Tuesday, October 27 | 2:15 - 3:30 pm

Vehicle-to-grid turns an EV from a charging load into a grid-interactive energy resource—and extends the cyber trust boundary far beyond the plug. The full chain can include the vehicle, EVSE, charging-network backend, certificate and roaming services, aggregator, utility or DERMS, cloud APIs, and local electrical controls. This panel will examine what is secure today, what ISO 15118-20, OCPP 2.1, PKI, and multi-root trust lists actually solve, and where implementation and governance gaps remain.

Panelists will explore high-consequence failure scenarios, safe limits on aggregated control, certificate lifecycle and incident recovery, and the role of Sandia’s emerging cloud-based PKI testing and open reference validation work. The discussion will close with practical controls and evidence that manufacturers, operators, aggregators, and utilities should require before V2G scales.

Key topics include:

From Plug & Charge to Grid Control: End-to-End Cybersecurity for V2G

  • A clear trust-boundary map: how risk and consequence change from the EV–EVSE session to fleet-scale cloud and grid control.

  • What standards and PKI do—and do not—prove: strong identity and encrypted links are necessary, but they do not make a valid command safe or create end-to-end authorization.

  • How to turn specifications into evidence: multi-root CTLs, negative testing, reference validation logic, revocation drills, and repeatable cloud/hardware interoperability testing.

  • A minimum V2G security baseline: local safety enforcement, least-privilege dispatch, segmented systems, secure updates and keys, monitoring, incident authority, and crypto-agile lifecycle operations.

Get in touch

Use this form to reach out. We will get back to you asap

Copyright 2026 Smart Grid Observer. All rights reserved