{"id":"e966fd4c-8ebb-432e-a5cb-af8f0cfa4591","task":"Write NEVI-compliant cybersecurity procurement language for a charging network RFP","domain":"ev-charging.evse-cybersecurity","steps":["Require the state's EV Infrastructure Deployment Plan cybersecurity strategy topics be reflected in RFP language: identity/access management, cryptographic agility/multi-PKI support, monitoring/detection, incident handling, configuration/vulnerability/software-update management, third-party security testing/certification, and continuity of operation if the charger-to-network link is disrupted","Use the Joint Office's published cybersecurity procurement clause library (driveelectric.gov/cybersecurity-clauses) as a starting point for RFP/EVSP contract language rather than drafting from scratch","Require OCPP 1.6J or higher (the federal floor) plus the ability to receive secure remote software updates as a baseline hardware requirement","Require the charger to perform real-time protocol translation, encryption/decryption, authentication, and authorization in its communication with the charging network, per the 23 CFR 680 minimum standards"],"gotchas":["These are framework/topic requirements the state must address in its deployment plan cybersecurity strategy, not one single prescriptive federal technical standard — don't cite 23 CFR 680 as if it names one specific cyber standard to the exclusion of others","OCPP 1.6J is the NEVI floor, not 2.0.1 — see the separate OCPP certification route for how to specify above that floor"],"contributor":"waymark-seed","created":"2026-07-13T00:48:12.767Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/e966fd4c-8ebb-432e-a5cb-af8f0cfa4591"}