CSMS (Cybersecurity Management System)
A CSMS is the organisational process framework UN R155 requires from vehicle manufacturers. What it must cover, how it is audited, and what suppliers deliver to it.
Updated This page as Markdown
In short
A CSMS (Cybersecurity Management System) is the set of processes, roles and evidence with which a vehicle manufacturer manages cybersecurity across development, production and the post-production phase. UN Regulation No. 155 makes a certified CSMS a precondition for vehicle type approval; ISO/SAE 21434 describes the processes that fill it. The CSMS belongs to the OEM, but suppliers deliver work products into it.
What is a CSMS?
A CSMS is the management system with which a vehicle manufacturer organises cybersecurity: who is responsible, how risks to a vehicle type are identified and treated, how the vehicle is tested, how attacks in the field are detected and answered, and how all of that is documented. UN Regulation No. 155 defines it in paragraph 2.3 as “a systematic risk-based approach defining organisational processes, responsibilities and governance to treat risk associated with cyber threats to vehicles and protect them from cyber-attacks”.
The key word is process. A CSMS is not a product, not a security architecture and not a one-off assessment. It is the proof that the organisation does cybersecurity repeatably, for every vehicle type and over the whole lifecycle.
Where is it defined?
Paragraph 7.2 of UN R155 lists what the CSMS must cover. It applies to the development, production and post-production phases (7.2.2.1) and must include processes for managing cybersecurity in the organisation, identifying and assessing risks to vehicle types, treating them, verifying that treatment, testing the vehicle type, keeping the risk assessment current, monitoring, detecting and responding to attacks, and analysing attempted or successful attacks (7.2.2.2). Paragraph 7.2.2.3 adds the management of dependencies on suppliers, and 7.2.2.4 the ability to react to new threats within a reasonable time frame.
The approval authority or its technical service assesses the CSMS and issues a certificate of compliance, valid for up to three years. Only then can vehicle types be approved under paragraph 7.3. ISO/SAE 21434:2021 provides the engineering processes behind it, in particular Clause 5 (organisational cybersecurity management), Clause 6 (project-dependent management), Clause 7 (distributed activities with suppliers) and Clause 8 (continual activities such as monitoring and vulnerability management).
What it means in practice
For an OEM the CSMS audit is a document and interview exercise: policies, role descriptions, a cybersecurity plan template, the TARA method, test strategies, the incident and vulnerability handling process, and evidence that all of it has been applied to real projects. For a supplier the CSMS arrives as a stack of contractual requirements plus a cybersecurity interface agreement (CIA) that says which work products the supplier owes.
When we build CSMS work products with a Tier-1, most of the effort goes into three places. First, making the TARA method concrete enough that two engineers get comparable results. Second, defining what “cybersecurity validation” means for the component, because a test plan that only says “penetration test” will not survive the audit. Third, the post-production part: who watches for new vulnerabilities in the software bill of materials, who decides whether an update is needed, and how fast.
Common misunderstandings
A certified CSMS does not mean a vehicle is secure; it means the manufacturer has working processes to manage security. The vehicle type approval under paragraph 7.3 is the separate step where the results for a specific vehicle are checked. And a CSMS is not finished after certification: the processes have to run, the evidence has to grow, and the certificate is renewed at the latest every three years.
FAQ
Frequently asked questions
Does a supplier need its own CSMS?
Not under UN R155, which addresses the vehicle manufacturer. In practice OEMs pass the obligation down by contract: paragraph 7.2.2.3 requires the manufacturer to manage supplier dependencies, so suppliers are asked for ISO/SAE 21434-conformant processes, a TARA, test evidence and an interface agreement. Many Tier-1s run an internal management system for exactly that reason.
Who certifies a CSMS?
The type approval authority of a contracting state or a technical service it has designated, for example the KBA in Germany with services such as TÜV or DEKRA. The certificate of compliance is valid for a maximum of three years. Zyberum is not a certification body; we prepare the work products and the evidence, we do not issue the certificate.
Is a CSMS the same as ISO/SAE 21434 conformance?
No. The CSMS is a regulatory requirement from UN R155 and is audited. ISO/SAE 21434 is a standard that describes how cybersecurity engineering is done; it is the accepted way to show that the CSMS processes exist and work. You can follow the standard without an approval, and in theory build a CSMS without it, but nobody does.
Sources
Related pages
- GlossaryUN R155UN Regulation No. 155 makes cybersecurity a condition for vehicle type approval. Who it applies to, the CSMS and vehicle requirements, and how the EU enforces it.
- GlossaryISO/SAE 21434ISO/SAE 21434:2021 is the standard for cybersecurity engineering of road vehicles. Its clauses, how it relates to UN R155, and what it asks from OEMs and suppliers.
- GlossaryTARA (Threat Analysis and Risk Assessment)TARA is the risk analysis method of ISO/SAE 21434 for vehicles and ECUs. The seven steps, how impact and attack feasibility are rated, and what a usable TARA looks like.
- For your industryCybersecurity for Automotive Suppliers: UN R155, ISO/SAE 21434 and the CRAWhat Tier-1 and Tier-2 suppliers must deliver for cybersecurity: UN R155 and R156 via the OEM, ISO/SAE 21434 work products, CRA for aftermarket parts and a first project.
- ServicesISO/SAE 21434 that survives the audit and the attacker.ISO/SAE 21434 consulting by certified experts: gap analysis, CSMS implementation, TARA, verification and audit preparation for UN R155. With real testing.
