Plug and Charge ISO 15118: how automatic EV authentication works


Plug & Charge is the ability for an EV to authenticate and authorise a charging session automatically, the moment it’s plugged in, with no app, card, or driver input needed. ISO 15118 is the standard that makes this possible, defining the certificate-based communication protocol between vehicle and charger that replaces manual sign-in with automatic, encrypted verification. For businesses running fleets or public chargers, the payoff is simple: hands-free billing and a lot less driver friction.
TL;DR:
Certificate lifecycle management and accurate clock synchronization are critical to prevent Plug & Charge authentication failures, especially in large networks.
Hardware compatibility, including secure cryptographic modules in EVs and firmware support in chargers, determines whether a vehicle can actually use Plug & Charge.
Interoperability between different networks depends on cross-certification models, with proper trust list management being essential for seamless operations.
Proper site surveys and proactive certificate renewal planning are vital for successful deployment and maintenance of Plug & Charge infrastructure.
The success of a plug and charge rollout hinges on a comprehensive governance approach to certificate management, not just on hardware compliance or standards adherence.
Table of Contents
What is plug and charge ISO 15118 and how does authentication actually happen?
Which vehicles and chargers actually support plug and charge?
What benefits does plug and charge deliver for fleets and site owners?
How do commercial installers actually deploy plug and charge?
What deployment and interoperability issues should operators expect?
What is plug and charge ISO 15118 and how does authentication actually happen?
Two components carry out every Plug & Charge transaction: the EVCC (Electric Vehicle Communication Controller) inside the car, and the SECC (Supply Equipment Communication Controller) inside the charger. They talk to each other over the same cable that delivers power, using ISO 15118’s vehicle to grid communication interface rather than a separate app or card system.
The session runs through a fixed sequence:
Discovery: the EVCC and SECC find each other over the charging cable’s data link.
TLS handshake: both sides establish an encrypted channel before any identity data moves.
Certificate verification: the SECC checks the vehicle’s contract certificate against a trusted root; the EVCC checks the station’s certificate in return.
Contract selection: the vehicle presents the relevant charging contract if it holds more than one.
Authorisation and charge start: once trust is confirmed, power flows without a driver touching a screen.
TÜV NORD explains that this encrypted certificate exchange is precisely what removes the need for RFID cards or payment apps: the car identifies and authorises itself.
TLS isn’t optional dressing here, it’s the mechanism that stops a rogue charger or spoofed vehicle identity from hijacking a session. Certificate chains typically run from a trusted root authority down through intermediate certificates to the individual vehicle or station certificate, and every link in that chain has to validate correctly.
Pro Tip: If a Plug & Charge session fails intermittently, check the charger’s clock before anything else. Certificate validation depends on accurate time, and a drifting internal clock is one of the most common, and most overlooked, causes of authentication failures on site.
Expired certificates, incomplete trust lists, and clock mismatches account for the bulk of real-world failures, which is why certificate lifecycle management matters as much as the initial installation.
What do the different ISO 15118 parts actually cover?
ISO 15118 isn’t one document, it’s a family of parts, each with a distinct scope, and knowing which one applies matters when you’re writing a procurement spec.
ISO 15118-1: sets out general requirements, terminology, and use cases. ISO’s own catalogue describes it as the foundation that the other parts build on, covering both conductive and wireless high-level communication.
ISO 15118-2: defines the original application layer protocol for AC and DC charging, including the earlier Plug & Charge implementation.
ISO 15118-20: the current generation, adding multiplexed communication streams, multi-contract handling, and native support for bidirectional and wireless power transfer.
The standard governs communication between the vehicle and the charging station. It does not dictate how a vehicle’s internal battery management system works, nor how a charging network’s backend billing platform is built, those sit outside its scope.
CTEK notes that 15118-20 mandates TLS throughout and introduces the multi-contract and multiplexing capabilities that newer DC chargers depend on. When you’re specifying hardware, reference the exact part number, “ISO 15118-20 compliant” and “ISO 15118-2 compliant” are not interchangeable claims, and a supplier who blurs the distinction is worth questioning further.
How does V2G-PKI governance keep Plug & Charge trustworthy?
Every certificate exchanged during a Plug & Charge session has to trace back to a root that both the vehicle and the charger recognise. That’s the job of the V2G-PKI, a public key infrastructure built specifically for vehicle-to-grid communication, and without it, a vehicle has no basis to trust a charger it has never encountered before.
CharIN, the industry body coordinating Plug & Charge standardisation, states plainly that the whole system depends on this PKI governance layer. Its practical work includes:
Coordinating OPNC (Open Plug & Charge Network Communication), which lets certificates issued by one operator be trusted by chargers run by another.
Supporting Plug & Charge Europe, an effort to align certificate trust across operators on a continental scale.
Defining how certificate authorities issue, renew, and revoke certificates so a compromised or expired credential doesn’t leave a security gap.
Two governance models exist in practice: a single, shared PKI that every participant trusts, or a multi-PKI arrangement where separate root authorities cross-certify each other. The industry has largely gravitated toward the latter, because it avoids handing one operator control over who gets to participate.
Pro Tip: Ask any charge point operator you’re evaluating which trust list management approach they use. If they can’t answer clearly, that’s a strong signal their Plug & Charge implementation hasn’t been tested against real-world interoperability events.
CharIN’s own analysis is direct about this: projects succeed when installers plan certificate lifecycle and governance from day one, not as an afterthought once hardware is already in the ground.
Which vehicles and chargers actually support plug and charge?
Not every EV on the road can use Plug & Charge, and the limiting factor is usually hardware, not software.
Check the EVCC hardware first. TÜV NORD’s analysis makes clear that some vehicles lack the secure cryptographic module the EVCC needs to perform the certificate handshake. Where that module is absent, no over-the-air update will add Plug & Charge later.
Confirm the model year and trim. Manufacturer rollout has been uneven: some OEMs enabled ISO 15118 on specific models years before extending it fleet-wide, so two cars from the same brand can differ in capability.
Verify charger-side TLS support and firmware version. A charger installed even a few years ago may need a firmware update, or in some cases new communication hardware, to handle the TLS handshake correctly.
Ask for CharIN interoperability testing evidence. Chargers and vehicles validated at CharIN testivals have a documented track record of working together, which matters far more than a spec sheet claim.
Build compatibility checks into procurement, not into snagging lists after installation. Retrofitting Plug & Charge onto an existing site is sometimes straightforward and sometimes impossible, depending entirely on what hardware is already installed.
What benefits does plug and charge deliver for fleets and site owners?
The technical detail matters less to a facilities manager than what it changes on the ground, and the changes are measurable.
Faster turnover at destination sites. No fumbling with an app or card means shorter dwell time at each bay, which matters wherever charger numbers are limited.
Higher asset utilisation for fleets. Drivers who don’t have to manage multiple charging accounts use the infrastructure they’re given more consistently.
Automated billing across contracts. Multi-contract handling in ISO 15118-20 lets a vehicle select the correct commercial agreement automatically, cutting manual reconciliation.
A platform for what comes next. CharIN frames ISO 15118 as strategic to the wider energy transition, because the same trusted communication channel that handles authentication also carries the signalling needed for smart charging and vehicle-to-grid participation once V2G vs V2L use cases and regulatory frameworks mature further.
TÜV NORD’s assessment is that reduced friction and improved utilisation are the two benefits operators notice first, well before any V2G revenue conversation begins.
How do commercial installers actually deploy plug and charge?
A Plug & Charge rollout succeeds or fails on groundwork most drivers never see. Site surveys need to check comms availability, meter capacity, and local network headroom, alongside whether the intended charge point management platform actually talks OCPP correctly with the hardware being installed.
Confirm site comms and meter capacity before ordering hardware.
Check that the OCPP version supported matches the management platform’s requirements.
Establish who provisions and renews certificates for the site, and how revocation is handled if a device is compromised.
Plan firmware update and incident response processes before commissioning, not after a fault call.
Certificate provisioning is frequently handled by a specialist PKI operator working alongside the installer, since ongoing lifecycle management, renewal and revocation, in particular, is a continuous operational task rather than a one-off setup step. Swiftcharging’s own commercial installations, including projects like the Carl Zeiss site and the Indestructible Paint installation, follow this same survey-to-commissioning discipline.
Pro Tip: Get certificate renewal cadence written into your maintenance contract explicitly. A lapsed certificate doesn’t just disable Plug & Charge, it can take a charger offline entirely until someone notices.
What deployment and interoperability issues should operators expect?
Cross-vendor interoperability remains the sharpest edge of real-world Plug & Charge rollouts. Certificate trust mismatches between operators, where a vehicle’s contract certificate isn’t recognised by a charger from a different network, are the most common failure reported at scale, alongside subtly different implementations of the same ISO 15118 message set.
Trust mismatches: solved incrementally through OPNC-style cross-certification rather than a single universal fix.
Implementation drift: different vendors interpreting the standard’s edge cases slightly differently, which testing events exist to catch before deployment.
Scale-related faults: certificate expiry and clock drift becoming more visible the more sites and vehicles a network manages.
The sensible mitigation is a phased rollout: validate a small site against documented CharIN conformance evidence before committing an entire fleet or estate, and treat testival participation by your hardware supplier as a genuine selection criterion, not a marketing footnote.
Why the industry’s PKI problem gets underestimated
Most conversations about Plug & Charge focus on the driver experience, tap in, walk away, get billed automatically, and that’s a fair way to sell the concept. What gets glossed over is that the entire system rests on a governance layer most buyers never think to ask about until something breaks.

We’d argue the real risk in a Plug & Charge project isn’t the standard itself, ISO 15118 is mature and well documented, it’s treating certificate governance as an IT afterthought rather than a core part of the commercial specification. A charger that ticks every hardware box but sits outside a properly managed trust list will authenticate nothing. That’s not a hypothetical: it’s the single most common reason Plug & Charge deployments underperform their promise in year one.
The businesses getting this right are the ones asking their installer, before signing anything, exactly who manages certificate renewal and what happens when one expires at 2am on a depot full of vehicles. That question separates a genuinely deployable site from one that looks compliant on paper.
— Swift Charging
How Swiftcharging supports your plug and charge rollout
Swiftcharging designs and installs commercial EV charging infrastructure with ISO 15118 readiness built into the specification from the survey stage, not bolted on afterwards. That’s the practical advantage over sourcing hardware and certificate management separately: one team accountable for the whole chain, from site assessment through to certificate lifecycle support.

Our services for Plug & Charge projects cover site surveys and feasibility assessment, charger supply and installation across AC and DC, integration with charging management software, and ongoing maintenance including firmware updates and certificate renewal support. We also help eligible businesses access UK EV charging grants to offset installation costs. If you’re planning a fleet depot, workplace, or destination site and want Plug & Charge working properly from day one, book a site survey for your commercial EV charging installation and we’ll assess exactly what your hardware and network need.
Sources
Recommended