EO 14421: What the Electricity Sector and Equipment Manufacturers Need to Do to Secure Their Supply Chains

Client Alert
September 4, 2026

The order gives the Department of Energy broad authority to restrict high-risk foreign-produced grid equipment and condition the use of existing assets. Utilities and suppliers should begin building the evidence needed for informed decisions as DOE develops the implementing rules.

Executive Order 14421, first identified as EO 14420 by the White House and in early reporting, signed August 26, 2026, declares a national emergency related to foreign supply of bulk-power system electric equipment on systems over 69kV. It authorizes the U.S. Department of Energy (DOE) to prohibit, condition, license, or require mitigation for certain transactions involving foreign-produced equipment connected to a Covered Foreign Entity when DOE determines that the transaction creates an undue or unacceptable national-security risk.

The order reaches beyond the original hardware purchase. It expressly includes:

  • critical components
  • software
  • firmware
  • digital and maintenance services
  • remote-access capabilities
  • lifecycle update mechanisms

DOE may also impose conditions on foreign-manufactured or foreign-operated equipment acquired or installed before August 26, including requirements to identify, isolate, monitor, secure, disconnect, replace, or remove equipment. Before directing disruptive action, DOE must consider reliability, safety, replacement availability, and continuity of essential service, and may phase compliance.

The order does not create a blanket ban on imported, Chinese, or other foreign equipment but it will impose substantial restrictions. Foreign origin alone does not make a transaction prohibited. For purposes of the order, foreign-produced means an article not manufactured, produced, or assembled in the United States.

 

Flag - China
Flag - Iran
Flag - Russia
Flag - North Korea

We expect the initial focus will be on supplies with links to China, Iran, Russia and North Korea. DOE must still make the risk findings specified in the order. Key details will depend on forthcoming rules, designations, licenses, and any pre-qualified vendor or equipment lists. Companies that run and contribute to the Bulk Power System have a practical window now to identify exposure, improve records, and prepare options before uncertainty turns into procurement delays or unplanned replacement costs.

Why EO14421 Matters

EO 14421 arrives when the security risks from foreign adversaries on critical infrastructure are heightened.  Attacks and exploitation against energy and water facilities are proliferating both domestically and internationally and a key mechanism for those attacks is technologies that underpin service delivery.  Security those technologies is a national priority, particularly because electricity demand from data centers, artificial intelligence, advanced manufacturing, electrification, and defense production is rising.

Many grid projects already face long lead times, limited domestic capacity, and globally distributed supply chains.  If adversaries attack those systems the problems will be exacerbated and could affect capital programs, supplier choices, maintenance arrangements, interconnection schedules, federal contracting, and the availability of replacement parts. Balancing security and availability of critical supplies is a must.

The business challenge is precise identification of impacted components in their supply chain in response to restrictions. Companies need to distinguish equipment and dependencies that may require mitigation from acceptable products that can remain in service or proceed through procurement. A headquarters address or Tier 1 supplier name will rarely answer the full question. Country of manufacture, beneficial ownership, component origin, embedded software, firmware update paths, remote access, maintenance providers, and sub-tier suppliers all matter.

Commercial Entities Affected: Who Needs to Take Action

Asset owners and operators

Generation companies, transmission owners, investor-owned and public power utilities, independent power producers, nuclear operators, and grid-scale storage developers should assess covered assets and planned transactions, especially where there is significant operational technology equipment.

Manufacturers of transformers, turbines, generators, inverters, batteries, relays, circuit breakers, industrial controls, and associated software or services may need to document production origin, ownership, component provenance, update mechanisms, and remote-access arrangements.

Companies that select, source, install, integrate, maintain, update, or remotely access covered equipment may hold information that asset owners need and may be directly involved in a covered transaction.

DOE is directed to recommend changes to the Federal Acquisition Regulation (FAR) that account for national-security risk and prioritize U.S.-manufactured energy infrastructure. Those requirements may flow into bids, contracts, and supplier evidence requests.

The order defines the bulk-power system to include transmission lines rated at 69 kV or higher and generation needed to maintain system reliability. Local distribution equipment is excluded. Covered equipment includes a broad list of generation, transmission, substation, control-room, and industrial-control assets. Applicability should be assessed at the asset, transaction, and dependency level rather than inferred from company type alone.

What Changes - and When

Timing

Government action

Business implication

Now

DOE may prohibit or condition covered transactions initiated after August 26, 2026, when it makes the required findings.

Review pending acquisitions, imports, transfers, and installations. Preserve supplier, origin, and procurement evidence.

No fixed deadline

DOE may require existing equipment to be identified, monitored, isolated, secured, disconnected, replaced, or removed. Reliability, safety, replacement availability, and continuity of service must be considered.

Build a usable equipment inventory and separate risks that may be mitigated from those that could require replacement.

As soon as practicable

DOE will identify potentially high-risk equipment and recommend ways to inventory, monitor, isolate, or replace it.

Expect closer scrutiny of certain technologies, suppliers, jurisdictions, and digital dependencies.

By Dec. 24, 2026

DOE is directed to publish implementing rules or regulations as needed.

Expect more detail on covered entities, equipment, licensing, evidence, and transaction review.

By Feb. 22, 2027

DOE will recommend FAR revisions for federal energy-infrastructure procurement.

Manufacturers and contractors selling to federal customers may face new sourcing and documentation requirements.

Within 90 days of DOE’s FAR recommendations

The FAR Council will consider proposing acquisition-rule changes for public comment.

New clauses could flow into federal contracts and supplier relationships.

Source: White House Executive Order 14420. DOE may also develop a pre-qualified equipment or vendor list; the order sets no deadline for that action.

What Companies Need to Do Now

  1. Create or strengthen the equipment inventory.
    Capture manufacturer, model, asset location, operating role, criticality, installation date, procurement status, and responsible business owner for equipment potentially within scope.
  2. Establish origin and ownership evidence.
    Document where equipment was manufactured, produced, and assembled. Trace supplier ownership, control, jurisdiction, and relevant sub-tier relationships instead of relying on headquarters location or vendor self-identification alone.
  3. Map digital and lifecycle dependencies.
    Identify embedded software and firmware, logic-bearing components, update channels, cloud or digital services, remote access, maintenance providers, subcontractors, and the parties able to modify or control the equipment.
  4. Review transactions already in motion.
    Prioritize acquisitions, imports, transfers, and installations initiated after August 26. Preserve contracts, bills of material, attestations, country-of-origin records, technical specifications, and decisions supporting supplier selection.
  5. Prioritize by consequence and replacement difficulty.
    Combine supplier and product risk with equipment criticality, operational consequence, lead time, concentration, and availability of secure alternatives. This supports proportionate mitigation rather than premature wholesale replacement.
  6. Prepare mitigation and sourcing options.
    Evaluate monitoring, isolation, access restrictions, compensating controls, alternative suppliers, redesign, phased replacement, and inventory strategies. Confirm that proposed remedies will not create greater reliability or safety risk.
  7. Coordinate across functions.
    Engineering, operations, OT cybersecurity, procurement, legal, compliance, government affairs, and finance should use a shared evidence set and escalation process. Suppliers should be ready to answer the same questions from multiple customers.

How Exiger Can Help with EO 14421 Compliance

Exiger helps companies identify where they are exposed, decide what requires attention first, and document the basis for action. The goal is visibility, prioritization, and cost avoidance. Compliance decisions remain with company leadership, engineers, legal counsel, regulators, and the government.

  • Inventory enrichment. Connect equipment and procurement records with manufacturer, supplier, ownership, jurisdiction, sanctions, location, and risk data.
  • Multi-tier supply-chain illumination. Map products, components, materials, and hidden supplier relationships; build or enrich bills of material when customer records stop at the prime contractor.
  • Digital dependency mapping. Identify relevant hardware, software, firmware, maintenance, update, cloud, and remote-access relationships.
  • Risk-based prioritization. Combine supplier and component findings with equipment criticality, operational consequence, concentration, lead times, and replacement feasibility.
  • Alternative-supplier analysis. Identify potential sources, assess concentration and transition risk, and support sourcing strategies when a current option becomes restricted or impractical.
  • Continuous monitoring and evidence management. Track changes in ownership, sanctions, supplier relationships, risk signals, and supporting records as DOE’s implementation develops.

What Exiger's HVPT Research Shows

Exiger began examining a key part of the Bulk Power System, high-voltage power transformer (HVPT) supply chains in early 2025 in anticipation of renewed federal action on foreign ownership, control, and influence risk. The research illustrates why this work must extend below the OEM and beyond the finished transformer.

Exiger’s analysis found that more than 80% of new HVPTs in the United States were imported as of 2019, while newly manufactured large power transformers faced lead times of up to 210 weeks. Less than one-third of companies identified across the mapped HVPT supply chain were U.S.-based. Seven transformer manufacturers directly sourced logic-bearing components from China or Hong Kong, and six mapped products had no identified U.S. supplier. The analysis also found concentration in critical materials such as grain-oriented electrical steel.

These findings do not establish that a supplier or product is prohibited under EO 14421. They show what multi-tier illumination can reveal: where foreign dependence is concentrated, which logic-bearing components warrant closer review, where ownership connections are obscured by intermediaries, and where replacement could be constrained by lead time or lack of alternatives. That evidence allows utilities and OEMs to focus on the highest-consequence dependencies and build practical mitigation plans.

 

How EO 14421 Relates to Existing NERC Requirements

NERC CIP

EO 14421 does not amend or replace NERC Critical Infrastructure Protection standards. NERC CIP-013 requires covered responsible entities to maintain supply-chain cybersecurity risk-management plans for applicable high- and medium-impact Bulk Electric System cyber systems, including processes for vendor incidents, vulnerabilities, software integrity, patches, and remote access.

EO 14421 creates a separate national-security authority. DOE can determine that a specific transaction must be prohibited, conditioned, licensed, or mitigated based on equipment origin, supplier ownership or control, associated services, and the risk presented. It can also reach physical equipment and legacy assets outside CIP-013’s principal high- and medium-impact cyber-system scope. NERC CIP compliance therefore remains necessary where applicable, but it does not establish that a transaction or asset is permissible under the EO.

What Remains Unresolved

DOE has not yet identified all countries, persons, suppliers, products, or services that will receive heightened scrutiny. The government has also not published the evidence expected from companies, the licensing process, the form of mitigation agreements, or a pre-qualified equipment and vendor list. The order does not prescribe a universal hardware or software bill of materials, supplier questionnaire, or domestic-content percentage.

Those open questions make early visibility work more valuable. Companies that can locate covered equipment, trace origin and control, explain digital dependencies, and compare mitigation options will be better positioned to respond when DOE provides additional direction.

Get Ready Before the Rules Arrive

The first useful step is a focused exposure assessment covering critical equipment, planned transactions, foreign and sub-tier dependencies, software and remote access, and replacement constraints. That assessment gives leaders a defensible starting point for procurement decisions, supplier engagement, mitigation planning, and future DOE requests.

Exiger can help utilities, energy producers, manufacturers, EPCs, integrators, and federal contractors build that evidence base and convert it into a prioritized action plan. 

Get in Touch

Get a Readiness Assessment

Contact Exiger to discuss an EO 14421 readiness assessment or a targeted illumination of critical grid equipment.

Contact us or reach out to your Customer Success Manager to get started.

Table of Contents

Get in Touch

Learn how you can build a more resilient supply chain.