KEY TAKEAWAY
What this means for solar-lighting buyers and project teams.
Connected inverters, battery systems and solar-lighting controllers should be bought as managed systems, not as isolated hardware. SEIA's new material on inverter and supply-chain cybersecurity is a timely prompt to document remote access, account ownership, update paths and incident responsibilities before equipment is commissioned.
What SEIA published
The Solar Energy Industries Association has published a factsheet addressing inverter and supply-chain cybersecurity. SEIA describes the document as identifying existing cybersecurity standards and best practices, with scope spanning both inverter and supply-chain risk.
The publication is guidance, not proof that a particular inverter or controller is secure. Nor does a vendor's reference to the factsheet establish that its product has been assessed against a defined standard. The valuable procurement response is to request evidence for the actual equipment, software release and service model being offered.
Remote access is a project requirement
Modern solar assets commonly use cloud portals, mobile applications, firmware updates and installer accounts. Standalone solar lighting may use the same patterns for dimming profiles, fault alerts, energy monitoring or fleet management. Each connection introduces questions about who can log in, what they can change, where data is stored and how access is removed when a contractor changes.
A specification should therefore identify the required operating modes during loss of connectivity, the minimum user roles, multi-factor authentication where available, audit logs, credential handover and a process for urgent security updates. It should also state whether the owner can operate safely if a vendor portal is unavailable or a communications service ends.
Supplier due diligence should be evidence-led
Ask bidders to map the supplied hardware, firmware, cloud services and subcontractors. Request a supported-software policy, vulnerability-reporting route, update and rollback process, end-of-support date and incident notification commitment. These are procurement controls, not guarantees that no vulnerability will occur.
For a public project, clarify who authorises remote changes to lighting schedules, battery limits or inverter settings. Require commissioning records to show the final firmware version, enabled communications paths and named owner accounts. Default credentials, undocumented shared installer accounts and vague claims of 'encrypted' communications should not pass acceptance without detail.
Buyer impact: include cyber controls in handover
Security is most effective when designed into scope, rather than added after devices are installed. Make cyber deliverables part of technical submittals, factory acceptance where appropriate, site commissioning and warranty support. Align them with electrical safety, data protection and local critical-infrastructure obligations that apply to the project.
The SEIA material is a useful starting point for connected-energy procurement. It does not replace a project-specific risk assessment, but it supports a practical rule: buy documented operational control, not just a connected feature list.
FREQUENTLY ASKED QUESTIONS
Questions this industry update may raise
Does SEIA guidance certify an inverter?
No. Guidance can inform procurement, but certification and security evidence must be checked for the specific product and deployment.
What should happen to installer access at handover?
The owner should receive named accounts and control of credentials, while any continuing contractor access is documented, limited and removable.
Why does this matter for solar lighting?
Networked lighting controllers can change operating schedules and report faults, so their access, updates and support arrangements affect field operation.
SOURCES

