{"id":"8325a04e-8d47-4212-821c-a58646abbfac","task":"Provision ISO 15118 Plug & Charge certificates","domain":"energy-general","steps":["Understand the ISO 15118 V2G PKI hierarchy: the V2G Root CA signs Sub-CA1 (operated by a trust anchor like Hubject or an OEM), Sub-CA2 signs the SECC leaf certificate (installed on the charge point), and the OEM Provisioning CA issues OEM Provisioning Certificates to vehicles during manufacturing.","As a CPO, obtain a SECC (Supply Equipment Communication Controller) leaf certificate from your chosen V2G Sub-CA2 provider via the EST interface: generate a CSR with the charge point's EVSE ID encoded in the SubjectAltName, then POST to the EST /simpleenroll endpoint to receive the signed certificate.","As a Mobility Operator (eMSP), obtain the vehicle's OEM Provisioning Certificate from the Provisioning Certificate Pool (PCP) — Hubject's OPCP or an equivalent — and use it to sign a Contract Certificate (also called an eMSP Certificate) that authorizes the EV for charging on your network.","Push the Contract Certificate and its certificate chain to the CSMS; the CSMS delivers it to the charge point via the OCPP 2.0.1 InstallCertificate / CertificateInstalled message flow so the charge point can provide it to the EV during the ISO 15118 TLS handshake.","Implement the ISO 15118-2 (or -20 for DC and AC with V2G) communication session on the charge point side: the EV presents its Contract Certificate during the TLS client authentication, the SECC verifies the certificate chain against the V2G Root CA, and the session proceeds without a separate RFID authorization step.","Monitor certificate expiry: SECC and Contract Certificates have defined validity periods; implement automated renewal workflows that generate new CSRs and submit to the Sub-CA before expiry to avoid service interruption."],"gotchas":["The AFIR regulation (effective January 2026 for new AC public chargers, January 2027 for all) mandates ISO 15118-2 Plug & Charge support across the EU; deployments not implementing the full PKI provisioning flow will be non-compliant regardless of whether basic charging works.","Root CA trust anchors differ by market: the V2G Root CA operated by Hubject is widely used but not universal — OEM ecosystems (e.g., Tesla, some Asian OEMs) may use different trust anchors, and a charge point must trust all relevant root CAs to accept all compatible EVs.","Certificate provisioning requires the charge point, CSMS, and eMSP backend to all be online and correctly integrated; testing end-to-end in a lab environment with a test V2G PKI (Hubject provides an open test PKI at openplugncharge) is essential before production deployment."],"contributor":"waymark-seed","created":"2026-06-12T06:28:48.276Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"sampled","method":"legacy-file-sample","at":"2026-06-13T18:44:12.974Z"},"url":"https://mcp.waymark.network/r/8325a04e-8d47-4212-821c-a58646abbfac"}