Xiaochong Energy

CYBERSECURITY & PROCUREMENT · ENGLISH BUYER GUIDE

EV charger cybersecurity procurement: 12 questions before remote access goes live

By Xiaochong Energy · · 7 min read

A charger is a connected operational asset, not only a power cabinet. Before acceptance, buyers need written answers about accounts, certificates, firmware, remote support, logs and incident ownership—matched to the exact charger, software version and management platform.

Xiaochong dual-gun DC charger representing a connected charging asset whose security scope must be defined per model and firmware

This is a procurement checklist, not a penetration-testing or live configuration procedure. Do not test, scan, reconfigure, unlock or update an operating charger without written authorization, approved model-specific instructions, qualified personnel, backups and a rollback plan. Never send production passwords, private keys, access tokens, payment data or customer records through ordinary email, WhatsApp or a public post.

Why the quotation must define operational security

The Open Charge Alliance (OCA) says security is integral to OCPP and its certification programs, and its 2026 Security Operations Guide complements protocol requirements with operational guidance for charging stations and management systems. That distinction matters: a protocol statement is not the same as a complete operating model for your site. Source: OCA Security Operations Guide.

The buyer should convert broad claims such as “remote maintenance,” “OCPP compatible” or “secure cloud” into named responsibilities, product-specific evidence and acceptance tests. The following 12 questions create that minimum discussion.

1–4. Accounts, credentials and remote access

1. Who owns the administrator account?

Name the legal asset owner, day-to-day custodian and authorized support roles. State what access the customer receives at handover and when a supplier account must be removed.

2. How are credentials issued and recovered?

Require unique project credentials, an approved storage method, role separation and a controlled recovery path. A shared default password or an undocumented personal account is not an acceptance plan.

3. How is remote support approved?

Define who can request, authorize, perform and review a remote session; what system records the event; and how access is disabled after the agreed support window.

4. What remains reachable from each network?

Document the charger, local controller, payment device, CSMS and service interfaces. Ask the responsible network designer to define segmentation and permitted communication for the real site.

5–8. Certificates, software and updates

  1. Which OCPP security profile and transport are implemented? Record the OCPP version, actual security profile, charger firmware and CSMS build. Do not infer a feature from the protocol name alone.
  2. Who manages certificates? Name the party responsible for issuance, installation, renewal, rotation, revocation, expiry monitoring and recovery. Agree what evidence is visible without exposing private keys.
  3. Where does firmware come from? Ask for the approved source, release identity, integrity or authenticity verification supported by the selected model, release notes and a record of who approved deployment.
  4. What happens if an update fails? Define maintenance windows, operational impact, staged rollout, monitoring, stop criteria, recovery route and the party authorized to execute the approved rollback.

OCA's current OCPP 1.6 Security Whitepaper identifies secure connection setup, security events/logging and secure firmware update as security improvements. Exact availability still depends on the selected implementation. Source: OCA OCPP 1.6 Security Whitepaper, Edition 4.

9–12. Detection, response and end of life

  1. Which security events and operational logs are available? Define the required event types, time synchronization, retention, access, export and review owner. Do not collect sensitive data merely because storage is available.
  2. How are vulnerabilities communicated? Request a documented reporting contact, acknowledgement route, affected-product identification, remediation communication and buyer notification responsibility.
  3. How long is the product supported? Record the security-support period, update channel, component or modem dependencies, end-of-support notice and commercial terms for support beyond the included period.
  4. How is a charger decommissioned or transferred? Define removal from the CSMS, revocation of credentials and certificates, SIM/account closure, approved data handling, asset records and evidence of completion.

Turn the answers into acceptance evidence

OCPP certification is product- and software-specific. OCA explains that official certificates can be checked by certificate number on its certified-products list. Ask for the exact evidence and verify it; do not treat a logo, company name or unrelated model as proof. Source: OCA certificate verification.

Buyer FAQ

Is an OCPP-compatible charger automatically secure?

No. Confirm the protocol version, implemented security functions, transport, certificate handling, firmware, configuration and operations for the exact charger and CSMS.

Who should own administrator credentials and certificates?

The contract should name the asset owner, operational custodian and authorized support roles, then define issuance, protected storage, rotation, recovery and revocation.

What evidence should be ready before acceptance?

At minimum: account and remote-access model, credential/certificate responsibility matrix, firmware and update process, event/log plan, vulnerability route, support lifetime, incident exercise and decommissioning procedure.

Discuss a project-specific AC or DC charging scope

Xiaochong Energy Technology (Zhongshan) Co., Ltd., China, can discuss project-configured OCPP, management-platform and technical-document requirements for selected AC and DC charging equipment. Cybersecurity functions, certificate handling, remote support, update process, certification and destination-market compliance must be confirmed for the exact model, firmware, platform and contract; no universal feature or certification is implied.

Send the destination country, charger type and quantity, required OCPP version and functions, intended CSMS, connectivity, payment scope, security requirements and acceptance owner. Use the free RFQ brief builder, read the backend exit-readiness guide, or review the English procurement pages.

xc0225888@163.com · Sales 1: +86 137 1772 6888 · Sales 2: +86 134 2580 6997

Related buyer guides

Primary sources reviewed 11 September 2026. This is Xiaochong's original procurement checklist. It is not an OCA endorsement, a cybersecurity audit, a test procedure or evidence that any Xiaochong model holds OCPP certification. Final requirements need authorized, project-specific review by qualified cybersecurity, electrical, platform and local-compliance specialists.