BESS Cybersecurity Checklist: Remote Access, Accounts, Networks and Logs
Buyer note: A battery energy storage system is not only batteries and power conversion equipment. Many commercial and industrial systems also include a BMS, PCS, EMS, meters, HVAC controls, fire-system interfaces, gateways and remote service connections. Each interface can affect who can view data, change settings or respond to alarms. A BESS cybersecurity checklist helps buyers define these responsibilities before commissioning and operational handover.
This guide is written for project owners, EPC teams, integrators, distributors and facility operators. It does not replace the owner's cybersecurity policy, a model-specific network design, a penetration test or advice from a qualified OT security professional. Use it to ask better questions, collect evidence and prevent account or remote-access assumptions from being discovered after the system is energized.
Why cybersecurity belongs in BESS project handover
Cybersecurity decisions are often postponed because the battery, PCS and switchgear dominate early project discussions. Yet the handover date is when temporary installer accounts, cellular routers, cloud portals and supplier laptops can become long-term operating dependencies. If ownership is unclear, a site may not know who can connect, which credentials must be changed, where alarms are stored or how access should be revoked.
Begin during design and procurement, then verify again during FAT, SAT and final handover. The goal is not to declare that a system is “secure.” The goal is to document the real architecture, reduce unnecessary access, assign decisions and preserve evidence. Pair this checklist with the C&I ESS commissioning and warranty handover checklist so electrical, controls and account acceptance are reviewed together.
Define the system boundary and responsible parties
Draw the boundary before discussing controls. List the battery racks, BMS levels, PCS, EMS, site meter, weather station, HVAC controller, fire panel interface, local HMI, network switches, router, cloud portal and any third-party aggregator. Mark which connections are local, which cross the owner's network and which leave the site. Do not assume that every BESS uses the same architecture.
For every component, assign an equipment owner, technical administrator, data owner, alarm recipient and service contact. The battery supplier may support the BMS while a separate PCS vendor manages inverter firmware and an EMS provider operates dispatch logic. The EPC may commission the complete system but not retain authority after handover. These boundaries should also align with the equipment and responsibility scope in the small commercial and industrial energy storage system checklist.
| Interface or asset | Questions for the supplier | Evidence to retain |
|---|---|---|
| BMS and local HMI | Which settings are view-only, operator-level or service-level? | Role matrix, account list and approved configuration export. |
| PCS controller | Who can change grid, protection and power-control parameters? | Access method, parameter baseline and change record. |
| EMS or site controller | Where are schedules, limits, alarms and user actions recorded? | Data-flow diagram, log example and backup procedure. |
| Remote gateway or router | Is inbound access required, how is it approved, and who disables it? | Network diagram, firewall rule list and access test record. |
| Cloud portal | Who creates, removes and reviews customer and vendor users? | Tenant owner, role list, recovery process and contract boundary. |
Build an asset and interface inventory
An inventory should identify more than model names. Record device purpose, manufacturer, model, serial number where appropriate, firmware or software version, IP or logical address, protocol, physical location, account owner and backup location. Include maintenance laptops, removable media processes, cellular modems and vendor-hosted services if they are needed to operate or support the site.
Keep the inventory usable. A list copied from a quotation may omit installed switches, gateways or replacement components. Update it from the as-built system and link each item to the responsible organization. For cabinet and container scope comparisons, review the BESS cabinet versus container checklist and confirm whether communication equipment is included, owner-supplied or installed by another contractor.

Use named accounts and controlled roles
Ask whether the platform supports named users, role-based permissions, password changes, account lockout and multi-factor authentication. Use the strongest functions the selected system supports, but do not claim a feature until the exact hardware, firmware and portal are confirmed. Shared service accounts may make individual actions difficult to trace. Default or temporary credentials should be addressed before acceptance.
Create a role matrix that separates routine monitoring from parameter changes, firmware work and account administration. A facility operator may need to acknowledge alarms without permission to alter protection values. A service engineer may need temporary elevated access for a defined task. Record who approves that elevation, when it expires and how the session is reviewed. The manufacturer's access capabilities should be requested alongside the documentary evidence in the C&I ESS manufacturing checklist.
Control remote access instead of assuming it
Remote access can support diagnostics and maintenance, but the project should state whether it is required. Ask for the connection direction, endpoint, authentication method, encryption method, approval workflow and logging behavior. Determine whether access is always available or enabled only for an approved maintenance window. Confirm the owner's method for disabling it without interrupting essential local operation.
Do not rely on a phrase such as “secure cloud connection.” Request a simple data-flow diagram and a witnessed demonstration. The site should know whether a vendor portal, VPN, remote desktop tool, cellular router or outbound gateway is involved. Supplier access should not remain active merely because it was convenient during commissioning. Define how former employees, subcontractors and replaced service companies are removed.
Separate BESS control traffic from business networks
Network segmentation should follow the owner's OT and IT design. At a minimum, the project team should identify where the BESS network meets the facility network, which protocols and destinations are allowed, and which firewall or gateway enforces the boundary. Avoid exposing a BMS, PCS or local HMI directly to the public internet. Exact architecture and rule design belong to the owner's qualified network and control-system specialists.
The U.S. National Institute of Standards and Technology publishes NIST SP 800-82 Rev. 3 guidance for operational technology security. It is a useful reference for concepts such as asset identification, segmentation, remote access and monitoring, but referencing it does not make a BESS compliant. Project requirements, local rules and the owner's risk process still control the design.
Verify logging, timestamps and data export
Logs are useful only when the team knows what is recorded and can interpret the time. Ask which systems record login attempts, account changes, parameter changes, remote sessions, alarms, firmware updates and communication failures. Check whether entries include a user or source, timestamp, action and result. Confirm the time source and timezone used by the BMS, PCS, EMS, gateway and cloud portal.
Agree on retention and export before an incident occurs. The owner may need a routine export, a portal download or support from the supplier. Test a small export during handover and record the file format. BMS operational logs and cybersecurity logs are related but not identical; use the C&I ESS maintenance checklist to connect system-health records with the site's broader maintenance evidence.

Plan firmware, configuration backups and recovery
Ask each supplier how approved firmware versions are identified, tested and released. An update may affect communications, protection settings, warranty support or interoperability, so the project needs an approval and rollback process rather than an automatic assumption that every new version should be installed. Record current versions at handover and identify who receives future notices.
Configuration backups should cover the systems the owner is expected to recover: EMS schedules, PCS parameters, BMS service settings where export is supported, network-device configuration and account records. Store backups in an owner-approved location and protect credentials separately. A backup is not proven merely because a file exists; document how it was created, which version it belongs to and who is authorized to restore it.
Add cybersecurity checks to FAT and SAT
FAT can confirm supplied account roles, firmware versions, enabled interfaces and the expected remote-access method before shipment. SAT can confirm the installed network boundary, owner accounts, time synchronization, remote-access approval and log export. Test only within an approved procedure; do not perform uncontrolled scanning or penetration testing on live equipment.
| Acceptance check | Practical demonstration | Close-out record |
|---|---|---|
| Account ownership | Owner administrator signs in and reviews active users. | Approved account and role list. |
| Remote access | Enable an approved session, confirm the log, then disable access. | Witnessed result and responsible contact. |
| Time and logs | Generate a harmless test event and export the matching record. | Timestamp comparison and sample export. |
| Configuration baseline | Export supported settings without changing live protection values. | Versioned file, checksum if used, and storage location. |
| Access revocation | Remove or disable a temporary commissioning user. | Closed user list and approval record. |
Coordinate these checks with electrical and functional acceptance. The battery energy storage commissioning checklist helps place account and data checks beside protection, controls, alarms and performance evidence rather than treating them as a separate last-minute task.
Prepare operating contacts and incident handover
The operator needs a clear route for abnormal access, unavailable monitoring, suspicious account activity and lost remote connectivity. Record who owns the first response, who can isolate a network connection, who can preserve logs and when the equipment supplier should be contacted. Cyber response should not create an electrical hazard or bypass safety procedures.
Maintain an offline contact list and a controlled copy of the network and account records needed during an outage. The U.S. Department of Energy's Cybersecurity Capability Maturity Model provides a broader way for energy organizations to review cybersecurity practices. It is an organizational reference, not a product certificate or a substitute for project-specific testing.
What to include in the RFQ and supplier response
Ask suppliers to identify connected components, protocols, local and remote interfaces, cloud dependencies, account types, supported authentication, logging, data export, firmware policy, backup capability, vulnerability contact and expected owner responsibilities. Request sample documents early enough to review them before purchase. Avoid contract language that promises undefined “military-grade” or “fully secure” protection.
For the wider commercial package, combine this cybersecurity scope with the C&I ESS supplier qualification checklist, the project evidence checklist and the Battery Storage Buyer Resources page. If you need a model-specific quotation review, send the site, system size, controls scope and required interfaces through Contact.
FAQ
What should a BESS cybersecurity checklist cover?
It should cover the actual asset and interface inventory, account roles, remote access, network boundaries, logging and time, firmware, configuration backups, acceptance tests, operating contacts and access revocation.
Should a BESS allow permanent vendor remote access?
That depends on the owner's requirements and the supported architecture. The project should document why access is needed, who approves it, how it is authenticated and logged, when it expires and how the owner disables it.
Is a cloud monitoring portal the same as the local EMS?
Not necessarily. A portal may display selected data while the local EMS performs dispatch or site control. Buyers should request a data-flow diagram and identify which functions continue if the external connection is unavailable.
What cybersecurity evidence should be checked during SAT?
Useful evidence includes the installed network boundary, owner account access, removal of temporary users, remote-access enable and disable behavior, synchronized timestamps, a sample log export and the approved configuration baseline.
Does following NIST or DOE guidance certify a BESS?
No. These sources provide guidance and maturity concepts. Product claims, project requirements and compliance decisions require their own documented assessment, qualified review and applicable contractual or regulatory evidence.
Related SolarStorageHub Resources
If you are turning this article into a buying decision, compare the relevant product families and send your inverter model, target capacity, installation country, and quantity plan for confirmation.






