SUNIFIED OEM Briefing · September 2026

Solar Battery Gateways Pathway > EU Compliance

Compliance is the sales instrument, not the cost line.

Four EU instruments land between this month and 2028, and together they change what a manufacturer is allowed to sell into Europe. None of them can be satisfied by a certificate at the border. Each one asks for data that had to be originated at the device and cannot be reconstructed afterwards. That is a problem for every manufacturer without silicon inside the product, and an advantage for the first ones that have it.

The clock, in order of arrival

11 SEP 2026
CRA Article 14 reporting
Manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA. Live in days, not years.
18 FEB 2027
EU Battery Passport
Mandatory for EV, LMT and industrial batteries above 2 kWh. No passport, no placing on the market.
18 AUG 2027
Battery due diligence
Supply chain due diligence obligations, deferred from 2025 by Reg. (EU) 2025/1561.
11 DEC 2027
CRA full obligations
Essential cybersecurity requirements and conformity assessment for all products with digital elements.
1 JAN 2028
CBAM downstream
Proposed extension to about 180 steel and aluminium intensive goods. Mounting systems and frames, not modules.
A

The regulatory argument

Eight sections, each self-contained. Read one, read all eight, none depends on another. Every claim carries its instrument so you can verify it without asking us.

EU-01

NIS2, or why your customer's customer is asking

Read this if a European integrator has suddenly sent you a security questionnaire.

The NIS2 Directive treats electricity as an essential sector. Utilities, DSOs and large integrators inside the EU are legally obliged to manage cybersecurity risk across their supply chain, which they discharge by pushing requirements down their contracts to component suppliers. Most manufacturers outside Europe meet NIS2 not as a filing obligation of their own, but as a procurement wall: the questionnaire that arrives before the purchase order, and the clause that follows it.

Incident reporting runs on a tight clock, with an early warning due within 24 hours of a significant incident. A supplier who cannot support that timeline is a supplier the integrator has to explain to its regulator.

Directive (EU) 2022/2555 · eur-lex.europa.eu/eli/dir/2022/2555/oj

Solar · BESS · Gateway
EU-02

Cyber Resilience Act, the one that binds the manufacturer directly

Read this if you ship any connected product: inverter, gateway, BMS, monitoring board.

NIS2 lands on the operator. The CRA lands on you. Any product with digital elements placed on the EU market carries obligations on the manufacturer: secure by default configuration, vulnerability handling for the support period, a software bill of materials, and CE marking backed by conformity assessment.

Two dates matter. 11 September 2026, when Article 14 reporting begins: actively exploited vulnerabilities and severe incidents must be notified to ENISA and the relevant CSIRT, with an early warning inside 24 hours. 11 December 2027, when the full essential requirements and conformity assessment apply.

The practical consequence for a hardware maker is that a coordinated vulnerability disclosure policy and a named security contact stop being good practice and become an entry condition.

Regulation (EU) 2024/2847 · eur-lex.europa.eu/eli/reg/2024/2847/oj

All lanes
EU-03

Network Code on Cybersecurity, where inverter fleets get caught

Read this if your devices are aggregated: DER portfolios, VPPs, fleet managed inverters.

Beyond the horizontal rules there is a sector specific network code for the cybersecurity of cross border electricity flows. It matters to hardware makers because it is the instrument that reaches aggregated fleets, thousands of small devices under one control channel, rather than only large plant. If your gateway or inverter can be commanded remotely at scale, it sits inside a risk perimeter someone is now formally required to assess.

Read the timing carefully. The 4 hour incident clock in Art. 38(3) is real, but it binds only high and critical impact entities, and binding identification of those entities is not due until 13 June 2028. Anyone demanding a 4 hour supplier clock from you today is running ahead of the instrument.

Commission Delegated Regulation (EU) 2024/1366 · eur-lex.europa.eu/eli/reg_del/2024/1366/oj

Solar · Gateway
EU-04

The industry's own position

The best single document to read if this looks like a European bureaucrat's idea.

This is not regulators pushing against industry. In July 2024 SolarPower Europe published its own position calling for a harmonised cybersecurity baseline for solar PV: stronger governance under NIS2, product security through the CRA, a dedicated standard for distributed energy resources, operational PV data held within the EU or equivalent security jurisdictions, and an EU level monitoring layer for manufacturer coordinated devices such as inverters.

Read it as a forecast. Where the trade body asks for a baseline, a baseline arrives.

Position paper · PDF, 11 July 2024

Solar · Gateway
EU-05

Battery Passport, the hard gate at 18 February 2027

Read this first if you assemble battery or BESS packs.

From 18 February 2027, every EV, LMT and industrial battery above 2 kWh placed on the EU market must carry a digital battery passport, reachable by a QR code on the battery itself. The passport holds a unique identifier, model and technical characteristics, carbon footprint specific to the manufacturing site and batch, and performance and durability data, with tiered access for the public, regulators and end of life processors.

A carbon footprint declaration obligation already sits alongside it, and due diligence obligations follow on 18 August 2027, deferred from 2025 by Regulation (EU) 2025/1561.

The commercial point is not the passport. It is that batch level carbon and lifecycle data has to exist before the pack leaves the line. Reconstructing it from ERP records afterwards is what auditors are built to find.

Regulation (EU) 2023/1542 · eur-lex.europa.eu/eli/reg/2023/1542/oj

BESS
EU-06

ESPR, the passport model spreading beyond batteries

Read this if you make modules and think batteries are somebody else's problem.

The Ecodesign for Sustainable Products Regulation is the framework that generalises the battery passport into a Digital Product Passport for other product groups, set by delegated acts over the coming years. It is the instrument to watch for photovoltaics: it carries product level carbon, durability, repairability and recycled content requirements, and it amends the Battery Regulation directly.

Nothing binds solar modules under ESPR today. The exposure is that the mechanism now exists and has been proven on batteries first.

Regulation (EU) 2024/1781 · eur-lex.europa.eu/eli/reg/2024/1781/oj

All lanes
EU-07

Solar Stewardship Initiative, the audit regime buyers already use

Read this if you sell modules into European utility scale tenders.

Ahead of any binding regulation, European developers, buyers and financiers have converged on the Solar Stewardship Initiative's ESG and Supply Chain Traceability Standards as the evidence they will accept. Traceability here means documented chain of custody from polysilicon through wafer, cell and module, the thing most supply chains cannot demonstrate because the record was never bound to the physical unit.

This one is voluntary, and it is the one already appearing in tender conditions. It is where a manufacturer can differentiate this year rather than in 2028.

solarstewardshipinitiative.org, Supply Chain Traceability Standard

Solar
EU-08

CBAM, stated precisely

Read this before anyone tells you the carbon border tax applies to your panels.

CBAM entered its definitive phase on 1 January 2026. Its scope is cement, iron and steel, aluminium, fertilisers, electricity and hydrogen. Solar modules and batteries are not in scope.

The Commission's December 2025 proposal would extend CBAM from 2028 to roughly 180 downstream goods averaging around 79% steel or aluminium content: fabricated metals, machinery, vehicle components, appliances. For a solar manufacturer the realistic exposure there is mounting systems, frames and trackers, not the module.

So the honest framing is this. CBAM is not your gate today. It establishes the principle that embodied carbon determines market access, and ESPR is the instrument likely to apply that principle to your product.

taxation-customs.ec.europa.eu, CBAM

All lanes
B

How we work with manufacturers

Two sections: what the commercial arrangement is, and a paragraph you can forward to a colleague without rewriting it.

GTM-02

The engagement model, in one paragraph

What it costs, and where the money actually comes from.

Our model is deliberately simple. The UNITY chip goes into the manufacturer's bill of materials at cost recovery. We do not make margin on silicon. Revenue is shared on the data and API subscription that the verified stream generates over the asset's life, paid by the parties who need the data: insurers, financiers, asset owners and traders. Sunified brings the European demand side, the manufacturer brings manufacture. The manufacturer gains a compliance and financing position that cannot be bought as a service, because the data has to be originated in the factory.

All lanes
GTM-03

Forward this to a colleague

Written so that passing it on costs you nothing.

Sunified is an Amsterdam company that puts a secure chip inside solar panels and battery packs so that generation, identity and carbon data are captured cryptographically at the device rather than reconstructed from spreadsheets later. They are looking for manufacturers who want a position in Europe as the Battery Passport, the Cyber Resilience Act and product level carbon rules come into force between 2026 and 2028. The chip goes into the manufacturer's BOM at cost recovery; Sunified brings the European buyers, insurers and financiers who need the verified data. Founder is Leon Gerard Vandenberg, who lived and worked in Shenzhen and is on European time. Worth twenty minutes.

All lanes
C

What UNITY actually is

From the sentence that describes it, to the detail a hardware engineer asks for third.

UNI-01

The short description

Start here.

Sunified's UNITY sensor sits inside the panel, the battery pack or the gateway and captures cryptographic proof of energy generation and device identity at source. Every electron creating a byte of data. It produces genesis data: hi-fidelity, panel level, secure, trusted and verified, from the factory floor through deployment to recycling. One verified data source, several compounding revenue streams built on top of it.

All lanes
UNI-02

Silicon and security posture

For the hardware or security engineer.

UNITY is built on a Silicon Labs EFR32MG24B with Secure Vault High, providing a hardware root of trust, secure key storage and secure boot. That is the foundation a CRA conformity claim rests on, and the assurance a NIS2 obligated integrator needs to see in a supplier. The secure element holds SESIP Level 3. IEC 62443 alignment runs through our integration partner.

Deployed as an option board today, with a path to main board integration. Sunified is the firmware author and, under the CRA, a manufacturer in its own right, which means the reporting and vulnerability handling obligations sit with us for our part of the stack rather than with the OEM.

BESS · Gateway
UNI-03

Data path, panel to buyer

How the data leaves the array.

The chip measures temperature, voltage and current at the panel. A Bluetooth mesh propagates readings across the array to gateways, which publish a signed stream to the Sunified API. Because each reading is signed at the device, the record is tamper evident along its whole path. That is the difference between telemetry and evidence.

What sits on top: predictive maintenance and yield, insurance and financing at asset level, and the chain of custody record behind traceability and carbon claims. Panel level truth rather than inverter level aggregate is the point. Aggregate data cannot tell you which panel, and every downstream claim needs to know which panel.

Solar
UNI-04

The property rights argument

For carbon credit, insurance and legal audiences. The differentiated argument, not the technical one.

A century of chain of custody discipline is why oil is financed, insured and traded with confidence. The solar electron has none of it. Sunified's purpose is to make solar a trusted asset class for OEMs, producers, owners, financiers and insurers of decentralised solar and battery assets.

The consequence is legal, not only technical. Where generation and custody are attested at the device, a stolen or double counted carbon credit becomes property theft rather than breach of contract: prosecutable, insurable, and recoverable. A carbon credit is only as defensible as the metering behind it.

All lanes

Ten minutes to see if it fits. Thirty to go deep.

We are looking for manufacturers in three lanes: solar module manufacture, battery and BESS pack assembly, and industrial or home energy gateways. If a board revision is opening in the next twelve months, that is the conversation worth having.

The short call is a fit check on mobile, WhatsApp or Hangout. The Zoom is the technical walk-through: silicon, data path, integration and where your BOM window sits.

Prefer to write first? LG@sunified.com · both calls book through Calendly.com/lgv