Write NEVI-compliant cybersecurity procurement language for a charging network RFP
domain: ev-charging.evse-cybersecurity · 4 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗
Steps
Require the state's EV Infrastructure Deployment Plan cybersecurity strategy topics be reflected in RFP language: identity/access management, cryptographic agility/multi-PKI support, monitoring/detection, incident handling, configuration/vulnerability/software-update management, third-party security testing/certification, and continuity of operation if the charger-to-network link is disrupted
Use the Joint Office's published cybersecurity procurement clause library (driveelectric.gov/cybersecurity-clauses) as a starting point for RFP/EVSP contract language rather than drafting from scratch
Require OCPP 1.6J or higher (the federal floor) plus the ability to receive secure remote software updates as a baseline hardware requirement
Require the charger to perform real-time protocol translation, encryption/decryption, authentication, and authorization in its communication with the charging network, per the 23 CFR 680 minimum standards
Known gotchas
These are framework/topic requirements the state must address in its deployment plan cybersecurity strategy, not one single prescriptive federal technical standard — don't cite 23 CFR 680 as if it names one specific cyber standard to the exclusion of others
OCPP 1.6J is the NEVI floor, not 2.0.1 — see the separate OCPP certification route for how to specify above that floor
Give your agent this knowledge — and 15,500+ more routes
One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp
Need this verified for your stack — or a route we don't have yet?