Maintenance technician crouched at an open public charging station inspecting the internal communication modules and cables, a service van in the background on a wet car park
SECURITY & DATA PROTECTION

BSI charging infrastructure report: the IT gaps in OCPP and ISO 15118

Germany has more than 200,000 public charging points, and almost every one is online. On 7 May 2026 the BSI checked for the first time how well these stations are protected against cyberattacks. The answer is uncomfortable: considerable room for improvement. The standards are fine. Their rollout is not.

The first BSI report on the IT security of public charging infrastructure, written jointly with the Federal Ministry of Transport, takes on the OCPP and ISO 15118 protocols and names the weaknesses openly. This article explains what the report finds, which threat scenarios it describes, how NIS2 and the AFIR regulation set the frame, and what operators should do now. If you want the certificate logic behind convenient charging, the details sit in ISO 15118 Plug and Charge and AFIR, and the grid operator frame in the IT security catalog under Section 5c EnWG.

Summary

The German Federal Office for Information Security (BSI) published its first report on the IT security of public charging infrastructure on 7 May 2026, jointly with the Federal Ministry of Transport. It covers the OCPP and ISO 15118 protocols along with testing activities and legal requirements such as the AFIR regulation. Core finding: considerable room for improvement. Both standards have significantly improved their security requirements and match the state of the art in many areas, but in practice they are often only partly implemented, for cost reasons and to keep older systems compatible. The report lists typical weaknesses in OCPP communication between charge point and backend, in the authentication of charging cards and apps, and in remote maintenance over unsecured connections. The backend in particular, meaning billing and load management, has hardly been examined so far and shows serious deficits. The attack scenarios range from manipulated charging sessions through payment data leaks to coordinated shutdown attacks on entire charge park clusters, with possible effects up to grid stability. The BSI recommends TLS encryption for OCPP, penetration tests, unique authentication, standardized certificate management and incident response plans, and above all binding requirements based on security by design and security by default rather than voluntary one-off measures. With the NIS2 transposition, charge point operators are becoming part of critical infrastructure anyway, so implementing the report also satisfies core NIS2 obligations.

A first BSI picture for charging stations

For the first time there is an official security picture for charging infrastructure. On 7 May 2026 the BSI, together with the Federal Ministry of Transport, published its report on the IT security of public charging infrastructure. It assesses systematically how well networked charge points are protected against cyberattacks, and sums up the result in three words: considerable room for improvement.

The timing is no accident. In April 2026 Germany passed 200,000 public charging points for the first time, and every new point is another networked computer in public space. That is exactly what makes the BSI nervous: networked charge points are a potential entry point for serious attacks. For this the report looks at the central protocols OCPP and ISO 15118, plus testing activities and legal requirements down to the AFIR regulation.

7 May 2026
first BSI report
on the IT security of public charging stations
> 200,000
public charging points
mark passed in April 2026
49,904
fast charging points, up 34 percent
as of February 2026, Bundesnetzagentur
8.87 GW
simultaneous charging power
sits on the grid, as of 1 June 2026
OCPP + ISO 15118
protocols assessed
plus reference to the AFIR regulation
around 50
measures per IT security catalog
the frame NIS2 pulls operators into

Until now operators had to piece their own security picture together. Now there is a shared reference on the table that municipal utilities, charge point operators and their service providers can align to. That is the real value of the report: not the headline, but the yardstick.

Where the report sees weaknesses

The standards are not the problem. OCPP and ISO 15118 offer modern cryptography and transport encryption, and the report says so plainly. The problem is that these protections often stay optional in practice, or are switched off entirely so older stations can still take part. The technology is ready. It is only half used.

Diagram: the charging communication chain from vehicle through charge point and backend to payment and roaming services, with three marked weak points.
Four stations, three weak points: where OCPP and ISO 15118 are exposed along the chain.

It shows most clearly at OCPP, the protocol between charge point and backend. The report lists typical weaknesses in OCPP communication, in the authentication of charging cards and apps, and in remote maintenance over unsecured connections. The core is transport encryption: TLS is increasingly used, but not consistently mandatory. Where it is missing, an attacker reads along.

Over-the-shoulder view into the open interior of a charging station, showing grey communication modules, a circuit board with a network connector and cable glands
Inside the station, communication modules, a network connector and power cables meet, and the attack surface often sits right here.

With ISO 15118 and Plug and Charge the risk sits elsewhere. Here complex certificate chains and distributed responsibilities create convenience, but also dependence on a few central trust anchors. If one such anchor is compromised, the consequences reach across the whole charging infrastructure. That is why the report singles out certificate management as especially critical.

The blind spot, though, is the backend. Billing and load management were mostly left out of earlier analyses, yet the real control sits there. The report finds default credentials, missing encryption and software gaps that could, in the worst case, take many stations offline at once. The BSI describes the protection level of many stations vividly as comparable to a computer from the 1990s. Overstated, yes. But the point lands.

OCPP (Open Charge Point Protocol) is the open communication protocol between a charging station and the operator's backend. It controls activation, the charging session, billing and remote maintenance. Since versions 2.0.1 and 2.1 OCPP supports TLS encryption and secure authentication, but in practice these functions are not enabled everywhere. This gap between the standard and its rollout is exactly what the BSI report names.

The threat scenarios

An attack on a charging station rarely hits just one driver. Because many charge points hang off shared control and the same backend services, a single access can reach a whole fleet. That is the uncomfortable part of the report.

The scenarios range from manipulated charging sessions and billing fraud through leaks of payment and customer data to coordinated shutdown attacks on entire charge park clusters. The BSI describes how whole regions could be cut off from charging infrastructure for a time. And it goes further: effects on the stability of the power grids are explicitly not ruled out. No wonder, since as of 1 June 2026 around 8.87 gigawatts of simultaneous charging power sat in the system.

How real this is shows in independent research. A relay attack on ISO 15118 Plug and Charge documented in late 2025 showed that a vehicle cannot reliably verify the identity of the charging station, so a stranger's car pays the bill. It is not the end of the world. But it is proof that the attack surface is not theoretical.

  • Manipulated charging sessions and billing fraud at the individual station.
  • Leaks of payment and customer data through insecure apps or backends.
  • Coordinated shutdown attacks that hit entire charge park clusters at once.
  • Grid effects, because controllable charging power in the gigawatt range hangs off the same system.

German and EU perspective

The report meets a legal frame that is tightening right now. With the NIS2 transposition, charge point operators become part of regulated critical infrastructure. That is more than a label: they have to run risk management to the state of the art, secure their supply chain and report incidents quickly. And they have to know which software even runs on their stations.

In parallel the IT security catalog under Section 5c EnWG applies, which the Bundesnetzagentur has already adapted to the new situation. Digital energy services move into the same set of duties as grid and plant operators. If you want to orient yourself here, the details on the catalog sit in the piece on the IT security catalog 5c EnWG, and the overarching network code in the piece on the NCCS cybersecurity obligations.

The report names the real problem itself: the requirements come today from many laws and regulations, of which many are not yet binding. This fragmentation is why existing technology does not reach the field everywhere. Affected is not only the station operator, but the whole chain: backend providers, mobility service providers, roaming platforms and the makers of the charging hardware. The data duties of that chain are covered in the piece on DATEX II in charging infrastructure.

Challenges and risks

The core question is not the technology. It is the obligation. The protections have long sat in the standards, but without a duty, an audit and proof, their rollout stays voluntary. And voluntary loses against cost pressure.

Operators sit in a genuine bind. Binding requirements meet legacy stations that cannot be retrofitted without effort, and backward compatibility that nobody wants to simply cut. On top comes a fragmented testing setup: authorities, testing bodies and certifiers hold overlapping responsibilities, which makes checks slow and expensive.

For all the urgency, a sober look helps. The image of a 1990s computer creates pressure to act, but it is a rhetorical sharpening, not a measured metric. Large, publicly documented outages from attacks on German charging infrastructure are not on record so far. The scenarios are meant as prevention, not as hindsight. That does not make them less important, but it helps to place them right: the report is a warning with lead time, not a damage log.

What operators should do now

The report offers a clear list of priorities, and the good part is that the most important steps cost more discipline than money. Whoever encrypts OCPP, authenticates cleanly and keeps an emergency plan covers the most common gaps and meets core NIS2 duties at the same time.

A driver holds a charging card to the reader of a public kerbside charging station, the charging cable already plugged into an electric car
Authentication of charging cards and apps is one of the three areas the report singles out.
  • Make TLS mandatory for OCPP: turn on transport encryption for every OCPP connection between station and backend and do not leave it optional, because that is exactly where an attacker reads along otherwise.
  • Authenticate uniquely and remove default passwords: give every charge point and every backend access a unique identity, remove default credentials consistently and secure remote maintenance over encrypted channels.
  • Test regularly and disclose weaknesses: schedule recurring penetration tests and set up a process for coordinated disclosure, so reported gaps do not vanish in an inbox.
  • Standardize certificates and incident response: bring certificate management for Plug and Charge into orderly, standardized processes and keep an incident response plan ready that has actually been rehearsed.
  • Build a software inventory of the fleet: keep a current list of which software and firmware runs on which station, because without that overview the NIS2 reporting duties cannot be met in an emergency.

Further reading

Frequently asked questions

What does the BSI report on charging infrastructure say? +

On 7 May 2026 the BSI published its first report on the IT security of public charging infrastructure, jointly with the Federal Ministry of Transport. The report assesses the OCPP and ISO 15118 protocols, names typical weaknesses in communication, authentication and the backend, and describes threat scenarios up to effects on the power grid. Its verdict: considerable room for improvement. The BSI recommends binding requirements instead of voluntary one-off measures.

What weaknesses does OCPP have according to the BSI? +

The report names typical weaknesses in OCPP communication between charge point and backend, in the authentication of charging cards and apps, and in remote maintenance over unsecured connections. The core issue is transport encryption: TLS is increasingly used but not consistently mandatory. In the backend, default credentials and missing encryption add to the picture and could, in the worst case, take many stations offline at once.

Are OCPP and ISO 15118 fundamentally insecure? +

No. The BSI certifies that both standards have significantly improved their security requirements and match the state of the art in many areas. The problem is the rollout: for cost reasons and to keep older systems compatible, the available protections often stay optional or unused. The technology is there, only its mandatory use is missing.

What does the report have to do with NIS2? +

With the NIS2 transposition, charge point operators become part of regulated critical infrastructure. They must show risk management to the state of the art, supply chain security and fast incident reporting, and they must know which software runs on their stations. The BSI recommendations such as TLS for OCPP, unique authentication and an incident response plan map directly onto the NIS2 obligations. Implementing the report also satisfies core NIS2 requirements.

What should charge point operators do now? +

First, make TLS mandatory for every OCPP connection instead of leaving it optional. Then authenticate charge points and backend uniquely, remove default credentials and secure remote maintenance. Regular penetration tests and a coordinated vulnerability disclosure process belong here too, as does a standardized certificate management for Plug and Charge and an incident response plan. A software inventory of the fleet keeps operators able to report under NIS2.