EU Parliament, Strasbourg, E-003112/2026 Commission.
Written Question.
On 24 February 2026, the partly publicly-owned German energy company EnBW concluded a multiannual agreement with XCharge for high-power charging stations. EnBW operates more than 8 000 fast-charging points and plans to expand its network to up to 20 000 by 2030.
XCharge was founded in Beijing. According to its US Securities and Exchange Commission (SEC) filings, its chief executive officer (CEO) and its chair/chief technology officer (CTO) control approximately 81.9 % of the voting power through Class B shares, while holding approximately 31.2 % of the share capital.
Operators of recharging points are expressly covered by the energy provisions of the Network and Information Systems (NIS 2) Directive, subject to its scope criteria. The Commission has also identified strategic dependencies, unauthorised access to operational data and remotely triggered disruptions as risks arising from connected energy equipment. It has restricted EU funding for projects using solar inverters from high-risk suppliers.
1. Beyond the general cybersecurity and supply-chain obligations under the NIS 2 Directive, does EU law require the assessment of suppliers’ ultimate control, third-country legal obligations, data access and remote software-update or maintenance capabilities?
2. Can charging equipment comply with the EU cybersecurity framework where persons exercising decisive control over the supplier retain remote-access or update capabilities and are subject to the laws of a third country presenting elevated security risks?
3. Will the Commission apply supplier-security and funding restrictions to networked charging infrastructure equivalent to those applied to solar inverters, or explain why charging networks should be treated differently?