EuroOilWatch Analysis β an audit of eight jurisdictions on a single question: can the public find out whether the grid can be rebuilt?
The title is not literally true, and it is worth conceding that in the first paragraph rather than the last.
Electricity companies do hold spare transformers. European law requires operators to maintain and rehearse system defence and restoration plans. Some transmission operators maintain substantial strategic inventories, and one member state publishes an actual number.
What nobody appears to have built is a transparent public standard by which any of this can be judged sufficient.
We are told that equipment exists. We are not told what proportion of critical infrastructure is covered, what level of simultaneous damage the arrangements are designed to withstand, whether smaller operators are included, or what restoration time the public should expect. The location and specification of individual assets may properly remain confidential.
Aggregate adequacy need not.
The missing reserve is therefore not necessarily a warehouse full of machinery. It is a measurable guarantee that the system can be rebuilt.
A regime that mandates rehearsal and forbids disclosure of the result
Start with the European instrument, because its structure explains a great deal about what follows.
Regulation 2017/2196 β the network code on electricity emergency and restoration β requires operators to test black-start capability at least every three years and to simulate restoration at least every five. That is a genuine, recurring obligation to rehearse.
It also imposes professional secrecy on the restoration plans themselves. It sets no deadline for putting customers back on supply. It requires no spare inventory of any kind. The word "spare" appears in it zero times β every apparent hit is the substring inside transparency.
So the exercises happen and the results are not public. There is no published standard the exercises are testing against, and no published finding about whether they passed.
Guidance issued in July 2026 moves in the right direction and stops well short. It suggests entities "should consider strategic stockpiling" and "should define recovery time objectives" β self-set, and explicitly not legally binding. The words transformer and lead time do not appear in it at all.
There is one instructive wrinkle. Germany publishes the joint system defence plan of all four of its transmission operators β 38 pages, both the 2020 and 2024 versions, containing zero occurrences of the German terms for confidential, security-relevant, or the federal information-security and critical-infrastructure designations. Only the network restoration plan is withheld. And reading the regulation directly, neither plan carries any publication duty: Article 4(5) requires only notification to the regulator.
Germany therefore publishes its system defence plan voluntarily, with no obligation to do so β which tells you the secrecy applied to the other plan is a content judgement, not a blanket legal requirement. The distinction between what must be secret and what is merely unpublished is available to every member state. Almost none of them draw it.
Why this question exists at all
Energy security is measured in stocks and flows. Days of supply. Installed capacity. Reserve margins. Barrels, cubic metres, gigawatts.
Almost nobody asks the other question: if a critical component is destroyed tomorrow, how long until it is replaced?
That question has become urgent for an unglamorous reason. The machinery that moves and converts energy has developed lead times measured in years. The International Energy Agency reports that waiting times for transformers and cables doubled in three years, that procurement now runs to two or three years for cables and up to four years for large power transformers β twice as long as in 2021, and that new transmission lines take four to eight years in advanced economies. Transformer prices have risen around 75% since 2019.
A grid can hold ninety days of fuel and still be uninsurable against a component that takes four years to arrive.
The word that means everything except this
Search for "strategic reserve" in any European grid context and you will find something. In the Netherlands and Sweden it means a generation capacity mechanism. In Germany it means frequency reserve β KapazitΓ€tsreserve, Netzreserve, Reservekraftwerke. In Spain it means gas and oil stocks. Germany's federal "Nationale Reserve Blackout" is mobile diesel generators.
The vocabulary of preparedness is everywhere. It is attached to fuel, to megawatts, to frequency β to everything except the physical equipment that takes four years to replace.
This is not a linguistic curiosity. It is the shape of the blind spot. Institutions have built formal, funded, audited frameworks for judging whether there is enough generation. There is no counterpart for asking whether there is enough equipment.
What the audit found
We put eight questions to eight jurisdictions β France, Germany, Italy, the Netherlands, Poland, Spain, Great Britain and the United States β and to the European Union's own instruments. The questions were not about inventories. They were about disclosure: is a regime acknowledged; is its scope defined; is participation mandatory; is a minimum adequacy requirement published; is a restoration-time objective published; are exercises reported; is there independent oversight; is aggregate adequacy assessed in public?
Two results were uniform.
Not one jurisdiction publishes a minimum adequacy requirement for spare equipment. Eight out of eight.
Not one publishes a replacement-time objective for destroyed equipment. Also eight out of eight.
Several publish something that looks like it and is not. Germany raised the European floor for black-start ride-through endurance from 24 to 72 hours. France requires 1,000 sites to hold 24 hours of autonomy and 1,800 to hold ten, and tracks progress against those targets. Spain specifies at least two black-start-capable hydro plants per restoration area. Britain requires 60% of regional demand restored within 24 hours and 100% within five days.
Every one of those is real, quantified and enforceable. And every one of them measures how long something survives without power, or how fast an intact system restarts. None measures how quickly a destroyed thing is replaced.
### Restarting the grid is not the same as rebuilding it Black-start capability restores a system that is intact but de-energised. Strategic spares restore a system that is physically damaged. A country can hold excellent black-start resources and still be unable to re-energise a region whose transformer has been destroyed β and replacing that transformer does not, by itself, mean the wider network can be synchronised and restarted. The two capabilities are complementary and are routinely conflated. Only one of them is measured in public.
The blackout that never asked the question
Spain provides the sharpest fact in the audit.
On 28 April 2025 it suffered a complete national blackout β the most consequential European grid failure in decades. It produced exactly the institutional response you would hope for: a national risk-preparedness plan already in place, an incident report from the grid operator, and an ENTSO-E expert-panel final report running to some 800 pages.
None of them assessed spare-equipment adequacy at all.
Not inadequately. Not inconclusively. The question was never asked, by any of the authorities involved, in any of the documents produced.
That is the finding that should trouble European regulators most, because it is not a gap in the law. It is a gap in the reflexes of the people responsible for learning from failure.
Poland publishes the number. Nobody judges it.
Poland is the exception that proves the rule. It is the only jurisdiction publishing a hard figure: the transmission operator discloses five reserve units totalling 966 MVA against 219 installed units totalling 62,159 MVA β and zero reserve units for its two highest voltage classes.
That is real disclosure. It is more than any other European country provides.
And no document anywhere β not from the operator, the regulator, the ministry or the European Commission β assesses whether it is adequate.
So the obstacle is not that the data cannot be published without compromising security. Poland has published it. The obstacle is that even when published, sufficiency is never judged.
Italy comes closest to a standard and stops short. Its national risk-preparedness plan is the only one that names the equipment: the operator "shall⦠prepare a significant set of spare parts and spare large components, such as autotransformers of any rated power and voltages." A significant set. Unquantified, unbudgeted, and carried into no binding instrument.
France frames it as supply chain, not reserves. Its parliamentary trail concerns qualifying additional manufacturers and long-term contracts. No strategic stock is mentioned.
Germany: a duty asserted, no data held, and no claim of secrecy
Germany is worth following in detail, because the chain of delegation is fully documented and it terminates nowhere.
In January 2026 an attack on a cable bridge left roughly 50,000 Berlin households without power, with full restoration only on the fifth day. Asked in March what statutory requirements exist for holding spare parts, the federal government replied that assessment of need and provisioning "is incumbent on the network operator," with requirements to "be formalised" in future through separate legislation.
A full search of that answer found no claim of confidentiality anywhere in it. Where the government lacked information, it said so plainly: it could not even state the cost of restoring the Berlin outage.
No requirement, no target, no data β and no claim of secrecy. That is a more serious position than secrecy, because secrecy at least implies somebody knows.
And the operators to whom the duty was delegated do not close the loop. All four German transmission system operators were examined β Amprion, TenneT, 50Hertz and TransnetBW. None publishes a spare-transformer holding, a spares policy, or a replacement-time objective.
More revealing than the absence is how they characterise the risk. Three of the four treat the scarcity of large equipment as a procurement problem. TransnetBW's chief executive states it cleanly: "the limited choice of suppliers constitutes a risk. Long lead times and supply bottlenecks noticeably slow down grid expansion." His proposed remedy is stronger European supply chains and procurement reform. Not inventory.
Amprion does not characterise it at all. Its statutory risk report identifies information security, personnel and liquidity, and concludes that in the 2024 financial year "no risks were identifiable which individually or in aggregate could endanger the continued existence of the group." The German word-stem for procurement appears zero times across the entire 218-page report.
So none of the four frames this as a stockholding question. And the strongest public artefact any of them has produced on the subject is a single sentence β about one reserve transformer at one substation β disclosed incidentally in a press release, because a bridge rebuild was about to make deliveries to the site impossible for between two and four years. Amprion has since taken that page down. It survives on a municipal council's mirror.
Procurement reform is a sound answer to supplier concentration. It is not an answer to a transformer destroyed on a Tuesday.
Nobody's auditor has ever asked
If the regulators do not measure adequacy, the obvious next question is whether anyone audits the regulators.
Germany's federal audit office has audited electricity supply security hard β and never audited this. Across its three energy reports the terms for spare transformers, spare parts, stockholding and storage appear zero times, on a search system demonstrably capable of reading full document text. Every occurrence of "reserve" refers to generation reserve.
The comparison that makes this damning is internal to the Bundesrechnungshof's own work. Its 2007 annual observations contain the word Ersatzteil β spare part β 43 times, in a finding that "planning defects lead to inappropriate spare-parts stockholding at the air force," which had failed for twenty years to establish a standardised method for determining initial spare-parts requirements.
The method exists. Germany's auditors know precisely how to examine whether an institution holds enough spare parts, and how to say so bluntly when it does not. They have applied it to the Luftwaffe. They have never applied it to the Stromnetz.
Britain has not reached that stage either. Its National Audit Office published a March 2026 report on resilience to severe space weather β a scenario it describes in its own words as causing "multi-month outages from transformer damage" β across which the words spare, stockpile, replacement, lead time, restoration and inventory appear zero times each.
Only the United States has the answer that should exist everywhere. In August 2023 the Government Accountability Office reported that the Department of Energy had failed to carry out a transformer-reserve adequacy assessment that Congress had required by law β due May 2022, delivered July 2024. GAO also found that "none of the co-ops or municipals we spoke to participated in existing industry sharing efforts," despite those operators holding "critical nodes and interconnections whose failure could result in large-scale outages."
America, in short, has publicly measured its own ignorance. No European institution has.
What a spare is actually worth
All of which would be abstract, were it not for one transmission owner that volunteered the answer.
In its most recent asset management strategy, SSEN Transmission β which operates the north of Scotland β published two case studies. In the first, a strategic spare circuit breaker returned a circuit to full service in six weeks against a typical minimum of three to six months. In the second:
**"The failure of a relatively young transformer (<10 years old)β¦ was rectified within 8 weeks due to the decision to hold a strategic spare transformer. The Grid Supply Point could have been at risk for 2 to 3 years based on the order time for asset replacement."**
Eight weeks, against two to three years. The difference between a manageable outage and a regional supply point compromised for the better part of a parliament β decided entirely by whether one company had chosen, in advance, to hold one transformer.
It was published voluntarily. It was required by nothing. No obligation exists to repeat it. And a neighbouring operator under the same regulator discloses the opposite posture, warning that a strategic cable stock "will be exhausted with no replenishment available" and that where components are unavailable, "spares are recovered from assets being removed from the system."
Two operators, one regulator, opposite postures β and neither measured against any standard, because no standard exists.
A recovery regime is not defined by the preparedness of its strongest members. It is defined by the least recoverable critical node on which the rest of the system still depends.
The people inside are asking for it too
There is a version of this argument that would be easy to dismiss: outsiders demanding a standard practitioners know to be unworkable. The most recent parliamentary evidence in Britain does not support that reading β the request for a published benchmark comes from the regulated side.
Asked in June 2026 whether industry was prepared for an escalating threat, Offshore Energies UK's security policy manager answered that preparedness cannot be assessed without a standard to assess it against:
**"Preparedness for the future requires us to first understand what the benchmark for resilience is that is expected by Government. For example, do we have certain performance standards and expectations for uptime and speed to prepare, and what might we need to do, whether it is a national resource for cable repair or piping repair?"**
The same session supplied a European case where the gap stopped being theoretical. Subsea data cables are covered by what one witness called an "ambulance service" β a subscription arrangement guaranteeing a repair vessel. Interconnectors have no equivalent:
**"If you don't have an ambulance service, it really is a free-for-all and you have to fight to find a repair vessel, which is exactly what happened to Fingrid in Finland. When EstLink 2 was struck on Christmas day, they had to call around to find a repair vessel. It took them a long time and they could not find a repair vessel."**
And the constraint this audit argues from the outside β that a recovery regime is defined by what happens when damage arrives in more than one place at once β was put from the inside by a maritime lawyer who negotiates these contracts. Operators hold repair contracts; the problem is that they all hold them with the same people:
**"It is likely to be the same people running those services⦠so the worry becomes: what if there is a volume situation or what if there are two situations? ⦠the call down would be for the same repair company or the same crew, the same spread, perhaps the same vessels, and they would be needed in two places."**
Her explanation for why no shared prioritisation framework exists is the conflation this article was written to challenge: "it would be quite difficult to negotiate that ambulance service because all of this is commercial information, it is sensitive and there are competing operators."
What should exist
One qualification first, because the record has moved. It would be wrong to say nobody is looking at this. Britain's system operator told Parliament in June 2026 that it had "literally just been given the resource to create a new team, to look at cascade and compounding risk," and framed the underlying problem in terms this publication has used elsewhere: "the grid has been designed and our markets have been designed to drive efficiency and lower cost," and "we need to build in deep, increasing redundancy." The claim here is not that institutions are inert. It is that after that work concludes, there is still no published standard against which the public can judge the result.
None of this requires publishing a map of vulnerable assets. The distinction the entire debate has failed to make is between operational secrecy, which is legitimate, and aggregate accountability, which is not the same thing.
A regulator need not disclose where a transformer is stored in order to report that all designated critical operators must meet a defined recovery standard, that coverage extends to a stated proportion of critical nodes, and that compliance has been independently tested. Germany's voluntary publication of its system defence plan proves the line can be drawn.
What is missing, and could be created without disclosing anything sensitive:
- a defined adequacy standard β what level of simultaneous loss the arrangements are designed to withstand;
- a published restoration-time objective for destroyed equipment, as distinct from black-start endurance;
- stated institutional scope β whether the regime covers transmission only, or distribution, municipal operators, generation step-up transformers and interconnectors;
- reported testing β and here the European regime is closest, because the exercises are already mandatory. What is missing is publication of the result;
- independent audit against that standard, which every jurisdiction examined already has the institutional machinery to perform;
- and an aggregate assurance statement β not an inventory, simply a public answer to the question of whether it is enough.
Method, and an invitation to be corrected
This audit records four possible findings for each question β yes, partial, no public evidence found, and not applicable β deliberately avoiding a binary.
A "no public evidence found" rating does not assert that a capability or requirement does not exist. It means we could not identify a publicly accessible document demonstrating that it does. Regulators, system operators and utilities are invited to provide a source, after which this audit will be amended and the change logged.
That care is not decorative. This research caught eight separate instances of a document appearing to contain nothing when in fact the text had never been read: a PDF that extracted as font binary; an HTML error page saved with a .pdf extension; a corrupted character mapping that rendered ordinary German words as gibberish; a text-search tool silently refusing to match on a document containing invalid byte sequences β which would have reported Germany's flagship audit report as never once mentioning security of supply; two encrypted annual reports that yielded 4,906 characters of noise from 218 pages until decrypted; an extractor that silently dropped umlauts, so that a search for the German word for "financial year" returned zero while a control term in the same document returned 351; and two documents rendered as binary garbage by an automated retrieval tool reporting "no such text found" β one of which contained a genuine finding.
Each would have produced a confident and entirely false "no public evidence found."
Two institutional search engines also had to be assessed rather than trusted. Germany's federal audit office indexes the full text of its PDFs β verified by searching for a term appearing only once, deep in a document body β so its zero-results carry weight. Britain's National Audit Office indexes titles and metadata only; it returned no results for a term appearing nine times in the body of its own report. Its nulls are worthless as evidence, and none is relied on here.
A final trap, in the other direction: a plain search for "spare" returns matches inside the word transparent, and did so in five separate documents here, including two European regulations. Every hit was read in context before it was counted.
**Security boundary.** This project does not attempt to identify the location, specification, quantity or vulnerability of individual spare transformers or critical grid assets. It audits only what responsible institutions publicly disclose about governance, minimum standards, testing and aggregate adequacy. It is an accountability exercise, not an inventory or a vulnerability map.
The reserve that was never the point
The energy debate measures security in days of supply. It should also measure it in days to repair.
A country may hold ninety days of oil, ample gas contracts and a comfortable reserve margin, and remain profoundly vulnerable if it cannot replace a large power transformer inside four years β or cannot say, when asked, how many it has.
The institutions responsible have not been negligent in the way the headline suggests. They built network codes, mandatory exercises, restoration plans and private inventories. What they never built was the part that lets anyone outside check the work.
Europe requires its operators to rehearse rebuilding the grid every five years. It does not require anyone to say whether the rehearsal would survive contact with a real one β and when a member state actually suffered the failure, across 800 pages of expert post-mortem, nobody asked.
The missing strategic reserve is not the machinery. It is the measurable guarantee.
This is a worked application of the framework set out in Why Cheap Energy Isn't Always Cheap β that a system optimised for efficiency cannot improvise redundancy once a crisis has begun. It shares its central proposition with Bypassing a Chokepoint 135 Barrels at a Time: nominal capacity is irrelevant when the narrowest indispensable link cannot carry β or restore β the flow. There, the constraint was throughput. Here, it is recoverability.
Audit conducted and sources checked 20 July 2026. Findings are date-stamped and will be amended on evidence.