House Bill 6011 would amend Michigan’s Clean and Renewable Energy and Energy Waste Reduction Act to add a new section focused specifically on cybersecurity and resilience for large-scale solar energy facilities. The bill defines covered facilities as solar electric generation facilities with at least 50 megawatts of nameplate capacity, including associated control systems and colocated energy storage. It states that the purpose is to address public health, safety, and emergency-response risks tied to the safe operation of these facilities, especially where inverter-based systems and battery storage are involved.
The bill requires operators of covered solar facilities to maintain reasonable security measures for safety-critical systems and to implement a risk-based cybersecurity and resilience program aligned with nationally recognized frameworks such as NIST or CISA guidance. The program may include risk identification, access controls, system segmentation, supply-chain risk management, and periodic testing. Operators must also maintain incident response plans, notify state police and local emergency management within 24 hours of a material cybersecurity incident, and provide a written summary within 72 hours. The bill also allows the attorney general to request documentation in limited circumstances, exempts sensitive security records from FOIA, and imposes civil fines of up to $25,000 per day for knowing or reckless violations, with a cure period before enforcement.
In terms of state law, the bill would add a new compliance obligation for operators of large-scale solar facilities without creating a broader cybersecurity regime or expanding state agency permitting or oversight authority. It expressly says it does not regulate siting or permitting, does not require changes to workforce levels or collective bargaining agreements, and does not impose duties on local governments or emergency responders. It also clarifies that ordinary mechanical failure, weather damage, manufacturing defects, and routine operational errors are not cybersecurity incidents unless unauthorized access or manipulation of safety-critical systems is involved.
Because there are no committee transcripts or recorded votes provided, there is no direct evidence of legislative debate or formal support/opposition in the materials supplied. The bill text itself suggests a generally pro-safety, pro-security framing, with repeated assurances that it is narrow, risk-based, and not intended to create a precedent for other sectors. The main likely point of contention is whether the bill’s incident-notification, documentation-retention, and civil-penalty requirements could impose new compliance burdens on solar developers and operators, even though the bill attempts to limit those burdens by tying obligations to existing frameworks and by excluding broader regulatory expansion.
The bill would amend the state’s renewable energy law by creating a new, facility-specific cybersecurity and resilience standard for large-scale solar energy facilities and associated energy storage systems. It would impose operational, reporting, recordkeeping, and incident-response obligations on facility operators, authorize enforcement by the attorney general or county prosecutors, and exempt sensitive security information from disclosure under the Michigan Freedom of Information Act. It does not change siting or permitting law, does not create a new state agency program, and does not impose duties on local governments or emergency responders.
No committee testimony or vote history is available, so the recorded legislative sentiment cannot be measured from the provided materials. The bill’s drafting language indicates a supportive posture toward solar development paired with heightened concern about cyber-physical safety risks, and it repeatedly emphasizes that the requirements are narrow, scalable, and intended to avoid unnecessary duplication with federal standards. The overall tone is precautionary and safety-oriented rather than punitive.
The principal area of potential contention is the scope of compliance obligations for operators of large-scale solar facilities, especially the requirement to maintain cybersecurity programs, report incidents quickly, and preserve sensitive records while avoiding disclosure. Industry stakeholders could view the civil penalties, documentation requests, and incident-notification timelines as burdensome, while supporters are likely to argue that the measures are limited to safety-critical systems and necessary to protect grid and emergency-response reliability. The bill also anticipates possible labor concerns by stating that it does not require workforce reductions, outsourcing, or changes to collective bargaining agreements, suggesting those issues may be sensitive even if not directly debated in the materials provided.