Cyber resilience

Czech cybersecurity law and BESS: a project checklist

Battery ownership alone does not determine legal scope. Good engineering still requires controlled remote access, supplier accountability and recoverable local operation.

Start with the regulated service

Applicability depends on the organisation, its service and the statutory criteria. A BESS, inverter or EMS may nevertheless become part of the technical environment supporting that service, so procurement should identify assets, accounts, data flows and supplier dependencies early.

Requirements worth specifying in every material project

  • named owners for local and remote administrator accounts,
  • multi-factor authentication and time-limited supplier access,
  • an inventory of firmware, cloud services and communication paths,
  • a documented vulnerability and update process,
  • logging that remains useful during incident investigation,
  • backup of configuration and a tested recovery procedure,
  • a safe local mode when cloud or external communications fail.

Turn policy into acceptance evidence

FAT and SAT should demonstrate role separation, access revocation, alarm handling, restoration of configuration and expected behaviour during loss of communications. Contractual wording without measurable evidence leaves the operational risk with the owner.

Primary sources and further reading

Information reviewed on 1 September 2026. Regulatory information is not legal advice.

First step

Data first. Technology second.

Describe the facility, operating constraint and required outcome. We will suggest the shortest useful next step.