September 2026 /

Cybersecurity in Battery Energy Storage Systems

Energy Storage Europe welcomes the European Commission's growing focus on cybersecurity in the energy sector and supports the direction of travel across the Cyber Resilience Act (CRA), the Network Code on Cybersecurity, and the proposed Cybersecurity Act (CSA) 2.0. Yet raises concerns that require targeted corrections to ensure these frameworks deliver on their security objectives without inadvertently slowing battery storage deployment.

Battery Energy Storage Systems (BESS) actively regulate the grid in real time. They are not inherently more vulnerable than other grid-connected technologies; but their combination of deep cyber-physical coupling, multi-vendor architectures, and third-party control dependencies creates a governance challenge where control-layer failures can escalate rapidly to grid-stability events. With BESS hitting 50 GW installed with 200 GW projected by 2030, cybersecurity risks are no longer isolated asset-level concerns.

The current EU framework does not yet provide a coherent approach to BESS cybersecurity risks. Important accountability gaps remain, particularly for legacy assets, outsourced operations, special purpose vehicle structures, and manufacturers without an EU legal entity. Divergent implementation of NIS2 and inconsistent connectivity requirements across Member States increase compliance costs, create unnecessary complexity, and slow project deployment. This is particularly burdensome for battery storage; a technology manufactured at scale through highly standardised global supply chains. As the supply chain framework under the Cybersecurity Act 2.0 continues to develop, the Industry calls for a clear, risk-based, and component-level approach to cybersecurity requirements, with proportionate obligations and realistic implementation timelines that support both resilience and investment.

Contact

Not a member yet ?

Explore the benefits of joining Energy Storage Europe

Learn More About Membership

Publications