When the Green and Digital Transition go hand-in-hand

Posted on 06/07/2026

Why Flanders' solar panel obligation is prompting steel distributors to think about NIS2 and cybersecurity*

The energy transition and the digital transition are often viewed as two separate challenges. For many steel traders in Flanders, however, they come together in the same place: on the roof of their warehouse.

With their large warehouse surfaces, steel companies have significant potential for solar energy generation. The Flemish requirement to install solar panels on buildings with an annual electricity consumption exceeding 1 GWh is accelerating this trend.

What is less well known is that these investments also raise a broader question for companies in Flanders and beyond: how secure is the digital infrastructure on which modern energy installations increasingly depend?

Flemish solar panel requirements, Belgian cybersecurity responsibilities

Although the obligation to install solar panels stems from Flemish energy and climate regulations, its implementation often involves digital systems that play a central role within the company.

Modern solar installations are connected to energy management platforms, monitoring software, cloud services and external service providers. As a result, energy management and cybersecurity are becoming increasingly intertwined.

For companies operating in sectors covered by NIS2, or that are part of a larger corporate group subject to NIS2, this development deserves particular attention.

Not every steel trader falls within the scope of NIS2

A common misconception is that installing solar panels or generating electricity automatically results in NIS2 obligations. This is not the case.

Most traditional steel traders do not fall directly within the sectors covered by NIS2. However, certain companies may come within scope, for example when they:

  • are part of a large international group;
  • operate in a sector covered by NIS2;
  • engage in waste management or other regulated activities in addition to steel trading;
  • belong to a corporate group whose size thresholds are assessed on a consolidated basis.

For such companies, the deployment of digital energy infrastructure may become an additional consideration within their broader cybersecurity strategy.

A solar installation is also digital infrastructure

Where solar panels were once primarily a technical installation, they are now closely connected to digital systems.

Inverters communicate through networks, production data is continuously monitored, and energy management increasingly relies on cloud-based platforms.

While these technologies provide significant benefits in terms of efficiency and visibility, they also introduce additional cyber risks. Every connected installation may represent a potential entry point for attackers.

As a result, a solar project is no longer merely an energy investment; it also becomes part of the company’s digital infrastructure.

Directors face broader responsibilities

Where a company falls within the scope of NIS2, the regulation imposes more than just technical requirements. Directors and senior management are also given explicit responsibility for identifying, managing and overseeing cyber risks.

This means cybersecurity should ideally be considered from the design stage of new digital and energy-related infrastructure. Access management, network segmentation, monitoring and incident response become just as important as financial returns and payback periods.

Two transitions, one strategic exercise

For the steel trading sector, this illustrates a broader trend. Sustainability, digitalisation and cybersecurity can no longer be treated as separate policy domains.

Installing solar panels does not automatically create an NIS2 issue. It can, however, provide an opportunity to assess the organisation’s digital resilience and its position within a wider corporate group.

Companies that approach the green and digital transitions together are not only building a more sustainable business, but also a more resilient and future-proof organisation.

 

*Disclaimer: Whether an organisation actually falls within the scope of NIS2 depends on various elements. Companies should therefore seek specific legal advice on a case-by-case basis.