Decoding the world of cybersecurity

EV charging enters Germany’s cyber security programme

Germany’s BSI is developing requirements for connected charging infrastructure, where backend services, remote maintenance, payments, and grid integration turn product weaknesses into operational risk.

EV charging enters Germany’s cyber security programme
Summary
  • Germany’s BSI has published security principles for public charging infrastructure and started implementation work with federal departments.
  • Charging networks depend on backend platforms, identity services, payment systems, remote maintenance, and software distribution.
  • Manufacturers and operators will need clear responsibility for authentication, updates, vulnerability handling, support periods, and incident recovery.

Germany has begun developing a national cyber security framework for electric vehicle charging infrastructure, bringing the systems behind public chargers into the country’s wider work on product security and energy resilience.

The Federal Office for Information Security, known as the BSI, published a key-points paper on 28 July and said implementation had started with the relevant federal departments. The work is intended to define requirements for charging equipment, operators, and the backend services used to manage connected installations.

Public charging points now form part of a larger digital service chain rather than operating as isolated electrical devices. They communicate with fleet-management platforms, payment providers, mobility applications, maintenance services, vehicles, and energy-management systems, while software updates and configuration changes may be distributed remotely across thousands of devices.

Each connection introduces a dependency that can affect availability and trust. Operators must authenticate users and equipment, protect management interfaces, secure update channels, and control access granted to installers and support providers. Backend systems may process account identifiers, payment information, location data, and operational telemetry while retaining authority to alter the behaviour of geographically dispersed chargers.

The BSI’s earlier assessment of public charging infrastructure identified weaknesses associated with exposed systems, credentials, software components, and communications between charging points and backend platforms. Interoperability standards allow different equipment and mobility providers to work together, but secure operation still depends on certificate management, authenticated communications, maintained software, and sound deployment.

Responsibility across the charging network

Control is divided among manufacturers, charging point operators, mobility providers, installers, cloud suppliers, payment processors, and electricity companies. A charger may remain in operation for many years, even after the supplier relationship or software platform under which it was installed has changed.

Support periods and vulnerability handling consequently become part of infrastructure reliability. Operators need to know how long equipment will receive updates, who can revoke certificates, which party monitors for newly disclosed flaws, and how an emergency update can be distributed without disabling a large part of the network.

Incident response becomes more difficult when no single organisation controls the full service chain. Unusual behaviour detected in a backend platform may originate in the charger, its communications module, an installer account, a cloud service, or software maintained by another supplier. Contracts need to establish which party preserves logs, leads an investigation, communicates with customers, and has authority to place equipment into a safe operating state.

The work will also intersect with the EU Cyber Resilience Act, which introduces security and vulnerability-management duties for manufacturers of products with digital elements. Charging infrastructure may fall within additional energy, transport, or essential-service requirements according to the operator and deployment model.

Product compliance at the point of sale will not cover weaknesses introduced during years of operation. Equipment can become exposed through unmaintained backend software, weak remote-access settings, reused installer credentials, expired certificates, or communications hardware that no longer receives updates.

Rapid deployment increases the effect of centralised failure. A management platform controlling thousands of chargers can simplify maintenance and provide consistent security policy, but compromise of the same platform could interrupt fleet depots, motorway sites, public car parks, and workplace charging at the same time.

Germany’s implementation work now has to convert the BSI’s principles into controls that can be tested throughout the operating lifecycle. Authentication, update integrity, remote access, vulnerability disclosure, supplier support, and recovery will determine whether the charging network remains dependable as its scale and connection to the electricity system increase.

×