
New framework provides robust security evidence for e-mobility
Stuttgart, October 2026 – Charging infrastructure for electric vehicles is developing rapidly – and with it, the attack surface available to cybercriminals. Operators, manufacturers and service providers are under growing pressure not only to raise security levels, but also to demonstrate them robustly to customers and regulators. asvin and ChargeIQ will shortly present a cybersecurity framework.
The CYSSDE-funded research project Pentest4CI by asvin and ChargeIQ demonstrates how a realistic penetration-testing framework can be used to systematically assess and demonstrably improve the cybersecurity of connected charging systems.
“For our customers, it is crucial that charging is not only convenient and transparent, but also demonstrably secure,” says Volker Fricke, CEO of chargeIQ. “With a reproducible penetration-testing framework, we can for the first time underpin security commitments with robust facts – and that also changes conversations with fleet operators, energy suppliers and local authorities.
From individual tests to systematic security evidence
To date, security assessments in e-mobility have often consisted of selective audits, manufacturer-specific tests or reactive measures following incidents.
The framework presented takes a different approach: it turns penetration testing into a structured, repeatable methodology based on established standards such as PTES, OWASP and NIST SP 800-115. The focus is not solely on individual components, but on the entire charging-infrastructure value chain – from the charging station (EVSE) and the front end and back end of the Charge Point Management System (CPMS) through to roaming interfaces and connected payment services.
At the core of the project, which began in October 2025 and is scheduled to run for 18 months, is a modular, scalable test environment that replicates a complete EV charging infrastructure under realistic but isolated laboratory conditions. Within this environment, typical attack vectors – such as unauthorised access, privilege escalation, web exploits, configuration errors or compromised credentials – can be simulated in a controlled manner, while countermeasures can be evaluated before they are rolled out in the field.
“E-mobility is critical infrastructure – and we need to approach penetration testing with the corresponding degree of professionalism,” stresses Mirko Ross, CEO of asvin. “What we are creating with this framework are repeatable, standards-compliant tests that can be scaled – from individual wallboxes to complex, connected charging networks across Europe.”
Structured penetration testing based on established standards
The framework defines clearly delineated test scenarios and test cases that apply across the entire charging-infrastructure architecture. These include authentication and authorisation, access control, session management, API security, input validation, TLS-secured communication and local configuration interfaces of charging stations. The tests can be carried out automatically, documented and compared across different systems and releases.
In practice, this means that operators and manufacturers can assess their products and services using the same set of attack patterns, thereby establishing consistent security benchmarks across different EVSE implementations and back-end systems. This provides a basis for objective comparisons and facilitates both internal security approvals and external audits.
Initial findings: strengths, vulnerabilities and specific recommendations for action
The project’s application scenarios to date show that key protective mechanisms have already been effectively implemented in the systems tested – including rate limiting, secure cookies, modern TLS configurations and effective XSS protection. At the same time, the penetration tests identified a specific vulnerability in the local EVSE web server: excessively detailed error outputs containing stack traces and library information that could provide potential attackers with valuable clues.
Electric Vehicle Supply Equipment web servers are part of the charging equipment for electric vehicles. The web server provides the APIs (interfaces) and the graphical user interface (GUI) for managing the EVSE communication module. From such findings, the project team derives clear recommendations for action, including rigorous error hygiene, minimising information disclosure and the secure exposure of APIs. The recommendations can be transferred directly into secure-engineering roadmaps, product development and DevSecOps processes. Through repeatable testing across multiple product generations and software releases, the framework supports the continuous improvement of the security posture.
“From a technical perspective, it was important to us not merely to identify individual vulnerabilities, but to obtain a robust picture of the entire attack surface,” explains Rohit Bohara, CTO of asvin. “To achieve this, we combine established standards with automatable scenarios and a laboratory environment that replicates real charging infrastructure as accurately as possible – including protocols, interfaces and typical misconfigurations.”
Relevance for the DACH market and European regulation
For OEMs, wallbox manufacturers, charge point operators and back-end providers in Germany, Austria and Switzerland, cybersecurity is becoming a central prerequisite for the acceptance and scaling of public charging infrastructure. Regulatory requirements and EU security directives increasingly require verifiable evidence that appropriate technical and organisational protective measures have been implemented.
The penetration-testing framework addresses precisely this gap: it provides a tool that can be used immediately for independent or audit-supported security assessments of components and services. Providers can therefore document to fleet customers, energy suppliers and regulatory authorities that security by design is not merely a marketing promise, but can be demonstrated through standardised testing and reproducible results.
Outlook: security benchmarks for a resilient e-mobility ecosystem
Beyond the individual test cases, the project aims to establish consistent security benchmarks for connected charging infrastructure in Europe. The planned stronger involvement of external stakeholders and end users in upcoming project phases is intended to help develop practical security guidelines and best practices for operators and manufacturers.
In the long term, the framework can make an important contribution to a resilient e-mobility ecosystem: through consistent security assessments across system boundaries, robust evidence for market partners and authorities, and the continuous improvement of security architectures in a highly dynamic technology field.
About chargeIQ:
chargeIQ is specialized in the simple management and automated billing of charging infrastructure for electric vehicles. The Leinfelden-Echterdingen based company enables efficient and easy management of private and semi-public charging infrastructure in various use cases with its accessible user-focused software. ChargeIQ´s modular platform makes it possible to freely choose hardware, software and operating mode without being dependent on proprietary systems. https://chargeiq.de/en
Media contact:
Volker Fricke
Mail: volker@chargeiq.de
About asvin:
asvin is a Stuttgart-based cybersecurity company specialising in cyber threat and risk intelligence for connected products, industrial infrastructures and complex supply chains. With AI-supported analysis, context-based risk assessment and automated CTI reports, asvin helps organisations identify threats at an early stage, prioritise risks and implement regulatory requirements efficiently. https://asvin.io/

Konrad Buck
Leiter der Presse- und Öffentlichkeitsarbeit
Hintergrund & Expertenzugang für Medien
- Produkt- & Technologieeinblicke – Technischer Kontext, Lösungsarchitektur und praxisnahe Anwendungsbeispiele für Fach- und Wirtschaftspresse.
- Expertenkommentare & Hintergrundgespräche – Unser CEO steht als Expert:innenquelle zu aktuellen Entwicklungen in der Cybersicherheit, Bedrohungslandschaften sowie den Auswirkungen von KI auf Sicherheit und Regulierung zur Verfügung.
Ich spreche offen, faktenbasiert und ohne PR-Floskeln. Als ehemaliger IT-Journalist mit jahrzehntelanger Erfahrung in der IT- und Cybersicherheitsbranche kenne ich die Höhen und Tiefen der Industrie. Hintergrundgespräche off the record sind auf Anfrage möglich.





