Urgent need for cybersecurity overhaul as BESS deployment accelerates, Energy Storage Europe says

LinkedIn
Twitter
Reddit
Facebook
Email
Energy Storage Europe BESS cybersecurity report
Released this month (September), Energy Storage Europe’s report, Cybersecurity in Battery Energy Storage Systems: Roles, Responsibilities, and Regulatory Gaps Across the Value Chain, warns that current regulatory gaps and inconsistent implementation across member states are increasing costs and slowing deployment whilst failing to adequately address grid-level risks. Image: Energy Storage Europe

Trade body Energy Storage Europe has called for significant reforms to the European Union’s (EU’s) cybersecurity framework for battery energy storage systems (BESS).

Energy Storage Europe’s new report, Cybersecurity in Battery Energy Storage Systems: Roles, Responsibilities, and Regulatory Gaps Across the Value Chain, warns that current regulatory gaps and inconsistent implementation across member states are increasing costs and slowing deployment, whilst failing to adequately address grid-level risks.

The trade body has welcomed the European Commission’s focus on cybersecurity in the energy sector and supports the direction of its Cyber Resilience Act (CRA), the Network Code on Cybersecurity (NCCS), and the proposed Cybersecurity Act (CSA) 2.0, but raised concerns about their practical application to battery storage.

Grid-scale risks

Cybersecurity is an ever-increasing concern for energy infrastructure. Recently news agency Reuters reported that the CEO of Europe’s largest grid operator, E.On, stated that grid attacks are “increasing significantly.”

This article requires Premium SubscriptionBasic (FREE) Subscription

Try Premium for just $1

  • Full premium access for the first month at only $1
  • Converts to an annual rate after 30 days unless cancelled
  • Cancel anytime during the trial period

Premium Benefits

  • Expert industry analysis and interviews
  • Digital access to PV Tech Power journal
  • Exclusive event discounts

Or get the full Premium subscription right away

Or continue reading this article for free

In the US, the Federal Bureau of Investigation (FBI) issued a public safety announcement in July warning that “malicious cyber actors (MCAs) are conducting cyber attacks targeting Operational Technology (OT) devices.”

According to Energy Storage Europe, whilst BESS are not inherently more vulnerable than other grid-connected technologies, their combination of deep cyber-physical coupling, multi-vendor architectures, and third-party control dependencies creates a governance challenge where control-layer failures can escalate rapidly to grid-stability events.

With BESS capacity reaching 50GW across Europe today and projected to hit 200GW by 2030, the organisation argues these risks are no longer isolated asset-level concerns but systemic threats that require a coherent regulatory approach.

The organisation further explained that current EU framework contains significant accountability gaps, particularly for legacy assets, outsourced operations, special purpose vehicle structures, and manufacturers without an EU legal entity.

Divergent implementation of the EU’s Network and Information Security (NIS2) Directive across member states is raising compliance costs and creating unnecessary complexity that slows project deployment—a particular burden for BESS, which is manufactured at scale through highly standardised global supply chains.

In response, Energy Storage Europe has outlined four targeted actions it believes are necessary to address these challenges:

Reclassify critical components under the Cyber Resilience Act

The organisation is calling for battery management systems (BMS), power conversion systems (PCS) and energy management systems (EMS) to be reclassified as critical products under the CRA, moving them to third-party conformity assessment.

Because these components control the operational behaviour of BESS, representing the primary attack surface for cyber threats.

Harmonise connectivity requirements

Energy Storage Europe wants the EU to mandate harmonised technical requirements for BESS connectivity at distribution level, ending market-specific configurations across the Single Market that create compliance complexity and without corresponding security benefits.

Publish joint implementation guidance

The industry body is requesting joint NIS2 and NCCS implementation guidance that clarifies overlap between the two frameworks and reduces duplicative audits, which it says currently impose administrative burdens on operators without enhancing security outcomes.

Provide early clarity on supply chain scope

Energy Storage Europe is asking the Commission to give the industry early clarity on CSA 2.0 supply chain scope and timelines, to allow manufacturers and project developers to plan compliance strategies in advance of formal requirements taking effect.

Specific concerns on Cybersecurity Act 2.0

On the proposed Cybersecurity Act 2.0 specifically, Energy Storage Europe has asked legislators to define “non-technical risk” with operational precision, based on ownership, jurisdiction and state-compelled access rather than supplier location alone.

The organisation wants credit given for technical and operational mitigating measures where appropriate, reflected in Articles 103(1) and 103(2) of the proposed legislation.

Energy Storage Europe is also calling for harmonised application of CSA 2.0 across member states and sectors, with a strengthened role for the EU Agency for Cybersecurity (ENISA) that includes a meaningful right of response for affected parties.

Notably, the industry body is requesting risk-based transition periods of at least one year, reflecting the 15-to-20-year asset lifecycles typical of BESS projects operating under multi-year contracts.

Shorter transition periods could force premature replacement of functioning equipment or breach existing contractual agreeements.

Finally, Energy Storage Europe wants CSA 2.0 to serve as the single reference instrument for supply chain cybersecurity, coherent with the CRA and NIS2 Article 21, with interim high-risk-supplier measures deferring to it rather than creating parallel compliance pathways.

Balancing security and deployment

Overly restrictive or poorly coordinated cybersecurity requirements could significantly constrain available technology, increase costs, and slow deployment without necessarily improving security outcomes.

Energy Storage Europe’s call for a component-level, risk-based approach reflects an industry view that effective cybersecurity regulation should focus resources on the systems that directly control grid interaction—BMS, PCS and EMS—rather than applying uniform requirements across all elements of a BESS installation regardless of their security relevance.

The organisation’s emphasis on harmonisation across member states also highlights the recurring challenge in EU energy regulation of balancing subsidiarity principles that give member states flexibility in implementation and the need for consistent rules to support cross-border investment and supply chains in technologies like BESS that are inherently standardised and internationally traded.

3 November 2026
Málaga, Spain
Understanding technology and supplier selection for Europe’s utility-scale PV market in 2027. PV ModuleTech Europe 2026 is a two-day conference that tackles these challenges directly, with an agenda that addresses all aspects of PV module, inverter and battery supplier selection; product availability, technology offerings, supply chain traceability, quality assurance, factory auditing, system reliability, and supplier bankability.

Read Next

September 28, 2026
Two publicly funded pilots have launched in NSW, testing ways to extend the benefits of distributed solar and battery storage to households.
September 28, 2026
Akaysha Energy has reached final commercial operations at its Waratah Super Battery in New South Wales, Australia.
September 28, 2026
The New South Wales (NSW) government has granted development consent for the 200MWh Deniliquin East battery energy storage system.
September 25, 2026
Recently, US BESS companies Energy Vault and Goshe, SMT Energy and Climate Adaptive Infrastructure, and NeoVolta and SK On have made major deals and secured strategic partnerships.
September 25, 2026
Spain-headquartered Power Electronics has opened a new factory in Houston, Texas, as the US market increasingly looks to build domestic content supply chains.