Automotive Cybersecurity

UNECE R155 · R156 · ISO/SAE 21434

Automotive cybersecurity is not new. What changed is that it stopped being an engineering choice and became a condition of sale.

We have worked on vehicle security since 2004 — first on cryptography inside the ECU, later on hardware security modules, and today on the management systems and evidence that type approval depends on. That continuity matters: the requirements auditors ask about now were engineering problems long before they were regulation.

How we got here

Twenty years from crypto to type approval

2004

Cryptography inside the ECU

Immobilisers, secure flashing, key handling. Security was a feature of individual components, solved by the engineers who happened to understand cryptography. There was no process, no standard and no auditor.

2009

Security moves into the architecture

The HIS Secure Hardware Extension and the EU EVITA project established hardware security modules as an architectural element rather than an add-on. Security began to be something you designed for, not something you bolted on.

2015

The remote attack becomes real

A remotely demonstrated attack on a production vehicle led to the recall of some 1.4 million cars. Connectivity had turned a component question into a fleet-wide product risk, and the industry could no longer treat security as a research topic.

2020

Regulation arrives

UNECE WP.29 adopted Regulations R155 and R156 in June 2020, tying vehicle type approval to a certified Cybersecurity Management System and a Software Update Management System. Security became an organisational capability that has to be demonstrated, not just a property of the product.

2021

ISO/SAE 21434 gives the method

Published in August 2021, ISO/SAE 21434 defined cybersecurity engineering across the full lifecycle — TARA, work products, the cybersecurity case. R155 says what a regulator demands; 21434 became the accepted way to show it.

2024

No certificate, no sale

Mandatory for new vehicle types since July 2022 and for all new vehicles since July 2024. Some models were discontinued rather than brought into compliance. A missing or lapsed CSMS certificate is now a commercial problem, not a documentation problem.

2027

Beyond the vehicle

The Cyber Resilience Act extends comparable duties to products with digital elements well outside the type-approval boundary — diagnostic tools, backends, aftermarket devices, development tooling. Reporting obligations have applied since September 2026; the regulation applies in full from December 2027.

More on the Cyber Resilience Act →

What we do

Where teams usually need help

Most organisations do not fail R155 on technology. They fail on evidence — the process exists in practice but cannot be shown to an auditor in a form that holds together.

CSMS build-up and audit readiness

UNECE R155 · R156

Building or repairing the management system behind type approval: process landscape, roles, evidence structure, and a dry run before the technical service arrives.

TARA facilitation

ISO/SAE 21434 Clause 15

Moderated threat analysis on your own item definition, producing a risk picture your engineers agree with and an auditor can follow — rather than a spreadsheet nobody revisits.

Automotive SPICE for Cybersecurity assessment

INTACS Principal Assessor

Formal assessment against the Security Extension, or preparation for one. Alexander Much is a certified INTACS Principal Assessor for Automotive SPICE with Security Extension.

Cybersecurity case and work products

Concept to production

Structuring the argument and the artefacts behind it, so the case reads as one line of reasoning instead of a folder of documents produced at different times by different people.

Safety and security co-engineering

ISO 26262 × ISO/SAE 21434

Resolving the interface between the two disciplines where it actually bites: shared items, conflicting requirements, and who owns a finding that is both a hazard and a threat.

Supply chain and post-production

CIA · monitoring · response

Cybersecurity interface agreements that suppliers can actually meet, plus the monitoring, triage and update path that R155 expects to remain in place for the life of the vehicle.

Scroll to Top