit outside FERC rate jurisdiction entirely. IEEPA reaches any person subject to the jurisdiction of the United States, with no public-utility gate in front of it, so state regulation isn't a shield here.
The order excludes facilities used in the local distribution of electric energy, then affirmatively lists battery energy storage systems, grid-connected inverters, and generation needed to maintain electric system reliability. A battery sitting on a distribution circuit is arguably a resource rather than a local distribution facility, which would put it inside. I don't know the answer and I don't think anybody does yet. It also happens to be the class with the heaviest foreign supply exposure. A study sponsored by the Department of Energy's Office of Cybersecurity, Energy Security, and Emergency Response found that more than 90 percent of grid-scale battery energy storage deployed in the United States contains critical components manufactured in China, including battery management systems, power conversion systems, and supervisory interfaces, which I covered in testimony to the US-China Economic and Security Review Commission last year. Those are the components that take firmware updates and report telemetry, which is to say they are the components this order actually reaches. So that is probably where this gets tested.
What We Already Built for Vendor Remote Access
CIP-003-9 became effective April 1, 2026, four months before this order. It added Requirement R1.2.6, so the low impact policy has to address vendor electronic remote access security controls, and it added Attachment 1 Section 6, which requires that for assets containing low impact BES Cyber Systems that allow vendor electronic remote access, the Responsible Entity implement processes to determine that access, to disable it, and to detect known or suspected malicious inbound and outbound communications associated with it.
Read Section 6.1 and 6.2 next to Section 2(b) of the order. The vendor access inventory and the ability to cut a vendor off are more or less exactly what a DOE directive on installed equipment would require an entity to exercise, probably on a short clock. Anyone who built Section 6 as practice rather than as documentation is some distance down the road already. That's not a small thing, and it's the strongest position most low impact entities have going into this.
The gaps are real, though. Section 6 reaches low impact BES Cyber Systems, which means 100 kV and up under the Bulk Electric System definition, and it triggers only where vendor access was established under Section 3.1, so external routable connectivity. The order reaches down to 69 kV, and reaches remote-access capability whether or not anyone has turned it on, along with firmware and lifecycle update mechanisms that no CIP-003 requirement touches at all. There's also a mismatch in how the two are organized. Neither "vendor" nor "vendor electronic remote access" is a defined term in the NERC Glossary, and your Section 6 inventory is almost certainly sorted by who has access. The order needs it sorted by who owns the manufacturer. Most of us have the first list and not the second. Building the second is the actual work.
CIP-003-11, approved in FERC Order No. 918 on March 19, 2026, merges Sections 3 and 6 of Attachments 1 and 2 so that all electronic access requirements sit in one place, and adds remote user authentication, protection of authentication information in transit, and broader detection of malicious communications. NERC's implementation plan even notes that entities may already have invested significantly in architecture to monitor vendor remote access under CIP-003-9, which is part of why the compliance date for the broadened detection requirement runs to the later of April 1, 2029 or the standard's effective date. Per NERC's compliance bulletin, that effective date is July 1, 2029.
So the vendor-specific framing is on its way out of CIP-003, folded into a single set of expectations for all remote users, at roughly the same moment an executive order makes vendor identity the controlling question. I don't think that's a problem, exactly. It does mean the vendor-oriented artifacts we're building for one regime won't map cleanly onto the other, and it's probably worth deciding now whether you keep maintaining a vendor-organized view after 2029 for reasons that have nothing to do with CIP.
What CIP-013 Doesn't Ask
The supply chain standard is the one most high and medium impact entities will reach for when they hear about a supply chain executive order. CIP-013-2 Requirement R1 calls for a documented supply chain cyber security risk management plan covering high and medium impact BES Cyber Systems and their associated Electronic Access Control or Monitoring Systems (EACMS) and Physical Access Control Systems (PACS). R1.1 wants processes for identifying and assessing cyber security risk from vendor products and services, both from procuring and installing them and from transitions between vendors. R1.2 wants six procurement processes, covering vendor notification of incidents, coordination of responses, notice when vendor access should no longer be granted, disclosure of known vulnerabilities, verification of software integrity and authenticity, and coordination of controls for vendor-initiated remote access.
Not one of those six asks who owns the manufacturer, who controls it, or where the equipment was built. R1.2.5 comes closest and still isn't close, since verifying software integrity and authenticity establishes only that what you installed came from the vendor unaltered. Country of origin and corporate control just aren't CIP-013 questions.
BES Cyber Systems are Cyber Assets, and a large power transformer isn't one, and neither is a circuit breaker, a shunt capacitor bank, or a generation turbine. So most of what this order lists has no CIP-013 counterpart at all, and the overlap stops at the relays, RTUs, PLCs, and IEDs sitting at the cyber end of the equipment list. R1.1 is the one part that helps, because it already requires a process for assessing risk in transitions from one vendor to another, which is the process a forced replacement under Section 2(b) would put you in, and my guess is most of us wrote it years ago (or earlier) and may have never actually used it.
NERC is working some of this under Project 2025-06, responding to FERC Order No. 912. Draft 1 of CIP-013-4 adds Protected Cyber Assets to R1, requires a fresh assessment before deployment when the last one is more than 24 calendar months old for high impact systems or 36 for medium, spares and emergency repairs included, and requires periodic reassessment of vendors, products, and services under existing contracts. Its technical rationale even lists country-of-origin changes among the factors that shift risk across a contract term. The requirement text still doesn't ask who owns the manufacturer, and Draft 1 drew 30.64 percent weighted segment approval against the two-thirds NERC requires, so whatever eventually reaches FERC will look different.
Order No. 912 carries two docket numbers. The second is a Notice of Inquiry FERC opened in September 2020, titled Equipment and Services Produced or Provided by Certain Entities Identified as Risks to National Security, asking whether the CIP standards adequately mitigate risk from equipment made by entities identified as national security risks, and citing Executive Order 13920 among its reasons for asking. Order No. 912 terminated it. Five years of comment on the ownership question, closed without a directive on it, about eleven months before an executive order answered the same question under a completely different statute.
The Installed Equipment Problem
Section 2(b) says the following:
Nothing like that appeared in 2020. The 2020 order was purely forward-looking, and DOE's reach into installed equipment came from a separate prohibition order that was later revoked.
The guardrails are worth reading carefully, because they're procedural. Before directing isolation, disconnection, replacement, or removal, the Secretary shall consider effects on reliability and safety, the availability of secure replacements, and continuity of essential service, and may establish phased compliance. Consideration is a documentation requirement rather than a limit on the outcome. There's no notice and comment step, no hearing right, and Section 7(c) says the order creates no right or benefit enforceable against the United States.
For those of us who have to execute one of these, the second-order effects are where the pain lives. Pulling a relay, an RTU, or an IED out of a substation on a federal clock lands on CIP-010 change management, CIP-005 access revision, possibly a CIP-002 categorization look, transient cyber asset and removable media controls during commissioning, CIP-014 if the substation is in scope, and the vendor coordination pieces of CIP-013. A federal directive isn't automatically a CIP Exceptional Circumstance, and I wouldn't want to be discovering that during the outage. The Project 2025-06 drafting team looked at this squarely and declined to build any CIP Exceptional Circumstance exclusion into CIP-013-4, noting that Order 912's directives reach even emergency repairs. So on the current draft, declaring a CIP Exceptional Circumstance would not relieve you of the pre-deployment assessment on the spare you are about to energize. Working the change management path for a hypothetical forced replacement now, while nobody is watching, is a lot cheaper than working it later.
The International Emergency Economic Powers Act (IEEPA) reaches property in which a foreign country or a national of one has an interest. For a fully paid, title-transferred transformer sitting in a yard, that interest is thin. The order's answer is the parenthetical in Section 2(a), which counts an interest in a contract for the provision of the equipment, together with the new coverage of software, digital service, maintenance service, and remote access. The same expansion that widens the scope is also what supplies the hook for reaching equipment already installed. On the text, legacy equipment with no live service or license relationship is harder to reach than equipment under an active maintenance agreement.
Two Authorities, Two Sets of Consequences
Congress has written more than one tool for this general problem, and the two most relevant ones carry different packages.
This order runs on IEEPA and the National Emergencies Act. Under 50 U.S.C. 1705, the maximum civil penalty per violation is the greater of $377,700 or twice the amount of the transaction that forms the basis of the violation, and willful violations carry criminal exposure. The new anti-evasion clause in Section 2(f) tracks the statute, so evasion, attempt, conspiracy, and causing a violation are each independently reachable. The "twice the transaction" measure is the one to sit with, because it scales with deal size rather than with harm. On a large transformer package that arithmetic gets uncomfortable fast, and it can exceed the familiar CMEP exposure of up to $1 million per violation per day by a significant margin. There's also no CMEP-equivalent architecture around it, so no self-report credit schedule, no mitigation plan process, and no reliability-preserving off-ramp of the kind we're used to.
Section 215A of the Federal Power Act, added by the FAST Act in 2015 and codified at 16 U.S.C. 824o-1, is the other tool. It lets the Secretary order emergency measures after a presidential grid security emergency declaration, with or without notice or hearing, reaching any owner, user, or operator of critical electric infrastructure, including municipals, cooperatives, and the federal power marketing agencies. DOE built the issuance procedures at 10 C.F.R. Part 205 in January 2018. Two features of 215A don't have IEEPA counterparts. Where a party prudently incurs substantial costs complying with a 215A order and can't reasonably recover them through regulated rates or market prices, FERC may establish a cost recovery mechanism. And 215A shields affected parties from what would otherwise be violations of the Federal Power Act or of specific reliability standards, absent gross negligence.
IEEPA reaches procurement, imports, and foreign suppliers in ways 215A doesn't. It also arrives without the cost recovery pathway and without the reliability standard protection. That's the trade, and it's worth understanding rather than arguing about.
Which brings up the money question, since Executive Order 14420 carries no appropriation. Section 7(b) says the order is implemented subject to the availability of appropriations, and that language funds the government's own work rather than anyone's compliance costs. If a directive under Section 2(b) requires replacement of installed equipment, the cost lands on the owner, and from there it goes to a prudence argument at a state commission, a transmission formula rate at FERC, or the Court of Federal Claims. Rates or shareholders, in other words, and probably some of each depending on the jurisdiction. I'd start that conversation with regulatory affairs early rather than after a directive shows up.
Expected Challenges
Something this broad usually gets tested, and the 2020 order never really was because it lapsed before there was a rule to argue about. The pressure points here mostly follow from what's already above. Section 2(b) is the obvious one, given how thin the foreign interest looks in a transformer that's been paid for and energized for a decade, and given that Congress wrote Section 215A to cover emergency directives to infrastructure owners with conditions attached. The state questions in the earlier section are the other likely source, and those will probably arrive through commissions and trade associations rather than through a court.
The definitional edges look contestable too. "Subject to the jurisdiction or direction of" a covered government is undefined and does most of the work in deciding whether a manufacturer is in scope, and "initiated" sets the boundary of the forward prohibition without appearing in the definitions section at all. Section 7(c) says the order creates no enforceable right, and there's no notice and comment step, so the first practical venue for most of this is probably a challenge to whatever DOE publishes in December rather than to the order itself. None of which is a reason to plan around a challenge succeeding, and I wouldn't build a compliance posture on the assumption that a provision goes away.
What to Do Before December 24
The rules aren't written, so anything you build now should be the kind of thing that's useful regardless of what they say.
Extend your equipment inventory below the CIP asset list. Everything at 69 kV and above, plus battery energy storage, grid-connected inverters, and uninterruptible power supply systems supporting critical infrastructure. Record country of manufacture, country of design, and the controlling parent of the manufacturer as three separate fields, because the order treats them as three separate questions.
Re-sort your CIP-003-9 Section 6 vendor access inventory by manufacturer ownership rather than by who holds credentials. This is the single largest gap between what we already have and what the order will want.
Document the initiation date of every pending procurement now, with evidence, while the records are fresh. The forward prohibition turns on transactions initiated after August 26, 2026, and "initiated" isn't defined.
Pull the change-in-law, force majeure, and assignment clauses out of your open supply agreements and read them. Section 2(d) applies the prohibitions notwithstanding any prior contract.
Walk the CIP change management path for a hypothetical forced replacement of a relay or an RTU, end to end, and find out where it breaks before someone else sets the schedule.
Watch for DOE orders and not only for rules. The 120-day rulemaking mandate is qualified with "as needed," and the 2020 experience was a prohibition order rather than a regulation. Nothing has come from the Department yet, so its own pages are the place to check.
Track 22 C.F.R. 126.1 as a live document rather than a snapshot.
Where That Leaves Us
The compliance floor and the security floor have never been the same thing. This order widens the distance between them in a direction most programs weren't built to look. What CIP asks of us at low impact is a process for vendor remote access. What this order contemplates is a determination about who made the box, followed potentially by an instruction to take it out. Those are different questions answered with different evidence, and the second one reaches equipment that our categorization work has told us for years we didn't need to worry much about.
I don't have a confident view on how far this goes. The 2020 version produced no rules in twelve months and then lapsed, and there's a version of the next twelve months that looks the same. There's also a version where a prohibition order lands in the first quarter of 2027 on a class of equipment that a lot of us have installed. December 24 is the first real signal either way, and until then the work that pays off in both cases is the same work, which is knowing what we have and who built it.