
At Sungrow, we maintain a robust global compliance framework that aligns with international standards and regional regulatory requirements across key markets.
The NIS2 Directive (Directive (EU) 2022/2555) is the EU framework for cybersecurity risk management and incident reporting at the level of organisations. It entered into force on 16 January 2023 and had to be transposed into national law by the Member States by 17 October 2024, covering 18 sectors including energy, digital infrastructure, public administration and manufacturing. In-scope entities must implement ten minimum risk-management measures under Article 21(2), including supply chain security, and must report significant incidents within 24 hours, 72 hours and one month under Article 23. Sungrow's products are developed and operated under a risk-based cybersecurity programme, and our PSIRT provides a contact way supporting operators in meeting their own supply chain obligations.