When you specify a commercial charging station in 2026, the connector on the cable gets the attention — but the protocol inside the firmware decides whether your network survives the decade. OCPP (Open Charge Point Protocol), maintained by the Open Charge Alliance, is the open language between your chargers and your backend (CSMS). And today there are two versions that matter: OCPP 1.6J and OCPP 2.0.1.
Picking wrong doesn’t just limit features — in the EU and US public funding programs, it can disqualify your project entirely.
What OCPP Actually Does
OCPP lets a charging station and a central management system talk about the things that matter: start/stop sessions, meter values, fault codes, firmware updates, authorization, and smart charging schedules. It is what stops you from being locked into one vendor’s software forever.
OCPP 1.6 was released in 2015. The “J” stands for JSON over WebSocket — the variant that won out over the older SOAP/XML “S” variant. OCPP 2.0.1 followed in 2020, and in October 2024 was adopted as IEC international standard IEC 63584; CENELEC published it as a European standard in 2025 . The US NEVI program (23 CFR 680) and California CALeVIP now require 2.0.1-aligned behavior for funded sites .

Head-to-Head: 1.6J vs 2.0.1
Capability | OCPP 1.6J | OCPP 2.0.1 (IEC 63584) |
|---|---|---|
Transport | JSON over WebSocket (SOAP optional) | JSON over WebSocket only |
TLS / Security | Optional, not mandated | Mandatory TLS 1.2+, X.509 PKI, 3 security profiles |
Device model | Flat (per charging point) | Hierarchical: Station → EVSE → Connector |
Smart charging | Static profiles (TxProfile) | Dynamic, central + local + external sources |
ISO 15118 / Plug & Charge | Not native | Native PnC, certificate install & validation |
Firmware updates | Basic, no signature check | Cryptographically signed, staged rollout |
Metering granularity | Per-session | Per-kWh / per-period / per-phase |
Message types | ~25 core | 100+ across functional blocks |
V2G path | None | Via 2.1 upgrade (architecture-ready) |
The single biggest operational difference: 1.6J does not mandate encryption. Many 1.6J networks rely on VPN tunnels or network segmentation — workable for a private depot, risky for a public corridor .

When 1.6J Is Still Defensible
Not every site needs 2.0.1. Legitimate 1.6J scenarios in 2026:
Small-scale AC installs (apartment block, 10× Type 2, RFID + flat-rate billing) behind a building firewall
Brownfield expansion where 200 existing 1.6J units are stable on a working CSMS
Emerging markets where local CSMS vendors haven’t fully validated 2.0.1 end-to-end
What is not defensible: new public DC fast charging in the EU, NEVI-funded US sites, or any project chasing ISO 15118 Plug & Charge. There, 2.0.1 is the floor.
Where 2.0.1 Pays Back
Security: Mutual TLS + signed firmware eliminates the “malicious OTA” and “session hijack” attack classes that 1.6J leaves open.
OPEX: A single manual firmware truck-roll costs $150–$400. Across 500 units, 2.0.1’s staged, signed remote updates save six figures annually .
Smart tariffs: SetChargingProfile + ISO 15118 lets your CSMS follow off-peak windows automatically — exactly what our Costa Rica bus depot used to cut energy cost [link to Costa Rica case study].
Future-proofing: 2.0.1 hardware is forward-compatible with OCPP 2.1 (2025), which adds V2G/V2X, DER control, battery-swapping flows, and local cost calculation
Avoiding the "Pseudo 2.0.1" Trap
Suppliers will say “OCPP 2.0.1 compatible” — verify before you sign:
- Ask for the OCA certification ID (only ~68 charger models globally held full 2.0.1 cert as of late 2025)
- Test Plug & Charge, signed firmware update, and security-event reporting live
- Confirm Full Profile (Core + Security + Smart Charging + Firmware), not just Core
Max Power's Position: Don't Lock Your Customer In
Every Max Power commercial DC charger — from the 80kW mobile unit in the Finnish mining site to the 240kW dual-gun in Costa Rica — ships with OCPP 1.6J today and a 2.0.1-ready firmware path. Operators can integrate with their existing 1.6J CSMS on day one, then upgrade to a 2.0.1 backend without replacing hardware.
That is the point of open protocols: the charger stays; the software evolves.
➡️ Plan your protocol strategy inside the [Commercial Charging Station Playbook]
➡️ See how mobility deployments are used in the specific scenarios: [The Mobile DC Charging Playbook: Power Wherever the Work Is]
➡️ Understand the physical plugs those protocols drive: [GB/T vs CCS2 vs NACS vs CHAdeMO]



