Join our Newsletter — 33% off our NHI Course
Architecture & Implementation

ISO 15118

← Back to Glossary
By NHI Mgmt Group Updated September 29, 2026 Domain: Architecture & Implementation

ISO 15118 is a communications standard for secure electric vehicle charging and vehicle-to-grid interaction. It defines encrypted, authenticated communication between vehicles and charging infrastructure, supporting trust in plug-and-charge workflows and helping reduce risks such as session manipulation, spoofing, and grid-related abuse during charging operations.

What ISO 15118 Means in Practice

ISO 15118 is more than a vehicle charging interface, it is the trust layer that lets an electric vehicle and charging system establish an authenticated session before charging begins. That matters because charging is not just power transfer, it is a negotiated digital transaction with safety, billing, and grid consequences.

The standard’s practical role is to make the handshake between car and charger predictable and verifiable. In plug-and-charge deployments, that reduces the operational burden of manual authentication and helps organisations avoid brittle workarounds that weaken assurance or create support friction.

For a glossary reader, the key point is that ISO 15118 sits at the boundary between physical infrastructure and digital trust. It helps determine whether the charger is speaking to the right vehicle, whether the session is authorised, and whether later control signals can be trusted.

How ISO 15118 Supports Secure Charging

ISO 15118 supports secure charging by defining authenticated communication and encrypted exchange during the charging workflow. That gives the vehicle, charging station, and supporting backend a common basis for trust when sessions are created, resumed, or extended.

The security value is strongest where charging is automated at scale. A well-implemented ISO 15118 flow can reduce the exposure created by ad hoc credentials, manual card handling, or loosely controlled local interfaces. It also helps establish a defensible identity relationship before energy delivery or vehicle-to-grid coordination begins.

In practice, this means the standard is part of the control surface for both confidentiality and integrity. It does not replace site security, device hardening, or backend governance, but it does narrow the space for spoofing and session tampering during the charging exchange.

Where ISO 15118 Fits in EV and Grid Architecture

ISO 15118 is best understood as a protocol layer inside a broader charging ecosystem. It interacts with vehicles, charge points, backend platforms, billing logic, and sometimes grid-facing orchestration, so its security value depends on the whole path being designed coherently.

That architecture matters because a secure protocol can still be undermined by weak endpoints, poor certificate handling, broken update processes, or misconfigured charger networks. The standard helps create trust between parties, but the surrounding environment determines whether that trust is durable.

This is why ISO 15118 is often discussed alongside charging infrastructure governance and certificate-backed trust models. The standard gives implementers a secure communication pattern, while operators still have to manage device inventory, lifecycle, and operational resilience around it.

Security Implications of ISO 15118

ISO 15118 is designed to reduce the kinds of failures that matter in charging systems, including spoofed sessions, unauthorised access, and manipulation of charging behaviour. If implementation is weak, the result can be fraudulent charging, disruption of vehicle availability, or abuse of grid-related functions.

Because the standard relies on trusted identities and cryptographic assurance, the surrounding certificate and key handling becomes a security dependency. Weak enrollment, stolen credentials, expired certificates, or inconsistent trust stores can all degrade the protection the protocol is meant to provide.

Where ISO 15118 is deployed in high-volume or high-availability environments, the operational impact can extend beyond a single charging session. A trust failure can cascade into customer experience problems, service disruption, or higher exposure for energy management systems that depend on stable charging behaviour.

Risk and Threat Considerations

ISO 15118 reduces some common charging risks, but it also concentrates trust in the charging handshake and the certificate-based relationships behind it. If those trust anchors are mismanaged, attackers may be able to impersonate a charger or vehicle, interfere with a session, or abuse charging workflows at scale.

Failure mechanism: Weak certificate lifecycle control, poor endpoint hardening, or insecure backend integration can let an attacker exploit the trust relationship that ISO 15118 is meant to establish.

Impact: The result can include fraudulent charging, denied service, unsafe session manipulation, or broader abuse of charging and grid-adjacent operations.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST SP 800-57, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementISO 15118 depends on managing certificates and trust material for authenticated charging sessions.
IA-2 — Identification and Authentication (Organizational Users)Secure charging ecosystems still rely on authenticated actors and privileged operators around the protocol.
SC-12 — Cryptographic Key Establishment and ManagementISO 15118 uses encrypted, authenticated exchanges that depend on sound key establishment and lifecycle control.
Recommendation — Manage certificates and related authenticators to preserve trusted vehicle-to-charger sessions. Require authenticated operator access for systems that provision, monitor, or revoke charging trust. Establish and rotate cryptographic keys to protect ISO 15118 trust relationships.
NIST SP 800-57Recommendation for Key ManagementISO 15118 deployments rely on lifecycle management of certificates and keys that support charging trust.
Recommendation — Apply key lifecycle practices to rotate, expire, and revoke charging credentials safely.
NIST Zero Trust (SP 800-207)Zero Trust ArchitectureISO 15118 is a trust-boundary protocol and benefits from never-trust, always-verify charging architecture.
Recommendation — Verify every charging session and trust boundary rather than assuming the network or charger is safe.
CIS Controls v8CIS-6 — Access Control ManagementCharging platforms need disciplined control of who can administer trust stores, chargers, and backend rules.
Recommendation — Control administrative access to charging infrastructure and revoke stale permissions promptly.

Practitioner Guidance

What to watch for: Treat ISO 15118 as a protocol trust framework, not a complete security programme. The standard is only as strong as the identity, certificate, and infrastructure controls around it, especially when plug-and-charge is used at scale.

Practitioner takeaway: The right implementation focus is not just “does the charger speak ISO 15118,” but “can every trusted actor in the charging chain be enrolled, validated, rotated, and revoked cleanly?”

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org