Write NEVI-compliant cybersecurity procurement language for a charging network RFP

domain: ev-charging.evse-cybersecurity · 4 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Require the state's EV Infrastructure Deployment Plan cybersecurity strategy topics be reflected in RFP language: identity/access management, cryptographic agility/multi-PKI support, monitoring/detection, incident handling, configuration/vulnerability/software-update management, third-party security testing/certification, and continuity of operation if the charger-to-network link is disrupted
  2. Use the Joint Office's published cybersecurity procurement clause library (driveelectric.gov/cybersecurity-clauses) as a starting point for RFP/EVSP contract language rather than drafting from scratch
  3. Require OCPP 1.6J or higher (the federal floor) plus the ability to receive secure remote software updates as a baseline hardware requirement
  4. Require the charger to perform real-time protocol translation, encryption/decryption, authentication, and authorization in its communication with the charging network, per the 23 CFR 680 minimum standards

Known gotchas

Related routes

Confirm NEVI Final Rule (23 CFR 680) compliance status before bidding an installer/site-host contract in 2026
ev-charging.nevi-compliance · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans