UK CPOs: 5 EV payment flows that keep chargers outside PCI DSS


An EV charger or operator falls into PCI DSS scope whenever it stores, processes or transmits cardholder data, or sits on a network with unrestricted access to systems that do. The most effective ways to limit that exposure are a PCI-listed P2PE solution or a fully hosted, redirect-based payment flow. UK contactless and roaming rules shape how payments are offered, but they do not replace or lessen PCI obligations.
TL;DR:
Using a PCI-listed P2PE solution or a fully hosted, redirect-based payment flow can significantly reduce PCI DSS scope for EV charging systems.
Systems performing encryption, decryption, or key management remain in scope despite encryption, as they can expose sensitive cardholder data.
Classifying payment architecture accurately, like P2PE or third-party hosted pages, determines the appropriate SAQ and compliance requirements.
Implementing strong TLS, hardware tamper resistance, and secure firmware updates are essential technical controls for PCI compliance in EV chargers.
UK regulations mandate contactless payment at certain chargers, but compliance with PCI DSS remains necessary regardless of the hardware features.
Table of Contents
When is an EV charging system in scope for PCI DSS?
Scope follows the cardholder data environment, or CDE: any system that stores, processes or transmits cardholder data, plus any connected system that could affect its security. For EV charging, that boundary is often wider than operators expect.
Systems typically inside the CDE include:
The point-of-interaction (POI) device on the charger itself, where cardholder data is captured.
Back-end transaction processing servers that route or authorise payments.
Logging systems that may handle primary account numbers (PANs), even temporarily.
Any network segment with unrestricted connectivity to the above, whether or not it handles payment data directly.
Encryption alone does not automatically remove a system from scope. PCI SSC guidance makes clear that systems performing encryption, decryption or key management stay in scope, because compromising them would expose the underlying data. Transient exposures, data briefly held in memory, written to a debug log or passed through a diagnostic tool, count just as much as permanent storage.
Borderline cases are common in distributed charging networks, so confirm classification with your acquirer and refer back to published PCI SSC documentation before assuming a system sits outside the CDE.
Common payment architectures and their PCI implications
Most EV charging deployments use one of a handful of payment models, and each carries a different scope outcome.
On-charger card reader (POI) without P2PE: typically in scope in full, since the device and everything it connects to sit inside the CDE.
On-charger POI with a PCI-listed P2PE solution: materially reduces scope because account data is encrypted at the point of interaction and only decrypted in the provider’s secure environment, often qualifying the operator for SAQ P2PE.
Mobile app paired with a hosted payment gateway: usually keeps the charger itself out of the CDE when the app never touches raw card data and the gateway handles the transaction.
QR code or redirect to a third-party hosted payment page: often removes the operator from scope entirely, provided the redirect is genuine and no cardholder data traverses operator-controlled systems.
Roaming and eMSP interactions: add complexity, since payment and authorisation data may pass through multiple parties, each with its own share of responsibility.
Classify your own deployment against these five patterns before deciding where to invest in scope reduction.
How operators can reduce or limit PCI DSS scope
Reducing scope is almost always cheaper than proving compliance across a sprawling estate, so it is worth treating as the first design decision rather than an afterthought.
Adopt a PCI-listed P2PE solution or a fully hosted checkout wherever the payment flow allows it.
Segregate payment systems from charger management and OCPP networks with documented, testable network boundaries.
Use third-party gateways only after confirming their PCI status, and put responsibilities in writing, in the style of Requirement 12.8.
Maintain POI chain-of-custody records and routine tamper checks across every device in a dispersed network.
Keep a current device inventory that ties each POI to its firmware version, location and last inspection date.
Pro Tip: Before signing any payment vendor, ask them directly which SAQ type their solution supports and request written confirmation, rather than relying on marketing claims.
Before finalising an approach, confirm with your acquirer which SAQ you are eligible for, what evidence they expect, and whether any card brand has additional validation requirements for your region.
Technical controls that meet PCI requirements for charging infrastructure
Scope reduction sets the boundary, but the controls inside that boundary still need to hold up under scrutiny.
Use strong TLS for every payment-related connection and validate endpoints rather than trusting default certificates.
Harden POI devices against physical tampering and favour hardware that meets PCI PTS device standards.
Avoid local key storage: where P2PE is in place, let the provider’s secure decryption environment handle key management.
Treat firmware updates as a supply chain risk, requiring signed packages and secure OCPP channels rather than unauthenticated pushes.
Run regular vulnerability scans, keep centralised logs, and gather evidence continuously rather than scrambling before an assessment.
Our post on securing commercial EV chargers against theft and cyberattack covers the operational technology side of this in more depth, and our OCPP protocol guide walks through firmware and communication security specifically.
UK regulatory context and what it means for payment handling
The Public Charge Point Regulations 2023 require contactless payment at new public charge points rated 8 kW or above, with rapid chargers given a defined compliance window to retrofit existing sites.
Mandated contactless capability does not change PCI obligations: the terminal and the flow behind it still need to meet the same PCI requirements as any other card-accepting system.
The Regulations also cover roaming support, open data publication and reliability targets, all of which touch systems that sit near, if not inside, the CDE.
Confirm with your acquirer and, where relevant, your roaming provider how these obligations interact with your chosen payment architecture before committing to hardware.
Our overview of UK public charge point regulations sets out the contactless and roaming requirements operators need to plan around.
Validation: choosing the right SAQ and preparing evidence
Picking the correct Self-Assessment Questionnaire depends on how payment data moves through your estate. SAQ P2PE suits operators using a validated P2PE solution; SAQ C-VT applies to virtual terminal setups; SAQ A and SAQ A-EP fit merchants who redirect or outsource payment pages with varying levels of control over the redirect mechanism.
Map your payment flow end to end, from card tap to settlement.
Confirm your provider’s PCI status and documentation for P2PE or gateway solutions.
Document network segmentation and test that it actually holds.
Collect evidence: network diagrams, the P2PE Instruction Manual, device inventory, chain-of-custody logs and segmentation test results.
Complete the appropriate SAQ or engage a qualified assessor where required.
Outsourcing payment processing reduces technical exposure but never removes operator responsibility: you still need to verify, in writing, that your providers meet their share of the requirements.
How Swift Charging supports secure, compliant payment deployments
We work with operators from feasibility and site assessment through to installation, payment integration and long-term maintenance, which means scope reduction gets considered at the design stage rather than bolted on afterwards. Our services span POI deployment, charger management software, ongoing maintenance and grant support, and we help clients prepare the documentation acquirers typically ask for during validation. Our plug and charge (ISO 15118) guide covers an emerging authentication flow relevant to future-proofing payment architecture.

Why PCI compliance is only part of a secure charging strategy
Treating PCI DSS as a standalone checklist misses the point: it works best woven into the same OT and IT security programme that covers firmware, OCPP communications and network segmentation. Operators who prioritise scope reduction and validated solutions spend less time firefighting audits later. Getting this right increasingly depends on operators, eMSPs, acquirers and regulators sharing the same baseline expectations, not on any one party acting alone.
— Swift Charging
Get help scoping a secure EV charging payment deployment
A short technical scoping call, paired with a site feasibility assessment, usually clarifies where your payment flow sits against PCI scope long before installation begins.

Site surveys and feasibility assessments for new or expanding charging estates.
Managed POI deployment alongside charger installation and commissioning.
Payment integration support and ongoing maintenance plans, including Basic, Standard and Fully Managed options.
Assistance identifying and applying for available UK EV charging grants.
Start with our workplace EV charging page to see how a scoped, payment-ready installation comes together.
This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.
FAQ
What are the specifications of an EV charging station?
Specifications vary by charger type, including lower-power AC units typical of workplace charging and DC rapid chargers delivering much higher power. The payment hardware specification matters just as much for compliance: whether the terminal supports P2PE, contactless and secure firmware updates shapes your PCI exposure.
Can I charge my electric car at work for free?
Some employers offer free workplace charging as a staff benefit, while others charge via RFID or app-based payment systems. Whether it is free or paid, any payment component still needs to meet the same PCI obligations described above.
What are CPOs in EV charging?
A CPO, or charge point operator, owns and manages the physical charging infrastructure and is typically the party responsible for PCI scope decisions across the network. CPOs often work alongside eMSPs and payment providers, which adds shared responsibility for compliance evidence.
How do I plan EV charging securely from a payment perspective?
Start by mapping your intended payment flow against the architectures described above, then confirm SAQ eligibility with your acquirer before selecting hardware. Favour a PCI-listed P2PE solution or hosted checkout wherever your use case allows it, since both meaningfully cut the work needed to demonstrate compliance.
Sources
Recommended