Administered by

  • HOME
  • CONTACT US
  • ABOUT THIS SITE
  • DISCLAIMER
  • Supported by
  • Australian Renewable Energy Agency (ARENA)
English (UK)
GB English (UK)
US English (US)
  • EXPLORE KNOWLEDGE BASE

  • CERI Knowledge Base

    • About the CERI knowledge base

      • Introduction to Australia’s electricity markets

        • Australian consumer insights

          • CER technical and interoperability standards

            • Connecting a customer to an electricity network

              • Connecting a generator to a distribution network

                • Utility interconnection (CSIP-AUS)

                  • Dynamic network export and generation control schemes

                    • Network load control schemes

                      • Network tariffs and network support services

                        • Participating in the National Electricity Market

                          • Participating in a frequency control market

                            • Participating in the RERT

                              • Participating in the Wholesale Electricity Market (Western Australia)

                                • Participating in the I-NTEM (NT)

                                  • Cyber security and data privacy arrangements

                                    • Consumer protection frameworks

                                    Cybersecurity and EV charging

                                    Last Updated on 4 August 2026

                                    SUGGEST AN EDIT

                                    LIKE THIS PAGE?

                                    Table of Contents

                                    Main EV charging data paths Securing EV to EVSE communications Securing EVSE to CSMS communications How does CSIP-AUS interact with EV charging? Cybersecurity Considerations for EV Telematics in Australia Related articles

                                    Compared to other CER, EV charging involves a relatively complex mix of established and diverse protocols, stakeholder relationships, use cases, and solution requirements. These can intersect with CSIP-AUS cybersecurity frameworks and their certificate solution providers along with a range of regulatory considerations.

                                    Main EV charging data paths

                                    EV charging security is centred on open, interoperable standards governing communication between:

                                    • An EV and an EVSE, and
                                    • An EVSE and a CSMS

                                    These links form the primary data path required for end-to-end interoperability and consistent security. Additional actors (e.g., EV OEMs, MSPs, CPOs, electricity retailers, CER aggregators, eRoaming providers and DNSPs) may participate in varying ways, in a range of smart charging, V2G, and smart grid integration models.

                                    Securing EV to EVSE communications

                                    Within the CCS, ISO 15118 defines the EV-to-EVSE communication and security framework, underpinned by a multi-actor PKI. ISO 15118-2 allows non-secure communication (TLS 1.2 only for optional secure services such as Plug & Charge), whereas ISO 15118-20 mandates TLS 1.3 for all sessions and introduces a more tightly defined PKI. Under ISO 15118-20, each EV must hold an OEM-issued Vehicle Certificate Chain supporting secure session establishment, contract-certificate provisioning, Plug & Charge, and Bidirectional Power Transfer (BPT).

                                    While ISO 15118-2 allows standard charging via External Identification Means without vehicle certificates, secure Plug & Charge and bidirectional power transfer under ISO 15118-20 rely on a full certificate-based security model. Uptake of these requirements in Australia remains limited due to the predominance of non-15118 chargers, incomplete PKI integration, and the lack of national interoperability mandates.

                                    The RCA ("V2G Root") is the top-level trust anchor in the ISO 15118 PKI. It is the highest certificate authority from which all other certificates in ISO 15118 communications are derived. As the V2G Root establishes trust across vehicle and charging station OEMs (serving as the trust anchor stored in both), commercial agreements are required between parties to drive interoperability. V2G Roots are typically issued regionally (e.g., EU, North America, APAC) by specialist vendors who are cross certified for interoperability. While some V2G Root certificates are issued in EVs and EVSEs sold in the Australian market by their OEMs, there are no commercial applications involving them in the Australian market as of 2025.

                                    ISO 15118 mandates strict certificate validation and revocation checking (CRL/OCSP) and accordingly, Contract Certificates (as used in Plug & Charge) have short lifetimes (days to a few years), whereas OEM and CA certificates are long-lived. Presently, ISO 15118 also coexists with CHAdeMO, which lacks a native PKI or protocol-level cybersecurity framework.

                                    Securing EVSE to CSMS communications

                                    OCPP defines communication between EVSEs and the CSMS. Version 1.6 supports basic authorisation, transaction handling and metering, but lacks standardised certificate lifecycle management, secure firmware delivery, and any mechanism for installing ISO 15118 trust anchors such as the V2G Root. The optional 1.6 “Security Profiles” are non-normative and do not meet ISO 15118 requirements.

                                    OCPP 2.x introduces formal Security Profiles with TLS, optional mutual authentication, and standardised certificate-management messages enabling the CSMS to provision EVSE-side certificates and ISO 15118 trust anchors (EV-side certificates remain within the ISO 15118 PKI). They also mandate cryptographically signed firmware with CSMS-coordinated distribution, though platform-integrity features such as secure boot remain outside the specification.

                                    Only OCPP 2.x provides the mechanisms necessary for secure EVSE-to-CSMS communication, Plug & Charge support and integration with the ISO 15118-20 security model. In Australia, widespread reliance on OCPP 1.6 and the absence of minimum cybersecurity requirements results in highly variable security across deployed charging infrastructure.

                                    How does CSIP-AUS interact with EV charging?

                                    CSIP-AUS, derived from IEEE 2030.5, can integrate into EV charging via an EMS connected to an EVSE, directly at an EVSE, or at a CSMS that then manages charging via OCPP. Its PKI authenticates parties and secures all CSIP-AUS sessions. This PKI is entirely separate from the PKIs used in ISO 15118 and OCPP, and certificates are not shared across protocols.

                                    Cybersecurity Considerations for EV Telematics in Australia

                                    Vehicle telematics can communicate directly with cloud platforms, but such solutions are typically proprietary and lack open, interoperable cybersecurity frameworks. International regulatory approaches vary widely, and no common automotive telematics security model exists.

                                    Several examples of telematics-based smart charging operate in the Australian market operating directly via OEM APIs or through a third party telematics service provider.

                                    Telematics data is classified as PII under the Privacy Act. When used for energy management purposes, its use needs to be considered in the context of the Cyber Security Act. AESCSF/Essential Eight, IEC 62443-aligned OT controls, SOCI Act supply-chain requirements, and state-based data residency or data sovereignty rules.

                                    The applicability of these arrangements may depend on the functions deployed, data collected, and the scale at which telematics-based controls could influence charging or bidirectional energy flows. Large-scale telematics-based coordination of EV charging is still emerging in Australia and regulatory scrutiny of telematics implementations may increase significantly in the coming years.

                                    Related articles

                                    • Utility Interconnection (CSIP-AUS)
                                    • CER Cybersecurity Roadmap
                                    • Australian energy sector cyber security framework
                                    • National Energy PKI (NEPKI) and CSIP-AUS

                                     

                                    cybersecurity ev charging ev charging infrastructure data protection electric vehicles communication ev security ev considerations cybersecurity and ev

                                    Copyright 2026 – CERI.

                                    Knowledge Base Software powered by Helpjuice

                                    Expand