Blog

Why compliance evidence is becoming critical for solar operators

Written by Negin Hashemi | Aug 27, 2026, 8:25:02 AM

Solar assets have traditionally been judged by energy yield, availability and performance. As plants become more connected and regulatory scrutiny increases, another measure is becoming important: whether operators can demonstrate that their assets are governed, monitored and resilient.

Centrii argues that having cybersecurity controls is no longer enough. Operators increasingly need evidence showing how those controls are managed across their portfolios.

A changing risk environment

Modern solar plants are networked operational environments. Inverters communicate through cloud platforms, supervisory control and data acquisition (SCADA) systems can connect with corporate IT networks and battery energy storage systems (BESS) use remote monitoring. Original equipment manufacturers (OEMs) and other suppliers may also have remote access.

Each connection creates another dependency that needs to be understood and managed.

Centrii points to the coordinated cyberattacks on wind and solar farms in Poland on 29th December 2025. Although the plants continued generating, malware reportedly damaged firmware and operational data and interrupted communications between sites and grid operators.

The result illustrates an important distinction: generation can continue while operators lose the visibility and control needed to demonstrate operational resilience.

Compliance becomes continuous

Regulation is also changing expectations. The feature highlights the EU’s NIS2 Directive, the Critical Entities Resilience (CER) Directive and standards including IEC 62443.

Under NIS2, operators may need to demonstrate risk management, incident response and supply chain oversight. Senior management can also carry personal liability, while fines for non-compliance can reach €10 million or 2 per cent of global annual revenue.

Operators increasingly need visibility across areas including:

  •  SCADA and control system configurations

  •  Inverter and BESS communications

  •  OEM and vendor remote access

  • ● Third-party dependencies

  • ● Monitoring and logging coverage

  • ● Incident response procedures

For portfolios spanning multiple assets and jurisdictions, maintaining that evidence becomes considerably more difficult.

Why manual compliance becomes a problem

Centrii argues that many operators already have relevant controls but struggle to demonstrate them consistently.

Cybersecurity information may be distributed between spreadsheets, emails, supplier agreements, audit records and separate teams. A control may exist, but its evidence may be difficult to locate when an insurer, investor or regulator requests it.

The company compares this challenge with operational monitoring. Solar operators would not manage a large portfolio without automated visibility of inverter, string and transformer performance. It argues that compliance evidence increasingly requires a similarly structured approach.

Turning the risk register into operational intelligence

One approach is a compliance risk register connecting assets, dependencies, identified risks, controls, remediation activities, ownership and supporting evidence.

For each risk, operators should be able to establish:

  •  Which assets and systems are affected

  •  Which suppliers or dependencies are involved

  •  What regulations or requirements apply

  •  Which controls are in place

  •  What evidence demonstrates those controls

  •  Who owns remediation and what has changed

Hybrie De Jager, Compliance Officer at Centrii, says operators often have the necessary information but keep it across too many locations. The company developed its risk register to bring these elements into a more consistent process.

This is a company-specific approach, but the wider principle is increasingly relevant: compliance needs to be demonstrable rather than simply documented.

Evidence becomes part of asset value

The implications extend beyond regulation. Investors and lenders may consider operational resilience during due diligence, insurers can examine cybersecurity controls when assessing risk and grid operators increasingly expect stronger governance.

Centrii’s argument is that operators should be able to produce evidence of cybersecurity governance, supplier oversight, monitoring and incident readiness in hours rather than weeks.

Energy yield and uptime will remain fundamental measures of solar performance. But as assets become more connected, the ability to demonstrate how operational risks are governed could increasingly sit alongside megawatts as a measure of a well-managed portfolio.

For the complete analysis, read the full feature from Centrii on compliance evidence, cybersecurity governance and operational resilience for solar assets in PES Solar: https://pes.eu.com/exclusive-articles/why-compliance-evidence-is-becoming-as-important-as-energy-yield