" " indicates required fields
The Department of Energy’s (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) has partnered with the Idaho National Laboratory (INL) to propose strategies aimed at mitigating risks from foreign-manufactured Battery Energy Storage Systems (BESS) and addressing vulnerabilities in the U.S. energy grid supply chain. The U.S. House of Representatives has also moved forward with the SHIELD Against CCP Act, designed to combat threats targeting U.S. critical infrastructure, particularly the electric grid and energy systems.
In this article, we will explore the vulnerabilities present in BESS sourced from Chinese manufacturers and the associated cybersecurity risks these systems pose to U.S. supply chain security and grid reliability.
Additional Reading
Is the CVE Program in Jeopardy?
New US Rule Finalizes Ban on Chinese and Russian Software in Connected Vehicles
Key Learnings from the Auto-ISAC SBOM Report
BESS is fundamental to maintaining the stability and reliability of modern energy grids. These systems store energy for future use, allowing utilities to balance supply and demand, integrate renewable energy sources, and improve grid resilience. However, as with any technology, the complexity and interconnectedness of BESS introduce new cybersecurity risks, particularly when critical components come from foreign sources with ties to adversarial state actors.
Dr. Emma Stewart, the Chief Power Grid Scientist at INL, highlighted during a hearing last month at the US House Select Committee that over 90% of Chinese manufacturers rely on at least one critical component made in China. This dependency raises concerns about cybersecurity risks that could undermine grid reliability and expose the U.S. supply chain to state-sponsored threats.
Chinese manufacturing is 60% cheaper than U.S. manufacturing for BESS and 31% cheaper for battery packs. Cost savings seem to outweigh supply chain and critical infrastructure security, where vulnerabilities can be directly attributed to battery storage systems.
Despite the risks associated with foreign-manufactured BESS, the United States remains the largest exporter of Chinese-manufactured lithium-ion batteries, accounting for 25% of China’s $60 billion battery export market in 2023. This continued both economic and geopolitical factors complicate reliance on PRC-based suppliers.
The Biden administration’s decision to raise tariffs on Chinese lithium-ion batteries, from 7.5% to 25% by January 2026, has further complicated the market landscape. Coincidentally, President Trump’s recent decision to raise tariffs on China by an additional 10% (reaching a whopping 48.4%) will directly impact Chinese-manufactured batteries and battery energy storage systems (BESS). These tariffs, along with ongoing tensions between the U.S. and China, are reshaping the dynamics of the battery storage market, although the price advantage of Chinese manufacturing is difficult to overcome.

As noted by the DOE CESER, addressing the vulnerabilities in foreign-manufactured BESS requires a proactive, multi-layered approach to ensure grid security. Key recommendations for mitigating these risks include:
What other proactive security measures can you take?
The recent initiative from the DOE CESER, INL, and the U.S. House of Representatives aims to strengthen U.S. critical infrastructure against cyberattacks from adversarial state actors. C2A Security’s EVSec platform complements these efforts, providing a comprehensive solution to cybersecurity concerns in the electric vehicle ecosystem, including BESS, grid systems, and chargers.
EVSec enhances cybersecurity in operational technology (OT) and supply chain management by providing the following key capabilities:
Schedule a demo to learn how C2A Security can help protect your power grid and supply chain from CCP-related threats.
Dynamic threat modeling and risk assessment aligned with global regulations
LLM-agnostic generative AI layer powering automation across every module
Aggregated threat feed contextualized against your actual products
Generate, manage, and triage all BOMs and vulnerabilities across the lifecycle
Quantitative optimization of mitigation strategy and security control allocation
Configurable dashboards and reports across every EVSec data layer
Extract software composition and risk from firmware and binaries without source code
Optimized anomaly detection for Ethernet and CAN, plus ECU runtime protection
Quantify and manage cybersecurity risk for products operating in the field
Enrich SOC events with deep product and architecture context
Context-driven test and validation with intelligent fuzzing, integrated into CI/CD
AI-powered static analysis integrated into CI/CD with reduced false positives
Foundational layer: cyber model, workspaces, and integration backbone to DevOps toolchain
Out-of-the-box and customizable workflows for regulatory and security processes
Centralized compliance management with evidence generated from live data