News

Laadpas vs. App vs. Plug & Charge: What Authorisation Method Is Right for Your Network?

Charge card held against an EV charger RFID reader

In EV charging, the moment of authorisation shapes everything that follows: the driver’s first impression, the reliability of your network, the accuracy of your billing, and even your support costs. There are three mainstream ways to start a session today, each with real advantages and real tradeoffs. Choosing the right mix is less about picking a winner and more about matching methods to site context, hardware, and user profiles.

Three ways to start a charging session

The humble RFID card (laadpas in Dutch) has dominated EV charging authorisation for a decade. But two newer alternatives — mobile app QR/NFC and ISO 15118 Plug & Charge — are now mature enough to deploy. Each has genuine tradeoffs.

  • RFID (laadpas): simple, familiar, and resilient, with offline options that keep sites running.
  • Mobile app / QR: flexible, real-time, and accessible to visitors without a physical card.
  • Plug & Charge (ISO 15118): the most seamless driver experience — when the car and charger support it.

Most networks benefit from a hybrid approach. Your decision should account for site type (fleet, workplace, public), connectivity, charger capabilities (AC vs DC), and how often first-time or occasional users visit.

RFID (laadpas)

RFID has been the workhorse of EV charging for a reason. It’s hardware-agnostic, widely supported across AC and DC chargers, and familiar to drivers. At a technical level, it’s simply a token (the card’s unique identifier) matched to an authorised account in your back-end or roaming partner. When connectivity is shaky or unavailable, chargers can fall back to a local authorisation list to keep sessions flowing — a major operational benefit on sites where network outages are possible.

Strengths:

  • Hardware-agnostic: Works across virtually all commercial chargers.
  • Offline-capable: A locally stored whitelist lets depots and car parks keep operating without a live connection.
  • Simple UX: Tap, beep, start. Drivers already know the pattern.

Limitations:

  • Physical dependency: Cards can be lost, shared, or forgotten, which may complicate account control and cost allocation.
  • Security posture varies: Depending on card type and implementation, cloning risk exists; good practice is to treat cards as low-trust tokens backed by server-side checks.
  • Data latency when offline: If the charger authorises from a local list, prices and usage data may not synchronise until connectivity returns.

Operational tips:

  • Keep local whitelists tight and refreshed to reduce fraud exposure while preserving uptime.
  • For fleets, link driver or vehicle cards to cost centres for clean reporting.
  • Provide a visible help path for visitors who arrive without a card (QR/app fallback).

Best for: closed fleet depots and workplace charging where drivers have a managed card.

Mobile app / QR code

Mobile authorisation (through an app or a QR code leading to a web flow) removes the need for a physical card. It also enables a richer pre-session experience: you can display the exact tariff before authorisation, show power availability, and collect consent or vehicle details as needed.

Strengths:

  • No physical card: Nothing to distribute, replace, or remember.
  • Real-time pricing: Drivers can see the tariff up-front and make informed choices.
  • Flexible onboarding: App stores and QR codes make it easy for first-time visitors to start a session quickly.

Limitations:

  • Requires a smartphone and connectivity at the point of charge: Underground car parks, rural areas, or shielded garages may challenge app or web flows.
  • Potential for friction: Account creation, payment setup, or poor QR signage can slow first-time users.
  • Support surface area: You may field more “how do I start?” questions from occasional users, especially if the app flow is not streamlined.

Operational tips:

  • Use clear, durable QR signage at eye level, near the connector, with concise instructions.
  • Offer a guest/one-time payment option to minimise account-creation friction for occasional users.
  • Optimise the flow for low signal areas (light pages, cached assets, minimal redirects).
  • If your site relies on variable tariffs, ensure the app displays the price before authorisation to avoid disputes.

Best for: public and semi-public charging where occasional visitors need access.

Plug & Charge (ISO 15118)

Plug & Charge allows the vehicle itself to present a cryptographic identity when you connect the cable. If the car and charger are both compatible, authorisation can happen automatically — you plug in and charging starts, no card or app required. The identity is backed by certificates, providing strong authenticity and reducing the risk of token sharing.

Strengths:

  • Zero friction: The smoothest possible start to a session — especially valuable at busy fast-charging sites.
  • Strong cryptographic identity: Certificates reduce ambiguity about who is charging, which can simplify billing and reduce certain fraud vectors.
  • Consistent experience: When supported, the flow is the same across sites — plug in and go.

Limitations:

  • Compatibility required on both sides: The vehicle must support ISO 15118 certificate-based authorisation, and the charger must be enabled accordingly.
  • Certificate lifecycle management: You need to provision, renew, and revoke certificates; this adds operational overhead and coordination.
  • Mostly DC today: While support is broadening, many deployments start with DC fast chargers because that’s where throughput benefits are most impactful.

Operational tips:

  • Label Plug & Charge availability clearly and provide fallbacks (RFID/QR) for non-compatible vehicles.
  • Maintain a robust process for certificate issuance and renewal to avoid failed starts.
  • Consider enabling Plug & Charge in new DC fast-charging deployments to future-proof the site and reduce start-time bottlenecks.

Best for: high-throughput fast-charging networks where speed of authorisation matters.

What really drives the choice: context and constraints

Beyond headline pros and cons, a few practical factors dominate deployment strategy:

  • Site profile and user mix:

    • Fleet depots and workplaces value predictable access and offline resilience. RFID shines here.
    • Public and hospitality sites see a steady flow of first-time users. A QR/app flow avoids card dependency.
    • High-turnover DC sites benefit most from Plug & Charge’s instant start.
  • Connectivity and resilience:

    • If connectivity is unreliable, prioritise methods that can operate offline (RFID with local lists).
    • For smartphone-reliant flows, test cellular coverage at each parking bay — not just at the site entrance.
  • Hardware and firmware readiness:

    • Verify charger support for app/QR authorisation and the ability to display or announce tariffs in your chosen flow.
    • For Plug & Charge, confirm the charger’s ISO 15118 implementation and the operational path for certificate management.
  • Tariffs and transparency:

    • Real-time pricing display is easy with app/QR, harder with pure RFID unless the driver’s eMSP communicates tariffs.
    • If you use time-of-use or demand-based pricing, the app flow can set clear expectations.
  • Roaming workflows:

    • RFID tokens are straightforward to roam via standard interfaces, making them familiar to drivers carrying third-party cards.
    • App-based ad hoc payments can serve visitors without a roaming agreement.
    • Plug & Charge roaming hinges on certificate trust relationships; ensure your partners are aligned before you rely on it.
  • Access control and security:

    • Decide whether you allow anonymous ad hoc use (typically via QR/app) or restrict access to known users (RFID/Plug & Charge contracts).
    • Protect offline whitelists with strict update intervals and auditing.
  • Support and signage:

    • Document and post the primary and fallback method at each bay.
    • Provide short, visual instructions for first-time users, including what to do if a method fails (e.g., “Try QR code if your card doesn’t work”).
  • Cost of ownership:

    • RFID involves card procurement and management but low per-session friction.
    • Apps reduce physical logistics but may increase onboarding and support tasks.
    • Plug & Charge centralises identity in the vehicle but introduces certificate operations.

Recommended deployment patterns

For most mixed-use sites, a layered approach works best:

  • Primary: RFID for known users. It’s fast, familiar, and tolerant of connectivity issues.
  • Fallback: App/QR for visitors and as an alternative when a driver forgets their card.
  • Future-ready: Enable or plan for Plug & Charge on new DC installations to capture speed and UX benefits as vehicle compatibility grows.

Within this model, standardise a simple decision tree for drivers:

  1. Tap your card if you have one.
  2. If not, scan the QR to start a session and see the tariff.
  3. If your car supports Plug & Charge and the site is enabled, just plug in — the charger will take care of the rest.

This reduces confusion, shortens queue times, and lowers support overhead.

Implementation checklist

Use this short list to reduce surprises during rollout:

  • Validate cellular coverage at each parking position; add repeaters if needed for app flows.
  • Configure and test offline whitelists on chargers at sites prone to connectivity interruptions.
  • Create durable, weatherproof signage for QR codes, with instructions and a support number.
  • Map your roaming strategy: which tokens and networks you’ll accept via RFID, and how app payments complement that.
  • For Plug & Charge, align stakeholders on certificate issuance, renewal cadence, and incident response if a certificate fails.
  • Train site staff or fleet managers on the authorisation methods offered and common troubleshooting steps.

Which should you deploy?

For most mixed-use sites (fleet + visitor), the answer is RFID as primary with app QR as fallback. Plug & Charge is worth planning for in new DC fast-charger deployments.

This approach balances uptime, inclusivity, and cost-to-serve. It gives known drivers a near-instant start with minimal overhead, welcomes occasional visitors without requiring a card, and prepares your fast-charging assets for a growing base of compatible vehicles.

Key takeaways

  • There is no one-size-fits-all authorisation method. Match the method to site context, hardware, and user mix.
  • RFID remains the most pragmatic default for fleets and workplaces thanks to offline resilience and simplicity.
  • App/QR unlocks real-time pricing transparency and easy access for visitors, but depends on smartphone connectivity.
  • Plug & Charge delivers the fastest, lowest-friction experience at DC sites, with strong cryptographic identity — but requires compatible vehicles, chargers, and certificate management.
  • A hybrid stack (RFID + app/QR, with Plug & Charge where supported) provides the best coverage and future-proofs your network.
  • Clear signage, tested connectivity, and a defined fallback path matter as much as the technology you choose.

Conclusion

Authorisation is the front door to your charging experience. Get it right, and sessions start quickly, pricing is clear, and support tickets drop. Get it wrong, and even the best hardware can feel unreliable. Choose a mix that fits your locations today, with a path to adopt Plug & Charge where it adds the most value.

ChargeControl’s OCPP central system supports all three methods on the same back-end — you can serve RFID, app, and Plug & Charge sessions from the same charger without reconfiguration.

Try it on your sites

Curious which mix will perform best at your locations? Run our free site scan to see opportunities and quick wins. It takes a minute to get started: /scan

One platform for your charging operation

Do the free scan and see your own number within 24 hours — no account needed.