Germany's Federal Office for Information Security (BSI) published a position paper on July 28, 2026 — jointly with the Transport, Interior and Economic Affairs ministries and the National Charging Infrastructure Office (NLL) — setting out cybersecurity requirements for the country's public EV charging network. The BSI's press release is notably measured: the agency says the current security situation is "nicht als besorgniserregend" — not alarming — while flagging "Raum zur Verbesserung der Resilienz," room to improve resilience, as the network scales.
That caution is earned. An earlier BSI study, published May 7, 2026 with the Transport Ministry, identified concrete technical gaps: weaknesses at the communication-protocol layer and in the software running on charging stations, plus deficiencies in certificate management — the mechanism by which a charger and a vehicle cryptographically verify each other under ISO 15118, the standard governing vehicle-to-grid communication, and OCPP, the protocol linking chargers to backend operators. The BSI frames charging infrastructure as "ein wichtiger Knotenpunkt im Geflecht kritischer Infrastrukturen" — an important node in the critical infrastructure mesh — given its links to the power grid, payment systems and, increasingly, vehicle data.
The Case for Binding Rules
The steelman for BSI's push is straightforward and worth taking seriously. Germany now has 209,605 public charging points as of July 1, 2026, according to the Bundesnetzagentur's charging-point registry — up from 196,353 in February — with fast chargers growing fastest. Each of those points is an internet-connected endpoint touching payment data, vehicle identity, and in aggregate, meaningful load on the electricity grid. A protocol-level flaw in certificate handling isn't a hypothetical: a compromised charger could theoretically manipulate charging sessions, intercept payment credentials, or — at scale — be used to synchronize load spikes against grid stability. Voluntary security-by-design guidance has a track record of being unevenly adopted across a fragmented operator landscape (municipal utilities, private networks, retail chains), and BSI's own study found real gaps, not theoretical ones. The agency's stated goal — "grundsätzlich EU-weit einheitliche Sicherheitsstandards," fundamentally uniform EU-wide security standards — is also the right level of ambition: a charger standard that varies by member state defeats the purpose of a single market for EVs.
BSI's paper points to two vehicles for making those standards binding rather than aspirational: the EU's Cyber Resilience Act (CRA) and the Alternative Fuels Infrastructure Regulation (AFIR). The timing is not incidental. Under the CRA, reporting obligations for actively exploited vulnerabilities and serious incidents in networked products begin September 11, 2026 — six weeks after BSI's paper — with full product-security requirements phasing in by December 11, 2027, per BSI's own implementation guidance. Folding charger security into that existing EU machinery, rather than legislating a bespoke German regime, is the more proportionate path, and BSI deserves credit for reaching for it instead of a unilateral national mandate.
Why the Timeline Should Worry Regulators, Not Industry
The harder question is sequencing — and here BSI's own recent record argues for caution before layering on new binding obligations. Germany's NIS2 Implementation and Cybersecurity Strengthening Act took effect December 6, 2025, requiring an estimated 29,500 companies across 18 sectors to register with BSI by March 6, 2026. By that deadline, only around 11,500 had registered — roughly 18,000 obligated operators simply hadn't, prompting BSI to quietly extend the practical registration window into July. That is not a story about industry indifference to security; it is a story about a regulator whose own onboarding process outpaced the capacity of the entities it regulates to comply with it, even for a threshold obligation as basic as registering.
Charger operators are a more fragmented, lower-margin population than the strategic-sector firms already struggling with NIS2 — municipal Stadtwerke, highway rest-stop concessionaires, retail chains bolting chargers onto parking lots. Layering CRA-based binding technical requirements onto that population, on a timeline set by Brussels regulatory dates rather than operational readiness, risks repeating the NIS2 pattern at a larger scale: rules that are technically in force but practically unmet, with compliance theater standing in for actual security improvement. The CRA's own phase-in — reporting duties this September, substantive requirements not until the end of 2027 — already builds in more runway than NIS2 got, which is the right instinct.
BSI's position paper explicitly favors quick-implementable "Quick Wins" alongside the long-term standardization push, and that mixed approach is the correct one: patch certificate-management gaps and protocol hygiene now, through guidance and vendor coordination, while reserving binding CRA/AFIR-based mandates for the multi-year timeline where operators can actually plan capital and engineering budgets around them. The security gap BSI found is real. So is the compliance gap NIS2 just exposed. Germany doesn't need to choose between them — but it does need to stop treating a binding deadline as self-executing evidence of security improvement, which is precisely the assumption its own NIS2 registration numbers just falsified.