Technical library / Technology

ISO 15118 Plug and Charge vs RFID Cards: Which Authentication Will Win in 2026?

ISO 15118 can enable certificate-based Plug and Charge, while RFID remains useful for fleet, workplace, roaming, and fallback access. Here is how the two methods fit together under the current EU rules.

Article details

Published
February 5, 2026
Updated
July 10, 2026
Reading time
3 min read
Publisher
ChargeRFID
Back to Resources

By ChargeRFID

Review method: We checked this guide against the primary regulatory, protocol, and manufacturer references listed below. Product recommendations reflect ChargeRFID's manufacturing perspective and should be validated with your reader, charger, and backend.

ISO 15118 Plug and Charge vs RFID Cards: Which Authentication Will Win in 2026?

ISO 15118 and RFID solve related but different parts of EV charging authentication. ISO 15118 can let a compatible vehicle and charge point exchange contract credentials through the charging cable. RFID lets a reader present a token that a charging backend can associate with a customer, driver, vehicle, or fleet policy. Neither method removes the need for the other across every use case.

What the EU Rules Actually Require

ISO 15118 defines communication between an electric vehicle and charging equipment. A Plug and Charge deployment uses certificates and supporting backend services so a compatible vehicle can authenticate a charging contract after it is connected. That experience depends on compatible vehicle and charger implementations, certificate provisioning, contract support, and the parties' commercial arrangements.

From 8 January 2026, AFIR's amended technical annex references EN ISO 15118-2:2016 and EN ISO 15118-20:2022 for specified publicly accessible AC and DC points installed or renovated from that date. This is not a rule that every public charger must activate Plug and Charge. Optional functions remain optional, and a commercial Plug and Charge service still needs the certificate and backend ecosystem around the charge point.

Where RFID Still Wins

RFID authentication is not disappearing. Several scenarios can still benefit from a separate physical credential.

Fleet vehicles often need driver-level or cost-centre attribution. A vehicle-held Plug and Charge contract commonly identifies the vehicle's charging contract, while a card can be assigned to a driver or operating unit. That assignment does not create accurate reporting on its own; the backend must preserve the token-to-user mapping and combine it with session, vehicle, location, and policy data where required.

Rental and car-sharing operators may also prefer a temporary credential when the vehicle's contract remains under fleet control. Whether the renter pays directly or the fleet re-bills the session depends on the service design and commercial agreement.

Older EVs manufactured before widespread ISO 15118 adoption—including many vehicles still under warranty and in active service—lack Plug & Charge capability. These drivers need alternative authentication methods for years to come.

The Hybrid Approach: Supporting Both

Smart charging network operators are implementing dual-authentication systems. Stations support Plug & Charge for compatible vehicles while maintaining RFID readers for fleet users, older vehicles, and guest access. This hybrid approach maximizes accessibility without forcing users into a single authentication method.

The implementation effort is site- and hardware-specific. Reader hardware, firmware, OCPP support, token provisioning, certificate services, payment systems, and backend rules all need to be tested together. Keeping RFID alongside ISO 15118 can broaden access, but operators should confirm cost and interoperability with their charger and backend vendors.

Security Considerations

The methods have different security models. Plug and Charge relies on public-key infrastructure, certificates, and the implementations that provision, store, validate, and revoke them. Its security therefore depends on more than the charging cable exchange alone.

RFID security depends on the chip and on what the reader and backend verify. Many charging networks authorize only a card UID; that identifier can be copied on some credential types and should not be described as equivalent to contactless-payment authentication. AES-authenticated 13.56 MHz credential-class cards can support mutual authentication and protected application data, but those controls help only when the reader, key management, and backend actually use them.

A separate physical credential can add a second possession requirement, but it also creates its own loss, sharing, and revocation risks. Operators should choose controls from their threat model instead of assuming either method is inherently safer in every deployment.

Making the Right Choice for Your Network

If you operate publicly accessible charging stations in the EU, first determine which AFIR payment, data, and technical provisions apply to each point. Do not treat "ISO 15118 capable" and "commercial Plug and Charge enabled" as the same procurement requirement. Maintaining RFID can continue to serve fleet operators, rental services, contracted customers, and drivers of vehicles without compatible Plug and Charge support.

For private or workplace charging installations not covered by public mandates, evaluate your user base. Employee parking garages serving company fleets benefit from RFID's accountability features. Retail locations seeking maximum consumer convenience might prioritize Plug & Charge with RFID as backup.

Rather than betting on one method, operators can test a layered design against the vehicles, chargers, roaming partners, and billing workflows they actually support.

Need help implementing dual-authentication charging solutions? Contact us to explore RFID cards that complement your Plug & Charge infrastructure.

Company, network and product names referenced in this article are the trademarks of their respective owners. They are used descriptively to identify systems our cards interoperate with. ChargeRFID is an independent manufacturer and this article does not assert any affiliation, partnership or endorsement.

Primary sources

Official references used to review the regulatory, protocol, and chip-level claims in this guide.

Share:

Next step

Turn the research into a card specification.

Share the reader, chip, data or rollout context and we will identify the decisions required for samples and production.