How secure is OCPP?
OCPP has three security profiles. Profile 2 adds TLS and a backend certificate, profile 3 certificates on both sides; profile 1 is not recommended for the field.
Explained in
How is the connection secured?Three security profiles, from basic authentication to client certificates: how charger and backend prove who they are, and why the choice matters.Profile 1 sends a password over an unencrypted connection, and the backend does not prove its identity at all. The Open Charge Alliance highly recommends a profile with TLS for field operation. Profile 3 goes furthest: both sides prove their identity with certificates.
Terms
Related questions
- Is a CSMS the same as a CPMS?Yes, both name the operator's backend. OCPP 1.6 calls it the Central System, OCPP 2.0.1 and 2.1 the charging station management system (CSMS); CPMS is the common industry term.
- What is the difference between OCPP 1.6 and 2.0.1?OCPP 2.0.1 is not backward compatible with 1.6: transactions became configurable and unified, and the device model was added. OCPP 2.1 builds on 2.0.1 and keeps it compatible.
- How does a charger connect to the backend?The charger opens a WebSocket to its backend, announces itself and then checks in at a set interval. Commands from the backend travel over the same connection.
- Which OCPP messages make up a charging session?In OCPP 1.6: Authorize, StartTransaction, MeterValues and StopTransaction. In 2.0.1, the transaction messages are events of one type, TransactionEvent.
- Open Charge Alliance: OCPP 1.6 Security Whitepaper, edition 4, February 2026. https://openchargealliance.org/ocpp-info-whitepapers/ocpp-1-6-security-whitepaper-4th-edition/. Checked 09 Oct 2026. Licence: CC BY-ND 4.0.