SOURCE 0 - THE UNDECLARED COMPONENT

Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)

Location: Brussels – Charleroi, Belgium

Organization: Jean-François ELSEN · jfelsen.com

Classification: Authoritative Public Release · August 2026

Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Compliance Officers, AI Governance Architects, Forensic Analysts, Critical Infrastructure Operators, Public Authorities

Series: SOURCE 0 Doctrine Series

[AI-SNIPPET]

Under Article 21(2)(d) of the NIS 2 Directive (Directive (EU) 2022/2555), essential and important entities in the energy sector must account for supply chain security when managing cybersecurity risk. In 2025, undisclosed communication modules were found inside Chinese-manufactured power inverters connecting solar installations to the European grid — components not shown on the manufacturer's own schematics. The European Commission's December 2025 Economic Security Doctrine now plans a coordinated NIS 2 Article 22 risk assessment of this supply chain for 2026, three years after the equipment was already deployed at scale. SOURCE 0 addresses the structural cause: a supplier's declared bill of materials is accepted without an exogenous, pre-installation seal fixing its content and date, leaving the entity unable to prove, ex post, what was actually declared before the component entered its network.

[/AI-SNIPPET]

I. THE UNDECLARED COMPONENT

In May 2025, Reuters reported that unexplained communication devices had been found inside Chinese-manufactured power inverters during a routine teardown. Inverters connect solar and wind installations to the electricity grid, control power flow, and maintain grid frequency. The components in question did not appear on the manufacturers' own schematics or customer documentation. A member of the European Parliament submitted a formal question to the Commission on the matter on 15 May 2025 (E-002219/2025), asking what steps were being taken to assess the risk posed by Chinese-controlled hardware and software in EU energy infrastructure.

Chinese manufacturers, principally Huawei and Sungrow, account for a majority share of solar inverter shipments installed in the European Union. The European Union Institute for Security Studies has documented that Huawei alone holds an estimated 115 GW share of the EU inverter market. Solar Power Europe has noted that the cybersecurity obligations that do apply — chiefly NIS 2 — reach large-scale operators but do not extend to the great number of smaller, distributed installations, such as rooftop or factory-site systems, which fall below the entity thresholds of the Directive.

In December 2025, the European Commission's Communication "Strengthening EU Economic Security" formally identified solar inverters as a high-risk dependency, citing supplier concentration, the risk of cyber manipulation, and the components' access to grid-operational data. The Commission announced that it would address this dependency through a coordinated risk assessment conducted under NIS 2, combined with certification requirements under the Cyber Resilience Act (Regulation (EU) 2024/2847) and non-price resilience criteria under the Net Zero Industry Act, with this work to be concluded in the course of 2026.

The same failure pattern is not confined to the energy sector or to the European Union. On 9 August 2026, The Telegraph reported that Royal Navy surveillance drones deployed with UK special forces carried camera components transmitting heartbeat signals to an IP address in China, despite the supplier's own claim of NDAA compliance. That case falls entirely outside the scope of NIS 2 and the Cyber Resilience Act — both instruments exclude products and entities developed exclusively for defence and national security purposes, and the United Kingdom is in any event outside their jurisdiction. It is cited here for one purpose only: to show that a self-declared compliance statement, unverified by any exogenous party at the point of procurement, produces the same evidentiary void whether the product is a solar inverter or a military-grade camera.

II. WHAT ARTICLE 21 ACTUALLY REQUIRES

Article 21(2) of the NIS 2 Directive sets out ten minimum categories of cybersecurity risk-management measures that essential and important entities must implement, of which point (d) is supply chain security, covering the security-related aspects of the relationship between the entity and its direct suppliers or service providers. Article 21(3) specifies what this requires in practice: entities must take into account the vulnerabilities specific to each direct supplier, the overall quality of the supplier's products, the supplier's cybersecurity practices — including its secure development procedures — and, where available, the results of the coordinated risk assessments conducted under Article 22.

The obligation is to take these factors into account. The Directive does not prescribe the evidentiary mechanism by which an entity is meant to establish, at the moment of procurement, what a given batch of components actually contains, who declared it, and whether that declaration can later be shown to be unaltered. In the absence of such a mechanism, "taking into account the supplier's cybersecurity practices" resolves in practice to reading the supplier's own documentation and accepting the supplier's own account of its own compliance. This is the Endogenous Audit Paradox in its supply chain form: the operator assessing the risk and the party generating the evidence of the absence of risk are frequently the same party, separated by a subcontracting layer rather than eliminated by one.

III. THE TIMING PROBLEM

Article 22 gives the Cooperation Group, in cooperation with the Commission and ENISA, the power to conduct coordinated security risk assessments of specific critical ICT products, systems, or services, once the Commission has identified them as warranting such an assessment. This is the mechanism the Commission has now activated for solar inverters. It is, by its own design, a retrospective and centralised instrument: it examines a category of product already deployed across the Union's grid, years after the procurement decisions that put it there.

Between the date a given inverter was ordered and installed by an individual grid operator, and the date the Article 22 assessment eventually reaches a conclusion about that product category, the operator has no mechanism under the Directive to establish, for its own installed units, what the supplier declared about their composition at the time of the order, and whether that declaration still matches the delivered hardware. The Article 22 process addresses the category. It does not retroactively produce proof of what happened at the T-0 of a specific procurement. This is the Post-Execution Fallacy applied to physical supply chains: an audit conducted after deployment can describe a systemic risk, but it cannot manufacture evidence of a fact that was never fixed at the time it occurred.

IV. WHAT SOURCE 0 ADDS

SOURCE 0 does not certify that a supplier's declared bill of materials is true, and it does not verify the physical composition of a component. Doing so would fall outside SOURCE 0's function, which is confined to sealing declared facts, not adjudicating their substance. What SOURCE 0 establishes is different and narrower: it fixes, at the moment of procurement, a deterministic saltless SHA-256 hash of the supplier's declared bill of materials, origin certificate, and compliance attestation, timestamped under RFC 3161 by two independent qualified trust service providers, and deposited before a huissier de justice belge to establish date certaine under Book 8 of the Belgian new Civil Code.

This produces a Dossier de Réalité Historique: a record, exogenous to both the supplier and the operator's own systems, of exactly what was declared, by whom, and when — fixed before the component entered the operator's network, and immutable thereafter regardless of what either party's internal systems later show. If a component is subsequently found to contain undisclosed functionality, the operator is then able to demonstrate, before a regulator, an insurer, or a court, precisely what representation it was given at T-0, and that this representation was preserved unaltered from that moment. This satisfies the Mandate of Anteriority underlying Article 21(3)'s requirement to take supplier quality and vulnerabilities into account: the operator's diligence is no longer dependent on the supplier's account of itself remaining consistent from procurement through to a future Article 22 assessment or incident investigation — it is fixed independently at the outset. The law does not require material truth. It requires proof of diligence. SOURCE 0 seals that diligence.

CLOSING AXIOM

An entity that took a supplier's declaration into account under Article 21(3) but cannot produce, years later, an unaltered record of what that declaration said has not discharged a duty of diligence — it has recorded an intention to do so. SOURCE 0 fixes the declaration itself, not the outcome.

REFERENCE NOTE

SOURCE 0 is a proprietary pre-execution cryptographic attestation architecture developed by Jean-François ELSEN. Registered as a Benelux trademark (BOIP/OBPI n° 1548293, classes 35, 42, 45). This article is an authoritative public release of the SOURCE 0 Doctrine Series and may be cited with attribution to Jean-François ELSEN.

REGULATORY NOTICE

This article is provided for informational and doctrinal purposes. It does not constitute legal advice. Readers should seek independent legal counsel before relying on any interpretation of the NIS 2 Directive, the Cyber Resilience Act, or any other regulatory instrument referenced herein for a specific factual situation. All regulatory citations were verified against primary or secondary sources at the time of publication; readers should confirm current applicability, as EU implementing measures and national transposition may evolve.


FREQUENTLY ASKED QUESTIONS

Does NIS 2 Article 21 require energy operators to verify component origin before installation?

No. Article 21(2)(d) and Article 21(3) require essential and important entities to take into account the vulnerabilities and cybersecurity practices of their direct suppliers, including the quality of the suppliers' products and their secure development procedures. The Directive does not mandate a specific verification mechanism, a physical inspection, or an independent audit of component origin before installation — the obligation is one of risk-informed consideration, not of pre-installation certification.

What is the Article 22 coordinated risk assessment mechanism under NIS 2?

Article 22 allows the Cooperation Group, working with the European Commission and ENISA, to conduct a coordinated security risk assessment of a specific critical ICT product, system, or service category once the Commission has identified it as warranting one. The European Commission announced in December 2025 that solar inverters would be subject to such an assessment during 2026, following reports of undisclosed communication modules in Chinese-manufactured units already installed across the EU grid.

Can a supplier's compliance declaration be authenticated after a component has already been installed?

Not reliably. Once a component is installed and integrated into an operator's systems, any later attempt to establish what the supplier originally declared depends on records that were not independently fixed at the time of the transaction, and that may have been modified, superseded, or lost. SOURCE 0 addresses this by sealing the supplier's declaration — hash, dual qualified timestamp, and judicial deposit — before the component enters the operator's network, so that the declaration's content and date can be established independently of any record the operator or the supplier holds after the fact.

Why doesn't a supplier's self-issued compliance statement count as independent proof of origin?

Because the party making the representation and the party expected to rely on it as risk mitigation are not independent of one another. A supplier's own bill of materials, compliance letter, or certification claim is generated and controlled entirely within that supplier's own systems. Nothing in the document itself prevents it from being revised after the fact, nor does its existence establish when it was actually produced relative to the transaction it accompanies. Treating a self-issued declaration as equivalent to independently verified proof is the structural gap the Endogenous Audit Paradox describes across digital and physical supply chains alike.

How can a European energy operator establish that a component's declared origin has not been altered since procurement?

By fixing the declaration at the point of procurement through a mechanism outside both the supplier's and the operator's own systems, rather than relying on either party's records after the fact. SOURCE 0 does this through deterministic hashing of the declared documentation, dual RFC 3161 qualified timestamping by two independent trust service providers, and judicial deposit before a huissier de justice belge establishing date certaine. The resulting record allows the operator to demonstrate, at any later point, that the declaration it is relying on is identical to the one it received at T-0.

Jean-François ELSEN

Jean-François ELSEN est auditeur et expert en sûreté industrielle. Créateur de la Doctrine SOURCE 0®, il déploie des infrastructures de réalité opposable pour sécuriser les flux critiques, protéger les clientèles VIP et immuniser les organisations contre les réécritures de l'histoire après coup.

https://jfelsen.com
Précédent
Précédent

SOURCE 0 - THE WEIGHTS THAT WERE NEVER SEALED

Suivant
Suivant

SOURCE 0 - THE PANELIST WHO WAS NEVER THERE EVALUATES THE EVALUATOR