On August 26, 2026, President Donald Trump signed an Executive Order declaring a national emergency related to foreign threats involving the U.S. bulk-power system, bringing new attention to cybersecurity and technology supply-chain risks within critical infrastructure. The order is designated Executive Order 14420.
The U.S. power grid supports national defense, emergency services, manufacturing, data centers, communications, and many other essential operations. As these systems become more connected to digital technology, protecting them is becoming both a cybersecurity and national security priority.
For defense contractors and organizations within the Defense Industrial Base (DIB), the announcement highlights an important lesson: cybersecurity risk does not always begin inside your own network.
Key Takeaways
- The U.S. has declared a national emergency related to foreign threats involving the bulk-power system.
- The concern includes cybersecurity and supply-chain risks associated with certain foreign-produced equipment and technology used within critical infrastructure.
- The Executive Order does not announce that the U.S. power grid was successfully hacked, and it does not change CMMC requirements.
- For businesses and defense contractors, the broader lesson is to understand the technology, vendors, remote access, equipment, and outside services their operations depend on.
Why Did the U.S. Declare a National Emergency?
The United States depends heavily on reliable electricity.
Power supports hospitals, emergency services, telecommunications, data centers, government facilities, manufacturing, defense production, and other critical infrastructures.
According to the Executive Order, certain foreign actors are increasingly creating and exploiting vulnerabilities in the U.S. bulk-power system.
The order also raises concerns about America’s reliance on certain foreign-produced bulk-power equipment.
Modern power infrastructure can contain much more than physical electrical components. Equipment may include or depend on software, firmware, digital services, maintenance services, industrial control systems, and remote-access capabilities.
The Executive Order warns that foreign-produced equipment could potentially contain vulnerabilities, including digital backdoors that could allow a foreign country to remotely access equipment.
That creates both a cybersecurity risk and a supply-chain risk. The Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER) serves as the Sector Risk Management Agency for the energy sector and leads federal efforts to strengthen energy infrastructure security.
Was the U.S. Power Grid Hacked?
The Executive Order does not announce that China or another foreign government successfully hacked or shut down the U.S. power grid.
This distinction is important.
The national emergency is focused on reducing the possibility that foreign actors could exploit vulnerabilities within critical power infrastructure.
Cybersecurity is not only about responding after an attack succeeds. It is also about identifying weaknesses and reducing risk before attackers have an opportunity to exploit them.
The Executive Order gives the federal government additional authority to address certain foreign-produced bulk-power equipment when it presents unacceptable national security, cybersecurity, or infrastructure risks.
What Technology Could Be Affected?
The Executive Order covers a wide range of equipment used within the bulk power system.
Examples include:
- Transformers
- Generators
- Battery energy storage systems
- High-voltage circuit breakers
- Protective relays
- Grid-connected inverters
- Industrial control systems
- Programmable logic controllers
- Remote terminal units
- Distributed control systems
- Safety instrumented systems
The government may also consider software, firmware, remote-access capabilities, maintenance and updating mechanisms, and other supply-chain dependencies associated with that equipment.
This is where the cybersecurity concern becomes especially important.
A piece of physical equipment may also have software running inside it, communicate with other systems, receiving updates, or allowing technicians to connect remotely.
Each connection needs to be understood and properly secured.
Cybersecurity Is Also a Supply-Chain Issue
Most organizations depend on outside companies for technology.
That may include hardware manufacturers, software vendors, cloud providers, managed service providers, telecommunications companies, equipment suppliers, and other third parties.
Those relationships create dependencies.
This is where Cybersecurity Supply Chain Risk Management (C-SCRM) becomes important.
NIST describes C-SCRM as identifying, assessing, and mitigating cybersecurity risks associated with interconnected technology products and service supply chains.
NIST SP 800-161r1 guidance emphasizes understanding technology suppliers, determining which suppliers and systems are most critical, establishing appropriate cybersecurity requirements, and integrating supply-chain cybersecurity into an organization’s broader risk-management activities.
The goal is not to assume every supplier is dangerous.
The goal is to understand where your organization depends on outside technology and what could happen if that technology or provider were compromised. CISA maintains additional supply-chain risk management resources for both large and small organizations.
Why This Matters to Defense Contractors
Defense contractors often depend on many outside technologies and services to perform their work.
These may include:
- Cloud platforms
- Managed service providers
- Software vendors
- Network equipment
- Telecommunications providers
- Manufacturing equipment
- Data centers
- Remote-access tools
Even when an organization has strong internal cybersecurity protections, an outside dependency can still create risk.
For example, a vendor may have legitimate remote access to equipment for maintenance.
That creates several important questions.
Who can access the equipment?
How are they authenticated?
What systems can they reach?
Is their activity monitored?
What happens if the vendor itself is compromised?
Understanding those connections helps organizations identify risk before an incident occurs.
What Does This Have to Do With CMMC?
The Executive Order does not change CMMC requirements.
However, it reinforces a broader cybersecurity principle that also matters to defense contractors: organizations need visibility into their systems, data, access, and technology dependencies.
The Cybersecurity Maturity Model Certification (CMMC) Program, codified at 32 CFR Part 170, is focused on verifying that applicable Department of Defense contractors and subcontractors implement required protections for Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
For organizations working toward CMMC Level 2, understanding where CUI is processed, stored, and transmitted is especially important.
CMMC requirements address areas such as access control, remote access, audit logging, configuration management, incident response, vulnerability management, and system security.
Broader cybersecurity supply-chain risk management goes beyond simply meeting CMMC Level 2 requirements.
The important point is that compliance and cybersecurity support each other, but they are not the same thing.
Organizations need to understand both the requirements they must meet and the real-world cybersecurity risks affecting their environment.
Five Cybersecurity Questions Organizations Should Ask
The power-grid emergency provides a useful opportunity for organizations to review their own technology environments.
The process can start with five areas:
1. Inventory: What Technology Do We Have?
Organizations should know what hardware, software, devices, and systems are connected to their environment.
An accurate inventory creates visibility.
Without that visibility, it becomes much harder to identify outdated systems, unauthorized technology, vulnerable devices, or other potential security gaps.
2. Access: Who Can Connect to Our Systems?
Organizations should understand who has access to important systems and why they need it.
This includes employees as well as vendors, contractors, manufacturers, service providers, and other third parties.
Remote access should be limited, properly authenticated, secured, and monitored.
3. Vendors: Who Do We Depend On?
Not every supplier presents the same level of risk.
Organizations should identify which technology providers are most important to their operations and consider what could happen if one of those providers became unavailable or compromised. The CISA ICT Supply Chain Risk Management Task Force publishes free vendor evaluation templates and small-business supply chain resources.
Knowing your critical vendors can help you better understand your overall cybersecurity exposure.
4. Vulnerabilities: Are Weaknesses Being Identified and Fixed?
Cybersecurity vulnerabilities can exist more than computers.
They can also appear in software, networking equipment, firmware, security appliances, connected devices, and industrial systems.
Organizations should have a process for identifying vulnerabilities, evaluating their risk, and applying appropriate updates or remediation.
5. Incident Preparedness: What Happens If a Provider Gets Hacked?
A cyberattack does not have to begin inside your company to become your problem.
Organizations should consider critical suppliers and technology providers when developing incident response and business continuity plans.
If an important provider becomes compromised or unavailable, teams should know how they will respond and continue essential operations.
Why This Matters Beyond the Power Grid
The national emergency is focused specifically on America’s bulk-power system, but the cybersecurity lesson applies much more broadly.
Organizations increasingly depend on connected hardware, software, cloud platforms, outside providers, and remote services.
That connectivity creates opportunities, but it can also create new paths for attackers.
A compromised account, vulnerable device, exposed remote connection, malicious software component, or compromised supplier could potentially affect an organization’s security or operations.
For defense contractors, understanding those dependencies is especially important when systems support government contracts or handle sensitive information.
Looking Ahead
The August 2026 Executive Order shows how closely cybersecurity, critical infrastructure, supply chains, and national security are becoming connected.
The order also directs the Secretary of Energy to publish implementing rules, so additional federal guidance is expected in the months ahead.
Organizations cannot control every cyber threat.
But they can improve their understanding of technology and people that have access to their environments.
Know your environment. Know who has access to it. Know what technology you depend on. And understand the risks before an attacker finds them first.
Frequently Asked Questions
Did China hack the U.S. power grid?
The Executive Order does not announce that China successfully hacked or shut down the U.S. power grid. It addresses broader foreign threats and potential vulnerabilities involving certain foreign-produced technology used within critical U.S. power infrastructure.
Why did the U.S. declare a national emergency over the power grid?
The national emergency addresses foreign threats involving the U.S. bulk-power system, including cybersecurity and supply-chain risks that could affect the security, integrity, or reliability of critical power infrastructure. See the White House fact sheet for the administration’s summary.
What is cybersecurity supply-chain risk?
Cybersecurity supply-chain risk involves potential security risks introduced through the hardware, software, suppliers, vendors, service providers, and other technology dependencies an organization relies on. NIST addresses this in SP 800-161r1.
Does the Executive Order change CMMC requirements?
No. The Executive Order does not change CMMC requirements. CMMC remains a separate Department of Defense program, established by the 32 CFR Part 170 final rule, focused on protecting FCI and CUI within applicable contractor and subcontractor environments.
Why should defense contractors care?
Defense contractors depend on electricity, technology providers, equipment, telecommunications, cloud services, and other outside infrastructure. A cybersecurity incident involving a critical dependency could potentially affect operations even when the contractor was not the original target.
Sources and Further Reading
- The White House — Executive Order 14420, Declaring a National Emergency to Secure the United States Bulk-Power System (August 26, 2026)
- The White House — Fact Sheet: Securing America’s Bulk-Power System
- U.S. Department of Energy — Office of Cybersecurity, Energy Security, and Emergency Response (CESER)
- NIST — Cybersecurity Supply Chain Risk Management (C-SCRM) Project
- NIST SP 800-161r1 — Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations
- NIST SP 800-171 Rev. 2 — Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
- NIST SP 800-171 Rev. 3
- DoD CIO — Cybersecurity Maturity Model Certification (CMMC)
- DoD CIO — CMMC Resources and Documentation
- eCFR — 32 CFR Part 170, CMMC Program
- Federal Register — CMMC Program Final Rule
- Supplier Performance Risk System (SPRS) — CMMC
- National Archives — Controlled Unclassified Information (CUI) Registry
- CISA — Information and Communications Technology Supply Chain Risk Management
- CISA — ICT SCRM Task Force Resources
Schedule a free consultation with the Brea Networks team to review your current environment, identify compliance risks, and understand what steps are required to move forward. A short conversation can help you avoid costly mistakes and focus on what matters for contract eligibility and security.