ISO 15118 Is Now Law. Where Should the Grid Functions Live?
Executive Summary
In July 2026, the International Organization for Standardization (ISO) published Amendment 1 to ISO 15118-20, which adds grid services for AC charging. On 1 January 2027, the EU’s Alternative Fuels Infrastructure Regulation (AFIR) makes ISO 15118-20 a requirement for new and renovated public charge points. The standard is still changing months before it becomes law, and the EU has not yet said how a charger proves that it complies.
ISO 15118 governs the digital conversation between an electric vehicle and a charger. Its newest part carries bidirectional power and grid services into that conversation, which makes the charger a grid device. Rules in California, Great Britain, and Germany, and US product certification, push grid functions into the charger too.
One decision rule covers all five. Place each grid function where the rule tests it: in the charger, in the charging platform, or in the link to the utility. Keep the optimizing (when to charge, how much, and for whom) in the platform, where no rule tests it. Then keep the boundary easy to move, because the standard, the test, and the date can all still change.
This paper is for CTOs, heads of product, and compliance leads at charger and distributed energy resource (DER) device makers.
The Charger Is Becoming a Grid Device: Five Rulebooks, One Product
For most of the last decade, a connected charger answered to one system, the operator’s back office, and any grid behavior lived there or in the building’s energy management. Regulators have moved that boundary. Each rule below writes a grid function into the product, and California’s even names a protocol, the Open Charge Point Protocol (OCPP) 2.0.1.
| Rule | Market | Date | Grid function it forces into the charger |
|---|---|---|---|
| AFIR, as amended by Delegated Regulation (EU) 2025/656 (ISO 15118-20) | European Union | 1 January 2027 (ISO 15118 since 8 January 2026) | A secured digital session with the vehicle, the basis for Plug and Charge, bidirectional power, and grid services |
| CEC EV charger data and reliability standards | California | Networked chargers installed from 28 September 2026 | Hourly data reporting over OCPP 2.0.1; 97% uptime for publicly funded DC fast chargers |
| Electric Vehicles (Smart Charge Points) Regulations 2021 (GOV.UK guidance) | Great Britain | 30 June 2022 | Default off-peak charging hours, a randomized delay, demand side response, security, and measurement |
| §14a EnWG, the German Energy Industry Act (statute) | Germany | 1 January 2024 | Accept a power reduction from the grid operator, down to a guaranteed 4.2 kW per device under direct control |
| UL 9741 and UL 1741, including the new UL 1741 SC route (UL 1741 SC program) | United States | UL 1741 SC published 21 May 2026; UL Solutions program since September 2026 | Inverter grid-support behavior when the charger and vehicle export power to the grid |
Read across the rows and the demands are modest in kind. Speak a named protocol. Accept a limit. Behave predictably when the link drops. Report what happened. When a fleet should charge, or which site should give up power at a peak, appears in none of them. That gap is where the placement decision lives.
ISO 15118-20 Moves Grid Services Into the Charge Session
The ISO 15118 protocol is the communication layer of the Combined Charging System (CCS). It runs over the control pilot wire defined in IEC 61851, using power line communication (PLC) based on HomePlug Green PHY.
Under ISO 15118-2, the charger passes a power schedule and the vehicle plans its charge within it. Under ISO 15118-20, the charger can also take power from the vehicle, and in the dynamic control mode it sets the power while the session runs. Grid behavior once decided in a back office is now negotiated and secured in the charger.
ISO 15118-2 and ISO 15118-20 side by side
The two parts are not compatible at message level, so chargers carry both stacks.
| Aspect | ISO 15118-2 | ISO 15118-20 |
|---|---|---|
| Published | 2014 | 2022; Amendment 1 in July 2026 |
| Power direction | Charging only | Charging and discharging (bidirectional power transfer), AC and DC |
| How power is controlled | The charger passes a power schedule; the vehicle plans its charge within it | Scheduled mode, plus a dynamic mode in which the charger sets power during the session |
| Transport security | TLS required for Plug and Charge, optional otherwise | TLS 1.3 required for every session |
| Plug and Charge | Introduced certificate-based authorization; one contract per session | Carried forward; a vehicle can hold contract certificates from more than one provider |
| Charging types | Conductive AC and DC | Conductive AC and DC, plus wireless charging and automated connection devices such as pantographs |
| Status under AFIR | Required for new and renovated public charge points since 8 January 2026 | Required from 1 January 2027 |
Plug and Charge and the certificate chain
ISO 15118 Plug and Charge lets a driver start a billed session with no card or app. The vehicle holds a contract certificate tied to an account with an e-mobility service provider (eMSP). Over a Transport Layer Security (TLS) connection, the charger and its backend check the certificate’s chain back to a trusted root. In Europe, a small number of specialist operators run that root role for the ISO 15118 public key infrastructure (PKI).
For the maker, the PKI is a life-cycle obligation: secure key storage, certificate renewal over OCPP, and defined behavior on expiry or revocation. ISO 15118-20 requires TLS on every session, so this applies even without Plug and Charge. Who should hold the certificate relationships is covered in Plug and Charge on a platform the operator owns.
Bidirectional power and grid services in Amendment 1
ISO 15118-20 introduced bidirectional power transfer for AC and DC charging. Amendment 1 adds AC DER services, services for the Megawatt Charging System (MCS) used by heavy trucks, and a revised security concept. In AC bidirectional charging the inverter sits in the vehicle, so grid requirements reach it through the charger. UL 1741 Supplement SC, published in May 2026, follows the same logic: it lets the charger supervise a vehicle’s onboard inverter built to SAE J3072.
That is why vehicle-to-grid (V2G) programs depend on the charger as much as on the vehicle. Our V2G standards readiness analysis maps the standards at each layer, and Codibly’s V2X solutions page covers the delivery work.
The AFIR Deadline for ISO 15118-20 Has No Conformity Route Yet
Under Delegated Regulation (EU) 2025/656, which amended AFIR, new or renovated publicly accessible charge points have had to implement ISO 15118 since 8 January 2026, and must implement ISO 15118-20 from 1 January 2027. CharIN, the association behind CCS, reads the 2027 obligation as reaching private chargers too.
On 22 April 2026, CharIN asked the Commission to move the ISO 15118-20 date to 1 January 2028. By 1 October 2026 the Commission had proposed no delay, and its consultation on the AFIR review closed on 3 August 2026. The date in the law is the one to plan for.
What the CharIN position paper asks for
CharIN’s position paper of 28 April 2026 explains why. The delegated act sets a date but no conformity assessment route. Conformance test cases for ISO 15118-20 are still in development, and no certification scheme exists for AC chargers. IEC 61851-23 Edition 3, the electrical side of bidirectional DC charging, is not expected before the end of 2027. CharIN asks for a phased rollout.
The result is a legal obligation with no agreed test to prove it. Implement against the standard as published. Then design the product so that a new test case or edition costs a firmware update and a re-test, and leaves the hardware unchanged.

Three Places a Grid Function Can Live: Charger, Charging Platform, Utility Link
The charger. Hardware, firmware, and the vehicle-facing protocol stacks. An ISO 15118 wallbox carries the vehicle conversation, the certificates, the local power limit, and its fallback when the network link drops, plus V2G behavior on bidirectional models.
The charging platform. The charging station management system (CSMS) or the maker’s cloud, connected over OCPP. It holds the fleet view, tariffs, schedules, and reporting. OCPP 2.0.1 carries ISO 15118 certificates and data, and OCPP 2.1 extends the link to bidirectional control.
The utility link. The connection from the platform, or sometimes the device, to a grid operator, utility, or aggregator. OpenADR is typically used for demand response events and price signals. IEEE 2030.5 with the Common Smart Inverter Profile (CSIP) is typically used for direct DER control under interconnection rules such as California’s Rule 21. In Germany, EEBUS is the preferred interface between the grid operator’s control box and devices covered by §14a. Its interface between charging stations and local energy management is now an international standard, IEC 63380.
| Function | Where it lives | Which rule tests it |
|---|---|---|
| Vehicle session, certificates, and bidirectional power negotiation | Charger: ISO 15118-2 and ISO 15118-20 stacks, PLC modem, secure key storage | AFIR, through ISO 15118-20 conformance testing once a route is defined |
| Default off-peak hours, randomized delay, response to a demand side response signal | Charger, with the signal arriving from the supplier’s or maker’s platform | Great Britain’s Smart Charge Points Regulations, enforced against the product |
| Power reduction from the grid operator, down to 4.2 kW | Charger or the home energy management system in front of it, through the control box or EEBUS | §14a EnWG and the Bundesnetzagentur determination |
| Inverter behavior when exporting | Charger power electronics and firmware, supervising the vehicle’s onboard inverter on the AC route | UL 9741 and UL 1741, including UL 1741 SC |
| Session, status, and uptime data | Charger reports over OCPP 2.0.1; platform stores and submits | California’s charger data and reliability standards |
| Demand response events, price signals, and DER control | Utility link in the platform: an OpenADR VEN, or an IEEE 2030.5 CSIP client | Utility program rules, through OpenADR Alliance or SunSpec Alliance testing |
| Optimizing: when to charge, how to share limits, what to offer a flexibility market | Charging platform | No rule; it is judged on commercial results |
Real products blur the split. A German home charger may receive its limit through a control box or the maker’s cloud. Our white paper on multi-protocol compliance treats the whole protocol stack as an architecture decision. Placement decides which component carries each function.
How to Decide the Split: The Rule Decides Where a Function Is Tested
Rules now start projects. Several charger and device makers that approached Codibly this year named a utility program or a network rule as the trigger. The rules can decide the architecture as well.
If a rule checks a function at the product, the function lives in the product. The British regulations are enforced against the charge point that is sold. A UL certificate is issued for the equipment. ISO 15118 conformance tests run against the charger. Moving such a function into the cloud leaves the test where it was.
If a rule checks a function at the program interface, the function belongs in the utility link. OpenADR Alliance and SunSpec Alliance testing certify the software that talks to the utility, so one certified implementation in the platform serves the whole fleet.
No rule checks the optimizing: when to charge, how to share a limit across sites, what to offer a flexibility market. It belongs in the platform, where it can change every week without re-testing a single charger. OCPP Alone Won’t Make Your Chargers Grid-Ready draws the same line, and Codibly’s smart charging work follows it.

Many makers will do less, and that can be rational. The rules cover only new and renovated sites, much of the work is a software update, and a ready protocol module lets a maker wait for testing to mature. A bought module covers only the charger side, though, and what stays out of the charger remains the maker’s decision.
The utility link is where testing is most mature. The Codibly OpenADR VTN 2.0b (Firmware 1.0) is certified by the OpenADR Alliance, and a major US pool equipment manufacturer took its OpenADR 2.0 VEN through certification in six weeks on Codibly’s pre-certified accelerator code. For IEEE 2030.5, Codibly is a SunSpec Alliance Authorized Test Laboratory and runs CSIP conformance testing itself. OpConnect used that route to bring IEEE 2030.5 CSIP, including the Australian CSIP-AUS profile, to its charging platform.
Testing a Standard That Is Still Moving
At the CharIN Testival in Arnhem in May 2026, 13 of 23 DC test systems and 7 of 11 AC systems supported bidirectional power flow, electrive reported. CharIN still considers V2G compliance testing against European grid requirements to be at a relatively early stage. Three habits reduce the cost:
- Test against real vehicles. Interoperability events find faults that simulators miss.
- Plan the certificate life cycle. Certificates expire and trusted roots change, so the update path must exist from the first shipment.
- Plan releases around known changes. Amendment 1 now, an EU conformity route later, IEC 61851-23 Edition 3 after that. Each triggers a re-test of whatever lives in the charger.
Protocol stacks behind a stable internal interface turn a new edition into a module swap. Codibly’s interoperability services cover this integration and test work. UL certification itself is carried out by UL Solutions.
What to Put on the 2027 Roadmap
Makers are already deciding. At least one European charger maker has cut its EU range to ISO 15118 products and set a last-buy date for its older models, with no conformity route in place. A 2027 roadmap should include:
- A rule-to-product map. For each model and market, the grid functions required and where each rule tests them.
- A hardware check. Models for EU public sites need the PLC modem, processing for TLS on every session, and secure key storage.
- Both ISO 15118 stacks. Older vehicles will use ISO 15118-2 for years, so the charger carries -2 and -20.
- A certificate path. Installation and renewal over OCPP 2.0.1, with defined behavior on expiry and revocation.
- A utility link per market, in your platform or your customers’.
- Optimizing kept out of firmware. The charger enforces limits. The platform decides them.
- A re-test budget. One after Amendment 1, another when the EU defines a conformity route.
A Charger Built for the Next Rule
These five rules will not be the last. Each new program will ask the charger to carry one more interface, accept one more limit, or report one more data point. Makers that place each function where its rule tests it absorb those changes as module updates and platform releases. Makers that spread grid logic across firmware re-test the whole product every time.
Codibly works on all three sides of the split: pre-certified protocol code for the charger and the platform, the certified Codibly OpenADR VTN 2.0b (Firmware 1.0) for the utility link, and SunSpec laboratory testing for IEEE 2030.5. The practical first step is a rule-to-product map for each model line, and Codibly’s e-Mobility team can build it with you.
Frequently Asked Questions
ISO 15118-2 (2014) covers one-way AC and DC charging, power schedules, and Plug and Charge. ISO 15118-20 (2022) adds bidirectional power transfer, a dynamic control mode, TLS on every session, and wireless and automated connection charging. The two are not compatible at message level, so chargers carry both and negotiate one per session.
In the EU, yes, for new and renovated publicly accessible charge points. Under AFIR, ISO 15118 is required from 8 January 2026 and ISO 15118-20 from 1 January 2027, and CharIN reads the 2027 obligation as covering private chargers too. Elsewhere, it usually arrives through funding programs and carmakers’ requirements.
The vehicle stores a contract certificate linked to the driver’s eMSP account. On connection, the vehicle and charger open a TLS session, the vehicle presents the certificate, and the charger and its backend check the chain to a trusted root, including expiry and revocation. If the checks pass, the session is authorized and billed with no card or app.
Many recent CCS vehicles support ISO 15118-2, and a growing number offer Plug and Charge. Support for ISO 15118-20 and bidirectional charging covers fewer models and often depends on the vehicle’s software version. For planning, test with real vehicles, because datasheets lag behind software updates.