The US energy grid runs on a paradox: the more critical the infrastructure, the less we audit its components. On May 2026, President Trump signed an executive order targeting foreign equipment risks in the US energy grid. The media coverage was thin—five bullet points, no specifics. No list of targeted countries. No equipment types. No compliance timeline. But based on my audit experience, this is where the real story begins. This isn't a trade policy. It's a security admission.
Context: The US grid's dependence on imported large power transformers is a known vulnerability. Roughly 80% of large power transformers are imported, with China accounting for about 20% of that share. The executive order, framed as a national security measure, aims to reduce this dependency. The immediate logic is supply chain resilience. The deeper logic, however, is about something far more uncomfortable: the possibility of a foreign actor holding a kill switch to American infrastructure.
Core: Let's break down the technical reality. The executive order targets not just transformers but the entire ecosystem of grid control: SCADA systems, high-voltage switches, and substation automation. From a security auditor's perspective, this is the right target. SCADA systems are the nervous system of the grid. A compromised SCADA device is not a supply chain issue; it's a remote code execution vulnerability in the most critical infrastructure in the country.
Here's the data point that matters: the US domestic transformer manufacturing capacity meets only about 20% of current demand. The average lead time for a new transformer is now 2-3 years. This isn't a hypothetical bottleneck; it's a measured one. The executive order, if enforced strictly, would force utilities to replace foreign-sourced equipment faster than domestic manufacturers can produce replacements. The math doesn't lie: you cannot mandate domestic production without first solving the production capacity problem. In my audits, I've seen this pattern repeatedly—a security mandate issued without a feasibility study creates a worse security posture in the interim.
The second layer is raw materials. Transformers require electrical steel, or grain-oriented electrical steel (GOES). China produces roughly 60% of the world's GOES. The US produces about 5%. Even if you build a new transformer plant in Ohio, you still need the steel. And the steel supply chain is Chinese. This is the same structural flaw I found in the bridge protocols I audited in 2022: the surface layer is decentralized, but the underlying dependency is single-point-of-failure. You can replace the assembly line, but not the input material. Security is not a feature; it is the foundation. And this foundation is made of Chinese steel.
Contrarian: The conventional narrative is that this executive order is about China. It's not. It's about the US's own blind spot. For years, US utilities have optimized for cost and speed, buying cheaper transformers from overseas. This is a classic security debt accumulation. The executive order is a response to a threat that has been visible for a decade, but the response is reactive, not proactive. Here's the uncomfortable truth: the order may create more vulnerabilities than it fixes. By forcing a rapid transition without addressing the raw material dependency, the US may end up with a grid that is domestically assembled but still foreign-sourced in its critical components. Trust the code, verify the trust—in this case, the code is the supply chain, and the verification is the raw material provenance. We're not doing that verification.
The deeper blind spot is cyber. The order likely targets hardware, but the grid's software layer—the protocols, the monitoring systems, the data flows—is equally exposed. I've spent years auditing smart contracts, and the same logic applies here: the attack surface isn't just the physical device; it's the entire communication stack. A transformer with a Chinese chip is a risk. But a SCADA system running unpatched software is a certainty. The executive order, if it only addresses hardware, will leave the software layer exposed. That's a critical gap.
Takeaway: This executive order is a signal, not a solution. It acknowledges a dependency that should have been addressed years ago. The real question is whether the US can execute a supply chain migration without creating a new set of vulnerabilities. The next 24 months will determine if this is a genuine security improvement or just a geopolitical gesture. In my line of work, we say a bug fixed today saves a fortune tomorrow. But this bug was identified decades ago. The question now is whether the fix will be worse than the disease. The grid's security depends on it.