EV charging security: ISO 15118 and Plug & Charge

How an EV and a charger authenticate each other — and the attack surface at the charging inlet

6 Jul 20265 min readAutoSifu

A new external interface into the vehicle

Every electric vehicle has an interface that a petrol car never had: a charging inlet that carries not just power but a data conversation. ISO 15118 is the standard that governs that conversation — the communication between the EV and the charging station over the course of a session. Its most visible feature is Plug & Charge, which lets the car identify and authorise itself the moment the cable is connected, with no app, RFID card or manual step.

From a security standpoint, the charging inlet is a physical, external interface that an attacker can reach without breaking into the vehicle at all. That places it squarely in the external-connectivity threat category of UN R155 Annex 5, alongside other ways the outside world touches the car. A charging session is a moment where the vehicle trusts something outside itself — and, as with V2X messages or an OTA package, the security of that trust decision comes down to certificates and keys.

How Plug & Charge authenticates

Plug & Charge works through certificate-based mutual authentication. When the cable is connected, the vehicle and the charging infrastructure each present digital certificates and verify the other before charging and billing proceed. The vehicle carries a contract certificate tied to a charging agreement; the charging station and the back-end e-mobility services carry their own credentials. Neither side simply trusts the physical connection — each proves its identity cryptographically.

This is the same PKI pattern that recurs across modern vehicle interfaces, resting on the key-generation, storage and lifecycle discipline covered in automotive PKI and key management. The convenience of Plug & Charge — plug in, walk away, get billed correctly — exists only because a certificate chain silently did its work at connection time. If those certificates or the keys behind them are weak, stolen or badly managed, the convenience becomes a fraud and abuse channel.

ISO 15118 is one of several places a vehicle authenticates an external party with certificates. Reading them side by side shows what is specific to charging and what is shared infrastructure.

Link What is authenticated Convenience it enables Primary risk
EV charging (ISO 15118 Plug & Charge) The vehicle and the charger to each other Automatic charging and billing Charging fraud; foothold via the inlet
V2X / C-ITS Broadcast safety messages between stations Cooperative safety and traffic services Forged or replayed safety messages
OTA update (UN R156) The update source to the vehicle Remote software updates Unsigned or tampered software

The V2X case is the closest relative and worth reading alongside this one — see V2X security and the C-ITS ecosystem. In every row the vehicle is deciding whether to trust an outside party, and in every row the answer is a certificate verified against a trusted authority.

The attack surface at the inlet

Because the inlet is physical and external, it presents several distinct risks a design must treat:

  • Certificate and credential abuse — forged, cloned or stolen contract certificates used to charge fraudulently or impersonate a vehicle. Mitigated by sound certificate issuance, secure hardware storage of keys, short lifetimes and revocation.
  • Man-in-the-middle on the link — intercepting or tampering with the vehicle-to-charger conversation. Mitigated by the mutual authentication and secure session establishment the standard specifies.
  • Pivot to internal networks — treating the charging port as a way toward the vehicle's internal buses. This is why the inlet must be isolated from safety-critical networks; an attacker who reaches the CAN bus inherits its lack of built-in authentication, as set out in CAN bus attacks explained.
  • Privacy exposure — leaking identity or location through charging metadata. Mitigated by careful handling of the data a session generates.

None of these are hypothetical extras. They are worked instances of the Annex 5 external-connectivity category, and they belong in the vehicle's threat analysis and risk assessment — the ISO/SAE 21434 TARA — during concept, not after a prototype exists.

The regulatory frame

EV charging security does not stand on ISO 15118 alone; it inherits vehicle-level obligations. Under UN R155, the charging interface is part of the vehicle's cyber security management system and its threat analysis, and the vehicle needs a CSMS certificate of compliance (valid three years) plus per-type approval. In India the aligned standard is AIS-189, whose enforcement is proposed in MoRTH draft G.S.R. 503(E) (phased from October 2026) but not yet finalised — and the design obligation to treat the inlet as an external threat surface does not wait on the final date. In the EU, the Cyber Resilience Act — Regulation (EU) 2024/2847 — adds horizontal obligations for products with digital elements, including secure-by-design, an SBOM and vulnerability handling, with reporting obligations from 11 September 2026 and the main obligations from 11 December 2027. Charging equipment and the vehicle's charging stack can both fall within that horizontal frame in addition to type approval.

The practical takeaway

The lesson of ISO 15118 is that convenience at the inlet is bought with cryptography behind it. Plug & Charge is only as trustworthy as the certificate estate and key management that stand it up, and the inlet is only as safe as its isolation from the vehicle's internal networks. Both of those are architecture decisions taken early. Designed in — mutual authentication enforced, keys in secure hardware, the charging domain segmented from safety-critical buses — the charging experience is seamless and defensible. Bolted on afterwards, it is a recurring finding.

The AutoSifu view

AutoSifu treats the charging interface as part of the whole-vehicle cybersecurity case, not a charging-team afterthought. We take the ISO 15118 authentication, PKI and isolation design into the TARA and the CSMS, and carry it through to the evidence an assessor opens — working one route from compliance to secure solutioning to CoC/VTA support under R155/R156 and AIS-189/AIS-190, with our strategic partner CIRT, the approval body, in the room from the start.

Questions

What is ISO 15118?
ISO 15118 is the international standard that defines communication between an electric vehicle and a charging station, including the messaging that governs a charging session. Its best-known feature is Plug & Charge, which lets a car authenticate and authorise charging automatically when the cable is connected. Security is central to the standard because the charging inlet is a physical, external interface into the vehicle.
What is Plug & Charge?
Plug & Charge is the ISO 15118 mechanism by which an EV identifies and authorises itself to a charger simply by plugging in, with no app, card or manual step. It works through certificate-based mutual authentication: the vehicle and the charging infrastructure each present digital certificates and verify the other before a session and its billing proceed. This removes user friction but makes the security of the underlying certificates and keys critical.
What are the security risks of EV charging?
The charging inlet is an external, physical interface, so the risks include forged or stolen certificates enabling charging fraud, tampering or eavesdropping on the vehicle-to-charger link, and using the connection as a foothold toward the vehicle's internal networks. UN R155 Annex 5 treats external connectivity such as charging as a threat category a cyber security management system must address. Certificate-based mutual authentication and sound key management are the primary mitigations.

09 — Start here

Bring us the file you are least sure about.

Most conversations start with a gap assessment, or a type approval submission that is closer than it feels. Either is a good place to begin.

Direct

Jaipur · registered office

Plot No. 8, ABS Plaza, Chanakya PuriJagatpura, Jaipur – 302017, RajasthanAUTOSIFU Pvt Ltd · India

Required