✅ Roughly speaking
- 🔐 The Agency for Natural Resources and Energy will require certain devices used for grid connection of distributed power sources such as solar and battery storage JC-STAR★1 This is thought to indicate a direction in which we are seeking to acquire it. Not just a recommendation, Practical requirements for lineage interconnections The fact that we are getting closer to this point seems important.
- ⚡ The target is not the power generation equipment itself, but the equipment used in it Devices with IP communication function Yes. Output control devices such as power conditioners (PCS, Power Conditioning System), battery management systems (BMS, Battery Management System), and energy management systems (EMS, Energy Management System), as well as remote monitoring devices and gateways, are envisioned.
- 🗓 The start of application is not uniform. Solar power and storage batteries are scheduled to be available in April 2027 for extra high and high pressure, October 2027 for low pressure, April 2027 for wind power (for the time being, early application limited to gateway firewalls, etc.), and April 2028 for fuel cells Read the target equipment and application period separately I believe it is essential.
- 🛠 Although existing facilities are not immediately applicable retroactively, Exchange and renewal situations Therefore, the new requirements could become a practical issue. Even if there are exceptions, they are not exemptions Reasons, evidence, transition plan, and immediate alternative measures It seems reasonable to read it as "conditional migration management" with.
Introduction
This time, the Agency for Natural Resources and Energy said, Cybersecurity measures for distributed power sources (Agency for Natural Resources and Energy) " (July 2026, Electric Power Infrastructure Development Division) will explain what cybersecurity measures will be required for distributed power sources such as solar, battery storage, wind, and fuel cells in the future. When it comes to re-energy, I think we tend to focus on issues such as power generation efficiency, grid constraints, FIP (Feed-in Premium), output control, and community coexistence "Risk management of the very nature of connected facilities" I also think that we will be unable to avoid passing through.
Regarding the overview of the JC-STAR system itself and its position in grid interconnection, long-term decarbonized power supply auction, subsidy, and contract practices, I wrote in my previous draft last month: Will JC-STAR become a new practical requirement for energy conservation projects " I organized it.
This article will avoid duplication as much as possible and will focus on more in-depth issues such as the identification of target equipment and the treatment and transition measures for existing equipment, in line with the Agency for Natural Resources and Energy's documents published in July 2026.
Frankly, I think the interesting thing about this material is that it elevates cybersecurity from "IT department talk" to "line connectivity talk." In other words, renewable energy equipment and batteries are not simply power generation and storage machines, but equipment that connects to the outside world through communication functions, and therefore Embedding minimum cyber requirements within the connection requirements This is the idea that has come to the forefront.
I won't go into detail about this article. We will focus on what is written in the materials and what can be naturally read from those materials. In practice, from a brave assertion, Distinguishing between what is definitive and what is speculative Because they ultimately believe they are strong.
What this document shows
First, let's assume that the official title of the document is "Cybersecurity Measures for Distributed Power Sources," and that it will be published in July 2026 by the Electricity Infrastructure Development Division of the Agency for Natural Resources and Energy. Just looking at the title, it looks like a general explanation, but the content is quite practical, and when it comes to connecting distributed power systems, Direction of making JC-STAR★1 label acquisition a requirement This clearly demonstrates this.
In this sense, I do not believe this document is an educational document that emphasizes the importance of cybersecurity. Rather, it should be read as a document intended to show the external design philosophy of which equipment, which devices, when and under what conditions it will be applied.
For those in the renewable energy industry, I feel this is a very important resource for understanding what is being emphasized in the preliminary stages of legal reforms and connection rule revisions.
Throughout this article, the facts are as follows: Cybersecurity measures for distributed power sources (Agency for Natural Resources and Energy) and can be referenced as a follow-up Cybersecurity in the Power Sector (Agency for Natural Resources and Energy) This is based on the description.
Why Distributed Power Supply Needs Cyber Protection Now
The problem with the materials is clear. As the deployment of distributed power sources and their connection to grids rapidly progresses, cybersecurity risks have been pointed out This sentence can be considered the starting point.
The important thing here is not to say that "reenergy is dangerous," The more distributed, communicating, and controlled equipment there is, the more targets there are to attack In a sense, this seems to be a natural reality, and it seems that we have begun to confront it head-on as a policy.
And the material does not escape into abstraction.
In addition to cyber attacks on distributed power sources overseas, vulnerabilities inherent in solar power monitoring devices have also been exploited domestically A case of being used as a stepping stone for cyber attacks This addresses the issue that is occurring.
I think the key word here is "stepping stone." Not only is there a risk that the equipment itself will be shut down, Risks that equipment could be a starting point for other attacks As a practitioner, I cannot overlook the point that is being made.
The document also mentions a cyberattack on the Polish power grid by the Federal Security Service (FSB).
This is not a sensational read, Policymakers are acutely aware of the significant impact that communication disruptions and disruptions to monitoring and control within the power grid, a social infrastructure, have on society as a whole It seems rather appropriate to read it in that context.
Where was the "vacuum" in the current system
Another important point I find in this document is that the policymakers themselves have made it clear that there were gaps in the existing system.
According to the document, the "Ministerial Ordinance Setting Technical Standards for Electrical Equipment" mandates cybersecurity measures for commercial electrical works of 50kW or more, Small-scale solar power generation equipment with less than 50kW Regarding this, the point is that under the Electrical Business Act, there was no clear technical standard provision specifically for ensuring cybersecurity.
I believe this point is quite significant, even from a practical standpoint.
Large-scale projects are often discussed in the energy industry, but in reality, Spread of small-scale facilities and large-scale connection of communication-enabled equipment It seems that this is precisely the aspect that creates new risks.
If that's the case, this move is not about suddenly introducing new strict regulations, Measures to fill areas that were not adequately covered by existing rules from the side of the system connection rules I believe it's natural to understand it as such.
The core of the system change. What is JC-STAR★1 requirement
The core of the document is about devices with IP communication capabilities, such as PCS and EMS, that will be newly connected via the system from April 2027 onwards Obtaining JC-STAR★1 as the minimum cybersecurity standard that must be ensured I believe that's the point.
The issue here is not the general theory of power generation equipment, Minimum safety of communication-enabled equipment used to connect to the system That allows us to organize it.
I think there are some interesting aspects to being future-oriented.
In previous renewable energy practices, the main issues were connectivity, output control, grid augmentation, certification, and FIP migration.
However, the more deeply distributed power sources are integrated as part of social infrastructure, the more the connectivity requirements become, not only for physical safety but also for other things Including cyber safety It is thought to be expanded into.
I feel that this document clearly indicates that direction.
In other words, this appears to be a shift from "security recommendations" to "security as a connectivity requirement."
The very center of gravity of the system is in motion.
Energy conservation companies and manufacturers believe it's best not to take this change lightly.
The target is not the entire equipment, but equipment with IP communication capabilities
This place is prone to misunderstandings, so I'd like to organize it a little more carefully.
Under the system, the facilities listed as eligible are solar power generation, battery storage, wind power generation, and fuel cells. On the other hand, the actual requirements are applied to those facilities Devices with IP communication capabilities Examples include output control devices such as PCS, BMS, and EMS, remote monitoring devices, and gateways.
Therefore, readings such as "all solar installations are covered" and "the panels themselves have labels" are not considered accurate.
The correct answer is, The problem lies in the equipment that can connect with the outside world through communication and participate in control and monitoring , I think that means.
This distinction is important at every stage of procurement, design, equipment renewal, and contract negotiations, and we believe that if the equipment is not properly identified, both the system's response and cost estimates will be misaligned.
Regarding fuel cells, the Agency for Natural Resources and Energy's relevant explanation states: This applies to models that use PCS, and also includes gas engines that are connected via PCS It is said that.
From this point on, it seems that the intention behind the system design is not to treat fuel cells in general in a one-way manner, but rather to target the communication and control contacts and enforce the requirements.
The start date of application is not uniform
Another important thing to consider is understanding the system The start date of application is divided by power source and category That's the point.
Solar power generation and storage batteries are categorized as high-voltage and high-voltage in April 2027, low-voltage in October 2027, wind power in April 2027, and fuel cells in April 2028.
The April 2027 application of wind power generation is currently limited to gateway firewalls (or equipment with equivalent defensive capabilities), and does not apply to all wind power systems at once ( Cybersecurity measures for distributed power sources (Agency for Natural Resources and Energy) ).
It seems natural to read that this difference reflects both policy priorities and market realities.
The difference of six months for low-pressure solar and battery storage is Consideration for distribution inventory, etc I understand that this perspective is at the background.
While the term "system" is often used in black and white, in practical terms, consideration is absolutely necessary for inventory, guarantees, existing contracts, and the timing of equipment renewal. In that sense, I believe that this system is designed with a sense of feasibility in mind, even if it is somewhat strict.
Also, the official explanation is, When applying for a contract with a general power transmission and distribution company The new requirements are said to be a problem.
This is not simply a general regulation of products on the market; Requirements confirmed at the stage of the route connection procedure It should be read as follows.
What will happen to the existing facilities (it's dangerous to read this here)
The official explanation for the existing facilities is quite clear.
For eligible equipment for which contract applications have been received by the end of March 2027, or for eligible equipment already in use in existing eligible equipment, the new requirements will not be applied retroactively, preventing immediate grid connection , is considered the general way of organizing things. First of all, I think it's okay for you to stay calm here.
However, once you're done with peace of mind, you'll get the impression that you've only read half of it, honestly speaking.
The same official explanation is From April 2027 onwards, when replacing equipment in existing equipment under new requirements In principle, the use of JC-STAR★1 acquired products is required.
In other words, existing facilities are not outside the system; Through the time axis of exchange and renewal, it will eventually enter the system I can understand that.
Furthermore, it is explained that replacing the equipment in question, even if it is the same equipment, is not treated as a "minor change."
We believe this is an area that is difficult for departments in O&M (Operation & Maintenance), equipment maintenance, and asset management to overlook. The selection of replacement components can directly lead to connection practices and legal adjustments.
Exception
I believe the system focuses not only on principles but also on the actual equipment situation.
If you request to replace your existing equipment with a JC-STAR★1 product due to compatibility issues, etc When the business operator is burdened with excessive costs, such as when other equipment needs to be replaced extensively This is because, under certain conditions, there is room for exchange for unacquired products and immediate use.
However, I want to emphasize here that I don't think this is simply an exemption.
After consulting with the general power transmission and distribution operators in the area, Plan in the prescribed format The plan requires the submission of at least three elements:
Firstly, there's the reason why it's difficult to replace the acquired product at that point.
Secondly, after indicating the planned year for extensive repocing or repowering (Repowering), all of the equipment to be replaced will ultimately be considered acquired products.
Thirdly, in the meantime, we need to implement certain cybersecurity measures.
Looking at this design, I feel that the system's concept is quite consistent.
In other words, we respect the circumstances that make it difficult to fully adapt at this time.
But instead, Provide reasons, provide evidence, promise a future timing of fit, and take alternative measures in the meantime That's what I'm asking for.
To be frank as a practitioner, this is not so much a "flexible exception" as it is a " Conditional migration management It seems more accurate to understand that this is the case.
What is "excessive burden"
In relation to exceptions, many readers will be concerned about what constitutes an "excessive burden."
The official explanation even includes specific examples of what is expected.
When a faulty PCS is replaced with a product that meets the new requirements, the equipment can no longer be used as before due to differences in compatibility with existing old PCSs, transformers, etc., or differences in set voltage If the transformer or the entire PCS needs to be replaced This is because the following is an example.
Other examples include extended warranty agreements concluded by the end of March 2026, and situations where it is difficult to exchange the product for a compatible product due to the relationship with replacement products already purchased or held in order to continue the business.
The system officials also said that the problems facing the field are not just "costs" Compatibility, warranty, existing stock, equipment outage risk, business continuity It appears you understand that this spans multiple areas.
Conversely, it seems that simply claiming these are abstractly "hard" is not enough; we need to be prepared to specify where, how much, and what kind of problems they will cause.
It is believed that the institutional response will not end with simply obtaining labels
I think this is also an important point.
The official explanation is to businesses operating existing equipment: "Guide to Supply Chain Security Measures for Power Control Systems" , "Guide to Inspecting Cybersecurity Risks in Power Systems" , "Visualization tool for cybersecurity measures in power systems" We encourage you to work on strengthening your daily cybersecurity measures while utilizing these resources.
In other words, this system cannot be considered complete solely on the basis of whether or not there is a "conforming label."
Supply chain, procurement, operation, maintenance, disposal, self-inspection, visualization, etc The entire management process by the business operator This is because it is within our field of vision.
The straightforward interpretation seems to be that having a label does not mean that everything is safe, but rather that a label is the minimum entry point, and in actual operation, separate management outside of that is naturally required.
I believe this is an issue that should be kept in mind as organizations tend to have separate technical and legal/compliance departments.
What businesses should check now
Based on the documents and official explanations, if there are any points that need to be confirmed at this time, I believe the main points are at least the following:
Firstly, for our own equipment and planning projects, Where to find devices with IP communication capabilities It's about finding out.
I feel that the way PCS, EMS, BMS, remote monitoring devices, gateways, etc. are really structured is surprisingly disorganized in many areas.
Even if it is listed on the drawings, it is not uncommon for the operational positioning to be unclear.
Secondly, Organize new and existing projects separately I think so.
New installations are a direct problem in relation to the timing of application, and existing installations are already in place, so it is necessary to consider how to handle them when replacing or renewing them in the future.
I feel that the "it's okay because it's moving now" approach is a bit insufficient.
Thirdly, Compatibility, warranty, inventory, maintenance contract This is an organization.
Exception measures can be problematic precisely because the circumstances surrounding them are actually quite serious.
Conversely, it seems that organizing those circumstances on a witness basis could be a practical tool.
This is a response to the system, Equipment asset management itself But there is.
Fourth, Manufacturer and vendor response status Yes.
Looking ahead to requirements in 2027 and beyond, we believe that which products are expected to meet and when will be a direct issue in procurement and case composition.
I believe we want to avoid a situation where only understanding the system takes the lead, and the products and exchange plans that are actually available cannot keep up.
How to read this system
I believe this document does not indicate a headwind for the widespread adoption of renewable energy Distributed power sources have truly begun to be treated as part of social infrastructure I believe that's the case.
As infrastructure, it seems rather natural that cybersecurity, as well as stable supply, security, and disaster response, will naturally become a requirement.
Of course, from the perspective of the site, I think there will be a burden.
Issues such as replacing existing cases, compatibility, guarantees, inventory handling, and avoiding equipment outages are not easy to address.
Nevertheless, when we look at the entire system design, we don't just suddenly apply it uniformly and discard it, Avoid retroactive application, request compliance sequentially at the time of renewal, and provide conditional exceptions for excessive burden The structure is as follows, and I believe there is a certain rationality to it as a transitional measure that is based on reality.
On the other hand, that doesn't mean it's a matter of peace of mind.
The message of the system is quite clear The era of distributed power generation will be advanced with cyber countermeasures That is.
This issue is sure to come to the forefront somewhere in future case formation, finance, EPC contracts, O&M contracts, long-term repair plans, insurance, and due diligence (Due Diligence).
I feel that those who can read ahead will have an advantage in the market a little further ahead.
summary
I believe that what we can learn from this Agency for Natural Resources and Energy document is that the cybersecurity of distributed power sources is no longer a peripheral issue.
Solar, battery, wind, and fuel cell facilities are connected to the grid via communication-enabled devices Minimum security standards are required at the connection entry point It seems we are moving in that direction.
What I particularly want to emphasize is that the target is not the entire facility Devices with IP communication capabilities While existing facilities are not immediately and retroactively applied, Practical implications when replacing or renewing and even if there are exceptions, Interim response with accountability and transition plan It's just that.
I believe that even if we carefully monitor this situation, the way we interpret the system will change significantly.
I believe the future of re-energy will not be determined solely by the amount of electricity generated.
I think it's fair to say that it depends on whether or not it is trusted as social infrastructure.
And the trust that will come from now on is not just about physical safety, This is the first time it has been established, including cybersecurity I feel like it's becoming something.
This document seems to quietly and rather clearly convey that reality.

comment