Skip to content Skip to footer

Updated whitepaper: Security Operations Guide Version 2

Tue 22 Sep 2026

News / Updated whitepaper: Security Operations Guide Version 2

At the beginning of 2026, the Open Charge Alliance published the first version of the Security Operations Guide. As EV charging infrastructure continues to grow and is increasingly regarded as critical infrastructure, cybersecurity is becoming more important than ever.

Security is therefore a fundamental element of the OCPP specification and OCPP certification programs. However, implementing security in practice often raises questions that go beyond what a technical specification alone can answer.

The Security Operations Guide was developed to bridge that gap. It takes a closer look at how OCPP security requirements can be translated into real-world implementations and provides practical considerations for charging station manufacturers, CSMS providers, Charge Point Operators and other parties involved in operating charging infrastructure securely.

Today, during the OCPP Plugfest & Conference Europe in Dublin, we are launching Version 2 of the Security Operations Guide, with additional guidance and several new topics. The Security operations guide is offered to Aja Teehan of the Zero emission vehicles Ireland, a dedicated office of the Irish departement of transport. Aja emphasized the importance of cyber security in e-mobility:

ZEVI welcomes the development by OCA of their security operations guide. Increasing the security of recharging infrastructure and e-mobility operations is an important objective for standards organisations to set and serve. When industry implements strong cybersecurity, it directly benefits EV drivers in Ireland, Europe and world-wide.

What is new in Version 2?

Separation of CSMS and CPO responsibilities
The previous CSMS-focused requirements have been reorganized into separate sections for CSMS providers and Charge Point Operators (CPOs), providing greater clarity on their respective security responsibilities.

Extended CSMS and CPO security requirements
The requirements for CSMS providers and CPOs operating these systems have been expanded with additional guidance on security operations and measures supporting the secure deployment and operation of charging infrastructure.

Introduction of a Post-Quantum Security Policy
A new Security Policy for Post-Quantum Cryptography has been added to help organizations prepare for the transition towards post-quantum cryptography.

Introduction of JC-STAR considerations
The guide now includes references to the JC-STAR Level 1 cybersecurity certification scheme.

Addition of a Defense-in-Depth approach
A new section on defense in depth introduces complementary security controls that can be applied alongside OCPP security mechanisms to further strengthen an implementation.

Guidance on Local Controllers
A new section addresses security considerations relating to the use of Local Controllers within OCPP-based charging infrastructure.

With Version 2, the Security Operations Guide provides an even broader practical resource for organizations working to securely implement and operate OCPP-based charging infrastructure.

Read the updated Security Operations Guide Version 2 here:

3 Months, 3 continents, 3 OCA Events

Over the coming three months, the Open Charge Alliance will bring the global OCA community together across three different continents. From Asia to Europe and Australia. Curious? Find out all details about the events here!