PCI DSS EV Charging Payment Terminals and Isolated Cellular Network Segmentation
- Why EV charging makes PCI scope harder
- Three ways to connect the terminal
- PCI DSS v4.0 points that affect the cellular design
- Encryption over public networks
- Segmentation has to be tested
- Timing
- Who is responsible for what
- Keeping chargers online without widening scope
- How this maps to Quanqiu IoT
- FAQ
- Does a separate SIM for the payment terminal take the charger out of PCI scope?
- Is a private APN required for PCI DSS?
- Does OCPP carry card data?
- Which PCI DSS version applies to new charging deployments?
- Who performs segmentation testing for charger networks?
- Official References
- 延伸阅读
Definition: Cellular segmentation for EV charger payments keeps card-terminal traffic on a network path separate from the charger’s OCPP and maintenance traffic, so fewer charger systems fall inside PCI DSS scope.
If a card reader is built into or mounted on your chargers, the network design decides how much of the charging estate a PCI DSS assessor will treat as in scope. Give the payment terminal its own cellular path to the payment processor, keep it away from the charge controller and the CSMS connection, and the cardholder data environment can stay small. Share one flat connection, and the charger controller, the router and possibly your back office can be pulled into scope. Segmentation is not a PCI DSS requirement in itself, but it is the main tool for limiting scope, and it has to be proven by testing.
Why EV charging makes PCI scope harder
Unattended public chargers increasingly accept contactless cards directly. OCPP 2.1, released by the Open Charge Alliance in 2025, added support for ad hoc payment through a built-in or stand-alone card terminal, along with secure dynamic QR codes. At the same time, the charger already has a cellular or wired connection to a charging station management system (CSMS) over OCPP, plus remote access for firmware updates and diagnostics. The payment flow and the charging flow sit in the same cabinet, often behind the same router.
The standard defines the cardholder data environment as the people, processes and system components that store, process or transmit cardholder data or sensitive authentication data, plus components with unrestricted connectivity to them. A charger controller that can freely reach the payment terminal is a candidate for scope, even though it never touches a card number.
Three ways to connect the terminal
| Design | Path to processor | Likely scope impact (assessor decides) | What must be proven |
|---|---|---|---|
| Terminal with its own cellular modem and SIM | Directly from terminal to payment gateway or acquirer | Smallest: charger controller and CSMS link can often stay out of scope | No connectivity between terminal and charger network beyond what is documented |
| Shared router, separate VLAN or interface plus firewall rules | Through the charger’s router and cellular SIM | Router is in scope as a segmentation device; controller may stay out if isolation is verified | Firewall rules, change control and segmentation penetration tests |
| Shared router and flat network | Through the same network as OCPP and maintenance traffic | Large: controller, router and connected systems likely in scope | All applicable PCI DSS requirements across those systems |
A separate SIM or a separate APN helps, but it does not settle scope on its own. Isolation is incomplete when a maintenance laptop or the charge controller can still reach the terminal over a local interface. Draw the data flows and every physical and logical interface before the design review.
PCI DSS v4.0 points that affect the cellular design
Encryption over public networks
Requirement 4 calls for strong cryptography when primary account numbers travel over open, public networks, and PCI DSS guidance lists cellular technologies among those networks. A private APN improves isolation, but it does not replace encryption of card data in transit. In practice the terminal and payment gateway handle this with TLS, and a validated point-to-point encryption (P2PE) solution can further reduce what is in scope.
Segmentation has to be tested
When segmentation is used to reduce scope, PCI DSS v4.0 requires penetration testing to confirm the segmentation controls work: at least every 12 months and after changes for merchants, and every six months for service providers. Plan how that testing will reach a sample of chargers in the field, including their cellular interfaces.
Timing
PCI DSS v4.0 was published in 2022 and v4.0.1 in 2024. The older 3.2.1 version was retired in March 2024, and the requirements marked as future-dated became mandatory at the end of March 2025. New deployments should be designed against the current version.
Who is responsible for what
Charging projects often involve a charge point operator, a hardware vendor, a payment terminal vendor, a payment service provider and a connectivity provider. Responsibility for PCI DSS controls has to be written down, typically in a responsibility matrix. A connectivity provider delivers the SIM and the network path; a SIM contract does not guarantee compliance, and buyers should be wary of any supplier that implies otherwise. Use PTS-approved terminals listed by the PCI Security Standards Council and confirm with your payment service provider which integration models they support.
Keeping chargers online without widening scope
Payment availability matters to drivers as much as charging availability. Where the terminal has its own SIM, decide whether it needs a multi-network profile or failover to a second operator, and check that any backup path keeps the same isolation. Remote maintenance of the terminal should go through the terminal vendor’s own management service, not through the charger’s maintenance VPN. For the OCPP side, the operational issues are covered in our guide to OCPP charging stations and CSMS backhaul.
How this maps to Quanqiu IoT
We supply Global IoT SIM connectivity for both sides of the charger: the controller’s CSMS link and, where the design calls for it, a separate SIM for the payment terminal. Start with IoT SIM for EV chargers and energy monitoring and, for terminal connectivity, how to choose an IoT SIM for POS terminals. The EV charger SIM page lists plan options for pilots.
Small pilots can use catalog plans. For a network rollout, the number of chargers, whether terminals get dedicated SIMs, private APN needs, target countries and CMP reporting requirements change the procurement model, so request a project quote with your architecture sketch. We confirm connectivity options during project validation; PCI DSS scope and compliance remain decisions for you, your payment provider and your assessor.
FAQ
Does a separate SIM for the payment terminal take the charger out of PCI scope?
A dedicated SIM helps a lot, but scope depends on all connectivity between systems, not just the SIM. If the controller or a maintenance port can reach the terminal, the assessor may still include it.
Is a private APN required for PCI DSS?
No. PCI DSS requires strong cryptography for card data over public networks and appropriate network security controls, not a specific APN type. It can support segmentation but does not replace encryption.
Does OCPP carry card data?
OCPP is the protocol between charging stations and the CSMS. In OCPP 2.1 ad hoc payment designs, the card transaction is handled by the payment terminal and payment provider; check your specific integration to confirm that no cardholder data passes through the charger controller or CSMS.
Which PCI DSS version applies to new charging deployments?
The v4.x line applies. Support for 3.2.1 ended in March 2024, and the future-dated v4.0 requirements have applied since the end of March 2025.
Who performs segmentation testing for charger networks?
The entity responsible for the cardholder data environment arranges it, usually with a qualified internal resource or external penetration tester. Agree in advance how testers will access representative chargers and their cellular paths.