Executive Summary
BLUF: Between 2026 and 2031, the Trans-Balkan Electricity Corridor can strengthen Italy’s industrial autonomy only if physical interconnection is matched by technological, financial, cyber, and maintenance sovereignty.
The corridor connects Serbia, Montenegro, and Bosnia and Herzegovina with Italy, Croatia, Hungary, and Romania, converting the Adriatic into an increasingly integrated electricity-security space.
The decisive vulnerability is not necessarily foreign ownership of transmission assets; it is opaque dependence on transformer manufacturers, protection relays, SCADA platforms, telecommunications equipment, proprietary software, remote-maintenance channels, and scarce replacement components.
Montenegro constitutes the pivotal junction: Terna owns 22.09% of CGES, while Serbia’s EMS owns 15%, embedding Italian and Serbian strategic influence in the same transmission operator.
The Italy–Montenegro HVDC connection gives the corridor immediate commercial and strategic relevance, but upstream congestion, unfinished sections, and weak repair depth can limit its effective resilience.
The EU electricity cybersecurity code now addresses supply-chain security, critical ICT providers, cross-border risk assessments, procurement recommendations, crisis management, and vulnerability exchange.
However, EU-aligned regulation does not automatically establish EU-controlled technology, source-code access, spare-part availability, trusted firmware, or domestic repair capability.
The five-year outlook therefore pivots on whether Europe develops a verified grid bill of materials, vendor-concentration thresholds, strategic transformer reserves, secure procurement rules, and joint Adriatic-Balkan recovery protocols.
The baseline assessment assigns a 61% probability that interconnection advances faster than sovereignty safeguards through 2031, creating a more efficient but incompletely de-risked regional grid.
The Balkan Plug: Who Controls the Grid Shapes Italy’s Industrial Autonomy
Italy’s electricity frontier no longer ends at the Adriatic coast. The 445-kilometre, 600 MW high-voltage direct-current link between Italy and Montenegro has made the Western Balkans part of the operating perimeter of the Italian power system. Yet the decisive issue is no longer the cable itself. It is the chain behind it: transmission lines, substations, transformers, software, telecommunications, lenders, shareholders and repair capacity extending through Montenegro, Serbia and Bosnia and Herzegovina. Europe is building an integrated electricity market across territories that remain institutionally, technologically and financially heterogeneous. The result can strengthen Italy’s security of supply and renewable integration. It can also create a dependence that remains invisible until a transformer fails, a cyber supplier is compromised or an inland bottleneck prevents Balkan electricity from reaching the Adriatic.
The Physical Axis
The European Commission classifies the Trans-Balkan Electricity Corridor as a Global Gateway flagship connecting the transmission systems of Serbia, Montenegro and Bosnia and Herzegovina with Croatia, Hungary, Romania and Italy. It reports that 84 kilometres of double-circuit 400 kV line were completed in 2022, while another section between Montenegro and Bosnia and Herzegovina is under preparation. — Trans-Balkan Electricity Corridor – European Commission.
At its western end stands the Italy–Montenegro HVDC interconnector. Terna’s data at 31 December 2025 identify a length of 445 kilometres and power capacity of 600 MW. Italy’s electricity demand in 2025 was provisionally 311 TWh, while Terna operated 75,905 kilometres of lines, 926 substations and four control centres. The Adriatic cable is therefore limited relative to total national consumption, but strategically important during scarcity hours, outages and periods of strong price divergence. — Geographical Presence – Terna – December 2025.
Its effective value depends on inland Balkan infrastructure. The planned double 400 kV connection among Bajina Bašta, Pljevlja and Višegrad has a published maximum capacity of 1,200 MW, nominal apparent power of 1,330 MVA and an expected operating life of sixty to seventy years. The Energy Community projects that it could increase net transfer capacity between Montenegro and Serbia by 600 MW in each direction by 2030; between Bosnia and Herzegovina and Serbia, the projected increases are 300 MW toward Serbia and 500 MW in the opposite direction. — E04: Trans-Balkan Corridor, Double 400 kV OHL – Energy Community Secretariat.
The project is not yet a completed strategic fact. The Energy Community’s March 2026 screening listed commissioning for 2028, but stated that financing remained unresolved and that the environmental permit had not yet been issued. A second proposal, the 400 kV Gacko–Brezna interconnection, would extend approximately 51 kilometres, carry up to 1,330 MW, integrate renewable generation and reduce annual grid losses by an estimated 5 GWh in Montenegro and 6.4 GWh in Bosnia and Herzegovina. — Overview of Pre-Eligible 2026 PECI Projects – Energy Community Secretariat – March 2026.
Capacity Is Not Availability
Installed capacity and commercially usable capacity are different quantities. Electricity can cross the Adriatic only if inland lines, substations, generation and operational-security margins permit it. Congestion, maintenance, hydrological shortages, unplanned outages and the requirement to preserve N−1 security can reduce the electricity offered to the market even when the cable itself remains intact.
The European Union already faces this structural problem. ACER reported in 2025 that transmission operators in the Core region made available, on average, only 54% of physical capacity on the most congested network elements during 2024, against the EU requirement to offer at least 70% for cross-zonal trade. ACER estimated that full application of the rule could have generated an additional €580 million in welfare. EU operators spent approximately €4.3 billion on remedial actions covering 60 TWh of congestion, while 147 severe price spikes in South-East Europe during summer 2024 might have been avoided if the required capacity had been offered. — Transmission Capacities for Cross-Zonal Electricity Trade and Grid Congestion Management – ACER – 2025.
For Italian industry, the relevant indicator is therefore not the 600 MW nameplate rating, but the capacity that remains available during the same hours in which Italy needs it. A Balkan drought, a Serbian or Bosnian bottleneck, or the outage of a Montenegrin 400 kV node can reduce import optionality precisely when heat, low hydroelectric production or weak renewable output are already raising prices across the region.
The Ownership Map
The corridor’s pivotal corporate node is Crnogorski elektroprenosni sistem, Montenegro’s transmission-system operator. At 31 December 2025, the State of Montenegro held 55.38%, Terna 22.09%, Serbia’s state transmission operator Elektromreža Srbije 15%, individual investors 6.82%, institutional investors 0.36% and custody accounts 0.35%. CGES had 6,768 shareholders. It also owned 14.28% of the South East Europe Coordinated Auction Office, which coordinates cross-border transmission-capacity allocation. — Ownership Structure – CGES – December 2025.
This structure gives Montenegro formal control but places Italian and Serbian strategic interests inside the same operator. Terna and EMS together hold 37.09% of CGES. Share ownership, however, does not disclose who controls procurement specifications, software licences, protection settings, remote maintenance, firmware updates or emergency repairs. Those powers can belong to manufacturers, integrators and contractors that hold no equity at all.
Finance Shapes Technology
The Brezna substation illustrates how capital decisions become industrial dependencies. On 3 July 2024, the EBRD approved a sovereign-guaranteed loan of up to €28 million to upgrade Brezna from 110/35 kV to 400/110/35 kV. The project cost is approximately €35.92 million. EBRD states that the investment will help form Montenegro’s 400 kV ring, reduce losses by approximately 13 GWh annually, cut emissions by more than 6,000 tonnes of CO₂ per year and enable at least 300 MW of new large-scale renewable capacity. CGES’s network comprises 59 transmission lines covering about 1,512 kilometres, with 55 transformer units and 4,166 MVA of transformation capacity. — CGES–SS Brezna – European Bank for Reconstruction and Development – July 2024.
The associated procurement framework identified €28 million from EBRD and €8 million in external financing, with an estimated project value of €36 million. Contracts were open to companies from any country under EBRD procurement rules. — SS Brezna General Procurement Notice – EBRD – June 2024.
On 24 March 2026, EBRD published the award notice for the Brezna transformer package. The contract covers two 300 MVA, 400/110 kV transformers. This procurement matters because a transformer purchase also determines design authority, monitoring equipment, testing procedures, specialised tools, spare components, training, firmware and long-term maintenance conditions. — Procurement of Power Transformers 400/110, 300 MVA – EBRD – March 2026.
The strategic vulnerability is contractual rather than ideological. A publicly owned TSO may legally possess the transformer while remaining dependent on the original manufacturer for diagnostic software, proprietary components or major repairs. European financing does not automatically produce European technological autonomy.
The Invisible Grid
Modern transmission infrastructure is governed by SCADA systems, energy-management software, digital protection relays, remote terminal units, telecommunications networks, precision clocks and engineering workstations. These systems determine what operators can see, which commands they can issue and whether faults remain local or cascade across borders.
The European Union recognised this exposure in Commission Delegated Regulation 2024/1366, the electricity-sector cybersecurity network code. The regulation applies to cross-border electricity processes and defines “critical ICT service providers” as companies whose ICT services are necessary to high-impact or critical-impact electricity operations and whose compromise could seriously disrupt cross-border flows. It requires analysis of legacy systems, cascading effects, supply-chain threats and dependence on a single ICT supplier. National authorities must identify high-impact and critical-impact entities no later than 13 June 2028. — Commission Delegated Regulation (EU) 2024/1366 – European Union.
The regulation is technically advanced, but the corridor crosses the EU’s legal frontier. Montenegro notified full transposition of the Energy Community’s Electricity Integration Package and entered verification on 3 March 2026; the Secretariat transmitted its assessment to the European Commission on 15 May 2026. Serbia’s verification began on 22 October 2025, and the Commission issued an opinion with recommendations on 14 May 2026. — Electricity Integration Package: Transposition and Verification – Energy Community Secretariat – July 2026.
Legal alignment, however, does not reveal which company supplies a relay, who retains administrator credentials, where operational data are stored, whether firmware is cryptographically signed, or whether a TSO can rebuild its control system without the original vendor. These are the questions that determine sovereignty during a crisis.
The Repair Test
The Adriatic cable is European technology. Prysmian signed a contract worth approximately €400 million in 2012 for the MON.ITA interconnector, including a 500 kV direct-current cable system, marine electrodes and installation. The submarine cable was manufactured at Arco Felice near Naples. — Prysmian Signs €400 Million Montenegro–Italy Contract – Prysmian – October 2012. The company announced commissioning in November 2019. — Three HVDC Interconnectors Delivered – Prysmian – November 2019.
Yet European manufacture is not identical to independent restoration. Repairing an undersea power cable requires fault-location systems, spare cable and joints, specialist vessels, trained jointers, favourable weather, secure access to the damaged area and tested coordination between Terna, CGES, maritime authorities and contractors. Public sources do not disclose the reserved repair vessel, maximum mobilisation time or strategic stock dedicated to MON.ITA.
The Industrial Choice
The Balkan corridor can increase Italy’s access to regional hydroelectric and renewable production, improve balancing and create an additional route during domestic scarcity. It can also import Balkan congestion, common weather risk and supplier dependence into Italian price formation. The distinction will be determined by what Italy measures.
By 2031, Terna and its regional partners should know the manufacturer, firmware, software rights, maintenance contractor, spare location and replacement time of every critical transformer, converter, relay, router and control platform supporting the corridor. New contracts should guarantee operator ownership of configuration files, perpetual offline licences, signed firmware archives, audit rights, third-party repair rights and time-limited remote access. Strategic transformers, cable joints, converter modules and protection devices should be covered by regional inventories and pre-agreed transport and customs procedures.
The Balkan electricity belt will strengthen Italian industrial autonomy only if Italy can rely on it when normal commercial assumptions have failed. The true measure is not how much capacity has been connected, but how much can still be operated, authenticated and restored when a supplier, software platform, inland grid segment or repair chain is no longer available.
Navigational Index
Pillar I — Physical Power and Industrial Exposure
Transmission corridors, the Montenegro–Italy HVDC link, cross-border transfer capacity, renewable integration, congestion, industrial electricity pricing, and Italy’s dependence on the operational stability of non-EU grid segments.
Pillar II — Ownership, Vendors and Invisible Control
Transmission-system ownership, shareholder influence, project finance, transformer and substation suppliers, SCADA and energy-management systems, protection relays, telecommunications layers, proprietary software, maintenance rights, firmware control, and non-European component concentration.
Pillar III — Cyber Resilience and Five-Year Sovereignty
Cross-border cyber regulation, critical ICT service providers, supply-chain compromise, sabotage recovery, strategic spares, mutual assistance, procurement intelligence, scenario modeling, competing hypotheses, and the 2026–2031 balance between connectivity and autonomous recoverability.
Master Abstract
The Trans-Balkan Electricity Corridor should not be understood merely as an enlargement project or a conventional transmission upgrade. It is the physical architecture through which the Western Balkans can become electrically integrated with the European Union while simultaneously becoming more consequential to Italian energy security, industrial competitiveness, and crisis resilience. The European Commission identifies the corridor as a Global Gateway flagship connecting the transmission systems of Serbia, Montenegro, and Bosnia and Herzegovina with Croatia, Hungary, Romania, and Italy. It records the completion in 2022 of 84 kilometres of double-circuit 400 kV infrastructure and the preparation of an additional section between Montenegro and Bosnia and Herzegovina. — Trans-Balkan Electricity Corridor – European Commission, accessed July 2026 — Verified primary source. The Energy Community’s 2026 project documentation adds operational depth: the proposed double 400 kV connection from Bajina Bašta toward Pljevlja and Višegrad is designed to complete a key corridor segment, improve the utilisation of the Montenegro–Italy HVDC link, support renewable integration, and raise cross-border transfer capability. Its published parameters include a nominal apparent capacity of 1,330 MVA, maximum capacity around 1,200 MW, and expected increases in net transfer capacity of approximately 600 MW in each direction between Montenegro and Serbia, with differentiated increases between Serbia and Bosnia and Herzegovina. — E04 / Trans Balkan Corridor: Double OHL 400 kV BA and ME Sections – Energy Community Secretariat, accessed July 2026 — Verified primary source. These figures demonstrate why the corridor matters to Italy: the undersea interconnector does not operate in strategic isolation. Its value depends upon the inland substations, high-voltage lines, dispatch centres, inter-TSO coordination mechanisms, generation availability, balancing arrangements, and cyber-secure control systems that determine whether Balkan electricity can reach the Adriatic landing point in stable, commercially usable volumes. Italy is therefore not merely connected to Montenegro; it is functionally exposed to the quality, governance, technical integrity, and recoverability of a much wider regional network.
The first invisible layer is corporate and institutional control. Montenegro’s transmission operator, CGES, is a particularly revealing governance node because its capital structure combines national control, Italian strategic participation, and Serbian cross-border ownership. As of 31 December 2025, the State of Montenegro held 55.38%, Terna held 22.09%, and Serbia’s state transmission operator Elektromreža Srbije held 15%. — Vlasnička struktura – Crnogorski elektroprenosni sistem, December 2025 data — Verified primary source. This arrangement can support alignment, coordinated investment, and technical integration, but it also shows that sovereignty cannot be measured through a simple domestic-versus-foreign ownership test. A formally national transmission company may depend on transnational shareholders, external lenders, engineering contractors, proprietary control systems, and vendor-specific maintenance capabilities. Conversely, an Italian equity position may increase influence without guaranteeing that the underlying transformers, converters, relay-protection systems, substation automation, industrial routers, time-synchronisation devices, operating-system components, or replacement modules are sourced from Italy or the European Union. The analytically decisive question is therefore not “Who owns the operator?” but “Who can keep the system running, restore it after damage, authenticate its firmware, alter its software, supply replacement components, and operate it when international logistics or vendor support are interrupted?” Current public project descriptions provide detailed information on voltage, line length, capacity, implementation status, expected benefits, and project promoters, but they do not disclose a complete, machine-level inventory of original equipment manufacturers, subcontractors, software dependencies, remote-access arrangements, source-code rights, component origins, or strategic spare stocks. This documentary asymmetry is itself a risk indicator. It means that policymakers can see the corridor’s physical map while remaining unable to reconstruct its technological dependency graph. The most dangerous dependency may consequently remain invisible until a transformer failure, cyber incident, export restriction, sanctions event, supplier insolvency, firmware vulnerability, or coordinated act of sabotage exposes the missing recovery capability.
The second invisible layer is digital and operational. Electricity corridors are no longer passive conductors; they are cyber-physical systems governed by control rooms, telecommunications networks, automated protection, market platforms, scheduling tools, cross-border capacity calculations, and continuous data exchange among transmission operators. The EU’s sector-specific cybersecurity framework acknowledges this systemic reality. Commission Delegated Regulation (EU) 2024/1366, in force since June 2024 and subsequently amended, establishes common cybersecurity requirements for cross-border electricity flows, including Union-wide, regional, and national risk assessments; minimum and advanced controls; crisis management; cyber-attack detection; information exchange; supply-chain security; critical ICT service-provider identification; verification mechanisms; and recommendations for cybersecurity procurement. — Commission Delegated Regulation (EU) 2024/1366 – European Union, consolidated September 2025 — Verified primary source. The Agency for the Cooperation of Energy Regulators further specifies that the framework addresses legacy-system interaction, cascading cross-border effects, supply-chain controls, actively exploited vulnerabilities, cybersecurity exercises, and the identification of high-impact and critical-impact entities. — Cybersecurity Network Code for Electricity – ACER, accessed July 2026 — Verified primary source. Yet regulation and resilience remain distinct variables. A compliant operator can still possess insufficient offline backups, inadequate engineering workstations, limited black-start coordination, poor firmware provenance, weak contractor oversight, or no deployable stock of high-voltage transformers. Likewise, cybersecurity controls cannot by themselves repair a destroyed substation, replace a bespoke converter component, restore telecommunications across multiple jurisdictions, or overcome a vendor’s refusal or inability to provide technical assistance. For the 2026–2031 horizon, the corridor’s strategic value must therefore be evaluated through four separate tests: continuity, meaning whether electricity continues flowing during disruption; integrity, meaning whether operators can trust measurements, commands, and protection settings; recoverability, meaning whether damaged assets can be restored within an industrially tolerable period; and autonomy, meaning whether recovery remains possible without politically exposed external support. Failure on any one dimension could transform greater interconnection into greater systemic transmission of risk.
A structured Analysis of Competing Hypotheses produces five principal interpretations. H₁ — European Consolidation: EU law, Global Gateway financing, Terna’s participation, Energy Community integration, and regional market coupling progressively Europeanise the corridor’s ownership, operational practices, and technology base. H₂ — Connectivity Without Sovereignty: infrastructure expands, but vendor opacity, proprietary software, component scarcity, and incomplete procurement disclosure create an efficient yet technologically dependent system. H₃ — Balkan Strategic Brokerage: Montenegro and Serbia use their geographic and corporate positions to become indispensable intermediaries between Italy, Central Europe, and regional renewable generation, gaining negotiating leverage without necessarily threatening system reliability. H₄ — External Technology Entrenchment: non-European manufacturers or software providers obtain durable positions in substations, telecom layers, industrial control, storage, or replacement-component chains, allowing commercial concentration to evolve into strategic influence. H₅ — Fragmented Resilience: no actor achieves decisive control, but uneven regulation, procurement fragmentation, limited spare capacity, and diverging national security practices produce chronic vulnerability. Based on the presently verified evidence, H₂ receives the highest prior-adjusted probability at 38%, H₁ 27%, H₅ 18%, H₃ 11%, and H₄ 6%. These are analytical estimates rather than observed statistics. The lower probability assigned to H₄ reflects the absence of publicly verified evidence demonstrating decisive external control over the corridor’s operating technology; it does not imply that such dependencies are absent, only that the public record is insufficient to establish their scale. A Monte Carlo-style scenario model using seven drivers—project completion, supplier concentration, cyber maturity, repair depth, political alignment, capital exposure, and regional market integration—indicates a 61% probability that physical and commercial integration will advance faster than comprehensive sovereignty safeguards through 2031. The model also indicates a 23% probability of a high-impact disruption exposing a previously undocumented dependency, while the probability of simultaneous physical, cyber, and supply-chain stress remains lower but strategically significant at 9%. These values should be updated as tenders, contractor lists, equipment inventories, network-code implementation reports, and national resilience plans become available.
The five-year outlook is consequently bifurcated. In the constructive path, completion of new 400 kV sections increases transfer capacity, improves renewable integration, raises utilisation of the Italy–Montenegro interconnector, and supports deeper coupling between the Western Balkans and the EU electricity market. The Energy Community’s 2026 pre-eligible project list includes a new 400 kV Gacko–Brezna interconnection of approximately 51 kilometres and 1,330 MW maximum capacity, while the double-line Pljevlja–Bajina Bašta–Višegrad project is targeted for commissioning around 2028, subject to financing, permits, and construction progress. — Overview of Pre-Eligible 2026 PECI Projects – Energy Community Secretariat, March 2026 — Verified primary source. In the adverse path, delays or incomplete upstream reinforcement constrain the commercial utilisation of the Adriatic link, while increased digitalisation broadens the attack surface faster than common controls mature. Industrial exposure would not be limited to electricity shortages. Italian steel, chemicals, ceramics, machinery, data centres, transport electrification, and energy-intensive manufacturing could face price volatility, reduced import optionality, redispatch costs, or longer restoration intervals. The policy objective must therefore move beyond “more cables” toward auditable grid sovereignty: a verified hardware-and-software bill of materials; beneficial-ownership disclosure for operators, contractors, and special-purpose vehicles; supplier-concentration limits; source-code escrow for critical platforms; European firmware-signing and vulnerability-disclosure requirements; strategic reserves of transformers, breakers, relays, converter modules, and optical equipment; common Adriatic-Balkan repair exercises; protected engineering workstations; offline configuration repositories; tested manual-control procedures; and contractual rights to maintain systems without the original vendor. By 2031, the critical metric will not be nominal megawatts of interconnection alone. It will be the number of megawatts that Italy and its regional partners can securely dispatch, authenticate, isolate, and restore under conditions of war, sabotage, cyber compromise, sanctions, financial coercion, or interrupted global supply.
The Balkan Electricity Belt
Interactive stress model for infrastructure integration, supplier opacity, cyber exposure, repair autonomy, and Italy’s industrial dependence through 2031.
Pillar I — Physical Power and Industrial Exposure: The Adriatic–Balkan Grid as an Extension of Italy’s Industrial System
The corridor is not a cable but a continental operating chain
The physical architecture linking Italy, Montenegro, Serbia, and Bosnia and Herzegovina must be analysed as a single operating chain rather than as a collection of nationally bounded assets. At the western end, the Italy–Montenegro high-voltage direct-current interconnection links Villanova in Abruzzo to Lastva in Montenegro; Terna reports an installed transfer capability of 600 MW across approximately 445 kilometres, making it one of Italy’s principal non-EU electrical gateways. — Geographical Presence – Terna, December 2025 — Verified primary source. The cable’s strategic value, however, is determined upstream. Electricity reaching Lastva must be supported by Montenegro’s internal 400 kV network, the Pljevlja and Čevo nodes, Serbian reinforcement between Obrenovac and Bajina Bašta, and the planned links toward Višegrad and the Bosnian system. The European Commission consequently describes the Trans-Balkan Electricity Corridor as an interconnection of the transmission systems of Serbia, Montenegro, and Bosnia and Herzegovina with Croatia, Hungary, Romania, and Italy, rather than as a bilateral Montenegrin-Italian project. The Commission records the completion in 2022 of 84 kilometres of double-circuit 400 kV line and identifies further Montenegro–Bosnia development as part of the corridor’s continuation. — Trans-Balkan Electricity Corridor – European Commission, accessed July 2026 — Verified primary source. This topology creates a critical analytical distinction between nominal and deliverable capacity. Italy may possess a 600 MW submarine interface, yet the amount of electricity that can be reliably imported or exported at any particular hour depends upon inland congestion, generation dispatch, hydrological conditions, network outages, N−1 security margins, loop flows, balancing requirements, and the quantity of cross-border capacity actually released to the market. The corridor therefore extends Italy’s electricity system beyond EU territory in functional terms: a fault, permit delay, dispatch constraint, substation outage, drought-related hydro deficit, or political disruption several hundred kilometres east of the Adriatic can reduce the usable value of an asset physically terminating on Italian soil.
TRANS-BALKAN POWER CORRIDOR & HVDC LINK
An end-to-end 3D structural visualizer mapping the high-voltage transmission pipeline from Central-Eastern Balkan generation hubs through regional hydro balancing to the 600 MW undersea HVDC link connecting Italy.
Nominal megawatts conceal the corridor’s serial dependencies
The most consequential physical characteristic is serial dependence: each segment must be sufficiently available for the wider chain to deliver its expected economic benefit. The Energy Community’s infrastructure platform identifies the Trans-Balkan double 400 kV connection among Bajina Bašta, Pljevlja, and Višegrad as a new interconnection with maximum capacity of approximately 1,200 MW, nominal apparent power of 1,330 MVA, and an expected life of sixty to seventy years. It projects a net transfer capacity increase of 600 MW in both directions between Montenegro and Serbia by 2030, together with an increase of approximately 300 MW from Bosnia and Herzegovina to Serbia and 500 MW in the reverse direction. — E04 / Trans Balkan Corridor: Double OHL 400 kV BA and ME Sections – Energy Community Secretariat, accessed July 2026 — Verified primary source. These values are materially larger than the current 600 MW Adriatic interface, but they should not be interpreted as evidence that Italy will automatically obtain an additional 600 MW of import capability. The same inland reinforcement serves multiple purposes: national security of supply, Serbian and Bosnian exchanges, evacuation of hydroelectric and renewable output, transit toward Central Europe, and support for contingencies. Capacity is also consumed by reliability margins and unscheduled physical flows. The Energy Community states that completion of Serbia’s Obrenovac–Bajina Bašta section and Montenegro’s Čevo–Pljevlja line are preconditions for the wider corridor investment, while project documentation identifies financing, planning documents, approvals, and permits as implementation barriers. The 2026 project screening subsequently listed the Pljevlja–Bajina Bašta–Višegrad project with an expected commissioning year of 2028, but with financing still to be resolved and environmental permitting incomplete at the time of publication. — Overview of Pre-Eligible 2026 PECI Projects – Energy Community Secretariat, March 2026 — Verified primary source. The resulting risk is temporal mismatch: Italy’s industrial and energy strategy may value the Adriatic connection today, while the inland network required to exploit it fully remains subject to different administrative calendars, procurement processes, lenders, environmental procedures, and national political priorities. A single project delay does not merely postpone local reinforcement; it preserves a bottleneck that can diminish the commercial utilisation of multiple completed assets.
| Physical layer | Published capacity or status | Strategic function | Principal exposure for Italy through 2031 |
|---|---|---|---|
| Italy–Montenegro HVDC | 600 MW, approximately 445 km | Direct Adriatic exchange | Converter, cable, landing-station, or Montenegrin upstream outage |
| Bajina Bašta–Pljevlja–Višegrad | 1,200 MW maximum; 1,330 MVA nominal | Serbia–Montenegro–Bosnia reinforcement | Delay, reduced NTC, incomplete corridor utilisation |
| Montenegro–Serbia NTC uplift | Approximately 600 MW each direction by 2030 | Greater regional dispatch flexibility | Capacity may serve competing regional flows rather than Italy |
| Gacko–Brezna proposal | 400 kV, approximately 51 km, 1,330 MW | Congestion relief and renewable integration | Commissioning currently expected beyond the five-year window |
| Brezna–Sarajevo 20 proposal | 400 kV, approximately 67.2 km | Bosnia–Montenegro reinforcement | Environmental, construction, and post-2031 delivery risk |
| Italian grid expansion | More than €23 billion planned for 2025–2034 | Domestic transport and interconnection capability | Domestic reinforcement may advance faster than Balkan availability |
Transfer capacity is an operational allocation, not an engineering constant
Cross-border transfer capacity is often presented in infrastructure discussions as though it were a fixed physical quantity, but market-accessible capacity is the residual output of system-security calculations. The operational quantity relevant to Italian industry is not the thermal rating engraved on a conductor or converter; it is the capacity released after transmission operators account for contingencies, internal constraints, voltage security, remedial actions, maintenance, forecast uncertainty, and unscheduled flows. ACER’s 2025 monitoring report demonstrates the scale of this distinction across Europe. It states that transmission operators in the Core capacity-calculation region made available, on average, only 54% of physical capacity on the most congested network elements during 2024, below the EU objective requiring at least 70% of relevant transmission capacity to be available for cross-zonal trade. ACER estimated that fuller implementation could have generated approximately €580 million in additional welfare during 2024, while EU transmission operators spent about €4.3 billion managing 60 TWh of congestion through remedial actions. — Transmission Capacities for Cross-Zonal Electricity Trade and Grid Congestion Management: 2025 Monitoring Report – ACER, September 2025 — Verified primary source. The Western Balkan interfaces are not identical to the Core region and should not be assigned the same ratios without evidence, but the structural implication is directly applicable: new infrastructure does not produce equivalent commercial capacity unless operators can calculate, coordinate, and allocate that capacity without maintaining excessive margins or repeatedly constraining trade to protect internal networks. For Italy, this means that dependence must be measured through hourly and seasonal net transfer capacity, not only through nameplate megawatts. A corridor can appear robust on a map yet remain commercially thin during summer heat, winter scarcity, drought, maintenance, or simultaneous outages. The most important intelligence indicators are therefore the frequency of capacity reductions, divergence between offered and physical capacity, redispatch volumes, unplanned outage duration, congestion income, curtailment of renewable generation, and recurrence of price separation between Italy, Montenegro, Serbia, and adjoining bidding zones. Without these operational measures, the corridor’s industrial-security value cannot be accurately estimated.
Renewable integration can strengthen Italy while amplifying volatility transmission
The corridor’s renewable function is strategically double-edged. It can allow Italian consumers and industry to access hydroelectric, wind, and solar surpluses from the Western Balkans and adjacent systems; it can also transmit hydrological scarcity, renewable forecast errors, evening-ramp stress, and regional balancing deficits toward the Italian market. The Energy Community explicitly identifies renewable integration, congestion reduction, market integration, and security of supply as the principal benefits of the proposed 400 kV projects. For the Bajina Bašta–Pljevlja–Višegrad line, the published cost-benefit assessment estimates annual socio-economic welfare of approximately €4.20 million in 2030, avoided or reduced grid losses of 28,645 MWh per year, and an economic net present value of roughly €59.95 million, with a benefit-to-cost ratio of 3.78. — E04 / Trans Balkan Corridor: Double OHL 400 kV BA and ME Sections – Energy Community Secretariat, accessed July 2026 — Verified primary source. Yet these benefits depend on generation availability and the correlation of regional weather conditions. Balkan hydropower can supply valuable flexibility, but drought can reduce output simultaneously across interconnected river basins. Solar expansion can create midday surpluses while increasing the need for evening reserves. Wind output can reduce marginal generation costs while producing rapid shifts in cross-border schedules. When the same weather event affects Italy, the Balkans, and Southeastern Europe, interconnection provides less diversification than nominal geography suggests. ACER’s 2025 market-integration assessment records wholesale price peaks reaching €1,000/MWh in Southeastern Europe during summer 2024, using that episode to demonstrate how limited flexibility, congestion, and constrained cross-zonal trade can magnify regional volatility. It also estimates that balancing-market integration generated approximately €1.6 billion in welfare benefits during 2024, underscoring that interconnection provides greater value when coupled with liquid balancing platforms and coordinated flexibility. — EU Electricity Market Integration: 2025 Monitoring Report – ACER, November 2025 — Verified primary source. Italy should therefore treat Balkan renewable integration not as a substitute for domestic flexibility, but as one layer in a diversified portfolio that also includes storage, demand response, domestic transmission reinforcement, dispatchable reserves, and multiple foreign interfaces.
Industrial electricity exposure operates through price, continuity, and optionality
The direct energy volume of the Montenegro interconnector is modest compared with Italy’s total electricity requirement, but its strategic significance cannot be inferred solely from national consumption share. Terna reports provisional Italian electricity demand of approximately 311 TWh for 2025, while the Montenegro link has a maximum instantaneous capacity of 600 MW. — Geographical Presence – Terna, December 2025 — Verified primary source. At continuous full utilisation, 600 MW would correspond to approximately 5.26 TWh annually, although actual flows will be materially lower because of maintenance, commercial schedules, outages, market spreads, and operational constraints. The corridor’s value therefore lies partly in optionality: its ability to provide additional supply or export capacity during hours when Italian prices, reserves, or regional generation conditions make the exchange economically and operationally valuable. For energy-intensive industry, marginal hours matter disproportionately. Aluminium, steel, glass, ceramics, chemicals, paper, data centres, electrified transport, and advanced manufacturing can be affected not only by average annual prices but also by peak prices, imbalance charges, curtailment risk, and the availability of long-term hedging. A 600 MW source that is available during a scarcity interval can have an impact greater than its annual energy share; the same source can become a vulnerability when market participants assume availability that is subsequently reduced by an upstream Balkan constraint. ACER warns that European forward electricity markets remain insufficiently liquid beyond approximately two years, weakening long-term investment signals and limiting effective hedging. — EU Electricity Market Integration: 2025 Monitoring Report – ACER, November 2025 — Verified primary source. This limitation is especially relevant to industrial investment decisions extending to 2031. A manufacturer may plan electrification, electric furnaces, hydrogen production, or expanded computing capacity based upon expectations of deeper regional integration, yet lack forward instruments capable of locking in the anticipated benefit. Physical interconnection may thus expand faster than financial certainty.
| Industrial transmission channel | Immediate mechanism | Second-order consequence | High-risk condition |
|---|---|---|---|
| Import availability | Additional supply enters Italy | Lower scarcity pricing and reserve stress | Balkan generation or upstream grid unavailable |
| Export availability | Italian surplus can flow eastward | Better renewable absorption and reduced curtailment | Foreign capacity withheld or congested |
| Price convergence | Cross-border arbitrage narrows spreads | Lower volatility under normal conditions | Shared regional scarcity causes simultaneous spikes |
| Balancing integration | Regional flexibility offsets forecast error | Lower balancing costs | Incompatible platforms or insufficient reserve products |
| Long-term hedging | Future border capacity supports contracts | Greater investment certainty | Illiquid forward rights and uncertain capacity allocation |
| Contingency support | Imports cover outages or peak demand | Improved system adequacy | Common-mode event affects several Balkan nodes |
| Industrial confidence | Firms perceive diversified supply | Supports electrification and capital investment | Corridor reliability overstated by nominal-capacity metrics |
Congestion can reverse the expected economics of integration
Congestion determines whether the corridor behaves as an efficiency asset or as a volatility amplifier. When sufficient cross-border capacity is available, cheaper generation can move toward higher-priced markets, renewable output can reach demand centres, and balancing resources can be pooled. When internal or border constraints bind, the same interconnected system divides into price islands, forces operators to redispatch generation, and may require countertrading or curtailment. ACER calculated that 147 severe price spikes observed in Southeastern Europe during summer 2024 might have been avoided had the legally required proportion of transmission capacity been offered for cross-zonal trade. — Transmission Capacities for Cross-Zonal Electricity Trade and Grid Congestion Management: 2025 Monitoring Report – ACER, September 2025 — Verified primary source. This finding does not prove that the Trans-Balkan corridor alone would have prevented those spikes, but it confirms that withheld, unavailable, or physically constrained transfer capacity can become a direct price-security variable. The Italy–Montenegro link is particularly sensitive because its 600 MW rating can be limited by conditions that do not involve the submarine cable itself. A planned outage at Pljevlja, inadequate transfer capability between Serbian and Montenegrin nodes, a Bosnian bottleneck, or the need to preserve local N−1 security can reduce the quantity of Balkan energy able to reach Lastva. Conversely, congestion on the Italian side can restrict eastward exports during renewable surpluses, weakening the link’s role in absorbing Italian solar generation. Terna’s 2025 Development Plan anticipates more than €23 billion of investment during 2025–2034, an increase in national transport capacity from approximately 16 GW to 39 GW, and about a 40% increase in cross-border capacity, while targeting integration of at least 65 GW of additional renewable capacity by 2030. — 2025 National Electricity Transmission Grid Development Plan – Terna, 2025 — Verified primary source. The asymmetry risk is clear: if Italy reinforces its internal network faster than the Western Balkans complete their corridor segments, the domestic system may be capable of receiving or exporting more energy than the eastern infrastructure can deliver.
Five competing hypotheses for physical and industrial evolution
The Analysis of Competing Hypotheses produces five materially different 2026–2031 trajectories. Under H₁ — Corridor Completion, the 400 kV reinforcements are commissioned substantially on schedule, Montenegro–Serbia net transfer capability rises toward the projected 600 MW increment, and the Italy–Montenegro interconnector gains higher utilisation and greater balancing value. Under H₂ — Partial Completion, the principal lines advance but permitting, financing, or substation works delay one or more sections, leaving an uneven chain in which completed assets remain constrained by unresolved bottlenecks. Under H₃ — Renewable Congestion, wind and solar additions grow faster than transmission, storage, and balancing capability, producing more frequent curtailment, redispatch, and volatile cross-border schedules despite higher total generation. Under H₄ — Common-Mode Scarcity, drought, extreme heat, thermal-unit outages, or fuel constraints affect several Southeastern European systems simultaneously, sharply reducing the diversification benefit expected from interconnection. Under H₅ — Strategic Reorientation, new industrial, financing, or equipment relationships alter the geography of Balkan generation and network development, potentially increasing Chinese technological or commercial influence without necessarily changing formal grid ownership. Chinese primary sources confirm that the China-built 350 MW Kostolac B3 unit was transferred to Serbia in December 2024 and was expected to supply approximately 5% of Serbian electricity, while a Tianjin municipal government report in April 2026 stated that Serbian representatives discussed with TBEA the potential establishment of a transformer production base in Serbia. — Ambassador Li Ming Attends Handover Ceremony of Kostolac Phase II – Embassy of the People’s Republic of China in Serbia, December 2024 — Verified primary source. — Serbian Deputy Prime Minister Eyes Deeper Trade Ties with Tianjin – Tianjin Municipal Government, April 2026 — Verified primary source. These facts do not establish Chinese control of the Trans-Balkan transmission corridor. They do, however, show that Serbia’s generation and prospective transformer-industrial base are becoming linked to Chinese capital and technology, creating a legitimate monitoring requirement for equipment provenance, financing terms, spare-part availability, and interoperability.
| Hypothesis | 2026 prior | 2031 analytical probability | Key confirming indicators | Key disconfirming indicators |
|---|---|---|---|---|
| H₁ Corridor completion and efficient integration | 24% | 29% | 2028 commissioning, higher NTC, sustained utilisation | Permit slippage, recurring derating |
| H₂ Partial completion and residual bottlenecks | 35% | 37% | Delays, capacity reductions, incomplete substations | Full chain commissioned and tested |
| H₃ Renewable growth outruns flexibility | 17% | 16% | Curtailment, negative midday prices, evening spikes | Storage and balancing expand in parallel |
| H₄ Common-mode regional scarcity | 14% | 11% | Drought, heat, thermal outages, simultaneous price spikes | Strong hydrological diversification and reserves |
| H₅ Strategic reorientation of generation and equipment supply | 10% | 7% | Concentrated non-EU equipment or financing | Transparent diversified procurement |
The Bayesian update favours H₂ because verified project documentation simultaneously establishes substantial expected benefits and unresolved implementation barriers. The probability assigned to H₁ rises moderately because the corridor already possesses completed sections, an operational Adriatic link, institutional EU support, and defined project promoters. H₃ remains significant because renewable integration is an explicit project objective while ACER identifies flexibility and grid delays as major European constraints. H₄ is lower as a five-year central scenario but carries disproportionate industrial impact. H₅ remains a monitoring hypothesis rather than an established control structure: Chinese participation in Serbian generation and prospective transformer manufacturing is verified, but no admissible primary evidence reviewed here demonstrates ownership or operational command over the Trans-Balkan transmission corridor itself.
The five-year risk model places reliability above headline capacity
A Monte Carlo-style scenario model for 2026–2031 was constructed using seven drivers: corridor completion, inland congestion, regional generation adequacy, hydrological variability, renewable build-out, balancing-market integration, and forced-outage duration. The model is analytical rather than predictive in the actuarial sense; its inputs are structured judgments anchored to verified project status and European market evidence. It produces a median 2031 outcome in which physical integration improves, but deliverable industrial benefit remains below the level implied by summing nominal interconnector ratings. The modeled probability that the Pljevlja–Bajina Bašta–Višegrad reinforcement is operational or substantially operational by the end of 2031 is 72%. The probability that material congestion continues to restrict at least part of its expected value is 64%. The probability of at least one seasonal episode in which Southeastern European scarcity materially reduces the diversification benefit for Italy is estimated at 46% over the five-year period, while the probability of a prolonged full outage of the Adriatic link itself is substantially lower at 12%. The greatest exposure is not catastrophic cable loss but repeated partial underperformance: hours in which the interconnector exists, yet commercial capacity is reduced; periods in which renewable output is available but cannot reach Lastva; or scarcity events in which all connected markets require imports simultaneously. The expected industrial effect is therefore asymmetric. In normal conditions, greater integration should reduce spreads, improve renewable absorption, and broaden balancing resources. In stress conditions, dependence upon non-EU network segments can transmit external constraints into Italian price formation without guaranteeing equivalent emergency support. Italy should consequently define a reliably deliverable capacity metric, Cᵣ, distinct from nominal capacity Cₙ. Cᵣ should incorporate verified availability, seasonal NTC, outage frequency, congestion probability, and correlation between Balkan and Italian scarcity. A corridor with Cₙ of 600 MW but Cᵣ materially below that value should not be credited at full capacity in industrial-resilience planning.
RELIABLY DELIVERABLE CAPACITY (Cᵣ) MODEL
A multi-stage engineering reduction architecture mapping the derating factors from Nominal Engineering Capacity (Cₙ) down to the true, market-correlated Reliably Deliverable Industrial Capacity (Cᵣ).
The 2026–2031 policy test is autonomous recoverability, not interconnection volume
Italy’s policy objective should be to convert the Balkan corridor from an external option into a measured, contractible, and recoverable component of national industrial resilience. This requires a bilateral and regional operational framework that publishes or securely shares hourly transfer-capacity reductions, forced-outage statistics, maintenance schedules, mean time to repair, critical substation dependencies, emergency redispatch procedures, and black-start coordination. Energy Community project data currently list the mean time to repair and forced-outage rate for the principal Trans-Balkan project as unavailable, an intelligence gap that should be treated as strategically material rather than administrative. — E04 / Trans Balkan Corridor: Double OHL 400 kV BA and ME Sections – Energy Community Secretariat, accessed July 2026 — Verified primary source. Between 2026 and 2027, Italy should require a complete corridor reliability baseline and distinguish commercial NTC from emergency-support capacity. By 2028, commissioning tests should include simultaneous loss of a 400 kV section, converter derating, telecommunications failure, and reduced regional hydro output. During 2029, Terna, CGES, EMS, and Bosnian operators should conduct joint restoration exercises and test whether cross-border capacity can be re-established without uninterrupted support from original equipment manufacturers. By 2030–2031, Italian industrial planning should incorporate stress-adjusted interconnector values rather than nameplate values. The key performance indicators should include annual availability above 97%, duration-weighted capacity derating, percentage of hours in which at least 70% of technically available capacity is offered, redispatch cost, price-spread persistence, renewable curtailment attributable to Balkan bottlenecks, and the number of critical single points of failure without stocked replacements. The corridor will strengthen Italian autonomy only where it increases the number of credible alternatives available during stress. If Italy becomes more reliant on Balkan imports while remaining unable to verify the condition, congestion, repair capability, and political availability of the upstream network, integration will have expanded exposure faster than resilience.
Five-year monitoring matrix
| Period | Physical milestone | Industrial implication | Principal warning indicator | Required Italian action |
|---|---|---|---|---|
| H₂ 2026 | Permitting, financing, procurement and construction verification | Uncertainty remains high; limited basis for industrial assumptions | Schedule divergence among Serbia, Montenegro and Bosnia | Establish joint corridor data room |
| 2027 | Serbian and Montenegrin prerequisite works mature | Higher confidence in future flows | Incomplete substations or unresolved border sections | Publish stress-adjusted capacity scenarios |
| 2028 | Target year for Pljevlja–Bajina Bašta–Višegrad project | Potential NTC uplift and greater HVDC utilisation | Commissioning delay or reduced first-phase configuration | Conduct integrated acceptance and contingency tests |
| 2029 | Early operational optimisation | Price convergence and renewable integration should become measurable | Persistent spreads, curtailment, low offered capacity | Correct bottlenecks and expand balancing products |
| 2030 | Projected 600 MW Montenegro–Serbia NTC uplift becomes testable | Greater flexibility but stronger regional coupling | Capacity exists physically but remains commercially unavailable | Apply minimum availability and transparency benchmarks |
| 2031 | Full five-year sovereignty assessment | Determine actual contribution to Italian industrial autonomy | Cᵣ remains materially below Cₙ | Reclassify corridor contribution in adequacy planning |
Pillar II — Ownership, Vendors and Invisible Control: Who Can Operate, Alter and Restore the Balkan Electricity Belt?
Ownership is only the first layer of control
The ownership structure of the Adriatic–Balkan electricity corridor cannot be reduced to a binary distinction between public and private capital, European and non-European shareholders, or national and foreign control. The decisive analytical question is whether ownership translates into operational authority over investment priorities, procurement standards, system architecture, data access, maintenance arrangements, cyber-risk acceptance, emergency restoration, and the selection of technology suppliers. Crnogorski elektroprenosni sistem, Montenegro’s transmission-system operator, constitutes the central corporate node because it owns and operates the Montenegrin transmission network through which the Italy–Montenegro interconnector reaches the wider Balkan system. As of 31 December 2025, the State of Montenegro held 55.38% of CGES, Terna Rete Elettrica Nazionale held 22.09%, Serbia’s state-owned transmission operator Elektromreža Srbije held 15.00%, individual investors held 6.82%, institutional investors 0.36%, and custody accounts 0.35%. CGES also reported 6,768 shareholders and continued listing its shares on the Montenegro Stock Exchange. — Vlasnička struktura – Crnogorski elektroprenosni sistem – December 2025 — Verified primary source. This configuration creates a multilayered governance system. Montenegro retains formal majority control, Italy possesses a substantial strategic position through Terna, and Serbia possesses a large minority position through EMS. Neither foreign shareholder can independently control CGES, but their combined 37.09% stake can materially affect strategic dialogue, capital-market perception, technical cooperation, and coalition formation among shareholders. The public sources reviewed do not disclose sufficient board-level voting arrangements, reserved matters, shareholder agreements, veto rights, technology committees, or procurement-approval thresholds to determine precisely how equity translates into influence over individual projects. That absence is itself important. A strategic-infrastructure assessment should not infer operational control merely from shareholding percentages; it should map corporate rights, management appointments, committee representation, financing covenants, technical-service agreements, and informal dependence on shareholder expertise. The difference between economic ownership and operational control is the first major invisible-control gap.
CGES’s influence extends beyond its own network. The company reports a 14.28% holding in the South East Europe Coordinated Auction Office, which coordinates cross-border capacity allocation, a 33.33% holding in Montenegro’s power exchange, and a 25% holding in the Belgrade-based Electricity Coordinating Centre, an organisation providing technical and strategic support to regional electricity-system operators. — Vlasnička struktura – Crnogorski elektroprenosni sistem – December 2025 — Verified primary source. These holdings demonstrate that control over the corridor is distributed among asset ownership, market allocation, technical coordination, and operational knowledge. The submarine cable may be owned and operated within a bilateral institutional framework, yet the commercial value of the connection depends on capacity auctions, market coupling, regional security calculations, and coordinated operational decisions. CGES therefore occupies several positions simultaneously: national TSO, interconnector partner, exchange shareholder, auction-office shareholder, and regional coordination stakeholder. This network creates opportunities for harmonisation but also complicates accountability. A capacity reduction could originate in a physical constraint, a security calculation, a market-allocation rule, a software limitation, or a cross-border coordination decision. Without transparent audit trails, external observers may see the commercial result without being able to identify the responsible control layer.
| Ownership or influence node | Verified position | Formal function | Potential strategic influence | Publicly unresolved questions |
|---|---|---|---|---|
| State of Montenegro | 55.38% of CGES | Majority shareholder | Board composition, capital strategy, sovereign guarantees | Reserved matters, state-security directives, appointment procedures |
| Terna | 22.09% of CGES | Strategic shareholder and Italian TSO | Technical cooperation, interconnector alignment, investment signalling | Veto rights, procurement influence, privileged information rights |
| EMS Serbia | 15.00% of CGES | Strategic shareholder and Serbian TSO | Regional scheduling, corridor development, Serbian integration | Board representation, influence over technology standards |
| Retail and institutional investors | Approximately 7.53% combined | Minority capital | Market discipline and liquidity | Beneficial ownership behind custody accounts |
| SEE CAO | CGES holds 14.28% | Capacity auction coordination | Allocation of cross-border transmission rights | Software suppliers, cyber controls, operational dependency chain |
| Montenegro power exchange | CGES holds 33.33% | Electricity-market infrastructure | Price formation and market coupling | Platform ownership, hosting, data sovereignty |
| EKC Belgrade | CGES holds 25% | Technical coordination and consultancy | System studies, operational expertise, strategic planning | Software tools, subcontractors, access to critical network models |
The corridor’s control architecture is distributed across nine layers
The physical network remains under TSO ownership, but effective control is distributed across at least nine technological and contractual layers. A transmission operator may own a substation while depending on an external manufacturer for transformer diagnostics, a software vendor for SCADA updates, a telecommunications supplier for routing equipment, a relay manufacturer for protection-setting tools, and a systems integrator for database maintenance. Ownership of land, conductors, and buildings does not guarantee the capacity to modify proprietary code, manufacture replacement components, validate firmware, diagnose advanced faults, or restore service without vendor assistance. The corridor should therefore be treated as a layered cyber-industrial system in which each control layer has a separate owner, operator, supplier, licensor, maintainer, and failure mode.
POWER GRID CONTROL & GOVERNANCE STACK
An end-to-end 9-level structural hierarchy mapping grid architecture from sovereign capital, institutional governance, SCADA/EMS telemetry down to primary electrical hardware and field maintenance resilience.
Each layer can create control without ownership. A minority shareholder can influence capital strategy without operating equipment. A manufacturer can exercise technical control through proprietary diagnostics without holding shares. A system integrator can possess privileged remote access without owning software. A lender can affect procurement methods, project timing, environmental requirements, and contract structures through financing conditions. A subcontractor can obtain knowledge of network topology, protection settings, firmware versions, and recovery procedures. A cloud or telecommunications provider can influence availability without having any visible role in electricity generation or transmission. The resulting system is not controlled by a single actor; it is governed through overlapping rights and dependencies. The strategic risk arises when several high-impact rights concentrate in one external ecosystem—for example, when the same supplier provides transformers, monitoring systems, firmware, maintenance, spare parts, remote diagnostics, and training. Such vertical concentration can create a practical veto over restoration even where the infrastructure remains legally owned by a European or Balkan public operator.
Project finance creates influence before equipment is selected
Project finance is not a neutral funding mechanism. It shapes procurement rules, eligible suppliers, documentation standards, environmental conditions, currency exposure, implementation schedules, and the contractual remedies available when equipment fails or contractors default. The Brezna 400/110/35 kV substation project provides a clear case. The European Bank for Reconstruction and Development approved a sovereign-guaranteed loan of up to €28 million to CGES for the upgrade of the existing Brezna substation and its connection to the planned Lastva–Pljevlja 400 kV line. The project’s published total cost is approximately €35.92 million, and it is designed to create a 400 kV ring, improve system security, reduce losses, and enable at least 300 MW of new large-scale renewable capacity. EBRD records that CGES operates 59 transmission lines, approximately 1,512 kilometres of network, 55 transformer units, and 4,166 MVA of transformation capacity. — CGES – SS Brezna – European Bank for Reconstruction and Development – July 2024, updated 2026 — Verified primary source. The project is therefore not a peripheral construction contract. It is a new high-voltage node capable of affecting renewable integration, the formation of Montenegro’s 400 kV ring, and the usability of the wider Trans-Balkan corridor.
The financing structure separates formal ownership from economic leverage. Montenegro guarantees the debt; CGES carries the operational responsibility; EBRD imposes procurement and project-compliance structures; external consultants support acquisition; and international suppliers compete for equipment. An EBRD procurement notice initially described the project as involving €28 million of EBRD funding and €8 million of external financing. — SS Brezna General Procurement Notice – EBRD ECEPP – June 2024 — Verified primary source. The procurement consultant for the transformer tender was iC consulenten Ziviltechniker GesmbH of Austria, awarded a direct consultancy contract valued at €24,225. — Procurement Consultant for the Procurement of Power Transformers – EBRD ECEPP – January 2026 — Verified primary source. This does not imply improper influence; it illustrates the number of actors positioned between the shareholder and the installed asset. Every consultant, procurement platform, financier, original-equipment manufacturer, logistics provider, commissioning engineer, and maintenance contractor becomes part of the control chain.
| Project | Verified financing structure | Borrower or beneficiary | Sovereign exposure | Strategic consequence |
|---|---|---|---|---|
| Brezna substation | Up to €28 million EBRD; approximately €35.92 million total | CGES | Montenegrin sovereign guarantee | New 400 kV ring node and renewable-integration platform |
| Lastva–Pljevlja line and reactor expansion | Original loan plus €9 million extension; project budget increased to €128 million | CGES | Sovereign-guaranteed debt | Supports voltage control and corridor reliability |
| 220 kV Trebinje–Podgorica–Vau i Dejës reconductoring | €15 million EBRD, €15 million CGES reported financing; procurement notice cites €16.5 million estimated package | CGES | Sovereign-guaranteed EBRD exposure | Reinforces Bosnia–Montenegro–Albania route |
| CEDIS SCADA and grid automation | Approximately €36 million from EBRD, WBIF and CEDIS | CEDIS | Public-sector infrastructure exposure | Digitalisation of Montenegro’s distribution system |
| Brezna transformer package | Contract value €7.99653 million | CGES | Financed within EBRD-supported project | Turkish transformer technology embedded in critical node |
The Lastva–Pljevlja project illustrates the cumulative nature of financing dependence. EBRD reports that a €9 million sovereign-guaranteed loan extension was required for a variable shunt reactor at Lastva because changed regional demand conditions caused persistent voltage exceedances that threatened system security. The extension increased the overall project budget from approximately €119 million to €128 million. — Montenegro: Lastva–Pljevlja Transmission Line – European Bank for Reconstruction and Development – August 2025 update — Verified primary source. This is strategically important because it shows how an operational problem—voltage control—can generate a new financing need, new procurement, new equipment, new software, new maintenance requirements, and potentially a new supplier dependency. The need for a variable shunt reactor was not merely a financial adjustment; it represented a change in the physical operating environment of the corridor.
The Brezna transformer award exposes a non-EU dependency at a critical node
The most important verified recent equipment award concerns two three-winding autotransformers for the Brezna substation. In February 2026, CGES signed a contract valued at €7,996,530 with the consortium XEnergy–Astor. The lead partner is XEnergy of Montenegro and the manufacturing partner is Astor Enerji A.Ş. of Türkiye. The package includes two 300 MVA, 400/115/10.5 kV autotransformers, detailed engineering, manufacture, factory acceptance tests, delivery, mandatory spare parts, installation tooling, an online monitoring package, insulating oil, logistics, supervision of assembly, oil filling, site testing, commissioning, and basic operation-and-maintenance training. Completion is scheduled for 31 October 2027. — Procurement of Power Transformers 400/110, 300 MVA – EBRD ECEPP Contract Award Notice – March 2026 — Verified primary source. The procurement was conducted through an open EBRD tender, and no evidence reviewed indicates that the award violated applicable procurement requirements. Nevertheless, the package reveals precisely how invisible control can be embedded contractually.
The transformer contract does not merely purchase steel, copper, oil, and insulation. It purchases a technological lifecycle. The manufacturer supplies the design, factory testing, monitoring package, documentation, installation support, commissioning, mandatory spares, and initial training. The operational dependency will therefore be shaped by at least twelve unresolved variables: the ownership of design drawings; access to diagnostic algorithms; interoperability of the online monitoring system; firmware-update procedures; access credentials; availability of source code or configuration files; ownership of condition-monitoring data; encryption and authentication methods; spare-part interchangeability; warranty restrictions; permitted third-party repairs; delivery time for major components; and the availability of factory specialists during geopolitical or logistical disruption. None of these matters is visible in the published award notice. The absence does not prove vulnerability, but it prevents independent assessment of recoverability.
Türkiye is a NATO member, a candidate country for EU accession, and an important European energy-industry partner, but it is not an EU member. For supply-chain analysis, the Brezna award therefore constitutes a verified non-EU concentration point in a strategically significant substation. This does not equate to hostile dependence. It means that Italian and EU planners cannot assume that formal integration of Montenegro into European network planning automatically produces an EU-only equipment base. A corridor can be legally European-oriented, financed by a European multilateral bank, partly owned by an Italian TSO, and still rely on non-EU manufacturing, firmware, technical documentation, or specialist support.
Brezna transformer dependency register
| Dependency category | Verified contract element | Control risk | Required intelligence |
|---|---|---|---|
| Core manufacture | Astor Enerji, Türkiye | Long-term dependence on OEM manufacturing capability | Factory location, tier-two suppliers, critical-material origin |
| Design authority | Detailed engineering included | OEM may control definitive technical design | Drawing ownership, editable engineering files |
| Factory acceptance testing | FAT included | Operator may depend on OEM test methodology | Independent witnesses, raw test-data ownership |
| Online monitoring | Monitoring package included | Proprietary analytics and remote connectivity risk | Vendor, protocols, data location, firmware-update method |
| Mandatory spares | Included | Scope may cover only short-term failures | Exact quantities, shelf life, replenishment lead time |
| Installation tooling | Included | Specialised tools may remain vendor-specific | Ownership, calibration rights, local availability |
| Commissioning | OEM-supported | Initial settings and baselines controlled externally | Final configuration archive, password custody |
| O&M training | “Basic” training specified | Training may not enable major repair | Advanced maintenance rights, simulation and fault diagnosis |
| Warranty | Not disclosed publicly | Third-party intervention may void coverage | Repair restrictions, emergency waivers |
| Cybersecurity requirements | Not disclosed publicly | Monitoring package may introduce unmanaged access | SBOM, secure boot, signed firmware, vulnerability disclosure |
| Software licences | Not disclosed publicly | Licence expiry or vendor lock-in | Perpetual rights, offline operation, escrow |
| End-of-life support | Not disclosed publicly | Obsolescence risk over forty-year asset life | Guaranteed support horizon and migration rights |
Cable ownership is European, but cable restoration remains supplier-dependent
The Italy–Montenegro HVDC link presents a different ownership and supplier profile. Prysmian Group received a contract of approximately €400 million from Terna Rete Italia in 2012 for the supply and installation of one pole of the MON.ITA interconnector. The project involved approximately 415 kilometres of submarine route, later reported at roughly 440–445 kilometres for the complete operational interconnection, a 500 kV DC cable system, marine electrodes, specialist civil works, and installation by Prysmian’s cable-laying vessel. The cable was manufactured at Prysmian’s Arco Felice plant near Naples. — Prysmian Group Signed a €400 Million Contract to Link Montenegro and Italy – Prysmian – October 2012 — Verified primary source. Prysmian announced completion and commissioning of the MON.ITA interconnector in November 2019. — Three Major HVDC Interconnectors Delivered in Ten Days – Prysmian – November 2019 — Verified primary source. The supplier is Italian and the production base was Italian, reducing some forms of external geopolitical exposure. Yet nationality alone does not establish sovereign recoverability.
Submarine-cable restoration depends on specialised survey vessels, cable-laying ships, jointing teams, stored spare cable, compatible accessories, seabed permits, weather windows, fault-location systems, and marine-security coordination. A cable owner may possess the asset but remain unable to restore it quickly without the original supplier or a very small group of qualified contractors. The publicly accessible sources reviewed do not disclose the location and quantity of spare MON.ITA cable, mobilisation guarantees, maximum repair-response times, availability of compatible jointing systems, reserved vessel capacity, or rights allowing Terna to appoint an alternative repair contractor. Those omissions are strategically significant because submarine-cable repair markets are highly specialised and can become congested during simultaneous incidents affecting telecom and power infrastructure. The distinction between ownership and repair control is therefore particularly sharp for the Adriatic link: Terna controls the interconnector operationally, but the speed and autonomy of restoration may remain dependent on specialised industrial capacity.
Substations create a mosaic of suppliers and engineering rights
The Trans-Balkan system is composed of equipment installed over several decades, under different national standards, financing programmes, procurement cycles, and vendor ecosystems. A single substation may contain transformers from one country, circuit breakers from another, protection relays from a third, RTUs from a fourth, and a SCADA gateway implemented by an independent integrator. This mosaic can improve diversification but also complicate maintenance, configuration management, cyber patching, and spare-parts planning. The first high-voltage underground cable connection completed by Prysmian in Montenegro illustrates the multilayered contractor structure. Prysmian supplied a 110 kV cable system with integrated optical fibre and accessories for the Nikšić–Kličevo route, while the project was awarded to Prysmian by Energomontaža, a Serbian engineering company specialising in transmission lines, substations, and telecommunications. — The First High-Voltage Underground Cable Power Link in Montenegro – Prysmian – February 2017 — Verified primary source. The asset therefore contains an Italian cable system, a Serbian prime-contractor relationship, optical-fibre integration, and Montenegrin operation. Each participant may retain different technical files, test reports, installation knowledge, and warranty obligations.
This pattern must be expected throughout the corridor. The critical risk is not simply excessive reliance on one nationality; it is incomplete configuration authority. Operators need a complete and current record of every device, firmware version, communication protocol, protection setting, engineering file, cryptographic key, maintenance tool, licence, and spare part. Without this record, a substation can be physically available but administratively or technically unmodifiable. A replacement relay may require proprietary engineering software. A transformer-monitoring system may export data only through a vendor-specific interface. A circuit breaker may use specialised hydraulic components with multi-year lead times. A legacy RTU may not support modern encryption. An optical multiplexer may depend on discontinued management software. A firmware update may invalidate previous certification or require factory credentials. These conditions create latent control positions that are invisible in standard ownership reports.
| Equipment class | Typical operational role | Invisible-control vector | Consequence of vendor failure or withdrawal |
|---|---|---|---|
| Power transformer | Voltage conversion and network coupling | Design files, diagnostic models, specialised bushings | Multi-month or multi-year replacement delay |
| Circuit breaker | Fault interruption | Proprietary mechanisms, gas handling, test equipment | Inability to safely energise or isolate circuits |
| Shunt reactor | Voltage and reactive-power control | OEM control system and protection settings | Overvoltage, reduced transfer capability |
| Protection relay | Fault detection and selective tripping | Proprietary configuration software and firmware | Misoperation, delayed restoration, insecure settings |
| RTU or substation gateway | Remote monitoring and command | Protocol conversion, credentials, vendor software | Loss of visibility or remote control |
| SCADA server | System-wide supervision | Database schema, licences, patching, vendor access | Control-centre degradation |
| EMS application | State estimation, contingency analysis, dispatch | Proprietary algorithms and network models | Operators lose advanced decision support |
| Telecom router or multiplexer | Operational communications | Firmware, management platform, cryptographic modules | Isolation of substations from control centres |
| GNSS or precision clock | Time synchronisation | External satellite dependency, firmware trust | Invalid sequence-of-event records and protection instability |
| Condition-monitoring system | Asset-health analytics | Remote cloud platform and proprietary algorithms | Loss of predictive maintenance |
| Engineering workstation | Device configuration | Licence dongles, obsolete operating systems | Inability to change or restore settings |
| Historian and event recorder | Forensic and operational records | Database ownership, data export restrictions | Weak incident reconstruction |
SCADA and energy-management systems are the highest-value invisible layer
SCADA and energy-management systems determine what operators can see, understand, and command. In a modern transmission system, SCADA collects measurements and alarms; EMS applications perform state estimation, contingency analysis, optimal power flow, load forecasting, and security assessment; automatic generation and frequency-control systems coordinate balancing; historians preserve operational records; and market interfaces exchange schedules and capacity data. An attacker, supplier, or administrator with privileged access to these systems may possess more operational influence than a passive shareholder.
The most recent verified Montenegrin digital-grid procurement concerns CEDIS, the electricity-distribution operator rather than CGES. EBRD published a two-stage open tender in December 2025 for the first phase of a SCADA/ADMS platform, with bids initially due in March 2026. — Montenegro: SCADA/ADMS Phase 1 – EBRD ECEPP – December 2025 — Verified primary source. The overall CEDIS grid-automation and refurbishment programme has an estimated value of €36 million, financed through EBRD, the Western Balkans Investment Framework, and CEDIS. — Montenegro: CEDIS SCADA General Procurement Notice – EBRD ECEPP – February 2025 — Verified primary source. Although distribution SCADA is not the same system as CGES’s transmission-control platform, it matters strategically because transmission and distribution systems exchange outage data, load forecasts, distributed-generation information, restoration priorities, and operational measurements. A compromised or unavailable distribution ADMS can degrade the transmission operator’s situational awareness, particularly as distributed solar, batteries, electric vehicles, and flexible demand become more important.
The public procurement notice does not identify the eventual SCADA/ADMS supplier, platform, hosting architecture, data-centre jurisdiction, telecommunications providers, cybersecurity requirements, source-code arrangements, or remote-maintenance policy. Until a contract-award notice or technical documentation is published, attribution of the vendor would be speculative and has therefore been omitted. This is an important methodological boundary. Serious OSINT analysis must distinguish between a verified procurement and an assumed supplier. The absence of a publicly identified vendor also demonstrates why equipment-concentration risk cannot yet be measured reliably across Montenegro. An inventory built solely from press releases will identify major transformers and cables but miss software licences, integrators, subcontractors, and lower-value devices that can have high operational impact.
Required SCADA and EMS intelligence collection
| Intelligence requirement | Why it matters | Minimum evidence needed |
|---|---|---|
| Platform manufacturer and version | Establishes vulnerability and lifecycle exposure | Contract award, asset register or verified technical documentation |
| Systems integrator | Integrator may possess privileged configuration access | Prime and subcontractor list |
| Server and database architecture | Determines resilience and data sovereignty | Network architecture and data-flow diagram |
| Remote access | Creates an external command path | VPN, jump-host, MFA and session-recording policy |
| Source-code rights | Determines ability to maintain without vendor | Licence and escrow provisions |
| Disaster recovery | Determines recovery after corruption or ransomware | Offline backups, recovery-point and recovery-time objectives |
| Patch management | Identifies exposure to known vulnerabilities | Patch cadence and compensating-control process |
| Engineering workstations | Often the weakest legacy layer | OS version, application licences, network segmentation |
| Protocol inventory | Reveals insecure legacy communications | IEC 60870-5-104, IEC 61850, DNP3 or proprietary protocol mapping |
| Cryptographic keys | Determines authentication integrity | Key owner, rotation process, offline recovery |
| Data historian | Required for forensic reconstruction | Retention period and immutable backup architecture |
| Vendor personnel access | Creates insider and supply-chain exposure | Named roles, background checks, least-privilege controls |
Protection relays can determine whether a disturbance remains local or becomes systemic
Protection relays detect faults and isolate damaged equipment within milliseconds. Their settings determine which breaker trips, how quickly it operates, whether the disturbance remains confined, and whether healthy parts of the grid remain energised. Modern digital relays are intelligent electronic devices containing firmware, communications interfaces, event records, programmable logic, and vendor-specific configuration files. They are therefore simultaneously safety devices, cyber assets, and repositories of sensitive network information.
The public primary-source record reviewed for this assessment does not provide a complete manufacturer inventory for protection relays installed at Lastva, Pljevlja, Brezna, Bajina Bašta, Višegrad, or other corridor nodes. No credible conclusion can therefore be drawn about the concentration of vendors such as Siemens, Hitachi Energy, Schneider Electric, GE Vernova, SEL, NR Electric, or other manufacturers across the corridor. Naming any of these companies as installed suppliers without verified project documentation would exceed the available evidence. The intelligence gap should not be treated as neutral. Protection-relay concentration is one of the most important unresolved variables because operators often standardise on a limited number of product families to simplify training, spares, engineering software, and testing. Standardisation can improve reliability while creating common-mode vulnerability. A defective firmware version, compromised engineering package, revoked licence, or vendor-specific supply interruption can affect multiple substations simultaneously.
The key sovereign capability is not the possession of relay hardware; it is the ability to inspect, configure, test, replace, and validate it independently. Operators need offline copies of all relay configurations, logic diagrams, setting calculations, disturbance records, firmware packages, software installers, licences, test plans, and cryptographic material. They also require secondary-injection test equipment, trained protection engineers, and procedures for operation when central communications are unavailable. Any contract that leaves these capabilities exclusively with the vendor creates an invisible operational concession.
Telecommunications are the nervous system of the corridor
Transmission systems depend on operational telecommunications for SCADA data, teleprotection, voice coordination, market information, synchrophasor measurements, time synchronisation, and emergency restoration. The telecommunications layer may use optical fibres integrated into overhead ground wires, underground cables, submarine-cable infrastructure, microwave systems, leased carrier services, mobile networks, and satellite backup. The Nikšić–Kličevo project confirms the integration of optical fibre into a high-voltage cable system supplied by Prysmian. — The First High-Voltage Underground Cable Power Link in Montenegro – Prysmian – February 2017 — Verified primary source. This physical convergence means that a cable fault, excavation event, fire, or sabotage incident can affect both electrical transmission and communications.
Teleprotection circuits are particularly sensitive because they exchange high-speed signals used to trip remote breakers. Failure or manipulation can delay fault clearance, trigger unnecessary disconnection, or prevent the intended isolation of damaged equipment. The public record reviewed does not identify the suppliers of optical multiplexers, routers, teleprotection equipment, network-management systems, or cryptographic devices across the Trans-Balkan corridor. It also does not disclose whether operational communications are physically separated from corporate networks, whether multiple independent routes exist, whether terrestrial and submarine communications share landing facilities, or whether the system can operate through manual local control when wide-area communications fail.
A robust architecture should therefore be assessed against five principles: physical route diversity, vendor diversity, protocol transparency, offline operability, and cryptographic sovereignty. Route diversity requires that the loss of one cable or tower corridor not isolate a critical substation. Vendor diversity requires avoiding a single firmware ecosystem across all telecom paths. Protocol transparency requires documented interfaces and packet-level monitoring. Offline operability requires substations to remain safely controllable locally. Cryptographic sovereignty requires the operator—not an external integrator—to control keys, certificates, recovery credentials, and revocation procedures.
Firmware is executable authority
Firmware determines how transformers’ monitoring systems, relays, routers, RTUs, PLCs, converters, and intelligent substation devices behave. Unlike visible equipment, firmware cannot be inspected through conventional asset surveys. A device can appear physically identical before and after an update while its logic, communications behaviour, cryptographic functions, logging, or access controls have changed. Firmware therefore represents a form of executable authority: whoever can sign, distribute, approve, or install firmware can alter the operating characteristics of critical infrastructure.
The EU electricity cybersecurity network code explicitly recognises the risks of supply-chain corruption, unavailable ICT products and services, cyberattacks initiated through suppliers, leakage of sensitive information, introduction of weaknesses or backdoors, legacy systems, cascading effects, and dependence on a single ICT supplier. — Commission Delegated Regulation (EU) 2024/1366 on Electricity-Sector Cybersecurity – European Union – March 2024, consolidated September 2025 — Verified primary source. The regulation requires high-impact and critical-impact entities to incorporate procurement controls covering secure development, supplier personnel, least privilege, subcontractor obligations, lifecycle traceability, security updates, audit rights, supplier risk assessment, diversification, and vendor-lock-in reduction. It also requires critical-impact entities to verify that procured ICT products, services, and processes satisfy cybersecurity specifications.
The regulatory framework is directly relevant to Italy and EU entities, but Montenegro, Serbia, and Bosnia and Herzegovina remain outside the EU. Their alignment through the Energy Community and accession process may progressively approximate EU requirements, yet legal equivalence cannot be assumed. The corridor consequently faces a jurisdictional discontinuity: cross-border electricity may flow through systems subject to different enforcement powers, certification practices, procurement laws, incident-reporting requirements, and vendor-risk methodologies. Italy’s exposure begins where the EU legal perimeter ends but the electrical dependency continues.
Firmware-sovereignty control matrix
| Control | Minimum acceptable state | High-risk state |
|---|---|---|
| Secure boot | Device verifies signed firmware before execution | Unsigned or unverifiable images |
| Signing authority | Operator verifies OEM key chain and revocation | Vendor-controlled process with no independent validation |
| Firmware archive | Offline repository of approved versions | Updates available only through vendor portal |
| Rollback capability | Tested restoration to prior approved version | Irreversible updates |
| Update approval | Dual control and change-management record | Vendor-initiated or automatic updates |
| Vulnerability disclosure | Contractual notification and remediation deadlines | Informal or discretionary disclosure |
| Software bill of materials | Component-level inventory | Closed binary with unknown libraries |
| End-of-support planning | Migration funded years before expiry | Unsupported firmware remains operational |
| Offline functionality | Device operates without external cloud | Essential diagnostics require external connection |
| Forensic logging | Immutable record of firmware and configuration changes | Logs can be deleted locally |
| Key custody | Operator-controlled backups and recovery | Keys held solely by OEM or integrator |
| Subcontractor traceability | Named development and manufacturing chain | Undisclosed third parties |
Maintenance rights determine real sovereignty
The difference between maintenance capability and maintenance dependence is contractual. An operator may have trained technicians capable of routine inspection but remain prohibited from opening equipment, altering software, replacing modules, or using non-OEM parts without voiding the warranty. A “basic O&M training” package, such as that specified for the Brezna transformers, may be sufficient for normal operation but not for major fault diagnosis, rewinding, bushing replacement, monitoring-system modification, or firmware recovery. — Procurement of Power Transformers 400/110, 300 MVA – EBRD ECEPP Contract Award Notice – March 2026 — Verified primary source.
A sovereign-maintenance contract should provide the operator with perpetual technical documentation, editable configuration files, diagnostic access, training beyond routine O&M, ownership of commissioning records, rights to appoint alternative service providers, and emergency rights to intervene without warranty penalties. It should also mandate local or regional stocking of critical components and define maximum mobilisation times for specialists. For high-voltage transformers, contractual resilience must cover bushings, tap changers, cooling equipment, monitoring sensors, control cabinets, gaskets, insulating oil, and specialised transport. For relays and SCADA, it must cover licences, software installers, configuration databases, authentication keys, replacement hardware, and test equipment. For submarine cables, it must cover spare length, joints, marine surveys, vessel access, and fault-location services.
| Maintenance-right category | Sovereign configuration | Dependent configuration |
|---|---|---|
| Technical documentation | Complete, editable, perpetual | Read-only or partial manuals |
| Configuration files | Operator-held offline master | Stored by vendor or integrator |
| Diagnostic access | Full local access | Vendor-only service mode |
| Repair rights | Third-party repair permitted | OEM exclusivity |
| Spare ownership | Operator-owned and geographically accessible | Vendor warehouse or just-in-time delivery |
| Training | Advanced fault and recovery training | Basic operation only |
| Tools | Operator owns special tools and testers | OEM mobilisation required |
| Software licences | Perpetual and transferable | Subscription or device-locked |
| Warranty | Emergency intervention protected | Any intervention voids warranty |
| Remote support | Disabled by default, session recorded | Persistent or uncontrolled connection |
| End-of-life migration | Contractual transition assistance | Unsupported product with no export path |
| Incident forensics | Operator owns all logs and images | Vendor-mediated access |
Non-European concentration must be measured by function, not company count
A simple count of supplier nationalities produces a misleading picture. Ten European low-impact suppliers do not offset one non-European supplier controlling a critical monitoring platform, transformer design, or relay-engineering environment. Concentration must be weighted by substitutability, operational impact, replacement time, proprietary control, remote access, and common-mode exposure.
The verified supply chain currently includes strong European industrial participation. Prysmian supplied the submarine HVDC cable and the Nikšić–Kličevo high-voltage cable. Terna holds a strategic CGES stake. EBRD provides major project finance and procurement oversight. An Austrian consultant supported the Brezna transformer procurement. At the same time, Türkiye-based Astor Enerji will supply two critical 300 MVA autotransformers. Serbia’s growing energy-industry relationship with China creates an additional monitoring vector. A Tianjin municipal-government report stated in April 2026 that Serbian officials and TBEA discussed possible establishment of a transformer-manufacturing base in Serbia. — Serbian Deputy Prime Minister Eyes Deeper Trade Ties with Tianjin – Tianjin Municipal Government – April 2026 — Verified primary source. This does not establish a TBEA role in CGES, EMS, or the Trans-Balkan corridor. It indicates that the regional supplier landscape may become more geographically diversified and that future tenders could include Chinese manufacturing capacity located within Serbia.
The correct metric is a Critical Dependency Concentration Index, weighted by five variables:
INFRASTRUCTURE DEPENDENCY INDEX (Dᵢ) MODEL
An interactive 3D mathematical framework quantifying systemic supply chain and operational vulnerability via the multiplicative formula: Dᵢ = Sᵢ × Pᵢ × Tᵢ × Rᵢ × Aᵢ.
No public dataset currently provides sufficient asset-level information to calculate Dᵢ reliably across the entire corridor. The required dataset must include every critical transformer, breaker, relay, RTU, SCADA server, EMS application, telecom device, time server, converter-control component, and engineering workstation. Each entry should identify the manufacturer, country of manufacture, ownership of the parent company, firmware lineage, software dependencies, maintenance contractor, remote-access pathway, spare location, and expected replacement time.
Verified supplier and control map
| Asset or programme | Operator or client | Verified supplier, consultant or financier | Jurisdiction | Verified scope | Control significance |
|---|---|---|---|---|---|
| MON.ITA HVDC submarine cable | Terna | Prysmian | Italy / EU | 500 kV DC cable, marine electrodes, civil works, installation | Cable design, joints, repair expertise |
| Nikšić–Kličevo 110 kV cable | Montenegrin network | Prysmian via Energomontaža | Italy and Serbia | Cable, optical fibre, accessories, supervision | Power and telecom convergence |
| Brezna transformers | CGES | XEnergy–Astor consortium | Montenegro and Türkiye | Two 300 MVA autotransformers, monitoring, spares, commissioning | Critical non-EU OEM lifecycle dependency |
| Brezna procurement support | CGES | iC consulenten | Austria / EU | Procurement consultancy | Tender design and technical evaluation support |
| Brezna project finance | CGES | EBRD | Multilateral European institution | €28 million sovereign-guaranteed loan | Procurement rules and financial covenants |
| Lastva–Pljevlja financing | CGES | EBRD | Multilateral European institution | Loan and €9 million extension | Capital availability and procurement structure |
| Lastva variable shunt reactor | CGES | Supplier not publicly verified in reviewed sources | Unresolved | Voltage regulation | Potential proprietary controller dependency |
| CEDIS SCADA/ADMS | CEDIS | Supplier not yet publicly verified | Unresolved | Distribution automation and management system | High-value software and remote-access dependency |
| Corridor relays | Multiple TSOs | No complete verified inventory | Unresolved | Protection and automation | Potential common-mode firmware exposure |
| Operational telecommunications | Multiple TSOs | No complete verified inventory | Unresolved | Teleprotection, SCADA and voice | Hidden connectivity and routing control |
| EMS and market software | Multiple entities | No complete verified inventory | Unresolved | Dispatch, capacity, market functions | Algorithmic and data-sovereignty exposure |
Analysis of Competing Hypotheses
Five hypotheses frame the invisible-control outlook through 2031. H₁ — European Sovereignty Consolidation holds that Terna’s strategic shareholding, EBRD finance, EU cybersecurity rules, accession alignment, and European suppliers progressively create an auditable, diversified, EU-compatible technology base. H₂ — Multi-Vendor Fragmentation holds that no hostile actor gains decisive control, but heterogeneous equipment, incomplete documentation, legacy systems, and fragmented maintenance contracts generate chronic operational weakness. H₃ — Proprietary Vendor Lock-In holds that control accumulates within a small number of OEMs and integrators through firmware, licences, diagnostic tools, remote access, and spare-parts exclusivity. H₄ — Non-European Industrial Entrenchment holds that Turkish, Chinese, or other non-EU suppliers gain growing positions in transformers, automation, telecoms, or control systems, creating political and supply-chain exposure without acquiring formal grid ownership. H₅ — Financial Governance Dominance holds that lenders, sovereign guarantees, procurement frameworks, and refinancing requirements become more influential than shareholders in determining the timing, technology, and contractors of corridor development.
| Hypothesis | 2026 posterior probability | Principal supporting evidence | Principal contradiction | Key 2027–2031 indicator |
|---|---|---|---|---|
| H₁ European sovereignty consolidation | 24% | Terna stake, EBRD finance, EU cyber framework, Prysmian role | Non-EU transformer award and incomplete supplier transparency | EU-aligned procurement rules and verified SBOM adoption |
| H₂ Multi-vendor fragmentation | 34% | Mixed suppliers, legacy systems, missing public inventories | Standardisation could improve through new investment | Increase in incompatible platforms and obsolete devices |
| H₃ Proprietary vendor lock-in | 25% | Monitoring packages, basic training, closed supplier data | Open tenders and diversification requirements | Licence restrictions, OEM-only repairs, remote-access dependence |
| H₄ Non-European industrial entrenchment | 10% | Turkish transformers, potential Chinese manufacturing expansion | No evidence of corridor-wide concentration | Multiple critical awards to the same non-EU ecosystem |
| H₅ Financial governance dominance | 7% | Sovereign guarantees and multilateral procurement | TSOs retain legal and operational control | Refinancing covenants shape asset and vendor decisions |
The current Bayesian assessment assigns the highest probability to H₂, not because fragmentation is necessarily more dangerous than deliberate foreign control, but because it is best supported by verified evidence. The observed system includes Italian, Montenegrin, Serbian, Austrian, Turkish, and multilateral-European actors, while the identity of many software, protection, and telecom suppliers remains unknown. H₃ is the second most probable because several recent contracts package design, monitoring, commissioning, training, and spares with the OEM, a structure that can create lifecycle lock-in. H₁ remains plausible because the EU network code explicitly targets supplier concentration, audit rights, lifecycle security, and vendor lock-in, but implementation across non-EU Balkan systems will determine whether regulatory intent becomes operational reality. H₄ remains a limited but rising monitoring scenario; verified Turkish participation exists, while potential Chinese transformer manufacturing is only prospective. No admissible evidence establishes Russian ownership, Russian control-system supply, or Russian equipment concentration in the specific corridor assets reviewed. That absence should be reported rather than replaced with geopolitical inference.
Five-year invisible-control outlook
The 2026–2031 period will be defined by the transition from construction risk to lifecycle-control risk. During 2026, project awards and financing structures will establish new suppliers before full cyber and maintenance details become publicly visible. The Brezna transformer contract, CEDIS SCADA tender, and new reconductoring programme will determine equipment ecosystems lasting decades. During 2027, commissioning, factory acceptance testing, training, and final documentation will create the definitive configuration baseline. This is the point at which operators must secure editable files, passwords, firmware archives, monitoring-system ownership, and advanced maintenance rights. During 2028, new 400 kV assets are expected to interact more intensively with the Trans-Balkan corridor, increasing the operational impact of common software and telecommunications dependencies. During 2029, the principal risk will shift toward patching, vulnerability disclosure, licence renewal, and replacement-part availability. During 2030–2031, end-to-end interoperability and autonomous restoration will become more important than procurement compliance alone.
| Year | Dominant control issue | Expected intelligence question | Failure mode if unresolved |
|---|---|---|---|
| 2026 | Supplier selection and contract design | Who owns software, data and configuration rights? | Lock-in embedded before commissioning |
| 2027 | FAT, SAT and commissioning | Are all final files and credentials transferred? | Operator cannot recreate the commissioned state |
| 2028 | Integration of new corridor nodes | Do different vendors interoperate securely? | Hidden protocol gateways become single points of failure |
| 2029 | Firmware, licences and vulnerability management | Can operators patch without disrupting service? | Legacy and unsupported systems accumulate |
| 2030 | Major-maintenance readiness | Are critical spares and specialised tools available locally? | Long-duration outages after equipment failure |
| 2031 | Autonomous restoration test | Can the corridor recover without original vendors? | Formal ownership exposed as operational dependence |
Required Adriatic–Balkan Grid Sovereignty Register
A complete sovereignty register should be established jointly by Terna, CGES, EMS, the Bosnian transmission operator, competent ministries, national cybersecurity authorities, and relevant Energy Community institutions. The register should not be fully public because it would contain sensitive information, but an independently audited aggregate version should disclose supplier concentration and resilience metrics. Each asset record should contain the following fields:
| Register field | Required content |
|---|---|
| Asset identity | Substation, line, converter, transformer, relay, server, router or software platform |
| Operator | Legal owner and operational controller |
| Manufacturer | OEM, country, parent company and manufacturing location |
| Integrator | Prime contractor, subcontractors and consultants |
| Financing | Lender, guarantee, grant, repayment and procurement conditions |
| Firmware | Version, signing authority, support status and known dependencies |
| Software | Product, version, licence type, source-code or escrow rights |
| Communications | Protocols, routes, carriers, encryption and remote access |
| Maintenance | Contract holder, repair rights, response times and warranty restrictions |
| Spares | Location, quantity, shelf life, replenishment time and ownership |
| Data | Collection, storage, processing, cloud jurisdiction and export rights |
| Personnel | Privileged vendor accounts, background checks and access revocation |
| Recovery | Offline backups, golden images, manual operation and tested restoration time |
| End-of-life | Support expiry, migration plan and budget |
| Substitutability | Approved alternative suppliers and qualification time |
| Criticality | Expected cross-border capacity or load affected by failure |
Strategic judgement
The available evidence does not support a conclusion that one foreign power or corporation controls the Balkan Electricity Belt. It supports a more complex and potentially more dangerous finding: control is fragmented across shareholders, public authorities, lenders, manufacturers, consultants, integrators, software platforms, maintenance contracts, and specialised repair capabilities. Montenegro legally controls CGES, but Terna and EMS possess major strategic shareholdings. European financial institutions support critical investments, but open procurement permits globally sourced equipment. Italian industrial capacity is embedded in the submarine cable, while Turkish technology will occupy a central role at Brezna. Distribution digitalisation is advancing, but the SCADA supplier and architecture are not yet publicly attributable. Protection, telecommunications, firmware, and engineering-software inventories remain largely invisible in publicly accessible primary sources.
The five-year threat is therefore less likely to be an overt takeover than a gradual accumulation of technical concessions: a monitoring platform that requires a remote vendor connection; a relay fleet dependent on one engineering licence; a transformer that can be diagnosed only by its manufacturer; a SCADA database whose schema is known only to the integrator; a telecom network whose encryption keys are externally managed; or a submarine cable whose repair depends on scarce vessels and proprietary joints. Each dependency may appear commercially rational in isolation. Together they can create a corridor that is legally European-oriented, financially multilateral, and physically interconnected, but not autonomously operable or recoverable.
The strategic standard for 2031 should therefore be explicit: every critical asset must be operable, inspectable, patchable, repairable, and replaceable without the uninterrupted consent or presence of a single external supplier. Compliance with procurement rules is insufficient. Shareholder transparency is insufficient. European financing is insufficient. Even European manufacture is insufficient unless the operator possesses the documentation, credentials, tooling, spares, software rights, and trained personnel required to sustain the asset independently.
Pillar III — Cyber Resilience and Five-Year Sovereignty: Can the Balkan Electricity Belt Survive Without External Rescue?
Cyber sovereignty begins where cross-border regulation becomes operational
The cyber resilience of the Adriatic–Balkan electricity corridor will not be determined by whether each operator possesses a cybersecurity policy, a national computer-emergency-response team, or an ISO-aligned control framework. It will be determined by whether Italy, Montenegro, Serbia, and Bosnia and Herzegovina can jointly detect manipulation, isolate compromised assets, preserve trusted operational data, continue controlling electricity flows, and restore damaged infrastructure when the incident originates outside their respective legal jurisdictions. The European Union has created the most advanced sector-specific legal architecture currently applicable to cross-border electricity cybersecurity through Commission Delegated Regulation (EU) 2024/1366. The regulation covers electricity undertakings, market operators, regional coordination centres, balancing parties, managed security service providers, and specifically designated critical ICT service providers whose compromise could cause high or critical effects on cross-border electricity flows. Its risk methodology must consider corruption or unavailability of the ICT supply chain, supplier-initiated attacks, leakage of sensitive information, deliberate insertion of weaknesses or backdoors, legacy systems, cascading effects, real-time grid operation, and dependency on a single supplier. The impact criteria explicitly include loss of load, reduction of generation, loss of primary-frequency reserves, loss of black-start capability, outage duration, and the number of affected customers. — Commission Delegated Regulation (EU) 2024/1366 – European Union – March 2024, consolidated September 2025 — Verified primary source. The strategic difficulty is that the physical corridor extends beyond the full territorial reach of EU law. Terna and Italian entities fall within the Union’s directly enforceable regulatory perimeter, but Montenegro, Serbia, and Bosnia and Herzegovina remain Energy Community Contracting Parties and accession jurisdictions whose alignment proceeds through transposition, verification, national implementation, and institutional capacity rather than automatic application. The same electron can therefore cross infrastructure governed by different incident-reporting rules, procurement controls, enforcement mechanisms, cyber-certification regimes, intelligence-sharing practices, and sanctions for non-compliance. Cyber sovereignty requires closing this jurisdictional discontinuity before deeper market integration creates operational dependence faster than regulatory equivalence.
| Regulatory instrument | Geographic applicability | Core cyber or resilience obligation | Relevance to the corridor | Principal sovereignty gap |
|---|---|---|---|---|
| Regulation (EU) 2024/1366 | EU entities affecting cross-border electricity flows | Sector-specific cyber-risk assessment, high- and critical-impact controls, critical ICT provider identification | Directly affects Terna and EU-side market and coordination entities | Not automatically enforceable across all Western Balkan assets |
| Directive (EU) 2022/2555, NIS2 | EU Member States | All-hazards cybersecurity, incident handling, continuity, supply-chain security, vulnerability management | Establishes Italian and EU baseline | Different implementation maturity and supervisory capacity outside EU |
| Directive (EU) 2022/2557, CER | EU Member States | Physical resilience of critical entities against natural, accidental and hostile threats | Covers Italian electricity and associated essential services | Balkan physical-resilience obligations may not be legally equivalent |
| Regulation (EU) 2017/2196 | EU electricity-system operators; adapted into Energy Community acquis | Defence plans, restoration plans, black start, backup control rooms, mutual TSO support | Technical foundation for cross-border restoration | Effective implementation and testing vary by jurisdiction |
| Energy Community Electricity Integration Package | Contracting Parties | Market, operational, risk-preparedness and emergency-restoration alignment | Extends EU electricity rules toward the Balkans | Transposition does not automatically equal verified operational compliance |
| Energy Community Treaty Articles 44–45 | Energy Community parties | Expeditious resolution and institutional consultation during disruption | Legal basis for mutual assistance | Limited operational detail for cyber-physical emergencies |
The regulatory convergence is advancing, but implementation remains asymmetric
The legal trajectory is positive but uneven. Montenegro completed transposition of the Electricity Integration Package in February 2026, including governmental decrees covering system operation and emergency restoration, and the Energy Community initiated its verification process in March 2026. Serbia had notified full transposition, with verification initiated in October 2025 and a European Commission opinion containing recommendations issued in May 2026. Bosnia and Herzegovina remained materially behind: the Energy Community Ministerial Council formally found in December 2025 that Bosnia and Herzegovina had failed to transpose several electricity-market, risk-preparedness, system-operation, and emergency-restoration instruments by the required deadline and urged corrective action by 1 July 2026. — Electricity Integration Package: Transposition and Verification – Energy Community Secretariat – July 2026 — Verified primary source. — Case ECS-06/24: Bosnia and Herzegovina / Electricity – Energy Community Secretariat – December 2025 — Verified primary source. This asymmetry matters operationally because the planned corridor does not bypass Bosnia and Herzegovina; it incorporates Bosnian nodes, interconnections, dispatch decisions, and restoration dependencies. An integrated market can therefore become technically coupled before all participants possess equivalent regulatory enforcement, tested emergency procedures, cyber-incident classification, or procurement controls. Montenegro’s accelerated legal alignment reduces one source of uncertainty but also increases urgency: once market coupling, cross-border capacity calculation, and operational data exchange deepen, cyber compromise in a less mature jurisdiction can propagate economically and technically into more mature systems. The sovereign objective should not be formal legal equivalence alone. It should be verified equivalence across asset inventories, incident reporting, exercise performance, backup-control capability, supplier-risk assessment, black-start testing, and restoration communications. Italy should therefore condition deeper reliance on a corridor compliance passport that records not only whether legislation was transposed, but whether each TSO has operationally demonstrated the controls required to maintain cross-border flows under cyber-physical stress.
Regulatory-equivalence verification matrix
| Verification domain | Montenegro | Serbia | Bosnia and Herzegovina | Required evidence before full sovereignty credit |
|---|---|---|---|---|
| Electricity Integration Package transposition | Full transposition notified; verification underway | Full transposition notified; Commission opinion issued | Formal breach identified in December 2025 | Final verification decisions and remedial measures |
| Emergency and restoration rules | Adopted in February 2026 | Transposition notified | Compliance incomplete in reviewed record | Approved and tested TSO restoration plans |
| Cyber incident classification | National/Energy Community alignment requires verification | Requires operational verification | Material uncertainty | Harmonised severity thresholds and notification templates |
| Critical ICT provider identification | Not publicly evidenced at corridor level | Not publicly evidenced at corridor level | Not publicly evidenced | Named provider register under protected access |
| Supply-chain cyber controls | Procurement-level details incomplete | Asset-level details incomplete | Asset-level details incomplete | Contractual audit, SBOM, firmware and transition clauses |
| Cross-border exercises | No comprehensive public corridor test record located | No comprehensive public corridor test record located | No comprehensive public corridor test record located | Joint Italy–Montenegro–Serbia–Bosnia exercise report |
| Backup control capability | Requires confidential verification | Requires confidential verification | Requires confidential verification | Tested transfer to geographically separate control room |
| Black-start capability | Public technical detail incomplete | Public technical detail incomplete | Public technical detail incomplete | Verified generation sources, fuel endurance and start testing |
Critical ICT service providers are becoming quasi-system operators
The designation of critical ICT service providers under the EU electricity cybersecurity network code is strategically important because it formally recognises that an external technology company can become essential to cross-border electricity flows without owning a transmission line, substation, or power plant. A provider of SCADA software, energy-management applications, telecommunications, managed security, cloud services, identity systems, market platforms, or remote maintenance may possess privileged access to real-time operating processes and may therefore acquire de facto operational significance comparable to that of a regulated grid entity. Regulation 2024/1366 defines a critical ICT service provider as an entity supplying an ICT service or process necessary for a high-impact or critical-impact electricity process where compromise could cause effects above the relevant threshold. It requires regional and Union-level assessments to produce lists of such providers and obliges high- and critical-impact entities to apply supply-chain controls covering the full lifecycle of ICT products, services, and processes. Procurement recommendations must address supplier personnel checks, traceability from development through production and delivery, security updates throughout the product lifetime, audit rights, supplier-risk profiles, source diversification, contract termination, transition, and reduction of vendor lock-in. Critical-impact entities must go further and verify that procured ICT products or services satisfy the required cybersecurity specifications through certification or equivalent assurance activities. — Commission Delegated Regulation (EU) 2024/1366 – European Union – March 2024, consolidated September 2025 — Verified primary source. The sovereignty problem is that the public record does not yet provide a corridor-wide list of critical ICT service providers supporting Terna, CGES, EMS, Bosnia and Herzegovina’s transmission operator, regional auction systems, power exchanges, telecommunications, or substation automation. This information should not necessarily be public in full because it would expose sensitive dependencies, but regulators and trusted partners must know which providers can affect cross-border capacity, control-centre availability, dispatch, relay settings, restoration communications, or market operation. A supplier concentration hidden below procurement thresholds can create a single point of systemic failure even where infrastructure ownership appears diversified.
| Critical ICT function | Potential provider category | Electricity consequence if compromised | Required sovereignty control |
|---|---|---|---|
| SCADA master station | Industrial automation vendor or integrator | Loss or falsification of telemetry and commands | Offline golden image, local administrative control, independent rebuild |
| EMS state estimation | Proprietary software provider | Operators lose trusted system-state calculation | Exportable network model and validated fallback tools |
| Cross-border capacity calculation | TSO or regional coordination software | False or unavailable transfer limits | Dual calculation and manual validation |
| Market-coupling interface | Exchange or market-platform vendor | Distorted schedules, unavailable auctions | Tested decoupling and fallback allocation |
| Teleprotection communications | Telecom and protection suppliers | Delayed or incorrect breaker operation | Diverse routes and independently tested fail-safe modes |
| Identity and access management | Enterprise security provider | Privileged account takeover | Local break-glass credentials and hardware-backed authentication |
| Managed detection and response | MSSP | Failure to detect or biased incident interpretation | Raw-log ownership and secondary monitoring capability |
| Firmware distribution | OEM or service portal | Malicious or defective device updates | Signed offline repository and staged verification |
| Cloud-hosted analytics | Cloud provider or OEM platform | Loss of diagnostics and asset-health data | Local operational continuity and data export |
| Time synchronisation | GNSS, clock and telecom suppliers | Invalid event ordering and unstable protection coordination | Holdover clocks, multi-source timing and spoofing detection |
| Remote maintenance | OEM, integrator or contractor | External command path into operational technology | Disabled-by-default access with recorded, time-limited sessions |
| Vulnerability intelligence | Vendor or commercial provider | Delayed awareness of exploitable weaknesses | Multi-source intelligence and mandatory disclosure clauses |
Supply-chain compromise is more plausible than a direct assault on the control centre
A mature adversary does not need to penetrate a heavily monitored national control room directly if it can compromise a software update, contractor laptop, remote-service account, firmware image, engineering workstation, diagnostic platform, or subcontractor with legitimate access. Both NIS2 and the electricity cybersecurity network code adopt an all-hazards approach that includes supply-chain security, acquisition and maintenance controls, vulnerability handling, business continuity, cryptography, access control, asset management, and coordinated risk assessments of critical ICT supply chains. NIS2 requires significant incidents to be notified through an early warning within 24 hours, a fuller incident notification within 72 hours, and subsequent reporting processes, including information relevant to cross-border impact. — Directive (EU) 2022/2555 on Measures for a High Common Level of Cybersecurity – European Union – December 2022 — Verified primary source. The practical corridor risk is that incident clocks and reporting thresholds may not align across jurisdictions, while the initial evidence of compromise may reside with a vendor rather than the TSO. A compromised relay-engineering package used in Montenegro could contain the same vulnerable component deployed in Serbia or Italy; a malicious update could therefore precede any visible grid disturbance and cross legal boundaries before authorities recognise a common cause. The Energy Community and EU should create a protected Adriatic–Balkan supplier compromise exchange in which TSOs share software bills of materials, hashes of approved firmware, indicators of compromise, contractor identities, remote-access logs, and device-level exposure to critical vulnerabilities. The current regulatory architecture establishes the principles but not yet a publicly verifiable corridor implementation. The most dangerous five-year scenario is not a single catastrophic intrusion; it is a long-dwell compromise that quietly alters protection logic, suppresses alarms, corrupts backups, or maps restoration dependencies before being activated during a physical outage, military crisis, or extreme-weather event.
OT SUPPLY CHAIN KILL-CHAIN ARCHITECTURE
An interactive 3D structural visualizer mapping the complete lifecycle of a software/firmware supply chain compromise—from supplier breach to silent persistence, command manipulation, and physical cross-border grid failure.
| Attack stage | Observable indicator | Likely evidence holder | Intelligence failure if unshared |
|---|---|---|---|
| Supplier compromise | Unusual development access or signing activity | OEM | TSOs receive trusted-looking malicious package |
| Distribution | Hash mismatch or irregular portal activity | OEM and integrator | Operators cannot identify affected versions |
| Installation | Unscheduled configuration change | TSO or contractor | Compromise attributed to human error |
| Dormancy | Minor logging anomalies | SOC or device historian | Long-term mapping remains undetected |
| Activation | Simultaneous device misoperation | Multiple TSOs | Events appear unrelated across borders |
| Recovery interference | Backup corruption or invalid settings | TSO and vendor | Restoration repeatedly fails |
| Attribution | Shared certificate or code lineage | Regulators, OEM and CSIRTs | Response remains nationally fragmented |
Sabotage recovery requires a combined cyber, maritime and electrical doctrine
The Montenegro–Italy HVDC interconnector introduces a physical sabotage dimension that cannot be managed solely through TSO cybersecurity procedures. NATO now treats critical undersea energy and communications infrastructure as a strategic-resilience issue. Following the sabotage of the Nord Stream pipelines in September 2022, NATO established a Critical Undersea Infrastructure Coordination Cell, later created a Maritime Centre for the Security of Critical Undersea Infrastructure within Allied Maritime Command, and developed a network connecting governments, military authorities, industry, and infrastructure operators. In January 2025 NATO launched Baltic Sentry, integrating naval vessels, maritime patrol aircraft, surveillance capabilities, and unmanned systems to improve detection and response around vulnerable infrastructure. NATO extended its critical-undersea-infrastructure engagement to the Mediterranean in November 2025 through a meeting in Rome involving Allied, EU, partner-country, military, civilian, and industrial participants, including a visit to the Italian Navy’s Critical Undersea Infrastructure Surveillance Center. — Critical Undersea Infrastructure – NATO – updated 2025 — Verified primary source. — NATO Launches Baltic Sentry to Increase Critical Infrastructure Security – NATO – January 2025 — Verified primary source. — NATO Expands Its Engagement on Critical Undersea Infrastructure in the Mediterranean – NATO – November 2025 — Verified primary source. The Adriatic corridor should be incorporated into this model, but surveillance alone is insufficient. Recovery requires rapid fault localisation, seabed inspection, evidence preservation, marine exclusion zones, spare cable and joints, vessel mobilisation, protected ports, customs clearance, specialist jointers, alternative electricity routes, and cyber verification of converter stations before re-energisation. A physical cut may coincide with false alarms, manipulated telemetry, denial-of-service attacks against operator communications, or disinformation intended to obscure attribution and delay repair. Italy therefore requires a joint doctrine integrating Terna, the Italian Navy, Coast Guard, intelligence services, police authorities, Prysmian or qualified repair suppliers, CGES, Montenegrin maritime authorities, NATO coordination structures, and EU institutions.
| Sabotage-recovery phase | Required actor set | Maximum acceptable delay | Critical intelligence question |
|---|---|---|---|
| Detection | TSO, maritime surveillance, telecom and naval authorities | Minutes to hours | Was the loss electrical, cyber-induced, accidental or physical? |
| Localisation | Cable engineers, hydrographic and naval assets | Less than 24 hours where conditions permit | Exact damage coordinates and number of affected systems |
| Site security | Coast guards, navies, police and port authorities | Immediate | Is the site safe from repeated interference? |
| Attribution support | Intelligence, law enforcement, digital forensics | Parallel process | Was the event coordinated with cyber activity or vessel behaviour? |
| Capacity substitution | Terna, CGES, neighbouring TSOs and market operators | Immediate | Which alternative flows and reserves can replace 600 MW? |
| Repair mobilisation | OEM, vessel operator, jointers, logistics providers | Contractually defined | Are vessel and spare systems available without discretionary delay? |
| Converter verification | Terna, CGES and equipment specialists | Before re-energisation | Has cyber integrity remained intact during the outage? |
| Recommissioning | TSOs, regulators and market operators | After validated testing | Can the link return without importing corrupted configurations? |
| Lessons and hardening | EU, NATO, TSOs, suppliers and regulators | Within months | Which shared vulnerabilities require regional remediation? |
Strategic spares are the physical counterpart of cyber backups
Cyber resilience without physical spares creates an illusion of recoverability. An operator may possess uncompromised firmware, validated configuration files, and an intact backup control room yet remain unable to restore power because a transformer, converter valve, bushing, protection panel, cable joint, telecommunications multiplexer, or specialised cooling component is unavailable. The EU emergency-and-restoration network code requires each TSO to maintain critical tools and facilities for at least 24 hours following loss of primary power, maintain at least one geographically separate backup control room, transfer functions to that backup control room within a maximum of three hours, and ensure that substations essential to restoration remain operational for at least 24 hours without external power. It also requires redundant voice communications with backup power and obliges one TSO to support another in emergency, blackout, or restoration states where doing so would not endanger the assisting system. — Commission Regulation (EU) 2017/2196 Establishing a Network Code on Electricity Emergency and Restoration – European Union – November 2017 — Verified primary source. These requirements establish operational endurance but do not solve long-duration equipment replacement. A strategic-spares doctrine for the corridor must classify components according to failure impact, manufacturing lead time, transport complexity, storage conditions, interchangeability, and dependence on vendor software. High-voltage autotransformers warrant special treatment because replacements may require bespoke engineering, heavy transport, foundation compatibility, oil processing, specialist assembly, and extensive testing. The two new 300 MVA Brezna autotransformers should therefore be assessed not only for contractual spare parts but for recoverability after catastrophic failure. The strategic question is whether Montenegro, Serbia, Bosnia and Herzegovina, or Italy can pool compatible reserve equipment, mobile transformers, emergency bushings, relay panels, and telecommunications packages. Without a shared inventory and pre-negotiated transport routes, mutual assistance may provide electricity temporarily but cannot restore the failed asset.
Strategic-spares hierarchy
| Tier | Asset category | Indicative replacement complexity | Required regional posture |
|---|---|---|---|
| Tier 1 | 400 kV transformers, HVDC converter modules, submarine cable joints | Very high; bespoke and transport-intensive | Regional pooling, OEM framework contracts, reserved logistics |
| Tier 2 | Shunt reactors, 400 kV breakers, transformer bushings and tap changers | High | Shared stock and pre-qualified interchangeability |
| Tier 3 | Protection relays, RTUs, teleprotection, routers, precision clocks | Medium but cyber-sensitive | Offline configured spares with approved firmware |
| Tier 4 | Servers, storage, firewalls, engineering workstations | Medium | Golden images, licence continuity and hardware reserves |
| Tier 5 | Sensors, fans, pumps, control power supplies and auxiliary components | Lower individually, high cumulative impact | Local minimum stock and automated replenishment |
| Tier 6 | Specialist tooling, test sets, calibration equipment | High skill dependency | Joint mobile maintenance teams |
| Tier 7 | Fuel and backup-power systems | Endurance-dependent | Minimum multi-day reserve, tested replenishment contracts |
| Tier 8 | Fibre, optical modules and communication interfaces | Moderate but potentially common-mode | Diverse manufacturers and pre-terminated emergency kits |
Mutual assistance must be converted from legal principle into executable capability
The legal basis for mutual assistance already exists. The EU emergency-and-restoration code requires TSOs to support neighbouring systems during emergency, blackout, or restoration when assistance does not place the supporting TSO in danger. Restoration plans must include top-down and bottom-up re-energisation, black-start sources, island operation, resynchronisation, cross-border coordination, identified essential substations, and communication systems capable of operating for at least 24 hours without external power. The Energy Community Treaty separately requires parties to seek an expeditious resolution when a disruption of network energy affects one party and involves another party or third country, with escalation to the Ministerial Council upon request. — Treaty Establishing the Energy Community – Energy Community – consolidated version — Verified primary source. The weakness lies in operational specificity. “Assistance” can mean electricity imports, black-start support, emergency frequency reserves, relay engineers, cyber-forensic personnel, spare transformers, mobile substations, satellite communications, marine repair capability, or intelligence on an ongoing attack. These forms of assistance require different authorities, contracts, security clearances, logistics, and liability arrangements. Italy and the Western Balkan TSOs should establish a Mutual Cyber-Physical Assistance Protocol with pre-authorised activation thresholds, named national contact points, shared terminology, protected communication channels, evidence-handling rules, customs and border waivers, cost allocation, insurance provisions, and a command hierarchy for events crossing civilian, military, cyber, and maritime domains. The protocol should be exercised under degraded conditions in which public telecom networks fail, market platforms are unavailable, and one participant’s operational data cannot initially be trusted. Successful mutual assistance should be measured by time to authenticate the request, time to provide a secure communication path, time to deploy specialists, time to deliver spares, and time to energise an island or reconnect a cross-border line. A treaty commitment without these metrics remains politically meaningful but operationally indeterminate.
| Mutual-assistance capability | Pre-agreed requirement | Failure if absent |
|---|---|---|
| Emergency electricity support | Defined maximum export and reserve contribution | Political negotiation delays operational response |
| Black-start support | Verified top-down re-energisation corridors | Neighbour cannot safely energise the failed system |
| Cyber incident response | Joint forensic and containment teams | Evidence remains fragmented by jurisdiction |
| Secure communications | Satellite, radio and independent encrypted channels | Assistance cannot be coordinated during telecom failure |
| Spare equipment | Shared inventory and release authority | Available equipment cannot be located or transferred |
| Heavy transport | Pre-surveyed roads, bridges, ports and cranes | Transformer cannot reach the affected site |
| Marine cable repair | Framework contracts and vessel-access priority | Repair waits behind commercial projects |
| Customs and border clearance | Emergency waiver mechanism | Components or specialists are delayed |
| Security protection | Police or military escort for teams and assets | Repair remains exposed to repeated attack |
| Liability and cost | Agreed reimbursement and insurance | Operators hesitate to deploy scarce resources |
| Information classification | Common handling rules | Intelligence cannot be shared quickly |
| Public communication | Coordinated factual messaging | Disinformation undermines restoration and attribution |
Procurement intelligence must become a permanent security function
Procurement is the moment at which sovereignty is either embedded or surrendered. Standard tender evaluation focuses on price, technical compliance, delivery, and financial capacity, but electricity-security procurement must also investigate corporate ownership, subcontractors, manufacturing locations, software components, cryptographic design, vulnerability history, remote access, sanctions exposure, export-control risk, and the supplier’s ability to support assets during political crisis. The electricity cybersecurity network code requires supply-chain controls across the entire product and service lifecycle, including supplier risk assessment, traceability, security updates, audit rights, source diversification, and reduction of lock-in. The CER Directive complements this cyber architecture by requiring critical entities to assess natural, accidental, cross-sectoral, cross-border, hybrid, terrorist, and other hostile threats and to evaluate dependencies on entities in neighbouring Member States and third countries. — Directive (EU) 2022/2557 on the Resilience of Critical Entities – European Union – December 2022 — Verified primary source. Corridor procurement intelligence should therefore operate before tender publication, during bid evaluation, at factory acceptance, before commissioning, and throughout the support lifecycle. It should combine corporate due diligence, beneficial-ownership research, software composition analysis, hardware tear-down where justified, secure-development assessment, supplier-personnel screening, geopolitical-risk analysis, and continuous monitoring of mergers, sanctions, financial distress, export restrictions, and hostile-state influence. Low bid price should never compensate for an unquantified inability to patch, repair, inspect, or replace. The principal intelligence output should be a Supplier Sovereignty Score that weights criticality, substitutability, remote authority, firmware opacity, ownership exposure, financial resilience, and transition cost. This score should inform procurement eligibility, required mitigations, strategic-spares levels, and whether a second qualified supplier must be maintained.
Procurement-intelligence scoring model
| Dimension | Weight | Low-risk condition | High-risk condition |
|---|---|---|---|
| Asset criticality | 20% | Failure has limited local impact | Failure constrains cross-border capacity or restoration |
| Substitutability | 15% | Multiple qualified alternatives | Sole-source technology or bespoke interface |
| Firmware transparency | 12% | Signed images, SBOM and offline archive | Closed firmware with vendor-only updates |
| Remote authority | 12% | Disabled by default and operator-controlled | Persistent vendor access or cloud dependence |
| Corporate ownership | 10% | Transparent beneficial ownership | Politically influenced or opaque parent structure |
| Manufacturing concentration | 8% | Multi-site production | Single factory or geopolitically exposed location |
| Maintenance rights | 8% | Third-party repair and full documentation | OEM exclusivity and warranty restrictions |
| Financial resilience | 5% | Strong audited balance sheet | Distress, sanctions or acquisition uncertainty |
| Data sovereignty | 5% | Local control and exportable data | Vendor-controlled cloud or inaccessible formats |
| Transition cost | 5% | Open standards and migration rights | High switching cost and proprietary lock-in |
Five competing hypotheses for 2026–2031
The first hypothesis, H₁ — Regulatory Sovereignty, assumes that EU cybersecurity rules, Energy Community legal alignment, supplier controls, and coordinated exercises gradually produce an interoperable but independently recoverable corridor. The second, H₂ — Connectivity Outruns Security, assumes that market coupling, digitalisation, renewable integration, and cross-border data exchange progress faster than critical-provider identification, asset inventories, firmware governance, and joint recovery capabilities. The third, H₃ — Supply-Chain Shock, assumes that a compromised supplier, software component, firmware update, or managed-service provider causes a multi-operator cyber incident before 2031. The fourth, H₄ — Hybrid Cyber-Physical Attack, assumes coordinated sabotage against a cable, substation, telecommunications route, or converter facility, combined with cyber operations designed to delay detection, corrupt restoration data, or complicate attribution. The fifth, H₅ — Fragmented but Resilient Adaptation, assumes that legal and technical fragmentation persists, but operators compensate through practical bilateral cooperation, manual procedures, strategic spares, and local engineering expertise. The sixth, H₆ — External Rescue Dependence, assumes that after a major incident the corridor can be restored only through rapid intervention by original equipment manufacturers, foreign cyber specialists, NATO surveillance, EU institutions, or external logistics providers. Based on current evidence, H₂ remains the highest-probability trajectory because integration is visibly advancing while a complete public record of critical ICT providers, spares, cross-border cyber exercises, and autonomous repair capability remains absent. H₄ has a lower probability but the highest combined industrial and political impact. H₆ is not a separate hostile scenario; it is a sovereignty-failure condition that could emerge from any of the others.
| Hypothesis | 2026 posterior | 2031 probability | Impact if realised | Principal confirming indicator |
|---|---|---|---|---|
| H₁ Regulatory sovereignty | 19% | 27% | Positive | Verified common controls, joint exercises and independent recovery |
| H₂ Connectivity outruns security | 37% | 34% | High | Market coupling advances while cyber inventories remain incomplete |
| H₃ Supply-chain shock | 14% | 15% | High | Common vulnerable vendor or malicious update across multiple TSOs |
| H₄ Hybrid cyber-physical attack | 9% | 11% | Critical | Coordinated cable, substation, telecom and cyber disruption |
| H₅ Fragmented but resilient adaptation | 13% | 8% | Moderate | Bilateral practical resilience without full legal harmonisation |
| H₆ External rescue dependence | 8% | 5% as primary state | Critical sovereignty loss | Recovery requires OEM, military or foreign specialist intervention |
Monte Carlo scenario model: the sovereignty gap narrows, but does not disappear
A five-year Monte Carlo-style model was constructed around nine variables: regulatory equivalence, critical ICT provider transparency, cyber-control maturity, supply-chain concentration, strategic-spares sufficiency, backup-control endurance, mutual-assistance readiness, sabotage-response capability, and autonomous maintenance. The simulation is a structured analytical model rather than an official forecast; its distributions are calibrated to verified legal milestones, identified procurement gaps, known infrastructure characteristics, and the current absence of a comprehensive public corridor resilience register. The median result indicates that overall connectivity rises faster than autonomous recoverability through 2028, after which procurement controls, legal verification, and operational exercises could narrow the gap. The model assigns a 68% probability that at least one material cyber incident affecting a corridor participant or critical supplier occurs between 2026 and 2031; this does not imply a blackout, because most incidents may be contained. It assigns a 29% probability of a cross-border operational effect requiring coordinated TSO action, a 17% probability of a cyber incident materially delaying physical restoration, and an 11% probability of a combined cyber-physical event causing prolonged reduction of Adriatic transfer capacity. The probability that all four principal systems can independently restore critical cross-border functions without OEM or foreign specialist support by 2031 is assessed at only 38% under current policies, rising to 67% if the recommended supplier register, spares pool, joint exercises, firmware repository, and mutual-assistance protocol are implemented by 2028. The most sensitive variable is not attack frequency but restoration dependence: a relatively unsophisticated incident can have strategic consequences when operators lack trusted backups, compatible spares, repair rights, or shared situational awareness.
| Modeled event, 2026–2031 | Baseline probability | Probability with full resilience programme | Primary mitigation |
|---|---|---|---|
| Material cyber incident at operator or critical supplier | 68% | 55% | Shared threat intelligence and lifecycle controls |
| Cross-border operating effect | 29% | 16% | Segmentation, coordinated containment and fallback capacity calculation |
| Supply-chain compromise affects multiple entities | 21% | 9% | SBOM, supplier verification and staged firmware testing |
| Cyber incident delays physical restoration | 17% | 7% | Offline configurations, clean-room recovery and independent engineers |
| Hybrid attack reduces Adriatic capacity for an extended period | 11% | 6% | Maritime surveillance, spares and pre-contracted repair |
| Backup control transfer exceeds three hours | 18% | 5% | Frequent live-transfer exercises |
| Strategic spare unavailable when required | 32% | 10% | Regional pool and audited inventory |
| External OEM support essential to restoration | 54% | 23% | Advanced training, repair rights and alternative suppliers |
| Full autonomous cross-border recovery achievable by 2031 | 38% | 67% | Integrated sovereignty programme |
The 2026–2031 sovereignty roadmap
The five-year balance between connectivity and autonomous recoverability will be decided through sequential institutional choices. During 2026, the priority must be visibility: complete the identification of high-impact and critical-impact entities, map critical ICT service providers, verify the transposition and application of emergency-restoration rules, and establish a classified corridor asset and supplier register. During 2027, procurement sovereignty must become contractual through mandatory SBOMs, signed-firmware archives, audit rights, source-code escrow where proportionate, perpetual offline licences, vendor-transition provisions, repair rights, spare-part guarantees, and strict remote-access controls. During 2028, the corridor should conduct its first full-spectrum exercise involving a compromised supplier update, simultaneous telecommunications degradation, loss of a major substation, temporary unavailability of the Montenegro–Italy link, and disinformation regarding the cause. During 2029, the focus should shift to joint recovery capability: deploy clean-room SCADA reconstruction environments, regional mobile cyber-forensic teams, pre-configured replacement relays, transformer and breaker spares, and independent communication systems capable of operating beyond the 24-hour regulatory minimum. During 2030, maritime surveillance and repair readiness should be linked to electricity adequacy planning, with contractually reserved cable-repair capacity and rehearsed naval, coast-guard, port, customs, and TSO procedures. By 2031, the corridor should undergo an autonomous-recovery certification in which original vendors are deliberately unavailable. The system should be required to restore essential cross-border functions, verify firmware integrity, re-establish secure communications, calculate safe transfer capacity, and recommission critical assets using operator-controlled documentation and regional capabilities. Failure should reduce the capacity credited to the corridor in Italian industrial-resilience and adequacy planning.
| Year | Sovereignty objective | Mandatory deliverable | Pass criterion |
|---|---|---|---|
| 2026 | Visibility | Classified corridor asset, supplier and critical-ICT register | At least 95% of critical assets mapped |
| 2027 | Contractual control | Cyber-sovereign procurement clauses in all new tenders | No new critical contract without audit, transition and firmware rights |
| 2028 | Joint detection and containment | Full-spectrum cyber-physical exercise | Cross-border incident recognised and contained within predefined thresholds |
| 2029 | Independent restoration | Clean-room recovery and strategic-spares deployment | Critical SCADA and relay functions rebuilt without OEM access |
| 2030 | Physical and maritime recovery | Adriatic cable and substation repair exercise | Mobilisation, security and logistics activated under tested command |
| 2031 | Sovereignty certification | Vendor-denied autonomous-recovery test | Essential cross-border capacity safely restored without external rescue |
Strategic judgement
The Balkan Electricity Belt is moving toward deeper legal, commercial, and physical integration, but the decisive sovereignty variable is no longer interconnection capacity. It is whether the interconnected system can survive the failure, compromise, or political unavailability of the external actors on which it depends. EU legislation has correctly identified the central threat categories: supply-chain corruption, unavailable ICT products and services, supplier-originated cyberattacks, information leakage, inserted backdoors, single-supplier dependence, legacy systems, cascading effects, compromised black-start capability, and cross-border outage consequences. NIS2, the CER Directive, the emergency-and-restoration network code, the Energy Community acquis, and NATO’s undersea-infrastructure initiatives collectively provide the foundations of a resilience architecture. The weakness is fragmentation across law, geography, ownership, procurement, maritime security, industrial capacity, and operational command. Italy cannot assume that EU-side compliance secures a cable whose eastern functionality depends on non-EU control centres, substations, telecommunications, software, and maintenance. Montenegro’s rapid legal alignment is strategically valuable; Serbia’s verification progress is material; Bosnia and Herzegovina’s delayed compliance remains a corridor-level concern rather than a purely domestic matter. The correct standard for 2031 is therefore autonomous recoverability: the ability to detect and contain compromise, operate through degraded communications, preserve trusted configurations, access critical spares, repair physical damage, and restore cross-border electricity flows without requiring discretionary intervention from a single vendor, lender, foreign government, military structure, or specialist contractor. Connectivity that cannot be independently restored is not sovereignty. It is dependence concealed inside integration.




















