源电社区

研报/未知/电池储能系统报告2024(英)

未知

电池储能系统报告2024(英)

202491

November 1, 2024This information was prepared as an account of work sponsored by an agency of the U.S. Government. Neither the U.S. Government nor any agency thereof, nor any of th…

源电解读

  • 转写自公开渠道研究报告,图表、公式与最终表述以 PDF 原文为准。
  • 全文约 91 页,发布于 2024;社区摘录便于检索,不构成投资或交易建议。
  • 读储能、现货与虚拟电厂结论时,建议对照源电分省预测和交易规则,而不是直接套用研报中的全国口径。

November 1, 2024

DISCLAIMER

This information was prepared as an account of work sponsored by an agency of the U.S. Government. Neither the U.S. Government nor any agency thereof, nor any of their employees, makes any warranty, expressed or implied, or assumes any legal liability or responsibility for the accuracy, completeness, or usefulness, of any information, apparatus, product, or process disclosed, or represents that its use would not infringe privately owned rights. References herein to any specific commercial product, process, or service by trade name, trademark, manufacturer, or otherwise, does not necessarily constitute or imply its endorsement, recommendation, or favoring by the U.S. Government or any agency thereof. The views and opinions of authors expressed herein do not necessarily state or reflect those of the U.S. Government or any agency thereof.

Table of Contents

Introduction 11 Methodology. .12 Use Cases, Penetration, and Functions of Grid Scale BESS. .13 Interconnection Timelines.. .16 Selected Use Cases for BESS .17 Overall Summary of Functions .17 Regional Performance - California. .20 Regional Performance - Hawaii. .22 Regional Performance - Texas .22 Known Operational Issues and Events. .23 Moss Landing. .23 Western Electricity Coordinating Council (WECC) Heat Event .. .24 Failure Data Analyses and Root Cause for BESS .25 Technical BESS Architecture, Components, and Functions. 25 Component Functions. .27 Battery Management Systems and Environmental Control. .27 Inverters .28 PCS .28 Power Electronic Transformers and Inverters 29 Sensors and Monitoring .29 Grid Transformers. .30 Site Control and EMS. .31 Communications and Cloud. .32 DERMS, Software, and Fleet Controllers. .34 Human-Machine Interface (HMI) .34 Supply Chain for BESS Components .35 Battery Cell/Modules. .37 Battery Cell and Integrator Relationships .38 BMS. .39 PCS .40 Inverters. .41 Summary: Presence of PRC in Combined BESS Supply Chain .43 Supply Chain Analysis Challenges: Commonality and Sources .43 Threats, Vulnerability, and Attack Exposure for BESS. ..46 Threats... .46 Vulnerability .47 Attack Exposure ..52 Common Digital and Communication Features in BESS and Power Electronics: Risk vs. Benefit. ..54 Communications and Inverters.. ..54 Condition Monitoring.. ..54 Supply Chain Threat of PRC Influence for Digital Energy Infrastructure: Evaluating the Technical Risk Landscape. ..55 Grid and Utility-Scale Operational Consequence of BESS Functions ..57 DERMS, Software, and Mass Orchestration . ..60 Integrator Risk Evaluation . .61 Scaling Integrator and Aggregator Risk at a Systems Level .62 Supply Chain Threat of PRC Influence for Digital Energy Infrastructure: Business Model and Policy Landscape .65 Roles and Responsibilities in the BESS and Inverter Sector. ..65 Potential Impact by Stakeholder.. .67 Decentralization of Ownership, Operations, and Maintenance .68 Expanding Markets for BESS Suppliers.. ..70 Legitimate Persistence within Communications Networks.. .71 Mitigation Planning and Relevant Initiatives. ...74 National Strategies and Policy ..74 Legislation . ..74 Rip-and-Replace.... ...75 Limitations of Ban Lists ..76 Prior Rip-and-Replace Initiatives.. ..77 Technical Solutions... ....8 Solution Stakeholders and Targets .78 Cyber-Informed Engineering (CiE) and Technical Assistance Programs .... ......81 Strategic Component Assessment ..81 Standards and Regulations. ...82 Develop Hardware and Firmware Citizenship.. ...82 Most-Critical Location Analysis .82 Long-Term Strategic Monitoring and Information Sharing.. ..83 Contracting and Procurement Guides.... ..83 Key Programs for Solutions.. .83 Summary and Conclusions... ..85 Appendix A: BESS Components and Functions .87 Appendix B: Consequence Ranking and Scoring... .89 Appendix C: Critical Component Prioritization .90

Figures

Figure 1. Strategic framework for supply-chain risk assessment and mitigation. .... ….13 Figure 2. 2023 U.S. energy storage installations by region (2.0 GW)9. ...14 Figure 3. U.S. energy storage installations by market share 11. ..15 Figure 4. U.S. West has 95% of U.S. battery storage capacity additions in Q2 2023 12. Figure 5. Annual U.S. cumulative installed battery capacity (as of November 2023). ......16 Figure 6. Capacity in interconnection queues as of the end of 202314. ..17 Figure 7. Battery-storage capacity and functions in CAISO, from the 2022 Event Report. ..20 Figure 8. Total capacity of CAISO-participating battery storage as of May 2023. ..21 Figure 9. Texas emergency discharge in February 2024, showing a close to 1 GW ramp in storage. .23 Figure 10. Western area outage of BESS caused by a misconfiguration and performance issue. .24 Figure 11. Global grid-scale BESS deployment and failure statistics. ...25 Figure 12. Global grid-scale BESS failure rates from 2018-2023. . ..25 Figure 13. BESS system architecture. ...26 Figure 14. Integrated strategy for component supply for an integrator.. ..27 Figure 15. Transformer components. ...31 Figure 16. BESS communication interconnections. ..33 Figure 17. Purdue diagram summary for BESS. ...3 Figure 18. U.S. lithium-ion battery imports during Q1 2023. ..38 Figure 19. Li-ion battery manufacturing planned (blue) or under construction (red). ....3 Figure 20. U.S. PCS providers vs. Chinese PCS providers. ...1 Figure 21. Global inverter companies45. ...42 Figure 22. Supply chain linkages for BESS. ...45 Figure 23. Criticality of BESS components to cyber, physical, and safety consequence outcomes.. ...57 Figure 24. Criticality of BESS functions in grid connection and operation. ...60 Figure 25: Assessment Matrix for Suppliers of BESS and integrators. ..63 Figure 26. Use case and comparison of a PRC-based integrator versus a U.S. one. ... .....65 Figure 27. Utility as owner, operator, and maintainer of BESS site. ..68 Figure 28. An example of third-party ownership; site in Texas. ..70 Figure 29 - List of DOE programs relevant to securing BESS. ..85

Tables

Table 1. BESS measurements and performed actions. .29 Table 2. Barriers and associated hazard types. .30 Table 3. HMI functionalities and connections in BESS. ..34 Table 4. Energy storage manufacturers meeting Bloomberg's NEF Tier 1 criteria as of Q2 FY 2024. .36 Table 5. Companies and their main products supplied. . .40 Table 6. Specificity of BESS components to supply chain vertical.. .44 Table 7. Attack types and potential outcomes .51 Table 8. Ability and negative impact of component misoperation. . .56 Table 9. CCE criteria scoring threshold. .59 Table 10: Integrator risk solutions on analysis scale. .63 Table 11. Roles and responsibilities in the BESS ecosystem.. .66 Table 12. Potential impact by stakeholder. .67 Table 13. Scenarios and correlating solution policies and technical approaches. .80 Table 14. BESS components and their functions. ..87 Table 15. Example of a consequence matrix.. .89 Table 16. Categorization of BESS components and their capabilities... ..90

Acronyms

<table><tr><td>AC</td><td>Alternating Current</td><td>DOE</td><td>Department of Energy</td></tr><tr><td>AOO</td><td>Asset Owner and Operator</td><td>DOS</td><td>Denial of Service</td></tr><tr><td>BABA</td><td>Build America Buy America</td><td>EIA</td><td>Energy Information</td></tr><tr><td rowspan="2">BESS</td><td>Act</td><td></td><td>Administration</td></tr><tr><td>Battery Energy Storage</td><td>EMS</td><td>Energy Management</td></tr><tr><td></td><td>Systems</td><td></td><td>System</td></tr><tr><td>BIL</td><td>Bipartisan Infrastructure Law</td><td>EV</td><td>Electric Vehicle</td></tr><tr><td>BMS</td><td>Battery Management</td><td>FEOC</td><td>Foreign Entity of Concern</td></tr><tr><td></td><td>System</td><td>FOCI</td><td>Foreign Ownership, Control,</td></tr><tr><td>BNEF</td><td>Bloomberg New Energy</td><td></td><td>or Influence</td></tr><tr><td></td><td>Finance</td><td>G&amp;T</td><td>Generation and</td></tr><tr><td>CAISO</td><td>California Independent</td><td></td><td>Transmission</td></tr><tr><td></td><td>System Operator</td><td>GDO</td><td>Grid Deployment Office</td></tr><tr><td>CATL</td><td>Contemporary Amperex</td><td>GW</td><td>Gigawatt</td></tr><tr><td></td><td>Technology Company, Limited</td><td>GWh</td><td>Gigawatt Hours</td></tr><tr><td>CCE</td><td>Consequence-driven Cyber</td><td>HBOM</td><td>Hardware Bill of Materials</td></tr><tr><td></td><td>Informed Engineering</td><td>HMI</td><td>Human-Machine Interface</td></tr><tr><td>CIE</td><td>Cyber-Informed Engineering</td><td>IBR</td><td>Inverter-Based Resource</td></tr><tr><td>CIP</td><td>Critical Infrastructure</td><td>IIJA</td><td>Infrastructure Investment</td></tr><tr><td></td><td>Protection</td><td></td><td>and Jobs Act</td></tr><tr><td>CMC</td><td>Chinese Military Company</td><td>INL</td><td>Idaho National Laboratory</td></tr><tr><td>CyTRICS</td><td>Cyber Testing for Resilient</td><td>IPP</td><td>Independent Power</td></tr><tr><td></td><td>Industrial Control Systems</td><td></td><td>Producer</td></tr><tr><td>DC</td><td>Direct Current</td><td>IRS</td><td>Internal Revenue Service</td></tr><tr><td>DER</td><td>Distributed Energy</td><td>ISO</td><td>Independent System</td></tr><tr><td></td><td>Resources</td><td></td><td>Operator</td></tr><tr><td>DERMS</td><td>Distributed Energy Resource</td><td>IT</td><td>Information Technology</td></tr><tr><td></td><td>Management System</td><td>LLC</td><td>Limited Liability Company</td></tr><tr><td>DOD</td><td>Department of Defense</td><td>LOTO</td><td>Lockout/Tagout</td></tr><tr><td>MW</td><td>Megawatt</td><td>PPA</td><td>Power Purchase Agreement</td></tr><tr><td>MWh</td><td>Megawatt Hour</td><td>PRC</td><td>People's Republic of China</td></tr><tr><td rowspan="2">NDAA</td><td>National Defense</td><td>PV</td><td>Photovoltaic</td></tr><tr><td>Authorization Act</td><td>SBOM</td><td>Software Bill of Materials</td></tr><tr><td rowspan="2">NERC</td><td>North American Electric Reliability Corporation</td><td>SCADA</td><td>Supervisory Control and</td></tr><tr><td>Non-Generator Resource</td><td></td><td>Data Acquisition</td></tr><tr><td>NGR NREL</td><td>National Renewable Energy</td><td>SEC</td><td>Securities and Exchange Commission</td></tr><tr><td></td><td>Lab</td><td>SIS</td><td>Safety Instrumented System</td></tr><tr><td>O&amp;M</td><td>Operation and Maintenance</td><td>SOC</td><td></td></tr><tr><td>OEM</td><td>Original Equipment</td><td>SOH</td><td>State of Charge</td></tr><tr><td></td><td>Manufacturer</td><td>VPP</td><td>State of Health</td></tr><tr><td>OT</td><td>Operational Technology</td><td></td><td>Virtual Power Plant</td></tr><tr><td>PCS</td><td>Power Conversion System</td><td>WECC</td><td>Western Electricity Coordinating Council</td></tr></table>

Introduction

The Bipartisan Infrastructure Law and other federal programs1 are driving the essential modernization and digitization of U.S. energy infrastructure. Still, the United States faces a key challenge in this grid transformation: our renewable and clean energy supply chains have limited capacity to source necessary digital assets through U.S. or allied sources.²

Batteries and their associated power electronic interfaces are key components to delivering clean and more resilient energy delivery, providing much-needed fast ramping, emergency discharge, generation, and operations support to the electric grid. These services have grown to be invaluable over the past 10 years and will soon be an irreplaceable component of energy delivery.

While there have been significant strides to move supply chains for raw and critical materials to the United States and allied nations,³ the control and power electronic industry has lagged, in part because of lower cost margins. For example, the United States now has a growing capacity to manufacture solar photovoltaic (PV) panels, but 90% of the inverters— which are essential to the conversion of direct current (DC) to alternating current (AC) for grid connection and controls—are made in or source parts from the People's Republic of China (PRC).4 A large number of the product integrators who leverage batteries, inverters, and associated devices are U.S-based- companies, employing American people in wellpaying jobs and creating hundreds of thousands of jobs in the past five years.5 Yet the sourcing of control equipment from Chinese-based entities has an inherent geopolitical concern.6

The United States can strategically address battery supply chain risks by pairing short-term steps to operate securely through today's risks with long-term steps to shape the supply chain over the coming years. Federal investments in semiconductors through the CHiPS Act7 and other manufacturing programs⁸ will result in U.S. supply chains for batteries and power electronics that will begin to mature over the next 5 to 10 years. In the meantime, U.S. asset owners must also leverage available battery and electronics equipment to meet their goals and maintain cost. The demand signal for these components must be maintained to continue domestic industry growth at a sufficient pace to realize the economic benefit of these federal supply chain investments.

Addressing the current push and pull between our accelerating energy transition and the cybersecurity of our future energy infrastructure will require a suite of policy, technical, and organizational approaches. Determining the optimal decisions requires an end-to-end assessment of the supply chain to identify and prioritize risks. This report details that assessment, including key findings on the state of risk and recommendations informed by quantifiable cyber-informed engineering and data-driven solutions.

Methodology

Our approach is a systemic analysis that evolves from a macro to a micro perspective, focusing on the tasks the systems are expected to perform and the penetration levels and use cases in the evolving energy-delivery system. Figure 1 represents the paper's analytical framework, illustrating the interdependencies between national security implications on the supply chain and subsequent policy and technological decisions, as well as the flow of consequences from grid and utility-scale to individual system and component levels. The analysis presented evaluates the national security implications of policy and technical and supply chain decisions through a series of consequence-driven components and a system of systems functionality study. Categorizing these risks on multiple levels enables a framework of decisions to be made, which optimize both technical and economic supply chain investment decisions for U.S. manufacturing and the prioritization of mitigations using Cyber-Informed Engineering9 and alternative types of tooling in development at the Department of Energy and other industry capabilities. The study can then be used to identify gaps in tooling and resources for future research and development as the policy changes to the supply chain take shape.

Figure 1. Strategic framework for supply-chain risk assessment and mitigation

This report offers a strategic plan for evaluating battery system components from end to end, employing methodologies and subject matter expertise to measure the magnitude of current challenges and benefits of a new evaluative approach—a system of systems approach. This requires not only a comprehensive assessment but also a strategic allocation of resources to bolster both the supply chain and the operational security of battery energy storage systems (BESS) and their associated systems.

Use Cases, Penetration, and Functions of Grid Scale BESS

Battery systems fulfill a variety of important roles in the electric grid contingent upon the unique market demands and specific challenges of regional grid infrastructures. These roles also vary due to the differing business models for ownership and operation and they are often adapted to regional capabilities and requirements.

The Storage Futures Study conducted by the National Renewable Energy Laboratory (NREL)1o forecasts significant growth in national storage capacity over the coming decades. In the reference case, it is projected to increase from approximately 25 gigawatts (GW) in 2020 to around 200 GW by 2050. Within this capacity, battery storage is anticipated to constitute approximately 175 GW, with the remaining amount supplied by pumped hydropower. The surge in demand for lithium-ion batteries is chiefly attributed to electric vehicles (EVs), although stationary storage is also expected to increase substantially, reaching approximately 1,000 gigawatt hours (GWh) by 2030. Projections for utility-scale BESS indicate a decline in energy prices by 2-3 times their 2020 levels by the year 2050. Figure 2 shows the potential for BESS installed and planned capacity in the United States.11

Figure 2. 2023 U.S. energy storage installations by region (2.0 GW)9.

The market has accelerated with a 10-fold increase in energy capacity (in megawatt hours) installed from 2018 to 2020.12 The U.S. Energy Information Administration (EIA)13 reports that the United States will install approximately 4 GW of new storage in 2023 (Figure 3), with 35% installed in California and 27% in Texas (Figure 4). The ElA also reported that as of January 2024 (Figure 4), installed storage capacity is predicted to double between 2024 and 2025 (Figure 5).

US annual battery storage capacity changes

Figure 3. U.S. energy storage installations by market share 11.

Figure 4. U.S. West has 95% of U.S. battery storage capacity additions in Q2 2023 12. <table><tr><td colspan="4">Top regional changes (% of total additions)</td></tr><tr><td colspan="2">Q2-23 additions</td><td colspan="2">Q3-23 planned additions</td></tr><tr><td>CAISO</td><td>WECC</td><td>CAISO</td><td>WECC</td></tr><tr><td>58.1%</td><td>36.7%</td><td>59.3%</td><td>24.2%</td></tr></table>

<table><tr><td>CAISO</td><td>Q2-23</td><td>(MW) Q2-22</td><td>Q2-21</td><td>Q2-23</td><td>- (MWh) Q2-22</td><td>Q2-21</td></tr><tr><td>ERCOT</td><td>6.314 3,287</td><td>3,636 2,322</td><td>1.921 784</td><td>24,552 4,243</td><td>13,927 3,079</td><td>7,289 995</td></tr><tr><td>FRCC</td><td>537</td><td>506</td><td>26</td><td>1.211</td><td>1,160</td><td>100</td></tr><tr><td>ISONE</td><td>364</td><td>292</td><td>173</td><td>849</td><td>676</td><td>378</td></tr><tr><td>MISO</td><td>91</td><td>79</td><td>68</td><td>150</td><td>126</td><td>94</td></tr><tr><td>NYISO</td><td>213</td><td>168</td><td>83</td><td>577</td><td>493</td><td>256</td></tr><tr><td>PJM</td><td>430</td><td>365</td><td>336</td><td>405</td><td>269</td><td>240</td></tr><tr><td>SERC</td><td>163</td><td>115</td><td>24</td><td>340</td><td>224</td><td>42</td></tr><tr><td>SPP</td><td>35</td><td>35</td><td>28</td><td>72</td><td>72</td><td>58</td></tr><tr><td>WECC (ex-CAISO)</td><td>1,255</td><td>404</td><td>192</td><td>4,504</td><td>1,316</td><td>480</td></tr><tr><td>Total</td><td>12,689</td><td>7,923</td><td>3,634</td><td>36,903</td><td>21,342</td><td>9,933</td></tr></table>

Figure 5. Annual U.S. cumulative installed battery capacity (as of November 2023)

Data source: U.S. Energy Information Administration, Preliminary Monthly Electric Generator Inventory, based on Form ElA-860M

Interconnection Timelines

Interconnection to the electric grid for energy delivery products—especially inverter-based resources such as BESS—requires a detailed set of power flow, environmental, operational, and dynamic studies to ensure they can operate reliably and beneficially.

The process tests system and operational scenarios, such as different load conditions and emergency scenarios in a power flow model of the electric site to which it is connecting. While crucial, this interconnection process presents a set of challenges to getting new projects online:

The recommendations of the interconnection studies often require cost estimates to interconnect grid upgrades or mitigations such as a max output requirement to a particular line;14 these are often performed by consultants and the utilities themselves.

During the interconnection process, equipment selection is often performed to ensure the right models are selected, which requires that inverter functions and battery operational requirements be known.

Additionally, interconnection queues form for sites waiting for these studies so they may begin building. In fact, as illustrated in Figure 5, as of the end of 2023, there is approximately 1030 GW of storage and hybrid storage in the queue—enough to serve all U.S. customers for 1 hour15.

Figure 6. Capacity in interconnection queues as of the end of 2023 14.

As of 2023, an interconnection takes a maximum of 50 months from request to agreement, at which point the requestor can proceed with the full build, which then can take more than 3 years to complete (Figure 6). Therefore, projects coming online in 2024 likely received interconnect agreements in 2021 and joined the interconnection queue between 2017 and 2018. Supply chain variations during this time have had an enormous impact on the bankability of these projects.

To be successful, projects must have a strong supply chain plan, consistent information and funding stability, and technical viability. However, most proposed projects have been withdrawn for a variety of reasons.

Selected Use Cases for BESS

Overall Summary of Functions

Batteries, particularly utility-scale batteries, provide a range of essential services to the power grid in the United States—services that are vital for maintaining the stability, efficiency, and reliability of the grid. To evaluate the risk associated with their growing penetration, including the impact of the supply chain and risk of foreign control, the functions of these systems and the services they provide must be well understood. Key grid services performed by batteries include:

1. Frequency and Voltage Regulation: Batteries help maintain the grid's electric frequency on a millisecond-to-second basis. This is one of their most common uses and is crucial to preventing deviations in frequency that can lead to system instability; batteries are ideal as they can quickly respond to changes without the need for startup time. Because they can quickly absorb surges and release energy, maintaining grid frequency close to its target value, batteries are well suited for frequency regulation. Similarly, they can help maintain a constant voltage on the power system by injecting or absorbing reactive power, which can correct voltage drops at the end of lines or help maintain voltage stability during transient events with droop control. Voltage support also requires a quick response time, which is a feature that batteries provide via their control systems and power electronics in the inverters.

2. Energy Arbitrage: Batteries can store electricity when prices are low and release it back into the grid when prices are high. This process, known as energy arbitrage, helps to balance electricity supply and demand and can lead to economic benefits by capitalizing on variable energy prices. The timeframe for energy arbitrage can vary widely, from a few hours to a full day. Batteries charge during periods of low electricity prices (often during low-demand times) and discharge when prices are higher (typically during peak-demand periods).

3. Ramping or Spinning Reserve: Ramping or spinning reserve involves quickly responding to sudden changes in the grid, such as a rapid change in demand or the sudden loss of generation; batteries used can typically respond within minutes to these sudden changes in grid conditions. This is particularly valuable in regions with a high proportion of renewable energy sources, such as wind and solar, where output can fluctuate based on changing weather conditions.

4. Load Following: Batteries can adjust their output to match changes in electricity demand. This capability is valuable for more efficient load change response, putting less stress on the grid compared to mechanical systems. Batteries performing load following adjust their output to match changes in electricity demand, generally operating on a scale of minutes to hours, responding to more gradual changes in load throughout the day.

5. Peak Shaving and Congestion Relief: By discharging during peak demand periods,16 batteries can reduce the need for higher-cost, seldom-used generation capacity, leading to overall lower wholesale electricity prices and a more balanced demand on the grid. For peak shaving, batteries discharge during periods of peak demand, which can last for several hours, usually in the late afternoon or early evening when electricity demand is highest. For congestion relief, the batteries are discharged to serve a local load and reduce the perceived demand for the transmission system. This occurs at times of high load when significant power has to be transferred from generation sources to load centers, putting stress on the capacity of the transmission system.

6. Storing and Smoothing Renewable Generation: Batteries can store excess electricity generated from renewable sources such as solar and wind and then supply it back to the grid or to local loads as needed. This reduces curtailments and helps in managing the intermittency of renewable sources. The timeframe depends on the variability of the renewable energy source. For solar energy, this could involve storing excess energy during midday and releasing it in the evening, while for wind energy, it could involve longer or more variable periods, depending on wind patterns.

7. Deferring Infrastructure Investment: Batteries can be used strategically to manage growing electricity demand in specific areas, largely by reducing peak loads over time, to help defer or delay the need for costly new grid infrastructure such as upgraded substations or additional distribution lines. This is a longer-term application where batteries might be used intermittently, depending on local demand growth patterns.

8. Reducing End-Use Consumer Demand Charges: For commercial and industrial facilities, onsite energy storage used during peak demand times can lower electricity demand charges, which are based on the highest rates of consumption observed during peak periods. This application typically targets peak demand periods, which can last for a few hours each day, particularly during times when electricity prices are highest.

9. Backup Power: For outages or to support electric reliability, batteries can provide backup power to households, businesses, and parts of the distribution grid. They are also integral to advanced microgrid setups, helping maintain power flow during temporary separations from the main grid. The duration for backup power can vary significantly based on the capacity of the battery system and the energy needs of the connected load, ranging from a few hours to days, especially in advanced microgrid setups.

10.Black Start and Grid Forming: In some cases, when an outage is experienced, immediate detection of the outage can allow local generation sources to quickly pick up the load and support a seamless transition to backup power. However, this is often not the case, and it may even be dangerous to do so at the risk of creating unintentional islands (i.e., powering loads that are not intended to be run on the backup power). After the outage begins, batteries can be used to black start the system, powering first local loads, then increasing output or supporting other generation sources as they come online to bring power back to the entire system. Because batteries cannot support as much inrush current as traditional synchronous generators of the same capacity, the reenergization of loads must be done with care and consideration. Batteries acting as a grid-forming source can enable other resources, such as wind and solar, to come online in a grid-following mode, which is often better suited for variable resources. The primary duty of a grid-forming source is to dynamically adjust its output to ensure that the load and generation are balanced at all times, which can be done using local feedback of voltage and frequency.

These services illustrate the growing importance of battery storage in enhancing the grid's resilience, flexibility, and ability to integrate renewable energy sources. As the deployment of battery storage continues to increase, its role in the U.S. energy grid is likely to expand and evolve, offering new solutions for energy management and grid stability.

Regional Performance - California

In California, BESS play a significant role in helping the state meet its ambitious clean energy goals and provide critical support in emergencies:

By storing excess energy generated from renewable sources during periods of low demand, BESS help optimize the utilization of clean energy resources, thereby reducing reliance on fossil fuels.

Their rapid response and ramping capabilities make BESS invaluable assets during heat emergencies17, in which spikes in energy demand can strain the grid. By providing additional power when needed most, BESSs enhance grid stability and help prevent disruptions in critical services.

Figure 7. Battery-storage capacity and functions in CAISO, from the 2022 Event Report.

As illustrated in Figure 7, the California Independent System Operator (CAISO) has experienced a significant expansion in battery storage capacity and related functions. By

May 2023, the total active battery capacity reached 5,000 megawatts (MW). Figure 8 details how the capacity expansion is distributed across various project types:

• Standalone projects contributed 2,200 MW

• Co-located projects added 2,000 MW

• Storage components of hybrid resources accounted for 700 MW

• Storage components of co-located hybrids contributed 100 MW

At the same time, the total active hybrid capacity, including generation components, reached 2,300 MW. This surge in battery-storage capacity reflects the increasing importance of energy storage in California's grid infrastructure, facilitating grid stability, renewable integration, and overall system reliability.

Figure 8. Total capacity of CAISO-participating battery storage as of May 2023.

During the 2022 heatwave, batteries showcased their flexibility, offering a significant portion of both charging and discharging capacity to the market. Early in the day, average output schedules—including energy discharging, regulation, reserves, and ramp—intentionally decreased to allow the batteries to charge. During peak hours, both charging and discharging schedules increased compared to usual trends, though charging remained low on average. Batteries provided a large share of total regulation, including full coverage for some intervals. On average, scheduled battery output was about 82% of available capacity. In both real-time and day-ahead markets, batteries actively sought to charge during mornings and early afternoons. Discharge bids in the day-ahead market remained constant throughout the day. Interestingly, despite high bids, batteries averaged below the peakdemand nodal price. Notably, real-time discharge bids even decreased during peak hours. CAISO operators leveraged exceptional dispatches (out-of-market manual interventions) for unit commitments and energy dispatches, when deemed necessary, to address reliability

issues or constraints. Battery-storage resources received exceptional dispatches throughout the heatwave, primarily to encourage charging in anticipation of peak demand hours.

With careful planning and investment, BESS can be a valuable asset to the CAISO grid. In CAISO's market, BESS operate under the Non-Generator Resource (NGR) model, allowing them to function both as generation resources when discharging and as load resources when charging. This unique framework enables BESS to participate in the market using a single supply curve that encompasses both charging and discharging prices. This streamlined approach enhances market efficiency and simplifies the dispatch process for BESS operators.

Regional Performance - Hawaii

Commissioned in 2023, a 185 MW BESS has been successfully deployed in Hawaii to replace coal on the island of Oahu, marking a significant milestone in Hawaii's transition to 100% renewable energy.18 This cutting-edge BESS, operated by Hawaiian Electric, is a key component in accelerating the state's renewable energy goals. With a storage capacity of 185 MW and capable of discharging 565 megawatt hours (MWh) of energy, the system enhances grid stability and facilitates the integration of renewable energy sources like solar and wind power. Its advanced capabilities enable efficient energy management, supporting Hawaii's ambitious targets for reducing carbon emissions and reliance on fossil fuels.

Hawaiian Electric's BESS is equipped with state-of-the-art technology, including advanced lithium-ion batteries and sophisticated control systems, ensuring optimal performance and reliability. The system's deployment underscores Hawaii's commitment to sustainable energy solutions and resilience against climate change impacts.

Regional Performance - Texas

The recent solar eclipse in Texas sheds light on the crucial role of battery storage in maintaining energy supply reliability during periods of intermittent renewable generation. As solar output dropped significantly during the eclipse, the grid faced challenges in balancing supply and demand (see Figure 9). However, battery storage systems helped bridge the gap by providing stored energy when solar generation was unavailable, demonstrating their importance in enhancing grid resilience and ensuring uninterrupted energy supply, especially in regions heavily reliant on renewable energy sources.

The eclipse event, coupled with another 17+ emergency dispatch events for BESS in 2022– 2024,19 illustrates the need for further investment and expansion of battery storage infrastructure to mitigate the impacts of renewable energy intermittency on grid stability and enhance overall system reliability.2º It also underscores the importance of adopting innovative energy storage solutions to support the transition towards a more sustainable and resilient energy system capable of meeting the evolving demands²1.

Figure 9. Texas emergency discharge in February 2024, showing a close to 1 GW ramp in storage.

Previous Day | Current Day

Known Operational Issues and Events

Moss Landing

While the 2022 fire incident involving a Tesla grid battery at Moss Landing in California raised concerns about the safety of grid-scale battery systems, it also served as a learning opportunity for stakeholders to address the industry's growing pains.22 The incident demonstrated the importance of stringent safety protocols and regulatory oversight in ensuring the reliability and security of energy storage deployments. Despite the setback, the incident also showcased the resilience of Tesla's battery technology, as the affected unit continued to function even after sustaining significant damage, preventing a potentially more severe outcome.

The Tesla grid battery fire brings attention to the need for continued innovation and improvement in energy storage technology and safety standards. As the industry matures, stakeholders must collaborate to develop robust safety measures and emergency response protocols to mitigate risks and ensure the long-term viability of energy storage deployments.

Western Electricity Coordinating Council (WECC) Heat Event

Several incidents—including BESS trips, reduced capacity, and thermal issues—occurred due to the extreme heat experienced by BESS in the Western Interconnection region (see Figure 10). As temperatures soared, BESS units struggled to manage thermal loads, resulting in degraded performance and, in some cases, complete shutdowns²3. The root cause of these failures was primarily attributed to the inability of BESS to effectively dissipate heat under extreme temperature conditions, together with poor commissioning, miscoded inverters, and bad data.

One of the key contributing factors to the heat-related failures was the design limitations of BESS cooling systems. Many BESS installations were not adequately equipped to handle the intense heat levels experienced during the event, leading to thermal stress on critical components. Additionally, operational practices such as reduced charge and discharge rates were implemented to mitigate thermal issues, further impacting BESS performance and grid reliability. The software was updated in both the CAISO 2022 and WECC 2023 events and tested to prevent a similar issue from occurring

Figure 10. Western area outage of BESS caused by a misconfiguration and performance issue.

Failure Data Analyses and Root Cause for BESS

While there is discussion of BESS with regards to fires and other events²4, tracked data indicates a reduction in fires, particularly those attributed to thermal runaway in the battery cell material. Overall catastrophic failures are lessening, now mostly driven by controls and power conversion systems (PCS). Material quality has improved; even with the majority of the material being produced in China. This runs counter to many assumptions of offshoring risk. The majority of fires are attributed to the controls and faults in the battery management system (BMS) and battery optimization system, along with the PCS (Figure 11 and Figure 12).

Figure 11. Global grid-scale BESS deployment and failure statistics.

Figure 12. Global grid-scale BESS failure rates from 2018-2023.

Courtesy EPRI and Wood Mackenzie.

Technical BESS Architecture, Components, and Functions

Different architectures for BESS can have various configurations and components, ranging from fundamental cell-level setups to comprehensive systems encompassing controls and additional functionalities. Batteries are but one component, with configuration dependent on features including size and utilization, as illustrated in Figure 13.

Figure 13. BESS system architecture.

Cell level: At the most basic level, BESS architecture revolves around individual battery cells. These cells form the foundational building blocks of the energy storage system. They are typically connected in series and parallel configurations to achieve the desired voltage and capacity requirements.

O This architecture focuses primarily on the electrochemical performance and characteristics of the battery cells themselves, including factors such as energy density, cycle life, and safety features.

Integrated controls and components: A more comprehensive approach involves integrating various controls and additional components into the BESS. This includes incorporating BMS to monitor and manage the performance, state of charge, and health of the battery pack. Additionally, safety mechanisms (e.g., thermal management systems and protective enclosures) are implemented to ensure safe operation under diverse conditions.

oIntegration with power conversion systems, inverters, and grid interfaces enables bidirectional power flow and seamless integration with renewable energy sources or electrical grids.

Integrated hardware and software: In more advanced BESS architectures, there is a focus on integrating the hardware components with sophisticated software solutions. This involves the deployment of intelligent control algorithms, predictive analytics, and optimization strategies to maximize the performance and efficiency of the energy storage system. Integrators play a crucial role in designing and implementing these

software-driven functionalities, tailoring them to specific use cases and operational requirements (Figure 14).

Figure 14. Integrated strategy for component supply for an integrator. <table><tr><td rowspan=1 colspan=4>Packs/System</td><td rowspan=2 colspan=8>Packs/System</td></tr><tr><td rowspan=1 colspan=2>Pack</td><td></td><td></td></tr><tr><td rowspan=1 colspan=2>Module</td><td rowspan=1 colspan=3>Module</td><td rowspan=2 colspan=1>SIS +ChargeControl</td><td rowspan=1 colspan=1>BMS</td><td rowspan=1 colspan=1>PCS</td><td rowspan=1 colspan=1>Inverter</td><td rowspan=1 colspan=1>Transformer</td><td rowspan=1 colspan=1>Protection</td><td rowspan=1 colspan=1>Grid</td></tr><tr><td rowspan=1 colspan=1>cell</td><td rowspan=1 colspan=1>cell</td><td rowspan=1 colspan=1>cell</td><td rowspan=1 colspan=2>Cell</td><td rowspan=1 colspan=3>Comms + Cloud</td><td rowspan=2 colspan=1>FleetController</td><td rowspan=1 colspan=2></td></tr><tr><td rowspan=3 colspan=9></td><td></td><td></td></tr><tr><td rowspan=2 colspan=1>DERMS</td><td></td><td></td></tr><tr><td rowspan=1 colspan=2>DSO or DO or TSO</td></tr></table>

Component Functions

Battery Management Systems and Environmental Control

The BMS is both a hardware and software component, which connects to the energy management system EMS and PCS to manage the system's charge and discharge and provide environmental monitoring of the battery cells. Common architectures and functions within the BMS play an important role in ensuring operational safety, efficiency, and reliability. These functions include signaling mechanisms, fire alarms, emergency stop functionalities, insulation breakdown detection, temperature monitoring, and management of over and under current. Each function safeguards against potential failures25 that could lead to adverse outcomes. For example:

• Failure in signaling mechanisms could result in delayed responses to operational issues.

•A malfunctioning fire alarm system could lead to delayed detection of fire hazards, potentially causing extensive damage or endangering lives.

• Failure in emergency stop functionalities could impede the ability to quickly halt operations in hazardous situations, increasing the risk of accidents.

Insulation breakdown detection failures might lead to electrical faults or short circuits, posing fire risks or damaging equipment.

•Malfunctions in temperature monitoring and management systems could result in overheating, reducing the lifespan of components, or even causing thermal runaway events.

Inadequate protection against overcharging could lead to battery degradation, reducing performance and longevity.

• Voltage imbalances, if left unaddressed, can cause uneven distribution of energy within the system, potentially leading to inefficiencies, reduced performance, or even damage to sensitive components.

When well-managed, advanced BMS can help optimize performance, improve lifetimes, and prevent runaway failures or catastrophes.

Inverters

The inverter is responsible for converting DC electricity from the battery into AC electricity, enabling integration with the electrical grid or other AC loads. It connects to both the battery system and the electrical grid or loads, forming a bidirectional link for energy flow. In BESS architecture, the inverter is typically positioned between the battery storage unit and the grid or loads, serving as an intermediary for power conversion and control. The inverter uses various measurements—including voltage, current, frequency, and temperature—to ensure efficient and stable operation. It is often combined with the power conversion system. Actions performed by the inverter include:

Performing frequency droop control and voltage droop control to regulate grid frequency and voltage levels, respectively

• Establishing voltage and frequency references

•Implementing virtual generator inertia to mimic the behavior of traditional generators

• Managing real power vs. reactive power output

• Supporting the utility grid during voltage or frequency disturbances through utility support mode

• Facilitating black start capabilities to restore power in the event of a grid outage

Inverters can be supplied as three-phase, single-phase, or micro. Many companies that sell inverter hardware also sell BMS and other devices as an interlinked system. In large BESS, three-phase inverters are the most common, but solar may also include microinverters if combined in hybrid configurations. Home storage units are usually single-phase or micro.

PCS

Power conversion systems are essentially the larger parent of the inverters, comprised of conversion and power conditioning equipment and potentially small transformers; they are often larger-scale systems that encompass multiple inverters, together with additional control and protection components. PCS refers to the combined system used to convert and manage the quality of power from one form to another within an electrical power grid. Functions and attributes of the PCS include the following:

Controls the power flow, integration, and synchronization among various power sources and loads, generally for large sites rather than distributed energy resources DER. This coordination enables efficient and reliable operation of diverse sources, as well as loading.

•Has significant processing power to allow advanced control algorithms to optimize power management.

•Monitors grid conditions, regulates voltage and frequency, and facilitates smooth transitions between power sources or operational modes.

Includes vital safety features such as fault detection, isolation, and protection mechanisms.

• Accounts for the wider perspective of system-level integration, control, and monitoring.

Power Electronic Transformers and Inverters

Many inverters also include a small transformer, often a solid-state transformer in more modern systems, to enable consistent power supply and connection to the electric grid. These transformers are embedded in the inverters themselves and separate from the onsite grid transformer.

Sensors and Monitoring

The BESS and its BMS rely on critical measurements such as state of charge (SOC), battery temperature, voltage and current levels, power output and input, and grid frequency and voltage. These measurements enable the system to perform actions such as controlling charging and discharging processes, managing thermal conditions, detecting and isolating faults, regulating grid frequency and voltage, and balancing loads and shaving peaks to ensure optimal performance and safety (Table 1. BESS measurements and performed actions.).

Table 1. BESS measurements and performed actions. <table><tr><td rowspan=1 colspan=1>Measurements</td><td rowspan=1 colspan=1>Actions Performed</td></tr><tr><td rowspan=1 colspan=1>State of charge</td><td rowspan=1 colspan=1>Charge and discharge control</td></tr><tr><td rowspan=1 colspan=1>Battery temperature</td><td rowspan=1 colspan=1>Thermal management (cooling/heating)</td></tr><tr><td rowspan=1 colspan=1>Voltage and current levels</td><td rowspan=1 colspan=1>Fault detection and isolation, charge and protection</td></tr><tr><td rowspan=1 colspan=1>Power output and input</td><td rowspan=1 colspan=1>Grid frequency and voltage regulation</td></tr><tr><td rowspan=1 colspan=1>Grid frequency and voltage</td><td rowspan=1 colspan=1>Load balancing and peak shaving</td></tr></table>

There is also significant sensoring required for safety, environment and physical security, as summarized in Table 2. Barriers and associated hazard types.. Most of these share data with the BMS or Environment Manager. Some perform manual actions with no cyber components, while others are connected with larger required fire protections.

Table 2. Barriers and associated hazard types. <table><tr><td rowspan=1 colspan=1>Barriers</td><td rowspan=1 colspan=1>Hazard Type</td><td rowspan=1 colspan=1>Function</td><td rowspan=1 colspan=1>Connected to</td></tr><tr><td rowspan=1 colspan=1>BMSmonitoring</td><td rowspan=1 colspan=1>Electrical,thermal</td><td rowspan=1 colspan=1>Current, voltage, SOC, andtemperature monitoring</td><td rowspan=1 colspan=1>BMS to EMS</td></tr><tr><td rowspan=1 colspan=1>Coolingsystem</td><td rowspan=1 colspan=1>Thermal</td><td rowspan=1 colspan=1>Temperature regulation of BESS</td><td rowspan=1 colspan=1>Fire and Environmental Safety - EMS</td></tr><tr><td rowspan=1 colspan=1>Thermalinsulation</td><td rowspan=1 colspan=1>Thermal</td><td rowspan=1 colspan=1>Minimize heat transfer betweenbattery modules/racks</td><td rowspan=1 colspan=1>BMS</td></tr><tr><td rowspan=1 colspan=1>Fire andsmokedetector</td><td rowspan=1 colspan=1>Fire</td><td rowspan=1 colspan=1>Detect smoke and produce visualand audible alerts at the controlcenter</td><td rowspan=1 colspan=1>Fire Safety and Control Center</td></tr><tr><td rowspan=1 colspan=1>Active firesuppression</td><td rowspan=1 colspan=1>Fire</td><td rowspan=1 colspan=1>Fire suppression, extinguishment,and cooling</td><td rowspan=1 colspan=1>Manual action detects manualconditions</td></tr><tr><td rowspan=1 colspan=1>Gasdetection</td><td rowspan=1 colspan=1>Explosion</td><td rowspan=1 colspan=1>Early detection for accumulation offlammable gases before reachingexplosive</td><td rowspan=1 colspan=1>Fire and environmental safety - EMS</td></tr><tr><td rowspan=1 colspan=1>Emergencyventilation</td><td rowspan=1 colspan=1>Explosion</td><td rowspan=1 colspan=1>Removal of gas before reachingexplosive concentration</td><td rowspan=1 colspan=1>Fire and environmental safety - EMS</td></tr><tr><td rowspan=1 colspan=1>Emergencyshutdown</td><td rowspan=1 colspan=1>Electrical/fire</td><td rowspan=1 colspan=1>Electrical isolation</td><td rowspan=1 colspan=1>Manual and Automated</td></tr><tr><td rowspan=1 colspan=1>Circuitbreaker</td><td rowspan=1 colspan=1>Electrical</td><td rowspan=1 colspan=1>Electrical isolation</td><td rowspan=1 colspan=1>Manual and Automated</td></tr><tr><td rowspan=1 colspan=1>Intrusiondetection</td><td rowspan=1 colspan=1>Physical</td><td rowspan=1 colspan=1>Detect unauthorized physical accessand open doors of BESS</td><td rowspan=1 colspan=1>Emergency response and controlcenter</td></tr></table>

Grid Transformers

BESS connected via grid scale transformers are key components in energy storage systems that help manage the flow of electricity between the battery system and the grid. Below is a breakdown of the main components typically found in BESS site transformers (illustrated in Figure 15. Transformer components.):

1. Transformer Core: The BESS transformer core is typically made of high-permeability materials such as iron or steel; it provides a low reluctance path for the magnetic flux generated by the transformer, facilitating efficient energy transfer.

2. Windings: Windings are conductive wires wound around the transformer core. In BESS transformers, there are typically two sets of windings: primary and secondary.

The primary windings are connected to the battery system, and the secondary windings are connected to the grid.

3. Tap Changer: A tap changer is a mechanism used to adjust the transformer's voltage ratio. In BESS transformers, tap changers may be used to accommodate variations in grid voltage or to optimize the performance of the battery system. They are more common in larger sites and substations than in BESS.

4. Cooling System: Since BESS transformers may experience varying loads and operating conditions, a cooling system is essential to dissipate heat generated during operation. Cooling may be achieved through natural convection, forced air, or liquid cooling.

5. Protection Devices: Protection devices are installed to ensure the safety and reliability of the transformer as well as the overall BESS system. These may include overcurrent protection, overvoltage protection, temperature sensors, and insulation monitoring systems.

6. Monitoring and Control Systems: Monitoring and control systems are integrated into BESS transformers to enable remote monitoring, data logging, and control of transformer parameters. These systems allow operators to optimize the performance of the transformer and respond quickly to changes in operating conditions.

7. Enclosure: Transformers are often housed in enclosures designed to protect them from environmental factors such as moisture, dust, and temperature extremes. The enclosure also provides mechanical protection for the transformer and its components.

Figure 15. Transformer components.

Site Control and EMS

Architecture designs for Site Control may vary depending on the specific design and requirements of the BESS. Common architectures include centralized control, distributed control, and hierarchical control, with each offering different levels of flexibility, scalability, and redundancy:

Centralized control involves a single controller managing all aspects of the BESS operation.

•Distributed control distributes control functions across multiple controllers for improved fault tolerance and responsiveness.

Hierarchical control combines elements of both centralized and distributed control, allowing for centralized coordination of high-level functions while delegating lowerlevel control tasks to distributed controllers.

In a BESS, Site Control or the EMS serves as the central hub for managing and coordinating the operation of various components within the system. It establishes a parent-child relationship with other control elements, acting as the master controller. Site Control connects to both the battery storage units and the grid, facilitating bidirectional communication and control.

Measurements used by site control typically include:

• Voltage: Monitoring grid voltage levels to ensure stability and compatibility with the BESS operation

• Frequency: Tracking grid frequency for frequency regulation and synchronization purposes

State of Charge: Monitoring the level of charge in the battery storage units to optimize usage and prevent overcharging or discharging

• Environmental monitoring

• Physical and safety monitoring

Communications and Cloud

External to the BESS, a cloud connection to DERMS or fleet control is often used. The growth and maturation of cloud computing have facilitated a transformative shift across various industries, with the energy sector at the forefront. Many, if not all BESS sites, aggregations, and OEMs use cloud and remote communications to monitor and manage their fleets. These cloud connections can vary from data storage to fully implemented DER management systems and mass orchestration. Figure 16. BESS communication interconnections. below illustrates the communication pathways and points of coupling for a BESS, while Figure 17 outlines the OT and IT interconnections.

Figure 16. BESS communication interconnections.

Figure 17. Purdue diagram summary for BESS.

DERMS, Software, and Fleet Controllers

While Site Control acts as the centralized management system for the BESS, it connects to DERMS and fleet controllers to manage and optimize the performance of the BESS, ensuring efficient energy storage and distribution. Within a fleet or network of BESS units, DERMS and other distributed control and mass orchestration platforms serve as central management systems that enable the coordination and optimization of multiple energy resources, providing crucial capabilities such as real-time monitoring, control, and coordination of energy storage assets to maintain grid stability, manage peak demand, and integrate renewable energy resources effectively. In the hierarchical structure, Site Control is the parent system, located at the top tier of the BESS architecture, overseeing multiple child subsystems, including individual battery modules and inverters; it coordinates operations and communications across all subordinate components. A fleet usually has one owner or operator, whereas mass control could confer across different boundaries of ownership in regions where that function is aggregated.

Beyond their functional roles in coordinating with the BESS, DERMS and mass control also contribute to grid stability, system reliability, and safety, enabling utilities and aggregators to visualize and control widely dispersed resources. Therefore, the accessibility and reliability of DERMS and mass control are paramount for ensuring the overall performance and safety of BESS deployments, particularly in large-scale operations within independent system operators (ISOs) with high resource penetration. Any disruption or failure in these components could have cascading effects on system operation, potentially compromising grid stability, energy supply reliability, and overall safety. Therefore, robust access and security controls between DERMS and fleet control functionalities, either through on-site management systems or cloud-based platforms, are essential for optimizing BESS performance and mitigating risks associated with misoperation or failure scenarios.

Human-Machine Interface (HMI)

The HMI is the interface between the operator and the BESS, connecting to the supervisory control and data acquisition (SCADA) system for monitoring and control. Facilitating local manual operations, such as resets and emergency stops, helps ensure compliance with safety protocols and offers direct interaction with the system components.

As shown in Table 3, the HMI serves as a child component under the SCADA system (parent) and interacts with various local subsystems (child), facilitating real-time data exchange and control within the BESS.

Table 3. HMI functionalities and connections in BESS. <table><tr><td>Connections and Functions</td><td>Description</td></tr><tr><td>SCADA to local via HMI</td><td>Enables SCADA system to communicate and control local subsystems through the HMI</td></tr><tr><td colspan="1" rowspan="1">SCADA to local/manual disable –lockout/tagout (LOTO) compliance</td><td colspan="1" rowspan="1">Ensures LOTO compliance by allowing manual disable functionsvia SCADA</td></tr><tr><td colspan="1" rowspan="1">HMI manual reset</td><td colspan="1" rowspan="1">Provides the capability to manually reset system components</td></tr><tr><td colspan="1" rowspan="1">HMI local only</td><td colspan="1" rowspan="1">Restricts operations to local control, ensuring security andoperational integrity</td></tr><tr><td colspan="1" rowspan="1">HMI local emergency stop</td><td colspan="1" rowspan="1">Facilitates immediate shutdown of the system in emergencies</td></tr><tr><td colspan="1" rowspan="1">Fire alarm</td><td colspan="1" rowspan="1">Integrates with the fire alarm system for safety and emergencyresponse</td></tr></table>

Supply Chain for BESS Components

A key supply chain risk was highlighted recently with the removal of the Contemporary Amperex Technology Co (CATL) battery from Camp Lejeune.26 The battery system, owned and operated by Duke Energy and located on Camp Lejeune, was disconnected in December 2023 after being commissioned in April 2023.27 CATL is publicly acknowledged as one of the top suppliers of cells and other integrated equipment or built systems in the United States. The company asserts itself to be the world's largest battery manufacturer.28While CATL's origin as a PRC-based manufacturer of cells and an integrator is now a focus of discussion, it is not an isolated case. The BESS market is largely dominated by PRC-based companies and components. Reviewing this supply chain is challenging and intricate – but overall, the dominance of PRC manufacture and supply is significant. Breaking it down into key components and leading companies forms a more complete picture for deriving solutions.

Reviewing common supply chain sources and ranking for energy delivery, the Bloomberg New Energy Finance (BNEF) Tier 1 Storage list29 for the second quarter of fiscal year 2024 (FY24 Q2), shown in Table 4 below, documents the top manufacturers and integrators globally of energy storage products. The Tier 1 list is identified from the BNEF Energy Storage Assets database, which included 9,000 energy storage projects worldwide as of June 2023 that are above 1 MW or 1 MWh in size and for which a supplier has provided battery storage systems in the last two years. The criterion to be listed as Tier 1 is that the vendor must have supplied or be firmly contracted to supply products to six different eligible projects within two years.

Table 4. Energy storage manufacturers meeting Bloomberg's NEF Tier 1 criteria as of Q2 FY 2024. <table><tr><td rowspan=1 colspan=1>Firm/Brand</td><td rowspan=1 colspan=1>Headquarters</td><td rowspan=1 colspan=1>Firm/Brand</td><td rowspan=1 colspan=1>Headquarters</td></tr><tr><td rowspan=1 colspan=1>Xuji Electric</td><td rowspan=1 colspan=1>China</td><td rowspan=1 colspan=1>JD Energy</td><td rowspan=1 colspan=1>China</td></tr><tr><td rowspan=1 colspan=1>Wartsila</td><td rowspan=1 colspan=1>Finland</td><td rowspan=1 colspan=1>Invinity</td><td rowspan=1 colspan=1>UK</td></tr><tr><td rowspan=1 colspan=1>Trina Storage</td><td rowspan=1 colspan=1>China</td><td rowspan=1 colspan=1>Hyperstrong</td><td rowspan=1 colspan=1>China</td></tr><tr><td rowspan=1 colspan=1>Tesla</td><td rowspan=1 colspan=1>United States</td><td rowspan=1 colspan=1>Hyosung Heavy Industries</td><td rowspan=1 colspan=1>South Korea</td></tr><tr><td rowspan=1 colspan=1>Sungrow</td><td rowspan=1 colspan=1>China</td><td rowspan=1 colspan=1>Huawei</td><td rowspan=1 colspan=1>China</td></tr><tr><td rowspan=1 colspan=1>Sermatec</td><td rowspan=1 colspan=1>China</td><td rowspan=1 colspan=1>Hithium</td><td rowspan=1 colspan=1>China</td></tr><tr><td rowspan=1 colspan=1>Samsung SDI</td><td rowspan=1 colspan=1>South Korea</td><td rowspan=1 colspan=1>Gotion High Tech</td><td rowspan=1 colspan=1>China</td></tr><tr><td rowspan=1 colspan=1>Saft</td><td rowspan=1 colspan=1>France</td><td rowspan=1 colspan=1>Fluence</td><td rowspan=1 colspan=1>United States</td></tr><tr><td rowspan=1 colspan=1>Robestec/ShanghaiRonghe</td><td rowspan=1 colspan=1>China</td><td rowspan=1 colspan=1>FlexGen Power Systems</td><td rowspan=1 colspan=1>United States</td></tr><tr><td rowspan=1 colspan=1>REPT BATTERO</td><td rowspan=1 colspan=1>China</td><td rowspan=1 colspan=1>Eve Energy</td><td rowspan=1 colspan=1>China</td></tr><tr><td rowspan=1 colspan=1>RelyEZ</td><td rowspan=1 colspan=1>China</td><td rowspan=1 colspan=1>Envision Energy/AESC</td><td rowspan=1 colspan=1>China/Japan</td></tr><tr><td rowspan=1 colspan=1>Powin Energy</td><td rowspan=1 colspan=1>United States</td><td rowspan=1 colspan=1>Cubenergy</td><td rowspan=1 colspan=1>China</td></tr><tr><td rowspan=1 colspan=1>Pinggao Group</td><td rowspan=1 colspan=1>China</td><td rowspan=1 colspan=1>CRRC Zhuzhou</td><td rowspan=1 colspan=1>China</td></tr><tr><td rowspan=1 colspan=1>NHOA Energy</td><td rowspan=1 colspan=1>Italy</td><td rowspan=1 colspan=1>CLOU Electronics</td><td rowspan=1 colspan=1>China</td></tr><tr><td rowspan=1 colspan=1>Narada</td><td rowspan=1 colspan=1>China</td><td rowspan=1 colspan=1>CATL</td><td rowspan=1 colspan=1>China</td></tr><tr><td rowspan=1 colspan=1>LG Energy Solution</td><td rowspan=1 colspan=1>South Korea</td><td rowspan=1 colspan=1>Canadian Solar e-STORAGE</td><td rowspan=1 colspan=1>Canada</td></tr><tr><td rowspan=1 colspan=1>Kehua</td><td rowspan=1 colspan=1>China</td><td rowspan=1 colspan=1>BYD</td><td rowspan=1 colspan=1>China</td></tr><tr><td rowspan=1 colspan=1>Jinko</td><td rowspan=1 colspan=1>China</td><td rowspan=1 colspan=1>Fluence</td><td rowspan=1 colspan=1>United States</td></tr></table>

\*Blue highlights signify most common in the U.S.

Of this list:

• 65% of the vendors have a Chinese headquarters

• 11% of those listed have a U.S. headquarters

• All the suppliers have a Chinese supplier for either the BMS, PCS, or inverter product The National Defense Authorization Act (NDAA) FY24 Section 15430 lists 6 BESS companies as prohibited from being sourced through DOD funds. They include:

• CATL

• BYD Company, Limited

• Envision Energy, Limited

• EVE Energy Company, Limited

• Gotion High Tech Company, Limited

• Hithium Energy Storage Technology Company Limited

The most common integrators in the U.S. are highlighted in blue, as of 2023 and 2024, combined from multiple media and supply chain reports 31 32. These integrators and their presence vary considerably each year, and some are new to the market or a company evolving from supplying components to fully integrated units 33.

Note that both cell providers and system integrators are considered battery manufacturers or brands eligible for this list. The inclusion of integrators allows for national companies to be listed as the primary brand despite sourcing components from other manufacturers.

Battery Cell/Modules

Illustrated by Figure 18 and Figure 19, the interplay of global trade highlights the current dependence of the United States on international battery suppliers, particularly from China, to the surging demand for lithium-ion batteries amidst the ongoing energy transition.

Figure 18. U.S. lithium-ion battery imports during Q1 2023.

Figure 19. Li-ion battery manufacturing planned (blue) or under construction (red).

Figure 16. Li-ion battery manufacturing planned (blue) or under construction (red) Source: [15] Bloomberg New Energy Finance, "Storage Data Hub, Cell Manufacturers," BloombergNEF, New York, 2020. Available: https://about.bnef.com/

Battery Cell and Integrator Relationships

Batteries suppliers also ship receivers, communications equipment, primary cells, enclosed full units with sensors, inverters, and other power electronics. Modular shipping and manufacturing are common practices. This is further discussed in Section 4 (Supply Chain for BESS Components) above. The supply chain is complex. Considering the complex relationships in integration and battery cell provision, we consider CATL to be the use case. There are at least 10 primary buyers of CATL technology in the US and global integrator market 34 based on export and import records linking their operation³5. The top 10 relationships from a shipping perspective, while indistinguishable from the EV Battery Market, are many of the top BESS product vendors in the US.

Evaluating commonly used battery cell providers, including other major PRC based companies such as Hithium [reference] there are a varied set of cell suppliers for some of the major integrators, and removal of these 6 will leave another set of 70 behind them. Many have limited safety records and low maturity 36. If CATL is removed from this picture, along with others on the NDAA FY24 List, there would be a shift to a set of suppliers that may have lower performance or less mature products and operations. It is unlikely the shift would be to fully onshore manufactured options, as there are none currently. The California Battery Supply List,37 is a list of suppliers eligible for tax credits in California who have passed rigorous safety checks. On this list, over 80 BESS and Battery Cell providers are included in varied configurations. Most companies on the list are PRC-owned and operated and meet the required performance specifications. Given this, integrators would likely not shift to a more costly U.S. manufacturer but to a different PRC-manufactured system.

BMS

The BMS supply chain has become increasingly more complex as many BMS are integrated with battery sensors and even cells. Often, if buying or contracting for cell supply, a BMS will be an integrated choice. The BMS manufacturer for a BESS is commonly not disclosed, and many BMS have the same supplier and hardware as the inverter. It is not usually possible in today's market, with BESS sold as a system of linked components, to replace the BMS with one not offered by the BESS vendor.

There are independent companies in the U.S. market, including Nuvation³8. Fluence and Flexgen have recently announced new U.S. onshore manufacture and software for BMS³9. Penetration of Chinese versus other entities cannot be ascertained with confidence individually, but based on the investigation of most common integrators, it is most likely the same penetration as inverters and other power electronics components. Often in literature, the BMS is discussed in terms of the software manufacturer, but hardware is likely the same vendor as the inverter. The independent providers of BMS are listed in Table 5 as of February 2024. Many of these are part of other parent companies or also sell to EVs, given the tied markets. The majority of independent BMS developers are non-PRC-based companies. Separating the Cell manufacture from BMS is a challenge as they are often integrated. Therefore this list does not necessarily represent penetration in the US Market.

Table 5. Companies and their main products supplied. <table><tr><td rowspan=1 colspan=1>Company</td><td rowspan=1 colspan=1>Location</td><td rowspan=1 colspan=1>Main Products</td></tr><tr><td rowspan=1 colspan=1>Leclanché</td><td rowspan=1 colspan=1>Switzerland</td><td rowspan=1 colspan=1>BMS/Cell/Modules</td></tr><tr><td rowspan=1 colspan=1>MOKOEnergy</td><td rowspan=1 colspan=1>China</td><td rowspan=1 colspan=1>BMS/PV Inverter</td></tr><tr><td rowspan=1 colspan=1>Nuvation</td><td rowspan=1 colspan=1>California</td><td rowspan=1 colspan=1>BMS</td></tr><tr><td rowspan=1 colspan=1>Intel</td><td rowspan=1 colspan=1>United States</td><td rowspan=1 colspan=1>BMS</td></tr><tr><td rowspan=1 colspan=1>Bosch</td><td rowspan=1 colspan=1>Germany</td><td rowspan=1 colspan=1>battery management &amp; thermal management system/e-axel/module</td></tr><tr><td rowspan=1 colspan=1>Denso</td><td rowspan=1 colspan=1>Japan</td><td rowspan=1 colspan=1>battery monitoring integrated IC</td></tr><tr><td rowspan=1 colspan=1>SK Innovation</td><td rowspan=1 colspan=1>South Korea</td><td rowspan=1 colspan=1>BMS/energy system</td></tr><tr><td rowspan=1 colspan=1>BYD</td><td rowspan=1 colspan=1>China</td><td rowspan=1 colspan=1>BMS</td></tr><tr><td rowspan=1 colspan=1>Panasonic</td><td rowspan=1 colspan=1>Japan</td><td rowspan=1 colspan=1>BMS/lithium-ion batteries</td></tr><tr><td rowspan=1 colspan=1>LG Chem</td><td rowspan=1 colspan=1>South Korea</td><td rowspan=1 colspan=1>BMS/energy system</td></tr></table>

PCS

PCS are a highly critical component in the BESS, combining inverters and other conversion systems to operate a consistent system. It is worth noting where PCS are sourced. Analysis of the California inverter40 allow lists indicate that there are 517 PCS models used either with or combined with the allowed inverters. Because manufacturers are eager to be on the allow list for California—which has the largest installed capacity of BESS and plans for continued growth—it can be assumed that even systems installed outside of California have a similar breakdown. As illustrated in , just 4.2% of PCS are from the U.S., while 69.4% are from China. The remaining 26.3% come from a country other than the U.S. or China.

Figure 20. U.S. PCS providers vs. Chinese PCS providers.

Understanding the penetration of foreign-manufactured components offers insight into the full supply chain beyond the primary named supplier.

Inverters

In addition to BESS, inverters are foundational components for clean energy sources such as hybrid systems, solar, and hydrogen fuel cells. Involving microchips, electronic switches, and PLCs, the inverter supply chain is complex. This complexity and the growing digitization associated with these components create supply chain cyber risks. For example, in solar environments—a related market often tied closely to BESS—the manufacturing market for solar panels and inverters is dominated by China.41,42According to the IEA,4³ global solar PV manufacturing capacity has increasingly moved from Europe, Japan, and the United States to China over the last decade.44,45 For panel manufacturing—which includes the development of polysilicon, ingots, wafers, cells, and modules—China's share exceeds 80%. Perhaps more concerning from a cyber security perspective, the top five vendors of solar inverters, based on GW capacity shipped, are all foreign entities of concern (FEOCs), accounting for 71% of total global solar inverter shipments in 2022,4⁶ as illustrated in Figure 21.47 The strong dependence on FEOC-manufactured solar PV systems requires a

better understanding of the risk these systems pose to U.S. energy security. Following the tariff application to solar cells and modules in 2018, and extension in 202048, and the injection of federal infrastructure funds, panel manufacturing has slowly but steadily been moving to the United States and allied countries, but inverters have not followed the same path;49 many now have primary sourcing from China.

Huawei Sungrow Ginlong Solis Growatt GoodWe SMA Power Electronics Sineng Aiswei Sofar TMEIC All Others

Figure 21. Global inverter companies45.

Source: Wood Mackenzie

Below is a list of the most commonly sourced large three-phase large inverters in the United States:

• FIMER SPA (ABB)

• Power Electronics

• Schneider Electronics

• SMA

• Siemens

• Delta Electronics

• Sungrow Power Supply

• Huawei Technologies Co

• Ginlong Solis

• Yaskawa Solectria Solar

• Toshiba Mitsubishi-electric Industrial Systems Corporation (TMEIC)

• Hitachi

On the California State Allow List alone, there are 96 manufacturers and over 1500 eligible inverter models; an even greater number of inverters are available for purchase in the United States beyond the list. Therefore, it would be nearly impossible to conduct a thorough analysis of either the supply chains and components of each model or all the manufacturers. Based on this vast scope, coupled with their importance in BESS security The primary criterion used to drive the analysis was inverter manufacturers with the largest potential impact to the grid based on deployed capacity.

Summary: Presence of PRC in Combined BESS Supply Chain

In evaluating the presence of PRC manufacture overall in the supply chain for battery energy system components, the dominance is clear. There are significant efforts to move this supply chain, through BIL funding, but this to date has focused on the cell material.

If we consider that at the lowest level, components and manufacture for electronics are sourced from a PRC-manufactured or imported material in the range of 70 to 100%50,51,52,53, we can estimate that 90 to 100% of the BESS will have 1+ PRC component (from above analysis 70% inverters and PCS, with over 90% having PRC linked businesses, and 100% of cells) . With the top 10 suppliers in the market PRC-owned and operated, it is likely that BESS systems have at least 1 control component sourced from China. This estimate indicates that it is unlikely that the core control supply chain can exclude PRC-manufactured electronics without significant actions driving change.

Supply Chain Analysis Challenges: Commonality and Sources

There are significant overlaps in supply chains between power electronic components, inverters, BMS, and industry verticals, such as solar, wind, EVSE. This adds additional risk and complication in disaggregating the entangled relationships and ownership models for these entities. Table 6 outlines the functions of critical BESS components, indicating, as well, if they are also used in other renewables or inverter-based resources, and where the supply chain overlaps, both in components and company roles. Similar functions offer insight as to where the supply for these components may be interlinked with another industry vertical, such as solar, wind, or electric vehicles. For example, inverters provided for solar or hybrid plants, use similar if not identical components in many cases, potentially with different software or configuration of functions enabled on the same hardware. Battery modules developed for stationary storage are likely the same cells used in electric vehicle batteries, and the Supervisory Control Systems are not often specific to BESS alone. This indicates the complex web that should be considered in analyses of any one supply chain vertical. This is also illustrated graphically in Figure 22.

Table 6. Specificity of BESS components to supply chain vertical. <table><tr><td rowspan=1 colspan=1>Item</td><td rowspan=1 colspan=1>Description of Functions</td><td rowspan=1 colspan=1>BESS Specificity</td></tr><tr><td rowspan=1 colspan=1>Battery modules,packs, and cells</td><td rowspan=1 colspan=1>Core energy storage functions andelectrochemistry</td><td rowspan=1 colspan=1>Stationary and Mobile Systems</td></tr><tr><td rowspan=1 colspan=1>PCS</td><td rowspan=1 colspan=1>Convert between AC and DC power,bidirectional and often combined with inverterin BESS (specific to BESS – not other IBR)</td><td rowspan=1 colspan=1>Specific to BESS</td></tr><tr><td rowspan=1 colspan=1>Inverters</td><td rowspan=1 colspan=1>Convert DC power from battery cells to ACpower</td><td rowspan=1 colspan=1>Solar, wind, EV other IBR – can bea combined or separate</td></tr><tr><td rowspan=1 colspan=1>BMS</td><td rowspan=1 colspan=1>Monitor and control battery SOC, state of health(SOH), and environmental safety</td><td rowspan=1 colspan=1>Stationary and mobile (EV)systems, along with other types ofbatteries</td></tr><tr><td rowspan=1 colspan=1>Supervisory controlsystems and EMS</td><td rowspan=1 colspan=1>Coordinate and manage BESS system levelfunctions</td><td rowspan=1 colspan=1>EMS and SCADA are common inIBR</td></tr><tr><td rowspan=1 colspan=1>Environment controlsystems</td><td rowspan=1 colspan=1>Regulate temperature and air quality withinBESS facilities</td><td rowspan=1 colspan=1>Specific to BESS</td></tr><tr><td rowspan=1 colspan=1>Fire suppression or firecontrol</td><td rowspan=1 colspan=1>Detect and suppress fires</td><td rowspan=1 colspan=1>Specific to BESS</td></tr><tr><td rowspan=1 colspan=1>Transformers</td><td rowspan=1 colspan=1>Step up or down voltage levels as needed</td><td rowspan=1 colspan=1>Common in power systems, newsolid state integrated with invertersare specific to BESS</td></tr><tr><td rowspan=1 colspan=1>HMI</td><td rowspan=1 colspan=1>Provide user interface for monitoring andcontrol on site</td><td rowspan=1 colspan=1>Common components</td></tr><tr><td rowspan=1 colspan=1>Electrical disconnects,circuit breakers, andswitches</td><td rowspan=1 colspan=1>Protect components from overloads or faults</td><td rowspan=1 colspan=1>Common components</td></tr><tr><td rowspan=1 colspan=1>Communications andmodems</td><td rowspan=1 colspan=1>Facilitate data exchange between componentsand external systems and controls</td><td rowspan=1 colspan=1>Common components</td></tr></table>

Figure 22. Supply chain linkages for BESS.

Multiple open-source and commercial references were used in this report to help identify the top vendors in the United States. Business models for OEMs and integrators vary more widely than traditional electric vendors, with common problematic elements including changing vendor names, changes in parent or holding companies, companies that have merged or separated,54 entries into new markets, withdrawal from the U.S. market (Huawei),55 and development of new business lines such as storage or electric vehicle supply equipment.56 In the U.S. market, published company penetration lists often leverage “pay-to-play” as inclusion criteria, leading to bias.

Threats, Vulnerability, and Attack Exposure for BESS

Threats

Threat actors interested in battery targets may range from nation-state actors to cybercriminal organizations to individuals with limited capabilities and physical criminals. For FEOC components, the threat over the lifecycle of the system, as an integrated unit is as important to consider as the threat actors for systems in operation, exploiting vulnerabilities from outside. Organizations should track the manufacturing country and the influence of the local government on their critical components. For example, the influence of the Chinese government on CATL includes the appointment of government workers to key positions within their corporate structure, as well as the use of specific mining locations57.

Even more difficult to track than the original component manufacturers are additional organizations with access to equipment during the assembling, shipping, and construction phases. The U.S. Department of Commerce found that some Chinese solar producers were shipping products through Cambodia, Malaysia, Thailand, or Vietnam to avoid payment of U.S. duties58. Similar actions could be taken by battery companies to avoid tariffs or bans on Chinese-manufactured components. Even if done legally (i.e., significant assembly or manufacturing occurs in a different country), intermediary companies and countries should be held to the same level of scrutiny as core component manufacturers to maintain trust in the security of the supply chain.

Operation of the battery may also expose it to a wide range of potential threat actors. Batteries used in critical applications may be seen as valuable targets for nation-state actors. Even those not used in critical applications may be seen as “low-hanging fruit” easily targeted by cybercriminals. In recent years there has been a rise in both nation-state actors and criminal actors targeting not only the energy sector in general but also specific renewable targets.59

Vulnerability

Vulnerabilities may exist in either individual components in the battery or within the overall system. Flaws may exist at the design, execution, system assembly, or at any layer, including firmware, software, hardware, and communications. Vulnerabilities may occur in key BESS components:

Battery modules, packs, and cells: While cells are free of integrated digital components, flaws in the manufacturing process could lead to degraded performance over time, eventually causing the battery to fail when performing key functions. Failure of a single cell can lead to failure of the entire module through thermal propagation.

PCS/Inverters: Widespread use and application of BESS increases the potential for functions to be affected by vulnerabilities in the PCS. As with battery modules, poor manufacturing could create hardware vulnerabilities that affect performance. Another hardware vulnerability is intentional tampering with the manufacturing or shipping process. China has been accused of tampering with computing equipment destined for the United States60 and even installing backdoors on chips used for military applications, nuclear power plants, and power distribution.61 Additionally, PCS communicate with the fleet, BMS, and outside world, often requiring firmware updates like the BMS and inverters. Vulnerabilities such weak password policies, hard-coded passwords, improper authentication, or improper storage of critical information may create attack paths for adversaries.

BMS: Both firmware (operating system and setup of the computing system) and software (programs running on the system to perform operational tasks) may have vulnerabilities, with weaknesses created by features similar to those for inverters and PCS. Many vulnerabilities are simply flaws in the design or execution of the code that lead to unintended functionality, such as memory overflows that allow for the insertion of arbitrary code. However, particularly for FEOC devices, malicious code insertion can cause undocumented activity to occur, such as leaving a backdoor open or sending beaconing signals. Though purchasers can require tracking of all software subcomponents on a device through an SBOM, the intentions of code authors and the execution and effectiveness of code quality reviews must also be considered. While it is extremely difficult to track the origin of every single line of code on a device, requiring vendors to submit their SBOMs to customers and show proof of code review processes can provide some visibility into the maturity of the digital supply chain for the product. The SolarWinds hack of 2020⁶62occurred because nation-state hackers were able to add malicious code into the SolarWinds software that was not detected before the code was certified and distributed to customers. In addition to intentional attacks on the software supply chain, vulnerabilities may occur through poor code-writing practices or the use of open-source (and often unsupported) code in enterprise applications.

Supervisory control system and EMS: The supervisory control system collects data and may send control signals to batteries based on the conditions of the grid. At this level of the BESS, key considerations include who has access to what data and functionalities, and how that access is managed.

Electrical disconnects, circuit breakers, and switches (protection): Historically, circuit breakers and switches were manual or electromechanical devices triggered by local sensor readings. However, with digital relays often being used as primary protection for grid systems, vulnerabilities in these devices have been shown to cause misoperation of devices.63

Communications networking switches and cables: In addition to battery-specific hardware, the supplementary equipment used in these systems—including IT and communications equipment—must be considered. The first publicly disclosed attack that affected U.S. renewables exploited a known vulnerability in Cisco firewalls, which caused them to reboot repeatedly, blocking the flow of data from several wind and solar sites to the aggregator, sPower.64More recently, both disclosed and zero-day vulnerabilities were exploited on systems belonging to several small Danish utilities65.

Common technical issues that can increase risk of cyber events for all source inverters, BMS, and PCS include:

• Hardcoded and weak passwords

• Direct connection to OEM for firmware management

• Direct connection to OEM for quality monitoring

• Application security issues

• Weak or limited access controls

• Mass orchestration via cloud and third-party platforms

While technical issues with power electronic-based control equipment may lead to significant challenges and areas for exploitation, solutions are in place to enable U.S. and non-FEOC operators to secure these components. Many non-FEOC vendors have robust reporting mechanisms or are growing their product security teams and have disclosed vulnerabilities in inter-nation inverters and related applications66, indicating a willingness to resolve challenges in the technology.

There are greater concerns, however, with FEOC vendors.67 While vendors must perform and certify tests for safety and evolving tests for cyber safety (UL 2941)68, technical testing to standard (by UL or Electrotek, for example) is authorized to be performed by PRC companies and, therefore, may not adhere to U.S. disclosure or reporting requirements. Future work will be required in geolocating testing and certification.

Technical issues with PRC-sourced power electronic conversion/management products include:

• Direct connection to offshore site for firmware management

•Direct connection to offshore site for quality monitoring, not segmented from control per standards

• Hardcoded passwords

• Poor chip quality

• Insecure support software to manage security features

• Bad documentation

• No vulnerability disclosures to U.S. or international governments

• Providing white labeling of products

Additionally, many inverters, BMS, and PCS sourced in the United States are governed by third-party contracts with integrators and suppliers with specific provisions forbidding

reverse engineering or inspecting components, leaving an extremely limited ability to identify or manage the vulnerabilities. This is true even with equipment sourced through U.S. companies. For example, an integrator may buy a shipment/set of inverters to incorporate into their BESS. This may be a long-term contract. To receive that supply, the integrator must sign an agreement with the OEM, which often enforces clauses on the integrator to not inspect, reverse engineer, or evaluate the internal workings of the device, creating a barrier to improving security within the integrators. So, while they may build their own software, they have limited ability to inspect the underlying hardware and firmware.

Some examples of reported vulnerabilities in BESS and other renewable components include:

• Enphase Envoy

O CVE-2020-25754: Custom privilege access management module uses password derived from the MD5 hash of the username and serial number. Serial number can be retrieved by an unauthenticated remote user69.

O CVE-2020-25753: Default admin password for certain versions set to the last 6 digits of the serial number, which can be retrieved by an unauthenticated remote user70.

0CVE-2020-25752: Hardcoded web-panel login passwords for the installer and Enphase accounts. Users are unable to change these passwords71.

0CVE-2019-7676: Weak password vulnerability discovered in Envoy R372.

• Contec SolarView

o CVE-2023-27512 use of hard-coded credentials may allow remote authenticated attacker to login with administrative privilege.73

• Fronius

CVE-2019-19228: Solar inverter allows attackers to bypass authentication because the password is stored in a plaintext file.74

Table 7. Attack types and potential outcomes <table><tr><td colspan="1" rowspan="1">Attack type</td><td colspan="1" rowspan="1">Potential enabling attackpaths</td><td colspan="1" rowspan="1">Potential Outcomes</td></tr><tr><td colspan="1" rowspan="1">Reconnaissance</td><td colspan="1" rowspan="1">Network scansStolen credentials (socialengineering)hardcoded credentialsPivotingSpyware</td><td colspan="1" rowspan="1">Leaked system configurationsLeaked operational data</td></tr><tr><td colspan="1" rowspan="1">Exfiltration</td><td colspan="1" rowspan="1">File transfer vulnerabilitiesvia cloud or DERMS</td><td colspan="1" rowspan="1">Leaked performance dataLeaked personal data</td></tr><tr><td colspan="1" rowspan="1">False datainjection</td><td colspan="1" rowspan="1">Access to PCS, Access toInverterAccess to metersAccess to data in transitUnencrypted protocolsLack/no authentication</td><td colspan="1" rowspan="1">Misoperation of BESS based on baddataHide further adversary activity</td></tr><tr><td colspan="1" rowspan="1">Wiper malware</td><td colspan="1" rowspan="1">Access to devices of interest</td><td colspan="1" rowspan="1">Destroyed forensicsDelayed cyber recoveryBricked devices</td></tr><tr><td colspan="1" rowspan="1">Botnets</td><td colspan="1" rowspan="1">Internet exposure viaapplications or unpatchedsystemsVulnerabilities enablingremote takeover</td><td colspan="1" rowspan="1">Degraded performance</td></tr><tr><td colspan="1" rowspan="1">Denial-of-critical-functionality</td><td colspan="1" rowspan="1">FloodingNetwork equipment DoSPower equipment DoS</td><td colspan="1" rowspan="1">Disable safety featuresPrevent operation in mission-criticalscenarios</td></tr><tr><td colspan="1" rowspan="1">Commandinjection</td><td colspan="1" rowspan="1">Malicious firmwareLotLBackdoor</td><td colspan="1" rowspan="1">Local OutageReverse Operation</td></tr><tr><td colspan="1" rowspan="1">Escalation &amp;Pivot</td><td colspan="1" rowspan="1">Pivot into cloud massorchestration, wider impact</td><td colspan="1" rowspan="1">Mass outageFinancial LossLoss of Load</td></tr></table>

Attack Exposure

Normally, the introduction of remote management systems for distributed resources increases the attack surface. For BESS and other inverter-based resources, however, remote management is necessary to maintain secure features through software and firmware updates which would be unlikely to be applied manually.

The United States' increasing reliance on batteries and their associated power electronics also increases the number of stakeholders requiring access to both data collection and command permissions, which in turn increases the potential attack surface. If any one of the authorized stakeholders were compromised, it could lead to an adversary using that stakeholder's level of access to perform malicious actions. This increasing access is a growing trend in renewables, where entities with third-party access (e.g., OEMs and maintenance providers) have ongoing connections to devices. In March 2022, an attack on Viasat SATCOM infrastructure interrupted satellite communications75, knocking out remote communications for over 5,800 ENERCON wind turbines76.

Many third-party stakeholders may not be subject to the same level of regulation as a utility or power provider. If these companies are hacked, there is potential attack exposure to the BESS through these third-party entities. Recent incidents have shown that affected organizations tend to cut off their remote access to renewable systems in the event of a compromise to prevent spread, but it remains unclear whether these incident response actions occur sufficiently quickly or completely. In another example, wind turbine manufacturers Nordex and Vestas and maintenance company Deutsche Windtechnik77 were forced to deactivate remote data monitoring capabilities for several days while they

responded to ransomware attacks on their enterprise systems78. While none of these incidents resulted in a loss of power production capability, they highlight the susceptibility of third parties to attacks with potential operational impacts, even if OT equipment is not directly affected.

As with threat actors, the attack exposure of the system must be considered throughout its lifecycle. Manufacturing, shipping, assembly, and development all represent potential points of exposure where vulnerabilities could be introduced or illegitimate access to systems gained prior to operation. Major challenges of remote BESS maintenance can include:

• Connectivity: Remote maintenance relies on robust communication networks. Any connectivity issues can hinder real-time monitoring and timely intervention.

• Security: Remote systems are potential targets for cyberattacks. Ensuring secure data transmission and access control is critical.

Diagnostics and Response: Remote diagnostics can be limited compared to onsite inspections, and remote response capabilities might not be adequate for all types of maintenance issues.

Examples of exploited vulnerabilities in recent years include:

• Enphase Envoy vulnerabilities (2023)79

oEnphase Envoy is a communications gateway that transmits home solar energy system performance data to the MyEnlighten portal

o Wired connection to microinverter, connected through user's router or cell modem to MyEnlighten

Used for monitoring and automatic software updates

oControl features include power export limiting and zero-export applications

o OS Command Injection in the gateway allows root access

• Mirai Botnet leveraging CONTEC vulnerabilities (June 2023)80

Palo Alto Networks Unit 42 describes threat actor activity leveraging loT vulnerabilities to spread a variant of Mirai botnet

o Contec SolarView vulnerabilities included, but not the only ones

oBots used to execute additional attacks, including denial of service (DoS)

Common Digital and Communication Features in BESS and Power Electronics: Risk vs. Benefit

Some common features in Power Electronics and BESS, which provide benefit, but also risk include persistence in communications and condition monitoring:

Communications and Inverters

BESS often require key digital components from non-domestic suppliers, which could give PRC-backed companies the ability to impact domestic energy resources. These supplier relationships enable the PRC to establish delivery mechanisms that, if exploited, could cause downstream impacts on regional energy infrastructure.

Some technical features of digital infrastructure enhance risk of adversary access. Distributed systems, for example, require communications and remote maintenance to manage security fixes, patches, and updates which enable secure operation. Because cyber safety may be compromised by out-of-date firmware and software, remote management is often the only practical path, given the volume of devices affected. However, componentry configured to accept updates from an OEM with negative influences can create a pathway to intrusion and a supply chain style attack.81 Furthermore, if service control is retained by the OEM, suppliers could dictate service provisions and potentially exert control over essential functions (e.g., Volt/Var management for Tesla). While OEM service control is a current business standard, efforts should be made to prioritize adding controls.

Condition Monitoring

Battery companies, in particular cell manufacturers, as common practice, collect condition and performance data across the operational fleet to identify early warnings of failure and degradation. For this communication, best practices and lEC requirements82 suggest segmenting it from the command and control and limiting transmissions with a one-way diode; however, if segmented, it could also pose a limited risk in normal and medium consequence operational systems. In most installations, these communication interfaces are poorly documented. For example:

“After a project is put into operation, CATL continues to monitor its operational status through Al-powered risk monitoring and an intelligent early warning system. It calculates the failure rate of energy storage products throughout their life cycle, and thus verifies the safety design goals while continuing to optimize them.” – CATL Publication May 202483

To facilitate the data exchange, the BESS must communicate outside the firewall of its utility or integrator connection. While many large vendors—including Tesla, Fluence, and Flexgen— operate this way, the risk is mitigated via the separation of communications and control, along with other features to isolate it from other networks.

Supply Chain Threat of PRC Influence for Digital Energy Infrastructure: Evaluating the Technical Risk Landscape

As part of this report's supply chain analysis, the criticality of the BESS functional components, together with the systemic consequence of their cyber or physical misoperation, were evaluated to identify their priority relevant to solution development. The evaluation considered the system functions, modes in which each can or should operate, and modes by which each can mis-operate. The operational functions of concern are shown in Table 8.

The BESS functionality's various critical aspects include communications ability (comms), charge and discharge control, and safety for equipment functions.

Comms facilitates communication within the BESS, enabling control over the charge rate and limiting the ability to turn the system on or off fully or trip it completely.

• Comms also allows incremental generation or discharge within predefined limits.

Safety measures are paramount to preventing equipment damage and ensuring life safety by averting potential risks of escalating damage or harm to personnel (e.g., electrocution).

BESS also has cybersecurity impact potential both through its connection with other cybersecurity components within a single system as well as its connections to external cybersecurity components, including site, fleet, or utility networks, amplifying cybersecurity risks and implications.

Table 8. Ability and negative impact of component misoperation. <table><tr><td rowspan=1 colspan=1>ComponentName</td><td rowspan=1 colspan=1>Function</td><td rowspan=1 colspan=1>Negative Impact of Misoperation</td><td rowspan=1 colspan=1>Can Operatein Isolation?</td></tr><tr><td rowspan=4 colspan=1>PCS/Inverter</td><td rowspan=1 colspan=1>Charge and dischargemanagement</td><td rowspan=1 colspan=1>Power system coordination (meetingthe load), ability to provide emergencyand backup support, power systemstability, two-way power flow</td><td rowspan=1 colspan=1>No</td></tr><tr><td rowspan=1 colspan=1>Turning the system on andoff</td><td rowspan=1 colspan=1>Power system coordination (meetingthe load), ability to provide emergencyand backup support, power systemstability</td><td rowspan=1 colspan=1>No</td></tr><tr><td rowspan=1 colspan=1>Voltage support</td><td rowspan=1 colspan=1>Power system stability</td><td rowspan=1 colspan=1>No</td></tr><tr><td rowspan=1 colspan=1>Frequency support</td><td rowspan=1 colspan=1>Power system stability</td><td rowspan=1 colspan=1>No</td></tr><tr><td rowspan=1 colspan=1>PCS</td><td rowspan=1 colspan=1>Coordination of power andcontrol functions for two-waypower flow, communicationfrom internal to externalcomponents</td><td rowspan=1 colspan=1>Cyber escalation can manage both theflow and the charge protections in theBattery Management System, stability,safety</td><td rowspan=1 colspan=1>No</td></tr><tr><td rowspan=1 colspan=1>EMS</td><td rowspan=1 colspan=1>Coordination of batteries in asite</td><td rowspan=1 colspan=1>Coordinated cyber impact (connectionto other cyber components within oneBESS)</td><td rowspan=1 colspan=1>No</td></tr><tr><td rowspan=1 colspan=1>Comms system</td><td rowspan=1 colspan=1>Connection of field system tooperations center or otherfield systems</td><td rowspan=1 colspan=1>Cyber escalation (connection to othercyber components outside the singleBESS)</td><td rowspan=1 colspan=1>No</td></tr><tr><td rowspan=1 colspan=1>BMS</td><td rowspan=1 colspan=1>Battery health monitoringand control</td><td rowspan=1 colspan=1>Escalating damage to components</td><td rowspan=1 colspan=1>Yes</td></tr><tr><td rowspan=3 colspan=1>SafetyInstrumentedSystem (SIS)</td><td rowspan=1 colspan=1>Fire prevention</td><td rowspan=1 colspan=1>Fires, equipment damage</td><td rowspan=1 colspan=1>Yes</td></tr><tr><td rowspan=1 colspan=1>Temperature control</td><td rowspan=1 colspan=1>Runaway fires, equipment damage</td><td rowspan=1 colspan=1>Yes</td></tr><tr><td rowspan=1 colspan=1>Life safety</td><td rowspan=1 colspan=1>Electrocution, harm of personnel</td><td rowspan=1 colspan=1>Yes</td></tr></table>

Analysts applied a Cyber-Informed, Consequence-Driven Engineering approach, generating a total consequence score for each component in the BESS, leveraging the impact of misoperation across cyber and physical domains to assign a priority to the consequence of the functions illustrated in Table 8. These scores were then used to identify the most critical components for both long- and short-term security solutions. These results are shown in Figure 23. This prioritization represents a technical, validated assessment of the capabilities of these devices and the potential impact of their exploit on the wider network (scores and functions for each item may be found in the appendices).

Figure 23. Criticality of BESS components to cyber, physical, and safety consequence outcomes.

Analysis of function, consequence, and cybersecurity capability concludes that PCS, BMS, and inverters should be prioritized at the BESS level, and site controllers prioritized at the fleet level. The PCS is the critical digital technology that allows the BESS to perform both charging and discharging, enabling a two-way flow of energy. The BMS, while critical to BESS health and safety, can be isolated from a communications standpoint, but the PCS, by nature of its function to decide when to charge and discharge, must communicate with higher level systems. The combined exposure and criticality of the PCS leads to its high criticality score.

Based on this analysis, resources and efforts should be allocated towards replacing or strengthening the protections and controls for the most critical components first. This may include implementing security measures such as encryption, access controls, intrusion detection systems, and regular security assessments and updates.

Grid and Utility-Scale Operational Consequence of BESS Functions

When prioritizing protections and controls for BESS, significant risks must be mitigated first. By first identifying and understanding the vulnerabilities and threats facing the BESS infrastructure, the risks can then be assessed, and policy actions prioritized based on replacing or enhancing the most consequential components of the system.

To assess the consequences of misoperation and failure scenarios for BESS in a large ISO with high resource penetration, criteria encompassing various aspects of system performance, safety, and reliability should be considered. Some potential criteria include:

1. Grid Stability Impact: Evaluate how misoperation or failure affects the stability of the grid, including voltage and frequency control, power quality, and overall system reliability.

2. Energy Supply Disruption: Assess the extent to which misoperation or failure disrupts energy supply to consumers, considering factors such as load shedding, blackouts, and curtailment of renewable resources.

3. Safety Risks: Determine the level of safety risk posed by misoperation or failure, including potential hazards to personnel, equipment damage, and environmental impact.

4. Economic Consequences: Evaluate the economic impact of misoperation or failure, considering costs associated with lost revenue, system repairs, compensation claims, and market penalties.

Once the criteria are established, they can be incorporated into a decision matrix ranking the consequences of misoperation and failure scenarios. Each scenario can then be evaluated against these criteria to determine its overall impact on system performance, safety, and economic viability.

The Consequence-driven Cyber-Informed Engineering's (CCE)84 criteria scoring threshold is illustrated in Table 9 below, with additional factors added specifically to BESS and its role in the national landscape. Environmental and reputational damage in this space are significant factors to consider in addition to the standard criteria for bulk energy systems. Many BESS and new generation components are supporting energy resilience upgrades, and the loss of these components via cyber attacks and supply chain issues would result in a significant impact on the communities they are connected to.

By systematically assessing the consequences of potential failures, stakeholders can prioritize mitigation measures and enhance the resilience of BESS deployments in highresource penetration environments within large ISOs.

Table 9. CCE criteria scoring threshold. <table><tr><td rowspan=1 colspan=1>Criteria</td><td rowspan=1 colspan=1>None</td><td rowspan=1 colspan=1>Low</td><td rowspan=1 colspan=1>Medium</td><td rowspan=1 colspan=1>High</td></tr><tr><td rowspan=1 colspan=1>Area/loadimpact</td><td rowspan=1 colspan=1>Inconsequential</td><td rowspan=1 colspan=1>Loss of failure toservice firm load ofless than 300 MW(or) load supply lossof MSC or 2,000MW, whichever islower</td><td rowspan=1 colspan=1>Loss of failure toservice firm loadbetween 301 and1,500 MW (or) loadsupply loss of between2,000 MW (or MSC,whichever is lower)and 3,000 MW</td><td rowspan=1 colspan=1>Loss of failure toservice firm loadgreater than 1,500MW (or) load supplyloss of greater than3,000 MW</td></tr><tr><td rowspan=1 colspan=1>Duration</td><td rowspan=1 colspan=1>Inconsequential</td><td rowspan=1 colspan=1>Return of all servicein less than 1 day(inability to servefirm load) (or) supplyoutage for less than1 week</td><td rowspan=1 colspan=1>Return of all service 1– 5 days (inability toserve firm load) (or)supply outage for 1week – 1 month</td><td rowspan=1 colspan=1>Return of all service&gt;5 days (inability toserve firm load) (or)supply outage &gt;1month</td></tr><tr><td rowspan=1 colspan=1>Safety</td><td rowspan=1 colspan=1>Inconsequential</td><td rowspan=1 colspan=1>Risk onsite</td><td rowspan=1 colspan=1>Definite safety riskoffsite</td><td rowspan=1 colspan=1>Loss of life potential</td></tr><tr><td rowspan=1 colspan=1>Assetowner/systemintegrity</td><td rowspan=1 colspan=1>Inconsequential</td><td rowspan=1 colspan=1>Can restore withconfidence inintegrity</td><td rowspan=1 colspan=1>Owner has knowledgebut no resources(money, time,personnel) to restore</td><td rowspan=1 colspan=1>Asset owner canrestore but noconfidence inintegrity</td></tr><tr><td rowspan=1 colspan=1>Cost</td><td rowspan=1 colspan=1>Inconsequential</td><td rowspan=1 colspan=1>Significant but canrecover</td><td rowspan=1 colspan=1>Multiple years tofinancially recover</td><td rowspan=1 colspan=1>Trigger of liquiditycrisis/potentialbankruptcy</td></tr><tr><td rowspan=1 colspan=1>Reputationaldamage</td><td rowspan=1 colspan=1>Inconsequential</td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1>Customer loss offaith in utility</td></tr><tr><td rowspan=1 colspan=1>Environmentaldamage</td><td rowspan=1 colspan=1>Inconsequential</td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1>Environmentaldamage</td></tr><tr><td rowspan=1 colspan=1>Breadth</td><td rowspan=1 colspan=1>Inconsequential</td><td rowspan=1 colspan=1>Impact to single unitnearby throughattack</td><td rowspan=1 colspan=1>Impact to distributionoperations throughattack</td><td rowspan=1 colspan=1>Impact to criticalBESS operationsthrough networkedattack</td></tr></table>

Figure 24. Criticality of BESS functions in grid connection and operation.

Low to High Consequence Score

The technical functions of the BESS and the potential scale of impact of disruption of its performance in its role on the grid, are then scored against the Criteria priority and impact to develop a prioritization and solutions list. This is outlined further in Appendix A: BESS Components and Functions. This prioritization, showing types of BESS performance that can lead to the most consequential events, enables strategic deployment of solutions across the national fleet. For example, if a BESS is performing a critical role in backup generation, a more focused approach on its supply chain provenance, and a high assurance security package would be considered. In normal or small-level operations, the impact of a disruption would be lower and a more limited but still applicable set of solutions could be considered.

DERMS, Software, and Mass Orchestration

In assessing the importance of components to site operation and safety for BESS, it is essential to consider their broader implications beyond individual system functions. While DERMS and mass control play significant roles in BESS operation, their importance extends beyond mere functionality to encompass broader implications for grid stability, system reliability, and safety. The theory underlying the assessment of component importance emphasizes the critical role of DERMS and mass control in enabling the seamless integration and operation of BESS units within broader energy systems. Any disruption or failure in these components could have cascading effects on system operation, potentially compromising grid stability, energy supply reliability, and overall safety. Therefore, ensuring robust access to DERMS and fleet control functionalities, whether through on-site management systems or cloud-based platforms, is essential for optimizing BESS performance and mitigating risks associated with misoperation or failure scenarios.

The DERMS and US marketplace for DERMS is an opportunity to secure the upper layers of a mass-orchestrated power electronic system. With a US vendor landscape, software design practices, and programs to assist with this can be implemented quickly and to US guidelines. DERMS is currently a \$1.2B market in the US.85 The key market leaders include GE Vernova, Siemens, Schneider Electric, and ABB. Secure by Design,86 and integrated practices could use this mature market to deploy solutions. A key consideration in the DERMS marketplace is the use of open-source software packages, and programs to evaluate this are a supply chain security option.

The DERMS and Mass Orchestration evaluation will be considered in later studies, given the cross-cutting applications of DERMS and the Cloud Functions.

Integrator Risk Evaluation

The concept of integrators versus component suppliers for BESS was introduced earlier in this report (Section 4: Supply Chain for BESS Components). As a final piece to the analysis, the integrator model is evaluated, which effectively is a company which sells a combination of products in a complete unit and ties the components together. Integrators can be also manufacturers and OEMs, or independent companies. An integrator is essentially a system of systems and offers opportunities for secure solutions in communications and software with the turnkey unit, or integrated BESS.

Evaluating the risk, or scale of risk in the integrator space, we consider the Source of Components, Integrator Country of Origin, and other features including their maturity and operations and maintenance model. Integrators that are PRC-owned, operated and connected offer little opportunity to develop secure US-based systems, as the software and hardware will all be from the one PRC entity. One of the biggest spaces for solutions is the US integrators, while they cannot purchase many of the US solutions, or have long term agreements in place, they can develop software packages, integrate OT monitoring solutions and create other secure design solutions which do not violate the terms of their contracts with suppliers.

As illustrated in

Transitioning from this detailed examination of roles, it is essential to understand the comparative use cases of integrators based in the PRC versus those in the U.S. (Figure 26).

Figure 26, a U.S. integrator can deploy BESS systems branded under the domestic company's name but which still use battery packs (e.g., via CATL), BMS, and inverter hardware (e.g., Sungrow) provided by PRC manufacturing companies. Comparing the risk factors a US integrator using the same components may present, in comparison to a PRC based integrator, illustrates the difference in solutions and challenges we can address. However, the software components, (e.g., firmware), related to communications and data, both concerns mentioned in the CATL statement on security concerns, are made by the U.S. integrator, rather than a PRC integrator who would use software developed by CATL or partners in the PRC. Additionally, long-term O&M may also be provided by the U.S. integrator but require CATL parts. One disadvantage of this approach, which provides more visibility and control in the cyber domain in the long term than a PRC integrator, is that supplier agreements are long-term and enforce requirements that an integrator cannot inspect or analyze supplied equipment firmware.

Scaling Integrator and Aggregator Risk at a Systems Level

To comprehensively address these concerns, a systematic evaluation framework is essential for assessing and mitigating risks at both the component and integrator levels. Through this approach, the analysis has addressed and evaluated a series of factors by which a company or systemic supply chain risk, can be assessed against consequence. This strategy enables a rapid assessment of suppliers and integrators, to address the most applicable solutions and resources for supply chain threats as they occur or new systems are being designed. This scale means that foreign equipment, and integrations can be assessed apples to apples rapidly for key factors such as willingness to comply with safety and security requirements, maturity of company and record of equipment supply. This can be assessed from public records and would enable a strategic assessment of vulnerability against dominance in the global markets.

Integrators in this assessment can be placed on the matrix, and rapidly reassessed based on new information periodically. Solutions are then designed on this framework, for targeted industry engagement.

Figure 25: Assessment Matrix for Suppliers of BESS and integrators AlI FEOC All US/Trusted Partner

Nonetheless, such a strategy may provide a way to obtain the benefits of BESS systems while mitigating attack surface exposure and long-term access to BESS facilities. Such a strategy should consider the observation that companies such as Hithium are executing multi-year supplier agreements with U.S. companies that develop EMS, and there is a challenging landscape for growing the U.S. power electronics supply. These solutions are defined in the final section and presented here (Table 10) as part of the evaluation.

Table 10: Integrator risk solutions on analysis scale.

PRC Owned, Operated, Connected

U.S.-Owned, Operated, Connected

<table><tr><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1>All FEOC, High Risk,more PRC Control andConnection, Less Abilityto Evaluate</td><td rowspan=1 colspan=1>May Have Non-FEOCEquipment, EmergingTech Relationships,Financial Ownership</td><td rowspan=1 colspan=1>Less Risk, All U.S.Connection. HigherAbility to Evaluate</td></tr><tr><td rowspan=1 colspan=1>Policy Solutions</td><td rowspan=1 colspan=1>Right to inspect/evaluatefor vulnerability andcontrol</td><td rowspan=1 colspan=1>Develop U.S. integratorand internationalcybersecuremanufactureagreements</td><td rowspan=1 colspan=1>U.S. supply chainincentives for powerelectronics</td></tr><tr><td rowspan=1 colspan=1>TechnicalSolutions</td><td rowspan=1 colspan=1>Procurement/contractguideConfiguration andinspectionOT monitoring andspecific detections forPRC controller/actorsCIE design</td><td rowspan=1 colspan=1>Configurations &amp;inspectionSecure by design forU.S.-made softwareSecure commsVulnerabilityassessmentprogramClean EnergyDefenders Training</td><td rowspan=1 colspan=1>Secure commsSecure equipmentmanufactureCIE designClean EnergyDefenders Training</td></tr><tr><td rowspan=1 colspan=1>CoordinationRequired From</td><td rowspan=1 colspan=1>U.S. AOO, Buyer of PRCProduct</td><td rowspan=1 colspan=1>U.S. AOO, U.S.Integrator, InternationOEM</td><td rowspan=1 colspan=1>U.S. AOO, Integrator,U.S. OEM</td></tr></table>

Transitioning from this detailed examination of roles, it is essential to understand the comparative use cases of integrators based in the PRC versus those in the U.S. (Figure 26).

Figure 26. Use case and comparison of a PRC-based integrator versus a U.S. one.

Supply Chain Threat of PRC Influence for Digital Energy Infrastructure: Business Model and Policy Landscape

Supply chain risk management often focuses analysis of manufactured devices on individual companies and components. BESS and the business model landscape in which they are manufactured, built, installed, maintained, and operated are complex and often obfuscated by many layers of process, which impacts the attack surface exposure of regional energy infrastructure and its downstream dependencies.

The recent focus on cyber supply chain risk management underscores how interorganizational relationships, just like cyber-physical dependencies, can be used to provide access, persistence, and unexpected and potentially adversarial impacts to energy sector systems. As a result, we must consider business models surrounding BESS as a source of long-term operational risk.

Roles and Responsibilities in the BESS and Inverter Sector

Various entities within the BESS ecosystem, with distinct roles and specific responsibilities, contribute to the system's functionality and efficiency. Unlike conventional utilities in which ownership, operation, and maintenance are typically consolidated within a single entity, the

BESS ecosystem features diverse stakeholders with specialized functions. As captured in Table 11, all these stakeholders—including builders and commissioners, owners, operators, maintenance providers, communicators with site infrastructure, and power sellers—fulfill crucial roles in the deployment and operation of BESS infrastructure, and all are affected by supply chain risk.

Table 11. Roles and responsibilities in the BESS ecosystem. <table><tr><td rowspan=1 colspan=1>Item</td><td rowspan=1 colspan=1>Builds andCommissions</td><td rowspan=1 colspan=1>Owner</td><td rowspan=1 colspan=1>Operator</td><td rowspan=1 colspan=1>PhysicalLocation andElectricalInterconnect</td><td rowspan=1 colspan=1>MaintainsCommunicationswith Site</td><td rowspan=1 colspan=1>SellsPower</td><td rowspan=1 colspan=1>DataAccess</td></tr><tr><td rowspan=1 colspan=1>Distribution orG&amp;T Utility</td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1>X</td><td rowspan=1 colspan=1>X</td><td rowspan=1 colspan=1>X</td><td rowspan=1 colspan=1>X</td><td rowspan=1 colspan=1>X</td><td rowspan=1 colspan=1>X</td></tr><tr><td rowspan=1 colspan=1>Third-PartyIndependentPowerProducer/Virtual/Aggregator</td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1>X</td><td rowspan=1 colspan=1>X</td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1>X</td><td rowspan=1 colspan=1>X</td><td rowspan=1 colspan=1>X</td></tr><tr><td rowspan=1 colspan=1>Third-PartyO&amp;M Company</td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1>X</td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1>X</td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1>X</td></tr><tr><td rowspan=1 colspan=1>BESS OEM</td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1>X</td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1>X</td></tr><tr><td rowspan=1 colspan=1>ISO</td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1>X</td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1>X</td></tr><tr><td rowspan=1 colspan=1>Third-PartyRetail Sales</td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1>X</td><td rowspan=1 colspan=1>X</td></tr><tr><td rowspan=1 colspan=1>Engineering,Procurement,andConstruction</td><td rowspan=1 colspan=1>X</td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1>X</td></tr><tr><td rowspan=1 colspan=1>InterconnectAnalysis Party</td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1></td><td rowspan=1 colspan=1>X</td></tr></table>

Because multiple organizations may maintain communications with the site, appropriate management or security procedures (e.g., multi-factor authentication, role-based access) is crucial; these measures help to reduce attack exposure by which the organizations could be used as an entry point to connect to the BESS or become a secondary targets as adversaries use BESS communications infrastructure to pivot into new networks.87 While utilities (distribution and G&T) are responsible for maintaining system reliability and may experience the highest consequences of BESS misoperation, other stakeholders—such as third-party IPPs, or VPP operators—may have more direct control over the BESS operation and should take an active role in cybersecurity risk mitigation.

Limited liability companies (LLCs) are a business structure that combines elements of both a corporation and a partnership or sole proprietorship.88 In an LLC, owners have limited liability, meaning their personal assets are typically protected from the debts and liabilities of the business. An LLC approach can help compartmentalize risks and legal obligations associated with individual installations.

Potential Impact by Stakeholder

We can also consider the potential impact by stakeholder, utilizing the potential vectors for issue. While all stakeholders may not be impacted by a system power outage, or cyber event, they may face impacts through the organizational relationship structures, shown in Table 12.

Table 12. Potential impact by stakeholder. <table><tr><td rowspan=1 colspan=4>Potential Impact by Stakeholder</td></tr><tr><td rowspan=1 colspan=1>Event</td><td rowspan=1 colspan=1>Utility(Non-Operator)</td><td rowspan=1 colspan=1>Operator(Facility, Aggregator, Utility)</td><td rowspan=1 colspan=1>Manufacturer, Integrator,or Installer</td></tr><tr><td rowspan=1 colspan=1>Loss ofControl</td><td rowspan=1 colspan=1>• Energy imbalance</td><td rowspan=1 colspan=1>• Propagated failures• Injury• Equipment damage</td><td rowspan=1 colspan=1>• Reduce reputation• Financial liability</td></tr><tr><td rowspan=1 colspan=1>Manipulationof View</td><td rowspan=1 colspan=1>• Improper controldecision</td><td rowspan=1 colspan=1>• Improper control decision</td><td rowspan=1 colspan=1>• Reduce reputation• Financial liability</td></tr><tr><td rowspan=1 colspan=1>Manipulationof Safety</td><td rowspan=1 colspan=1>• Extendedrestoration time• Failure ofregulatorycompliance</td><td rowspan=1 colspan=1>• Injury or death• Loss of intellectual property• Technical investigation</td><td rowspan=1 colspan=1>• Devalue brand name• Reduce market share• Decommission product frommarket• Financial liability</td></tr></table>

Decentralization of Ownership, Operations, and Maintenance89

Just as communications and computer networks have enabled physical decentralization of generation via DER, decentralization is increasingly a trend in clean energy business models, motivated by specialization and economies of scale. For example, offering BESS O&M as a service is gaining traction.90 But while specialized services can reduce costs and spur investment within the sector by decoupling ownership from operational expertise, they also decouple financial ownership from operational control. Additionally, to realize economies of scale, these services must be widely adopted, which increases the potential impact of a disruption.

Figure 27. Utility as owner, operator, and maintainer of BESS site.

Case Study 1: Utility as Owner, Operator, and Maintainer

Traditionally, utilities have been the primary owners of BESS installations. As illustrated in Figure 27, a distribution utility with a Generation and Transmission (G&T) component is approached to host a BESS site to bolster generation and distribution support. The site is owned and operated by the G&T entity, which assumes responsibility from both a cyber and a physical standpoint. Each site is interconnected at 69 KV and falls under 10 MVA capacity so that in the future it will be registered as a generator under NERC CIP,91 and subject at a minimum to Low Impact Generator owner requirements—that is, the asset owner and operator (AOO) must follow the NERC CIP requirements for this site (when implemented). In this case, the AoO is the utility itself, which retains control over the interconnect process, performance monitoring, and cybersecurity measures and ensures comprehensive oversight and management of the BESS site.

Case Study 2: Third-Party Ownership

In contrast, there has been a noticeable shift towards third-party ownership, primarily driven by financiers seeking investment opportunities in energy infrastructure. In this case study example, as illustrated in Figure 28Figure 28. An example of third-party ownership; site in Texas.

, a third-party independent power producer (IPP) secures rights and interconnect agreements for site development. The site is then sold to another IPP before sourcing and construction commences. This second IPP finalizes interconnect agreements with the local distribution utility. The utility secures a Power Purchase Agreement (PPA) with the site but does not assume ownership, operation, or maintenance responsibilities. Instead, the IPP enters into a 4th party O&M contract.77 The site is interconnected with both the O&M site and the ISO. The site operates within the ISO market pool and is connected at 138 kilovolts (KV) with a capacity of 2x100 MVA. Following an acquisition in 2023, all assets are owned by a French company.92; physical location requirements are overseen by the distribution utility, with the ISO serving as the market controller and defining interconnect standards.

While the model in which the utility owns the unit preferable from a management and responsibility standpoint (i.e., one clear asset owner and operator who will fall under a standard for cybersecurity), the potential for the AOO to have limited staffing resources and understanding of the system, coupled with increased management costs, may lead to security vulnerabilities and/or a limited or minimal application of required standards. In this scenario, the primary impact of a failure on the electric grid or local area and the responsibility for managing it are held by the same entity.

In the third-party model, the utility is still receiving electricity from the site, but is not managing its security, as there is a different owner and operator. There are many more points of connection that could impact the cyber risk of this site that must be managed. Additionally, the AOO or Generator Owner is not a U.S. company, and if there was a need to register under NERC CIP, it would not be clear exactly who would be registered. The impact of an attack will still be with the physical device and connection to the electric grid.

The trend toward decentralization of ownership, operations, and maintenance of a BESS facility, results in more complex business relationships that may increase operational risk.

While there is limited choice in manufacture from non-PRC locations there are business models and technical configurations which reduce the risk of that influence. Domestic integrators may reduce the long-term attack surface exposure for turnkey BESS installations.

Figure 28. An example of third-party ownership; site in Texas.

Expanding Markets for BESS Suppliers

BESS facilities and other clean-energy technologies require key digital components, but the supply chains for many, if not all, these digital components are dominated by foreign-owned suppliers. As a result, these foreign-backed suppliers can reduce risk by indirectly entering a newer market via a domestic partner, with the potential over time to compete with that partner and/or become vital to the operation and maintenance of increasingly prevalent clean-energy systems. This may occur by leveraging the distribution channels of U.S.-owned companies through long-term supplier agreements, gaining access to key digital technologies through strategic partnerships, leveraging clean-energy tax incentives available to partners, and participating in U.S.-hosted industry groups, conferences, and standards bodies.

Case Study 1: White Label, Integrated Component Suppliers Expanding Up the BESS Vertical

Suppliers of BESS digital components can pivot from a manufacturer role to an integrator and turnkey provider role—currently a common shift in the clean energy industry. The entity can enter and learn about an emerging market via long-term supplier agreements with U.S. companies, providing either a component, such as a battery cell or chip to be integrated into other devices, or a white-labeled device, such as a basic inverter, which is then relabeled as a different provider. Over time, as the supplier learns more about the market, they may be able to expand their business model up the vertical and become an integrator; for example, renowned battery cell manufacturers CATL93 and SYL Ningbo are transitioning from simply supplying battery cells to offering integrated systems with advanced features including sensors, often branded under their own names.94

Case Study 2: Suppliers Expanding Across the BESS and Clean Energy Infrastructure Lifecycle

Alternatively, suppliers of digital components for BESS can expand their influence across the BESS lifecycle by becoming a service provider. For example, in Tesla's EV model, service control is retained by the OEM,95 illustrating the significance of the OEM in dictating service provisions and potentially exerting control over essential functionalities such as Volt/Var management. Additionally, the integration of sensors necessary for operation, optimization, and safety systems can provide an opportunity for legitimate, legal, continuous monitoring as a service.

Case Study 3: Integrators and Turnkey Products

The choice of a domestic integrator may provide an approach to decreasing the attack surface exposure of a BESS site. In its December 2023 rebuttal to security concerns, CATL noted that integrators “manage connections to the grid and the grid operators set up an additional layer of security measures.96” These connections include those for electrical power, and integrators also make facility design choices that impact network architectures to enable long-term operations and maintenance. Therefore, choosing a U.S. rather than a PRC-based integrator may help mitigate long-term attack surface exposure within the BESS site, while still enabling commerce and integration of cutting-edge technology.

Legitimate Persistence within Communications Networks

Clean energy systems depend upon reliable communications to coordinate and optimize generation via renewables and BESS to help stabilize the grid. The clean energy transition promises increased dependency on such systems; such dependencies, if not explicitly managed, have the potential to erode national sovereignty via legal, grey-zone business practices.

As noted earlier in this report, DER require communications to coordinate generation across a wide geographic area. While such technologies drive efficiencies and enable some security features such as regular patching, they also increased risk. Supplier entity influence or

insertion of a firmware vulnerability into their supply chain, like the SolarWinds incident,97 are key risks in this architecture—risk that is enhanced by a foreign business ownership model. While the risk may be mitigated technically, often negotiated via contracts with the OEM, many maintain the connection for ease. Similarly, many battery companies, under enhanced scrutiny for safety and fire risk, also maintain connections across their fleet to gather data on battery performance and develop early warning systems for faults and fires98. In many cases, the BESS company has been required to provide that data to investigators, so removing that connection may be a challenge, with the benefit of safety outweighing the cyber risk.

Even after installation, operation and maintenance of physical systems is an area in which the OEM can have influence. Adversarial manufacturers and integrators that provide O&M as a service to BESS may be able to apply living-off-the-land and data collection tactics, often seen in the cyber domain, via connectivity required by Service-Level Agreements (SLAs) or enabled by strategic partnerships. Such services can increase the complexity of underlying network architectures, further complicating network configuration and maintenance, implementation of access and security controls, and development of incident response plans. For example, in 2018 at the AWEA Conference, a technician working for a manufacturer, used a poorly maintained laptop which had downloaded malware from hotel internet and uploaded that malware upon physically connecting to the renewable energy infrastructure.99

Case Study 1: Pivoting from Multi-Year Supplier Agreements to Design

Suppliers of digital components for BESS may leverage multi-year supplier agreements to gain access to and potentially influence emerging technologies. Securities and Exchange Commission (SEC) filings from late 2023 and early 2024 show the existence of three-year supplier agreements between Hithium and U.S. companies that develop energy management systems100101102 . In the EV space, CATL has multi-year supplier agreements with several auto companies103 104 105. These agreements between private U.S. business entities are likely difficult to legally dissolve.

Case Study 2: Influencing Network Architecture via Service Level Agreements

Moreover, OEMs that can pivot to provide operation and management services gain legitimate, persistent access to a BESS facility across its lifecycle. These O&M services are expressed within a BESS facility's communication network architecture (an instance of Conway's Law).106 Visibility and telemetry over operations, accessible via a management dashboard, become part of the value proposition that customers expect. As noted by a 2021 DOE EERE SETO article, “[a] solar-plus-storage system can help you to better track the energy your system is generating through monitoring capabilities, providing an enhanced level of transparency and precision. These systems allow you to track the energy your home is producing and using in real time."107Moreover, a 2017 report by Sandia notes that “remote access to DER equipment from foreign companies is permitted."108 In other words, many DER systems have a design-level dependency on telemetry and monitoring, services that suppliers are naturally able to provide following an installation. For example, Sungrow, a foreign-owned manufacturer and supplier of BESS components for the Chisholm Grid in Fort Worth, Texas, maintains this facility under a long-term service agreement109.

Mitigation Planning and Relevant Initiatives

National Strategies and Policy

Legislation

Multiple stakeholders—including utilities, regulators, and independent system operators—make up the complex ownership and operation models of the U.S. grid and its digital energy components. Coordination of cybersecurity efforts across these diverse entities is challenged by different priorities, resources, and levels of cybersecurity maturity. Legislation provides one mechanism for coordinating action across the industry. The NDAA, the Build America Buy America Act (BABA), and tax credit limitations for equipment manufactured by Foreign Entities of Concern (FEOC) offer strategies relevant to securing the digital supply chain for BESS.

Several versions of the NDAA seek to mitigate supply chain risks by creating and enforcing lists of banned companies. Section 889, signed into law via the NDAA FY19, applies to federal agencies, their contractors, and grant or loan recipients. Section 889 within the NDAA prohibits agencies from procuring equipment, doing business with companies that use covered equipment, or funding the purchase of covered equipment using federal money.11o While the original NDAA applied to telecommunications and video surveillance equipment that were critical technologies or essential system components, the NDAA for FY21 directed the Secretary of Defense to list Chinese Military Companies (CMCs) annually until the end of 2030.111 Most recently, the Pentagon provided an updated list of CMCs with NDAA FY24.112,113

The Buy America standards for equipment and materials used in federally funded projects are designed to prioritize the use of domestically produced items. These standards are part of the Buy America Act and BABA114, enacted as part of the

Infrastructure Investment and Jobs Act (IIJA)115 or Bipartisan Infrastructure Law (BIL).116 BABA applies a domestic content procurement preference requirement to federally funded, public infrastructure projects. Various agencies, including the U.S. Department of Agriculture117 and Department of Energy (DOE)118 have implementation guidelines, which aim to promote domestic manufacturing and reduce reliance on foreign suppliers. Key points of these standards include Domestic Content Preference, Specific Requirements for Construction Materials, Exceptions and Waivers, Rolling-Stock Requirements, and Waivers for Specific Situations.

The IIJA provides tax credits for infrastructure projects. For example, in May 2023, the Internal Revenue Service (IRS) issued preliminary directives for entities aiming to be eligible for the domestic-content tax credit. The IRS sets thresholds for the total direct costs of manufactured products that originated from within the United States: 40% of total direct costs through 2024 and 55% of those costs by 2027.119 The BIL also imposes limits when the project includes FEOC. DOE's Office of Manufacturing and Energy Supply Chains provided guidance relevant to their Battery Materials Processing and Manufacturing grant12o as well as their Clean Vehicle tax credit.121

Rip-and-Replace

A common high-level approach to concerns about dependence on a non-U.S. supply chain for critical energy infrastructure is to replace the equipment with a U.S. supply. However, rip and replace is unrealistic in the immediate and short term but also the long term.

Immediate Term: As previously noted, there was approximately 16 GW of BESS capacity installed by the end of 2023, with plans to reach 30 GW by the end of 2024. Both the existing systems and the systems under construction have already selected suppliers and procured equipment. Even if a domestic supply chain were immediately available, it would be prohibitively costly to replace all this equipment. Additionally, the labor needed to make substitutions and the downtime that operators would

experience during the process would be unacceptable for an industry that prioritizes high availability and reliability.

Short Term: In the short term (5–10 years), it will be difficult to create a fully domestic supply chain. Manufacturing costs must be reduced to make supply competitive with non-U.S. manufacturers. Battery cells require rare minerals (e.g., lithium), for their production, which requires access to mining operations. Maturity in manufacturing, security, and support operations can only be gained via execution over time. The development of a domestic supply chain may face opposition from large, foreign-owned stakeholders in the BESS market. While steps can be taken in the near term to promote U.S. manufacturing, it will take time to develop a domestic industry.

Long Term: A robust U.S. supply chain for BESS can be built up in the long term. Even with the requirement for mined materials to create battery cells and the environmental impacts of production, government incentives, and industry support can drive the development of domestic manufacturing. While there are many benefits of a fully domestic supply chain for energy security, cybersecurity concerns can be addressed in the long term by developing and requiring better component interoperability standards. Rather than a BESS requiring a custom BMS, PCS, and EMS, likely all developed by the same manufacturer, interoperability requirements could allow for the integration of trusted digital components with the battery cells and modules that may still be manufactured outside of the United States.

Although these challenges exist, risk mitigations to address the supply chain's existing systems and systems installed in the short term must be put in place while long-term solutions for a domestic supply chain are developed. The most consequential functions can be protected while longer term supply chain mitigations happen. For existing systems, the scope of risk on a system can be assessed, and protective measures put in place to limit the impacts of potential misoperation. For systems designed and installed in the near term, mitigations can be included in the system design, and thoughtful selection of suppliers can limit association with FEOCs and prioritize monitoring, redundancy, and protection of highimpact components.

Limitations of Ban Lists

The policies outlined above define strategies for reducing reliance on foreign suppliers within federally funded infrastructure projects. At a high level, these policies primarily impact the BESS supply chain through procurement and expensive post-procurement mitigations. However, procurement is just one stage within the lifecycle of critical infrastructure components. Based on publicly available information about domestic BESS projects, policymakers should consider the direct and indirect impacts of actions across the entire BESS component lifecycle to employ a defense-in-depth strategy.

Another currently employed strategy with significant limitations and obstacles is the creation and maintenance of banned lists to drive federal infrastructure funding and tax credits.

Controlling Procurement: The federal government must be able to create and maintain banned lists to implement the NDAA as well as BIL-based tax credits. While bans on certain equipment under the NDAA aim to mitigate supply chain risks, implementing and enforcing these bans effectively is challenging. To be useful, blacklists put enforcing departments— whether those working in procurement in industry or federal agencies—in a reactive position because they must continually check contracted business relationships against the blacklist as part of a vendor risk assessment. This overhead in time and resources increases in accordance with the size of the blacklist. Moreover, blacklists must be updated at a frequency consistent with the adversarial behavior they seek to mitigate; the business operations of banned companies, and their names, can change dramatically over even a few months. In contrast, updating such lists annually via the NDAA, is too slow for an agile approach that keeps pace with the threat cadence of the threat and again encourages a reactive posture.

Prior Rip-and-Replace Initiatives

There is significant movement at present to remove, ban, or otherwise replace PRC infrastructure, including the NDAA Prohibited Battery List from FY24.122The precedence for this includes the ban of Huawei and ZTE by the FCC via the Secure and Trusted Telecommunications Networks Act,123 which required and funded a rip-and-replace budget for both civilian critical infrastructure, and military. Huawei at the time was also the second largest manufacturer globally of inverters,124 but in 2019, following the FCC implemented Act, it announced its exit from the U.S. Market.125 The Secure Networks Act also enabled funding for entities to replace that infrastructure, many of whom were small and mediumsized rural electric cooperatives and municipalities. Those entities were limited from participating in the Broadband funding program without performing the rip and replace of Huawei equipment. It was estimated that this replacement would take approximately \$4B and 4 years.126 The UK followed suit with a similar order. 127While it was expected that order, and funding would dent Huawei and decrease their hold over this market, in 2024, they are the number 1 inverter manufacturer in the world. In 2023, Huawei reported

a strong economic status, with revenue increasing 9% to over \$99 billion, 128 and net profit more than doubling. This was despite the company being a focus of the rivalry between Washington and Beijing. Huawei's revenue growth was attributed to a stronger-thanexpected performance in its electronics business, particularly its smartphone handsets, and its Enterprise Business Group, which includes cloud, loT, and private networks.

In 2024, the FCC (who funded the rip and replace), was estimated to have a budget shortfall of over \$3B. 129 and the rip-and-replace effort was not expected to continue or be successful as most affected entities had not replaced the technology or been able to access the allocated funds. The Pentagon, citing a risk to national security from removing technology without effective replacement, also requested a waiver to the NDAA Ban on Huawei until effective technology could be sourced.130

The replacement of existing equipment and enabling new sources of battery technology will cost many more times the funding than the Huawei example, with the current stock of BESS installed being over \$10B of equipment. It is unlikely a replacement will be sourced rapidly despite investment. Therefore, following a similar path to the FCC's rip and replacement of Huawei is likely to be ineffective.

Technical Solutions

Solution Stakeholders and Targets

Manufacturers: Manufacturers are an important aspect of BESS supply chain security that impacts many downstream systems. Recent efforts have sought to increase domestic manufacturing of critical BESS components, which in turn increases U.S. jobs. Although the direct impacts of such a strategy are beneficial to communities in the short term, if not carefully managed over time, domestic manufacturing plants can introduce long-term dependencies on foreign entities and technologies near the base dependencies within the BESS supply chain network. For example, several domestic manufacturing sites for EVSE equipment components have the potential to provide U.S. jobs at the expense of dependence on business processes and technologies under foreign influence. Tesla is currently working on a factory to manufacture and operate CATL batteries domestically.131

In addition, Ford recently halted work on a \3.5B EV battery factory which included \1.7B in state incentives and could have employed approximately 2,500 workers.132 133 134

Integrators: Integrators and O&M service providers offer opportunities for long-term, indirect influence over a BESS site. Integrators integrate the technical and physical infrastructure that enables decentralization of the ownership, operations, and maintenance in BESS systems. As acknowledged within CATL's December 2023 rebuttal to security concerns, integrators “manage connections to the grid and the grid operators set up an additional layer of security measures."135

Operations and Maintenance: O&M activities also provide an opportunity for long-term influence over BESS. For example, Sungrow pivoted from being a supplier of BESS components for the Chisholm Grid in Fort Worth, Texas, to providing maintenance under a long-term service agreement. This privately funded project, not dependent on federal funding, falls outside of the scope of the NDAA and BABA. Furthermore, Sungrow components were purchased for the Revolution project in Texas136 via a \$92M tax equity investment enabled via the Inflation Reduction Act.137 138 Table 13 highlights some of the riskier scenarios and the correlating potential policy and technical solutions.

Table 13. Scenarios and correlating solution policies and technical approaches. <table><tr><td colspan="1" rowspan="1">Risky Scenario</td><td colspan="1" rowspan="1">Solution Policy</td><td colspan="1" rowspan="1">Solution Technical</td></tr><tr><td colspan="1" rowspan="1">PRC integrator/PRCequipment</td><td colspan="1" rowspan="1">Firmware AnalysisCommunications BanEquipmentBan/SanctionsAOO is not the integratorFOCI requirement tooperate/maintainwarranty batteries in U.S.Tariffs on control andmost consequentialequipment</td><td colspan="1" rowspan="1">Full hardware/software/AOO is not the integratorSecure communicationsresearch</td></tr><tr><td colspan="1" rowspan="1">Non-U.S. Integrator/PRCEquipment</td><td colspan="1" rowspan="1">Firmware AnalysisCommunications BanEquipmentBan/SanctionsAOO is not the integratorFOCI requirement tooperate/maintainwarranty batteries in U.S.Tariffs on control andmost consequentialequipment</td><td colspan="1" rowspan="1">IR plan framework withthird-party battery owner-operators</td></tr><tr><td colspan="1" rowspan="1">U.S. integrator/PRCEquipment</td><td colspan="1" rowspan="1">Firmware AnalysisCommunications BanEquipmentBan/SanctionsSecure by Design inSoftware andInterconnection</td><td colspan="1" rowspan="1">IR plan framework withthird-party battery owner-operators</td></tr><tr><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">FOCI requirement tooperate/maintainwarranty batteries in U.S.</td><td colspan="1" rowspan="1"></td></tr><tr><td colspan="1" rowspan="1">U.S. integrator/U.S.equipment</td><td colspan="1" rowspan="1">Secure by Design inManufacturing</td><td colspan="1" rowspan="1"></td></tr></table>

Cyber-Informed Engineering (CiE) and Technical Assistance Programs

CIE is an innovative approach developed by DOE CESER, INL, and NREL to integrate cybersecurity principles into the engineering life cycle. This challenges practitioners to go beyond the traditional IT-centric perspective of cybersecurity to embed security considerations and engineered controls directly into the design, operation, and maintenance of industrial control systems and OT. The goal is to achieve a cybersecurity protection scheme from both engineering controls and digital controls as well as to ensure that cybersecurity is not just an afterthought but an intrinsic part of the engineering process; all of this is further encouraged in the Cyber-informed Implementation Guide139 140.

CiE focuses on identifying and protecting against high-consequence events that could result from cybersecurity adversaries exploiting the digital components of process systems. It emphasizes a proactive and preemptive strategy, whereby potential pathways for cyberattacks are eliminated or mitigated during the design phase. This strategy reduces the likelihood of successful exploitation which could impact critical operations.

Existing federal secure-by-design initiatives141 could focus upon long-term needs for key software packages and global adherence to better standards, whereas CiE can provide direct engineering solutions for existing integrations and guidance for interconnection.142 In a subsequent BESS report, we will delve further into the application of CiE for protecting BESS.

Strategic Component Assessment

A Strategic Component Assessment initiative entails evaluating critical components and systems within the energy supply chain to identify potential vulnerabilities and risks and should focus on the prioritized components of the BMS, inverters, and PCS. This involves employing metrics and methodologies to assess the cybersecurity of various components, including supply chain dependencies, reliability, and resilience. If a battery is designated as FEOC, measures will be taken to ensure that the inverter is not similarly affected. Collaboration with integrators will facilitate adjustments to component models and configurations to align with cybersecurity requirements and mitigate supply chain risks.

Standards and Regulations

BMS, inverters, and PCS are combinations of hardware and software. Development of U.S.- controlled, secure software packages in addition to non-domestic components can mitigate risk significantly and enable continued operation in adverse conditions. The development of standards for renewable energy and power electronics can sometimes lag technological advancements, posing challenges for their widespread adoption. Key standards in progress include IEEE 1547.3 for energy storage integration.143 UL 2941 for system safety,144and SunSpec Modbus for communication protocols.145 Despite their importance, standards development can be slow due to consensus-building and regulatory processes. Nonetheless, these standards are vital for ensuring safety, reliability, and interoperability in renewable energy systems. Collaboration among stakeholders is crucial to expedite the development and implementation of these standards, keeping pace with evolving technologies. Additionally, scale-up of testing “in country” would be required.

Develop Hardware and Firmware Citizenship

The Develop Firmware and Hardware Citizenship initiative focuses on the security and integrity of firmware and hardware components within energy infrastructure systems through proactive measures. This initiative includes replacing parts during installation to ensure authenticity and mitigate the risk of compromised hardware. Additionally, a process is implemented wherein firmware is validated upon installation or update, enabling the detection and removal of any malicious or faulty firmware components. Furthermore, extra monitoring systems are installed for critical components, such as fire and environmental condition sensors, to provide real-time monitoring and early detection of abnormalities or potential security threats.

Most-Critical Location Analysis

Installation should be optimized for "non-FEOC non-waivered" equipment, particularly in critical locations or functions. For example, in hospitals or high-risk regions where functions are essential for emergency response, no waivers should be granted, even if higher costs

result. By prioritizing the security of critical infrastructure, this approach ensures greater resilience against cyber threats and enhances emergency preparedness.

Long-Term Strategic Monitoring and Information Sharing

Advanced sensors in key sites can be strategically placed to evaluate data in near-real-time and historical contexts, establishing a Renewable Energy Security Operations Center, or integrating with the DOE Energy Threat Analysis Center (ETAC). This allows for enhanced monitoring capabilities and documentation of sources.

Contracting and Procurement Guides

Outline procedures for evaluating vendors, negotiating contracts, and implementing cybersecurity clauses to ensure suppliers meet specified security standards. By standardizing contracting and procurement practices, organizations can enhance the security of their supply chains and mitigate risks associated with third-party vendors.

Long-Term Supply-Chain Moves: Relocating or building capacity to produce control equipment onshore or in allied locations to enhance cybersecurity resilience. Effective risk mitigation strategies can reduce the risk of high-consequence events without requiring total replacement or redesign of existing systems. By focusing on protecting the core functions of the BESS, operators and utilities can feel confident in their reliance on BESS, even with the presence of untrusted components.

To achieve this goal, several key steps need to be taken:

Cost Assessment: Conduct a thorough evaluation to determine the financial implications of moving control equipment onshore.

Identification of Components: Identify which components, from a technical consequence and techno-economic analysis of the control equipment need to be relocated onshore.

• Prioritization Based on Security and Consequence: Prioritize components based on their security implications and potential consequences of supply chain disruptions.

• Focus on Techno-Economic Factors: Emphasize a holistic approach that considers both technical and economic factors in decision-making and policy.

Key Programs for Solutions

DOE and the national laboratories offer several management best practices and mitigation measures that can be applied to currently installed projects or projects under development (Figure 29Figure 29).

•CESER is working to address existing systems with a CIE strategy (see previous section). In this approach, systems are evaluated to understand the largest possible impact of malicious cyber activity, and engineering controls are put in place to mitigate the impact of these high-consequence events.

GDO is utilizing tools developed through IIJA and in partnership with CESER to support and assist more robust security measures being placed around systems currently under development. As organizations apply for funding from GDO to support new projects, GDO can offer applicants CIE resources, including a playbook for applying CiE to BESS systems, complete with recommended controls, to help them mitigate the risk of their proposed systems. GDO is releasing procurement guidance and contracting language, a key risk factor for integration, and will be partnering with other offices to extend these comprehensive solution sets in the coming months.

The national laboratories have advanced subject matter expertise in supply chain and component analysis. Through programs like Cyber Testing for Resilient Industrial Control Systems (CyTRiCS), risks or vulnerabilities associated with specific equipment can be discovered, and appropriate responses or mitigations put in place. CyTRiCS leverages best-in-class test facilities and analytic capabilities at six DOE National Laboratories and strategic partnerships with key stakeholders to perform expert testing, share information about vulnerabilities in the digital supply chain, and inform improvements in component design and manufacturing.

Figure 29 - List of DOE programs relevant to securing BESS.

1. Cyber Informed Engineering-https://www.energy.gov/ceser/cyber-informedengineering

a. Products in IBR, Interconnection, Microgrids, and BESS to guide secure configuration

2. Cyber Testing for Resilient Industrial Control Systems (CyTRICS) – https://cytrics.inl.gov/

3. Energy Cyber Sense -https://www.energy.gov/ceser/energy-cyber-sense-program

a. Principles Targeted as Guidelines for IBR and BESS Manufacture

b. Analysis and Assessment Combined

4. Cyber Labeling (Inverters) -https://energy.sandia.gov/programs/electricgrid/cyber-security-for-electric-infrastructure/cyber-labeling-research-initiative/

5. CECA -https://www.nrel.gov/security-resilience/cybersecurity-accelerator.html

6. DER AI Work -https://www.energy.gov/ceser/articles/doe-announces-39-millionresearch-funding-enhance-cybersecurity-clean-distributed

7. Liberty Eclipse -https://www.energy.gov/ceser/liberty-eclipse a. Battery Assessments in GMLC

8. CyberStrike (STORMCLOUD) -https://inl.gov/national-security/cyberstrike/

9. Energy Threat Analysis Center (ETAC) - https://www.energy.gov/ceser/energythreat-analysis-center-0

10.RESCUE -https://www.energy.gov/ceser/articles/doe-nrel-and-clean-energyindustry-stakeholders-partner-address-cybersecurity-hybrid

11.CESER OT Defender - https://otdefender.inl.gov/

12.Cyber Security through Hardware Integration, Education, and Layered Defense (CyberSHIELD) -https://resilience.inl.gov/inlcybershield/

13.GDO TA for GRIP -https://www.energy.gov/gdo/grid-resilience-and-innovationpartnerships-grip-program-technical-assistance-resource-center

14.CESER BESSIE – development of strategic mitigations for BESS security challenges

Summary and Conclusions

This report describes a detailed examination of battery supply-chain risks and the complex interplay between energy security and sustainable energy transition within the United States. Key findings include the following:

1. Supply Chain Analysis: The evaluation of regional battery system functionalities and their security considerations highlighted the importance of understanding and adapting to local market demands and grid challenges. The diversity of utility models across regions necessitates tailored strategies for ownership and operation.

2. Legislative Impact: The influence of the NDAA for Fiscal Year 2023146 and related legislation, on the battery supply chain was identified as a critical factor in shaping future supply-chain strategies.

3. Cybersecurity Integration: The adoption of CiE methodologies emerged as essential for embedding cybersecurity in the life cycle of battery systems, from design through operation.

4. Geopolitical Concerns: Incidents involving FEOC and reports of cybersecurity threats in the energy sector underscore the geopolitical complexities affecting the supply chain. These events necessitate a vigilant and responsive approach to supply-chain management.

5. Supply-Chain Diversification: The report advocates for a compartmentalized strategy in supply-chain management, prioritizing the components deemed highest risk or most impactful on control and communication systems.

6. Consequence-Based Prioritization: A modular consequence-based assessment framework was employed to prioritize supply-chain components and, in turn, influence strategic manufacturing and security decisions.

7. Recommendations for Resilience: A set of strategic initiatives was proposed, targeting both immediate and long-term mitigation strategies to address supply-chain vulnerabilities. These initiatives were evaluated against their cost implications and potential to enhance FEOC.

8. Operational and Regional Consequence Assessment: The report highlighted the need to address consequences sensitive to regional and seasonal variations, who and what the battery is serving, and the availability of emergency resources.

Appendix A: BESS Components and Functions

Table 14. BESS components and their functions. <table><tr><td colspan="1" rowspan="1">Component</td><td colspan="1" rowspan="1">Description</td><td colspan="1" rowspan="1">Function</td></tr><tr><td colspan="1" rowspan="1">Cell</td><td colspan="1" rowspan="1">Electrochemical cells,cathodes, and anodes</td><td colspan="1" rowspan="1">Primary electrochemical reaction</td></tr><tr><td colspan="1" rowspan="1">Module</td><td colspan="1" rowspan="1">Collection of cells</td><td colspan="1" rowspan="1">Combines cells to make a deployable unit within thebattery at the right voltage</td></tr><tr><td colspan="1" rowspan="1">Pack</td><td colspan="1" rowspan="1">Collection of modules withfire suppression and BMSintegrated</td><td colspan="1" rowspan="1">Modules, which connect to supply the kW needed for thepack</td></tr><tr><td colspan="1" rowspan="1">System</td><td colspan="1" rowspan="1">Integrated multiple packsfor larger sites</td><td colspan="1" rowspan="1">Can contain BMS, EMS, PCS Transformers and Inverters– along with the packs, cells and modules – the systemis the grid connected piece</td></tr><tr><td colspan="1" rowspan="1">PCS</td><td colspan="1" rowspan="1">Power control/conversionsystem</td><td colspan="1" rowspan="1">Used to connect the inverter and the BMS, often used inDC coupled systems to couple – also to help with chargeand discharge regulation</td></tr><tr><td colspan="1" rowspan="1">Inverter</td><td colspan="1" rowspan="1">Power conversion and gridconnection</td><td colspan="1" rowspan="1">Sometimes combined with PCS, converts DC to AC, tosynchronize with the electric grid, can be grid forming,can control charge rates or switch</td></tr><tr><td colspan="1" rowspan="1">BMS</td><td colspan="1" rowspan="1">Battery managementsystem</td><td colspan="1" rowspan="1">Connects cell measurements to control on state ofcharge and safety against overcharge, state of healthand state of charge, along with environmental sensing.Can actuate the fire protection and other protection forthe cells, primary purpose is safety controls.</td></tr><tr><td colspan="1" rowspan="1">EMS</td><td colspan="1" rowspan="1">Supervisory control</td><td colspan="1" rowspan="1">Overarching management of the system and combinationof sensors and components. Above the PCS and Inverters– not always present</td></tr><tr><td colspan="1" rowspan="1">Transformer</td><td colspan="1" rowspan="1">Voltage step up or stepdown</td><td colspan="1" rowspan="1">Can be combined with the PCS and Inverter in variouscases</td></tr><tr><td colspan="1" rowspan="1">FleetController</td><td colspan="1" rowspan="1">Controls multiplesites/systems</td><td colspan="1" rowspan="1">Overarching monitoring of all BESS in an owner's fleet orsphere of operations</td></tr><tr><td colspan="1" rowspan="1">FireSuppression</td><td colspan="1" rowspan="1">Suppresses fire</td><td colspan="1" rowspan="1">Mechanical actuation of fire protection based onresponse from BMS and other sensing</td></tr><tr><td colspan="1" rowspan="1">Modem</td><td colspan="1" rowspan="1">A device that modulatesand demodulates signals</td><td colspan="1" rowspan="1">Facilitates communication between a computer or digitaldevice and an internet service provider, enabling internetconnectivity</td></tr><tr><td colspan="1" rowspan="1">Cloud</td><td colspan="1" rowspan="1">Remote servers accessedover the internet</td><td colspan="1" rowspan="1">Provides scalable and flexible storage, computingresources, and services to users and organizations.</td></tr><tr><td colspan="1" rowspan="1">DERMS</td><td colspan="1" rowspan="1">Software platform formonitoring and controllingdistributed energyresources</td><td colspan="1" rowspan="1">Optimizes the operation of resources like solar panelsand energy storage systems to enhance grid stability andefficiency</td></tr><tr><td colspan="1" rowspan="1">DO/ADMS</td><td colspan="1" rowspan="1">Software platform formanaging the distributiongrid</td><td colspan="1" rowspan="1">Monitors, analyzes, and controls grid operations in realtime, improving asset performance and grid reliability</td></tr></table>

Appendix B: Consequence Ranking and Scoring

Each consequence is weighted, and the impact is ranked and then scored using the CCE methodology. List of consequences include:

• Load Impact (O to Bulk)

• Duration of Load Impact (0 to over 3 days)

• Safety Human (0 to death)

• Safety Fire/Discharge (0 to wildfire)

• System Cyber Integrity (0 to complete loss of trust)

• Cost (0 to bankruptcy)

• Environmental Damage

• Climate Change

• Single Site Does Not Perform/performs the opposite action

•Geographically/Grid Local/State Fleet Does Not perform

• Geographically dispersed

Table 15. Example of a consequence matrix. <table><tr><td colspan="1" rowspan="1">Service</td><td colspan="1" rowspan="1">Timeframe</td><td colspan="1" rowspan="1">Normal</td><td colspan="1" rowspan="1">Strained</td><td colspan="1" rowspan="1">Emergency</td><td colspan="1" rowspan="1">Associated InverterCapability</td></tr><tr><td colspan="1" rowspan="1">Arbitrage</td><td colspan="1" rowspan="1">Hours</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">一</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">Price signal response</td></tr><tr><td colspan="1" rowspan="1">Operating Resource (OR) -Primary frequency response</td><td colspan="1" rowspan="1">4+ Hrs</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">一</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">Price signal response</td></tr><tr><td colspan="1" rowspan="1">OR - regulation</td><td colspan="1" rowspan="1">seconds</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">Frequency andvoltage droop control</td></tr><tr><td colspan="1" rowspan="1">OR - contingency spinning</td><td colspan="1" rowspan="1">15 min - 1hr</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">Voltage andfrequency reference</td></tr><tr><td colspan="1" rowspan="1">OR -replacement/supplemental</td><td colspan="1" rowspan="1">30 in to 2 hr</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">Virtual generatorinertia</td></tr><tr><td colspan="1" rowspan="1">OR - ramping/load following</td><td colspan="1" rowspan="1">hrs</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">Utility support mode</td></tr><tr><td colspan="1" rowspan="1">T + D Deferral</td><td colspan="1" rowspan="1">30 mins tohrs</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">Utility support mode</td></tr><tr><td colspan="1" rowspan="1">Black Start</td><td colspan="1" rowspan="1">hrs</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">Real power vs.reactive powerlimiting</td></tr><tr><td colspan="1" rowspan="1">Exceptional Discharge</td><td colspan="1" rowspan="1">hours</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">Black start/gridforming</td></tr></table>

Appendix C: Critical Component Prioritization

Using Table 16 shown below, the total score for each component has been calculated to determine its impact of misoperation and assign a priority to the consequence of the function marked in top row. This is then used to prioritize the most critical components for style of solutions that can be applied to secure them in both the short and long term. This is performed for a single site or BESS initially.

Table 16. Categorization of BESS components and their capabilities. <table><tr><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">Comms</td><td colspan="1" rowspan="1">Charge /DischargeControl</td><td colspan="1" rowspan="1">On1OFF</td><td colspan="1" rowspan="1">Gen –incremental</td><td colspan="1" rowspan="1">EquipmentSafety</td><td colspan="1" rowspan="1">LifeSafety</td><td colspan="1" rowspan="1">CyberAccessPotentialto ImpactOtherFunctionsin BESS</td><td colspan="1" rowspan="1">Cyber AccessPotential MassControl/Orchestration</td></tr><tr><td colspan="1" rowspan="1">Device (SingleSite)</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td></tr><tr><td colspan="1" rowspan="1">Battery modules,packs &amp; cells</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td></tr><tr><td colspan="1" rowspan="1">Power conversionsystem/Inverters(PCS)</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td></tr><tr><td colspan="1" rowspan="1">Inverter</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">X</td></tr><tr><td colspan="1" rowspan="1">Batterymanagementsystems (BMS)</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td></tr><tr><td colspan="1" rowspan="1">Environmentalcontrol system(heating,ventilation and air-conditioningsystem)</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td></tr><tr><td colspan="1" rowspan="1">Fire suppressionsystem or firecontrol system</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td></tr><tr><td colspan="1" rowspan="1">Transformer</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td></tr><tr><td colspan="1" rowspan="1">Human-machineinterface (HMI)</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1"></td></tr><tr><td colspan="1" rowspan="1">Electricaldisconnects, circuitbreakers, andswitches(protection)</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1"></td></tr><tr><td colspan="1" rowspan="1">Communicationsnetworkingswitches andcables.</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1"></td></tr><tr><td colspan="1" rowspan="1">Modem</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td></tr><tr><td colspan="1" rowspan="1">Site Controller(single site)/EMS</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1">X</td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td><td colspan="1" rowspan="1"></td></tr></table>

研报原文

正文为转写文本,图表、公式与印章以 PDF 为准。

下载研报原文(PDF)