logo
Últimas notícias da empresa sobre EU AFIR & CRA: Compliance Requirements and Timeline for EV Charger Exporters

September 25, 2026

EU AFIR & CRA: Compliance Requirements and Timeline for EV Charger Exporters

EU AFIR & CRA: Compliance Requirements and Timeline for EV Charger Exporters

For EV charger manufacturers planning to export or already exporting to the European market, two EU regulations require thorough understanding: the Alternative Fuels Infrastructure Regulation (AFIR) and the Cyber Resilience Act (CRA). AFIR sets binding deployment targets and user experience requirements for charging infrastructure, while CRA imposes mandatory cybersecurity requirements on all products with digital elements. Both regulations are now in their implementation phase, and non-compliant products cannot be legally sold in the EU. This article systematically outlines the core provisions, timelines, and specific impacts of both regulations on EV charger manufacturers.

1. AFIR: Deployment Framework for Charging Infrastructure

AFIR, formally Regulation (EU) 2023/1804, is part of the EU's "Fit for 55" climate package, aiming to reduce greenhouse gas emissions by at least 55% by 2030. It sets legally binding deployment targets for charging infrastructure across EU member states.

1.1 Highway Network Deployment Targets

AFIR requires that on the TEN-T core road network, by 31 December 2025, there must be at least one recharging pool every 60 km in each direction, with a minimum total power output of 400 kW including at least one 150 kW recharging point. By 31 December 2027, each pool must provide at least 600 kW and include at least two 150 kW points. By 2030, the full TEN-T network (including the comprehensive network) must be covered. For heavy-duty vehicles (trucks and buses), dedicated recharging stations are required every 120 km.

últimas notícias da empresa sobre EU AFIR & CRA: Compliance Requirements and Timeline for EV Charger Exporters  0

 

Figure 1: AFIR Key Timeline

1.2 Fleet-Based Capacity Targets

AFIR also sets fleet-based public charging capacity targets: at least 1.3 kW of public charging capacity per registered BEV, and at least 0.8 kW per registered PHEV. This ensures infrastructure growth keeps pace with EV adoption. According to Transport & Environment's July 2026 report, all EU member states except Malta have met this fleet-based target, and the EU's total public charging capacity exceeds the minimum requirement by 180%.

1.3 User Experience and Payment Requirements

AFIR mandates that all public chargers must support ad-hoc payment — users must be able to charge without prior registration, subscription, or contract. Charging prices must be reasonable, transparent, easily comparable, and displayed before charging begins. This directly impacts hardware design: chargers must integrate contactless payment terminals or support ISO 15118 Plug & Charge.

1.4 Current State of EU Charging Infrastructure

According to the European Alternative Fuels Observatory (EAFO), as of August 2026, the EU27 has 1,157,551 public recharging points, nearly doubling from 632,423 at the end of 2023. The European Commission targets 3.5 million public charging points by 2030. On the TEN-T core network, 79% of road segments already meet AFIR's 2025 distance target (one 150kW+ ultra-fast station every 60 km), and 20 member states have already met the 2027 comprehensive network target ahead of schedule.

últimas notícias da empresa sobre EU AFIR & CRA: Compliance Requirements and Timeline for EV Charger Exporters  1

 

Figure 2: EU27 Public Recharging Points Growth


últimas notícias da empresa sobre EU AFIR & CRA: Compliance Requirements and Timeline for EV Charger Exporters  2

 


Figure 3: AFIR Target Progress (Mid-2026)

2. CRA: Mandatory Cybersecurity Requirements

CRA, formally Regulation (EU) 2024/2847, is the EU's first horizontal cybersecurity regulation covering all products with digital elements. EV chargers, as connected devices, fall fully within CRA's scope. According to the European Network for Cybersecurity (ENCS) analysis from February 2026, all requirements in CRA Annex I apply to electric vehicle charging stations.

2.1 Core CRA Requirements

CRA requires manufacturers to ensure cybersecurity throughout the product lifecycle, including: secure-by-design principles, vulnerability management processes, secure software update mechanisms, and reporting obligations for known vulnerabilities and security incidents. Products must pass conformity assessment before bearing the CE mark, which will also indicate CRA compliance. CRA imposes severe penalties: up to 4% of global annual turnover or EUR 20 million (whichever is higher).

2.2 CRA Timeline

CRA entered into force on 10 December 2024. Vulnerability and security incident reporting obligations apply from 11 September 2026. The main obligations (including secure design requirements, conformity assessment, and CE marking) apply fully from 11 December 2027. This means by end of 2027, all EV chargers sold in the EU must meet CRA cybersecurity requirements. On 27 July 2026, the European Commission published practical guidelines to help manufacturers prepare for CRA compliance.

últimas notícias da empresa sobre EU AFIR & CRA: Compliance Requirements and Timeline for EV Charger Exporters  3

 

Figure 4: EU Cyber Resilience Act Timeline

3. Specific Impacts on EV Charger Manufacturers

AFIR and CRA affect charger product design and export from different dimensions:

Hardware: AFIR requires new public fast charging stations to support at least 150 kW and ad-hoc payment, meaning DC fast charger products exported to Europe must integrate contactless payment terminals or support ISO 15118 Plug & Charge. AC chargers, while not subject to power requirements, must also meet transparent pricing and ad-hoc payment rules.

Software: CRA requires charger embedded systems to have secure boot, secure updates, and vulnerability management. Manufacturers need established security incident response processes, reporting vulnerabilities to EU authorities within 24 hours of discovery. IEC 62443 industrial automation cybersecurity standards can serve as the technical framework for CRA compliance.

Certification: CRA compliance will be integrated into the CE marking process, meaning existing CE certification workflows need to add cybersecurity assessment. Manufacturers should select CRA-qualified notified bodies early to avoid bottlenecks before the end of 2027.

4. Compliance Preparation Recommendations

First, conduct an immediate product gap analysis. Assess existing product lines against AFIR payment/power requirements and CRA cybersecurity requirements, and develop remediation plans. In particular, software security architecture upgrades must be completed before CRA fully applies in December 2027.

Second, prioritize high-power product development. AFIR is driving EU public fast charging toward 150 kW+, and liquid-cooled DC fast chargers supporting 150-360 kW will see growing demand. Products supporting OCPP 1.6/2.0 smart charging and ISO 15118 Plug & Charge will be more competitive.

Third, establish a cybersecurity management system. Build secure development processes per IEC 62443, including security requirements analysis, secure design, penetration testing, and vulnerability response, with complete technical documentation for CRA conformity assessment.

Fourth, monitor national implementation details. AFIR is transposed into national law by each member state, with potential differences in payment methods, price display, and site selection. Verify target market-specific requirements before export.

Sources

European Commission, Regulation (EU) 2023/1804 (AFIR), EUR-Lex

European Commission, Regulation (EU) 2024/2847 (CRA), EUR-Lex

European Commission Delegated Regulation (EU) 2025/656, April 2025

European Alternative Fuels Observatory (EAFO), Data Update August 2026

European Parliament, AFIR Implementation Background Paper, February 2026

Transport & Environment, EV Charging Progress Report 2026

European Network for Cybersecurity (ENCS), Coverage of CRA Annex I by IEC 62443 for EV Charging Stations, February 2026

European Commission Digital Strategy, Cyber Resilience Act policy page, updated September 2026