What is EV charging infrastructure?

EV charging infrastructure is the combination of charging points for electric vehicles, the backend systems that manage them remotely and the links to payment services and the power grid, with the Open Charge Point Protocol (OCPP) as the standard language between charger and backend. A charger is therefore no longer a socket but a networked OT device with firmware, a SIM card or internet connection and a controllable power output. The Netherlands alone has almost 210,000 public and semi-public charging points (2025), the highest number in the European Union. As a result, the security of chargers bears directly on grid stability and on grid congestion.


🧱 Which parties play a role in EV charging infrastructure?

The charging market is split into roles, each with its own systems and connections. Knowing the roles also shows you where the attack paths run.

Role What does it do? Main interface
Charge Point Operator (CPO) Operates and maintains charging points OCPP to every charger
CSMS / backend The CPO’s central management system: sessions, tariffs, firmware, configuration OCPP (server), OCPI, OSCP
Charging point (EVSE) Delivers energy to the vehicle, meters and authorises OCPP (client), ISO 15118 to the car
eMobility Service Provider (eMSP) Issues charging cards and apps, bills the driver OCPI to CPO or roaming hub
Roaming hub Connects many CPOs and eMSPs, such as Hubject or Gireve OCPI or OICP
Distribution system operator (DSO) Monitors grid capacity, requests flexibility OSCP, OpenADR
Electric vehicle (EV) Requests energy, can feed back with V2G ISO 15118-2 / -20

πŸ”§ Which protocols does EV charging infrastructure use?

EV charging runs on a stack of open protocols. OCPP is the backbone; the others connect the chain to the vehicle, the market and the grid.

Protocol Link Status and features
OCPP 1.6J Charger ↔ CSMS 2015; JSON over WebSocket, basic smart charging; still the most widely deployed version
OCPP 2.0.1 Charger ↔ CSMS 2020; built-in security, device model, ISO 15118 support; international standard IEC 63584 since late 2024
OCPP 2.1 Charger ↔ CSMS January 2025; bidirectional charging, control of distributed energy resources, payment terminals; IEC 63584-210:2025
OCPI 2.2.1 / 2.3 CPO ↔ eMSP / hub Roaming, tariffs, real-time availability; 2.3 is aligned with AFIR
OSCP 2.0 DSO ↔ CSMS 2020; capacity forecast for the next 24 hours
ISO 15118-2 / -20 Vehicle ↔ charger 2014 and 2022; Plug & Charge with certificates, -20 adds bidirectional charging
OpenADR DSO/aggregator ↔ backend Demand response; 2.0 is also IEC 62746-10-1, version 3.0 (2023) is REST-based
IEC 63110 Management of charging infrastructure IEC 63110-1:2022 defines roles, use cases and cybersecurity

OCPP has Dutch roots. ElaadNL, the knowledge centre of the Dutch grid operators, commissioned the protocol in 2009 so that chargers from different vendors could connect to a single backend. The first version appeared in 2010. Since 2014 the specification has been maintained by the Open Charge Alliance, a foundation under Dutch law.


πŸ” How does OCPP secure the connection?

A charger opens a WebSocket connection to the CSMS itself. OCPP 2.0.1 defines three security profiles, which the OCPP 1.6 Security Whitepaper also makes available for 1.6J:

Profile Transport Charger authentication Backend authentication Use
1 Unencrypted HTTP Basic (password) None Only within a trusted network or VPN
2 TLS 1.2 or higher HTTP Basic over TLS Server certificate Common baseline for public charging
3 TLS 1.2 or higher Client certificate (mutual TLS) Server certificate Recommended; strongest identity per charger

Beyond transport, OCPP 2.0.1 adds a security event log sent to the backend, signed firmware updates and remote certificate management. That makes certificate management a core task for the CPO: certificates expire, must be renewed in time and can be revoked when a key leaks. Plug & Charge under ISO 15118 adds its own V2G PKI with separate root certificates, independent of the OCPP certificates.


⚠️ What threats affect EV charging infrastructure?

  • Mass load switching β€” an attacker who takes over a CSMS or cloud platform can switch thousands of chargers on or off at once. Simulations of such load-altering attacks show that coordinated switching of a few tens of megawatts of charging load can destabilise a grid, whereas a comparable amount of residential load does not.
  • Vulnerable chargers β€” at the first Pwn2Own Automotive in Tokyo (January 2024), researchers targeted the ChargePoint Home Flex, Autel MaxiCharger and JuiceBox 40; the first two were successfully compromised, partly over Bluetooth, and an exploit for the JuiceBox 40 was published shortly afterwards. The January 2025 edition yielded 49 zero-days, again including several chargers.
  • Supply chain backdoors β€” in February 2022, chargers along Russia’s M11 motorway displayed anti-Putin messages; their controllers came from a Ukrainian supplier. A textbook case of supply chain risk.
  • Fraud and manipulation β€” cloned RFID charging cards, tampered meter values and abuse of payment terminals.
  • Privacy β€” session data links a charging card, location and time to a person and falls under the GDPR, known in the Netherlands as the AVG.
  • Exposed management interfaces β€” charger web interfaces and Modbus ports reachable straight from the internet, just as with internet-exposed OT and solar inverters.

πŸ‡ͺπŸ‡Ί What does EV charging look like in the Netherlands and the EU?

The number of public charging points in the Netherlands grew from around 63,000 in 2020 to almost 210,000 in 2025, with an average of some 1,600 new points added every month in 2025. Because the grid is full in many places, smart charging is no longer optional. In a pilot in the province of Utrecht, grid operator Stedin, ElaadNL, the municipality of Utrecht and eight CPOs reduced the charging power of about 3,500 public chargers between 16:00 and 21:00 on weekdays. The evening peak fell by almost 50 per cent, from 11.5 to 5.8 MW. Enexis and Stedin now apply this grid-aware charging to more than 5,200 public chargers. At business sites, smart charging is often combined with a battery energy storage system behind the meter.

At European level, AFIR, Regulation (EU) 2023/1804, sets the rules. It has applied since 13 April 2024 and requires, among other things:

  • Ad hoc payment β€” every public charger must allow charging without a subscription; new points of 50 kW and above need a payment card or contactless reader
  • Digital connection β€” all public charging points had to be digitally connected by 14 October 2024
  • Smart charging β€” public points built after 13 April 2024 or renovated after 14 October 2024 must be capable of smart charging

Product rules come on top. Chargers with Wi-Fi, 4G or Bluetooth have been subject to the cybersecurity requirements of the Radio Equipment Directive since 1 August 2025 (Delegated Regulation (EU) 2022/30, harmonised standards EN 18031). From December 2027 the Cyber Resilience Act applies in full. Large CPOs may also fall under NIS2.


πŸ› οΈ How do you secure your charging infrastructure step by step?

For a fleet manager or site owner with their own charging hubs, this sequence works well:

  1. Build an inventory β€” record for every charger the make, model, firmware version, OCPP version, security profile and communication path (4G, LAN, Wi-Fi).
  2. Require at least profile 2, preferably 3 β€” disable unencrypted OCPP and give every charger its own client certificate.
  3. Segment β€” place chargers in a dedicated VLAN or private APN, separated from office and building networks, in line with network segmentation.
  4. Lock down local interfaces β€” change default passwords and disable unused web interfaces, Bluetooth configuration and Modbus.
  5. Manage firmware β€” accept only signed firmware (firmware signing) and include chargers in your patch management.
  6. Limit power centrally and locally β€” keep a hardware or local load limit that still works if the backend is manipulated.
  7. Monitor β€” forward OCPP security events to your security monitoring and watch for unexpected configuration changes and switching patterns.
  8. Assess suppliers β€” ask for OCA certification, RED/EN 18031 conformity, an SBOM and a penetration test report, for instance from the ElaadNL Testlab in Arnhem.

❓ Frequently asked questions

What is OCPP?

OCPP (Open Charge Point Protocol) is the open communication protocol between a charger and the central management system of the charge point operator. Through OCPP, charging sessions are started and stopped, meter values reported, firmware updated and charging power controlled. OCPP is maintained by the Open Charge Alliance and, as OCPP 2.0.1, is also international standard IEC 63584.

What is the difference between OCPP 1.6 and OCPP 2.0.1?

OCPP 1.6J from 2015 is the most widely used version, but only received security later through a separate whitepaper. OCPP 2.0.1 from 2020 has security profiles, signed firmware, a security event log and ISO 15118 support at its core. OCPP 2.0.1 is not backwards compatible with 1.6, whereas OCPP 2.1 is compatible with 2.0.1.

Is an EV charger operational technology?

Yes, an EV charger is operational technology: it is a networked device that physically switches electrical power. A manipulated charger or charging backend can control large amounts of power at once and so load the distribution grid. That is why EV chargers belong in the same OT security approach as inverters, building automation and other connected energy installations.

Which security profiles does OCPP define?

OCPP defines three security profiles: profile 1 with only a password and unencrypted transport, profile 2 with TLS and a password, and profile 3 with TLS and a client certificate per charger. Profile 1 is only acceptable within an isolated network. For new installations, OCPP security profile 3 is the recommended choice.

What does AFIR require of EV chargers?

AFIR, Regulation (EU) 2023/1804, has applied to publicly accessible charging infrastructure in the EU since 13 April 2024. AFIR requires ad hoc payment without a subscription, a digital connection for all public charging points and smart charging capability for new and renovated points. For fast chargers of 50 kW and above, a payment card reader or contactless reader is mandatory.

What is grid-aware charging?

Grid-aware charging temporarily lowers the charging power of public chargers during the evening peak on the power grid, in the Netherlands on weekdays between 16:00 and 21:00. In a pilot in Utrecht, grid-aware charging almost halved the peak load of the participating chargers, while drivers could opt out if they wanted to charge at full power. The limit is applied through the charge point operator’s backend, which controls the chargers via OCPP.


πŸ“Œ In summary

EV charging infrastructure is a fast-growing, networked OT system in which OCPP links chargers to backends, and whose security directly affects the stability of the power grid. Choose OCPP 2.0.1 or later with security profile 3, segment your chargers, actively manage certificates and firmware, and make sure local power limits keep working if the backend is attacked.