OCPP 2.0.1, explained for buyers
The Open Charge Point Protocol is the language your charger speaks to its back office. Version 2.0.1 changes what that language can say — and what you should demand on a datasheet.
Reading time 7 min · Updated August 2026 · ems-charge engineering

When you buy an EV charger for a public network, a fleet depot or a retail car park, the unit does more than deliver kilowatts. It has to start and stop sessions, meter energy, price each charge, throttle power when the grid is stressed, receive firmware updates, and report why it failed. All of that happens over OCPP — the Open Charge Point Protocol, an open standard maintained by the Open Charge Alliance. If a charger only works with one vendor's proprietary cloud, you are renting your own asset. OCPP is the open alternative that keeps chargers portable across networks and software platforms.
This guide is written for the person signing the purchase order, not the protocol engineer. It covers what changed in OCPP 2.0.1, why the version number matters commercially, and the five questions to ask before you commit. It assumes you already know the rough shape of the market: EV penetration is heading past 40% by 2030, and fast-charging capacity is projected to grow roughly tenfold in the same window, which means the chargers you buy today will be managed, diagnosed and load-shifted for a decade — not just plugged in and left alone.
1.6 vs 2.0.1Two versions, one protocol — very different toolboxes
Most chargers shipping today still advertise OCPP 1.6J. It is mature, widely deployed and cheap to implement, and it covers the essentials: starting and stopping a transaction, reading meter values, updating firmware, and reserving a connector. What 1.6 does poorly is model the hardware, secure the channel, and let the grid manage power intelligently.
OCPP 2.0.1 was written to close exactly those gaps, and it lands at the same moment regulators are forcing the market to move. The EU's AFIR timetable now mandates ISO 15118 communication on public chargers — ISO 15118-2 for public AC from 2026-01-08, and ISO 15118-20 (which carries V2G) from 2027-01-01. OCPP 2.0.1 is the management layer built to transport those richer messages. The practical rule: 1.6 is the safe default for a single-market deployment with a locked backend; 2.0.1 is the version you want if the charger will still be on a public network past 2027.
| Capability | OCPP 1.6J | OCPP 2.0.1 |
|---|---|---|
| Transport security | Optional TLS, basic auth | TLS 1.2+ required, signed firmware |
| Device model | Flat list of config keys | Hierarchical, per-component reporting |
| Smart charging | Single charging profile | Prioritised profiles from multiple actors |
| Transactions | Basic start / stop | Offline authorisation, ISO 15118, reservations |
| Diagnostics & OTA | Limited | Logging, monitoring, signed updates |
| V2G readiness | No | Yes, pairs with ISO 15118-20 |
Device model, security, smart charging
Device model. In 1.6, a charger exposes a flat list of configuration keys. In 2.0.1, every component — the meter, each connector, the contactor, the display, the fan — is a node in a hierarchy that reports its own state. For a network operator that is the difference between "charger 42 is offline" and "connector 2's contactor failed while connector 1 is still usable." That granularity is what turns a failure into a workable dispatch. It matters because real-world reliability is still the industry's weakest link: across public fast charging, roughly 14% of charging attempts fail, and about 60% of those failures trace back to a charger that is down or offline. A protocol that tells you precisely which component failed is the first step to fixing it remotely instead of rolling a truck.
Security. OCPP 2.0.1 enforces TLS 1.2 or higher on the transport and requires signed firmware updates. That closes the gap that let older chargers be spoofed or remotely reflashed. For a public or fleet network, a charger that can be remotely controlled must also be remotely trustworthy; a compromised charger is not just lost revenue, it is a grid-connected device an attacker can switch.
Smart charging. 2.0.1's ChargingProfile lets several actors — the grid operator, the CPO, the site owner — submit power limits at the same time, resolved by priority. This is the mechanism behind demand-charge avoidance at a depot or a retail site, where a single DC charger can pull 50–150 kW on its own and demand charges can be 30–70% of a commercial electricity bill. A protocol that can cap a whole site to a negotiated ceiling is, in many cases, worth more than the charger hardware itself.
Buying impactWhat to check before you sign
OCPP 2.0.1 is not a marketing checkbox. Vendors describe chargers as "2.0.1 compatible" when the firmware only partially implements the spec, so verify rather than assume. Certification is a concrete signal: formal OCPP 2.0.1 certification runs roughly $2,000–5,000 per unit line, so a charger that actually carries it has been through an independent conformance test, not just an internal self-declaration.
- Ask "certified or compatible?" — "compatible" often means "some messages map to 2.0.1"; "certified" means a test lab verified it.
- Confirm transport security. — which TLS version, and whether firmware updates are signed end to end.
- Check ISO 15118 pairing. — if the charger will serve EU public sites after 2027, it needs ISO 15118-20 (and therefore 2.0.1), not just 1.6.
- Verify the backend. — a 2.0.1 charger talking to a 1.6-only management system degrades silently to 1.6. The charger and the CSMS have to match.
- Confirm the device model is real. — ask for the component tree, not a screenshot of a settings page.
| OCPP 2.0.1 certification cost | $2,000–5,000 per line |
|---|---|
| ISO 15118-2 (public AC) deadline | 2026-01-08 (AFIR) |
| ISO 15118-20 (V2G) deadline | 2027-01-01 (AFIR) |
| US public charge failure rate | ~14% (60% charger fault) |
Buy the charger for 2030, not 2019
OCPP 1.6 still runs most of the world's chargers, and it is fine for a closed, single-market deployment. But the direction of travel is clear: richer device diagnostics, enforced transport security, and ISO 15118-based Plug&Charge and V2G are all arriving through OCPP 2.0.1. If your site will be public, multi-vendor, or grid-interactive after 2027, write "OCPP 2.0.1 certified" into the specification now — it is far cheaper than retrofitting a fleet of 1.6-only cabinets later. ems-charge ships AC and DC chargers on OCPP 2.0.1 with TLS 1.2+ and ISO 15118 readiness as standard; tell us your market and backend and we will match the right firmware profile to it.
Get a charger that speaks 2.0.1 natively.
Tell us your target market, power level and CSMS — we'll confirm the OCPP and ISO 15118 profile and reply with specs, pricing and lead time in 48 hours.
Send Inquiry